Certificate of analysis software produces the document that proves a batch meets its specification: the tests run, the limits agreed and the results measured, signed off by quality. At Lleverage we think most CoA products automate the template and leave the harder half with your quality team: reading each customer's specification and keeping it current.
The scene is familiar in chemicals, coatings and food ingredients plants. The truck is booked, the batch has passed in the lab, and someone in quality is still copying results from the LIMS export into a Word template. This customer wants viscosity in a different unit, a test method nobody else asks for, and tighter limits than the standard product sheet. The customer's specification sits in a PDF attached to an email from last spring, and nobody is certain it is still the latest revision. This article sets out what a certificate of analysis has to contain, compares the 4 common ways of producing one, and explains where an AI agent changes the work.
That view comes from working with manufacturers and processors whose quality and order desks run on customer documents that no system reads for them. We build AI agents that read those documents, check the record against the rules, draft the paperwork that leaves with the shipment and hand the exceptions to a person, which is the same work our export document and delivery agents do off the order. If you want to see it against your own customer specifications, book a demo.
What is certificate of analysis software?
Certificate of analysis software generates, stores and sends the batch-level quality certificate that travels with a product. It pulls the test results for a lot and lays them against the specification. It then formats the document per product or customer, records the approval and archives the output for the day a customer or auditor asks.
The term covers several kinds of product. Process ERP vendors such as Deacom generate the certificate inside the ERP at shipment, quality control systems such as AlisQI build it from templates per product or per product and customer, and distribution systems such as VISCO warn before a lot ships outside a customer's requirements. Those descriptions come from each vendor's own product pages as they stood in September 2026.
What they share is an assumption that the specification already exists as structured data, typed in by somebody and kept current by somebody when the customer changes it. Where most volume ships on the standard sheet, that is manageable. Where much of it ships against customer-specific specifications, it is most of the job, and it is the part the software does not do.
What must a certificate of analysis contain?
A certificate of analysis names the product and batch, lists every test performed with its acceptance limits and the result obtained, and carries a dated signature from an authorised person in the quality unit. For active pharmaceutical ingredients those contents are written down in the ICH Q7 guideline; food, chemicals and cosmetics customers usually set their own.
The clearest published reference is ICH Q7, the good manufacturing practice guideline for active pharmaceutical ingredients, which the US Food and Drug Administration publishes as guidance (Revision 1, September 2016). Section 11.4 of that guideline sets out what a certificate should carry:
- The name of the intermediate or active ingredient, its grade where appropriate, the batch number and the date of release.
- The expiry date or the retest date, where the material has one.
- Each test performed in accordance with compendial or customer requirements, with the acceptance limits and the numerical results obtained.
- A date and signature from authorised personnel of the quality unit, plus the name, address and telephone number of the original manufacturer.
- Where a repacker, reprocessor, agent or broker reissues the certificate, the laboratory that performed the analysis, a reference to the original manufacturer and a copy of the original batch certificate.
Two phrases in that list do most of the damage. "Compendial or customer requirements" means one certificate per product and customer, each with its own tests and limits. "The numerical results obtained" means every certificate is a fresh reconciliation between what the lab measured and what that customer specified. Outside pharmaceuticals the legal wording varies, but food, coatings and chemical buyers write their own specifications into supply agreements and expect the certificate to answer them line by line.
Why is CoA management still so manual in process plants?
CoA management stays manual because the input is unstructured. Customer specifications arrive as PDFs, spreadsheets and email threads. Each has its own layout, units and test names, and they change without warning. Someone has to read every one, translate it into the system's fields and notice when a revision arrives. That reading is the work.
When a new customer specification arrives, the quality desk reads it, picks out the parameters the customer cares about and maps each to a test the lab already runs (the customer writes "kinematic viscosity at 40 °C", the LIMS says "VISC-40"). It converts units, notes where the customer's limit is tighter than internal release, and keys it all into whichever system prints the certificate. When revision 4 arrives, someone has to spot the difference and do it again.
The same problem runs in the other direction, because every raw material batch arrives with its supplier's certificate. The US drug manufacturing rules in 21 CFR 211.84(d)(2) let a manufacturer accept a supplier's report of analysis in place of its own testing. The conditions are at least one specific identity test of its own and periodic proof that the supplier's analyses are reliable. ICH Q7 section 7.31 goes further and asks for complete analyses on at least 3 batches before in-house testing is reduced. Both rules assume someone is reading the supplier certificate carefully enough to compare it.
We think this is why so many plants that own certificate of analysis software still produce certificates in Word. The system prints a certificate perfectly once the specification is in it. Getting the specification into it, and keeping it right, is the step nobody bought software for. It is also a master data problem in disguise: a customer specification is a record that lives in several places at once, and it drifts the same way a VAT number does.
How do certificate of analysis software approaches compare?
There are 4 common ways to produce certificates of analysis: manual Word or Excel templates, a LIMS certificate module, a quality or ERP module that prints at shipment, and an AI agent layer that reads specifications and drafts the certificate. The first 3 differ in where the template lives; only the fourth changes who reads the customer's specification.
| Word or Excel templates | LIMS certificate module | ERP or QMS quality module | AI agent layer | |
|---|---|---|---|---|
| Where results come from | Copied by hand from the lab record | The LIMS itself | Quality records in the ERP or QMS | Read from the LIMS, ERP or lab export |
| Customer specification | In someone's folder, re-read each time | Typed into templates per product and customer | Held on the customer or item record | Read from the customer's own document and matched to your tests |
| Spec revisions | Noticed if someone remembers | Re-entered by quality | Re-entered by quality | Flagged when a new revision arrives, for a person to confirm |
| Out-of-spec check | The person's eye | Automatic once limits are entered | Automatic once limits are entered, some block the pick | Automatic, with the batch held for a person |
| Supplier CoAs coming in | Read by hand | Some modules import them | Usually read by hand | Read and compared against the purchase specification |
| Best fit | Very low volume, few customer specs | Lab-centred plants with stable specs | Plants that want one system of record | Many customer-specific specs that change often |
The 3 established kinds of certificate of analysis software are good at producing a certificate. They also check a result against a limit once that limit is in the system. None of them reduces the reading. With few, stable specifications a LIMS or ERP module is the right answer and an agent adds little; with many customer documents that change, the reading is where the hours go.
What does an AI agent add to certificate of analysis automation?
An AI agent does the reading that certificate of analysis software leaves to people. It maps each customer requirement to the test your lab runs, compares batch results against the customer's limits and drafts the certificate in that customer's format. Anything out of specification or ambiguous waits for a person, who reviews a finished draft instead of building one.
We have not published a certificate of analysis customer yet, so the proof below is adjacent. The closest match is SPL Treatments, an aerospace surface engineering company in Sheffield working to Nadcap accreditation. The job is structurally the same: read a customer's order, find the specifications it references, check them against a library of more than 800 aerospace standards, and decide what the part needs. At SPL Treatments that decision used to take around an hour per first-time part and now takes 2 to 2.5 minutes, with every recommendation cited to the specification section it came from. In its first 3 weeks in production the SPL workflow ran 136 times.
The design choice that matters for certificates is that the agent flags gaps instead of filling them: a missing reference, an ambiguous requirement, 2 sections that conflict. A person makes the call, and the correction teaches the agent. Grant Riley, who owns every treatment decision at SPL, put it this way:
"90% of things are correct within a result. It feels a bit negative to give it a thumbs down." Grant Riley, Operations and Technical Lead, SPL Treatments
Two other published stories show the pieces a CoA workflow depends on. At Oude Reimer, a precision machinery business, an agent answers technical questions across 170 manuals in 70 seconds, citing the exact manual and section. That is the citation discipline a certificate needs. At Microtechniek, purchase orders reach the on-premise ERP with 99.5% field-level accuracy across more than 100 real orders. That is the accuracy you want before an agent transcribes lab results.
Which customer calls a test by which name, which unit they want, which statements they expect printed: that knowledge sits in a company knowledge layer your team can read and correct, rather than in one quality officer's memory.
How do you stop an out-of-spec batch from shipping with a certificate?
You stop it by making the certificate step a check rather than a formatting job. Every result is compared against the customer's own limit as well as the internal release limit. A batch outside it, or a requirement the system cannot match with confidence, goes to a named person before any document is issued.
The common trap is a batch that passes internal release and ships to a customer with a tighter specification: internal moisture limit 0.5%, customer limit 0.3%, batch measured 0.4%. Any certificate of analysis software prints the true result, and the problem surfaces at the customer's goods-in. Deacom, per its product page, handles this by letting warehouse staff pick only lots that meet the tighter specification. An agent reaches the same outcome from the document side, because it read the customer's limit and holds the certificate.
What should always go to a person?
In our setup a threshold decides what the agent completes on its own and what waits for review, every action is logged with what it read and why, and the line only moves when you move it. That control and audit trail is what a quality auditor will ask to see. For certificates we recommend a conservative line:
- A result outside the customer's limit holds the certificate and alerts quality.
- A requirement the agent cannot map to a lab test goes to quality with the passage quoted.
- A new specification revision is compared with the previous one, and the differences are shown for approval before they apply.
- A signature is never applied by the agent; the authorised person in the quality unit signs.
Inbound supplier certificates follow the same logic: read, compared with your purchase specification, clean ones passed to goods-in and deviations held. That is a compliance check on the record itself rather than a report read a month later.
Which CoA management approach fits a process manufacturer?
The right approach depends on how many customer-specific specifications you hold and how often they change. A few stable specifications suit a LIMS or ERP module. Many customer documents that change often suit an AI agent layer in front of the system you already have, because the reading is the bottleneck, not the printing.
Our reading of it is this. If you already run certificate of analysis software in a LIMS or process ERP, keep it as the home for results and archived certificates. Then put the reading in front of it: an agent that turns each customer specification into the fields your module expects, notices revisions and drafts certificates for quality to approve. If you still work in Word, the agent can draft into your templates while you decide whether a quality module is worth the project.
A practical test takes an afternoon. Count the customer-specific specifications you maintain, how many changed in the last 12 months, and who knows how each key account wants its certificate. If the answers are "dozens", "more than we tracked" and "one person", start with the reading. Sales orders arrive the same way, which is why order entry and certificates often share one set of customer rules.
Frequently asked questions
What is the difference between a certificate of analysis and a certificate of conformance?
A certificate of analysis reports the measured test results for a specific batch against its specification limits. A certificate of conformance states that the product meets a specification or standard without necessarily listing results. Process manufacturers usually issue a certificate of analysis because customers want the numbers, batch by batch, for their own incoming inspection.
Who is allowed to sign a certificate of analysis?
Under ICH Q7 section 11.43, certificates for active pharmaceutical ingredients should be dated and signed by authorised personnel of the quality unit. Outside pharmaceuticals, the supply agreement usually sets who signs. Certificate of analysis software or an AI agent can draft and check the certificate, but the signature belongs to the authorised person.
Can a supplier's certificate of analysis replace our own testing?
Partly, under conditions. ICH Q7 section 7.30 allows a supplier's certificate in place of other tests if at least one identity test is run on each batch and suppliers are evaluated. The US rule in 21 CFR 211.84(d)(2) also requires periodically validating the supplier's results. The certificate still has to be read and compared every time.
Does certificate of analysis software need to connect to our LIMS or ERP?
It needs the batch results from wherever they are held. A connection to the LIMS or ERP is the cleanest route, but it is not a precondition: an agent can work from a lab export, and at SPL Treatments, whose legacy ERP has no way in, the confirmed output is keyed in by hand and the time is still saved upstream.
See it on your own customer specifications
The quickest test is the documents that cost your quality team the most time. Bring 3 or 4 customer specifications, one that changed recently, and a batch of results, and we will show the agent reading them, matching them to your tests and drafting certificates, with out-of-spec cases held for review. Book a demo and we will set it up with your quality lead.
