Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Checklist Plug-and-play starting point Supply Chain & GDP

Checklist: Trading-Partner DSCSA/EPCIS Interoperability Qualification

A plug-and-play checklist for qualifying a new DSCSA trading-partner data connection before the first commercial shipment: authorization, master data alignment, EPCIS/CBV version and transport, VRS responder registration, round-trip test, and data-ownership agreement, with a filled specimen.

Document type: Checklist

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use checklist for qualifying a new DSCSA trading-partner connection, manufacturer to distributor, distributor to dispenser, or either party to a 3PL or repackager, before the first serialized commercial shipment moves. Authorization (license and registration) answers the permission question: is this a partner you are allowed to trade with. This checklist answers the separate, technical question: can your systems actually exchange data with theirs. Replace every <<FILL: ...>> placeholder. A filled specimen follows. This content is educational and general, not legal or regulatory advice; confirm current requirements before you rely on it.

Document control header

FieldEntry
Document titleTrading-Partner DSCSA/EPCIS Interoperability Qualification Checklist
Document number<<FILL: CHK-ID, e.g. CHK-SC-018>>
Version<<FILL: version>>
Effective date<<FILL: effective date>>
Document owner<<FILL: role, e.g. Director, Trade Compliance>>
Applies to<<FILL: new trading-partner connections, all types>>

How to use this checklist

  1. Run one instance per new trading-partner connection, not once per counterparty company; a partner with multiple ship-from or ship-to locations may need more than one qualification if the technical connection differs by site.
  2. Work through each section in order. Record Pass, Gap, or N/A with the evidence reference.
  3. A connection goes live for commercial shipment only when every applicable line is Pass, or a Gap has a dispositioned interim control (for example, manual verification while an automated fix is pending).
  4. Re-run the relevant sections whenever the partner or your own platform changes EPCIS/CBV version, transport, or VRS responder.

1. Authorization and role determination

#CheckPass criterionEvidenceResult
A1Trading-partner type confirmedManufacturer, repackager, wholesale distributor, dispenser, or 3PL is correctly identified based on activities performed (title, repackaging, shipping), not commercial labelRole determination memo<<FILL>>
A2License and registration verifiedCurrent FDA registration and/or state license confirmed against the primary source (state board, FDA database)Screenshot or extract, dated<<FILL>>
A3Authorized-trading-partner register updatedPartner added with evidence attached and a re-verification date setRegister entry<<FILL>>

2. Master data alignment

#CheckPass criterionEvidenceResult
M1GTIN-to-NDC mapping confirmedBoth parties’ master data resolve the same GTIN to the same NDC, in the same format (4-4-2, 5-3-2, or 5-4-1)Master-data comparison sheet<<FILL>>
M2GLNs exchanged and confirmedEvery ship-from and ship-to location has an agreed GLN, confirmed on both sidesGLN cross-reference list<<FILL>>
M3Expiry-date and lot-format conventions matchFormat (for example YYMMDD) and lot-number conventions agreeFormat specification, signed off by both parties<<FILL>>

3. Technical connection

#CheckPass criterionEvidenceResult
T1EPCIS and CBV version agreedBoth parties confirm and document the EPCIS and CBV version (1.2 or 2.0) for this connectionSigned technical specification or interface agreement<<FILL>>
T2Transport method agreedFile-based (AS2/SFTP) or API/REST, and the endpoint, confirmed by both partiesInterface agreement<<FILL>>
T3Credentialing completeCertificates, API credentials, or platform-specific onboarding complete and testedCredential exchange record<<FILL>>
T4Schema validation passedTest EPCIS messages validate against the agreed GS1 US application standard schemaValidation report<<FILL>>
T5Round-trip test passedA live test message is sent, received, and successfully ingested by the partner’s actual receiving system, not a generic validatorRound-trip test log, both parties’ confirmation<<FILL>>

4. Verification (VRS)

#CheckPass criterionEvidenceResult
V1Responder reachable (if issuing party)The manufacturer/repackager’s VRS responder returns correct results for the GTINs in scopeTest verification result<<FILL>>
V2Routing confirmed (if requesting party)The requester’s platform successfully routes a query to the responder and receives a resultTest verification result<<FILL>>
V3Timeout and no-response handling definedBoth parties agree what “no response” means operationally (seconds/retries) and the fallback quarantine actionInterface agreement or WI reference<<FILL>>

5. Data ownership and responsibility

#CheckPass criterionEvidenceResult
D1Scanning and event-generation responsibility statedThe contract or quality/technical agreement states who physically scans and who generates the resulting EPCIS event, especially where a 3PL is involvedSigned agreement, clause reference<<FILL>>
D2T3/TS obligation owner statedThe agreement states which party carries the Transaction Information/Statement obligation for this connectionSigned agreement, clause reference<<FILL>>
D3Genealogy-preservation obligation stated (repackager connections only)Where the partner is a repackager, the agreement states the obligation to preserve traceability back to the original manufacturer lot and serialsSigned agreement, clause referenceN/A or <<FILL>>
D4Escalation contacts definedNamed contacts and escalation path for both a data exception and a suspect-product event are documented and sharedContact list<<FILL>>

Gap summary

Gap refCheck #DescriptionRisk (H/M/L)OwnerInterim control / remediationStatus
<<FILL: G1>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>><<FILL>>

Overall result and go-live approval

FieldEntry
Lines assessed<<FILL: count>>
Pass<<FILL: count>>
Gap (open, with interim control)<<FILL: count>>
N/A<<FILL: count>>
Go-live decisionApproved / Approved with interim controls / Not approved
Trade compliance sign-off (name, date)<<FILL>>
QA sign-off (name, date)<<FILL>>

References

DSCSA, section 582 of the Federal Food, Drug, and Cosmetic Act (21 U.S.C. 360eee-1). FDA guidance on DSCSA implementation and current exemptions (confirm the posture for each trading-partner type). GS1 US DSCSA implementation guideline (application standard for EPCIS/CBV in DSCSA exchange). Partnership for DSCSA Governance (PDG), Interoperability Blueprint (industry reference for transaction data exchange, verification, tracing, and credentialing).

Confirm the current version of each reference before issue.

Revision history

VersionDateAuthorSummary of change
<<FILL: 1.0>><<FILL: date>><<FILL: author>>Initial issue.

Filled specimen

The following shows a completed qualification for an example new wholesale-distributor connection onboarded by a manufacturer. Company, system, and evidence references are illustrative.

#CheckResultEvidence / note
A1Trading-partner type confirmedPassWholesale distributor, confirmed by activity (buys, resells, does not repackage)
A2License and registration verifiedPassState wholesale distributor license verified against state board database, 03 Aug 2026, expires 03 Aug 2027
A3Register updatedPassEntry TP-2026-0142, re-verification due 01 Jul 2027
M1GTIN-to-NDC mapping confirmedPassBoth parties resolve GTIN 00312345678906 to NDC 0312-3456-78, 5-4-1 format, cross-checked 05 Aug 2026
M2GLNs exchangedPass3 ship-to GLNs confirmed for the distributor’s regional DCs
M3Format conventions matchPassYYMMDD expiry confirmed both sides
T1EPCIS/CBV version agreedPassEPCIS 1.2 / CBV 1.2 for this connection, per interface agreement IA-2026-014; distributor is not yet on 2.0
T2Transport agreedPassAS2, endpoint confirmed
T3Credentialing completePassAS2 certificates exchanged and tested 08 Aug 2026
T4Schema validation passedPass20 test messages, 0 schema failures, report VAL-2026-0091
T5Round-trip test passedPassLive ship/receive test 10 Aug 2026, distributor confirmed ingestion into their WMS
V1Responder reachablePassManufacturer VRS responder returned correct valid/invalid results on 5 test GTINs
V2Routing confirmedN/AManufacturer is the issuing party for this connection
V3Timeout handling definedPass15-second timeout, 2 retries, then quarantine, per interface agreement
D1Scanning/event responsibility statedPassDistributor scans and generates receiving events at its own DCs; no 3PL involved on this connection
D2T3/TS obligation owner statedPassManufacturer generates outbound T3; distributor generates its own T3 on resale
D3Genealogy obligationN/ADistributor is not a repackager
D4Escalation contacts definedPassContact list shared, both data-exception and suspect-product paths

Overall result: 16 Pass, 2 N/A, 0 open Gap. Go-live approved 12 August 2026, K. Ofori (Trade Compliance) and R. Gomez (QA).

Common inspection findings this checklist prevents

  • A new trading partner connected and shipping commercially with no documented round-trip test, so the first real failure is discovered on a live shipment.
  • Master data (GTIN-to-NDC mapping, GLNs) never formally cross-checked, so downstream verification fails silently for weeks before anyone notices the pattern.
  • A 3PL or repackager relationship with no written statement of who scans, who owns the EPCIS event, and who carries the T3 obligation, discovered only when a data gap needs an owner.
  • EPCIS version mismatch discovered in production because neither party documented which version the connection was built to.
  • No defined timeout or fallback behavior for VRS unavailability, so returns processing stalls or waves product through under pressure.

How to adapt this checklist

  1. Set your document number, owner, and effective date in the header.
  2. Add or remove lines in section 5 depending on whether the partner is a 3PL, repackager, or a straightforward buyer/seller relationship; the data-ownership questions matter most exactly where the role is not a simple change of title.
  3. Tie this checklist to your onboarding workflow so a connection cannot go live commercially without a completed, approved instance.
  4. Re-run sections 3 and 4 whenever either party changes platform, EPCIS/CBV version, or VRS provider.
  5. Confirm the current statute, FDA guidance, and GS1 US implementation guideline version before issue.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.