Regulatory Intelligence
Regulatory intelligence is the organisation's ability to see regulatory change coming and be ready when it arrives: systematically watching the authorities, harmonisation bodies, and compendia that govern its products; filtering the stream for what applies; assessing impact against its actual products, filings, systems, and procedures; and routing the response into change control with time to execute before the effective date. ICH Q10 expects the quality system to be maintained against current requirements — which quietly presupposes a mechanism for knowing what current means. ICH Q12 sharpens the filing side: knowing which commitments are established conditions determines which regulatory changes touch the marketing authorisation and which the quality system can absorb internally.
What this page does not claim
A capability is something an organization must be able to do; it is not a maturity score and not an assessment domain. The scored domains measure how consistently capabilities are performed, they do not map one-to-one, and nothing on this page rates your organization.
What this capability is
Regulatory intelligence is the organisation's ability to see regulatory change coming and be ready when it arrives: systematically watching the authorities, harmonisation bodies, and compendia that govern its products; filtering the stream for what applies; assessing impact against its actual products, filings, systems, and procedures; and routing the response into change control with time to execute before the effective date. ICH Q10 expects the quality system to be maintained against current requirements — which quietly presupposes a mechanism for knowing what current means. ICH Q12 sharpens the filing side: knowing which commitments are established conditions determines which regulatory changes touch the marketing authorisation and which the quality system can absorb internally.
The capability lives or dies on the assessment step. Detection is increasingly cheap — feeds, alerts, and consultation calendars are public — but a stream of unassessed alerts forwarded to busy inboxes is noise wearing the costume of vigilance. The working question for every detected change is specific: which of our products, markets, systems, and documents does this touch, by when, and what must change? Mature organisations answer it against maintained maps of their own regulatory obligations, engage during comment periods rather than discovering final rules, and measure themselves on the only metric that matters — compliant on the effective date, without heroics.
WHY IT MATTERS
- Regulatory change is the one category of change the organisation does not schedule. Revisions, new guidance, transition deadlines, and pharmacopoeial updates arrive on the regulator's calendar — and an organisation without surveillance meets them in an inspection finding.
- The cost curve of late detection is brutal: a change caught at consultation is a comment and a plan; caught at publication, a project; caught at the effective date, a compliance gap; caught by an inspector, a finding with a history attached.
- Multi-market organisations multiply the problem. The same product answers to diverging requirements on different clocks, and reconciling them — implementing the strictest, tracking the exceptions — is impossible without a maintained picture of who requires what.
- Impact assessment is where the capability usually fails. Most organisations receive the news; far fewer can say within days which SOPs, systems, filings, and sites it touches — because that answer requires maintained mappings, not heroic recall.
[ POSITION IN THE FRAMEWORK ]
7 DIMENSIONS · 22 LINKSRegulatory intelligence watches the framework's external clock: detecting regulatory change early, judging impact against products, filings, and systems, and landing the response through change control before the effective date.
06 · QUALITY MATURITY — REGULATORY INTELLIGENCE, REACTIVE TO ADAPTIVE
Regulatory change is discovered by accident — a consultant's newsletter, a peer's remark, an inspector's question. Responses are scrambles priced at panic rates, and some changes are simply missed until the finding arrives.
Named people watch defined sources and circulate summaries on a cadence. Applicability is judged informally, impact assessment depends on who reads the email, and the trail from a detected change to completed implementation runs through inboxes rather than a system.
Surveillance coverage matches the regulatory footprint. Each detected change receives a documented applicability decision and, where applicable, an impact assessment against products, filings, systems, and documents — routed into change control with owners and dates driven by the effective date.
The organisation works ahead of the rulebook: consultations are tracked and commented on, transition periods are project-planned from announcement, and the implementation status of every applicable change is visible at a glance — with time-to-compliance measured and improving.
Intelligence is anticipatory: the organisation reads the direction of regulatory travel — draft guidance, inspection trends, harmonisation agendas — and positions itself before requirements land, influencing where it can and adapting early where it cannot. Regulatory change has become a managed input, not an interruption.
SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →
07 · REGULATORY & EVIDENCE
GOVERNING STANDARDS · 3
Derived from the 3 standards SPEQ maps to this subject, across 2 regulatory bodies: ICH, ISO.
RECORDS & OBJECTIVE EVIDENCE
- Documented surveillance sources matched to the full regulatory footprint
- Applicability and impact assessments for each detected change
- Implementation routed through change control, dated to the effective date
- Maintained mappings of established conditions and registered commitments
- Tracked transition plans for applicable-but-not-yet-effective requirements
COMMON INSPECTION FINDINGS
- New requirements first learned of from an inspector
- Effective dates passed with implementation incomplete
- Surveillance stopping at the home market while product ships wider
- Impact assessments unable to name the SOPs and systems a change touches
- Pharmacopoeial updates never assessed against current specifications
HOW YOU’D SEE WHERE YOU SIT
- Pick a significant regulatory change from the last two years and trace it: when the organisation first knew, when applicability was decided, and whether implementation completed before the effective date.
- Whether the sources actually watched cover every market the organisation sells into, or the surveillance footprint quietly stops at the home region.
- Ask what the organisation submitted to the last relevant public consultation — engagement during comment periods is the difference between watching the future and receiving it.
- How long it takes to answer "which of our SOPs and systems does this new requirement touch?" — days against maintained mappings, or weeks of archaeology.
- Whether a current list of applicable-but-not-yet-effective requirements exists, with owners and dates, or the future is stored in individual memories.
Observable behaviours, not a self-rating — what a capability looks like from the outside, the same way SPEQ’s Quality Culture assessment reads behaviour rather than felt safety.
FREQUENTLY ASKED
How is regulatory intelligence different from regulatory affairs?
Regulatory affairs manages the organisation's formal interactions with authorities: submissions, variations, meetings, commitments for specific products. Regulatory intelligence is the surveillance-and-assessment function that feeds it — and feeds quality, manufacturing, and engineering too, because much regulatory change lands on systems and procedures rather than filings. The two overlap in people and often in reporting line, but they fail independently: an excellent submissions team can be blindsided by a guidance change no one was watching for, and a superb watch function is wasted if its findings never reach the owners of the documents and systems that must change. The capability described here is the watch, the judgement, and the handoff.
What does ICH Q12 have to do with regulatory intelligence?
Q12 defines the boundary the capability's impact assessments constantly navigate: established conditions — the elements of a product's registration that legally bind the marketing authorisation — versus everything the quality system may manage on its own authority. When a regulatory change arrives, or an internal response to one is designed, that boundary determines the answer to the most expensive question in the workflow: does this require a regulatory submission, and in which markets? An organisation with mapped established conditions answers by construction; one without them answers by memory and hope, and discovers the difference during an inspection or a variation assessment.
The maturity assessment has a Regulatory Intelligence domain — is that the same thing?
Same name, different role, and the distinction is the model's central idea. The capability described on this page is a function: the organisation's ability to detect, assess, and land regulatory change. The assessment domain of the same name is a measurement axis: scored questions that observe how consistently that function — and neighbouring behaviours like inspection engagement and commitment management — actually operates. The name collision is honest, because here the mapping happens to be close; elsewhere a single domain measures several capabilities at once. Read the ladder here to understand the function's maturity; take the assessment to locate your organisation on it.
MEASURED THROUGH THE MATURITY ASSESSMENT
This capability is about what you must be able to do. How consistently you do it is what the maturity assessment scores — through the domain below.
Contributes to the FDA QMM practice area Management Commitment to Quality (a SPEQ mapping).
Score your quality system →