[ OPERATING INTERSECTION ]
Continuity, shortage & controlled recovery
Maintaining supply while protecting quality, safety, authorization, and evidence during disruption.
What this page does not claim
SPEQ synthesis for education. Confirm applicable law, current guidance, standards editions, contractual duties, and organization-specific controls before making a regulated decision.
The seam below, its failure modes and its decision boundaries are SPEQ’s practitioner framing — not a regulatory requirement, and not an assessment of any organization.
OPERATING QUESTION
Can alternate operations and recovery preserve control rather than merely restore output?
Capabilities in the same decision
Why this is hard
Continuity planning is built around a clock and regulated supply is built around a filing, and the two cannot be made to agree. A recovery plan is exercised against a recovery-time objective: hours to the alternate data centre, weeks to the alternate line, days of finished-goods cover. The alternate site, the alternate supplier and the alternate route are also particulars of a marketing authorisation in every market the product is sold in, and moving them is a regulatory transaction measured in months. A plan that reads as complete therefore assumes a flexibility the dossier does not grant, and the discovery happens on day two of a real disruption rather than in the tabletop exercise, because the exercise tested the operational hop and not the authorisation standing behind it. Pressed on top of that is an inversion this seam has and almost no other operating decision does. Normally a quality decision that halts product costs money, and the patient argument sits on the side of the control. In a shortage the patient argument sits on the side of shipping, everybody in the room knows it, and the harm from withholding is immediate and named while the harm from a weakened control is statistical and deferred. That is not a failure of character. It is an asymmetry in how two harms present themselves, and it is why decisions taken honestly under scarcity need a different kind of record than decisions taken in normal operation.
How it fails
Each of these happens with every function doing its own job correctly. That is what makes them seam failures rather than performance problems.
The recovery plan names a site the filing does not
The continuity plan identifies an alternate line, a second site or a contract manufacturer, and the exercise that validated it confirmed the operational hop: equipment available, materials sourceable, people trainable. What the exercise did not test is whether that location is a registered manufacturing site in each market, which change pathway would be required, and how long each authority takes. Those answers sit with regulatory affairs, who were not in the exercise, and the plan and the dossier were each reviewed on their own cadence by people who never compared them.
Temporary controls quietly become the permanent process
Recovery runs on workarounds that are correct at the time: manual recording while a system is down, a second-source material under an interim specification, an extended campaign to rebuild cover, a deferred requalification. Each is documented and each is meant to be temporary. Restoration is declared when output returns, and output returning is a visible event while a workaround expiring is not, so the interim arrangement persists — still authorised, still on file, and now describing how the process actually runs. Recovery has no equivalent of a turnover punch list, so nothing forces the list to reach zero.
Risk accepted under pressure is never re-examined
The decision to keep operating with a single qualified supplier, a stretched maintenance interval or a deferred verification is taken deliberately, with the supply argument stated, and it is frequently the right decision. What is usually missing is the second decision. The acceptance is written as a state rather than as a standing position with a review trigger, so when the constraint that justified it eases, nothing prompts anyone to revisit it. The exception outlives its own justification, and the rationale on file still reads as current because it was true when it was written.
Nobody tells surveillance that the process changed
During recovery the conditions producing the product move — a different line, a different component source, longer campaigns, newer operators — and the place any effect will surface is the complaint and signal stream, months later. That review continues on its usual cadence against an undifferentiated baseline, so a rise attributable to the alternate arrangement is diluted inside normal volume and never attributed to it. The information needed to stratify the analysis existed the whole time; it simply never crossed from the people running the recovery to the people watching the product.
What good looks like
The plan is tested against the constraint that actually binds. An exercise that ends when the alternate line runs has tested the easy half; the useful version asks what the authorisation permits, where markets diverge, and what the lead time is for each pathway — and records those answers inside the plan rather than as work to be done later. Interim arrangements are opened with a named expiry and an owner accountable for closing them, and the count of open ones is reported to the same group that receives the output-recovery number, so the two are read together. Risk taken under scarcity is written as a position with a stated review point and the conditions that would end it, not as a one-time approval. Surveillance is told in advance which product, which period and which change, so the postmarket view can be stratified while the data is still arriving instead of reconstructed afterwards. And where a regulator must be told about an interruption in supply, the trigger is wired into the operating process rather than left to somebody remembering, because that notification clock usually starts long before the shelf is empty.
Who decides what
Operations decides how to keep running; it does not decide what running is allowed to look like. The boundary of acceptable alternatives belongs jointly to Quality, regulatory affairs and — where product is already in patients’ hands — the safety function, and the practical point is that the boundary has to be drawn before a disruption, because a boundary negotiated during one is negotiated by people with an urgent reason to move it. Regulatory affairs owns the statement of what the authorisation currently permits and what each departure from it would require, and that statement is a precondition of the plan rather than a response to an incident. Quality owns acceptance of residual risk and, critically, owns the expiry: authority to accept a weakened control should carry an obligation to name when the acceptance is reviewed. Executive leadership owns the allocation of scarce capacity between products and markets, which is genuinely an executive decision and is frequently made informally by a scheduler instead. The authority most often left unassigned is the one to declare recovery finished — and if it rests with whoever restored output, the interim arrangements never close, because from where they stand the job is done.
Questions practitioners ask
Is a business-continuity plan enough to cover regulated supply?
Not by itself. A continuity plan is designed to restore capability and is usually good at that. It rarely carries the second half of the question — whether the restored capability is one the product is authorised to be made on, and what evidence the restored state needs before it can produce releasable material. Those are separate assessments, and they belong inside the plan rather than alongside it.
Does a shortage justify releasing product that does not meet its specification?
Not on the manufacturer’s own authority, and framing the question that way hides where the real decisions are. Specification conformance is not the flexible element. What actually gets traded under scarcity is everything around it: how much redundancy the supply chain runs with, how long a verification is deferred, how much testing is done beyond the required set, how quickly a deviation closes. Those are legitimate risk acceptances and deserve to be recorded as such rather than absorbed as pressure. Where genuinely exceptional supply arrangements exist, they are the regulator’s decision to make and are sought, never assumed.
When does an alternate supplier need regulatory action before use?
It depends on what the authorisation says about that material in that market, which is exactly why the answer belongs in the plan and not in the incident. Some changes are notified, some require approval before use, and the same change can sit in different categories in different markets — so a plan written around one market’s pathway can fail in another while everything about the operation is identical.
How long should an interim arrangement be allowed to run?
Long enough is a judgement, but running with no stated end is not a judgement at all. The workable practice is to give every interim control a date and an owner at the moment it is opened, and to treat an extension as its own decision with its own rationale — so a control that has run for a year has been deliberately extended several times rather than simply never revisited.
Critical handoffs
- Operations and supply identify threatened capacity.
- Quality, regulatory, safety, and security bound acceptable alternatives.
- Leadership allocates constrained resources and records residual risk.
Shared evidence
- Business-impact and continuity assessments
- Alternate-source, change, regulatory, and quality decisions
- Recovery test, reconciliation, shortage, and executive records