[ ENTERPRISE PILLAR 02 ]

Regulatory Strategy & Intelligence

Translate product intent and changing authority expectations into viable pathways, maintained licenses, and controlled commitments.

What this pillar does not claim

This pillar governs market and authority strategy; it does not duplicate the source-level regulator, standard, citation, or live-intelligence catalogs.

The capability framing below, its failure modes and the boundary with neighbouring pillars are SPEQ’s practitioner reading — not a regulatory requirement, and not an assessment of any organization.

THE CAPABILITY

What this capability is

This is the organization's working map of what applies to it, held as a live position rather than a filed conclusion. It runs in two directions at once, and the two are one object read from opposite ends. Outward, it is the case the organization intends to put to an authority: what the product is, which route it will travel, what evidence will support the ask, and what the organization is prepared to promise in return for permission. Inward, it is the machinery that notices the outside world has moved and routes that movement to whoever now has to act. The record of promises made and the record of obligations imposed are the same record, because both constrain the same operations and both are read by the same reader. Split them, and an organization ends up with an intelligence function that knows the rules, a submission function that knows the promises, and nobody holding the position.

Why it is hard

The subject matter changes on somebody else's schedule and in somebody else's vocabulary. Every other capability moves when the organization moves it; here a published change arrives phrased in an authority's terms and someone has to decide whether it touches products described in the company's terms. That is a mapping problem with no key, performed under time pressure by whoever happened to receive the alert. The economics of the decision then push steadily one way. Concluding that something does not apply generates no assessment, no task, no owner and no reviewer; concluding that it does generates visible work for people who did not ask for it. The screening step is therefore biased toward not-applicable, and because non-events leave no trace the bias never surfaces in any measure of how the function is performing. Layered on top is the strange half-life of what this pillar creates. A sentence in a meeting record, a paragraph answering a question, a value written into a submitted document — each becomes a binding constraint on operations, made by people who will have moved on before it bites, and stored in correspondence archives that nothing operational ever queries. An organization can hold an immaculate view of external requirements and still be in breach of a promise it made about itself.

How it fails

Each of these happens with the individual branches below being run competently. That is what makes them capability failures rather than performance problems.

Intelligence is a distribution list rather than a decision

A digest goes out weekly to a wide audience, and the act of circulating it is recorded as the control. Every recipient reasonably assumes the applicability judgement happened upstream; upstream assumes the recipients are the judges. Nothing is refused and nothing is assessed. The gap surfaces the first time somebody asks who evaluated one specific change, and the honest answer turns out to be the mailing list.

The commitment register holds what people remembered to log

Undertakings are made in meetings, in answers to questions and in the fine print of documents that were submitted years ago. Some of them reach a register; the rest live in an archive organized by date and correspondent rather than by obligation. The usual discovery route is somebody reading that file for an unrelated reason, long after the operation the promise constrains has quietly changed shape.

The registered position and the operating one drift apart

Each change was individually assessed, each assessment concluded no notification was needed, and each conclusion was reasonable on its own terms. What nobody holds is the cumulative distance between what was authorized and what is now run, because the assessment unit is the single change while the exposure unit is the sum of them. The discovery event is nearly always external, and nearly always arrives as a question about something else.

Applicability is screened by product family, not attribute

Incoming change is matched against a portfolio list or a therapeutic grouping, because that is how the register is organized and how people think about the business. What gets missed is everything sharing the attribute the change actually addresses — a component, an excipient, a sterilization step, a claim on a carton — while sitting under a label nobody thought to open.

WHERE THIS STOPS

Ours or theirs

This pillar decides what must be true and what must be told. It does not create the evidence that makes it true: development, clinical, manufacturing and the laboratory own the underlying work, and a function that writes the scientific justification itself has moved the argument out of the place where it can be defended. The seam that generates the most argument is change assessment. This capability owns whether a change must be notified or approved before it takes effect; governance owns whether the change is acceptable at all. The two judgements are made on the same form, at the same meeting, and each side can quietly assume the other has answered the question of whether the change is a good idea. The second seam is labelling: the approved text belongs here, while the artwork, the print vendor and the carton on the line belong to operations, and the version that was approved and the version being printed sit in different systems with different change clocks. The third is the reporting clock in safety, which starts on somebody else's document even when the notification eventually leaves over this function's signature.

Questions practitioners ask

Is regulatory intelligence just horizon scanning under another name?

Scanning is the collection step and the easier half. Intelligence is what happens after collection: deciding applicability against a specific portfolio, sizing the impact, naming an owner, and tracking the result to a change that is either made or consciously declined. A function that only scans produces a stream. A function with intelligence produces decisions with owners attached to them.

Who decides whether a change needs telling before it takes effect?

This pillar makes that judgement, but it cannot make it alone, because the answer turns on technical facts only the change owner holds: what exactly moved, how far, and against what was originally described. The arrangement that works is that the change owner supplies the characterization and this function supplies the classification, both recorded in one assessment rather than in two that never meet.

What counts as a commitment, in operating terms?

Anything the organization has said it will do that a reader could later hold it to: a study offered at a meeting, a monitoring frequency written into a submitted document, a value stated as a limit, a date given in a response. The practical test is whether an operation would have to change if the statement were withdrawn. If it would, it is a commitment and it needs a named owner.

Why does this pillar not simply own the regulator and standards library?

A catalogue of sources answers what exists in the world. This capability answers what applies here, to this product, in this market, this quarter, which is a judgement about the organization rather than a fact about the world. Keeping the two apart stops the library from being quietly edited to fit a position somebody has already taken.

CAPABILITY BRANCH MAP

What this pillar contains

01

Classification & pathway strategy

Determining what the product legally is — drug, biologic, device, combination, food, cosmetic — in each market, and which development and authorisation route follows from that. The answer sets the evidence, the timeline and the regulator.

Classification is the decision every other regulated activity inherits. Get it wrong and the studies run to the wrong standard, the quality system is built against the wrong regulation, and the error surfaces at submission when it is most expensive to correct.

HOW IT FAILS

  • Classification is assumed from a similar product rather than reasoned from the intended use and mechanism actually claimed.
  • A single classification is applied globally, so a product regulated as a device in one market is developed only to drug expectations.
  • The rationale is never written down, so when a regulator challenges the route nobody can reconstruct why it was chosen.

WHAT CONTAINS IT

  • A documented classification rationale tied to intended use, mechanism of action and the claims to be made.
  • Jurisdiction-by-jurisdiction confirmation rather than extrapolation from the lead market.
  • Re-assessment when intended use, claims or formulation change during development.

EVIDENCE IT OPERATES

  • Classification and pathway rationale with the regulatory basis cited.
  • Authority correspondence or scientific advice confirming or challenging the route.
  • Change records showing re-assessment when the product definition moved.
02

Regulatory intelligence & horizon scanning

Watching the sources that can change what the organisation must do, deciding whether a given publication applies, and routing it to an owner who can act — before the effective date rather than after an inspection.

Regulatory change is continuous and mostly published in plain sight. The failure is almost never that a change was secret; it is that nobody was accountable for noticing it, so a transition period elapsed while the organisation was busy.

HOW IT FAILS

  • Monitoring covers the primary regulator and misses the standards bodies, compendia and notified-body guidance that bind just as hard.
  • Detection has no triage step, so everything is circulated to everyone and nothing is assessed by anyone.
  • Applicability is decided informally, so a change judged irrelevant leaves no record of who judged it or why.

WHAT CONTAINS IT

  • A defined source list with named owners, reviewed for gaps rather than assumed complete.
  • Documented applicability triage with an accountable decision, including a reasoned "does not apply".
  • A route from an applicable change into change control with a target date ahead of enforcement.

EVIDENCE IT OPERATES

  • Source register and monitoring records showing coverage and cadence.
  • Applicability assessments with rationale, owner and disposition.
  • Change records traceable back to the publication that triggered them.
03

Health-authority engagement

The conduct of the relationship with health authorities: meeting requests, scientific advice, questions and responses, inspection interactions, and every undertaking given in the course of them.

What an organisation says to a regulator becomes a commitment it will be held to, often years later by different people. Engagement is therefore a controlled activity, not a conversation — and inconsistency between what two functions tell the same authority is read as a quality-system failure.

HOW IT FAILS

  • Commitments are made verbally in a meeting and never captured in a system anyone tracks.
  • Different functions answer the same authority inconsistently because no single record of position exists.
  • Responses are drafted to close the question rather than to be defensible when the underlying issue recurs.

WHAT CONTAINS IT

  • A single controlled record of positions, questions and responses per authority and product.
  • A commitment register capturing every undertaking, its owner and its due date at the moment it is made.
  • Cross-functional review of responses before they are sent, including by the function that must deliver them.

EVIDENCE IT OPERATES

  • Meeting requests, briefing packages, minutes and authority feedback.
  • Commitment register with status and the evidence that closed each item.
  • Response packages with the internal approvals behind them.
04

Submission strategy & planning

Designing the dossier: what modules exist, which functions own which content, what each depends on, when it must be ready, and how it is compiled, validated and dispatched in the required electronic format.

A submission is the point where every other function is asked to produce evidence simultaneously. Where the plan is weak, the critical path is discovered late, and content is written to a deadline rather than to the standard the reviewer will apply.

HOW IT FAILS

  • Content plans list documents but not the dependencies between them, so a late study report silently blocks four other sections.
  • Readiness is measured by document count rather than by whether the content supports the claim being made.
  • Publishing and validation are treated as an administrative step at the end and become the actual bottleneck.

WHAT CONTAINS IT

  • A dependency-aware content plan with named owners and dates that reflect the true critical path.
  • Defined readiness criteria per module, assessed by someone other than the author.
  • Technical validation rehearsed before the real dispatch rather than discovered during it.

EVIDENCE IT OPERATES

  • Submission plan with owners, dependencies and readiness gates.
  • Document approval and quality-review records for submitted content.
  • Validation and dispatch records, including acknowledgement of receipt.
05

Registrations, licenses & establishment obligations

The authorisations that let an organisation operate at all — product approvals, manufacturing and wholesale licences, establishment registrations, importer and responsible-person designations — and keeping each current in every market served.

These are the permissions the business runs on, and they lapse quietly. A registration that expired because a renewal was missed stops supply just as effectively as a failed batch, and with no quality signal to warn anyone.

HOW IT FAILS

  • Renewal dates live in individual calendars or a spreadsheet with no owner, so a lapse is discovered by a customs hold.
  • A site or process change is made without checking which licences describe the site as it was.
  • Market-specific obligations — local representative, importer of record — are assumed to be the distributor’s problem and are nobody’s.

WHAT CONTAINS IT

  • A registration and licence inventory with expiry, renewal lead time and a named owner per entry.
  • Change control that asks which authorisations describe the thing being changed before it changes.
  • Explicit allocation of each market-specific role, agreed in writing with the party performing it.

EVIDENCE IT OPERATES

  • Current licences, registrations and certificates with expiry tracking.
  • Variation and notification records following site or process change.
  • Agreements defining local representative, importer and responsible-person duties.
06

Labeling, claims & promotional compliance

Control of what the product says about itself and what the organisation says about the product: approved labelling and its translations, artwork change control, and the boundary between authorised claims and promotion.

Labelling is a regulated output that reaches the patient directly, and a claim beyond the authorisation is an enforcement matter rather than a marketing dispute. Artwork errors are also among the most common causes of recall.

HOW IT FAILS

  • Artwork changes follow a marketing timeline rather than change control, so an unapproved version reaches print.
  • Translations are treated as a linguistic task rather than a regulated one, and meaning drifts from the approved text.
  • Promotional material is reviewed for brand consistency but not against the authorised indication and safety information.

WHAT CONTAINS IT

  • Artwork and labelling under formal change control with proofing against the approved text as the release step.
  • Translation verification back to the approved source, performed by someone qualified to judge meaning.
  • Promotional review that includes regulatory and medical sign-off against the authorisation.

EVIDENCE IT OPERATES

  • Approved labelling versions with the change history behind each.
  • Artwork proofing and release records, including translation verification.
  • Promotional review approvals with the authorised claims they were checked against.
07

Post-approval lifecycle management

Everything that happens to an authorisation after it is granted: variations and supplements, renewals, annual reports, commitments made at approval, transfers of ownership, and eventual discontinuation.

Most of a product’s regulatory life is post-approval, and this is where the gap between the approved product and the manufactured product opens. A change made on the line that was never filed means the product being sold is not the product that was authorised.

HOW IT FAILS

  • A process or supplier change is assessed for quality impact but not for whether it alters the filing.
  • Variation categorisation is chosen for speed, and a change that needed prior approval is implemented as a notification.
  • Commitments made at approval are closed in the regulatory system without evidence that the underlying work was done.

WHAT CONTAINS IT

  • Change control that routes every change through a regulatory-impact assessment before implementation.
  • Documented variation categorisation with the regulatory basis for the category chosen.
  • A managed strategy for post-approval change — established protocols where the science supports them, so change is predictable rather than improvised.

EVIDENCE IT OPERATES

  • Regulatory impact assessments attached to change records.
  • Variation and supplement submissions with approval confirmations.
  • Commitment closure evidence and annual-report content traceable to source data.
08

Regulatory operations & information management

The systems and disciplines that hold regulatory information: the RIM platform, dossier and correspondence archives, structured content, publishing standards and the controlled vocabularies underneath them.

Regulatory information is only useful if it can be found and trusted years later. When the archive is unreliable, teams re-derive what was already filed — and occasionally file something that contradicts it.

HOW IT FAILS

  • Product and registration data are maintained in parallel spreadsheets alongside the system of record, and the two disagree.
  • Submission archives capture what was sent but not the approved version that came back, so current status is inferred.
  • Controlled vocabularies drift per region, making a global view of registrations impossible to assemble.

WHAT CONTAINS IT

  • A single system of record for registration status, with other views derived from it rather than maintained beside it.
  • Archival of both the submitted and the approved artefacts, linked to the product and market.
  • Governed vocabularies and data standards applied at entry, not reconciled afterwards.

EVIDENCE IT OPERATES

  • System-of-record data with completeness and reconciliation reporting.
  • Submission and approval archives retrievable by product, market and date.
  • Data-standard governance records and audit trails for regulatory data changes.
09

Policy, standards & external engagement

Engagement with regulation while it is still being written: consultations, standards development, harmonisation initiatives and trade-association positions — the layer above compliance with what already exists.

Requirements are shaped long before they are enforced, and organisations that engage understand the intent behind a rule rather than only its text. It is also the earliest possible warning of a change that will be expensive to implement late.

HOW IT FAILS

  • Consultation windows close unnoticed because nobody owns watching for them, and the organisation comments on nothing.
  • Positions are taken by individuals attending working groups without an agreed internal view behind them.
  • Intelligence gathered in a standards committee never reaches the functions that will have to implement the outcome.

WHAT CONTAINS IT

  • Ownership for consultation monitoring and a defined internal route to an agreed response.
  • Mandates for participants in external bodies, so an individual represents a position rather than an opinion.
  • A feedback path from external engagement into horizon scanning and planning.

EVIDENCE IT OPERATES

  • Consultation responses submitted, with the internal approval behind each.
  • Participation records and mandates for external working groups.
  • Horizon entries traceable to intelligence gathered externally.

Why it matters in regulated work

  • Shapes classification, evidence strategy, submissions, and authority engagement.
  • Maintains registrations, labeling, commitments, and post-approval obligations.
  • Connects external change to internal owners and affected artifacts.

Principal failure modes

  • Wrong pathway or incomplete evidence strategy
  • Uncontrolled commitments and post-approval change
  • Late detection of policy or market-access change

Control objectives

  • Maintain a traceable regulatory strategy
  • Control submissions, commitments, and registered information
  • Convert intelligence into bounded change decisions

Evidence families

  • Regulatory strategy and authority correspondence
  • Submission, registration, labeling, and commitment records
  • Horizon assessments and change-impact decisions

CONNECTED OPERATING MODEL

Where this capability connects

Lifecycle reach

  • Research & Discovery
  • Nonclinical Development
  • Clinical Development
  • Regulatory Submission & Approval
  • Technology Transfer
  • Process Development & Characterisation
  • Commercial Manufacturing
  • Packaging & Serialisation
  • Storage & Distribution
  • Pharmacovigilance
  • Post-Market Surveillance
  • Discontinuation & Record Retention

Quality capabilities

  • Regulatory Intelligence
  • Change Control
  • Document & Record Control
  • Quality Risk Management

System classes

  • RIM
  • eQMS
  • Safety / PV Database

Roles to start with

  • Regulatory Affairs Associate
  • Quality Assurance Associate
  • Complaint & Vigilance Specialist

MATURITY ORIENTATION · SPEQ SYNTHESIS

What stronger operation looks like

  1. 01ReactiveOwnership and evidence are reconstructed after events; controls depend on individuals.
  2. 02DefinedScope, roles, methods, records, and escalation are documented for routine use.
  3. 03ControlledCritical controls are risk-based, verified, monitored, and governed through change.
  4. 04PredictiveLeading signals connect performance, drift, capacity, risk, and intervention.
  5. 05AdaptiveLearning improves the operating model without weakening accountability or evidence.

HIGH-VALUE INTERSECTIONS

SOURCE BASIS

REGULATORY BASIS

What governs this capability

The 12 standards SPEQ maps to this pillar, and the 5 regulatory bodies behind them. Which standards belong to a pillar is a SPEQ judgement; the bodies, disciplines and industries below are read from the standards themselves.

Also reached through the systems this pillar runs on

These 17 standards govern the system classes this pillar depends on rather than the pillar itself. The distinction matters: a standard that governs a system is not thereby a standard of every capability that uses it.

ICH Q10EU GMP Annex 1621 CFR Part 11EU GMP Annex 11ISPE GAMP 5 (2022)MHRA GxP DI (2018)ICH Q9(R1)21 CFR Part 21121 CFR Part 820ISO 13485:2016ISO 9001:2015EU GVP ModulesICH E2AICH E2B(R3)ICH E2C(R2)21 CFR 314.8021 CFR Part 312

PROFESSIONAL · READINESS ORIENTATION

Turn the pillar into a bounded operating conversation.

Rate observable operation from 0 (not established) to 4 (adaptive). The protected output prioritizes operating dimensions and evidence—not a compliance score.