We are at Vitafoods Asia.

Come and say hello, or reach us from here.

Get in touch

Guide

How should I organize supplement compliance documents by lot?

By Jake, founder · Published · Updated

File by product, then by lot within each product, then by document within each lot. A COA belongs to one lot, not one product. Keep the COA, spec sheet, and label per lot; the cGMP certificate and insurance per facility; and retain everything at least as long as 21 CFR 111.605 requires.

The structure: product, then lot, then document

The unit that compliance evidence actually attaches to is the lot, not the product line. A Certificate of Analysis is issued for one production run; a spec sheet may be revised between runs; a label version changes when a formulation or claim does. Filing by product alone, one folder per SKU with one COA inside it, hides which lot that COA belongs to and whether a newer lot has already shipped without one. The fix is a three-level structure: product, then lot within the product, then the documents that belong to that lot.

What to keep, and at what level

Document, the level it belongs to, and why
DocumentLevelWhy
Certificate of Analysis (COA)Per lotTest results are specific to the lot tested; a newer lot's COA is the one a review checks, not an older one for the same SKU.
Specification sheetPer product (new version per formulation change)Identity, potency, and limits for the product as formulated, versioned when the formulation changes rather than every lot.
cGMP certificatePer facilityCertifies the manufacturing facility, not an individual product or lot.
Quality agreementPer manufacturer relationshipGoverns the whole relationship with that contract manufacturer, not one SKU.
Product liability insurancePer accountA single certificate of insurance typically covers the brand's full catalogue.
Label / artworkPer product (new version per change)Tied to the formulation and claims in effect for the lots printed with it.

What "per lot" looks like with more than one active lot

A brand selling steadily usually has more than one lot of a SKU in circulation at once: one still on a shelf somewhere, one just shipped, one about to be produced. Filed by product only, that looks like one folder with one COA in it, which hides the question a reviewer actually asks: does the lot currently being sold have a current COA behind it? Filed by lot, the same product looks like three subfolders, each with its own COA, spec version, and, if the formulation changed between runs, its own label version. The newest lot's COA is the one that matters for a review; the older lots' documents still need to be kept for the retention period below, but they stop being what a reviewer asks for once that lot is no longer being sold.

Naming that survives a search

A filename should answer four questions without opening the file: which product, which lot, which document type, and what date is on the document itself. A pattern like SKU / lot number / document type / document date sorts correctly, searches correctly, and, critically, makes the certificate's own date visible, which is the date a document-age window like the one described in how long a COA stays valid for Amazon counts from, not the date it was filed or the date the sample was tested.

Document-age window applied here: 182 days, the strictest reported value; other sources report 274 and 365 days. Last verified 2026-07-24. This is provider policy, not regulation, so confirm the current figure with your TIC provider before relying on it.

How long to keep it

21 CFR 111.605 sets the retention floor for records required under Part 111: they must be kept "1 year past the shelf life date, if shelf life dating is used, or 2 years beyond the date of distribution of the last batch of dietary supplements associated with those records," whichever applies. Records may be kept as originals, true copies, or electronic records. Separately, 21 CFR 111.610 requires that records be readily available for FDA to inspect and copy on request during that retention period, which argues for records being actually retrievable by lot, not merely stored somewhere.

These are the regulatory floor for records Part 111 requires you to keep. A retailer or a TIC provider may separately want a document that is more recent than the retention floor requires: a COA older than the window described above is retained for the regulation but not usable for a current review.

The spreadsheet version, and where it breaks

A spreadsheet with one row per SKU and a column for "COA on file" is a reasonable start: it tracks that something exists. What it can't do is read the certificate date off the PDF attached to that row, catch that a lot shipped without a matching COA, or warn before the newest COA ages out. Those gaps don't show up until a review or an audit asks for the document a spreadsheet says exists, and it turns out to be for the wrong lot or past its usable window.

  • It tracks existence, not content: no automatic read of the date, potency result, or lot number inside the file.
  • It has one version of the truth per row, so a second lot for the same SKU means a second row someone has to remember to add.
  • Nothing warns ahead of an expiry; the gap is discovered when a review already needs the document.
  • It scales to a handful of SKUs and one person maintaining it. Past that, entries drift out of sync with what's actually on file.
  1. Start with the three-level structure above, even in folders: product, then lot, then document.
  2. Name every file with SKU, lot, document type, and document date.
  3. Track the retention floor from 21 CFR 111.605 separately from the shorter document-age windows a retailer or TIC provider applies.
  4. Run the free check to see where this breaks today. It reads the dates off your existing COAs and shows which SKUs and lots are missing a current one.

Related: how to read a Certificate of Analysis, 21 CFR Part 111 explained for brand owners, and the FDA Part 111 requirements library.

Sources

Frequently asked questions

Why organize by lot instead of by product?
Because a Certificate of Analysis belongs to one production lot, not the product in general. A brand with three active lots of one SKU has three COAs and three separate clocks on when each ages out, and filing by product alone hides that a newer lot's document is the one a reviewer actually needs.
How long do I have to keep these records?
21 CFR 111.605 sets the floor: 1 year past the shelf-life date, if shelf-life dating is used, or 2 years beyond distribution of the last batch tied to those records, whichever applies. Records must also be readily available for FDA to inspect and copy on request under 21 CFR 111.610.
What documents are per-lot versus per-facility?
Per-lot: the Certificate of Analysis and, where testing changes between runs, the specification sheet. Per-facility or per-account: the cGMP certificate, insurance, and the quality agreement. A label is usually per-SKU unless a formulation or claim changes, at which point it becomes its own version tied to the lots printed with it.
What naming convention keeps this findable?
Include the product, the lot number, the document type, and the document's own date. For example, a file named with SKU, lot, "COA", and issue date sorts and searches correctly without opening it. The certificate's own date is what matters for a COA, not the date it was filed.
Where does a spreadsheet stop working?
A spreadsheet tracks that a document exists but not what's inside it. Nothing reads the certificate date off an attached PDF, flags a lot with no COA, or warns before a document ages out. It works until a brand has more than a handful of SKUs or more than one person needs to check the same file.

Would your own paperwork read this way?

Tell Compliant Always what you make and where you sell it, and we will come back to you with what those markets require of it and how the agents handle it.

No card and no account. It takes a minute.