1. Why are many DSCSA/EU FMD programs compliant but not operationally resilient yet?
Compliance gets you through an audit. Resilience gets medicines to patients on the day something unexpected happens. The DSCSA's enhanced requirements took effect November 2024, but real interoperability required three more rounds of accommodation (phased implementation), with the small-dispenser exemption closing out in November 2026. Most serialisation failures are not technology failures; instead, they're data governance failures that technology merely exposes. Visibility reduces decision latency, and decision latency is what delays product release and recalls. The real KPI isn't "percent compliant” but its mean time to resolve an exception without disrupting supply.
2. What lessons can LifeScience or pharma learn from digital transformation in other industries?
Every industry I've worked in is optimised for something different. High-tech optimised inventory velocity. I notice in Retail, It optimized customer experience, and in Automotive, it optimised manufacturing synchronisation. Pharma is the first industry required to optimise for trust, every other objective sits downstream of that. Retail and logistics solved track-and-trace a decade before pharma had a mandate, because revenue consequences forced it. The transferable lesson isn't the tech stack rather it's treating data quality as a product, not a project.
3. How does serialisation fit into a broader enterprise data strategy?
Pharma still largely thinks product → serialisation → compliance. I'd argue the real chain now is product → trusted data → AI → automation → compliance → business value → patient outcome. Compliance isn't the destination instead, it's a checkpoint the data passes through on its way somewhere more useful. Most companies have built product identity and trusted data; the competitive gap opening up now is in partner interoperability and operational intelligence, the two layers just beneath patient confidence.
4. How is AI changing exception management?
Exception management today looks like a relay race with no clear finish line: person to person, spreadsheet, email, meeting, CAPA, ERP, partner. Every handoff adds delay. AI collapses that into a shorter loop: evidence, recommendation, human approval, execution, learning. The cost was never detecting the exception but it's the time spent deciding who owns it, who needs to drive the collaboration. The defensible ROI today is narrow: AI generating exception summaries and audit-ready documentation for human sign-off. Full closed-loop execution is still the frontier, not the norm.
5. What challenges does AI pose in a validated, GxP environment: In particular, the agentic AI?
In most industries, an AI that's 90% right is a success story. In GxP manufacturing, one that can't explain the other 10% is a liability that can stop a line. On April 2, 2026, FDA issued its first warning letter explicitly citing AI misuse in a cGMP context to Purolea Cosmetics Lab. The primary violation was insanitary conditions, but the AI piece was precedent-setting: the company used AI agents to generate specifications and production records the quality unit never reviewed, then blamed the AI agent for not flagging the required validation step. AI will not replace quality professionals instead, it will expose organisations that never documented how quality decisions are made.
6. How should quality and IT collaborate differently as AI starts recommending decisions?
The old model was "IT builds it, Quality validates it, once." A learning system doesn't stay validated that way, and its behavior shifts as it ingests new data. Quality teams now need enough technical literacy to review model drift; IT needs monitoring and explainability built in from day one. Build the governance committee before the use case, like post-Purolea, regulators won't extend patience to organisations that treat AI governance as an afterthought.
7. What breaks down most during CMO/CDMO technology transfer?
Our biggest lessons rarely came from successful launches. They came from exceptions that exposed assumptions nobody realised existed like a batch record format, an aggregation hierarchy, a GS1 identifier convention, or two systems interpreted differently. Roughly half of all technology transfers hit a quality problem, and it's almost never the science; it's the handoff. If a CMO's line isn't configured to the sponsor's exact identifiers and EPCIS structure, the sponsor inherits a compliance gap that may not be detected until the product is already in the field.
8. How should serialisation data flow between brand owners and CMOs, and what's the highest hidden cost when that goes wrong, including in M&A?
A serialised identifier is only as trustworthy as its weakest handoff, and that's almost always the sponsor-to-CMO boundary. Under both DSCSA and EU FMD, the brand owner keeps ultimate responsibility even when a CMO applies the barcode, which means the relationship needs real-time visibility into the CMO's line, not a monthly reconciliation report. This compounds in M&A: due diligence checks the pipeline and the balance sheet, rarely whether two companies' serialisation systems can talk to each other on day one. Pharma M&A is running hot, if you see 2025 alone, biopharma deal value roughly doubled to ~$133B, and Q1 2026 alone topped $65B and inherited CMO relationships are a genuine integration project, not a data-migration afterthought. Tech Transfer or reconciling GTINs and EPCIS formats across merged entities adds to it.
9. What role do smart, connected factories play in the next phase of pharmaceutical traceability?
The packaging line, not the back office, is where automation lands next. Connected equipment can generate its own event stream like line speed, rejection rate, environmental conditions etc., alongside the serialisation data it's already producing, and that combination is what makes real-time exception detection possible instead of a monthly audit. It also raises the stakes on launch timing: serialisation, packaging-line validation, and trading-partner connectivity are still routinely scoped late in launch planning, after commercial dates are already locked, even though this equipment-level work takes real calendar time. In the next five years, I expect packaging lines to move toward greater autonomy, with digital twins increasingly replacing physical validation rehearsals.
10. What does a genuinely secure supply chain require beyond serialisation?
A serial number proves where a product started; trusted data proves everything that happened afterwards. The complete picture needs tamper-evident packaging, verification at multiple points in the chain, and visibility into sub-tier API suppliers. A newer exposure: connected drug delivery devices with Bluetooth or cellular connectivity introduce a cybersecurity attack surface, since compromised firmware could in principle manipulate dosage data. Map security across four layers (be honest about what is in use and what exists in a policy document): package authentication, tamper-evidence, sub-tier visibility, and device cybersecurity
11. Why are ‘collaboration’ and ‘interoperability’ becoming a competitive advantage rather than just a compliance checkbox?
DSCSA and FMD are network mandates: one company's serialised data is worthless if a downstream partner can't consume it. No single trading partner can make a supply chain resilient alone. That's a genuine commercial differentiator now because partners increasingly choose suppliers based on integration friction, and an organisation's AI is only as good as the data quality of everyone it exchanges with. Bodies like GS1 US, the Partnership for DSCSA Governance, HDA, and EMVO are where practical standards get worked out ahead of formal regulation.
12. What should organisations prioritise now to prepare for the NDC-12 transition?
DSCSA digitised the product. NDC-12 will digitise enterprise identity. The companies still treating it as a barcode change will spend the next decade correcting architecture decisions they didn't know they were making. FDA's final rule for a uniform 12-digit NDC was published March 5, 2026, effective March 7, 2033, with a hybrid transition through March 2036. DSCSA effectively gave the industry 13 years; NDC-12 gives roughly seven, reaching further into financial and clinical systems than DSCSA ever touched, and unlike DSCSA, it's a structural data-capacity constraint, not a policy that can simply be relaxed. The transition to NDC12 and dual operability across supply chain and NDC "collision problem, where conversion could fail, all concentrates in the 2033–2036 window. But the window to get ready for interoperability and build system processes for dual operability is NOW.
13. What should organisations prioritise this year to move from compliance to genuine competitive advantage?
Close the exception-management gap, since speed now directly protects product availability. Treat NDC-12 as a 2026 inventory project, not a 2030 implementation one. Build AI governance now because it is no longer a future concern, and stay engaged with the bodies writing the standards. None of this requires a moonshot: the companies making the fastest progress are aligning quality, supply chain, regulatory, IT, and commercial teams around common data and common ownership. Technology enables transformation. Organisational alignment delivers it.
Throughout my career, I've learned that technology rarely creates trust by itself. Trust comes from disciplined execution, transparent data, and people willing to collaborate across organisational boundaries. Regulations may define the minimum standard, but organisations decide whether compliance becomes a cost or a capability that ultimately protects patients.