The audit answer is structural, not reconstructed
Regulatory Affairs owns the submission timeline and the answer to who approved this, and when. DitaExchange makes that answer queryable at the component level: the reconstruction work that used to fill an audit week becomes a SharePoint query.
Documents drift. The audit response carries the cost
Regulatory content is managed as documents almost everywhere: Word files, PDFs, manuscripts. The same approved paragraph lands in a CCDS, a CCSI, an SmPC, a USPI, twenty local pack inserts, and three submission packages, and once it lands it stops being one thing. The next update touches one of those copies; the rest drift. The drift is invisible until a regulator notices, an audit asks, or a translator bills again for content that should not have moved.
The fix is structural. Treat the approved statement as a component with its own version history, approval record, and assembly references. Then the answer to which version of the warning is in this submission is a query against the component, not a textual diff against twenty rendered documents.
"Which version of the warning was in the 2024 submission?"
An inspector's question, traced through what the team has to do to answer it. The component model collapses the path from six steps to two.
What changes for Regulatory Affairs
| What changes | How |
|---|---|
| The audit answer in seconds, not days | Component-level version history, queryable through SharePoint. Who approved this, and when is a query, not a reconstruction. |
| The same approved statement, everywhere it is used | Component reuse. One approved fragment refreshes every assembly that references it. No twenty-document sweep before submission. |
| Multi-region label variants, one document | Conditional profiling: author once, profile per market, language, product variant, audience. Variants emit at publish time, not edit time. |
| Submission-format readiness, no separate toolchain | Multi-format publishing inside Dx5: Word, HTML, XML. Portal pages and API endpoints feed downstream submission tools. |
| Targeted updates, no manual propagation | A fragment edit and approval propagate automatically. Every document referencing the change refreshes, and the audit trail captures it once. |
Different frameworks. Same structural expectation
Pharma and medical device
FDA QMSR (effective February 2026), 21 CFR Part 11, EU GMP Annex 11, EMA IDMP, eCTD. Customers include MagVenture.
Aerospace and defense
EASA Easy Access Rules, FAA Part 25 / Part 23, NATO STANAG, MIL-STD, ITAR / DFARS. Customers include EASA (regulator), EDA, Lockheed Martin, GKN Fokker.
Nuclear and energy
Multi-decade licensing dossiers, IAEA standards, periodic safety review content. Customer: Canadian Nuclear Safety Commission.
Financial services
DORA, MiFID II, EU prospectus regulation, sustainability disclosure. Customer: LSEG.
The frameworks differ on what they prescribe. None of them prescribes a tool. All of them assume that when the question comes, who approved this, and when?, the answer is already structured and can be retrieved without manual reconstruction.
Frequently asked questions
We already run a RIM or submission publishing system. Where is the boundary?
The register and the submission pipeline stay where they are. Large pharma organizations usually have a regulatory information management system in place, Veeva Vault RIM or equivalent, and that is not what is being replaced here. What sits underneath is the narrative content held as components, with the version and approval record attached, reaching downstream tools through the SharePoint API and the Dx5 API.
Does this need a dedicated tools specialist inside Regulatory Affairs?
It needs somebody who owns the vocabulary, not somebody who runs a server. Taxonomies are maintained by an administrator in the SharePoint Term Store, content rules are written by content specialists or with outside help, and the platform provisions its own SharePoint libraries on first run. The judgment calls, which document family goes first and how it splits into topics, are what your specialist is for.
How long does the record stay retrievable, and who sets that?
You do, in the tenant. Retention, backup and audit logging are whatever your SharePoint estate is already configured for, and Dx5 adds no separate plan for any of them, which is also why there is nothing new to clear with legal. Snapshots sit on top of that: a frozen version of the content at a chosen point, for an archive or a submission freeze.
Some of our submission content is written by outside partners. How does it come in?
As a conversion, once per body of content. Files are read in the formats they were written in, metadata is captured on the way in rather than reconstructed afterward, styling is aligned to the target model, and references that pointed at a page or a file are repointed at components. It is not an unattended process, and the topic split stays a human decision.
Which part of an audit response does this not remove?
The judgment. A query can tell you which version of a statement was in a submission, who approved it and when, and which other assemblies carry it. It cannot tell you whether the approval was the right one, whether the procedure was followed, or whether the statement is scientifically correct. What changes is that the audit week goes on those questions instead of on finding the record.
Start with the submission where the next audit is largest
Most rollouts in Regulatory Affairs begin with the one document family where the audit cost of inconsistency is most visible: a labeling program, a submission, a safety report. It compounds from there.