Most regulatory affairs and QA teams already have some version of shortage-prevention documentation. The honest question isn't whether it exists — it's whether it would hold up if an auditor or a national authority asked to see it tomorrow. This checklist is meant to be run against what you already have, not a from-scratch build.
Structure and version control
- Each critical product has its own SPP, not a shared portfolio-level document that vaguely covers "high-risk products."
- Every document carries a version number and a last-updated date visible on the document itself, not buried in a file properties panel.
- There's a record of who approved the current version and when — not just who wrote it.
- Previous versions are retained and retrievable, not overwritten in place.
Ownership and accountability
- Each document names a specific individual as owner, with a named backup — not a department or a role title.
- The person listed as owner still works there and still owns it. (This one fails more often than it should.)
- It's clear from the document alone who is responsible for the next review, without needing to ask around.
Currency of the underlying data
- Supplier and manufacturing-site information matches your current quality dossiers, not a snapshot from the last major registration change.
- The rolling forecast is dated, and that date is within the stated review cadence — a 3-month forecast that's 7 months old isn't a rolling forecast, it's an artifact.
- Vulnerability scores reflect current supplier counts, not the state of the supply chain when the document was first drafted.
Deadline and notification readiness
- You can state, for any given critical product, when the next notification deadline would fall if a discontinuation decision were made today — see the 12- and 6-month rule if you need the reference.
- There's a defined internal deadline that sits weeks before the statutory one, not just the statutory date itself.
- Someone specific is responsible for actually filing a notification via the ESMP, and they know the process — see how to notify via the ESMP if that's still unclear internally.
Vulnerability and dependency data
- Single-source dependency is assessed at the API, finished-dose, and regional level separately, not as one combined flag — see how to map single-source dependency for the method.
- Alternative suppliers listed as "backup" are actually qualified and validated, not just identified as theoretically possible.
- You know, without checking, which of your critical products carry the highest risk — the answer shouldn't require reassembling data from three systems.
Portfolio-level readiness
- You can produce a complete list of which products sit on the Union List of Critical Medicines without cross-referencing manually — see our explainer on the Union List of Critical Medicines if you haven't mapped your portfolio against it yet.
- If the Commission or a national authority requested capacity and supplier information tomorrow under the cooperation duty, you could assemble an accurate answer within days, not weeks.
- Your Shortage Prevention Plans and Shortage Mitigation Plans use the same trigger definitions, so there's no ambiguity about which plan is active when a signal fires.
Scoring yourself honestly
Most teams check most of the boxes on individual products and fail the portfolio-level ones — not from lack of diligence, but because each SPP was built as a standalone document rather than drawn from one shared, current source of supply chain data. That's the pattern to watch for: strong documents, weak system underneath them.
If most of this checklist depends on manually reassembling data from separate files: that's the exact problem we're building Crucial to solve — one product register that every SPP, SMP, and deadline pulls from, so "audit-ready" doesn't mean a scramble every time someone asks. Talk to us as a pilot partner.