Introducing ARIA: AI for Regulatory Intelligence & Authoring, our new AI agent, built on everything you already know from NuMantra.
September 28, 2026
Creative buffer
Chemistry, manufacturing and controls (CMC) content is where many submissions get stuck. Quality gaps commonly appear in FDA information requests and deficiency letters, and the consequences depend on the application type. For an IND, FDA can impose a clinical hold under 21 CFR 312.42. For an NDA or BLA, FDA can issue a Complete Response Letter, which states the deficiencies that prevent approval in the current form (21 CFR 314.110 and 21 CFR 601.3).
The underlying challenge is structural. CMC data lives in LIMS exports, batch records, stability databases and method validation reports spread across SharePoint folders and legacy document systems. Turning that into ICH M4Q(R1) structured narratives, tables and cross-references is manual work, and comprehensive checking before submission is hard to do by hand.
This article defines a Module 3 CMC audit, lists six checks worth running, walks through an illustrative example, and shows where automation helps. It is general information, not regulatory advice
A Module 3 CMC audit is a systematic review of sections 3.2.S (drug substance) and 3.2.P (drug product) to confirm four things: the required ICH M4Q(R1) subsections are present and populated, the content agrees with itself across sections, every claim traces to source data, and the eCTD structure and links work. It is a pre-submission quality check on the content, not only on the file structure.
Check | Where | Typical |
Structural completeness against ICH M4Q(R1) | 3.2.S.1 to S.7 and 3.2.P.1 to P.8 | Sections present but holding only |
Specification versus data | 3.2.S.4.1, S.4.4, S.4.5 and 3.2.P.5.1, | An impurity in batch data that is absent |
Method versus validation | 3.2.S.4.2 and S.4.3, 3.2.P.5.2 and P.5.3 | Method described, validation report missing |
Stability completeness | 3.2.S.7 and 3.2.P.8 | Missing time points or storage conditions |
Narrative versus process records | 3.2.P.3.3 to P.3.5, batch analyses | Batch identifiers that differ between |
Cross-references and hyperlinks | Module 2.3 to Module 3, and within Module 3 | Links that resolve to the wrong leaf or to |
Every attribute you test and report should appear in the specification, or have a documented reason for its absence. Specifications should be justified in 3.2.S.4.5 and 3.2.P.5.6, with reference to ICH Q6A. For impurities, ICH Q3A(R2) (drug substance) and Q3B(R2) (drug product) frame the reporting and qualification thresholds.
Each analytical procedure in 3.2.S.4.2 or 3.2.P.5.2 should have a matching validation summary in 3.2.S.4.3 or 3.2.P.5.3, and the versions should agree. A narrative that cites “Method V1.2” while the validation report covers “Method V1.3” is a small error that draws questions.
Storage conditions and testing frequency come from ICH Q1A(R2). Evaluation of the data follows ICH Q1E. Check that every planned time point is reported, that batch identifiers match the batch analyses, that the stability summary (3.2.S.7.1 or 3.2.P.8.1) agrees with the data (3.2.S.7.3 or 3.2.P.8.3), and that any post-approval commitment is stated where expected (3.2.S.7.2 or 3.2.P.8.2).
The description of the manufacturing process and controls (3.2.P.3.3) should match the process validation or evaluation (3.2.P.3.5) and the executed batch data submitted. Batch identifiers should read the same in 3.2.S.4.4, 3.2.S.7.3, 3.2.P.5.4 and 3.2.P.8.3.
FDA reviewers follow links from the Quality Overall Summary (Module 2.3) into Module 3. A link that resolves is not enough. The section it lands on has to support the statement that pointed to it.
Most small and mid-size sponsors use one of three approaches.
None of these is wrong. Each leaves a different part of the problem uncovered.
The scenario below is hypothetical and does not describe a specific customer. A mid-size oncology biotech is preparing an NDA for a small-molecule kinase inhibitor. The regulatory operations director wants confirmation that 3.2.S is ready before the eCTD is compiled. An audit against the six checks might surface findings like these:
Section | Finding | Remediation |
3.2.S.4.1 | An impurity present in batch data is missing | Add the impurity with an acceptance |
3.2.S.4.2 and S.4.3 | The method narrative cites version 1.2 while | Align the narrative to the correct version, |
3.2.S.7.3 | The accelerated condition is missing its 6 | Add the data, or explain the gap and state |
3.2.S.4.4 | Only two commercial-scale batches are | Add a commercial-scale batch or justify the |
Each of these is fixable once it is found. The hard part is finding them across a large document set before the compile date.
ARIA, NuMantra’s AI Regulatory Intelligence and Authoring platform, gives the audit a structured foundation and shortens remediation. It does not replace your team’s judgment.
Every draft and classification stays under human review before it is final. Customer data is never used to train underlying AI models.
3.2.S covers the drug substance: its manufacture, characterization, control and stability. 3.2.P covers the drug product: its composition, development, manufacture, control and stability. 3.2.P often cross-references 3.2.S data, for example shared analytical methods.
No. A Complete Response Letter applies to NDAs and BLAs. An IND can be placed on clinical hold under 21 CFR 312.42, and FDA can also send information requests.
In 3.2.S.4.3 for the drug substance and 3.2.P.5.3 for the drug product. The procedures themselves are in 3.2.S.4.2 and 3.2.P.5.2.
At each significant change to the source data, and once more before compile. Running it only once shortly before filing leaves little time to fix what it finds.
Next step
If Module 3 is on your critical path, see how ARIA structures raw CMC data, classifies source documents and validates the package before compile.