XGene CMC IntelligenceXGene Intelligence

ISO IDMP 11615 — The Data Model Behind Global CMC Harmonization

IDMP / SPORBiologicsGlobal CMC / Lifecycle

ISO 11615 is the international standard that defines how medicinal products are uniquely identified globally — and understanding its data model is the key to understanding why EMA's SPOR system…

By Khaled Aamer, PhD · Founder, XGene LLC Aug 22, 2026 10 min read
On this pageArticle overview

    ISO 11615 is the international standard that defines how medicinal products are uniquely identified globally — and understanding its data model is the key to understanding why EMA’s SPOR system works the way it does and where global CMC data harmonization is heading.

    Most pharmaceutical companies encounter ISO IDMP through the pressure of EMA’s Product Management Service submissions and treat the encounter as a form-filling exercise. That framing is the source of their problems. ISO 11615:2017, the full title of which is “Identification of Medicinal Products — Data elements and structures for the unique identification and exchange of regulated medicinal product information,” is not a submission format. It is a relational data architecture that defines how substances, pharmaceutical products, authorized medicinal products, and packaged products relate to one another as discrete, coded data entities — and every regulatory data system that interacts with EMA’s SPOR is either aligned to that architecture or accumulating technical debt that will demand resolution when the next phase of IDMP enforcement arrives.

    The companies navigating this well are not the ones who hired a consultant to populate SPOR fields before the EMA deadline. They are the ones whose regulatory data architects understood the four-layer IDMP data model before a single field was submitted — because that understanding determines whether your internal CMC data infrastructure can sustain cross-agency harmonization or whether it will fracture under the pressure of simultaneous FDA, EMA, and PMDA regulatory data obligations.

    ────────────────────────────────────────────────────────────────────── What ISO 11615 Defines: The Medicinal Product Identification Standard Architecture ──────────────────────────────────────────────────────────────────────

    ISO 11615:2017 is the center of a five-standard IDMP family. The other four standards each define a specific data domain that ISO 11615 references: ISO 11238:2018 governs substance identification (substance name, molecular structure, CAS registry number, UNII); ISO 11239:2023 governs dose forms, units of presentation, routes of administration, and packaging; ISO 11240:2012 governs units of measurement, expressed through the Unified Code for Units of Measure (UCUM); and ISO 11616:2017 governs pharmaceutical product identification — the PhPID that links pharmaceutically similar products across regions by active substance, strength, reference strength, and administrable dosage form. ISO/TS 20443:2017 sits alongside these as the implementation guideline for ISO 11615 itself, translating the data model into field-level submission guidance for EMA’s PMS — a companion document, not a sixth peer standard. ISO 11615 itself defines the medicinal product data object — but it does so across four structurally distinct layers, and the boundaries between those layers are not stylistic. They are functional separations that determine how data flows between regulatory agencies, how updates propagate when a formulation changes, and how a product’s identity is maintained across jurisdictions with different authorization frameworks.

    The first layer is the substance layer, governed by ISO 11238. At this layer, a drug substance is defined by its chemical or biological identity — name, molecular structure, CAS number, and UNII code — independent of any formulation or commercial product. The second layer, the pharmaceutical product layer within ISO 11615, describes the clinical concept of the product: dose form, route of administration, and the strength of each ingredient, all coded against ISO 11239 and ISO 11240 UCUM units. This layer exists independently of any marketing authorization — it represents what the product is pharmacologically, not where it is approved. The third layer is the regulated medicinal product layer, which introduces jurisdiction: marketing authorization number, marketing authorization holder, legal basis for authorization, authorization status, and the country of authorization. The fourth layer is the packaged medicinal product layer, which defines the commercial package: package type, size, and container material. Each layer has its own data elements, its own coded terminologies, and its own update triggers.

    Understanding why this architecture matters operationally requires one concrete reference point. The EUPI — the EU Product Identifier assigned through EMA’s Product Management Service — is an ISO 11615 identifier for the regulated medicinal product layer. It is not a package identifier, not a substance identifier, and not a dose form code. A company that conflates the EUPI with an overall product identifier and propagates it across all four layers in their internal regulatory database has built a structural error into their IDMP architecture — one that will surface as data inconsistencies when variation applications require layer-specific updates.

    ────────────────────────────────────────────────────────────────────── The Data Elements ISO 11615 Requires and Their Mapping to Current MAA Sections ──────────────────────────────────────────────────────────────────────

    The data elements required by ISO 11615 are not a new category of information — they are largely information already present in a Module 3 CTD package, restructured as coded, machine-readable data rather than narrative text. The operational gap for most companies is not that the underlying information is absent; it is that the information exists in formats, terminologies, and system architectures that were never designed for IDMP’s relational data model. Dose form, for example, is described in Module 3.2.P.1 and in the Summary of Product Characteristics — but the description is free text drafted to satisfy a reviewer’s comprehension, not a code from the EDQM Standard Terms list specified by ISO 11239. When EMA’s Product Management Service requires a dose form code and a company’s regulatory data system produces a text string, the dissonance is not a documentation problem. It is an architecture problem, and it cannot be resolved by editing a form.

    The same architecture problem appears in strength expression. ISO 11240 requires that ingredient strength be expressed using UCUM codes — a standardized, machine-parseable unit system that distinguishes between, for example, mg (milligrams, mass) and mg/mL (milligrams per milliliter, concentration) in a way that is computationally unambiguous. A company whose specifications express strength in narrative formats inconsistent across products and markets will encounter EMA eAF technical validation failures that are not fixable at the submission level. The fix requires upstream alignment of the strength data model to UCUM — which means a regulatory data governance decision, not a document revision. The eAF validation failure is the symptom; the root cause is that no one defined UCUM as the required unit expression standard when the regulatory data system was built.

    The marketing authorization holder data element at the regulated medicinal product layer carries its own complexity for companies that have undergone post-authorization transfers. ISO 11615 requires the MAH to be identified as a coded organization — aligned to EMA’s SPOR Organization Management Service — not as a free-text name. Companies that have processed MAH transfers and maintained the MAH identity as a text field across multiple submission documents will find that their SPOR data does not reflect the transfer history in a form that supports IDMP-compliant cross-referencing. This is a specific failure mode encountered repeatedly in post-merger regulatory data remediation: two companies’ SPOR data cannot be consolidated because neither used consistent OMS-coded MAH identifiers from the point of initial product registration.

    ────────────────────────────────────────────────────────────────────── How ISO 11615 Connects to EMA SPOR and ICH M8 eCTD Architecture ──────────────────────────────────────────────────────────────────────

    EMA’s Product Management Service is the operational implementation of ISO 11615 for EU authorized products. The PMS accepts, validates, and maintains ISO 11615-structured data for every centrally authorized product in the EU, and its validation rules enforce the coded terminologies — EDQM Standard Terms for dose form and route, UCUM for strength units, OMS-coded identifiers for MAH — that ISO 11615 and its companion standards specify. A submission that fails PMS technical validation has not failed because of a missing field. It has failed because a data element was not expressed in the coded format the ISO 11615 data model requires. That distinction matters for remediation: the correction is not editorial, it is data architectural.

    The connection to ICH M8 eCTD architecture is less direct but increasingly consequential. ICH M8’s eCTD v4.0 specification, built on the HL7 Regulated Product Submission (RPS) message standard, restructures regulatory submissions from static, document-equivalent files into coded, machine-parseable content — and with Japan’s PMDA mandating eCTD v4.0 for all new applications from April 2026, the expectation that substance, product, and package data be expressed in coded, interoperable formats will extend into Module 3 sections that currently accept narrative. Companies whose CMC data systems cannot output IDMP-structured data are not just facing a SPOR compliance problem today; they are facing an eCTD architecture gap that will constrain their ability to comply with future structured data requirements across FDA, EMA, and PMDA submissions simultaneously.

    The global IDMP implementation landscape as of mid-2026 reflects three distinct trajectories. EMA is enforcing ISO 11615 through PMS on a phased schedule — data enrichment deadlines for centrally authorized products on the Union List of Critical Medicines extend to mid-2026, with non-centrally-authorized products following through 2027. Japan’s PMDA has not mandated ISO IDMP submission outright, but its April 2026 eCTD v4.0 mandate moves the agency toward the same coded, structured data foundation IDMP requires. FDA’s position is neither adoption nor rejection: per its March 2023 guidance “Identification of Medicinal Products — Implementation and Use,” FDA’s internal committee determined that the NDC — prefixed with the two-letter GENC “US” country code — produces a code structurally comparable to the ISO 11615 MPID, and that the Unique Ingredient Identifier and UCUM already conform to ISO 11238 and ISO 11240, respectively. What FDA has not adopted is the EUPI-based SPOR submission architecture itself; the agency describes global IDMP implementation as a phased effort still being worked out with ISO, HL7, and other regulators, with no operational cross-reference between NDC-based US registration and EUPI-based EU registration. That divergence between FDA’s NDC-based regional conformance model and EMA’s EUPI-based SPOR submission model is not a temporary gap — it is a structural difference that requires companies with both FDA and EU portfolios to maintain parallel product identification systems with no automated cross-reference. Understanding that gap at the data architecture level, rather than discovering it during a regulatory submission, is precisely what separates organizations that manage global IDMP strategically from those that manage it reactively.

    ────────────────────────────────────────────────────────────────────── [FRAMEWORK BOX] XGene ISO IDMP Regulatory Data Architecture Assessment ──────────────────────────────────────────────────────────────────────

    The XGene ISO IDMP Regulatory Data Architecture Assessment is a structured engagement designed to determine whether a company’s regulatory data systems can sustain ISO 11615-compliant IDMP submissions across all four data model layers — and to build the remediation roadmap when they cannot.

    Step 1 — ISO 11615 Four-Layer Data Model Mapping: Map each product’s current regulatory data against the four IDMP layers (substance, pharmaceutical product, regulated medicinal product, packaged product) and identify which data elements exist as coded fields versus free text — this step surfaces the structural gaps that cause PMS technical validation failures before a submission is attempted.

    Step 2 — ISO 11239 Dose Form and Route Coding Gap Assessment: Audit every dose form and route of administration descriptor across the EU portfolio against the EDQM Standard Terms list required by ISO 11239 — the output identifies all non-coded descriptors that will fail EMA eAF technical validation and the system-level changes required to enforce coded term selection at the point of data entry.

    Step 3 — ISO 11240 UCUM Strength Expression Validation: Extract strength expressions from specifications, SmPC, and eAF data across all products and validate each against ISO 11240 UCUM codes — this step identifies unit expression inconsistencies that generate eAF validation errors and confirms whether the regulatory data system enforces UCUM at the source or allows free-text unit entry.

    Step 4 — Cross-Agency IDMP Harmonization Roadmap: Assess the regulatory database architecture for IDMP compatibility and produce a structured roadmap connecting EMA SPOR product data, FDA substance registration records, and the company’s internal CMC data system — the roadmap defines the cross-reference schema, the data governance rules, and the system integration requirements for maintaining a single authoritative product data record that serves IDMP-compliant submissions across all active regulatory jurisdictions.

    The output of this assessment is an IDMP Architecture Remediation Package: a layer-by-layer data model gap report, a coded terminology alignment register for dose form, route, and strength units, a regulatory database architecture assessment with system-specific remediation requirements, and a cross-agency harmonization roadmap — not a readiness checklist, but an executable implementation plan tied to specific data systems, submission timelines, and agency enforcement schedules.

    ──────────────────────────────────────────────────────────────────────

    Organizations that treat IDMP compliance as a SPOR form-filling task will build regulatory data systems that are technically correct for today’s EMA submissions and architecturally incompatible with tomorrow’s global structured data requirements. When FDA extends its NDC-to-MPID conformance work toward a fuller IDMP alignment — and when ICH M8’s eCTD v4.0 structured-content requirements extend coded data expectations into Module 3 sections — the companies that did not align their regulatory data architecture to the ISO 11615 four-layer model will face remediation costs that dwarf the investment required to build the architecture correctly. The cost of reactive remediation in regulatory data is not measured in consultant hours; it is measured in delayed submissions, failed technical validations, and the organizational friction of rebuilding data governance under regulatory time pressure.

    Select one product from your EU portfolio and map its PMS data against the four ISO IDMP 11615 data layers — substance (ISO 11238), pharmaceutical product, regulated medicinal product, and packaged product — and verify that each layer’s coded data elements (dose form, route, strength units) use the EDQM Standard Terms and ISO 11240 UCUM codes required for IDMP compliance.