One example of the kind of work The BioChain Advisory does: helping organisations work out whether their systems can actually prove what they claim, before a regulator, investor, customer or incident forces the question. Here is how that played out.
A life-sciences company relied on several external partners to deliver a critical scientific and operational workflow. One supplier performed laboratory testing. Another provided sequencing. A third hosted part of the analytical environment. A specialist consultancy contributed interpretation. The client organisation received the final outputs and retained some associated records internally.
Each supplier maintained a strong audit trail within its own environment. The difficulty appeared at the boundaries between them.
The client knew a sample had been sent to a laboratory and later received a result, but did not retain a complete record of how identifiers had been translated between the two organisations. Sequencing data arrived through a secure transfer, but the relationship between the original specimen and the delivered files depended on a manifest generated by the supplier. An analytical provider returned a final report without enough information to reconstruct which version of a pipeline or reference dataset had been used.
No individual supplier was doing anything wrong. The evidence chain simply crossed several organisational boundaries.
We mapped that chain from the client’s own perspective: where responsibility changed, which evidence remained under the client’s control, which evidence existed only with third parties, how identifiers survived transfers, and what records would be needed if the organisation had to reconstruct the complete history later. We also tested assumptions contained in contracts, procedures and supplier documentation against the evidence actually available. The client had assumed a supplier retained raw data for a set period, but had never tested whether that data could be retrieved in a usable form. A service agreement described an audit trail, but the client did not know which parts of it would remain accessible after the contract ended.
The purpose was not to tell the organisation to bring every process in-house. Outsourcing was entirely appropriate here.
Does the organisation know where its own evidence chain stops, where a supplier’s begins, and whether the two can be reconnected when necessary?
The recommendations that followed included changes to retained records, identifier conventions, supplier hand-offs, evidence requirements, contractual questions to raise with providers, and simple operational controls that materially improved future traceability.
Some access helps, but the review starts from what you can see and control today, and identifies exactly where you would need supplier cooperation to go further.
No. It applies to any outsourced step in an evidence chain — analytics, hosting, interpretation, manufacturing — anywhere responsibility crosses an organisational boundary.
We typically start with the suppliers carrying the highest-consequence evidence, then extend the same mapping to the rest once the approach is proven on the ones that matter most.
Yes. The gaps this surfaces often translate directly into specific evidence and retention clauses worth adding to future agreements, not just fixes for existing ones.
The BioChain Advisory helps organisations understand how evidence actually moves through their existing systems, independent of whether they ever deploy The BioChain platform itself. Engagements typically take one of two forms: a Data Integrity Audit, tracing representative evidence chains from source to conclusion to establish what can genuinely be demonstrated, or a Regulatory & Cross-Border Readiness Review, examining whether an organisation's systems and records can support the claims a new jurisdiction or regulation requires.