New CARO. So what?
- Christiane Wirrig

- 4 days ago
- 4 min read
Updated: 3 days ago
Spherity has released a new CARO version - v1.3.

“What’s CARO?”, I hear you ask.
CARO is Spherity’s US Drug Supply Chain Security Act (DSCSA) compliance solution. Up until recently, it’s essentially existed as a Verification Router Service (VRS) enhancement by adding interoperable, standardized (OCI-specified) DSCSA Authorized Trading Partner (ATP) credentials straight into each VRS message exchange. This way the VRS user has reasonable assurance that the interaction partner is duly authorized to engage in the information exchange. ATP credentials can also be used for product tracing in a similar manner by being attached to the respective information request and response messages. You will have heard in its educational webinars and live demonstrations that the Louisiana Board of Drug and Device Distributors is actively using this technology for inspections.
ATP credential usage in VRS has seen increasing traction (read latest OCI comment). Since almost all FDA exemptions have expired with the last one not far away and following FDA’s warning letters, more wholesalers and dispensers are getting their systems ready. There’s even a free lightweight VRS app out there for small pharma businesses.
Now with the latest version upgrade to v1.3, CARO is aiming higher.

If you think about it, ATP credentials basically represent a set of entity master data. Depending on the chosen entity for the OCI-specified due diligence process, the ATP credential often represents the HQ of an organization. Thus, the onboarding process for ATP credentialing may not only be leveraged for VRS and tracing, but also other business processes that require trading partner vetting, data accuracy, and secure data sharing. So, CARO v1.3 is taking first strides into expanding the use of the organizational Identity and ATP credentials trading partners already have.
Further, CARO v1.3 is adding more entity master data for users to manage. This includes real-time license checks back to authoritative sources. And that’s not all! There is also a message portal that connects trading partners directly within CARO whether or not they possess ATP credentials. A CARO user can invite their supply chain partners to use the message function in order to resolve data inquiries and other tasks or issues, or to request master data in the form of self-attestations or verifiable credentials, such as ATP credentials.
So, how would you think through the new master data management capabilities?
The flowchart below walks through the general decision-making process on whether and how to use those CARO v1.3 features.

Let’s go through the flowchart and begin with the challenge: There’s a trading partner that needs to be assessed according to your organizational SOPs. Say, they’ve asked you about product details outside of the VRS network. You choose to use CARO’s new functionalities for the counterparty vetting.
First, you decide whether the interaction requires you to confirm their ATP status. If so, you can request their ATP credential through the CARO message portal. If they have none, you’ll need to take an alternative route outside of CARO. However, you can ask them to obtain an ATP credential for future interactions and connect their CARO profile to yours for easier monitoring going forward.
If no ATP check is required, you assess the need for other checks. CARO offers the possibility to perform various real-time checks, such as FDA registrations, State or DEA licenses. We will keep adding more based on customer needs.
If none of those checks are required, maybe you just want to confirm certain master data, such as GLN or address, with them. You can request their details through the CARO message portal. CARO will then log them in the database for future reference.
If none of the above is required, you can still invite them to join your CARO network and exchange secure messages through the portal, or simply keep interacting with them outside CARO.
Since CARO is readily tied in with most active VRS providers, one question we keep receiving is whether CARO can help with vetting uncredentialed, unknown VRS users (indirect trading partners).
The flowchart below depicts how CARO v1.3+ can help with uncredentialed indirect as well as direct trading partners.

Let’s go through this flowchart.
You have data on known (direct) and unknown (indirect) trading partners. These may be extracts from your ERP, VRS, or other systems.
The first thing then is to get these data into CARO.
If you identify gaps in your data to the point that performing due diligence is impossible, e.g. unknown license number, you will need a secure way of contacting the counterparty. Hence, we recommend inviting them to CARO to leverage the secure message portal and interactive data maintenance functionalities.
Whether you have requested the missing data or any data updates directly through CARO or ingested them from outside CARO, you can then use CARO’s independent, automated due diligence features, currently license and ATP credential checks.
If you prefer to automate regular checks instead of managing them as one-offs, CARO will enable you to create a routine for ongoing monitoring.
At Spherity, we believe in strong partnerships with specialist services so that each piece of the puzzle fits as neatly as possible. That’s why CARO v1.3 is building on our existing partnership with the forward-thinking regulatory compliance experts from Legisym. From license checks to ATP credentials, Legisym is committed to enabling the highest level of compliance also within CARO.

CARO v1.3 was built to show the tremendous potential of CARO as a DSCSA compliance platform. It is to inspire more things to come - more automation, more integrations with ERP or other external systems, more secure and efficient data sharing.
Update once, share to many. That’s the goal.


