Sunshine Act: Traceability and Data Quality
Author

Maria Paola Carosio is a passionate and visionary executive with extensive experience across the Healthcare and Life Sciences sectors. She specializes in navigating complex regulatory landscapes, driving compliance, and providing strategic guidance that supports sustainable business growth. Throughout her career, she has managed global projects and led cross-functional teams at both local and international levels.
Her expertise spans Regulatory Affairs, Compliance, Scientific Services, Medical Affairs, Product Safety, and Quality, with experience across a broad range of product categories, including prescription drugs, biologics, generics, OTC products, medical devices, cosmetics, food supplements, and homeopathic medicines.
Recent Blogs
Cerchi supporto per la compliance al Sunshine Act?
Hai domande pratiche?
Dai un’occhiata alla nostra sezione Domande Frequenti per risposte chiare su scadenze, obblighi e strategie.
In recent years, many companies in the healthcare sector have already gained experience with the transparency systems introduced by Farmindustria, Egualia, and Confindustria Dispositivi Medici. While requiring the collection and publication of transfers of value, these models are primarily based on industry association frameworks.
The Italian Sunshine Act is a law that, in addition to extending its application to all “companies engaged in activities directly related to the production or marketing of medicines, instruments, equipment, goods or services, including non-healthcare products, including nutritional products, that can be marketed within the field of human and veterinary health, as well as companies involved in the organization of conferences and congresses concerning the same subjects”, which, in their activities, interact with “individuals operating in the healthcare sector” and with “healthcare organizations”, introduces a significantly higher level of detail, control, and accountability, transforming transparency from an industry initiative into a regulatory obligation.
For this reason, treating it as a simple compliance requirement risks being a mistake.
There is considerable discussion around processes, responsibilities, cross-functional collaboration, and training. All of these are important areas that every company should address. However, it is important to keep in mind that end-to-end traceability and data quality will determine a company’s ability to be genuinely compliant and prepared for an audit.
Many organizations already possess the information necessary to meet their Sunshine Act obligations. The problem is that this information often resides in different systems, is managed by different functions, or is integrated manually through Excel files and consolidation activities.
ERP, CRM, event management systems, expense reports, travel platforms, legal departments, HR, external consultants, and agencies all produce information that contributes to the construction of the final data to be published.
If there is no clear view of all the processes and of how the data to be submitted is generated, transformed, and transferred between the various systems, the risk of errors increases rapidly. And when an anomaly emerges, reconstructing what happened can require days of work and the involvement of numerous business functions.
What does it really mean to have traceable data?
It is not enough to know the final amount. The company must be able to demonstrate:
- which document or transaction the data originates from
- which system generated it
- who entered or modified it
- which controls and approvals were carried out
- why any changes were made over time
This capability becomes essential not only in the event of an inspection by the authorities, but also for managing internal controls, requests for clarification, and disputes raised by the parties involved.
An organization that depends on the knowledge of a few key individuals or on manual reconstructions exposes itself to a high level of operational risk.
Data quality is equally important.
Information can be perfectly traceable and still be incorrect, incomplete, or inconsistent.
To be usable for Sunshine Act purposes, data should meet several fundamental requirements:
- accuracy, meaning that it correctly represents the transaction carried out
- completeness, containing all information required by the legislation
- consistency, being identical across the different systems in which it is used
- timeliness, being updated according to the required timelines
- integrity, preventing unauthorized or undocumented changes
When these requirements are not guaranteed, the risk of incorrect publications, penalties, and requests for verification from the authorities increases.
Before investing in new technologies, many companies should begin with a concrete assessment of their current situation by:
- mapping all data sources involved in the individual process, including manual processes
- identifying the steps through which data is transformed and consolidated
- clearly defining the roles and responsibilities of data owners
- standardizing transaction classification rules
- implementing automated controls on critical data
- maintaining documentary evidence that can be easily retrieved
- ensuring that changes are recorded through structured audit trails
These measures are not only intended to reduce the risk of non-compliance, but also improve operational efficiency by reducing manual activities, limiting errors, accelerating internal checks, and improving the overall quality of corporate information.
Companies that approach the Sunshine Act as a data governance project will certainly derive greater benefits than those that consider it solely a regulatory obligation.
Maria Paola Carosio
Strategic Regulatory, Scientific Service and Compliance Consultant
In recent years, many companies in the healthcare sector have already gained experience with the transparency systems introduced by Farmindustria, Egualia, and Confindustria Dispositivi Medici. While requiring the collection and publication of transfers of value, these models are primarily based on industry association frameworks.
The Italian Sunshine Act is a law that, in addition to extending its application to all “companies engaged in activities directly related to the production or marketing of medicines, instruments, equipment, goods or services, including non-healthcare products, including nutritional products, that can be marketed within the field of human and veterinary health, as well as companies involved in the organization of conferences and congresses concerning the same subjects”, which, in their activities, interact with “individuals operating in the healthcare sector” and with “healthcare organizations”, introduces a significantly higher level of detail, control, and accountability, transforming transparency from an industry initiative into a regulatory obligation.
For this reason, treating it as a simple compliance requirement risks being a mistake.
There is considerable discussion around processes, responsibilities, cross-functional collaboration, and training. All of these are important areas that every company should address. However, it is important to keep in mind that end-to-end traceability and data quality will determine a company’s ability to be genuinely compliant and prepared for an audit.
Many organizations already possess the information necessary to meet their Sunshine Act obligations. The problem is that this information often resides in different systems, is managed by different functions, or is integrated manually through Excel files and consolidation activities.
ERP, CRM, event management systems, expense reports, travel platforms, legal departments, HR, external consultants, and agencies all produce information that contributes to the construction of the final data to be published.
If there is no clear view of all the processes and of how the data to be submitted is generated, transformed, and transferred between the various systems, the risk of errors increases rapidly. And when an anomaly emerges, reconstructing what happened can require days of work and the involvement of numerous business functions.
What does it really mean to have traceable data?
It is not enough to know the final amount. The company must be able to demonstrate:
- which document or transaction the data originates from
- which system generated it
- who entered or modified it
- which controls and approvals were carried out
- why any changes were made over time
This capability becomes essential not only in the event of an inspection by the authorities, but also for managing internal controls, requests for clarification, and disputes raised by the parties involved.
An organization that depends on the knowledge of a few key individuals or on manual reconstructions exposes itself to a high level of operational risk.
Data quality is equally important.
Information can be perfectly traceable and still be incorrect, incomplete, or inconsistent.
To be usable for Sunshine Act purposes, data should meet several fundamental requirements:
- accuracy, meaning that it correctly represents the transaction carried out
- completeness, containing all information required by the legislation
- consistency, being identical across the different systems in which it is used
- timeliness, being updated according to the required timelines
- integrity, preventing unauthorized or undocumented changes
When these requirements are not guaranteed, the risk of incorrect publications, penalties, and requests for verification from the authorities increases.
Before investing in new technologies, many companies should begin with a concrete assessment of their current situation by:
- mapping all data sources involved in the individual process, including manual processes
- identifying the steps through which data is transformed and consolidated
- clearly defining the roles and responsibilities of data owners
- standardizing transaction classification rules
- implementing automated controls on critical data
- maintaining documentary evidence that can be easily retrieved
- ensuring that changes are recorded through structured audit trails
These measures are not only intended to reduce the risk of non-compliance, but also improve operational efficiency by reducing manual activities, limiting errors, accelerating internal checks, and improving the overall quality of corporate information.
Companies that approach the Sunshine Act as a data governance project will certainly derive greater benefits than those that consider it solely a regulatory obligation.
Maria Paola Carosio
Strategic Regulatory, Scientific Service and Compliance Consultant
Author

Maria Paola Carosio is a passionate and visionary executive with extensive experience across the Healthcare and Life Sciences sectors. She specializes in navigating complex regulatory landscapes, driving compliance, and providing strategic guidance that supports sustainable business growth. Throughout her career, she has managed global projects and led cross-functional teams at both local and international levels.
Her expertise spans Regulatory Affairs, Compliance, Scientific Services, Medical Affairs, Product Safety, and Quality, with experience across a broad range of product categories, including prescription drugs, biologics, generics, OTC products, medical devices, cosmetics, food supplements, and homeopathic medicines.
Recent Blogs
Cerchi supporto per la compliance al Sunshine Act?
Hai domande pratiche?
Dai un’occhiata alla nostra sezione Domande Frequenti per risposte chiare su scadenze, obblighi e strategie.


