Podcast Episode

03 | Rethinking the Fence: Data, Standards, and the New Energy in Regulatory — with Crystal Allard

About this episode

About the Guest Crystal Allard is Senior Director of Government Strategy at Veeva Systems, where she works with regulators and industry to shape the future of the submissions ecosystem and increase speed to market. Crystal spent roughly 15 years at the FDA across innovation and technology roles — including time working for the agency's Chief Data Officer and at the Center for Tobacco Products, plus stints as an FDA consultant. She also worked in regulatory operations before joining the agency, giving her a rare full-circle view of how submissions are built, reviewed, and inspected. She recently co-authored published commentary on the joint FDA–EMA Guiding Principles of Good AI Practice in Drug Development (January 2026) and is a speaker at the Veeva R&D and Quality Summit. Key Topics A new wave of energy. After years of stasis, health authorities are increasingly open to modern, data-driven technology. Crystal's read: it feels inevitable now in a way it simply didn't two years ago. Standards bodies in flux. Standards like CDISC have been in place for essentially Crystal's whole career — but new leadership at CDISC, HL7, and its Vulcan FHIR Accelerator is creating real willingness to revisit old assumptions. HL7 groups already use AI to draft standards, data models, APIs, and implementation guides, compressing timelines with far fewer resources. The new bottleneck: the testing, voting, and adoption infrastructure, still geared to a three-years-ago cadence. The lasting lesson of COVID. Rolling reviews proved faster review is possible — but regulators did it the hard way, because data wasn't in the format they needed. The insight: standardization doesn't always equal usability, or even validity. Data needs to be accessible and analyzable. The goal now is to keep the speed but build the "easy button." Global convergence — and its limits. At DIA Europe, multiple health authorities discussed reliance and the "inevitability" of a shared submission process, while staying cagey on technology. Standards organizations are quietly driving convergence — ICH guidelines like M4Q(R2) now publish in a common format across many countries. Missed opportunities remain, notably the lack of shared data-security requirements and a separate ICH Module 1 per country. Rethinking the submission "fence." Today's model is over-the-fence: build a package, toss it across. Crystal floats a reframe — what if the space between sponsor and regulator isn't just a transfer point but a shared storage and viewing space? APIs and direct connections could enable continuous, "live" review. It's a different paradigm than eCTD and even eCTD v4.0, which Crystal frames as both a globalization attempt and a missed opportunity at better exchange technology. Security, IP, and who owns the data. Centralization cuts both ways — a single shared space is either a bigger target or a better-defended fortress. In the US, submission data is owned by the sponsor; FDA only stewards it — so sponsors can do more with their own data, and their own FDA letters, than they realize. Meanwhile FDA wants earlier access to sponsor data but can't share its review memos across authorities — a catch-22 that may take legislation to resolve. The RIM blind spot — and the special-format mistake. Many at health authorities have never built a submission, so they underestimate the data management, QC, and validation work behind one — and were often unaware of regulatory information management (RIM) systems at all. Crystal shares a candid "learning experience" from her Center for Tobacco Products days: special submission formats (a PDF-backbone structure, and later eSTAR and other e-submitter formats) were designed to be easier — but modern AI tooling is now so good at standard formats like eCTD that the special ones cost more time and money. The reviewer disconnect. Many format rules exist not because a reviewer wants to read a document, but because review software needs specific data sets for automated