Applying OCI-Compliant Credentials to Trading-Partner Master Data
Use Case: Connecting Verified Enterprise Identity, ATP Status, and Trading-Partner Master Data
Prepared by the Open Credentialing Initiative | September 30, 2026
Morris & Dickson reported completing setup in a matter of hours; as part of the initial exercise, four trading partners added its signed master data.
ABOUT THIS MEMBER PROJECT. This case study describes a project conducted by Morris & Dickson and LedgerDomain. OCI did not operate or independently audit the deployment. Project details and reported outcomes are attributed to the participating organizations.
Summary
Morris & Dickson (M&D), a U.S. wholesale distributor, used a credential-backed address book provided by LedgerDomain to publish signed master data for its trading partners. The project connected OCI-compliant digital credentials with corporate identity, facility, identifier, licensure, and contact records. The goal was to replace spreadsheet-centered exchange with a governed, auditable way for authorized trading partners to review and consume current information.
According to the participants, M&D configured its self-published data in April 2026 in a matter of hours. Three health systems and one manufacturer then added the signed records to their own address books. The exercise also prompted data cleanup and demonstrated a privacy-aware way to share DSCSA contact details.
Introduction
The U.S. Drug Supply Chain Security Act (DSCSA) establishes interoperable requirements for identifying and tracing prescription drugs across the distribution supply chain. Manufacturers, repackagers, wholesale distributors, third-party logistics providers, and dispensers must be able to establish that their counterparties are authorized trading partners (ATPs) and exchange the transaction information required for covered drug movements.
Organizations also need current facility and licensure information to support ship-to and ship-from checks. In practice, those records are often distributed across spreadsheets, internal systems, public registries, and inboxes. That fragmentation makes repeated partner validation slow and difficult to audit.
Key challenges include:
Distributed records. Corporate, facility, license, identifier, and contact data may live in different systems.
Ongoing change. Licenses expire, facilities and identifiers change, and operational contacts need to stay current.
Repeated verification. Trading partners may request the same information through separate manual workflows.
Source assurance. Recipients need confidence in who supplied the data and whether it has been altered.
Privacy-aware access. Sensitive operational contact information should be shared with the appropriate ATPs, not exposed broadly.
Context: From Credentials to Credentialed Master Data
OCI-compliant digital credentials are already used for authentication and authorization within the Verification Router Service (VRS). M&D first received its DSCSA credential in October 2024. The project participants described the same credentialing approach being reused for additional signed-data workflows, including ATP confirmation, exceptions management, and investigations involving suspect or illegitimate products.
In this case study, “credentialed master data” is an operational description rather than a separate OCI credential class. The approach combines OCI-compliant credentials - which support verification of enterprise identity and ATP status - with a signed set of business records supplied by the trading partner. The signature provides tamper-evident evidence of the source while leaving the trading partner responsible for the accuracy and maintenance of its own data.
Morris & Dickson’s Approach
In April 2026, M&D published its own records through LedgerDomain’s Address Book. The implementation was intended to make current information easier for customers and suppliers to obtain, reduce administrative work, and support continued product movement as DSCSA processes become part of daily operations.
How It Works
Manage first-party data. M&D maintains corporate details, facility addresses, state licenses, Global Location Numbers (GLNs), and preferred contact information through a web dashboard.
Manage trading partners. Credentialed partner records can be added and supplemented. Organizations without credentials can be selected from a directory or entered manually.
Request and review information. A named contact receives a prefilled request, reviews the information, and revises it when necessary before returning it.
When OCI-compliant credentials are used, signing operations support each workflow. The product also permits directory, manual, and other alternative methods, so not every record is necessarily credentialed. Publicly available data can accelerate onboarding, but only a trading partner can sign its own messages and data.
Implementation Timeline
October 2024: M&D’s DSCSA credential was first issued before the end of the FDA stabilization period.
April 2026: M&D configured its self-published Address Book data; the participants reported that setup took a matter of hours.
Initial exercise: Four trading partners - three health systems and one manufacturer - added M&D’s signed data to their address books.
Data Included
The published records covered the information M&D and its partners use for DSCSA and related facility-level workflows.
M&D remains responsible for updating these records as licenses, facilities, identifiers, and contacts change.
Partner Exchange and Privacy
Credentialed Partners
A trading partner with its own ATP credential can add M&D to its address book and receive a signed block of master data. Once both parties participate, each organization’s credentialed information becomes available to the other through what the participants describe as a “mutual handshake.”
Partners Without an Address Book
A partner without an address book can request the information and receive a signed, standardized email in a human-readable format. This provides a transitional path for organizations that have not yet adopted the same tooling.
Privacy Controls
The participants reported that DSCSA contact email addresses remain visible only to other ATPs through the mutual-handshake process, even though many other data elements are publicly available. In this implementation, identity and authorization are used to support selective disclosure of operational information.
Reported Outcomes from the Initial Exercise
M&D and the project participants reported the following observations during the initial implementation:
Faster partner validation. Health systems conducting ATP validation could review M&D’s complete dataset, including licensed ship-from locations, without a new spreadsheet exchange.
Improved data quality. Preparing the records prompted corrections to names, addresses, and license information.
Lower administrative friction. A governed record and standardized exchange reduce repeated requests and manual reconciliation.
Privacy-aware sharing. The workflow limits preferred DSCSA contact details to ATPs participating in the mutual exchange.
Auditable provenance. Signed messages provide tamper-evident evidence of who supplied the data and support a traceable exchange history.
Conclusion
M&D’s project illustrates how OCI-compliant digital credentials can be reused beyond VRS requests as part of credential-backed master-data workflows. Although this deployment is member-led and vendor-specific, the underlying lesson is broader: verified enterprise identity and ATP status can help trading partners exchange business data with less manual reconciliation and clearer provenance.
OCI’s role is to maintain an open architecture, governance model, specifications, and conformance guidelines that support interoperable implementations. Solution design, data accuracy, and reported performance remain the responsibility of the participating organizations.
About the Open Credentialing Initiative
The Open Credentialing Initiative (OCI) is an independent collaborative non-profit group supporting the pharmaceutical supply chain’s use of verifiable credentials and digital wallets. OCI establishes and maintains open conformance and interoperability criteria, technical specifications, governance, and implementation guidance in a neutral industry forum.
Sources and Attribution
Original project case study: LedgerDomain - Morris & Dickson Operationalizes DSCSA with Credentialed Master Data (published May 7, 2026).
OCI editorial reference: Case Study: Onboarding New Customers to VRS with OCI-Compliant Credentials.
Member-project context and commercial disclaimer: OCI Member Case Studies and OCI Disclaimer.
References to commercial products and services are provided for informational purposes and do not constitute OCI endorsement or recommendation.

