Where Do US Drug Ingredients Come From? The China Risk

Ask where a US medicine is made and the answer usually points to a familiar brand. Ask where its ingredients come from and the picture narrows fast. In a recent Open Door Salon conversation, Theresa Campobasso, a former US Marine Corps intelligence officer and Senior Vice President at Aardwolf Global, described an exposure most companies treat as a procurement detail rather than a strategic risk.
The concentration most companies miss
The vulnerability is in the active pharmaceutical ingredients, or APIs, and the chemical precursors most drugs are built from.
"APIs is an area where the United States does have pretty significant concentration risk, and when you get into some of the subtier supply chain, a lot of APIs come from one or two locations in China or India."
Concentration is the operative word. When a critical input traces back to one or two sources, a disruption or a regulatory change at either one ripples straight through to the finished product, no matter how diversified the company looks at the top tier.
Why it is hard to fix
Campobasso is candid that this is not a problem a company can unwind in a quarter.
"That's going to be one where I'm really interested to see what happens, because it may be difficult to mitigate."
That difficulty is exactly why she expects APIs and precursors to draw regulatory attention next. The dependency is real, it is concentrated, and it cannot be reshuffled overnight, which makes it both a national concern and a slow one to address.
The same risk shows up in hardware
The exposure is not limited to molecules. For medical technology, Campobasso notes, it shifts to components, where the failure mode is counterfeit or compromised hardware, and she points to a concrete example from the pandemic.
"We saw this in 2020 with Operation Warp Speed. The rates of counterfeits that were discovered, many from China, was excessive. Almost half a billion dollars of fraudulent acquisitions were being considered, and fortunately they had a threat-based lens, using AI and data and tools to assess the hidden risks."
Without those questions, she notes, that half-billion in fraudulent purchases would have gone through. The lesson is that the same sub-tier blind spot that hides an API source can hide a counterfeit component.
Why standard sourcing checks miss it
The reason this risk persists is that conventional diligence stops at the immediate supplier. A company verifies the vendor in front of it, confirms the financials and the contracts, and considers the work done. The concentration risk lives one or two tiers deeper, below where that check reaches, which is why a chain can look healthy at the top and be fragile at the base.
What to do now
Provenance is the discipline that closes the gap
The defense Campobasso describes is not exotic. It is provenance: knowing, and being able to verify, where a material actually originates rather than trusting that the supplier in front of you has already done that work. For a physical input like an API or a precursor, that means tracing the chain past the immediate vendor to the locations where the raw material is genuinely produced. The good news she offers is that this is far more achievable than it was a few years ago, because modern data tools can map those connections at a scale and speed a human team never could; the hard part is deciding to look.
The cost of getting it wrong
Treating this as a back-office detail is what turns a manageable exposure into a crisis. A company that does not know where a critical ingredient comes from cannot move quickly when a single source is disrupted, sanctioned, or pulled into a new regulation, and in a concentrated chain those events hit the finished product directly. The Operation Warp Speed example is instructive precisely because the threat-based screen caught the problem before the money moved; the counterfactual, half a billion dollars in fraudulent acquisitions, is what happens when no one is asking. The same is true, quietly and continuously, for the API base that most companies never map.
The practical move is to look past the immediate supplier and map the subtier chain, the suppliers behind the suppliers, before a rule or a shortage forces the question. That means asking where an ingredient actually originates, identifying where a single location carries too much of the load, and investigating alternative or domestic sources while there is time to qualify them. Knowing where an ingredient really comes from is the difference between a managed adjustment and a scramble. For companies working through that exposure, that is the conversation Open Door Salon exists to host. You can work with us here.
This piece is drawn from the recorded, on-the-record conversation with Theresa Campobasso on Open Door Salon. The bills referenced are proposed US legislation; consult current congressional coverage for their status.
