Supplier & vendor audits

Three days, and a prepared audience.

A supplier audit is conducted on someone else’s premises, on their systems, with the evidence they choose to bring, in the time the contract allows. Everything depends on what you ask for and how quickly you notice what is missing.

A wide field of evidence points converging through a focusing lens into a single conclusion node, with one sample marked as a finding.

Perspective

Suppliers who host regulated customers audit well. The quality manual is complete, the presentation is polished, the certificates are current. None of that tells you whether the service you are buying is under control — and a general quality audit will usually stop exactly where the answer starts.

Capabilities

Specialist support, connected to the whole system.

Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.

01

Qualification audits

Establish before commitment whether capability and control exist to support the intended activity at all.

02

Routine & surveillance

Re-assess on a risk-based cycle, confirming an acceptable state has held and change since then has been controlled.

03

Technology depth

Audit software development, release, environments, configuration, interfaces, logs, and audit trails rather than the manual describing them.

04

AI supplier audits

Examine model lifecycle, evaluation evidence, monitoring, and change practice where a supplier has added AI to a regulated service.

05

Remote audit execution

Run system-based scope efficiently through live screen-shared walkthroughs, with evidence requests structured to prevent curation.

06

Finding & CAPA challenge

Grade on risk and evidence, then test whether the response addresses cause — across an organizational boundary where you cannot verify directly.

Supplier types

Different suppliers, different places to look.

Scope is risk-based and defined for the service and controls involved. What changes between supplier types is where control genuinely lives, and therefore where an audit day is worth spending.

01

Software & SaaS providers

Development lifecycle, release and environment control, configuration management, and what their validation actually leaves to you.

02

Cloud & hosting providers

Shared responsibility in practice, subprocessors, change notification, and whether the certificate scope covers your service.

03

AI & analytics providers

Training data provenance, evaluation evidence, model change and substitution, monitoring, and what they will commit to in writing.

04

eClinical platforms

EDC, CTMS, eTMF, eCOA, ePRO, and IRT: study build control, edit checks, audit trails, data export integrity, and support practice.

05

Laboratories & imaging

Instrument interfaces, chromatography and imaging data handling, integration practice, and second-person review that genuinely happens.

06

CROs & service providers

Delegation clarity, personnel qualification and stability, subcontracting, and their oversight of the parties behind them.

Getting past the presentation

What separates a real audit from a guided tour.

A supplier audit is a short window against a well-prepared counterpart. These are the moves that reliably find the difference between the documented process and the operating one.

  • Evidence requested before arrival, specifically enough that substitution is obvious
  • Live demonstration in the production system rather than screenshots of it
  • Samples chosen by the auditor, including records nobody expected to discuss
  • One transaction traced end to end, through every hand-off and every system
  • Deviations, incidents, and complaints read in full, not in summary
  • Subcontractors and their controls treated as part of the audited service
  • The gap between the certificate scope and the service you are actually buying

Approach

Context first. Evidence throughout.

A clear sequence keeps the work rigorous while avoiding unnecessary process.

  1. 01

    Define the risk

    Connect scope to the service, regulated process, data, and responsibilities involved — then resist scope drift on the day.

  2. 02

    Prepare the evidence request

    Ask for specific records early, so preparation time works for the audit instead of against it.

  3. 03

    Follow the evidence

    Use demonstrations, traceable samples, and the people doing the work to understand ordinary operation.

  4. 04

    Report for reliance

    Produce a report someone else can rely on for a qualification decision, with the basis for every conclusion stated.

Deliverables

What you receive.

An audit record complete enough to support a qualification decision and to be shown to a sponsor, a client, or an inspector.

  • An audit plan with scope, risk rationale, agenda, and a structured evidence request
  • A written report with graded findings and the basis for each conclusion
  • An explicit suitability conclusion, with conditions or restrictions where relevant
  • Review and challenge of the supplier’s response and corrective action plan
  • Formal closure documentation once actions are verified as effective

Reference frameworks

The expectations applied across the boundary.

Supplier audit criteria come from the regulations governing your use of the service, not from the supplier’s own choice of framework. Those below come up most often.

ICH E6(R3)
Sponsor oversight of delegated activity, proportionate to risk and documented.
EMA guideline on computerised systems and electronic data in clinical trials
European expectations a clinical technology provider has to be able to evidence, including validation, audit trails, and its own service providers.
EU GMP Chapter 7
Contract giver and contract acceptor responsibilities, and the written agreement between them.
EU Annex 11 & 21 CFR Part 11
Computerized systems, electronic records, audit trails, and the controls a supplier has to be able to evidence.
ISO 19011
Audit competence, evidence, and sampling discipline applied under access and time constraints.
ISO/IEC 27001 & SOC 2
Read for what they actually cover: certificate scope, report period, exceptions, and complementary controls left to you.

These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.

Typical applications

Where this work can apply.

  • Pre-contract qualification of a new supplier or platform
  • Periodic and surveillance audits in an oversight programme
  • Technical audits of software, cloud, or AI providers
  • Requalification after a material scope or service change
  • Audits where a general quality auditor could not reach the controls
  • Technology providers preparing to be audited by regulated customers

Start a conversation

Bring the right level of assurance to the next decision.

Begin with a focused discussion about context, risk, evidence, and the outcome you need.

Request a Supplier Audit