Qualification audits
Establish before commitment whether capability and control exist to support the intended activity at all.
Supplier & vendor audits
A supplier audit is conducted on someone else’s premises, on their systems, with the evidence they choose to bring, in the time the contract allows. Everything depends on what you ask for and how quickly you notice what is missing.
Perspective
Suppliers who host regulated customers audit well. The quality manual is complete, the presentation is polished, the certificates are current. None of that tells you whether the service you are buying is under control — and a general quality audit will usually stop exactly where the answer starts.
Capabilities
Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.
Establish before commitment whether capability and control exist to support the intended activity at all.
Re-assess on a risk-based cycle, confirming an acceptable state has held and change since then has been controlled.
Audit software development, release, environments, configuration, interfaces, logs, and audit trails rather than the manual describing them.
Examine model lifecycle, evaluation evidence, monitoring, and change practice where a supplier has added AI to a regulated service.
Run system-based scope efficiently through live screen-shared walkthroughs, with evidence requests structured to prevent curation.
Grade on risk and evidence, then test whether the response addresses cause — across an organizational boundary where you cannot verify directly.
Supplier types
Scope is risk-based and defined for the service and controls involved. What changes between supplier types is where control genuinely lives, and therefore where an audit day is worth spending.
Development lifecycle, release and environment control, configuration management, and what their validation actually leaves to you.
Shared responsibility in practice, subprocessors, change notification, and whether the certificate scope covers your service.
Training data provenance, evaluation evidence, model change and substitution, monitoring, and what they will commit to in writing.
EDC, CTMS, eTMF, eCOA, ePRO, and IRT: study build control, edit checks, audit trails, data export integrity, and support practice.
Instrument interfaces, chromatography and imaging data handling, integration practice, and second-person review that genuinely happens.
Delegation clarity, personnel qualification and stability, subcontracting, and their oversight of the parties behind them.
Getting past the presentation
A supplier audit is a short window against a well-prepared counterpart. These are the moves that reliably find the difference between the documented process and the operating one.
Approach
A clear sequence keeps the work rigorous while avoiding unnecessary process.
Connect scope to the service, regulated process, data, and responsibilities involved — then resist scope drift on the day.
Ask for specific records early, so preparation time works for the audit instead of against it.
Use demonstrations, traceable samples, and the people doing the work to understand ordinary operation.
Produce a report someone else can rely on for a qualification decision, with the basis for every conclusion stated.
Deliverables
An audit record complete enough to support a qualification decision and to be shown to a sponsor, a client, or an inspector.
Reference frameworks
Supplier audit criteria come from the regulations governing your use of the service, not from the supplier’s own choice of framework. Those below come up most often.
These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.
Typical applications
Start a conversation
Begin with a focused discussion about context, risk, evidence, and the outcome you need.