Cloud & hosting audits
Audit hosted services against the regulated process they support, including shared responsibility, subprocessors, and change practice.
Technology, cloud & systems audits
Regulated work runs on services nobody in the organization operates: managed platforms, hosted data stores, third-party interfaces, and product features that change on the supplier’s release schedule.
Perspective
The question is not whether a system was validated, but whether the operating reality behind it can be relied upon — how data moves, where it is transformed, which controls belong to the supplier, which quietly remained yours, and what happens on the day the interface silently starts dropping records. Answering that requires reading configuration and logs, not just procedures.
Capabilities
Scope is tailored to the engagement; these are the core areas in which QA4Tech can contribute.
Audit hosted services against the regulated process they support, including shared responsibility, subprocessors, and change practice.
Examine validation state, configuration, access, audit trails, and whether the system in use still matches the one that was validated.
Trace data from origin to reported result through every transformation, interface, and manual intervention along the way.
Examine the places systems meet — reconciliations, error handling, and the silent failures that live between two owners.
Assess development, support, hosting, and managed-service providers on the practices that actually bear on your regulated activity.
Help technology providers understand, evidence, and withstand the assurance expectations of regulated customers.
Audit scope
Scope is defined by the regulated process and the risk it carries, not by a fixed technology list. These are the layers the work most often reaches, and each rewards a different kind of attention.
Hosting, compute, storage, network, backup and recovery, and the shared-responsibility boundary between provider and tenant.
eClinical, laboratory, manufacturing, and quality systems: validation state, configuration control, access, and audit trail adequacy.
Warehouses, lakes, transformations, and reporting layers, where the original meaning of a value is most often lost.
APIs, middleware, and file transfers between organizations, including reconciliation and what happens to a failed record.
Software development, release, environment management, support, and managed operations performed by people you do not employ.
Where failures hide
Failures rarely occur in the middle of a well-understood system. They occur at boundaries — of ownership, of data, of change, and of attention.
How it is commissioned
Technology audits run under any of the audit types. The subject sets what is examined; the type sets the access, the preparation time, and what the report has to support.
Auditing your own environments, systems, and change practice, often as part of a self-inspection programme.
Auditing a software, cloud, hosting, or managed-service provider before qualification or on a risk-based cycle.
After an outage, a data loss, an integrity signal, or a migration that did not go as planned.
Approach
A clear sequence keeps the work rigorous while avoiding unnecessary process.
Establish the regulated activity, the decisions it produces, and the data that has to be trustworthy for those decisions to hold.
Trace the real path end to end, including the steps nobody documented, using live demonstration rather than description.
Determine which controls the supplier operates, which are yours, and which are assumed by both and operated by neither.
Set out the exposures that matter, the evidence behind them, and a proportionate route to closing them.
Deliverables
A technical audit record that a quality unit can act on and an engineering team cannot dismiss.
Reference frameworks
Regulatory expectation and technical control frameworks are used together, so a finding lands with both the quality unit and the engineering team.
These are examples, not a complete list. The frameworks and criteria that apply to a particular engagement are identified and agreed as part of defining its scope.
Typical applications
Start a conversation
Begin with a focused discussion about context, risk, evidence, and the outcome you need.