Digital & Technology Compliance
SaaS & Cloud Vendor Assurance
Independent qualification and assurance services for SaaS platforms, cloud providers and third-party software vendors used in GxP-regulated environments — quality agreements, vendor risk assessments and ongoing monitoring frameworks.
Executive Overview
Pharmaceutical, biotechnology and medical device organisations are increasingly dependent on cloud-hosted and SaaS platforms for quality-critical operations — electronic quality management systems, laboratory information management, manufacturing execution systems, clinical trial management and regulatory information management. Each of these systems, and the vendors who operate them, must be qualified and managed as part of the organisation's GxP supply chain.
SaaS vendor qualification differs from traditional software qualification in important ways. The customer typically cannot access source code, cannot control update schedules and shares infrastructure with other customers. Qualification depends heavily on vendor-provided evidence, shared responsibility models and contractual controls embedded in quality agreements. Organisations that apply traditional validation approaches to SaaS systems either create unsustainable compliance overhead or produce qualification records that do not withstand regulatory scrutiny.
Sthira Assure provides independent SaaS vendor qualification, cloud provider assurance and third-party IT vendor audit services. We assess vendors against GxP requirements specific to the system's intended use, produce risk-based qualification packages and design quality agreements that protect the organisation's compliance position throughout the vendor relationship lifecycle.
Regulatory Frameworks
- GAMP 5 (2nd Edition)
- 21 CFR Part 11
- EU GMP Annex 11
- ISO 27001 / SOC 2
- GDPR & Schrems II
- ICH Q10 (QMS)
- EU GMP Chapter 7
Qualify Your SaaS Vendors
Speak with our team about your cloud and SaaS qualification requirements.
Request a ConsultationCommon Compliance Risks
Shared Responsibility Misunderstanding
Cloud and SaaS arrangements operate under shared responsibility models where security, compliance and operational obligations are divided between vendor and customer. Many regulated organisations have not formally documented these boundaries, do not understand which compliance obligations remain with them and have not verified that vendor responsibilities are actually being met. Inspectors expect clarity on who is responsible for what — and documented evidence that vendor obligations are being discharged.
Inadequate Vendor Change Management
SaaS vendors update their platforms continuously. Without formal change notification agreements and systematic impact assessment procedures, regulated organisations accumulate unreviewed changes to their GxP systems. Each unreviewed update is a potential validation gap. Quality agreements with SaaS vendors must specify notification timelines, change classification expectations and the customer's right to assess changes before deployment to production environments.
Insufficient Vendor Quality System Evidence
Pharmaceutical quality systems require that third-party software suppliers demonstrate appropriate quality management. Many SaaS vendors are not pharmaceutically-regulated organisations and do not automatically provide the quality system evidence — SOC 2 reports, penetration test summaries, business continuity plans, subprocessor disclosures — needed to support GxP qualification. Qualification without this evidence is not defensible on inspection.
Data Residency and Subprocessor Risks
Regulated organisations must understand where their GxP data is stored and processed, and who has access to it. SaaS vendors routinely use subprocessors — cloud infrastructure providers, analytics platforms, support tools — whose access to customer data is rarely disclosed proactively. For organisations subject to GDPR, the Schrems II requirements and data integrity obligations simultaneously, subprocessor risk assessment is a mandatory element of vendor qualification.
Scope of Services
Typical Deliverables
Frequently Asked Questions
Can a SaaS system be used in a GxP-regulated environment?
Yes, provided it has been appropriately qualified. Qualification of SaaS systems requires a risk assessment of the system's GxP impact, review of the vendor's quality system and security controls, establishment of a quality agreement defining responsibilities, testing of GxP-critical functions and documentation of the qualification outcome. The FDA and EU regulators both acknowledge SaaS use in GxP environments — they expect it to be managed, not avoided.
What should a quality agreement with a SaaS vendor include?
A quality agreement with a SaaS vendor should cover: GxP system classification and applicable regulatory requirements, vendor responsibilities for system security, availability, data integrity and change management, customer notification timelines for planned changes, incident reporting obligations, access to audit evidence (SOC 2, penetration test reports), subprocessor disclosure, data residency commitments and data deletion or return procedures on contract termination.
How do you assess a SaaS vendor who is not familiar with pharmaceutical requirements?
Many commercially successful SaaS vendors operate outside the pharmaceutical industry and have not designed their systems specifically for GxP use. Our assessment approach examines their controls against the specific GxP requirements applicable to the intended use — GAMP 5 system category, relevant Part 11 or Annex 11 requirements, data integrity expectations. We identify gaps and provide specific, actionable requirements for the vendor to address in order to support qualification.
What is the difference between SOC 2 and GxP qualification?
SOC 2 reports provide assurance over security, availability, processing integrity, confidentiality and privacy controls — but against AICPA Trust Services Criteria, not pharmaceutical regulatory requirements. A SOC 2 Type II report is useful evidence within a GxP vendor qualification package, particularly for security controls, but it does not constitute qualification. GxP qualification must also address system-specific validation, data integrity, audit trail configuration and the vendor's pharmaceutical quality obligations.
Qualify Your Technology Vendors
Contact our team to discuss your SaaS and cloud vendor qualification requirements and the assurance programme your organisation needs.