Services/SaaS & Cloud Vendor Assurance

Digital & Technology Compliance

SaaS & Cloud Vendor Assurance

Independent qualification and assurance services for SaaS platforms, cloud providers and third-party software vendors used in GxP-regulated environments — quality agreements, vendor risk assessments and ongoing monitoring frameworks.

Executive Overview

Pharmaceutical, biotechnology and medical device organisations are increasingly dependent on cloud-hosted and SaaS platforms for quality-critical operations — electronic quality management systems, laboratory information management, manufacturing execution systems, clinical trial management and regulatory information management. Each of these systems, and the vendors who operate them, must be qualified and managed as part of the organisation's GxP supply chain.

SaaS vendor qualification differs from traditional software qualification in important ways. The customer typically cannot access source code, cannot control update schedules and shares infrastructure with other customers. Qualification depends heavily on vendor-provided evidence, shared responsibility models and contractual controls embedded in quality agreements. Organisations that apply traditional validation approaches to SaaS systems either create unsustainable compliance overhead or produce qualification records that do not withstand regulatory scrutiny.

Sthira Assure provides independent SaaS vendor qualification, cloud provider assurance and third-party IT vendor audit services. We assess vendors against GxP requirements specific to the system's intended use, produce risk-based qualification packages and design quality agreements that protect the organisation's compliance position throughout the vendor relationship lifecycle.

Regulatory Frameworks

  • GAMP 5 (2nd Edition)
  • 21 CFR Part 11
  • EU GMP Annex 11
  • ISO 27001 / SOC 2
  • GDPR & Schrems II
  • ICH Q10 (QMS)
  • EU GMP Chapter 7

Qualify Your SaaS Vendors

Speak with our team about your cloud and SaaS qualification requirements.

Request a Consultation

Common Compliance Risks

Shared Responsibility Misunderstanding

Cloud and SaaS arrangements operate under shared responsibility models where security, compliance and operational obligations are divided between vendor and customer. Many regulated organisations have not formally documented these boundaries, do not understand which compliance obligations remain with them and have not verified that vendor responsibilities are actually being met. Inspectors expect clarity on who is responsible for what — and documented evidence that vendor obligations are being discharged.

Inadequate Vendor Change Management

SaaS vendors update their platforms continuously. Without formal change notification agreements and systematic impact assessment procedures, regulated organisations accumulate unreviewed changes to their GxP systems. Each unreviewed update is a potential validation gap. Quality agreements with SaaS vendors must specify notification timelines, change classification expectations and the customer's right to assess changes before deployment to production environments.

Insufficient Vendor Quality System Evidence

Pharmaceutical quality systems require that third-party software suppliers demonstrate appropriate quality management. Many SaaS vendors are not pharmaceutically-regulated organisations and do not automatically provide the quality system evidence — SOC 2 reports, penetration test summaries, business continuity plans, subprocessor disclosures — needed to support GxP qualification. Qualification without this evidence is not defensible on inspection.

Data Residency and Subprocessor Risks

Regulated organisations must understand where their GxP data is stored and processed, and who has access to it. SaaS vendors routinely use subprocessors — cloud infrastructure providers, analytics platforms, support tools — whose access to customer data is rarely disclosed proactively. For organisations subject to GDPR, the Schrems II requirements and data integrity obligations simultaneously, subprocessor risk assessment is a mandatory element of vendor qualification.

Scope of Services

SaaS supplier qualification and vendor assessment
Cloud provider assurance and shared responsibility reviews
Third-party compliance audits for regulated systems
IT vendor qualification programme design
Vendor security and data integrity assessment
Quality agreement review for software vendors
Ongoing vendor monitoring programme design
SaaS system change notification and update impact assessment

Typical Deliverables

SaaS Vendor Qualification Report
Cloud Provider Assurance Assessment
Shared Responsibility Matrix
Quality Agreement Review and Recommendations
Vendor Risk Assessment Report
IT Vendor Qualification Programme Design
Ongoing Monitoring Framework Documentation

Frequently Asked Questions

Can a SaaS system be used in a GxP-regulated environment?

Yes, provided it has been appropriately qualified. Qualification of SaaS systems requires a risk assessment of the system's GxP impact, review of the vendor's quality system and security controls, establishment of a quality agreement defining responsibilities, testing of GxP-critical functions and documentation of the qualification outcome. The FDA and EU regulators both acknowledge SaaS use in GxP environments — they expect it to be managed, not avoided.

What should a quality agreement with a SaaS vendor include?

A quality agreement with a SaaS vendor should cover: GxP system classification and applicable regulatory requirements, vendor responsibilities for system security, availability, data integrity and change management, customer notification timelines for planned changes, incident reporting obligations, access to audit evidence (SOC 2, penetration test reports), subprocessor disclosure, data residency commitments and data deletion or return procedures on contract termination.

How do you assess a SaaS vendor who is not familiar with pharmaceutical requirements?

Many commercially successful SaaS vendors operate outside the pharmaceutical industry and have not designed their systems specifically for GxP use. Our assessment approach examines their controls against the specific GxP requirements applicable to the intended use — GAMP 5 system category, relevant Part 11 or Annex 11 requirements, data integrity expectations. We identify gaps and provide specific, actionable requirements for the vendor to address in order to support qualification.

What is the difference between SOC 2 and GxP qualification?

SOC 2 reports provide assurance over security, availability, processing integrity, confidentiality and privacy controls — but against AICPA Trust Services Criteria, not pharmaceutical regulatory requirements. A SOC 2 Type II report is useful evidence within a GxP vendor qualification package, particularly for security controls, but it does not constitute qualification. GxP qualification must also address system-specific validation, data integrity, audit trail configuration and the vendor's pharmaceutical quality obligations.

Qualify Your Technology Vendors

Contact our team to discuss your SaaS and cloud vendor qualification requirements and the assurance programme your organisation needs.