Services/Supplier Qualification

Supplier Qualification

Supplier Qualification Audits

Risk-based qualification programmes for API suppliers, CDMOs, packaging manufacturers, CROs, IT vendors and logistics providers, delivering independent assurance that your supply chain meets regulatory expectations.

Executive Overview

Pharmaceutical and medical device manufacturers are responsible for the quality of the products they release to market, regardless of how much of the manufacturing, testing and distribution chain is outsourced. EU GMP Chapter 7 (Outsourced Activities) and FDA CGMP regulations establish clear expectations: the contract giver must verify GMP compliance of contract acceptors through qualification and periodic audit.

Supplier qualification is one of the highest-risk areas in pharmaceutical quality management. Supply chain complexity continues to increase, API manufacturing is concentrated in a small number of countries, CDMOs handle multiple product lines simultaneously and packaging supply chains span multiple jurisdictions. Each link in this chain presents quality risks that contract givers cannot reliably assess without independent audit.

Sthira Assure supplier qualification audits follow a structured, risk-based methodology. We begin with risk classification of your supplier base, prioritise audit scope and frequency based on supply chain criticality and regulatory exposure, and conduct audits against the specific regulatory requirements applicable to each supplier category. Our reports provide the evidence base your quality system needs to support approved supplier list decisions.

Supplier Categories

  • API Suppliers

    ICH Q7, EU GMP Part II, FDA 21 CFR 211.84

  • Excipient Manufacturers

    IPEC-PQG GMP, ICH Q7 principles

  • Packaging Suppliers

    PS9000 standards, EU GMP Chapter 5

  • CDMOs

    EU GMP Chapter 7, ICH Q10, FDA CGMP

  • CROs

    ICH E6(R2), 21 CFR Parts 312, 320

  • IT Vendors & SaaS Suppliers

    FDA 21 CFR Part 11, EU Annex 11, GAMP 5

  • Wholesale Distributors

    EU GDP Guidelines, MHRA GDP Guidance

  • Laboratory Services

    OECD GLP, ISO 17025, ICH Q2(R1)

Qualify Your Supply Chain

Discuss your supplier base and qualification programme requirements.

Get in Touch

Common Compliance Risks

Insufficient Initial Qualification

Many organisations approve suppliers based on questionnaire responses, certificates of analysis or regulatory filing history rather than independent on-site assessment. This approach systematically overestimates supplier GMP compliance and leaves significant quality risks unidentified until a product failure, recall or inspection observation forces a review.

Inadequate Quality Agreements

Quality agreements must reflect the actual allocation of quality responsibilities between sponsor and supplier. Inspectors find agreements that are generic, do not address specific products or processes, pre-date current operations and have not been reviewed following changes to supplier arrangements. An inadequate quality agreement is both a regulatory finding and a contractual risk.

No Periodic Reassessment

Supplier qualification is not a one-time event. EU GMP Chapter 7 and FDA expectations require periodic reassessment of critical suppliers based on risk. Organisations frequently lack formal reassessment programmes, rely on supplier-provided self-assessments and fail to audit suppliers following significant changes to their operations, ownership or regulatory status.

Process Change Notification Failures

Suppliers that implement manufacturing process changes, site transfers, material substitutions or personnel changes without notifying customers introduce undetected quality risks. Effective supplier qualification programmes require change notification obligations in quality agreements, backed by audit verification that the supplier's change control system is functioning as specified.

Scope of Services

API and drug substance supplier qualification audits (ICH Q7)
CDMO and contract manufacturer qualification assessments
Excipient and packaging material supplier audits
CRO and investigator site qualification audits
IT vendor and SaaS supplier quality assessments
Wholesale distributor and 3PL provider audits (GDP)
Quality agreement review, gap analysis and development
Approved supplier list design and risk-based management
Supplier change notification system assessments

How We Qualify Suppliers

01

Supplier Risk Classification

Risk-based classification of suppliers by criticality, regulatory exposure and supply chain position. Determines audit frequency, scope depth and documentation requirements.

02

Pre-Audit Documentation Review

Review of quality manuals, SOPs, regulatory filing history, previous inspection outcomes, quality agreements and supplier questionnaire responses before the audit visit.

03

Onsite or Remote Assessment

Structured audit against applicable GxP framework and your organisation's supplier qualification requirements. Facility walkthrough, system assessment, document review and personnel interviews.

04

Risk-Rated Findings Report

Written audit report with critical, major and minor findings, regulatory references, risk assessment for each finding and recommended CAPA actions. Issued within 10 working days.

05

CAPA Review and Approval Decision

Review of supplier CAPA responses. Approval, conditional approval or rejection recommendation based on CAPA adequacy and residual risk assessment.

06

Ongoing Monitoring

Annual or periodic reassessment scheduling based on supplier risk rating. Change notification review. Integration into your organisation's approved supplier list management system.

Typical Deliverables

Supplier Risk Classification Matrix
Supplier Audit Report with Risk-Rated Findings (Critical / Major / Minor)
CAPA Response Review and Assessment
Supplier Approval Recommendation
Quality Agreement Gap Analysis and Revised Draft
Approved Supplier List Framework Documentation
Annual Reassessment Programme Design

Frequently Asked Questions

How frequently should critical suppliers be audited?

There is no single regulatory requirement specifying audit frequency, but risk-based practice expects critical suppliers — particularly API manufacturers and CDMOs — to be audited at least once every two to three years, with more frequent assessment following significant changes to their operations, regulatory status or quality performance. EU GMP Chapter 7 requires that outsourced activities are assessed by the contract giver. FDA CGMP expectations are broadly consistent. Supplier audit frequency should be documented in your quality management system and should reflect each supplier's risk classification and performance history.

Can supplier qualification audits be conducted remotely?

Remote audit formats are viable for document-intensive assessments — quality agreement reviews, quality system document evaluations and desktop assessments for lower-risk suppliers. For critical GxP suppliers, particularly API manufacturers and CDMOs, on-site audit is recommended as it enables facility inspection, observation of operations and personnel interviews that remote assessment cannot replicate. Regulatory authorities have noted that remote audit programmes should not replace on-site qualification of critical suppliers.

What should a quality agreement with a CDMO contain?

A quality agreement with a CDMO must define the responsibilities of each party for GMP compliance in relation to the specific products and processes involved. Essential elements include: scope of the agreement, responsibilities for manufacturing, quality control, change control, deviations and CAPA, batch release, complaint handling, recall procedures, regulatory inspection obligations, right-to-audit provisions, notification obligations for changes and the review and renewal process. Generic quality agreements that do not address product-specific arrangements are a consistent inspection finding.

How do we maintain an approved supplier list efficiently for a large supply chain?

An effective approved supplier list management system combines risk-based classification (determining which suppliers require audit versus questionnaire versus certificate review), a scheduled reassessment programme aligned to supplier risk ratings, change notification integration (automatic review triggers when suppliers notify significant changes), performance monitoring (quality complaints, deviations, OOS results linked to supplier origin) and documented approval decision records for each supplier.

Discuss Your Supplier Qualification Programme

Contact our team to discuss your supplier base, qualification requirements and ongoing monitoring programme design.