Supplier Qualification
Supplier Qualification Audits
Risk-based qualification programmes for API suppliers, CDMOs, packaging manufacturers, CROs, IT vendors and logistics providers, delivering independent assurance that your supply chain meets regulatory expectations.
Executive Overview
Pharmaceutical and medical device manufacturers are responsible for the quality of the products they release to market, regardless of how much of the manufacturing, testing and distribution chain is outsourced. EU GMP Chapter 7 (Outsourced Activities) and FDA CGMP regulations establish clear expectations: the contract giver must verify GMP compliance of contract acceptors through qualification and periodic audit.
Supplier qualification is one of the highest-risk areas in pharmaceutical quality management. Supply chain complexity continues to increase, API manufacturing is concentrated in a small number of countries, CDMOs handle multiple product lines simultaneously and packaging supply chains span multiple jurisdictions. Each link in this chain presents quality risks that contract givers cannot reliably assess without independent audit.
Sthira Assure supplier qualification audits follow a structured, risk-based methodology. We begin with risk classification of your supplier base, prioritise audit scope and frequency based on supply chain criticality and regulatory exposure, and conduct audits against the specific regulatory requirements applicable to each supplier category. Our reports provide the evidence base your quality system needs to support approved supplier list decisions.
Supplier Categories
API Suppliers
ICH Q7, EU GMP Part II, FDA 21 CFR 211.84
Excipient Manufacturers
IPEC-PQG GMP, ICH Q7 principles
Packaging Suppliers
PS9000 standards, EU GMP Chapter 5
CDMOs
EU GMP Chapter 7, ICH Q10, FDA CGMP
CROs
ICH E6(R2), 21 CFR Parts 312, 320
IT Vendors & SaaS Suppliers
FDA 21 CFR Part 11, EU Annex 11, GAMP 5
Wholesale Distributors
EU GDP Guidelines, MHRA GDP Guidance
Laboratory Services
OECD GLP, ISO 17025, ICH Q2(R1)
Qualify Your Supply Chain
Discuss your supplier base and qualification programme requirements.
Get in TouchCommon Compliance Risks
Insufficient Initial Qualification
Many organisations approve suppliers based on questionnaire responses, certificates of analysis or regulatory filing history rather than independent on-site assessment. This approach systematically overestimates supplier GMP compliance and leaves significant quality risks unidentified until a product failure, recall or inspection observation forces a review.
Inadequate Quality Agreements
Quality agreements must reflect the actual allocation of quality responsibilities between sponsor and supplier. Inspectors find agreements that are generic, do not address specific products or processes, pre-date current operations and have not been reviewed following changes to supplier arrangements. An inadequate quality agreement is both a regulatory finding and a contractual risk.
No Periodic Reassessment
Supplier qualification is not a one-time event. EU GMP Chapter 7 and FDA expectations require periodic reassessment of critical suppliers based on risk. Organisations frequently lack formal reassessment programmes, rely on supplier-provided self-assessments and fail to audit suppliers following significant changes to their operations, ownership or regulatory status.
Process Change Notification Failures
Suppliers that implement manufacturing process changes, site transfers, material substitutions or personnel changes without notifying customers introduce undetected quality risks. Effective supplier qualification programmes require change notification obligations in quality agreements, backed by audit verification that the supplier's change control system is functioning as specified.
Scope of Services
How We Qualify Suppliers
Supplier Risk Classification
Risk-based classification of suppliers by criticality, regulatory exposure and supply chain position. Determines audit frequency, scope depth and documentation requirements.
Pre-Audit Documentation Review
Review of quality manuals, SOPs, regulatory filing history, previous inspection outcomes, quality agreements and supplier questionnaire responses before the audit visit.
Onsite or Remote Assessment
Structured audit against applicable GxP framework and your organisation's supplier qualification requirements. Facility walkthrough, system assessment, document review and personnel interviews.
Risk-Rated Findings Report
Written audit report with critical, major and minor findings, regulatory references, risk assessment for each finding and recommended CAPA actions. Issued within 10 working days.
CAPA Review and Approval Decision
Review of supplier CAPA responses. Approval, conditional approval or rejection recommendation based on CAPA adequacy and residual risk assessment.
Ongoing Monitoring
Annual or periodic reassessment scheduling based on supplier risk rating. Change notification review. Integration into your organisation's approved supplier list management system.
Typical Deliverables
Frequently Asked Questions
How frequently should critical suppliers be audited?
There is no single regulatory requirement specifying audit frequency, but risk-based practice expects critical suppliers — particularly API manufacturers and CDMOs — to be audited at least once every two to three years, with more frequent assessment following significant changes to their operations, regulatory status or quality performance. EU GMP Chapter 7 requires that outsourced activities are assessed by the contract giver. FDA CGMP expectations are broadly consistent. Supplier audit frequency should be documented in your quality management system and should reflect each supplier's risk classification and performance history.
Can supplier qualification audits be conducted remotely?
Remote audit formats are viable for document-intensive assessments — quality agreement reviews, quality system document evaluations and desktop assessments for lower-risk suppliers. For critical GxP suppliers, particularly API manufacturers and CDMOs, on-site audit is recommended as it enables facility inspection, observation of operations and personnel interviews that remote assessment cannot replicate. Regulatory authorities have noted that remote audit programmes should not replace on-site qualification of critical suppliers.
What should a quality agreement with a CDMO contain?
A quality agreement with a CDMO must define the responsibilities of each party for GMP compliance in relation to the specific products and processes involved. Essential elements include: scope of the agreement, responsibilities for manufacturing, quality control, change control, deviations and CAPA, batch release, complaint handling, recall procedures, regulatory inspection obligations, right-to-audit provisions, notification obligations for changes and the review and renewal process. Generic quality agreements that do not address product-specific arrangements are a consistent inspection finding.
How do we maintain an approved supplier list efficiently for a large supply chain?
An effective approved supplier list management system combines risk-based classification (determining which suppliers require audit versus questionnaire versus certificate review), a scheduled reassessment programme aligned to supplier risk ratings, change notification integration (automatic review triggers when suppliers notify significant changes), performance monitoring (quality complaints, deviations, OOS results linked to supplier origin) and documented approval decision records for each supplier.
Discuss Your Supplier Qualification Programme
Contact our team to discuss your supplier base, qualification requirements and ongoing monitoring programme design.