Supplier qualification and third party audits

You remain accountable for what your suppliers do. Regulators expect a documented, risk based programme that shows why each supplier was approved, how often they are re-assessed, and what happens when performance slips. We build that programme and we perform the audits.

What we provide

Supplier audits

On site and remote audits of API manufacturers, contract manufacturers, laboratories, packaging suppliers and distributors.

Risk based programme

A defensible classification of your supply base, with audit frequencies that follow from the risk rather than from habit.

Quality agreements

Agreements that state who does what, reviewed against what actually happens rather than what was intended.

Who needs qualifying

The obvious ones are active substance manufacturers, excipient suppliers and contract manufacturers. The ones that get missed are usually primary and printed packaging suppliers, contract laboratories, transport and cold chain providers, waste contractors handling regulated material, calibration and maintenance providers, pest control, and increasingly the vendors behind computerised systems that hold GMP data.

A programme that qualifies the API supplier thoroughly and gives the transport provider a one page questionnaire is not risk based. It is simply following the path of least resistance.

Building a defensible programme

The core of it is a documented rationale. For each supplier you should be able to answer four questions without hesitation. What is the criticality of what they provide, and what happens to the patient if it is wrong. What is their regulatory status and inspection history. What is their performance history with you. What level of assessment does that combination justify, and how often.

Once those answers exist, audit frequency stops being an argument. A supplier of a critical starting material with a poor history is audited on site regularly. A supplier of secondary packaging with five clean years may be managed by questionnaire and performance data. Both positions are defensible because the reasoning is written down.

What we usually find

No documented rationale for audit frequency, so the schedule cannot be justified when challenged. Quality agreements that were signed years ago and never revisited, often with a responsibilities matrix that no longer matches how the relationship works. Suppliers who were approved once and never re-qualified. No performance data, so the qualification decision is never revisited between audits. Approved supplier lists that do not agree with what purchasing is actually buying, which is the finding that most alarms an inspector because it means the control is not real.

Audits abroad

A large part of the supply base sits in India and China, and an audit there is only useful if the auditor knows what to look for and how to interpret what they are shown. We perform these audits and we report plainly. If a site is not acceptable we say so, with the evidence, even when that answer is commercially inconvenient. Companies that use audits to confirm a decision already made get findings later from someone who is not on their payroll.

How we work

1. Map the supply base

Everything that touches product, data or storage conditions, including the ones usually forgotten.

2. Risk classify

Criticality, regulatory status and history combined into a written classification per supplier.

3. Assess

Questionnaire, remote or on site audit, matched to the risk classification.

4. Maintain

Quality agreements, performance review and a re-qualification schedule that actually runs.

Common questions

Can you audit suppliers outside Europe?

Yes. We travel for audits across Europe, and to India and China where the supply base requires it. Travel and expenses are quoted separately and in advance.

Do you write the quality agreement?

We draft it and we review the one you already have. The most useful part is usually the responsibilities matrix, because that is where the gaps between two companies become visible.

How often should we re-audit a supplier?

There is no fixed interval in the guidance, which is deliberate. The interval has to follow from your risk assessment. In practice a critical supplier with issues is seen every year, and a low risk supplier with a clean history may go three years with questionnaire and performance monitoring in between.

Can we use a shared or third party audit report?

Sometimes, and it can be a sensible use of budget. You still have to assess whether the scope covered what matters to you, and record that assessment. A purchased report filed without review is not qualification.

We have over a hundred suppliers. Where do we start?

With the classification, not with the audits. Most companies find that a small number of suppliers carry nearly all the risk, and that the programme becomes manageable as soon as that is written down.

Speak with a GMP specialist

If your approved supplier list and your purchasing records do not fully agree, that is the place to start. We can review the programme in a few days.