
GxP audit & supplier evaluation - confidence through independent assessment.
An audit shows you what you can build on - and turns your supplier's documentation into part of your chain of evidence instead of a second pile of work. Every supplier gets evaluated - how deeply is a question of risk: for a standard system, a reasoned evaluation without an audit can suffice; for a critical partner, an auditor is on site for up to a week.
Trust on a foundation that holds.
In qualification and validation, you rely on your suppliers' activities and documents. For that trust to bear weight, three things must be in place - if one is missing, the result does not stand.
Objective evidence
Substantiated facts instead of self-declaration. What no one can show does not count.
Documented
Verifiable rather than remembered - still standing in the inspection two years from now.
Audit criteria
The criteria are set in advance. Measure only afterwards and you are measuring yourself.
An audit serves to build trust. It creates the basis on which you can trust your supplier's work - initially at selection, continuously in operation. When that trust rests on documented evidence, the supplier's documentation becomes part of your chain of evidence, rather than the full documentation having to be created from scratch. With demonstrably good suppliers, that lowers your effort - not because less is demonstrated, but because the evidence that already exists may be used. Annex 11 names supplier competence and reliability as key factors in selection - and makes the need for an audit dependent on a risk assessment.
Whose procedure do we audit by?
The regulations say that you audit. How an audit is to run, they leave almost entirely open - someone has to bring the procedure. There are three legitimate answers, and you decide which one applies:
Six phases from initiation to follow-up.
Every phase produces traceable audit evidence. The sequence holds regardless of audit mode - postal, remote or on site:
- 1
Initiation
Appointing the audit team, establishing contact with the auditee - and checking feasibility: a fresh acquisition, key people who have left, or an ongoing authority inspection can render an audit worthless. Then it gets postponed, not pushed through.
- 2
Preparation
Assessing the process and system landscape - via an SOP list and a system inventory, for instance - not to determine conformity, but to size scope and effort. This produces the audit agenda (to be approved by the client) and the working documents: checklists, sampling plan, document log.
- 3
Execution
Opening meeting, interviews, document review, observation on site. Only verifiable information is accepted as audit evidence. At the opening meeting we expect executive management - able to speak for the whole company, not just for one department.
- 4
Deficiencies & grading
Evidence is evaluated against the audit criteria and graded: critical, major, other. There is no obligation to grade - we grade anyway, and in the very scheme an inspector would apply to your deficiencies: derived from the German GCP inspectorates' procedure for GCP inspection reports (ZLG) and the Community format of the EU GMP inspection report. Diverging views are resolved before the report, not carried into it.
- 5
Report & closure
The report records the extent to which the criteria are met - evidenced, graded, traceable. Plus the auditee's response and, on request, an audit certificate.
- 6
CAPA & follow-up
Deriving corrective and preventive actions, tracking their effectiveness, scheduling a follow-up audit where needed - so a deficiency becomes a closed loop, not a line in the next inspection report.
An audit is only as good as the person leading it.
ISO 19011 devotes an entire chapter to auditor competence for good reason: subject-matter knowledge alone does not make an auditor. What else matters is set down in our process:
Continuing education is demonstrated, not claimed: we train internally, mentor along the way and send our auditors to external courses - and we keep their CVs current, so you can see who is auditing you.
From mock audits to AI providers.
We have led more than one hundred audits - from mock audits to AI providers. Every supplier gets evaluated - not every one gets audited. The evaluation is the chain; the audit is one link in it. For a widely used, low-risk standard system, market information and the procurement answers (RfI/RfP) can suffice, recorded in an evaluation document with a reasoned decision. If that falls short, the format escalates: postal, remote, on site. IT supplier audits in the GxP environment goes deeper on IT and software suppliers.
Certificates are necessary. They are not sufficient.
Certificates and attestation reports show what was assessed - a SOC 2 report, for instance, covers security, change and access controls. For infrastructure that may suffice; the GxP-specific evidence for an application - specification, verification, operation - lies outside its criteria, and the responsibility stays with you. We know first-hand which gaps remain: at the ISPE AI in Life Sciences Summit 2026 in Boston, QFINITY led the workshop on working with AI providers, where regulated companies and providers jointly rated the typical gaps - dealbreaker, fixable, or acceptable risk. Four of them stay invisible until someone asks to see the evidence:
Audits work best in concert.
Catch the deficiencies before the inspector does.
We set up your audit - as a single audit or a program, by your procedure or ours. In an initial call we clarify scope, audit criteria and mode: postal, remote or on site.
Book an intro call
