GxP audit - QFINITY
QFINITY · Service · Audit & Supplier Evaluation

GxP audit & supplier evaluation - confidence through independent assessment.

An audit shows you what you can build on - and turns your supplier's documentation into part of your chain of evidence instead of a second pile of work. Every supplier gets evaluated - how deeply is a question of risk: for a standard system, a reasoned evaluation without an audit can suffice; for a critical partner, an auditor is on site for up to a week.

What is an audit?

Trust on a foundation that holds.

In qualification and validation, you rely on your suppliers' activities and documents. For that trust to bear weight, three things must be in place - if one is missing, the result does not stand.

Objective evidence

Substantiated facts instead of self-declaration. What no one can show does not count.

Documented

Verifiable rather than remembered - still standing in the inspection two years from now.

Audit criteria

The criteria are set in advance. Measure only afterwards and you are measuring yourself.

An audit serves to build trust. It creates the basis on which you can trust your supplier's work - initially at selection, continuously in operation. When that trust rests on documented evidence, the supplier's documentation becomes part of your chain of evidence, rather than the full documentation having to be created from scratch. With demonstrably good suppliers, that lowers your effort - not because less is demonstrated, but because the evidence that already exists may be used. Annex 11 names supplier competence and reliability as key factors in selection - and makes the need for an audit dependent on a risk assessment.

GxP Audit Supplier Audit On-Site Audit Remote Audit Postal Audit GMP
Systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled.Per ISO 19011
Procedure

Whose procedure do we audit by?

The regulations say that you audit. How an audit is to run, they leave almost entirely open - someone has to bring the procedure. There are three legitimate answers, and you decide which one applies:

By our procedure

Our audit SOP - based on ISO 19011, applicable to management systems in GMP, GCP and GLP environments as much as to IT systems in GxP processes. It brings an audit agenda and a report template. The default when you have no procedure of your own - or would rather not commit yours.

By your procedure

You set your SOP, we audit to it - your process, your templates, your grading logic. Our SOP steps in only where yours leaves a point uncovered. The report fits into your QM system without a seam.

We create your procedure

You do not have one yet - for a single audit or a full audit program? We create your SOP or your audit program.

Audit process

Six phases from initiation to follow-up.

Every phase produces traceable audit evidence. The sequence holds regardless of audit mode - postal, remote or on site:

  1. 1

    Initiation

    Appointing the audit team, establishing contact with the auditee - and checking feasibility: a fresh acquisition, key people who have left, or an ongoing authority inspection can render an audit worthless. Then it gets postponed, not pushed through.

  2. 2

    Preparation

    Assessing the process and system landscape - via an SOP list and a system inventory, for instance - not to determine conformity, but to size scope and effort. This produces the audit agenda (to be approved by the client) and the working documents: checklists, sampling plan, document log.

  3. 3

    Execution

    Opening meeting, interviews, document review, observation on site. Only verifiable information is accepted as audit evidence. At the opening meeting we expect executive management - able to speak for the whole company, not just for one department.

  4. 4

    Deficiencies & grading

    Evidence is evaluated against the audit criteria and graded: critical, major, other. There is no obligation to grade - we grade anyway, and in the very scheme an inspector would apply to your deficiencies: derived from the German GCP inspectorates' procedure for GCP inspection reports (ZLG) and the Community format of the EU GMP inspection report. Diverging views are resolved before the report, not carried into it.

  5. 5

    Report & closure

    The report records the extent to which the criteria are met - evidenced, graded, traceable. Plus the auditee's response and, on request, an audit certificate.

  6. 6

    CAPA & follow-up

    Deriving corrective and preventive actions, tracking their effectiveness, scheduling a follow-up audit where needed - so a deficiency becomes a closed loop, not a line in the next inspection report.

Who audits

An audit is only as good as the person leading it.

ISO 19011 devotes an entire chapter to auditor competence for good reason: subject-matter knowledge alone does not make an auditor. What else matters is set down in our process:

At least six years in the GxP field - before the first audit
Documented training in quality assurance
Questioning technique and report craft - neither is learned on the side
Steadfast, even when the result is uncomfortable

Continuing education is demonstrated, not claimed: we train internally, mentor along the way and send our auditors to external courses - and we keep their CVs current, so you can see who is auditing you.

What we audit

From mock audits to AI providers.

We have led more than one hundred audits - from mock audits to AI providers. Every supplier gets evaluated - not every one gets audited. The evaluation is the chain; the audit is one link in it. For a widely used, low-risk standard system, market information and the procurement answers (RfI/RfP) can suffice, recorded in an evaluation document with a reasoned decision. If that falls short, the format escalates: postal, remote, on site. IT supplier audits in the GxP environment goes deeper on IT and software suppliers.

  • Mock Audit

    The inspection before the inspection - inspection readiness ahead of FDA and EMA.

  • Friendly Audit

    Being audited is a skill - and skills can be practiced. In a friendly audit we coach your people instead of grading them, while mistakes still cost nothing.

  • Internal quality audit

    Your audit program, our auditors. An internal audit stays internal even when we lead it - ISO calls it a first-party audit: conducted by the organization itself, or on its behalf.

  • Supplier audit

    Assessing software providers and service providers - before engagement and during operation.

  • Hosting partners (IaaS/PaaS)

    Data center and platform operators your GxP systems run on - including the sub-suppliers behind them.

  • Private cloud providers

    Large software vendors that run their own hosting in a private cloud - application and operation in one hand, one audit. The cloud provider of a manufacturing execution system (MES), for example.

  • AI providers

    Providers with embedded AI - model documentation, data segregation, drift monitoring, sub-providers.

  • Follow-up audit

    Repeat audits of partners already audited - tracking actions over time.

AI suppliers

Certificates are necessary. They are not sufficient.

Certificates and attestation reports show what was assessed - a SOC 2 report, for instance, covers security, change and access controls. For infrastructure that may suffice; the GxP-specific evidence for an application - specification, verification, operation - lies outside its criteria, and the responsibility stays with you. We know first-hand which gaps remain: at the ISPE AI in Life Sciences Summit 2026 in Boston, QFINITY led the workshop on working with AI providers, where regulated companies and providers jointly rated the typical gaps - dealbreaker, fixable, or acceptable risk. Four of them stay invisible until someone asks to see the evidence:

1
Documentation
No model card.
Intended Use, performance behavior, training data scope, known limitations - none of it documented. That removes the basis for your validation strategy and the reference point for assessing changes.
2
Process
The model provider was never evaluated.
The provider behind the provider - the operator of the cloud-hosted language model - appears in no supplier evaluation. Your audit scope does not end with your contract partner. It reaches as far as your data flows.
3
Process
Model changes without notice.
A new model version, adjusted query logic - no lead time, no notification. In a GxP environment, that is an unapproved change to a validated system. Your system's validated status no longer holds - and you do not know it.
4
Data & contracts
No audit right in the contract.
Without an explicit clause, the provider may refuse any audit request - lawfully. Your duty to oversee your suppliers remains regardless. The right belongs in the contract, even if you rarely exercise it.
More services from QFINITY

Audits work best in concert.

Catch the deficiencies before the inspector does.

We set up your audit - as a single audit or a program, by your procedure or ours. In an initial call we clarify scope, audit criteria and mode: postal, remote or on site.

Book an intro call