IT supplier audit - QFINITY
IT Supplier Audits

Qualify suppliers, reduce risk.

A supplier audit makes visible what you would otherwise have to take on trust: how the supplier develops software, how it assures quality, whether it keeps changes under control and whether it will support you in operation. What the supplier can substantiate, you can build on - what it cannot, you have to cover yourself.

Your responsibility does not end at the company boundary. Whatever a supplier contributes must meet GxP requirements too - and the evidence is yours to provide. A risk-based audit program therefore links supplier assessment, audit and inspection support, and the compliant use of cloud services.

GAMP 5 EU GMP Annex 11 Supplier Audit ALCOA++ Critical Thinking Risk-based Data Integrity
If you do not assess a supplier of a GxP-regulated system, you must be able to justify that decision - in documented form. The assessment is not the exception; its absence is.
Assessment Depth

Every supplier is assessed. Not every supplier is audited.

The assessment is the chain - the audit is a link in it, not a synonym. So the starting point is not a questionnaire but a risk decision: which form of assessment this supplier needs. For a widespread, low-risk standard system, market information and what the vendor already discloses in procurement - in the request for information (RfI) and request for proposal (RfP) - can carry the assessment. Then you assess without auditing - and record the outcome and its rationale in an assessment document.

If that foundation does not hold, the form escalates: postal, remote, on site. The FDA's Computer Software Assurance guidance rests on the same logic: evidence depth follows risk.

AspectBaseline assessmentPostal auditRemote auditOn-site audit
Formatmarket information and vendor answers from the RfI/RfP, summarized in an assessment document with rationalequestionnaires, self-assessmentguided review by video and screen sharinginspection at the supplier's site
Risk ratingstandard system, low risklow criticalitymedium criticalityhigh criticality
QA systemindirect, from existing sourcesdocument-basedlive, but remotecomplete, including on-site processes
Developmentno dedicated review - the waiver is justifiedbased on submitted evidencelive spot checksin depth, including SDLC evidence
Typical useestablished standard product without direct patient impactinitial assessment, re-assessmentcritical suppliers without the need to travelhigh-criticality service providers, mock audits
Lifecycle

The qualification and audit life cycle.

Supplier qualification is not a one-off exercise but a documented, risk-based cycle - from defining the processes through to continuous follow-up.

  1. 1

    Define processes & roles

    Set out the qualification processes, including roles and responsibilities, along with the standards for evaluation and ongoing supplier management - covering both regulatory and security requirements.

  2. 2

    Risk-based assessment

    Assess the supplier's quality assurance systems, development processes and support capability. Criticality then determines the depth of the audit (postal, remote or on site).

  3. 3

    Plan & conduct the audit

    Plan, carry out and follow up on the qualification activities - auditing technology suppliers and service providers in whatever form the risk calls for.

  4. 4

    Reuse SDLC evidence

    A robust software development life cycle on the supplier side provides data and documentation that can be reused in subsequent implementation and validation.

  5. 5

    Audit & inspection support

    Define processes for audit and inspection support, and run mock audits to prepare specifically for audits and inspections.

  6. 6

    Continuous management

    Follow up on suppliers and re-assess them periodically, and keep the use of cloud services compliant across the entire life cycle - from the platform (IaaS/PaaS) to the business application delivered as a service (SaaS).

The Benchmark

Working through a checklist does not amount to an assessment.

The GAMP guide on supplier assessment is unusually direct on one point: its sample question sets are expressly meant as orientation only, to be adapted to the supplier at hand - and critical thinking is to be applied before and during the assessment instead of working blindly through a checklist. This is where an audit stands or falls: what counts is not the number of questions, but whether someone understands what the answers mean.

That is why the auditors we put in the room know the system they are assessing - no one is there just to work through a questionnaire.

Our Service

Your IT supplier audit - with targeted support.

Beyond assessment alone, we support the entire qualification and audit cycle - from defining the processes to specialized GxP training. Suppliers can use the same format too: as a preparatory audit before your customers come knocking - for instance against the requirements for electronic records and signatures.

  • Qualification processes

    Defining qualification processes, including roles and responsibilities.

  • Evaluation standards

    Defining standards for evaluating and continuously managing suppliers, covering regulatory and security requirements.

  • Audits at any depth

    Planning, conducting and following up on qualification activities - postal, remote and on-site audits of technology suppliers and service providers.

  • Audit & inspection support

    Defining processes for audit and inspection support throughout supplier management.

  • Mock audits

    Running mock audits to prepare for audits and inspections.

  • Training & cloud services

    Training and support for supplier audits, plus specialized GxP training on the compliant use of cloud services - platform (IaaS/PaaS) and business application (SaaS) alike.

More from our service areas

Audits need the validation framework.

Your risk-based audit program, set up right.

We prioritize your IT suppliers by criticality and set the right audit depth for each one - postal, remote, or on-site. Start with a free intro call (about 30 minutes) where we assess your supplier base and audit needs.

Book an intro call