IT supplier audit - QFINITY
IT Supplier Audits

Qualify suppliers, reduce risk.

A supplier audit makes visible what you would otherwise have to take on trust: how the supplier develops software, how it assures quality, whether it keeps changes under control and whether it will support you in operation. What the supplier can substantiate, you can build on. What it cannot substantiate, you have to cover yourself.

Your responsibility does not end at the company boundary. Whatever a supplier contributes must meet GxP requirements too, and the evidence is yours to provide. A risk-based audit program therefore links supplier assessment, audit and inspection support, and the compliant use of cloud services.

GAMP 5 EU GMP Annex 11 Supplier Audit ALCOA++ Critical Thinking Risk-based Data Integrity
If you do not assess a supplier of a GxP-regulated system, you must be able to produce a documented justification for that decision. The assessment is not the exception; its absence is.
Assessment Depth

Every supplier is assessed. Not every supplier is audited.

The assessment is the chain. The audit is a link in it, not a synonym. So the starting point is not a questionnaire but a risk decision: which form of assessment this supplier needs. For a widespread, low-risk standard system, the assessment can rest on market information and on what the vendor already discloses during procurement, for instance in its responses to the request for information (RfI) and the request for proposal (RfP). In that case you assess without auditing and record the outcome and its rationale in an assessment document.

If that foundation does not hold, the form escalates: postal, remote, on site. The FDA's Computer Software Assurance guidance rests on the same logic: evidence depth follows risk.

AspectBaseline assessmentPostal auditRemote auditOn-site audit
Formatmarket information and vendor answers from the RfI/RfP, summarized in an assessment document with rationalequestionnaires, self-assessmentguided review by video and screen sharinginspection at the supplier's site
Risk ratingstandard system, low risklow criticalitymedium criticalityhigh criticality
QA systemindirect, from existing sourcesdocument-basedlive, but remotecomplete, including on-site processes
Developmentno dedicated review where the waiver is justifiedbased on submitted evidencelive spot checksin depth, including SDLC evidence
Typical useestablished standard product without direct patient impactinitial assessment, re-assessmentcritical suppliers without the need to travelhigh-criticality service providers, mock audits
Life cycle

The qualification and audit life cycle.

Supplier qualification is not a one-off exercise but a documented, risk-based cycle, running from defining the processes through to continuous follow-up.

  1. 1

    Define processes & roles

    Set out the qualification processes, including roles and responsibilities, along with the standards for assessing and continuously managing suppliers, which include regulatory and security requirements.

  2. 2

    Risk-based assessment

    Assess the supplier's quality assurance systems, development processes and support capability. Criticality then determines the depth of the audit (postal, remote or on site).

  3. 3

    Plan & conduct the audit

    Plan, carry out and follow up on the qualification activities, namely audits of technology suppliers and service providers in whatever form the risk calls for.

  4. 4

    Reuse SDLC evidence

    A robust software development life cycle on the supplier side provides data and documentation that can be reused in subsequent implementation and validation.

  5. 5

    Audit & inspection support

    Define processes for audit and inspection support, and run mock audits to prepare specifically for audits and inspections.

  6. 6

    Continuous management

    Follow up on suppliers and re-assess them periodically, and keep the use of cloud services compliant across the entire life cycle, from the platform (IaaS/PaaS) to the business application delivered as a service (SaaS).

The Measure

Working through a checklist does not amount to an assessment.

The GAMP guide on supplier assessment is unusually direct on one point: its sample question sets are expressly meant as guidance only and are to be adapted to the supplier at hand. Critical thinking is to be applied before and during the assessment rather than working through a checklist blindly. This is where an audit stands or falls: what counts is not the number of questions, but whether someone understands what the answers mean.

That is why the auditors we put in the room know the system they assess, instead of just working through a questionnaire.

Our Service

Your IT supplier audit, with targeted support.

Beyond assessment alone, we support the entire qualification and audit cycle, from defining the processes to specialized GxP training. If you are a supplier yourself, you can use the same format too, as a preparatory audit before your customers audit you, for instance against the requirements for electronic records and signatures.

  • Qualification processes

    Defining qualification processes, including roles and responsibilities.

  • Assessment standards

    Defining standards for assessing and continuously managing suppliers, including regulatory and security requirements.

  • Audits at any depth

    Planning, conducting and following up on qualification activities in the form of postal, remote and on-site audits of technology suppliers and service providers.

  • Audit & inspection support

    Defining processes for audit and inspection support throughout supplier management.

  • Mock audits

    Running mock audits to prepare for audits and inspections.

  • Training & cloud services

    Training and support for supplier audits, plus specialized GxP training on the compliant use of cloud services, whether platform (IaaS/PaaS) or business application (SaaS).

More from our service areas

Audits need the validation framework.

Your risk-based audit program, set up right.

We prioritize your IT suppliers by criticality and set the right audit form and depth for each one, whether postal, remote or on site. Start with a free intro call (about 30 minutes) in which we take stock of your supplier base and audit needs.

Book an intro call