GxP audit - independent assessment of processes, systems and suppliers
QFINITY · Service · Audit & Supplier Evaluation

GxP audit & supplier evaluation - confidence through independent assessment.

An audit shows you what you can build on, and it turns your supplier's documentation into part of your chain of evidence instead of a second pile of work. Every supplier is evaluated. The depth of the assessment depends on the risk: for a standard system, a reasoned evaluation without an audit can suffice, while for a critical partner an auditor is on site for up to a week.

What is an audit?

Trust built on verified ground.

A GxP audit is the independent assessment of whether a supplier, a process or a computerized system meets audit criteria defined in advance. The judgment rests on objective evidence. In qualification and validation, you place trust in your suppliers' activities and documents. That trust has three prerequisites. If one is missing, the result does not hold.

Objective evidence

Substantiated facts. A supplier's self-declaration is not evidence.

Documented

Written down, so that the evidence can still be checked in an inspection two years from now.

Audit criteria

The criteria are set in advance. Anyone who sets them only after the audit is measuring their own expectations, not the supplier.

Such trust is needed initially at selection and continuously in operation. When it rests on documented evidence, the supplier's documentation becomes part of your chain of evidence. Instead of recreating that evidence, you reference it, and with demonstrably good suppliers that reduces your effort. The requirement on the evidence does not drop. It is simply not produced twice. EU GMP Annex 11 explicitly ties the need for an audit to a risk assessment.

GxP Audit Supplier Audit On-Site Audit Remote Audit Postal Audit GMP
Systematic, independent and documented process for obtaining objective evidence and evaluating it objectively to determine the extent to which the audit criteria are fulfilled.Per ISO 19011
Procedure

Whose procedure do we audit against?

As the client, you decide which procedure the audit follows: QFINITY's audit SOP, your own SOP or a procedure we set up for you. The regulations require the evaluation but say little about how an audit itself should run. EU GMP Annex 11 ties supplier selection to the supplier's competence and reliability. ICH Q10 describes the oversight of outsourced activities as a task of the pharmaceutical quality system. The methodology comes from ISO 19011, the international guideline for auditing management systems, current edition 2018. It describes audit principles, the audit program and the conduct of individual audits, but it prescribes no procedure. That gap is closed by the client's procedure. All three procedural routes lead to the same result, a report that identifies deficiencies, substantiates them and assigns them to the audit criteria. The report fits into your quality management system. This is how the three routes differ:

By our procedure

Our audit SOP is based on ISO 19011 and applies to management systems in GMP, GCP and GLP environments as well as to IT systems in GxP processes. It comes with an audit agenda and a report template. This is the default when you have no procedure of your own or prefer not to make yours mandatory for this audit.

By your procedure

You provide your SOP with its process, templates and grading logic. We audit to it. Our SOP only fills the gaps yours leaves. The report follows your report template.

We create your procedure

If you still lack an audit SOP or a full audit program, we create the SOP or the program with you, aligned with your QM system, and then audit against it.

Audit process

How does a GxP audit work?

A GxP audit runs in six phases: initiation, preparation, execution, grading of deficiencies, report and closure, and follow-up of the actions. The sequence is aligned with ISO 19011 and applies to every audit mode, from a postal audit to an on-site audit. The guideline describes this sequence in outline. Our audit SOP implements this sequence as a binding procedure. Each phase produces traceable audit documents, from the working documents through the audit agenda to the report. Between preparation and execution, you as the client approve the audit agenda; between report and follow-up, the auditee responds. How long an audit takes depends in practice on risk and scope. A postal audit takes hours, an on-site audit up to a week. The outcome is a report listing the deficiencies, graded using the same scheme a regulatory inspector uses. The six phases in detail:

  1. 1

    Initiation

    Appointing the audit team, establishing contact with the auditee and checking feasibility. A recent acquisition, key people who have left or an ongoing regulatory inspection can render an audit worthless. In that case we reschedule the audit.

  2. 2

    Preparation

    Assessing the process and system landscape, for instance from the SOP list and the system inventory, to establish scope and effort rather than to determine conformity. This yields the audit agenda for your approval as the client and the working documents: checklists, sampling plan and document log.

  3. 3

    Execution

    Opening meeting, interviews, document review, observation on site. Only verifiable information is accepted as audit evidence. At the opening meeting we expect executive management, because they can speak for the whole company and not just for one department.

  4. 4

    Deficiencies & grading

    We evaluate the evidence against the audit criteria. The deficiencies derived from it are graded: critical, major, other. ISO 19011 does not require grading by severity. We grade nonetheless, using the scheme an inspector uses as well. It is derived from the ZLG procedural instruction "Inspektionsbericht GCP" for the German GCP inspectorates and the Community format of the EU GMP inspection report. We settle any differing views before the report is written.

  5. 5

    Report & closure

    The report records which criteria are met and which are not. Every deficiency in it is evidenced and graded. It is accompanied by the auditee's response and, on request, an audit certificate.

  6. 6

    CAPA & follow-up

    Deriving corrective and preventive actions, tracking their effectiveness and scheduling a follow-up audit where needed. That way every deficiency is worked through to the end instead of showing up as an open line in the next inspection report.

Who audits

An audit is only as good as the person leading it.

ISO 19011 devotes an entire chapter to auditor competence: discipline knowledge, audit methodology and personal behavior, demonstrated through education, work experience, auditor training and audit experience. How we ensure this is set down in our process:

At least six years in the GxP field before the first audit
Documented training in quality assurance
Questioning technique and report writing from training and practice
Standing firm, even when the result is uncomfortable

We train our auditors internally, mentor them along the way and enroll them in external courses. We keep evidence of that continuing education, and we keep their CVs current, so you can see who is auditing you.

What we audit

From mock audits to AI providers.

We have conducted more than one hundred audits, at manufacturers, service providers and software vendors. Not every evaluation leads to an audit. Where the risk is low, market information and the responses obtained during procurement (RfI/RfP) are enough. The reasoned decision is recorded in an evaluation document. How we evaluate IT and software suppliers is set out in detail on the page IT supplier audits in the GxP environment.

  • Mock Audit

    The dress rehearsal for the regulatory inspection, whether by the FDA or a European authority.

  • Friendly Audit

    Handling an audit is a skill that can be practiced. In a friendly audit we coach your team rather than grade its performance, while mistakes still carry no consequences.

  • Internal quality audit

    Your audit program, our auditors. It remains your audit, even when we lead it. ISO 19011 calls it a first-party audit, conducted by the organization itself or on its behalf.

  • Supplier audit

    Assessing software vendors and service providers, before engagement and during operation.

  • Hosting partners (IaaS/PaaS)

    Operators of the data centers and platforms your GxP systems run on, including the sub-suppliers behind them.

  • Private cloud providers

    With large software vendors that run their own hosting in a private cloud, application and operation are in the same hands. One audit covers both, for example at the cloud provider of a manufacturing execution system (MES).

  • AI providers

    Providers whose products contain AI. We assess model documentation, data segregation, drift monitoring and the sub-suppliers behind them.

  • Follow-up audit

    A repeat audit of partners already audited, to track the actions over time.

AI suppliers

Certificates are necessary. They are not sufficient.

Certificates and attestation reports show what was assessed. A SOC 2 report, for instance, covers security as well as change and access controls and may suffice for the infrastructure. However, the GxP-specific evidence for an application, covering specification, verification and operation, lies outside the assessment criteria of such a report. The responsibility stays with you. We know first-hand which gaps that leaves. At the ISPE AI in Life Sciences Summit 2026 in Boston, Frank Henrichmann represented QFINITY on the core team of the GAMP workshop on working with AI providers. There, regulated companies and providers jointly rated the typical gaps as a ground for exclusion, as a fixable point or as an acceptable risk. Four of them stay invisible until someone asks to see the evidence:

1
Documentation
No model card.
Intended Use, performance characteristics, training data scope and known limitations are not documented. That leaves you without the basis for your validation strategy and without the reference point for assessing changes.
2
Process
The model provider was never evaluated.
The provider behind the provider, the operator of the cloud-hosted language model, appears in no supplier evaluation. Your audit scope does not end with the party you contracted with. It reaches as far as your data flows.
3
Process
Model switched without notice.
The provider switches the model version and the query logic without advance notice. In a GxP environment, that is an unapproved change to a validated system. Your system loses its validated state without you noticing.
4
Data & contracts
No audit right in the contract.
Without an explicit clause, the provider can refuse any audit request and remain within the contract. Your duty to oversee your suppliers continues regardless. The right belongs in the contract, even if you rarely exercise it.

Last updated:

More services from QFINITY

Audits work in concert.

Avoid deficiencies before the inspection arrives.

We conduct single audits and set up entire audit programs, by your procedure or ours. In an initial call we clarify scope, audit criteria and mode: postal, remote or on site.

Book an initial call