
GxP audit & supplier evaluation - confidence through independent assessment.
An audit shows you what you can build on - and turns your supplier's documentation into part of your chain of evidence instead of a second pile of work. Every supplier is evaluated - how deeply is a question of risk: for a standard system, a reasoned evaluation without an audit can suffice; for a critical partner, an auditor is on site for up to a week.
Trust built on a foundation that holds.
In qualification and validation, you rely on your suppliers' activities and documents. For that trust to carry weight, three things must be in place - if one is missing, the result does not stand.
Objective evidence
Substantiated facts instead of self-declaration. What no one can show does not count.
Documented
Verifiable rather than remembered - and still verifiable in an inspection two years from now.
Audit criteria
The criteria are set in advance. Measure only afterwards and you are measuring yourself.
An audit serves to build trust. It creates the basis on which you can trust your supplier's work - initially at selection, continuously in operation. When that trust rests on documented evidence, the supplier's documentation becomes part of your chain of evidence, instead of you having to produce the entire documentation again from scratch. With demonstrably good suppliers, that reduces the work on your side - not because less is demonstrated, but because you may use the evidence that already exists. Annex 11 names supplier competence and reliability as key factors in selection - and ties the need for an audit to a risk assessment.
Whose procedure do we audit by?
The regulations say that you audit. They say next to nothing about how an audit is to run - someone has to bring the procedure. There are three legitimate answers, and you decide which one applies:
Six phases from initiation to follow-up.
Every phase produces traceable audit evidence. The sequence holds regardless of audit mode - postal, remote or on site:
- 1
Initiation
Appointing the audit team, establishing contact with the auditee - and checking feasibility: a recent acquisition, key people who have left, or an ongoing regulatory inspection can render an audit worthless. Then the audit is postponed, not pushed through.
- 2
Preparation
Assessing the process and system landscape - via an SOP list and a system inventory, for instance - not to determine conformity, but to establish scope and effort. This produces the audit agenda (to be approved by the client) and the working documents: checklists, sampling plan, document log.
- 3
Execution
Opening meeting, interviews, document review, observation on site. Only verifiable information is accepted as audit evidence. At the opening meeting we expect executive management - able to speak for the whole company, not just for one department.
- 4
Deficiencies & grading
Evidence is evaluated against the audit criteria and graded: critical, major, other. There is no obligation to grade - we grade anyway, and in the very scheme an inspector would apply to your deficiencies: derived from the German GCP inspectorates' procedural instruction "Inspektionsbericht GCP" (ZLG) and the Community format of the EU GMP inspection report. Diverging views are resolved before the report is written, not carried into it.
- 5
Report & closure
The report records the extent to which the criteria are met - evidenced, graded, traceable. It is accompanied by the auditee's response and, on request, an audit certificate.
- 6
CAPA & follow-up
Deriving corrective and preventive actions, tracking their effectiveness, scheduling a follow-up audit where needed - so a deficiency ends in a closed loop, not a line in the next inspection report.
An audit is only as good as the person leading it.
ISO 19011 devotes an entire chapter to auditor competence for good reason: subject-matter knowledge alone does not make an auditor. What else matters is set down in our process:
Continuing education is demonstrated, not claimed: we train internally, mentor along the way and send our auditors to external courses - and we keep their CVs current, so you can see who is auditing you.
From mock audits to AI providers.
We have led more than one hundred audits - from mock audits to AI providers. Every supplier is evaluated - not every one is audited. The evaluation is the chain; the audit is one link in it. For a widely used, low-risk standard system, market information and the information obtained during procurement (RfI/RfP) can suffice, recorded in an evaluation document with a reasoned decision. If that falls short, the format escalates: postal, remote, on site. IT supplier audits in the GxP environment goes deeper on IT and software suppliers.
Certificates are necessary. They are not sufficient.
Certificates and attestation reports show what was assessed - a SOC 2 report, for instance, covers security, change and access controls. For infrastructure that may suffice; the GxP-specific evidence for an application - specification, verification, operation - lies outside its assessment criteria, and the responsibility stays with you. We know first-hand which gaps remain: at the ISPE AI in Life Sciences Summit 2026 in Boston, QFINITY led the workshop on working with AI providers, where regulated companies and providers jointly rated the typical gaps - dealbreaker, fixable, or acceptable risk. Four of them stay invisible until someone asks to see the evidence:
Audits work in concert.
Close the deficiencies before the inspection arrives.
We set up your audit - as a single audit or a program, by your procedure or ours. In an initial call we clarify scope, audit criteria and mode: postal, remote or on site.
Book an initial call


