
GxP audit & supplier evaluation - confidence through independent assessment.
An audit shows you what you can build on, and it turns your supplier's documentation into part of your chain of evidence instead of a second pile of work. Every supplier is evaluated. The depth of the assessment depends on the risk: for a standard system, a reasoned evaluation without an audit can suffice, while for a critical partner an auditor is on site for up to a week.
Trust built on verified ground.
A GxP audit is the independent assessment of whether a supplier, a process or a computerized system meets audit criteria defined in advance. The judgment rests on objective evidence. In qualification and validation, you place trust in your suppliers' activities and documents. That trust has three prerequisites. If one is missing, the result does not hold.
Objective evidence
Substantiated facts. A supplier's self-declaration is not evidence.
Documented
Written down, so that the evidence can still be checked in an inspection two years from now.
Audit criteria
The criteria are set in advance. Anyone who sets them only after the audit is measuring their own expectations, not the supplier.
Such trust is needed initially at selection and continuously in operation. When it rests on documented evidence, the supplier's documentation becomes part of your chain of evidence. Instead of recreating that evidence, you reference it, and with demonstrably good suppliers that reduces your effort. The requirement on the evidence does not drop. It is simply not produced twice. EU GMP Annex 11 explicitly ties the need for an audit to a risk assessment.
Whose procedure do we audit against?
As the client, you decide which procedure the audit follows: QFINITY's audit SOP, your own SOP or a procedure we set up for you. The regulations require the evaluation but say little about how an audit itself should run. EU GMP Annex 11 ties supplier selection to the supplier's competence and reliability. ICH Q10 describes the oversight of outsourced activities as a task of the pharmaceutical quality system. The methodology comes from ISO 19011, the international guideline for auditing management systems, current edition 2018. It describes audit principles, the audit program and the conduct of individual audits, but it prescribes no procedure. That gap is closed by the client's procedure. All three procedural routes lead to the same result, a report that identifies deficiencies, substantiates them and assigns them to the audit criteria. The report fits into your quality management system. This is how the three routes differ:
How does a GxP audit work?
A GxP audit runs in six phases: initiation, preparation, execution, grading of deficiencies, report and closure, and follow-up of the actions. The sequence is aligned with ISO 19011 and applies to every audit mode, from a postal audit to an on-site audit. The guideline describes this sequence in outline. Our audit SOP implements this sequence as a binding procedure. Each phase produces traceable audit documents, from the working documents through the audit agenda to the report. Between preparation and execution, you as the client approve the audit agenda; between report and follow-up, the auditee responds. How long an audit takes depends in practice on risk and scope. A postal audit takes hours, an on-site audit up to a week. The outcome is a report listing the deficiencies, graded using the same scheme a regulatory inspector uses. The six phases in detail:
- 1
Initiation
Appointing the audit team, establishing contact with the auditee and checking feasibility. A recent acquisition, key people who have left or an ongoing regulatory inspection can render an audit worthless. In that case we reschedule the audit.
- 2
Preparation
Assessing the process and system landscape, for instance from the SOP list and the system inventory, to establish scope and effort rather than to determine conformity. This yields the audit agenda for your approval as the client and the working documents: checklists, sampling plan and document log.
- 3
Execution
Opening meeting, interviews, document review, observation on site. Only verifiable information is accepted as audit evidence. At the opening meeting we expect executive management, because they can speak for the whole company and not just for one department.
- 4
Deficiencies & grading
We evaluate the evidence against the audit criteria. The deficiencies derived from it are graded: critical, major, other. ISO 19011 does not require grading by severity. We grade nonetheless, using the scheme an inspector uses as well. It is derived from the ZLG procedural instruction "Inspektionsbericht GCP" for the German GCP inspectorates and the Community format of the EU GMP inspection report. We settle any differing views before the report is written.
- 5
Report & closure
The report records which criteria are met and which are not. Every deficiency in it is evidenced and graded. It is accompanied by the auditee's response and, on request, an audit certificate.
- 6
CAPA & follow-up
Deriving corrective and preventive actions, tracking their effectiveness and scheduling a follow-up audit where needed. That way every deficiency is worked through to the end instead of showing up as an open line in the next inspection report.
An audit is only as good as the person leading it.
ISO 19011 devotes an entire chapter to auditor competence: discipline knowledge, audit methodology and personal behavior, demonstrated through education, work experience, auditor training and audit experience. How we ensure this is set down in our process:
We train our auditors internally, mentor them along the way and enroll them in external courses. We keep evidence of that continuing education, and we keep their CVs current, so you can see who is auditing you.
From mock audits to AI providers.
We have conducted more than one hundred audits, at manufacturers, service providers and software vendors. Not every evaluation leads to an audit. Where the risk is low, market information and the responses obtained during procurement (RfI/RfP) are enough. The reasoned decision is recorded in an evaluation document. How we evaluate IT and software suppliers is set out in detail on the page IT supplier audits in the GxP environment.
Certificates are necessary. They are not sufficient.
Certificates and attestation reports show what was assessed. A SOC 2 report, for instance, covers security as well as change and access controls and may suffice for the infrastructure. However, the GxP-specific evidence for an application, covering specification, verification and operation, lies outside the assessment criteria of such a report. The responsibility stays with you. We know first-hand which gaps that leaves. At the ISPE AI in Life Sciences Summit 2026 in Boston, Frank Henrichmann represented QFINITY on the core team of the GAMP workshop on working with AI providers. There, regulated companies and providers jointly rated the typical gaps as a ground for exclusion, as a fixable point or as an acceptable risk. Four of them stay invisible until someone asks to see the evidence:
Last updated:
Audits work in concert.
Avoid deficiencies before the inspection arrives.
We conduct single audits and set up entire audit programs, by your procedure or ours. In an initial call we clarify scope, audit criteria and mode: postal, remote or on site.
Book an initial call


