[ HOW-TO GUIDE ]

How to Conduct Quality & Regulatory Due Diligence

Assess a target’s real compliance exposure before a transaction closes.

What a how-to is not

A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.

Quality and regulatory due diligence evaluates a target company’s or site’s compliance state during a transaction — inspection history, open commitments, data-integrity posture, and remediation needs — so the acquirer understands the exposure and reserves it buys. It is a practitioner assessment, not legal or transaction advice.

THE STEPS
  1. 1

    Scope the assessment and gather records

    Scope the assessment against what is actually being acquired — a site, a product, a marketing authorisation, a pipeline — because the exposure differs sharply between them, and gather the records that show history rather than status. Inspection history and responses, warning letters and their closure, recall records, deviation and CAPA trends, audit reports, and the quality agreements in force. A current clean status tells you less than the trajectory that produced it.

  2. 2

    Assess inspection and enforcement exposure

    Assess inspection and enforcement exposure by reading what the authority actually found and what was committed in response, then testing whether those commitments were kept. Unmet commitments are the highest-value finding in this exercise: they represent both a known deficiency and a demonstrated failure to close one, and they are visible in the records long before they are visible in a subsequent inspection.

  3. 3

    Assess data integrity and quality-system maturity

    Assess data integrity and quality-system maturity together, because the first is usually a symptom of the second. Look for the structural signals rather than for incidents: shared accounts, audit trails never reviewed, investigations resolving to human error, CAPA effectiveness checks that never fail, and a deviation rate implausibly low for the operation’s size. Each is cheap to observe and expensive to remediate.

  4. 4

    Estimate remediation and integration effort

    Estimate the remediation and integration effort in terms the transaction can use — what must be fixed before the asset can operate as intended, what must be fixed before the acquirer’s own quality system can absorb it, and how long each takes. Remediation timelines are usually governed by requalification and revalidation rather than by capital, which is a different and longer clock than commercial models assume.

  5. 5

    Report exposure and what does not transfer

    Report the exposure plainly, and state what does not transfer. Approvals, licences, quality agreements and inspection histories move on their own terms, and some do not move at all; assumptions about continuity are among the most expensive errors in this area. A report that separates verified findings from inferred risk lets the transaction price each correctly.

USE THE TEMPLATE
Quality & Regulatory Due-Diligence Checklist
Skip the blank page — start from SPEQ’s structured, regulator-aligned template for this procedure. Open the template →
COMMON PITFALLS
  • !Relying on the target’s self-assessment rather than inspecting objective evidence.
  • !Overlooking data-integrity posture, which can dwarf other findings.
  • !No estimate of remediation reserves or integration effort.
  • !Assuming all accountability transfers with the asset.

How to Conduct Quality & Regulatory Due Diligence: frequently asked questions

Common questions on conduct quality & regulatory due diligence.

What is quality and regulatory due diligence?

A practitioner assessment of a target company’s or site’s compliance state during a transaction — inspection exposure, open commitments, data-integrity posture, remediation reserves, and quality-system integration effort. It informs the deal; it is not legal or transaction advice.

What is the highest-risk area to assess?

Data integrity and quality-system maturity. A data-integrity failure can undermine the reliability of a target’s entire submission and manufacturing record, turning a routine finding into an existential one — so it deserves particular scrutiny.

What does not transfer in an acquisition?

Regulatory accountability for past conduct does not simply transfer with an asset; the acquirer inherits exposure and remediation obligations but the historical accountability and some liabilities are more complex. Diligence should make this explicit rather than assume a clean transfer.