How to Qualify a Supplier
Bring a supplier onto the approved list — and keep them worthy of it.
What a how-to is not
A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.
Supplier qualification is how you gain, and maintain, confidence that a supplier consistently meets your quality requirements. It is risk-based: the depth of qualification scales with what the supplier provides and how much it matters to your product. It is also continuous — qualification is a status you maintain, not a box you tick once.
- 1
Define criticality and risk
Classify the supplier by what they provide (an API, an excipient, a service, a component) and its impact on product quality. Criticality sets how much qualification effort is warranted — a critical-material supplier earns an audit; a low-risk one may not.
- 2
Run the initial assessment
Gather documented evidence of the supplier’s quality system — a questionnaire, certifications, regulatory history, and relevant certificates of analysis. This is the desk assessment that precedes any on-site work.
- 3
Audit where the risk warrants it
For critical suppliers, perform an on-site (or justified remote) audit of the quality system against your requirements. The audit is where you verify that the questionnaire answers are real.
- 4
Put a quality agreement in place
Codify responsibilities in a quality agreement — specifications, change notification, deviation escalation, audit rights, and sub-tier controls. Without it, the gap between the two quality systems is undefined.
- 5
Approve and add to the approved supplier list
On satisfactory assessment, formally approve the supplier and add them to the approved supplier list (ASL), with the scope of approval defined (which materials, which sites).
- 6
Monitor and re-qualify
Qualification is ongoing. Monitor performance (defects, deviations, on-time delivery), re-assess on a risk-based cycle, and re-qualify when the supplier changes a process, site, or sub-supplier.
- !Treating qualification as one-and-done instead of a maintained status.
- !Approving a critical supplier on a questionnaire alone, with no audit.
- !No quality agreement — so change notification and escalation are undefined.
- !Ignoring sub-tier suppliers, where the real risk often sits.
How to Qualify a Supplier: frequently asked questions
Common questions on qualify a supplier.
What is the difference between supplier qualification and a supplier audit?
The audit is one activity within qualification. Qualification is the whole process — risk classification, initial assessment, audit where warranted, quality agreement, approval, and ongoing monitoring. An audit alone does not qualify a supplier; it is the evidence-gathering step for critical ones.
Do all suppliers need an on-site audit?
No — qualification is risk-based. Critical-material suppliers typically warrant an on-site (or justified remote) audit; lower-risk suppliers may be qualified on documented assessment and monitoring. The depth of qualification should match the supplier’s impact on product quality.
What is a quality agreement?
A written agreement that defines each party’s quality responsibilities — specifications, change notification, deviation escalation, audit rights, and sub-tier controls. It closes the gap between your quality system and the supplier’s, so nothing falls between them.
How often should suppliers be re-qualified?
On a risk-based cycle, and whenever a triggering change occurs — a new process, site, or sub-supplier, or a decline in performance. Higher-risk suppliers are re-assessed more frequently; the interval should be justified, not arbitrary.