· INTERSECTION

Supplier Quality × Outsourced Manufacturing

Supplier qualification assumes you can inspect what arrives. A CDMO supplies an operation, not a material — so assurance must reach the quality system that runs it, and accountability never transfers with the work.

All 20 intersections →

What this page does not claim

An intersection covers what happens only where two axes overlap. It does not restate what either parent page says, and it is not a substitute for reading them.

WHAT MEETS HERE

WHAT ONLY EXISTS IN THE OVERLAP

  • You cannot incoming-inspect a manufacturing process. The classic supplier-quality toolkit — specification, certificate of analysis, receipt testing — samples the output of an operation; when the purchased thing is the operation itself, the qualification object becomes the CDMO's quality system, which demands a different kind of evidence entirely.
  • The quality agreement is the load-bearing document of the relationship: a written division of GMP responsibilities between two quality units. Most cross-boundary failures trace to an activity each party assumed the other owned — a gap that exists only because there are two parties.
  • A deviation at a CDMO is investigated in a quality system the customer does not operate, under procedures the customer did not write, with CAPA effectiveness the customer cannot directly observe. Risk-and-CAPA maturity must now work at a distance, through notification thresholds, shared review, and evidence on request.
  • Change control acquires many masters. The CDMO's process improvement touches every client on the line; the client's regulatory commitments constrain a facility it does not run. Neither party's change system was designed for the other's obligations.
  • Release accountability never moves. Whatever the contract says, the batch is certified against the marketing authorisation by the holder's side — in the EU by a Qualified Person relying substantially on another company's records — and regulators treat contract manufacture as the owner's GMP exposure.

A supplier of operations, not materials

Supplier qualification grew up around materials: define a specification, qualify the source, test what arrives, and escalate sampling or scrutiny with demonstrated history. Every control in that toolkit assumes the purchased thing arrives at a dock and can be examined there. A CDMO breaks the assumption. What it supplies is manufacturing itself — people, facilities, utilities, process execution, and the documentation that proves them — and by the time output reaches the customer, the GMP that matters has already happened or already failed. Testing a finished batch samples the result of the operation; it cannot assure the operation, any more than final testing was ever able to test quality into a product.

So the qualification object shifts from the product to the system that produces it. Assessing a CDMO means assessing its quality system in operation: how deviations are actually investigated, whether CAPAs actually prevent recurrence, how changes are actually controlled, what its data-integrity posture actually is, and how it behaves under load — because the customer's batches will be made under that system's habits, good and bad. This is why an audit of a CDMO is a different exercise from an audit of an excipient vendor, and why the ICH Q10 model extends the pharmaceutical quality system explicitly across outsourced activities: the customer's quality system does not end at its own gate. It ends where its product's GMP ends, which is inside someone else's building.

The quality agreement carries the weight

Two companies, two quality units, one batch record — the arrangement functions only if every GMP responsibility has exactly one named owner, and the quality agreement is where that assignment lives. It is not the commercial contract wearing a quality hat; it is a distinct, quality-unit-owned document that divides the regulated activities: who approves specifications and master batch records, who investigates which class of deviation, who must be notified of what and how fast, who approves changes with regulatory impact, who releases the batch, and who faces the regulator when the answer matters. ICH Q7 sets the same expectation for API contract manufacture, where the principle has the longest history.

The characteristic failure is not a badly written clause but an unwritten one. Cross-boundary findings cluster in the activities each party assumed the other owned: environmental excursions the CDMO judged routine and the customer never heard about, a specification interpretation that quietly diverged, stability commitments nobody scheduled, a supplier-of-the-supplier change that reached neither quality unit. The maturity test of the agreement is whether it has been exercised rather than filed — walked through against real scenarios, revised when a gap appeared in practice, and reviewed on a cadence as products, processes, and regulations move. An agreement last touched at signature is a map of the relationship as it was imagined, not as it operates.

Deviations and CAPA across a corporate boundary

When a deviation occurs during contract manufacture, the investigation happens in the CDMO's quality system: its procedures, its root-cause methods, its CAPA machinery, its records. The customer — who owns the product, the filing, and the patient-facing risk — participates from outside. Everything the risk-and-CAPA maturity domain measures inside one company must now operate across two: notification thresholds that bring the customer in early enough to influence the investigation rather than merely receive it; classification criteria aligned in advance, so "minor" means the same thing on both sides of the agreement; and the customer's right to review investigation records and challenge a root cause before the batch decision, written down and used.

CAPA effectiveness is where distance bites hardest. Inside one company, an effectiveness check is a follow-up in your own system; across the boundary, the customer must verify — without operating the system — that the corrective action was implemented and actually works. That takes designed mechanisms: effectiveness evidence delivered, not just promised; recurrence visible in trend data the customer reviews; targeted follow-up in the next audit. There is also a signal only the customer can see. A CDMO's clients each observe a slice of its deviation history, and a root cause that recurs across products is invisible to any single slice — which is why mature customers trend their CDMO's quality events over time and treat "the same investigation, again" as a finding about the quality system, not about the batch.

Change control with many masters

A CDMO's change control serves many clients at once; a client's change control constrains a facility it does not operate. Both directions strain systems designed for one company's obligations. When the CDMO improves a shared utility, replaces an equipment train, or requalifies a cleanroom, the change touches every product on the line — but which client must approve, which must merely be notified, and whose regulatory filings are implicated differs per product and per market. The sorting mechanism is the quality agreement's change categories, and the recurring failure is a change the CDMO sincerely judged invisible to the customer that in fact touched a registered detail — because the CDMO cannot see the filings, only the process.

That blindness is structural, and ICH Q12's vocabulary names the repair: the customer knows its established conditions — the elements of the process that are regulatory commitments — and the CDMO knows the facility. Neither list is useful alone. Mature relationships translate the registered commitments into facility terms the CDMO's change system can screen against, so the flag is raised by construction rather than by luck. The multi-client fact also raises risks no single-company change process ever weighed: a new product introduced onto shared equipment changes the cross-contamination assessment for everyone already there, which is why customers reasonably expect visibility into the facility's product portfolio logic under the risk-based principles of ICH Q9(R1) — and why "who else runs on this line" is a qualification question, not a commercial one.

The decision that never leaves home

However much manufacturing moves, the release decision does not. In the EU model the point is explicit in the architecture: EU GMP Annex 16 places batch certification with a Qualified Person on the authorisation holder's side, who confirms the batch was made in accordance with GMP and the marketing authorisation — largely on the strength of another company's records, audits, and agreements. The US framework reaches the same end through the predicate rules: the quality unit's responsibilities under 21 CFR 211 do not lapse because the operations were contracted, and regulators have long treated contract manufacture through the plain principle that owners and contract facilities are each accountable for the GMP of the work they perform — with the product's owner answerable for the whole.

This is the fact that organises everything upstream. The certifying side must rely on evidence it did not generate, so the whole apparatus of the intersection — system-level qualification, an exercised quality agreement, deviation visibility, CAPA verification at a distance, change screening against registered commitments, and ongoing oversight through audits, data access, and review of quality metrics — exists to make that reliance defensible rather than hopeful. Read this way, oversight cadence is not relationship management; it is the evidentiary basis of a release signature. A customer that cannot show how it knew its CDMO's state of control has no answer to the only question that ultimately gets asked: on what basis did you release this batch?

FREQUENTLY ASKED

Is a CDMO qualified like any other supplier?

The principle is the same — risk-based assurance before reliance — but the object and the evidence differ in kind. A material supplier is qualified around a specification, with certificates of analysis and receipt testing as the ongoing control. A CDMO supplies an operation, and no incoming test can examine an operation after the fact, so qualification means assessing the quality system that will run your product: deviation and CAPA practice, change control, data integrity, facility and cross-contamination controls, and behaviour under pressure. The ongoing control is correspondingly different — audits, quality metrics, deviation visibility, and an exercised quality agreement rather than a sampling plan at the dock.

Who releases the batch when a CDMO manufactures it?

The product's owner side, always — manufacture transfers, certification does not. In the EU, Annex 16 places batch certification with a Qualified Person acting for the marketing-authorisation side, who confirms GMP compliance and conformity with the authorisation, relying on the CDMO's records plus the audits and agreements that make that reliance defensible. In the US, the owner's quality unit retains its responsibilities under 21 CFR 211 regardless of who performed the operations, with the contract facility accountable for the GMP of the work it did. A CDMO may perform testing and issue its own disposition of the work it performed, but the decision that sends product to market stays with the owner.

Whose CAPA system handles a deviation that occurs at the CDMO?

The CDMO investigates in its own system — it owns the procedures, the personnel, and the direct evidence — but the customer cannot treat that as the end of its involvement, because the product risk and the regulatory accountability are the customer's. The workable pattern is defined in the quality agreement: notification thresholds that bring the customer in early for anything meeting agreed criteria, customer review of the investigation and root cause before the batch decision, and CAPA effectiveness demonstrated to the customer with evidence rather than assurance. Significant events typically also open a mirrored record in the customer's own quality system, so its risk assessment, its filings impact, and its own actions are captured where its accountability lives.

How much oversight of a CDMO is enough?

Enough to make the release decision defensible — which is a risk question, not a calendar question. The audit cadence should follow ICH Q9(R1) logic: product risk, process complexity, the CDMO's demonstrated performance, and the maturity of the relationship all move it. But audits alone are a snapshot; the steadier signal comes from standing mechanisms — deviation and change notifications arriving per the quality agreement, periodic review of the CDMO's quality metrics and trends, timely access to batch documentation, and, for critical operations, presence in the facility at meaningful moments. The test to apply: if this batch were challenged, could you show contemporaneous evidence of how you knew the CDMO's state of control, not merely that you had the right to ask?