[ OPERATING INTERSECTION ]
Supplier work, shared controls, retained accountability
How delegated work, privileged access, evidence, and incidents cross organizational boundaries.
What this page does not claim
SPEQ synthesis for education. Confirm applicable law, current guidance, standards editions, contractual duties, and organization-specific controls before making a regulated decision.
The seam below, its failure modes and its decision boundaries are SPEQ’s practitioner framing — not a regulatory requirement, and not an assessment of any organization.
OPERATING QUESTION
Does the operating model identify who performs, informs, investigates, approves, and escalates?
Capabilities in the same decision
Why this is hard
A supplier is judged against the contract; the buying organization is judged against the outcome — and the contract is only a proxy for that outcome, written before either party knew what would actually go wrong. The seam lives in that gap. An obligation can be discharged completely and transfer nothing usable: the supplier reports inside the agreed window that a deviation occurred in a manufacturing area, which satisfies the clause, closes the item on their side, and leaves the receiving quality unit unable to say whether any of its own lots are affected. Neither party has failed. The asymmetry is that the party holding the operational detail has no obligation to volunteer what it was not asked for, and the party carrying the answerability does not know enough to ask. Two further imbalances compound it. Answerability runs the length of the chain while visibility stops at the one contract you signed, so second-tier arrangements rest on a flow-down clause that has been asserted and never exercised. And the commercial relationship quietly confers operational power: a support engineer with standing remote access can change a live configuration in an afternoon, under an agreement your quality system never read.
How it fails
Each of these happens with every function doing its own job correctly. That is what makes them seam failures rather than performance problems.
The notification arrives without the information
The agreement specifies a window, so the supplier reports inside it, in the vocabulary of its own quality system and at whatever level of detail its own investigation has reached. What is missing is the linkage the customer needs: which batches, which materials, which of our shipments. A clock is now running on an investigation that cannot start, and on the supplier’s side the obligation reads as met, which turns the follow-up into a request for a favour rather than the exercise of a right.
Vendor support changes the system outside change control
A remote session resolves a fault by adjusting a setting, which is exactly what the support agreement was bought to do. The customer’s change process never saw it, because that process begins with a customer’s request, and the qualified configuration description now no longer matches what is installed. It surfaces when behaviour differs from a sister system, or when someone compares live settings against the approved ones for the first time in two years.
Qualification is frozen between audits
An audit two years ago found a capable organization and nothing has formally changed since. Meanwhile a process step moved to a second site, the key technical person left, a subcontractor was replaced and a raw material was resourced — each within the supplier’s own rules, none matching the agreement’s definition of a notifiable change. The status stays green because it records a week of observation rather than a continuing judgement about a moving organization.
Flow-down is a clause nobody has exercised
The customer’s obligations reach the supplier, and the supplier’s own contract passes equivalent words further down. Nobody has ever asked the second tier to demonstrate a single one of them, so the first test of the arrangement is an incident — at which point it emerges that the sub-tier reads the clause differently, holds different records, or was never told which of its customers the requirement originated with.
What good looks like
Obligations are written as the questions they exist to answer. Instead of a bare reporting window, the agreement states the determination the buying organization must be able to make and by when — whether our material is affected, whether our data was exposed — and the required content of a notification follows from that rather than the other way round. The list of changes requiring notice is drafted from the customer’s risk but expressed in the supplier’s operational vocabulary, because the person who has to recognise a notifiable event works in the supplier’s plant and reads the supplier’s words. Both sides name an individual authorised to speak, not a mailbox. Privileged remote access is requested, time-bounded, logged and reconciled against the change history on a routine cycle, so a support session becomes an input to change control instead of an exception to it. Between audits the relationship is watched through signals that move — rejection and complaint rates, delivery performance, turnover of key staff, sub-tier substitutions — and at least one plausible scenario has been walked through jointly before it was needed, which is the only dependable way to find the clause each side reads differently.
Who decides what
Disposition, release and the decision to place product on the market stay with the regulated organization however much of the work was performed elsewhere; that line does not move. The supplier owns execution, and owns a second duty distinct from performing well: handing back a complete account of what it did, including what went imperfectly. Two authorities cause most disputes at this seam and should be settled before any work starts. The first is who judges whether a change at the supplier is notifiable — in practice the supplier’s staff apply the criteria, so the criteria have to be written where they will be read, and the buyer retains a right to hear about anything ambiguous rather than only about anything listed. The second is who decides when an event inside the supplier becomes the buyer’s own investigation, because waiting for the supplier’s root cause to close before assessing product impact is the most common way a field action becomes late. Granting standing privileged access is a third, and it should not sit with the person who owns the delivery date.
Questions practitioners ask
Can a regulated company delegate a quality decision?
It can delegate the activity and the technical judgement inside it, and it keeps the decision that the outcome is acceptable for its own product and patients. A workable test is whether the conclusion would still be defensible had the supplier reasoned differently: where the answer rests entirely on trusting the supplier’s judgement, the decision has moved rather than the work.
Does an audit establish that a supplier is capable?
It establishes what was observable during the days it ran, against the scope it covered. Capability between audits is held up by signals that change — performance data, notified changes, movement of key people, sub-tier arrangements — not by the memory of the last visit. An audit programme with no monitoring between visits yields a status that is accurate on two weeks in three years.
What do most quality agreements leave out?
The determination the buyer must be able to make. Agreements commonly specify who tells whom within how many days and omit what the recipient has to be able to conclude, so both parties can comply exactly and still be unable to answer the question the notification existed to serve. Writing the conclusion first makes the required content obvious.
Who investigates when the problem happened at the supplier?
Both, with different scopes and on different clocks. The supplier owns root cause within its own process; the buyer owns the impact on its product, its records and its patients, and that assessment cannot wait for the supplier’s investigation to close. Running them in sequence rather than in parallel is what turns a contained event into a late one.
Critical handoffs
- The regulated company defines the outcome and oversight.
- The supplier performs agreed activities and preserves evidence.
- Both parties execute notification, investigation, change, and continuity obligations.
Shared evidence
- Supplier risk and qualification
- Contract and quality/security responsibility map
- Performance, change, incident, and review records