01
Supply-network strategy & resilience
The shape of the supply network: design, make-versus-buy, capacity, dual sourcing, where dependency concentrates, scenario analysis and the continuity that follows from all of it.
Resilience is designed years before it is needed, and qualification lead times mean an alternative source cannot be created during a disruption. The organisation supplies from the network it built, not the one it would now choose.
HOW IT FAILS
- Dual sourcing is recorded at supplier level while both suppliers depend on the same upstream manufacturer.
- Alternatives are identified but never qualified, so they are unusable in the window that matters.
- Concentration is assessed by spend rather than by criticality, so a low-value single-source excipient is invisible.
WHAT CONTAINS IT
- Dependency mapping beyond the direct supplier to the manufacturing site and upstream source.
- Qualified — not merely identified — alternatives for critical materials, maintained in a usable state.
- Concentration analysis weighted by criticality and substitutability, not by value.
EVIDENCE IT OPERATES
- Network maps showing upstream dependency and single points of failure.
- Qualification status of alternative sources for critical materials.
- Scenario analyses and the continuity decisions taken from them.
02
Supplier selection, qualification & lifecycle
A supplier from first consideration to exit: requirements, due diligence, approval, onboarding, ongoing monitoring, change notification, requalification and disengagement.
Qualification is a judgement about capability at a moment in time, and suppliers change — new sites, new subcontractors, new owners. Where monitoring is limited to incoming inspection, the organisation is testing product rather than assuring capability.
HOW IT FAILS
- Approval rests on a certificate and a questionnaire, with no assessment of the site that actually manufactures.
- Change notification obligations exist in the agreement and are not monitored, so the first sign of a change is a different result.
- Requalification is calendar-driven and repeats the original assessment rather than examining what has changed.
WHAT CONTAINS IT
- Risk-based qualification depth, with on-site assessment for critical suppliers and materials.
- Active monitoring of change notifications, with absence of notification treated as a signal.
- Requalification scoped by change and performance history rather than by elapsed time.
EVIDENCE IT OPERATES
- Supplier qualification records including site assessment where warranted.
- Change notifications received, assessed and dispositioned.
- Performance monitoring and requalification records with scope rationale.
03
Materials, components & packaging controls
Control of what comes in: specifications, provenance, sampling, testing, status control, traceability, storage conditions and the notification obligations attached to change.
Material attributes propagate directly into product. A specification that omits an attribute the process depends on will be met by material that does not work, and the supplier will be correct in saying it complied.
HOW IT FAILS
- Specifications state compendial limits and omit the functional attributes the process actually needs.
- Provenance is verified to the distributor rather than to the manufacturing origin.
- Reduced testing is adopted on the basis of supplier history without the ongoing verification that justified it.
WHAT CONTAINS IT
- Specifications covering functional and process-relevant attributes, not only compendial compliance.
- Provenance traced to the original manufacturing site, with the supply route documented.
- Reduced testing schemes with defined ongoing verification and a trigger to revert.
EVIDENCE IT OPERATES
- Material specifications with functional attribute rationale.
- Provenance and supply-route documentation for critical materials.
- Incoming testing records including reduced-testing justification and periodic full testing.
04
CDMO, CRO & delegated operations oversight
Oversight of delegated regulated work at CDMOs, CROs and laboratories: responsibility allocation, governance, performance, access, audit, escalation, data and where accountability finally rests.
Regulators hold the contract giver accountable for work performed by the contract acceptor. Oversight that consists of receiving reports satisfies a procedure and not the obligation, because a report describes what the provider chose to disclose.
HOW IT FAILS
- Oversight is exercised through performance metrics the provider generates, with no independent view of underlying quality data.
- The provider subcontracts part of the work and the contract giver learns of it during an inspection.
- Deviations at the provider are dispositioned by the provider, with the contract giver informed after closure.
WHAT CONTAINS IT
- Access to underlying quality data and systems, agreed contractually and actually exercised.
- Subcontracting requiring prior written approval, with the chain visible to the contract giver.
- Deviation and change notification with contract-giver involvement before disposition, not after.
EVIDENCE IT OPERATES
- Oversight plans and records including data reviewed and audits performed.
- Approved subcontractor list with the chain documented.
- Deviation and change notifications with contract-giver assessment.
05
Quality and technical agreements
The document that allocates quality responsibility between two organisations: roles, records, release, deviations, complaints, changes, audit rights, subcontracting and termination.
The quality agreement decides who does what when something goes wrong, written while nothing has. Where it is a template signed by procurement, the ambiguity surfaces during a deviation — the worst possible moment to discover that neither party thought they owned the decision.
HOW IT FAILS
- Responsibilities are allocated to both parties jointly, which in practice means neither acts first.
- The agreement is signed and never reconciled against how the relationship actually operates.
- Termination terms omit record retention and transfer, so data become inaccessible at exit.
WHAT CONTAINS IT
- Single-party allocation for every responsibility, with consultation stated separately from ownership.
- Periodic reconciliation of the agreement against observed practice, with amendment where they differ.
- Termination terms covering record transfer, retention and continued access.
EVIDENCE IT OPERATES
- Executed quality agreements with unambiguous responsibility allocation.
- Periodic review records comparing agreement to practice.
- Termination and record-transfer provisions with evidence of exercise.
06
Procurement, contracting & category management
How supply is bought: requirement definition, sourcing, commercial terms, service levels, risk allocation, ethical standards and the regulated obligations that must survive into the contract.
Procurement decisions create quality obligations that quality did not negotiate. A supplier selected on price with no audit right or change-notification clause has been contracted into a position from which oversight is impossible.
HOW IT FAILS
- Quality requirements are attached after commercial terms are agreed, so leverage to secure them is gone.
- Service levels cover delivery and price with nothing on quality performance or notification.
- Category strategies consolidate spend onto a single supplier without a quality-risk assessment.
WHAT CONTAINS IT
- Quality and regulatory requirements defined before sourcing and carried into the commercial process.
- Contractual audit rights, change notification and quality performance terms as standard, not exceptions.
- Consolidation decisions assessed for supply and quality risk, not only for commercial benefit.
EVIDENCE IT OPERATES
- Sourcing requirements including quality and regulatory criteria.
- Contracts with audit, notification and quality performance terms.
- Category strategy assessments including quality and continuity risk.
07
Warehousing, distribution & cold chain
Moving and holding product: lane qualification, custody, condition monitoring, excursion handling, security, logistics partners, returns and the records across all of it.
Distribution is where a correctly manufactured product is most often degraded, and the conditions are controlled by parties who are not manufacturers. An unmonitored lane is an unqualified process with product in it.
HOW IT FAILS
- Lane qualification covers the expected route and not the delay and diversion scenarios that actually occur.
- Excursion assessment relies on a supplier-provided stability statement rather than on product-specific data.
- Returned product is restocked on the strength of a visual check without knowing its transport history.
WHAT CONTAINS IT
- Lane qualification covering seasonal extremes, delays and diversion, with worst case justified.
- Excursion assessment against product-specific stability data, with a defined decision authority.
- Return acceptance requiring verified custody and condition history, not visual inspection alone.
EVIDENCE IT OPERATES
- Lane qualification protocols and data including worst-case scenarios.
- Temperature monitoring and excursion assessments with disposition.
- Returns records including condition history and acceptance decisions.
08
Trade, import/export, serialization & anti-counterfeit
Legitimacy across borders and the supply chain: licences, customs, chain of ownership, product identifiers, traceability, verification and controls against diversion and counterfeit.
Serialisation exists because falsified medicines reach patients through legitimate supply chains. The controls only work if the data are accurate end to end — a mis-aggregated pallet breaks verification for every pack inside it.
HOW IT FAILS
- Aggregation data are corrected in the system to clear an exception without establishing the physical truth.
- Trade compliance is treated as a logistics matter, so a licence lapse becomes a customs hold with product in transit.
- Verification exceptions at a trading partner are handled as their problem, so a diversion signal never reaches the manufacturer.
WHAT CONTAINS IT
- Aggregation exceptions resolved by physical verification before system correction.
- Licence and trade obligations tracked with expiry and ownership, alongside quality authorisations.
- Partner verification exceptions routed back with defined investigation obligations.
EVIDENCE IT OPERATES
- Serialisation and aggregation records with exception handling.
- Import, export and licence records with validity tracking.
- Verification exception reports and investigations, including partner-reported events.
09
Shortage prevention & business continuity
Preventing and managing supply failure: demand and supply signals, critical material identification, scenarios, allocation, alternatives, regulatory notification and recovery.
Drug shortages are a patient-harm event and increasingly a reportable one. Most trace to a single site or a single upstream supplier — which means they are foreseeable from the network map long before they occur.
HOW IT FAILS
- Criticality is judged commercially, so a low-revenue product with no therapeutic alternative is not treated as critical.
- Notification obligations are met late because the internal signal reached regulatory affairs after the decision.
- Allocation during shortage is made commercially with no documented clinical-need basis.
WHAT CONTAINS IT
- Criticality including therapeutic alternatives and patient impact, not revenue alone.
- Defined internal escalation timed so regulatory notification obligations can be met.
- Allocation principles agreed in advance, documented, and applied consistently under pressure.
EVIDENCE IT OPERATES
- Critical product and material lists with criticality rationale.
- Supply risk assessments, scenarios and mitigation status.
- Shortage notifications, allocation decisions and recovery records.
10
Supplier performance & network intelligence
Watching the network: quality, delivery and capacity performance alongside financial, cyber, geopolitical and sustainability signals — with defined escalation when one moves.
Supplier failures are usually preceded by observable signals in other domains. Financial distress, a cyber incident or a site sale precede quality problems often enough that treating them as separate intelligence loses the warning.
HOW IT FAILS
- Quality, financial and cyber signals are held by different functions and never combined per supplier.
- Scorecards report lagging quality measures with no leading indicator of capability decline.
- Escalation depends on someone noticing, with no threshold that obliges action.
WHAT CONTAINS IT
- A combined supplier view across quality, delivery, financial, cyber and geopolitical signals.
- Leading indicators — staff turnover, audit findings, notification behaviour — alongside lagging quality data.
- Defined escalation thresholds with an obligatory response.
EVIDENCE IT OPERATES
- Supplier scorecards combining signals across domains.
- Escalation records showing thresholds breached and actions taken.
- Risk re-assessments triggered by external intelligence.