· THIRD-PARTY OVERSIGHT

Supplier Audit Program

A supplier audit program is the systematic set of activities — audit planning, execution, reporting, and follow-up — an organisation runs to verify, on an ongoing basis, that qualified suppliers of materials, components, or contracted services continue to meet applicable GxP and quality requirements. Initial qualification establishes that a supplier meets requirements at a point in time; the audit program is what confirms that status is actually maintained.

What an explainer is not

A topic explainer is SPEQ’s synthesis of what a practice involves, cited to the standards that govern it. It does not reproduce their text, and it does not determine which of them apply to your product or process.

[ POSITION IN THE FRAMEWORK ]

7 DIMENSIONS · 21 LINKS

Qualification is a photograph and the audit programme is the film: a supplier is approved once and then changes continuously, so the programme exists to detect the drift approval cannot see.

06 · QUALITY MATURITY — SUPPLIER AUDIT PROGRAM, REACTIVE TO ADAPTIVE

L1
Reactive

Suppliers are audited when a problem arises or when a customer asks whether they were.

L2
Defined

A schedule exists on a fixed interval per supplier category, and audits are performed against a standard checklist regardless of what the supplier does.

L3
Controlled

Interval and depth follow the supplier’s criticality and its own performance history, and each audit’s scope is set from what has changed since the last one.

L4
Predictive

Incoming data, complaints and notifications feed the schedule, so a deteriorating supplier is visited sooner rather than on its date.

L5
Adaptive

Oversight is largely continuous — shared data, performance signals, joint improvement — and the on-site audit confirms a picture already held.

SPEQ’s shared five-stage progression, labelled synthesis — not the FDA QMM rating scale. Where does your organization sit? Score your quality system →

07 · REGULATORY & EVIDENCE

GOVERNING STANDARDS · 3

Derived from the 3 standards SPEQ maps to this subject, across 3 regulatory bodies: ICH, PIC/S, ISO.

RECORDS & OBJECTIVE EVIDENCE

  • The audit schedule with the criticality basis for each supplier’s interval and depth
  • Audit reports with scope, findings and the supplier’s response
  • Verification that supplier corrective actions were completed, not merely promised
  • The link between audit outcome and continued approved status
  • The trigger rules by which performance data can bring an audit forward

COMMON INSPECTION FINDINGS

  • A critical supplier on the same interval and checklist as a low-risk one
  • Audits deferred repeatedly with no risk assessment supporting the deferral
  • Supplier corrective actions accepted on the response letter with no verification
  • Poor incoming performance or repeat complaints not reflected in the schedule
  • Approved status retained after an audit whose findings were never closed
EVERY CHIP IS A DOOR · WALK THE FRAMEWORK FROM ANY SUBJECTHow SPEQ maps the framework →

Audit Program vs. One-Time Qualification

Supplier qualification establishes eligibility to use a supplier in the first place, typically through a documented assessment, sometimes including an on-site audit. The audit program is the recurring mechanism — risk-based scheduling, periodic reassessment, for-cause audits triggered by a quality event — that keeps that qualification current rather than treating it as a permanent, unreviewed status.

ICH Q10 frames supplier and contract manufacturer/laboratory management as an explicit element of a functioning pharmaceutical quality system, extending quality oversight beyond the manufacturer’s own four walls to the parties whose materials or services directly affect product quality.

Risk-Based Scheduling

Audit frequency and depth are typically scaled to the criticality of what the supplier provides — a supplier of a critical starting material or a contract manufacturer of finished product generally warrants more frequent and deeper audits than a supplier of low-risk packaging components — consistent with the risk-based principles in ICH Q9(R1).

A supplier’s own performance history (deviation rate, complaint trends, prior audit findings, change notifications) is itself a legitimate risk input into scheduling — a supplier with a clean, stable performance record can often justify a longer audit interval than one with recurring issues, provided that logic is documented and consistently applied.

Conducting the Audit

ISO 19011 provides the generic methodology most supplier audit programs draw on — audit planning against defined criteria, competent and where possible independent auditors, objective evidence gathering, and a documented report with findings graded by criticality. Audits assess not just documentation but observed practice: whether what the supplier’s procedures say happens is actually what happens on the floor.

Remote and paper-based audits have become more common and are broadly accepted for lower-risk suppliers or as a supplement between on-site cycles, but for higher-risk suppliers most quality systems still expect periodic on-site verification, since some things — facility condition, actual practice, equipment state — are difficult to assess remotely with confidence.

From Finding to Continued Qualification

Audit findings feed the same CAPA discipline used for internal deviations: the supplier is expected to investigate, propose corrective action, and demonstrate effectiveness, with the auditing organisation tracking closure rather than treating the audit report as the end of the interaction. SPEQ interpretation: a supplier audit program’s real test is what happens when a critical supplier fails an audit badly — whether the organisation has a genuine disqualification and dual-sourcing pathway, or whether commercial dependency on a single supplier quietly overrides the quality conclusion.

FREQUENTLY ASKED

How often should a critical supplier be re-audited?

There is no single fixed interval mandated across all GxP regulations; frequency is expected to be risk-based, taking into account the criticality of the supplied material or service and the supplier’s own performance history, and the resulting schedule and its rationale should be documented.

Can a supplier questionnaire replace an on-site audit?

For lower-risk suppliers it is often an accepted part of a risk-based program, but for suppliers of critical materials or contracted GxP activities, most quality systems still expect periodic on-site (or at minimum robust remote) verification rather than relying on self-reported questionnaire responses alone.

What happens if a supplier refuses an audit?

Refusal to permit a reasonable audit is itself a significant quality and risk signal, and most quality agreements make audit access a contractual right — an organisation unable to exercise that right typically cannot maintain the supplier’s qualified status on the basis of unverified claims.

PROFESSIONAL · INSPECTION PLAYBOOK · SPEQ SYNTHESIS

The inspection-readiness playbook for this topic

CHECKING ACCESS

Checking your Professional access…