A supplier audit is where most quality systems either earn their keep or expose how thin they really are. Anyone can read an SOP and nod. The skill that separates a competent auditor from a clipboard-carrier is the ability to walk onto an unfamiliar site, find the few things that actually matter inside two or three days, prove them with objective evidence, and write findings that hold up when the supplier pushes back and when your own management reads the report six months later.
This page covers the auditor’s fieldwork end to end: what an audit is and why regulators require it, how to plan and scope one, how to run the opening meeting, how to sample and follow evidence, how to grade and write findings, the structure of a defensible audit report, and how to drive the supplier’s corrective actions to closure. It assumes you already know the supplier needs auditing. The decision logic for which suppliers to audit and how often lives in supplier and vendor qualification; read that alongside this.
What a supplier audit is and why it is required
A supplier audit is a planned, independent, documented examination of a supplier’s quality system and operations against a defined standard, to determine whether that supplier can reliably furnish materials or services that meet your requirements. “Independent” means the auditor does not own the supplier relationship or the result. “Documented” means it produces objective evidence and a report. “Against a defined standard” means you are not just forming an impression; you are comparing what you observe to specific GMP requirements, the quality agreement, and the supplier’s own commitments.
The regulatory basis is direct. Under the US cGMP regulations, 21 CFR 211.84 requires that incoming components, containers and closures be examined and tested, and the broader framework of 21 CFR Parts 210 and 211 holds the manufacturer responsible for the quality of materials it uses regardless of where they came from. You cannot delegate accountability to a supplier; you can only delegate the work. ICH Q7 (2000), the API GMP guideline, handles incoming materials in its materials management section, and the expectation it sets there is that you form your own evidenced view of anyone supplying critical material rather than accepting their paperwork at face value. Reading that section directly is worth the ten minutes, because the way it ties the depth of supplier evaluation to how critical the material is, and to how much testing you still do on receipt, is the same proportionality logic that should be driving your audit program. Where a material matters enough, going to look at the supplier is treated as an ordinary part of that evaluation rather than an exceptional escalation. ICH Q10 (2008), the Pharmaceutical Quality System, names management of outsourced activities and purchased materials as a core element and requires the company to verify supplier capability before use and to monitor it over the lifecycle. In the EU, EudraLex Volume 4, Chapter 5 (Production) and Chapter 7 (Outsourced Activities) require qualification and approval of suppliers and a written contract that defines responsibilities. For combination products and any device-constituent operations, the FDA Quality Management System Regulation (21 CFR Part 820, effective 2 February 2026) governs purchasing controls through ISO 13485:2016 Clause 7.4, incorporated by reference (the legacy 21 CFR 820.50 section is now reserved); it requires the manufacturer to evaluate and select suppliers based on their ability to supply product that meets requirements.
The quality rationale underneath the regulation is simpler. Most product defects, recalls and data integrity failures trace back to something that entered the process from outside: a contaminated excipient, a mislabeled component, an API with an undeclared impurity, a contract lab that fabricated a result, a sterilizer that was never properly qualified. You audit because incoming testing alone cannot detect everything (you cannot test quality into a product), and because a certificate of analysis is only as trustworthy as the system that produced it. The audit is how you earn the right to rely on that paper. For the wider context of why outsourcing does not transfer accountability, see CDMO oversight and quality agreements.
Types of audit you should be able to distinguish
| Type | Trigger | Typical depth | Notes |
|---|---|---|---|
| Qualification (initial) | New supplier, before approval | Full system + relevant process | Highest scrutiny; result gates approval |
| Periodic (re-qualification) | Risk-based interval | Focused on changes, prior findings, current performance | Interval set by risk tier |
| For-cause | Quality event, complaint trend, recall, regulatory action at supplier | Targeted at the failure mode | Often unannounced or short-notice |
| Pre-approval / readiness | Ahead of a regulatory filing or technology transfer | Specific process or data package | Ties to quality in technology transfer |
| Remote / desktop | Travel constraint, low risk, document-only scope | Records and responses only | Cannot replace an on-site walkthrough for high-risk suppliers |
Know which one you are doing before you arrive. A for-cause audit that wanders into a general system review wastes the visit and tips off the supplier to sanitize the area you actually came to see.
Planning and scoping the audit
Planning is where audits are won. A weak auditor improvises on site; a strong one arrives with a hypothesis, the right documents pre-read, and an agenda that protects the time for the highest-risk areas.
Define scope and objective first
Write one or two sentences stating exactly what this audit will and will not cover, and why. Vague scope (“audit the supplier”) produces a shallow walk-through. Sharp scope (“evaluate the supplier’s aseptic fill and environmental monitoring program, sterility assurance, and data integrity of the QC microbiology LIMS, to support qualification for sterile drug product”) tells you which records to pull and which SMEs you need in the room.
Set the audit standard explicitly. List the references you will audit against: the applicable CFR parts or EudraLex chapters, ICH Q7 or Q10, the quality agreement, the relevant ISO standard, and any product-specific or compendial requirements. The standard is the ruler you measure with, and it must appear in the report.
Build the audit plan
The audit plan (sometimes called the audit notification or agenda package) is the controlling document. It should contain:
- Supplier name, site address, and the specific activities performed at that site.
- Audit type and objective.
- Scope (in and out).
- Standard / criteria.
- Dates and proposed daily agenda.
- Audit team: lead auditor, co-auditors, technical SMEs, and their roles.
- Areas and processes to be covered, mapped to time blocks.
- Documents requested in advance.
- Logistics: confidentiality, photography policy, escort arrangements, site safety induction.
Send the plan to the supplier far enough ahead that they can make the right people and records available, but resist letting them rewrite your scope. A common manipulation is the supplier proposing an agenda so packed with presentations that no time remains for the floor and the records.
Pre-read before you travel
The pre-read separates an informed auditor from a tourist. Request and review, before the visit:
- The site quality manual and organization chart.
- The site master file or equivalent facility description.
- A list of products/services and the processes used.
- The supplier’s regulatory history (inspection dates, outcomes if shareable).
- Prior audit reports and the status of prior findings.
- Performance data you already hold: complaints, deviations affecting your material, OOS at receipt, on-time-in-full, CoA discrepancies.
- The current quality agreement and any open quality issues against it.
From the pre-read, build a short list of focus questions and a few specific records to trace. If incoming inspection flagged three lots in the last year, you will trace those three lots. If a complaint pointed at a sterilization deviation, you will read that deviation and its CAPA on day one.
Risk-based time allocation
You will never have time to look at everything. Allocate time to the areas where failure would most damage product quality or patient safety. A simple heat-map approach works: rate each process area by impact (effect of a failure on the product) and by likelihood/uncertainty (how much you already trust it). Spend your hours on the high-impact, high-uncertainty cells. For the underlying method, see quality risk management.
Acceptance criteria for a good plan: scope and objective are one paragraph and unambiguous; the standard is named with citations; at least 60 percent of on-site time is reserved for the floor and records rather than presentations; the team has the technical SME the scope demands; and you have three to five specific records or events you intend to trace.
The audit team and roles
Auditing is a team sport even when one person signs the report.
| Role | Responsibility |
|---|---|
| Lead auditor | Owns scope, plan, conduct, findings classification, and the report. Runs the meetings and controls the pace. Makes the call on disputed observations. |
| Co-auditor / technical SME | Brings process depth the lead lacks (microbiology, sterilization, computer systems, analytical). Probes technical detail and confirms findings are technically sound, not just procedural. |
| Auditor in training | Observes, takes notes, does not lead lines of questioning unsupervised. |
| Supplier host / QA contact | Provides records, arranges access, manages the supplier’s people, captures findings on their side. |
| Supplier SMEs | Answer for their areas during interviews and the walkthrough. |
| Supplier management | Attend opening and closing; commit to actions. |
The lead auditor must be qualified and independent: trained in auditing technique, competent in the relevant GMP, and free of any conflict of interest in the result. A purchasing manager auditing a supplier whose contract they negotiated is not independent. Document auditor qualification (training, prior audits, technical background) because regulators and the supplier may both ask “who are you to judge this.”
The opening meeting
The opening meeting sets the tone and the rules. Keep it short, ideally 20 to 40 minutes. Its purpose is alignment, not theater.
Cover, in order:
- Introductions and roles on both sides.
- Purpose and scope restated from the plan. Confirm the supplier understands what you will and will not look at.
- Standard / criteria you are auditing against.
- Agenda and logistics: daily schedule, breaks, escort, access to the floor, access to records and to the people who own them.
- Confidentiality: reaffirm the confidentiality agreement; clarify the photography and copying policy. Many sites prohibit photography; agree how you will capture evidence instead (record IDs, transcribed entries, supplier-provided copies).
- How findings will be handled: that you will share observations as you go (no surprises at the close), the classification scheme you use, and that the closing meeting will summarize them.
- Safety and site rules: gowning, hazards, induction.
Two practical points. First, ask up front for a quiet room with a table, a contact who can fetch records quickly, and printing or screen-sharing for electronic records. Friction in record access is the single biggest time sink. Second, listen during introductions for who is missing. If the QC manager is “off site today” on a for-cause audit about QC data, note it; you may need to escalate or extend.
Common mistake: letting the opening meeting drift into a long corporate slide presentation. Politely cap it. You are not there to receive marketing; you are there to verify.
Conducting the fieldwork: sampling and evidence
This is the core of the job. The audit is built from a sample of evidence because you cannot examine the whole population. The art is choosing a sample that is representative, risk-weighted, and traceable, and then following the evidence wherever it leads.
Three lines of inquiry
A strong auditor triangulates every important point across three sources and looks for where they disagree:
- What the procedure says (the SOP, the master batch record, the protocol).
- What people say happens (interviews on the floor and in QA).
- What the records prove happened (executed records, logbooks, audit trails, raw data).
A gap between any two of these is where findings live. The SOP says samples are pulled in triplicate; the analyst describes pulling one; the logbook shows one. That is a finding, and you found it because you crossed the lines.
Sampling strategy
Decide what you are sampling and how you will pick. Useful approaches:
- Trace-forward: start at an incoming lot and follow it through receipt, testing, release, use. Tests the whole chain.
- Trace-backward: start at a released CoA or a finished result and trace down to the raw data and instrument. Excellent for data integrity, because fabrication usually breaks somewhere in the chain.
- Event-driven: pull the supplier’s deviations, OOS, complaints, change controls and recalls for the period, then sample the most serious and the most recent. This is the fastest route to how the quality system behaves under stress.
- Random within risk strata: within a high-risk process, pick records at random so the supplier cannot pre-select clean examples.
Always pick at least one record you name, not one the supplier offers. “Show me the batch record for lot 24-0417” beats “show me a good batch record.” Pull the most recent example and an older one; pull one associated with a known problem.
Following the audit trail (electronic records)
For any computerized system in scope, the audit trail is the heart of the evidence. Verify that audit trails are enabled, that they capture create/modify/delete with the who/what/when/old-value/new-value, that they cannot be altered by ordinary users, and that someone actually reviews them. Then test it: take a result and look at its audit trail for re-injections, aborted runs, renamed files, changed integration, or processing outside the audit-trailed system. The deep technique is covered in audit trail design and review and, for chromatography specifically, chromatography data system integrity. Ground yourself in ALCOA+ (see ALCOA+ in detail) so you know what “attributable, legible, contemporaneous, original, accurate” looks like in practice.
Interview technique
- Ask open, then narrow. “Walk me through how you release a lot” before “who signs the final disposition.”
- Ask the doer, not just the manager. The operator on the line knows what really happens; the manager knows what the SOP says.
- Stay silent after the answer. People fill silence with detail.
- Never coach or lead. “You do check the temperature, right?” gets you a yes that proves nothing.
- Follow the thread. If an answer surprises you, chase it before moving on. The unplanned thread is often the real finding.
- Be courteous and specific. You are testing the system, not the person. Aggression makes people defensive and stops the flow of evidence.
Record evidence as you go
Every potential finding needs objective evidence captured contemporaneously: the document title and number, version, the specific record ID (batch/lot, instrument, sequence), the date, the exact discrepancy, and the requirement it violates. “Cleaning records were poor” is useless. “Cleaning logbook CL-204, entries dated 12 Mar through 18 Mar 2026, show no recorded verification signature for the second operator required by SOP-CLN-007 rev 4 step 6.2; 9 of 14 entries affected” is a finding. Keep a running log so the closing meeting and report write themselves.
Acceptance criteria for fieldwork: every claimed deficiency is backed by a named record and the specific requirement it breaches; the sample spans high-risk areas and includes auditor-chosen records; and at least one full trace (forward or backward) was completed through the most critical process.
Classifying findings: critical, major, minor
A finding is a documented gap between what you observed and the requirement. Grading the finding drives how the supplier and your own organization respond, so it must be consistent and defensible. The widely used three-tier scheme follows the PIC/S Guidance on Classification of GMP Deficiencies (PI 040-1, in force 1 January 2019) and aligned EU GMP inspection practice. One point of vocabulary is worth getting right, because it is easy to cite the source for something it does not say. PI 040-1 names its three categories Critical, Major and Other, and it treats one-off minor discrepancies as matters raised with the manufacturer as comments rather than as formal deficiencies. Most company audit programmes label that third category “Minor” instead, which is the convention used below, so map your own terms onto the source deliberately rather than assuming they line up. ISO 19011, Guidelines for auditing management systems, covers generic audit management and works in conformity and nonconformity terms rather than the GMP grades. It does not itself define major or minor nonconformity, which come from certification-scheme standards such as ISO/IEC 17021-1, and it leaves the grading convention to the auditing organisation. The current edition is ISO 19011:2026, published May 2026, superseding the 2018 edition, so confirm terminology against the edition you hold. The scheme is:
| Grade | Definition | Typical examples |
|---|---|---|
| Critical | Patient harm is on the table. Either product capable of hurting someone has already been made, or the control failure in front of you makes that outcome realistically reachable. Any indication that records were falsified, back-dated or selectively created belongs here as well, whether or not product was affected, because it removes the basis for trusting anything else the site showed you. | Falsified data, no sterility assurance for sterile product, release of failing material, gross cross-contamination risk. |
| Major | No credible route to patient harm, but the failure is serious on its own terms: product that may not meet what it was registered or contracted to meet, a control that a working GMP system is expected to have and does not, or a group of smaller failures that share one weak parent system and together say that system is not being run. | No CAPA effectiveness checks, untrained operators on a critical step, missing validation for a critical process, systemic documentation gaps. |
| Minor | A real departure from what the standard requires, but isolated, contained, and with no plausible route to product or patient impact. Worth writing down and worth fixing, and not evidence that a system has stopped working. | Isolated documentation error, an SOP overdue for periodic review, a calibration label missing on a non-critical gauge. |
Grade by impact and reach, not by how annoyed you are. The decision sequence: Did it harm or could it harm a patient, or is it fraud? If yes, critical. If not, could it cause out-of-spec product, or is it a systemic breakdown, or several related minors pointing to one weak system? If yes, major. Otherwise minor. The detailed rubric, including how to roll up clusters of minors into a major, is in audit finding classification.
Two disciplines keep classification honest. First, separate the finding (the objective fact) from the grade (your judgment) so the supplier can dispute the grade without disputing the fact. Second, write the requirement reference into every finding; a finding with no cited requirement is just an opinion.
Common mistake patterns regulators and auditors see: inflating every observation to major to look thorough, which destroys credibility; or burying a critical inside a list of minors because the auditor did not want a confrontation. Both are failures of nerve, not technique.
The closing meeting
The closing meeting (exit meeting) presents what you found to supplier management. No surprises rule: every finding here should have been raised on the floor already, so the meeting confirms rather than ambushes.
Run it like this:
- Thank the host, briefly. You will likely audit them again.
- Restate scope and standard so findings are read in context.
- Present findings by grade, most serious first, reading the objective evidence and the requirement for each. Keep it factual.
- Distinguish findings from your overall conclusion. State whether the conclusion is approve, approve with conditions, or do-not-use pending remediation, and that it is preliminary until the report is issued.
- Hear the supplier’s response. If they produce evidence on the spot that refutes a finding, downgrade or withdraw it and note it. If they merely disagree, record their position; do not negotiate a true finding away.
- Set expectations for CAPA: the response timeline, that you want root cause and not just correction, and how follow-up will work.
Hold your ground on critical findings while staying professional. A critical does not become a minor because management is unhappy. Equally, do not invent severity to project authority. The closing meeting is judged later by whether the report matches what was said in the room.
Writing the audit report
The report is the deliverable that outlives the visit. It is read by people who were not there: your management deciding whether to use the supplier, your own regulators during an inspection of your oversight, and the supplier’s team building the CAPA. Write it so a stranger can understand the risk and the basis for your conclusion.
Standard structure
- Header / administrative: supplier name and site, audit dates, type, report number and date, distribution, confidentiality marking.
- Scope and objective: what was and was not covered, and why.
- Standard / criteria: the references audited against, with citations.
- Audit team and supplier attendees.
- Areas and processes covered: with enough detail to show depth (which lines, which systems, which records traced).
- Summary of findings: a table by grade with a one-line statement of each.
- Detailed findings: one entry per finding (see template below).
- Positive observations (optional but useful): genuine strengths, briefly. Balance builds credibility.
- Overall conclusion and recommendation: approve / approve with conditions / not approved, with the rationale tied to the findings.
- CAPA request and timeline: what the supplier must respond to and by when.
- Auditor signature(s) and date.
Finding entry template
Each detailed finding should carry: a finding number, the grade, the objective statement (what was observed, with record IDs and dates), the requirement breached (cited), and the risk/impact in plain terms. Keep the requested action and root cause as the supplier’s job; the report states the gap, not the fix.
Worked example of one finding:
Finding 03 - Major Observation: Environmental monitoring excursions in the Grade A fill zone for the period Jan-Mar 2026 (records EM-EX-2026-014, -019, -027) were closed without an assignable root cause and without an assessment of impact on the batches filled during the affected sessions. Three of three reviewed excursions show “no root cause identified” and no batch-impact statement. Requirement: EudraLex Volume 4, Annex 1 (2022) requires investigation of EM excursions including impact assessment; the supplier’s own SOP-EM-011 rev 6 section 8 requires a documented batch-impact evaluation for any Grade A excursion. Risk/impact: Sterile product may have been released without confirming that contamination control was maintained during filling. Potential patient safety impact. Grade rationale: Systemic failure to assess product impact for the highest-risk classified area; pattern across multiple events.
That single entry shows the discipline: a named record, a cited external requirement and the supplier’s own procedure (so they cannot argue the bar was unfair), a plain-language risk, and an explicit reason for the grade.
Writing standards
- Factual and specific. Every finding traceable to evidence captured on site.
- No new findings. Nothing in the report that was not raised at the closing meeting.
- Plain language for risk. A reader who is not a microbiologist must understand why finding 03 matters.
- Timely. Issue within the period your procedure commits to, commonly 10 to 30 calendar days. A report that lands two months later loses force and memory fades.
- Conclusion that follows from the findings. If you logged a critical, “approved” is indefensible.
For the broader craft, see technical writing for GxP.
Acceptance criteria for the report: a reader who never visited can state the supplier’s main risks and your recommendation; every finding cites a requirement and a record; the conclusion is consistent with the worst finding; and it issued on time.
CAPA, follow-up and closure
The audit is not over when the report ships. The point of finding a problem is to fix it, verify the fix, and confirm it stays fixed.
Requesting and reviewing the supplier’s response
Ask the supplier to respond to each finding with: an immediate correction (containing the problem now), a root cause (why it happened, not just what happened), a corrective action (preventing recurrence of this cause), and where warranted a preventive action and an effectiveness check, each with an owner and due date. This is standard CAPA structure; the discipline behind it is in what is a CAPA and the root cause methods in root cause analysis techniques.
When the responses arrive, evaluate them critically. The two most common weak responses, and how to push back:
- Correction dressed up as corrective action. “We retrained the operator and re-issued the SOP.” Retraining a person does not address why the system allowed the gap, and “retraining” as a standalone CAPA is one of the most frequently criticized responses in inspection findings. Ask what about the process design, supervision, or record allowed it, and what prevents the next person from doing the same.
- Root cause that stops at human error. “Operator failed to record the second signature.” Why? Was the step practical, was the form clear, was the workload survivable? Push past blame to the systemic cause. See human error in deviations.
When the response was drafted with an AI assistant
Supplier CAPA responses are increasingly drafted with help from a language model, and it shows. The tell is a response that is fluent, well structured, uses the right vocabulary, and says nothing specific: a root cause that restates the finding in different words, corrective actions that could apply to any company, and no reference to the supplier’s own procedures, records, or people.
The MHRA Inspectorate published a post on 29 June 2026, “Use of AI for GXP inspection responses: setting standards without stifling innovation,” noting that organisations have submitted AI-generated content to compliance teams following GxP inspections. It is a blog post setting out expectations rather than formal guidance, but the expectations it states are a reasonable bar to hold a supplier to as well. In substance the post asks that anything sent to a regulator be true and checkable against a record, be read and challenged by someone with the technical background to spot an error, carry the name of a person senior enough to be answerable for it, have evidence behind every factual assertion, and address the finding actually raised in its actual regulatory context rather than a generic version of it. Voluntary disclosure of AI use is encouraged rather than required. The post also restates the long-standing position that materially false statements to inspectors are a regulatory offence however they were produced.
Applied to reviewing a supplier response, that translates into a few practical checks:
- Does it name things? Real records, real dates, real procedure numbers, the actual equipment or system. Generic responses cite nothing.
- Does the root cause explain this specific failure? A cause that would equally explain any deviation is not a cause.
- Is there an accountable signatory? A named person with the standing to commit the site, not an unattributed document.
- Does the evidence exist? Ask for the artifacts behind the claims: the revised procedure, the training record, the effectiveness data.
None of this makes AI-assisted drafting a problem in itself. A well-drafted response that is accurate, specific, and owned is a good response regardless of what helped write it. The problem is the opposite case, and it is worth naming in the follow-up: an eloquent response with no verifiable content is a weaker response than a badly written one that names the record and the fix.
Verifying effectiveness
A CAPA is not closed when the action is done; it is closed when the action is verified to work. For a major or critical, require an effectiveness check: a defined metric, a review after enough time and enough events to be meaningful, and evidence that the failure has not recurred. Verifying effectiveness, not just completion, is the discipline covered in CAPA effectiveness verification. For a critical finding you may verify on site at the next audit or via a focused remote review rather than accepting paper alone.
Closing the loop and the audit record
Track every finding to closure in a log (finding, grade, due date, response received, accepted/rejected, effectiveness verified, closed). Do not close the audit while findings are open; keep it open with a documented status. Feed the outcome back into the supplier’s status: a clean re-audit may extend the next interval, while critical findings may shorten it, trigger increased incoming testing, or move the supplier to conditional or disapproved. That feedback loop into approved-supplier status is the connection to supplier and vendor qualification and to your overall internal audit program governance.
Acceptance criteria for closure: each finding has an accepted root cause and corrective action with an owner and date; majors and criticals have effectiveness checks defined; nothing is closed on correction alone; and the result has updated the supplier’s qualification status.
Where to spend the hours, by supplier type
Scope emphasis changes with what the supplier actually does for you. The audit standard and the fieldwork technique stay the same; the areas that earn the most time do not. Use this to sanity-check an agenda before you send it.
| Supplier type | Highest-value areas | Records to trace | Classic weak spot |
|---|---|---|---|
| API or intermediate manufacturer | Process control and change history, impurity profile control, cleaning and cross-contamination, ICH Q7 quality-unit independence | A recent campaign from starting material through release, plus every change to the route or specification since your last audit | Undeclared process or route changes, and changes made without notifying the customer as the agreement requires |
| Excipient or raw-material supplier | Supply-chain traceability and re-labelling, upstream supplier controls, specification and CoA basis | One lot traced back to the original manufacturer, not just the distributor | Distributor presenting itself as manufacturer; CoA transcribed rather than tested |
| Sterile fill-finish CMO | Contamination control strategy, aseptic process simulation, environmental monitoring and excursion handling, sterility assurance, batch disposition | Media fill records, EM excursions with impact assessments, a batch record with its deviations | Excursions closed without assignable cause or batch-impact statement |
| Cell and gene therapy or biologics manufacturer | Starting-material and donor traceability, chain of identity and chain of custody, potency and stability control, comparability after change | One patient or lot traced end to end through identity checkpoints | Chain-of-identity breaks at transfer points; poorly controlled manual steps |
| Contract testing laboratory | Data integrity, audit trails, method validation and transfer, OOS handling, sample chain of custody | A released CoA traced backward to raw instrument data and the audit trail | Re-injections and re-integrations without justification; unreviewed audit trails |
| Packaging and component supplier | Change control on tooling and artwork, labelling accuracy, cleanliness for primary contact, particulate control | Artwork or label change history and reconciliation records | Uncontrolled artwork changes reaching the line |
| Logistics, storage, and distribution | Temperature control and mapping, excursion management, security and traceability | A shipment with its temperature record and any excursion assessment | Excursions accepted with no product impact assessment |
For software and computerized-system suppliers the technique diverges enough that it is treated separately in software supplier assessment and CSA.
When the supplier restricts access
Sooner or later a supplier declines to show you something. Sometimes it is legitimate (another customer’s confidential batch record), sometimes it is a genuine site policy, and sometimes it is the area you most needed to see. How you handle it decides whether your report means anything.
Work through it in this order:
- Ask precisely, and say why. “I need to see the deviation record for the excursion on 14 March because it affected material supplied to us” is harder to refuse than “show me your deviations.”
- Offer a workable alternative. Redaction of other customers’ identifiers, viewing on screen without a copy, a summary extract certified by their QA, or reviewing a sanitized equivalent record. Most legitimate confidentiality objections are satisfied by redaction.
- Check the agreement. The quality agreement and the confidentiality agreement usually already grant audit access rights. Cite the clause rather than argue in the abstract.
- Escalate in the room. Bring the supplier’s QA head or site head in. A refusal that survives escalation is a different fact from a host who simply lacks authority.
- Record the refusal as a fact. Note what was requested, the reason given, who declined, and when. This goes in the report whether or not it becomes a finding.
- Reflect it in scope and conclusion. If you could not examine an area within scope, the report says so as a documented limitation of scope, and the conclusion cannot claim assurance you did not obtain.
A refusal to provide records that the quality agreement entitles you to see is itself a finding, and a serious one, because it goes to the reliability of everything else they showed you. Persistent restriction in a high-risk area is a legitimate basis for withholding approval. The failure mode to avoid is the silent one: quietly dropping the area from the report so the conclusion reads clean.
Deciding the supplier’s status after the audit
The report’s conclusion has to translate into an actual decision about using the supplier, and that decision should follow the evidence rather than the commercial pressure in the room.
The condition that most often goes wrong is “approve with conditions” where the conditions are written and then never tracked. If nobody owns the condition and no date carries it, the supplier is functionally approved outright. Conditions belong in the same tracking system as the findings, with the same closure discipline. See supplier and vendor qualification for how status, tier, and interval interact over the lifecycle.
Remote and hybrid audits: what transfers and what does not
Remote auditing moved from an emergency measure to a standing part of most programs, and the technique is different enough to be worth stating. ISO 19011, the guideline for auditing management systems, addresses audit methods including remote ones; the current edition is ISO 19011:2026, published May 2026, which superseded the withdrawn 2018 edition.
What works well remotely:
- Document and record review. Often better than on site, because you can read at your own pace beforehand and arrive with specific questions.
- Data integrity review of computerized systems. Screen sharing into a live system, with the supplier working through it at your direction, lets you inspect audit trails, user lists, and configuration directly. Insist on driving the query rather than receiving exported screenshots.
- Interviews. One to one video interviews with the people who do the work are effective, provided the supplier does not stack the call with managers.
- Follow-up and CAPA verification. Verifying a documentary corrective action rarely needs travel.
What does not transfer:
- The floor. You cannot smell a solvent, notice a propped-open airlock door, see the state of a gowning room at shift change, or watch how an operator actually handles a component. Live video helps, but it shows you where the camera points.
- Unplanned observation. Most of the best findings come from something you were not looking for. A curated camera tour is the opposite of that.
- Reading the room. Hesitations, deference patterns, and who looks at whom before answering are much harder to read through a screen.
Practical controls that make a remote audit defensible: agree in advance who drives the screen and that the auditor selects the records; require live navigation of systems rather than pre-exported files; ask for the camera to be moved on your instruction during any floor segment; record the technology limitations in the report; and state plainly in the conclusion which areas were assessed remotely. For a high-risk supplier, treat a remote audit as a supplement to, not a replacement for, an on-site visit, and say so in the qualification record.
Common mistakes and real finding patterns
Patterns that weaken audits, drawn from how audits and the inspections of company oversight programs actually go wrong:
- No objective evidence. Findings phrased as opinions (“documentation was sloppy”) with no record ID. They collapse under challenge and are worthless to the CAPA team.
- Accepting the curated sample. Looking only at records the supplier offers. Always name your own, including the messy and the recent.
- Skipping the floor. Auditing from the conference room on paper. The gap between the SOP and the line is where the real findings live.
- Audit trail review only on paper. Confirming the system has audit trails but never opening one. Data integrity findings hide in the trail, not the SOP.
- Grade inflation or deflation. Either erodes credibility. Grade by patient impact and systemic reach.
- No-surprises rule broken. A finding appearing first in the report, never raised on site. The supplier rightly objects, and trust is gone.
- Report that does not match the conclusion. A critical finding and an “approved” recommendation. An inspector reviewing your oversight will seize on it.
- Treating retraining as a CAPA. Accepting “we retrained” closures, which is among the most commonly criticized supplier-oversight weaknesses an inspector finds in a company’s audit files.
- Closing on completion, not effectiveness. Marking CAPA done because the action finished, with no check that the problem stopped recurring.
- Stale reports. Issuing weeks late, after memory and momentum are gone.
- Auditing without a standard. Forming impressions against no defined criteria, so nothing can be objectively a finding.
When your own company is inspected, the regulator does not just look at your suppliers; it looks at your audit program: are your audit reports objective, are findings classified consistently, did you follow up on supplier CAPA, and did supplier status actually change when an audit said it should. A pile of audit reports with no evidence of follow-up is itself a finding against you.
Interview-ready: questions and strong answers
“How would you scope a first-time qualification audit of a sterile API supplier with two days on site?” State scope and objective in one sentence tied to the intended use; name the standard (ICH Q7, Annex 1, the quality agreement); pre-read their regulatory history, prior findings, and your own incoming/complaint data; allocate most of the two days to the floor and records in the highest-risk areas (sterility assurance, EM, data integrity of QC systems); and pre-select three to five specific records to trace. Show that you plan around risk and arrive with a hypothesis.
“You suspect data integrity problems in the QC lab. How do you find them?” Trace backward from a released CoA to the raw data and the instrument audit trail. Look for re-injections, aborted or unsaved runs, renamed or deleted files, manual integration changes, and processing timestamps that do not line up with the logbook. Cross-check the SOP, the analyst’s account, and the audit trail; integrity failures show up as a break between the three. Reference ALCOA+ and confirm audit-trail review is actually performed, not just enabled.
“What is the difference between a major and a critical finding?” The dividing line is patient harm. I put a finding in the critical band when the failure has already produced, or could realistically produce, product capable of hurting someone, and I put anything touching falsified or manipulated records there too, because that undermines every other piece of evidence the site handed me. Major is where there is no credible harm route but the failure still matters on its own: product that may not meet what it was registered to meet, a control the GMP system is expected to have and does not, or several smaller gaps that all trace back to one system nobody is actually running. Past the definitions, I would say that I grade on impact and reach rather than on how thorough I want the report to look, that I cite the requirement in every finding, and that I keep the objective observation separate from the grade in my notes so the supplier can argue about the grade without touching the facts. I would also flag that the classification vocabulary varies between the source documents and individual company programs, so the first move is confirming which scheme the audit is being run under.
“The supplier disputes a finding in the closing meeting. What do you do?” If they present objective evidence that refutes it, downgrade or withdraw and document why. If they merely disagree, record their position and keep the finding. Never negotiate a genuine deficiency away to keep the room comfortable, and never let a critical be talked down. The report must match what you can prove, not what keeps the relationship smooth.
“The supplier’s CAPA says ‘operator retrained, SOP re-issued.’ Acceptable?” Not on its own. That is a correction, not a corrective action, and retraining as a standalone fix is one of the most criticized responses in inspections. Push for the systemic root cause (process design, supervision, record usability) and a corrective action that prevents recurrence regardless of which person does the task, plus an effectiveness check for a major or critical.
“How do you decide audit frequency for a supplier?” Risk-based: criticality of what they supply, their quality and compliance history, complexity of the process, regulatory standing, and recent audit results. Higher risk and worse history mean shorter intervals and more on-site time; a clean record with low-impact material can move to periodic remote review. Tie the decision to your supplier qualification SOP and document the rationale.
“When would you do an unannounced or for-cause audit?” For-cause when a quality event, complaint trend, recall, or regulatory action at the supplier signals a specific failure mode; scope it tightly to that failure rather than a general review. Short-notice or unannounced when announcing it would let the supplier sanitize the very area you came to examine, subject to the access rights in your quality agreement.
Practical tips
- Carry your own list of records to pull. The supplier’s curated examples are always clean.
- Capture evidence the moment you see it, with full identifiers. You will not reconstruct it accurately that evening.
- Triangulate every important point: SOP, person, record. The disagreement is the finding.
- Open at least one audit trail per system in scope. Never review data integrity on paper alone.
- Raise findings on the floor as you go, so the closing meeting holds no surprises.
- Keep the objective finding and your grade separate in your notes; it makes the report and any dispute cleaner.
- Cite the supplier’s own SOP alongside the regulation in a finding; it removes the “your bar was unfair” argument.
- Write the report within days, not weeks. Force fades fast.
- Chase CAPA to effectiveness, not completion, and let the result actually move the supplier’s status.
Related reading
- Supplier and vendor qualification - the decision logic for which suppliers to audit and how to manage approved-supplier status.
- CDMO oversight and quality agreements - written agreements and ongoing oversight of contract manufacturers.
- Audit finding classification - the detailed rubric for grading critical, major and minor.
- What is a CAPA and CAPA effectiveness verification - driving and closing the supplier’s corrective actions.
- Root cause analysis techniques and human error in deviations - testing the quality of a supplier’s root cause.
- Audit trail design and review and ALCOA+ in detail - the data integrity evidence at the heart of fieldwork.
- Internal audit program and software supplier assessment CSA - related audit governance and the variant for software vendors.