Why Supplier Assessment Is Part of Validation

In GAMP 5, the supplier of a software system is not just a vendor โ€” they are a contributor to the validation evidence. The regulator's logic is straightforward: if a system integrator or software vendor has a mature quality management system and can demonstrate they test their products rigorously, the pharmaceutical company can leverage that work rather than repeat it entirely. Conversely, a supplier with no documented QMS is a risk that must be compensated for with more extensive in-house testing.

This is why EU GMP Annex 11 ยง3 requires supplier assessment before the contract is awarded โ€” not after the system is installed. An assessment completed retrospectively is a finding.

Annex 11 vs Part 11 on Suppliers

EU GMP Annex 11 ยง3 explicitly requires supplier assessment and audit as part of the validation process. 21 CFR Part 11 addresses this less directly โ€” it requires validation of the system, and leveraging a supplier's testing evidence is an accepted approach under CSA. See our Annex 11 vs Part 11 comparison for the full picture.

The Supplier Assessment Questionnaire (SAQ)

The SAQ is a structured questionnaire sent to the supplier before contract award. It covers: Quality Management System certification (ISO 9001, ISO 13485), software development lifecycle methodology, defect tracking and release management processes, test documentation practices, and post-delivery support arrangements.

The SAQ is not an audit โ€” it's a paper assessment. The supplier completes it and provides supporting evidence (ISO certificates, sample procedures). Based on the SAQ response, the pharmaceutical company decides whether a more detailed on-site audit is needed, or whether the paper assessment is sufficient.

The Supplier Assessment Report (SAR)

The SAR documents the outcome of the supplier assessment. It references the SAQ responses, notes any gaps or concerns identified, and draws a conclusion: the supplier's QMS is adequate to support leveraging their testing evidence, or it is not and additional in-house testing will compensate for the gap.

The SAR should be completed and approved before the URS is sent to the supplier for FDS authoring. It informs both the validation scope (what vendor testing evidence will be leveraged) and the contract (what documentation deliverables the supplier must provide).

SUPPLIER ASSESSMENT PROCESS โ€” SEQUENCE AND OUTPUTS STEP 1 Issue SAQ Pre-contract STEP 2 Review SAQ + evidence STEP 3 Audit? If gaps found STEP 4 Issue SAR Approved pre-URS ADEQUATE QMS Leverage vendor test evidence in OQ GAPS FOUND Extended in-house testing required
// THE SAR CONCLUSION DIRECTLY IMPACTS YOUR OQ SCOPE โ€” A STRONG SUPPLIER QMS REDUCES YOUR TESTING BURDEN. DOCUMENT THE LOGIC.

What to Ask in the SAQ

An effective SAQ for a PLC/SCADA system integrator covers:

What "Leveraging Supplier Testing" Actually Means

When the SAR concludes that a supplier's QMS is adequate, the pharmaceutical company can leverage the supplier's test evidence in their own OQ. In practice this means: if the supplier has factory test records showing that a specific function was tested and passed, those records can be referenced as supporting evidence in the OQ rather than requiring a full re-execution from scratch.

The critical condition is that the factory test records must exist, be retrievable, and specifically cover the functions being claimed. "The supplier is ISO certified" is not the same as "the supplier has documented test records for the batch sequencing logic we're leveraging." The SAR should specify exactly which functions are being leveraged and what evidence exists.

In the QLean Framework

The framework includes a Supplier Assessment Questionnaire template (16 structured questions covering QMS, development lifecycle, testing, and support) and a Supplier Assessment Report template with the assessment summary, gap analysis, and conclusion section. The SAR conclusion section explicitly references which OQ functions can leverage supplier evidence and which require independent testing.