Skip to main content

Vendor/Supplier
Qualification Assessment FAQ

Direct answers on qualifying GxP suppliers — how assessment rigor should scale with risk, when a questionnaire is enough versus an audit, how to handle a finding or a sub-tier supplier, and what inspectors check when they trace a material or system back to its supplier's qualification record.

Written by: Sundar · Published: August 7, 2026 · Last updated: August 7, 2026
Quick Answer

Can a single questionnaire response be used to qualify a supplier for multiple unrelated products they sell?

No — supplier qualification should be scoped to what's actually being supplied. A questionnaire response covering their quality system for one product line doesn't automatically extend to a different product or service from the same supplier if the manufacturing process, risk profile, or quality controls differ meaningfully between them.

ICH Q9(R1); ICH Q10

Evidence-backed answers

Vendor/Supplier Qualification Assessment FAQs

20 questions covering assessment scope, audits and tiering, findings and requalification, and inspection expectations.

Section 01

What a supplier qualification assessment actually evaluates

How it differs from proposal evaluation, whether every supplier needs one, and who decides how rigorous it should be.

What's the difference between evaluating a vendor's proposal and actually qualifying them as a supplier?

Industry practice Direct link

Evaluating a vendor's proposal checks whether their specific product or service meets a project's stated requirements; supplier qualification is a broader, ongoing assessment of the vendor's own quality management system, manufacturing controls, and track record — confirming they're a reliable, compliant organisation to do business with, not just that one product looks suitable.

A vendor can submit a technically excellent proposal for a specific system while still having an inadequate quality system overall — proposal evaluation and supplier qualification answer different questions and both are needed before committing to a GxP-critical relationship.

Does every supplier need a full qualification assessment, or can some be approved through a simpler process?

Industry practice Direct link

No — the depth of supplier qualification should be risk-based, scaled to the GxP criticality of what the supplier provides; a supplier of a non-critical commodity item can often be approved through a lighter documented review, while a supplier of a GxP-critical material, system, or service warrants a full assessment, potentially including an audit.

Sources

What should a supplier qualification assessment actually look at beyond whether their product meets the URS?

Industry practice Direct link

A supplier qualification assessment should evaluate the supplier's quality management system, change notification practices, regulatory compliance history, financial and operational stability, sub-tier supplier controls, and technical support and escalation capability — factors that determine whether the relationship will remain reliable over the system's operational life, not just whether the initial product meets specification.

  • Quality management system maturity and certifications.
  • Change notification process for their product or service.
  • Regulatory inspection or compliance history, where available.
  • Technical support responsiveness and escalation path.
  • Financial and operational stability as an ongoing business.
  • Sub-tier supplier or subcontractor controls, where relevant.

Does a software vendor need to be qualified differently than a hardware or equipment supplier?

Industry practice Direct link

Yes — a software vendor's qualification assessment should additionally evaluate their software development lifecycle practices, version control and release management, cybersecurity posture, and how they support validation activities such as providing audit-ready documentation, since these factors don't apply in the same way to a hardware or equipment supplier.

Who's responsible for deciding how rigorous a given supplier's assessment needs to be?

QMS-specific Direct link

QA, often in collaboration with the system or material owner, should determine the required rigor of a supplier's qualification assessment, based on a documented risk assessment of what the supplier provides and its GxP impact — this decision shouldn't be left to procurement alone, since cost and delivery considerations can bias toward a lighter assessment than the risk actually warrants.

Sources

Section 02

Audits, questionnaires, and risk-based tiering

When a questionnaire is enough, how to tier suppliers by risk, and whether certifications or remote audits carry the same weight as an on-site assessment.

When is a supplier questionnaire enough, and when do you actually need an on-site audit?

Industry practice Direct link

A documented questionnaire, sometimes supplemented by a review of certifications and public inspection history, is often sufficient for lower-risk suppliers, while an on-site or remote audit is generally warranted for suppliers of GxP-critical systems, materials, or services where the questionnaire responses can't be independently verified with confidence, or where the supplier's compliance history raises concerns.

Sources

How do you tier suppliers by risk, and what determines which tier a supplier falls into?

Industry practice Direct link

Supplier risk tiering is typically based on the GxP criticality of what they provide, the complexity of their product or service, their compliance and quality track record, and how directly their output affects product quality or patient safety — a tier structure lets an organisation apply proportionate assessment rigor rather than treating every supplier identically.

  • GxP criticality of the material, system, or service provided.
  • Direct versus indirect impact on product quality or data integrity.
  • Complexity and customisation level of the product or service.
  • Known compliance or quality history, where available.
Sources

Can a supplier's own ISO certification substitute for a dedicated GxP supplier audit?

Industry practice Direct link

A relevant ISO certification, such as ISO 9001 or ISO 13485, can reduce the depth of a required GxP supplier audit and serve as supporting evidence of quality system maturity, but it generally shouldn't be treated as a full substitute, since ISO certification doesn't specifically assess GxP or pharmaceutical regulatory requirements — a supplement addressing the GxP-specific gaps is usually still warranted.

What should a supplier qualification questionnaire actually ask that a generic checklist misses?

Industry practice Direct link

An effective questionnaire goes beyond yes/no certification questions to ask for specifics — how the supplier notifies customers of a change affecting a qualified product, what their change control and deviation management process looks like, how they handle a product recall or field alert, and what evidence they can provide of both, not just an assertion that a process exists.

Sources

Does a remote or virtual supplier audit hold the same weight as an on-site audit?

Industry practice Direct link

A remote or virtual audit can be an acceptable, risk-justified alternative to an on-site audit, particularly when combined with document review and video walkthroughs, but it typically can't fully replace an on-site audit for the highest-risk suppliers, since some physical, environmental, or process observations are difficult to verify remotely with full confidence.

Sources

Section 03

Findings, requalification, and subcontracted suppliers

What happens when an audit finds a gap, how often to reassess, and whether sub-tier suppliers need their own qualification.

What happens if a supplier audit finds a significant quality system gap — can they still be approved?

Industry practice Direct link

A significant quality system gap found during audit doesn't automatically disqualify a supplier, but approval should be conditional on a documented corrective action plan with defined timelines, and the gap's severity relative to what the supplier provides should determine whether approval is granted with conditions, delayed until remediation is verified, or the supplier is rejected entirely.

Sources

How often does an approved supplier need to be reassessed?

QMS-specific Direct link

There's no universal regulatory interval — reassessment frequency should be risk-based, commonly ranging from annual reviews for the highest-risk suppliers to reassessment every few years for lower-risk ones, and should be defined in the site's supplier management procedure rather than left undefined once initial approval is granted.

Sources

What triggers an unscheduled requalification of a supplier outside the normal cycle?

Industry practice Direct link

Unscheduled requalification is typically triggered by a significant quality issue traced to the supplier, a regulatory inspection finding at the supplier's site, a major change the supplier makes to their process or facility, or a pattern of recurring minor issues that individually wouldn't trigger review but collectively suggest a systemic problem.

Sources

Do subcontracted or sub-tier suppliers need their own qualification, or does qualifying the primary vendor cover them?

Industry practice Direct link

Sub-tier suppliers that materially affect a GxP-critical product or service should be identified and assessed, at least at a level proportionate to their impact, rather than assumed to be covered simply because the primary vendor is qualified — the primary vendor's own supplier management process for their sub-tier suppliers should itself be part of what's evaluated during the primary vendor's qualification.

Does a supplier need to be requalified if they change their own manufacturing location or key personnel?

Industry practice Direct link

A change in manufacturing location generally requires a targeted requalification, since the physical facility, equipment, and local quality controls are often central to the original qualification; a key personnel change alone is usually assessed for impact but doesn't automatically trigger full requalification unless it affects a role critical to the qualification basis, such as the quality unit lead.

Sources

Section 04

Documentation, approval, and inspection expectations

What a completed assessment needs to include, who approves it, how long to keep it, and the most common mistake organisations make.

What documentation does a completed supplier qualification assessment need to include to be inspection-ready?

Industry practice Direct link

An inspection-ready supplier qualification record should show what was assessed, the evidence reviewed, any findings and how they were resolved, the risk tier assigned to the supplier, the approval decision and approver, and the date the next reassessment is due — a record that only states "supplier approved" without this supporting detail doesn't demonstrate the assessment actually occurred.

  • Supplier name, scope of qualification, and risk tier assigned.
  • Assessment method used: questionnaire, document review, or audit.
  • Findings identified and their resolution or corrective action plan.
  • Approval decision, approver, and date.
  • Date the next reassessment is due.
Sources

Who has to approve a supplier before they can be used for a GxP-critical system or material?

QMS-specific Direct link

QA should formally approve a supplier for GxP-critical use, typically documented through addition to an approved supplier list, following review of the completed qualification assessment — procurement or engineering may recommend a supplier, but QA approval is the control point that confirms the supplier meets quality requirements, not just technical or commercial ones.

How long must supplier qualification records be retained?

Regulatory basis Direct link

Supplier qualification records should be retained for at least as long as the relationship with the supplier is active, plus the retention period applicable to the GxP records or materials the supplier's product or service supports, since the qualification record is the evidence justifying reliance on that supplier throughout that period.

Sources

What does an inspector actually check when reviewing supplier qualification records?

Industry practice Direct link

Inspectors typically check that a GxP-critical supplier was formally qualified before being used, that the assessment rigor matched the supplier's actual risk tier, that reassessments occurred on schedule, and that any past findings against the supplier were tracked to resolution rather than left open indefinitely.

A frequent finding is an approved supplier list with no accessible underlying qualification records, or reassessment dates that have quietly lapsed without any documented risk-based justification for the delay.

Sources

What's the most common mistake organizations make with supplier qualification?

Industry practice Direct link

The most common mistake is treating supplier qualification as a one-time gate at onboarding rather than an ongoing relationship that needs periodic reassessment — a supplier can be thoroughly qualified at the start and drift into a compliance risk years later through an unnoticed ownership change, quality system decline, or accumulation of unresolved minor issues that were never tracked collectively.

Source transparency

Regulatory references and scope

  • ICH Q9(R1): Quality Risk Management — International quality-risk-management principles underpinning the risk-based tiering and assessment rigor applied to supplier qualification.
  • ICH Q10: Pharmaceutical Quality System — International Pharmaceutical Quality System framework that identifies supplier and outsourced activity management as a core element of an effective quality system.
  • ISPE GAMP 5, Second Edition — Industry framework for computerised system validation that expects supplier assessment scaled to a software vendor's GAMP category and development practices. Not a regulation.
  • FDA General Principles of Software Validation — FDA guidance on software validation principles, relevant to assessing a software vendor's development lifecycle and support practices.