Evidence-backed answers
Vendor/Supplier Qualification Assessment FAQs
20 questions covering assessment scope, audits and tiering, findings and requalification, and inspection expectations.
Section 01
What a supplier qualification assessment actually evaluates
How it differs from proposal evaluation, whether every supplier needs one, and who decides how rigorous it should be.What's the difference between evaluating a vendor's proposal and actually qualifying them as a supplier?
Evaluating a vendor's proposal checks whether their specific product or service meets a project's stated requirements; supplier qualification is a broader, ongoing assessment of the vendor's own quality management system, manufacturing controls, and track record — confirming they're a reliable, compliant organisation to do business with, not just that one product looks suitable.
A vendor can submit a technically excellent proposal for a specific system while still having an inadequate quality system overall — proposal evaluation and supplier qualification answer different questions and both are needed before committing to a GxP-critical relationship.
Does every supplier need a full qualification assessment, or can some be approved through a simpler process?
No — the depth of supplier qualification should be risk-based, scaled to the GxP criticality of what the supplier provides; a supplier of a non-critical commodity item can often be approved through a lighter documented review, while a supplier of a GxP-critical material, system, or service warrants a full assessment, potentially including an audit.
What should a supplier qualification assessment actually look at beyond whether their product meets the URS?
A supplier qualification assessment should evaluate the supplier's quality management system, change notification practices, regulatory compliance history, financial and operational stability, sub-tier supplier controls, and technical support and escalation capability — factors that determine whether the relationship will remain reliable over the system's operational life, not just whether the initial product meets specification.
- Quality management system maturity and certifications.
- Change notification process for their product or service.
- Regulatory inspection or compliance history, where available.
- Technical support responsiveness and escalation path.
- Financial and operational stability as an ongoing business.
- Sub-tier supplier or subcontractor controls, where relevant.
Does a software vendor need to be qualified differently than a hardware or equipment supplier?
Yes — a software vendor's qualification assessment should additionally evaluate their software development lifecycle practices, version control and release management, cybersecurity posture, and how they support validation activities such as providing audit-ready documentation, since these factors don't apply in the same way to a hardware or equipment supplier.
Who's responsible for deciding how rigorous a given supplier's assessment needs to be?
QA, often in collaboration with the system or material owner, should determine the required rigor of a supplier's qualification assessment, based on a documented risk assessment of what the supplier provides and its GxP impact — this decision shouldn't be left to procurement alone, since cost and delivery considerations can bias toward a lighter assessment than the risk actually warrants.
Section 02
Audits, questionnaires, and risk-based tiering
When a questionnaire is enough, how to tier suppliers by risk, and whether certifications or remote audits carry the same weight as an on-site assessment.When is a supplier questionnaire enough, and when do you actually need an on-site audit?
A documented questionnaire, sometimes supplemented by a review of certifications and public inspection history, is often sufficient for lower-risk suppliers, while an on-site or remote audit is generally warranted for suppliers of GxP-critical systems, materials, or services where the questionnaire responses can't be independently verified with confidence, or where the supplier's compliance history raises concerns.
How do you tier suppliers by risk, and what determines which tier a supplier falls into?
Supplier risk tiering is typically based on the GxP criticality of what they provide, the complexity of their product or service, their compliance and quality track record, and how directly their output affects product quality or patient safety — a tier structure lets an organisation apply proportionate assessment rigor rather than treating every supplier identically.
- GxP criticality of the material, system, or service provided.
- Direct versus indirect impact on product quality or data integrity.
- Complexity and customisation level of the product or service.
- Known compliance or quality history, where available.
Can a supplier's own ISO certification substitute for a dedicated GxP supplier audit?
A relevant ISO certification, such as ISO 9001 or ISO 13485, can reduce the depth of a required GxP supplier audit and serve as supporting evidence of quality system maturity, but it generally shouldn't be treated as a full substitute, since ISO certification doesn't specifically assess GxP or pharmaceutical regulatory requirements — a supplement addressing the GxP-specific gaps is usually still warranted.
What should a supplier qualification questionnaire actually ask that a generic checklist misses?
An effective questionnaire goes beyond yes/no certification questions to ask for specifics — how the supplier notifies customers of a change affecting a qualified product, what their change control and deviation management process looks like, how they handle a product recall or field alert, and what evidence they can provide of both, not just an assertion that a process exists.
Does a remote or virtual supplier audit hold the same weight as an on-site audit?
A remote or virtual audit can be an acceptable, risk-justified alternative to an on-site audit, particularly when combined with document review and video walkthroughs, but it typically can't fully replace an on-site audit for the highest-risk suppliers, since some physical, environmental, or process observations are difficult to verify remotely with full confidence.
Section 03
Findings, requalification, and subcontracted suppliers
What happens when an audit finds a gap, how often to reassess, and whether sub-tier suppliers need their own qualification.What happens if a supplier audit finds a significant quality system gap — can they still be approved?
A significant quality system gap found during audit doesn't automatically disqualify a supplier, but approval should be conditional on a documented corrective action plan with defined timelines, and the gap's severity relative to what the supplier provides should determine whether approval is granted with conditions, delayed until remediation is verified, or the supplier is rejected entirely.
How often does an approved supplier need to be reassessed?
There's no universal regulatory interval — reassessment frequency should be risk-based, commonly ranging from annual reviews for the highest-risk suppliers to reassessment every few years for lower-risk ones, and should be defined in the site's supplier management procedure rather than left undefined once initial approval is granted.
What triggers an unscheduled requalification of a supplier outside the normal cycle?
Unscheduled requalification is typically triggered by a significant quality issue traced to the supplier, a regulatory inspection finding at the supplier's site, a major change the supplier makes to their process or facility, or a pattern of recurring minor issues that individually wouldn't trigger review but collectively suggest a systemic problem.
Do subcontracted or sub-tier suppliers need their own qualification, or does qualifying the primary vendor cover them?
Sub-tier suppliers that materially affect a GxP-critical product or service should be identified and assessed, at least at a level proportionate to their impact, rather than assumed to be covered simply because the primary vendor is qualified — the primary vendor's own supplier management process for their sub-tier suppliers should itself be part of what's evaluated during the primary vendor's qualification.
Does a supplier need to be requalified if they change their own manufacturing location or key personnel?
A change in manufacturing location generally requires a targeted requalification, since the physical facility, equipment, and local quality controls are often central to the original qualification; a key personnel change alone is usually assessed for impact but doesn't automatically trigger full requalification unless it affects a role critical to the qualification basis, such as the quality unit lead.
Section 04
Documentation, approval, and inspection expectations
What a completed assessment needs to include, who approves it, how long to keep it, and the most common mistake organisations make.What documentation does a completed supplier qualification assessment need to include to be inspection-ready?
An inspection-ready supplier qualification record should show what was assessed, the evidence reviewed, any findings and how they were resolved, the risk tier assigned to the supplier, the approval decision and approver, and the date the next reassessment is due — a record that only states "supplier approved" without this supporting detail doesn't demonstrate the assessment actually occurred.
- Supplier name, scope of qualification, and risk tier assigned.
- Assessment method used: questionnaire, document review, or audit.
- Findings identified and their resolution or corrective action plan.
- Approval decision, approver, and date.
- Date the next reassessment is due.
Who has to approve a supplier before they can be used for a GxP-critical system or material?
QA should formally approve a supplier for GxP-critical use, typically documented through addition to an approved supplier list, following review of the completed qualification assessment — procurement or engineering may recommend a supplier, but QA approval is the control point that confirms the supplier meets quality requirements, not just technical or commercial ones.
How long must supplier qualification records be retained?
Supplier qualification records should be retained for at least as long as the relationship with the supplier is active, plus the retention period applicable to the GxP records or materials the supplier's product or service supports, since the qualification record is the evidence justifying reliance on that supplier throughout that period.
What does an inspector actually check when reviewing supplier qualification records?
Inspectors typically check that a GxP-critical supplier was formally qualified before being used, that the assessment rigor matched the supplier's actual risk tier, that reassessments occurred on schedule, and that any past findings against the supplier were tracked to resolution rather than left open indefinitely.
A frequent finding is an approved supplier list with no accessible underlying qualification records, or reassessment dates that have quietly lapsed without any documented risk-based justification for the delay.
What's the most common mistake organizations make with supplier qualification?
The most common mistake is treating supplier qualification as a one-time gate at onboarding rather than an ongoing relationship that needs periodic reassessment — a supplier can be thoroughly qualified at the start and drift into a compliance risk years later through an unnoticed ownership change, quality system decline, or accumulation of unresolved minor issues that were never tracked collectively.