Quality System Remediation
Supplier Audits and Supplier Controls
Your suppliers and contract manufacturers make part of your device, and auditors and investigators treat their failures as yours. We help you build supplier controls scaled to risk, and conduct supplier audits whose records stand up to FDA review.
What You Receive
- 01Risk-Ranked Approved Supplier List
- 02Supplier Control Procedure
- 03Quality Agreement Templates
- 04Supplier Audit Reports
- 05Supplier Monitoring Criteria
Every finding is reviewed and approved by a qualified QMS advisor before it reaches you.
What It Is
ISO 13485:2016 expects you to evaluate and select suppliers on their ability to provide product that meets your requirements, with controls proportionate to the risk the purchased product or service carries for your device. Purchasing information has to state what you need clearly enough to buy it right. Purchased product is verified, by incoming inspection or other means, before use. Suppliers are monitored and re-evaluated, and problems feed back into your system.
Outsourced processes get particular attention. If a contract manufacturer, sterilizer, test lab or software developer performs part of your process, you remain responsible for it, and the controls belong in a quality agreement that defines who does what, how changes are communicated and what records you can see. FDA's Compliance Program 7382.850 groups these requirements in the Outsourcing and Purchasing area of an inspection.
Supplier audit records are now inspectable. Under the QMSR, supplier audit reports are open to FDA in the same way as internal audit and management review records. An approved supplier list built on questionnaires alone, with nothing linking supplier risk to the level of control, gives an investigator an easy thread to pull.
When You Need It
- Your approved supplier list includes suppliers with no documented evaluation or risk rationale
- Critical suppliers or contract manufacturers work without a signed quality agreement
- You outsource a process such as sterilization, machining, assembly or software development and need to show control over it
- Supplier nonconformances keep recurring and never reach supplier corrective action
- Supplier audits are due and you don't have the people to plan and conduct them
- A customer or notified body has asked how you control a specific critical supplier
What We Do
- 01
Inventory Suppliers and Rank by Risk
We build or clean up the supplier list and rank each supplier by the risk its product or service carries for device safety and performance.
- 02
Set Controls Proportionate to Risk
We define what each tier needs: evaluation method, quality agreement, incoming inspection, monitoring frequency and whether an on-site or remote audit is warranted.
- 03
Write Quality Agreements and Purchasing Data
We draft or review quality agreements for critical suppliers and outsourced processes, and check that purchasing documents carry the specifications, change notification requirements and records you need.
- 04
Plan and Conduct Supplier Audits
Our advisors audit suppliers on your behalf or with your team, and write factual, specific reports, because FDA can now read them.
- 05
Connect Monitoring to Corrective Action
We link incoming inspection results, supplier nonconformances and performance reviews to re-evaluation and supplier CAPA, so a recurring problem changes the supplier's status.
Deliverables
Risk-Ranked Approved Supplier List
Each supplier's risk tier, required controls and current status, with the rationale recorded.
Supplier Control Procedure
Evaluation, selection, monitoring, re-evaluation and audit requirements in one procedure.
Quality Agreement Templates
Templates for component suppliers, contract manufacturers and service providers, with change notification and records access terms.
Supplier Audit Reports
Reports for the audits we conduct, with findings, requested corrections and follow-up.
Supplier Monitoring Criteria
What you measure for each tier and the thresholds that trigger re-evaluation or supplier CAPA.
How the Platform Helps
Supplier Files in One Place
Upload questionnaires, supplier certificates, quality agreements and audit reports as they are. Originals are preserved and duplicate files are flagged.
Supplier CAPA Records
Correction, root cause, corrective action and effectiveness verification for supplier issues, with the evidence your supplier sends reviewed by an advisor.
Practice Producing Supplier Evidence
The FDA Inspection Simulator can scope a practice inspection to the Outsourcing and Purchasing area, so your team rehearses producing supplier records on request.
Audits and Inspections It Prepares You For
Supplier Audit
Audits you perform of your own suppliers and contract manufacturers as part of purchasing controls.
Customer Audit
A customer's audit of your quality system, often a device maker auditing a supplier or contract manufacturer.
FDA Baseline Surveillance Inspection
FDA's comprehensive surveillance inspection of your quality system under Compliance Program 7382.850.
EU Notified Body Audit (Including Unannounced Audits)
Conformity assessment, surveillance and unannounced audits by an EU notified body under the MDR or IVDR.
Remote and Hybrid Audits
Audits and regulatory assessments run partly or fully through video, screen sharing and electronic records.
Standards and Regulations in Scope
Questions About This Service
Do we need to audit every supplier?
No. The level of control should match the risk the supplier's product or service carries for your device. Low-risk suppliers may need only an evaluation and monitoring of results, while critical suppliers and outsourced processes often warrant audits. Record the reasoning for each tier.
Are supplier audit reports open to FDA?
Yes. Under the QMSR, supplier audit records are open to FDA inspection. Write them factually, show the follow-up, and keep your approved supplier list consistent with what the audits found.
What belongs in a quality agreement?
Typically the responsibilities of each party, the requirements the supplier must meet, how and when changes must be notified, which records the supplier keeps and how you can access them, and your right to audit. For an outsourced process, it should say exactly which steps the supplier performs and how the output is verified.
Can a supplier's ISO 13485 certificate replace our evaluation?
It's useful evidence, but it doesn't replace your own evaluation. A certificate shows the supplier's system was audited against the standard, not that the supplier can meet your requirements for your product. Use it as one input, scaled to risk.
How does FDA look at suppliers during an inspection?
Under Compliance Program 7382.850, purchasing and outsourced processes fall in the Outsourcing and Purchasing area. Inspections are risk-based and start from your risk management documentation, so an investigator may follow a high-risk component or outsourced process back to how you selected and control that supplier.
Request an Assessment
Discuss Supplier Audits and Supplier Controls With an Advisor
Tell us about your devices, your documents and your timeline, and an advisor will scope the work with you. Please don't send confidential documents yet: secure upload is set up after onboarding.


