QMSAdvisor

Quality System Remediation

Supplier Audits and Supplier Controls

Your suppliers and contract manufacturers make part of your device, and auditors and investigators treat their failures as yours. We help you build supplier controls scaled to risk, and conduct supplier audits whose records stand up to FDA review.

What You Receive

  1. 01Risk-Ranked Approved Supplier List
  2. 02Supplier Control Procedure
  3. 03Quality Agreement Templates
  4. 04Supplier Audit Reports
  5. 05Supplier Monitoring Criteria

Every finding is reviewed and approved by a qualified QMS advisor before it reaches you.

What It Is

ISO 13485:2016 expects you to evaluate and select suppliers on their ability to provide product that meets your requirements, with controls proportionate to the risk the purchased product or service carries for your device. Purchasing information has to state what you need clearly enough to buy it right. Purchased product is verified, by incoming inspection or other means, before use. Suppliers are monitored and re-evaluated, and problems feed back into your system.

Outsourced processes get particular attention. If a contract manufacturer, sterilizer, test lab or software developer performs part of your process, you remain responsible for it, and the controls belong in a quality agreement that defines who does what, how changes are communicated and what records you can see. FDA's Compliance Program 7382.850 groups these requirements in the Outsourcing and Purchasing area of an inspection.

Supplier audit records are now inspectable. Under the QMSR, supplier audit reports are open to FDA in the same way as internal audit and management review records. An approved supplier list built on questionnaires alone, with nothing linking supplier risk to the level of control, gives an investigator an easy thread to pull.

When You Need It

  • Your approved supplier list includes suppliers with no documented evaluation or risk rationale
  • Critical suppliers or contract manufacturers work without a signed quality agreement
  • You outsource a process such as sterilization, machining, assembly or software development and need to show control over it
  • Supplier nonconformances keep recurring and never reach supplier corrective action
  • Supplier audits are due and you don't have the people to plan and conduct them
  • A customer or notified body has asked how you control a specific critical supplier

What We Do

  1. 01

    Inventory Suppliers and Rank by Risk

    We build or clean up the supplier list and rank each supplier by the risk its product or service carries for device safety and performance.

  2. 02

    Set Controls Proportionate to Risk

    We define what each tier needs: evaluation method, quality agreement, incoming inspection, monitoring frequency and whether an on-site or remote audit is warranted.

  3. 03

    Write Quality Agreements and Purchasing Data

    We draft or review quality agreements for critical suppliers and outsourced processes, and check that purchasing documents carry the specifications, change notification requirements and records you need.

  4. 04

    Plan and Conduct Supplier Audits

    Our advisors audit suppliers on your behalf or with your team, and write factual, specific reports, because FDA can now read them.

  5. 05

    Connect Monitoring to Corrective Action

    We link incoming inspection results, supplier nonconformances and performance reviews to re-evaluation and supplier CAPA, so a recurring problem changes the supplier's status.

Deliverables

  • Risk-Ranked Approved Supplier List

    Each supplier's risk tier, required controls and current status, with the rationale recorded.

  • Supplier Control Procedure

    Evaluation, selection, monitoring, re-evaluation and audit requirements in one procedure.

  • Quality Agreement Templates

    Templates for component suppliers, contract manufacturers and service providers, with change notification and records access terms.

  • Supplier Audit Reports

    Reports for the audits we conduct, with findings, requested corrections and follow-up.

  • Supplier Monitoring Criteria

    What you measure for each tier and the thresholds that trigger re-evaluation or supplier CAPA.

How the Platform Helps

  • Supplier Files in One Place

    Upload questionnaires, supplier certificates, quality agreements and audit reports as they are. Originals are preserved and duplicate files are flagged.

  • Supplier CAPA Records

    Correction, root cause, corrective action and effectiveness verification for supplier issues, with the evidence your supplier sends reviewed by an advisor.

  • Practice Producing Supplier Evidence

    The FDA Inspection Simulator can scope a practice inspection to the Outsourcing and Purchasing area, so your team rehearses producing supplier records on request.

See the full platform

Audits and Inspections It Prepares You For

Standards and Regulations in Scope

Questions About This Service

Do we need to audit every supplier?

No. The level of control should match the risk the supplier's product or service carries for your device. Low-risk suppliers may need only an evaluation and monitoring of results, while critical suppliers and outsourced processes often warrant audits. Record the reasoning for each tier.

Are supplier audit reports open to FDA?

Yes. Under the QMSR, supplier audit records are open to FDA inspection. Write them factually, show the follow-up, and keep your approved supplier list consistent with what the audits found.

What belongs in a quality agreement?

Typically the responsibilities of each party, the requirements the supplier must meet, how and when changes must be notified, which records the supplier keeps and how you can access them, and your right to audit. For an outsourced process, it should say exactly which steps the supplier performs and how the output is verified.

Can a supplier's ISO 13485 certificate replace our evaluation?

It's useful evidence, but it doesn't replace your own evaluation. A certificate shows the supplier's system was audited against the standard, not that the supplier can meet your requirements for your product. Use it as one input, scaled to risk.

How does FDA look at suppliers during an inspection?

Under Compliance Program 7382.850, purchasing and outsourced processes fall in the Outsourcing and Purchasing area. Inspections are risk-based and start from your risk management documentation, so an investigator may follow a high-risk component or outsourced process back to how you selected and control that supplier.

Request an Assessment

Discuss Supplier Audits and Supplier Controls With an Advisor

Tell us about your devices, your documents and your timeline, and an advisor will scope the work with you. Please don't send confidential documents yet: secure upload is set up after onboarding.