Existing evidence can help when it matches the claim
Supplier evidence may include development and test records, release information, known-defect lists, security reports, configuration specifications, and service arrangements. Different evidence answers different questions. A security certification does not demonstrate that your CAPA routing is correct.
Before relying on evidence, establish the product and version it covers, the tested environment, the tested behavior, the expected and actual outcomes, the handling of failures, and any exclusions. Decide whether you can review enough detail to support your use.
Example 1: Standard password behavior
A supplier test demonstrates the standard authentication behavior for the installed version. Local checks confirm your identity-provider integration and actual policy settings. The supplier record helps with the standard feature; local evidence covers your configuration and connection.
Example 2: Configured CAPA approval
The supplier proves that its workflow engine supports conditional routing. Your organization configures escalation according to site, severity, and product family. You need evidence that those local conditions route correctly, including blank fields and unauthorized edits. Engine evidence cannot establish the correctness of values the supplier never configured.
Example 3: Restricted SaaS documentation
The supplier provides only a summary and refuses detailed test records. Document what is available and why it is insufficient for particular claims. Compensating activities may include focused local testing, stronger monitoring, contractual clarification, or rejecting the proposed use. Do not describe unseen tests as reviewed.
Completed reliance note — fictional: “Supplier package SP-42 supports standard document versioning in release 8.3. It excludes our migration utility and role configuration. We will use SP-42 for standard behavior and execute local tests for migrated version relationships, effective-state permissions, and retrieval of historical approved records.”
Questions worth asking the supplier
How are significant defects communicated? Can a release be deferred? Which components can change without advance notice? What evidence identifies the deployed version? How are records returned at contract termination? How is restoration tested? Which responsibilities remain with the customer?
The output of this review should be a clear reliance decision, not just a completed questionnaire.