Evidence assessment table
| Supplier evidence | Potential use | Key limitation |
|---|---|---|
| Requirements or specifications | Understand standard functionality and intended product behavior | May not describe local configuration or business process |
| Supplier development testing | Support standard functionality | Applicability, version, environment, acceptance criteria, and scope must be understood |
| Supplier regression testing | Support release assessment | May not cover customer-specific configuration, data, roles, or interfaces |
| Release notes | Identify reported changes and known issues | May not identify every dependency relevant to local use |
| SOC report | Support review of applicable organizational or security controls | Does not demonstrate GxP functional suitability |
| ISO certification | Provide context on supplier management systems | Does not replace validation of the intended use |
| Penetration testing | Support security assessment | Does not demonstrate regulated-process functionality |
| Backup and recovery documentation | Clarify supplier capabilities and responsibilities | Customer recovery, retrieval, retention, and interpretation needs may differ |
Evidence decision record
For each source, record the issuer, title, version, date, system or service scope, function or risk supported, review performed, credibility, limitations, accepted use, local evidence still needed, reviewer, and approval. Do not translate a certificate or pass count into functional coverage it does not contain.
Completed fictional decision
A supplier provides an SDLC summary, SOC 2 report, release notes, standard-workflow regression summary, defect list, and recovery description for a multi-tenant eQMS. The customer uses the SDLC and SOC report as context, accepts version-specific regression evidence for unchanged standard controls, and uses the recovery description to define responsibilities. Local CAPA routing, identity mapping, signed exports, migrated records, and recovery of customer-required attachments remain subject to customer testing.
Link to supplier assessment
Evidence credit depends on the service boundary and responsibility model documented in the Supplier Assessment.
Regulatory and procedural context
Primary sources. FDA CSA guidance ↗ supports a risk-based approach and consideration of available information. EU GMP Annex 11 ↗ includes supplier and service-provider expectations for applicable GMP systems.
Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.
CSVtoCSA practitioner interpretation. Credit supplier evidence only for the version, function, configuration, environment, and failure modes it actually addresses; state the limitation and local gap explicitly. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.