Supplier assessment scope
Assess the organization and responsibilities, quality-management practices, software development lifecycle, requirements and design controls where applicable, supplier testing, release and configuration management, incident and problem management, security, backup and recovery, business continuity, data handling and retention, sub-processors, AI or model suppliers, customer notification, and contractual responsibilities.
Supplier assessment supports the validation approach. It does not replace assessment of the regulated company’s intended use, configuration, interfaces, data, electronic records, procedures, roles, or local controls.
Completed fictional assessment
A multi-tenant eQMS supplier provides a software development lifecycle summary, security control report, release process, problem-management process, recovery description, sub-processor list, and customer-change terms. The regulated company finds the supplier suitable for the proposed service, subject to contract actions for material-change notice and recovery evidence. The customer retains responsibility for its CAPA configuration, identity mapping, signed exports, migrated records, procedures, user access, and release decisions.
Related evidence decision
Use the Existing Supplier Evidence Assessment to determine what each supplier source can support and what local evidence is still required.
Regulatory and procedural context
Primary sources. FDA CSA guidance ↗ supports a risk-based approach and consideration of available information. EU GMP Annex 11 ↗ includes supplier and service-provider expectations for applicable GMP systems.
Company procedure. The organization’s approved validation, change-control, supplier-management, information-security, data-integrity, records-retention, and Quality approval procedures determine the required records, roles, and approval route.
CSVtoCSA practitioner interpretation. Supplier suitability and responsibility must be assessed for the service and intended use; a supplier assessment is not customer validation. This is a recommended validation approach, not a statement that every listed activity is a direct regulatory requirement.