Practitioner template

Supplier Assessment Template

Evaluate whether the supplier, service controls, lifecycle practices, and available evidence are suitable for the intended use.

Author
CSVtoCSA editorial
Published
12 September 2026
Last reviewed
2026-09-12
Version
1.0
Content type
Template
Primary references
Apply the sources and approved procedures relevant to the system
Download Template

Blank template

  1. Supplier and service
  2. Intended use supported
  3. Service and release model
  4. Lifecycle and quality evidence
  5. Security and availability evidence
  6. Test and defect evidence
  7. Change notification
  8. Data and record responsibilities
  9. Evidence limitations
  10. Assessment conclusion and actions

Completed fictional example

Fictional teaching example: This is not an executed or approved validation record.

Supplier and service
Fictional multi-tenant eQMS provider
Intended use supported
CAPA creation, approval, signature, retention, and export
Service and release model
Weekly supplier-managed releases
Lifecycle and quality evidence
SDLC summary and controlled release process reviewed
Security and availability evidence
SOC 2 report reviewed for control context only
Test and defect evidence
Version-specific standard-workflow regression summary
Change notification
Release notes five days before production
Data and record responsibilities
Supplier hosts records; customer controls configuration, roles, procedures, and export use
Evidence limitations
No coverage of local CAPA routing or identity mapping
Assessment conclusion and actions
Conditionally suitable; perform configuration testing and strengthen change-notification terms