# Supplier Assessment Template

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Evaluate whether the supplier, service controls, lifecycle practices, and available evidence are suitable for the intended use.

## When to use

For purchased software, SaaS, cloud services, foundation models, managed platforms, and material supplier changes.

## Instructions

- Define the service and customer-controlled configuration.
- Review evidence relevance, credibility, and coverage.
- Record customer and supplier responsibilities.
- Identify gaps that require contract, control, monitoring, or local testing.

## Blank template

1. Supplier and service

   Response: 

2. Intended use supported

   Response: 

3. Service and release model

   Response: 

4. Lifecycle and quality evidence

   Response: 

5. Security and availability evidence

   Response: 

6. Test and defect evidence

   Response: 

7. Change notification

   Response: 

8. Data and record responsibilities

   Response: 

9. Evidence limitations

   Response: 

10. Assessment conclusion and actions

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. Supplier and service

   Fictional multi-tenant eQMS provider

2. Intended use supported

   CAPA creation, approval, signature, retention, and export

3. Service and release model

   Weekly supplier-managed releases

4. Lifecycle and quality evidence

   SDLC summary and controlled release process reviewed

5. Security and availability evidence

   SOC 2 report reviewed for control context only

6. Test and defect evidence

   Version-specific standard-workflow regression summary

7. Change notification

   Release notes five days before production

8. Data and record responsibilities

   Supplier hosts records; customer controls configuration, roles, procedures, and export use

9. Evidence limitations

   No coverage of local CAPA routing or identity mapping

10. Assessment conclusion and actions

   Conditionally suitable; perform configuration testing and strengthen change-notification terms

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
