
Audit Management Module
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreA risk-based, structured, independent examination of a supplier's quality systems and processes — the principal way firms turn supplier qualification claims into verified assurance.
Documentation reviews and self-completed questionnaires only go so far. A supplier audit is the on-the-ground (or properly-structured remote) verification that a supplier's quality system actually works the way it claims to. It's the main mechanism firms have for managing external quality risk.

A supplier audit is a systematic, independent, documented examination of a supplier's quality systems, processes, and controls. It verifies compliance with regulatory, contractual, and quality requirements. The work is hands-on, whether on-site or structured remote. Supplier audit is distinct from document review and questionnaire-based qualification: those are paper-side controls; audit is the in-person (or virtual-in-person) check.
Modern regulator practice treats supplier audits as the principal mechanism firms have for managing external quality risk. The reasoning is direct. When something goes wrong with a supplied material — contamination, specification failure, recall — the firm carries responsibility regardless of who manufactured the input. Supplier audit is where the firm builds the assurance that supports that responsibility.
Supplier audit is regulated explicitly under 21 CFR §211.84 (component testing and approval), 21 CFR §820.50 (purchasing controls), EU GMP Chapter 7 (Outsourced Activities) and Chapter 5 (Production), ISO 13485 §7.4 (Purchasing), ISO 9001:2015 §8.4, ICH Q10, and ISO 19011. The expectation is universal: structured, risk-based, documented supplier audits with credible follow-up.
Self-completed supplier questionnaires are useful for screening and ongoing oversight, but they aren't audits. They prove the supplier can answer questions about itself. Audit proves the supplier can be observed doing what it claims. Inspections increasingly check whether high-risk suppliers were audited rather than questionnaired.
Supplier-driven quality events have driven some of the largest regulatory actions of the last decade. Contamination in active pharmaceutical ingredients — the nitrosamine wave is the recent example. Specification failures in critical components. Documented data integrity issues in contract laboratories. Cybersecurity incidents at outsourced IT services. In each case the auditing firm carries regulatory and commercial consequence regardless of which entity actually caused the issue. Supplier audit is the mechanism that lets the firm see the problem before the regulator does, or, when it can't, demonstrates that the firm exercised the oversight expected.
Recent enforcement has produced a consistent pattern around supplier audit discipline. Critical suppliers without recent audits. Scopes that covered documentation but didn't verify on-the-ground practice. Auditors without the technical qualification for the subject. Significant findings closed administratively without verifying corrective action effectiveness. Audit programs that ran but didn't feed supplier qualification decisions — suppliers with significant findings still on the approved list with no risk-based reassessment.
Specific things have shifted recently. ICH Q9(R1) (effective 2023) raises the bias-awareness bar on supplier risk assessment. EU GMP Annex 21 (effective 2022) tightened importation oversight. The 2024 final QMSR brings the device side closer to ISO 13485 supplier expectations, with the February 2, 2026 effective date now active. None of this is theoretical; inspections cite it.
The cultural side is concrete. When supplier audits get framed as commercial-relationship management, they tend to be light and miss things. When they're framed as risk management, they find what's there. The difference often shows up in finding rates: programs with consistent zero-finding audits over time usually have audit-quality issues, not supplier-quality success.
Inspector perspective: a credible review of supplier audits samples critical suppliers and asks four things. Was the audit done within the defined frequency? Was the scope adequate for the supplier's risk profile? Did the auditor have technical qualification for what was being audited? Were significant findings followed through to verified closure? When supplier audits look more like commercial visits than risk-management activities, the sample tends to expand.
Supplier audit obligations sit across multiple frameworks:
The practices that hold up at inspection share a common shape:
The controls that hold up at inspection:
Closing supplier findings based on the supplier's CAPA response document alone — without verifying that implementation actually happened and was effective — is one of the most consistently-cited supplier audit findings. Critical and major findings need verification: a revisit, evidence review, or follow-up audit. Programs that close on paper response alone accumulate findings that the next audit cycle catches.
Supplier audit is the main mechanism your team has for managing external quality risk. Complere is built to run the full lifecycle — planning, execution, finding classification, CAPA-linked follow-up, closure, and feedback into supplier qualification — as one connected, traceable process.
Your team plans each audit on a single record: scope, objectives, criteria, the audit team you've assigned, the agenda, and the pre-audit document review notes. Whether it's an internal, external, supplier, or regulatory audit drives how the record behaves and how it reports. During execution, your auditor captures opening-meeting notes, document-review observations, walkthrough findings, interview notes, and attached evidence — all against the same record, so when you reconstruct the audit later there's no scattered paper to chase.
Findings come out as structured records, classified under your defined tiers (critical, major, minor, observation), with the description, the supporting evidence, the recommended action, a target closure date, and an owner. For significant findings, your team can require cross-functional sign-off — and the platform confirms each signer actually has the authority before letting them sign. Your auditor's sign-off carries identity, timestamp, and the meaning of the signature, and you have your own service-level windows you can track on each audit so overdue work surfaces before it embarrasses you.
When the supplier comes back with a CAPA response, your team captures their corrective action plan, implementation evidence, and effectiveness verification against the original finding. Closure is gated on documented verification per your SOP — no closing on the response document alone, which is one of the most-cited supplier audit findings in inspections. Where your own firm needs to act on a systemic issue surfaced by the audit, that routes into your CAPA workflow with the audit referenced as the source.
The audit history feeds back into supplier qualification. Repeated significant findings flag the supplier; your qualification decisions can be made with the full audit context visible. Program-level metrics — findings by severity, closure rates, recurring patterns across your supplier base, SLA performance — are reportable across the audit workflow and feed your Management Review inputs.
What stays with your team: tiering your suppliers by risk, defending the audit frequency rationale, qualifying your auditors for the scope they cover, keeping classification consistent, holding the line on unverified CAPA closures, and letting audit outcomes actually move suppliers between qualification states. Complere supplies the workflow, the record structure, and the aggregated reporting; the quality judgment is yours.
Common questions about Supplier Audit sourced from regulatory references and inspection patterns.
It's a systematic, independent, documented examination of a supplier's quality systems, processes, and controls to verify compliance with regulatory, contractual, and quality requirements. It goes beyond document review and questionnaires. A supplier audit is hands-on, whether on-site or structured remote, and confirms that the supplier actually operates the way its documents claim. Modern enforcement treats supplier audits as the main mechanism firms have to manage external quality risk.
Risk-based, but with consistent expectations across regulators. Critical suppliers (whose materials or services directly affect product quality), high-risk materials (sterile actives, biologicals, single-source materials), new suppliers (before first commercial use), suppliers undergoing significant change (ownership, site, process, scope), and suppliers with recurring quality issues. Routine frequency is risk-based — typically annual or biennial for critical suppliers, less often for lower-risk. Inadequate frequency justification is itself a finding.
Yes, explicitly. 21 CFR §211.84 covers testing and approval of components, drug product containers, and closures, with ongoing supplier oversight implicit. 21 CFR §820.50 requires manufacturers to evaluate and select suppliers, contractors, and consultants based on their ability to meet specified requirements. EU GMP Chapters 7 (Outsourced Activities) and 5 (Production) both require structured supplier oversight. ISO 13485 §7.4 governs purchasing including supplier evaluation and re-evaluation. ICH Q10 frames supplier management as a quality system element. ISO 19011 is the audit methodology framework.
Risk-based, with on-site historically expected for critical suppliers. The COVID-19 period normalised remote audits for many situations, and modern guidance accepts remote as legitimate when properly structured: pre-audit document review, video site walkthrough, real-time access to records, structured interviews. Remote demands more rigour in preparation and execution to be credible. High-criticality, complex-process, or first-time audits often still need on-site presence. The decision needs documented rationale per audit.
Typically into severity tiers. Critical (immediate quality, safety, or regulatory impact; requires immediate containment and escalation). Major (significant quality system deficiency; structured CAPA with defined closure). Minor (improvement opportunity; documented but lower priority). Observation (note for supplier improvement, not formal finding). The classification drives the response — critical and major need formal CAPAs with effectiveness verification; minor needs corrective action; observations may be informational. Classification consistency across audits is itself an inspection focus.
Auditors must be competent: independent of the activity being audited, trained on the audit methodology (typically ISO 19011), and qualified on the technical subject matter. Auditor competency requirements are defined per the firm's audit SOP and assessed. For technical audits (sterile manufacturing, complex analytical methods, software development) the auditor's subject-matter qualification matters as much as audit-methodology training. Lead auditors are typically formally qualified through ISO 19011-aligned programs.
Findings are communicated to the supplier with timelines for response and corrective action. The supplier's corrective action plan is evaluated for adequacy. Implementation is verified. Closure is documented. Critical and major findings may require on-site verification of CAPA effectiveness. The audit-to-closure cycle feeds back into supplier qualification status — repeated significant findings can trigger requalification, conditional approval, or disapproval. Findings not closed are themselves findings for the auditing firm.
Critical suppliers not audited per schedule. Scope inadequate (paper review only when on-site needed). Auditor not qualified for the technical scope. Finding classification inconsistent across audits. Significant findings not closed within defined timelines. Closure documentation inadequate (signed off without verification). Audit outcomes not feeding supplier qualification decisions. Remote audits inadequately structured. Quality agreements not aligned with audit scope. The audit program itself not periodically reviewed. §820.50 and EU GMP Chapter 7 get cited consistently.
Explore related topics, modules, and compliance resources for a deeper understanding of your quality system.

Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
Explore
Explore this topic in more depth to build a complete picture of your quality and compliance operations.
ExploreWalk through how Complere's audit workflow with structured findings supports supplier audit planning, execution, finding classification, CAPA-linked follow-up, and the audit-history feed into supplier qualification status.