Checklist

CDMO eQMS requirements checklist

A strict yes/no list for a CDMO evaluating an eQMS — the five seams where a shared quality system breaks between sponsors, the five demands, and the architecture question underneath — with a second tab for the sponsor's side of the same boundary.

A CDMO is not buying an eQMS for itself. It is buying for the sponsor, the auditor and the next hand-off nobody wants to explain twice. This workbook turns the demands in why CDMO quality systems break into fifteen questions you answer only when the vendor has produced the evidence in the room — one closed shared-equipment change with its per-sponsor dispositions, one sponsor-scoped audit-trail export with its access log, one exit export with linked records. Underneath all of them sits the question that decides the rest: is each sponsor's scope a database of its own or a column on a shared table? The sponsor tab asks the same boundary from the other side, scored one to five.

Free · Excel workbook · unlocks in seconds
Best eQMS for CDMOs and CMOs
CDMO eQMS requirements checklist — the Excel workbook you download, showing its section, question, evidence and yes/no columns

What the checklist covers

The workbook has three tabs. An Instructions tab explains how to run the list, what each column means, and the four regulatory texts the rows rest on. The CDMO requirements tab holds fifteen yes/no questions in three blocks, each with the evidence you ask the vendor to produce before you answer. The Sponsor RFP questions tab is the same boundary seen from the sponsor's side: twelve questions to put to a CDMO's eQMS in an RFP or audit, scored one to five against a written key.

Block A is the five seams where a shared quality system breaks between sponsors — a change to shared equipment that only names the sponsor who asked for it, an audit-trail export filtered out of a shared pool, retention enforced by hand, a cross-sponsor deviation that leaks the originating sponsor's batch context, and a platform release nobody dispositioned. Block B is the five things a CDMO should demand: the current quality agreement retrievable in one place, sponsor change requests tied to the real implementation path, external parties who can see without controlling, training and approvals that stay linked to the change, and an audit story that holds across site, sponsor and third-party records. Block C is the architecture underneath all of it.

  • The five seams — shared-equipment change control, sponsor-scoped audit-trail export, per-sponsor retention, cross-sponsor events without context leak, vendor releases as per-sponsor change events
  • The five demands — the quality agreement, sponsor change requests, external visibility without control, linked training and approvals, the connected audit story
  • The architecture underneath — database or column, the query behind the filter, what happens on onboarding and on exit, what an inspection request under 21 CFR 200.10(b) produces
  • An evidence-to-ask-for column on every row, so Yes means something was produced in the session, not promised
  • Twelve sponsor-side RFP questions scored 1–5, with the key on the tab

How to use it

Work the CDMO requirements tab during the vendor demo, one row at a time. Read the question, then ask for the evidence in the next column before you touch the Yes/No dropdown — a worked export for one sponsor, produced in the session, with its access log; a closed change on shared equipment with each affected sponsor's disposition; a test sponsor provisioned in front of you with the existing sponsors' records shown unchanged. Yes means it was produced. Anything short of that is No, and a No on any row means the system is not ready for external work. Write what you saw, how long it took and who showed it in the Notes column; that is what the next evaluation starts from.

Sponsors, and CDMOs rehearsing a sponsor audit, use the second tab. Score each of the twelve answers one to five: five walks the architecture and produces the evidence in minutes, two needs engineering to build a custom export, one includes the words "we tag records by client". File the completed workbook in the supplier-qualification record — the CDMO's file on its eQMS vendor, the sponsor's file on the CDMO — alongside the supplier qualification checklist, so the scores sit under evaluate and the segregation clause under approve.

How an inspector reads this

FDA regards a contract facility as an extension of the manufacturer's own facility (21 CFR 200.10(b)), so an inspection request on one sponsor's product reaches the CDMO's records. EU GMP Chapter 7 puts the records of the outsourced activity within the contract giver's reach (7.16) and its audit rights in the contract (7.17); ICH Q10 §2.7 makes the pharmaceutical company ultimately responsible for the control of outsourced activities; FDA's 2016 guidance on quality agreements expects the agreement to say how changes are reported and approved — including changes to products that share a production line, equipment train or facility. An inspector, or a sponsor's auditor, does not read those texts at the CDMO. They ask for one sponsor's records and watch how they are produced.

A list filtered out of a shared pool and an export produced from a scoped space look the same on the first page and different on the access log. That is why every row of this checklist asks for evidence rather than an answer, and why the Notes column matters more than the dropdown: what was produced, from where, and how long it took is the record the next audit at the next CDMO starts from. The full argument is in how CDMOs prove sponsor segregation.

Frequently asked questions

What should a CDMO require from an eQMS?

Five things before any feature list: the current quality agreement retrievable as a controlled record, sponsor change requests tied to the site's real change path, external parties who can see the right record without controlling the system, training and approvals that stay linked to the change that caused them, and an audit story that holds across site, sponsor and third-party records. The checklist turns each into a yes/no question with the evidence to ask for.

Why does "database or column" matter for sponsor segregation?

In a shared-table system every screen, report and export depends on a developer remembering to add the sponsor condition to the query, and one miss is a silent leak. When each sponsor's scope is its own database, which data a request can reach is decided by the connection, not by a filter in code. Row C1 asks the vendor to show the query behind the filter rather than a demo screen.

How is this different from a supplier qualification checklist?

The supplier qualification checklist frames the whole lifecycle — classify, evaluate, approve, monitor — for any supplier. This workbook is the evaluate step for one specific case: a CDMO choosing an eQMS that has to hold more than one sponsor's records, and a sponsor auditing that choice. File the completed scores under evaluate in the supplier file; put the segregation clause under approve.

Bring the checklist to a CDMO-focused demo

Book a demo and work the fifteen rows against Complere with the evidence in front of you — the per-sponsor change record, the scoped export, the query behind the filter — so the Yes/No column is filled from what you saw, not from a pitch.