On this page
Vendor Audits
Scientific Snapshot
Discipline: Quality Management and Supplier Oversight
Difficulty: Intermediate–Advanced
Course position: Lesson 3 of 5
Core concepts: audit scope, evidence, sampling, findings, risk classification, corrective action, follow-up.
Learning Objectives
Readers should be able to:
- Explain the purpose of a vendor audit.
- Distinguish on-site, remote, and document-based audits.
- Describe audit planning and execution.
- Classify findings based on risk.
- Explain follow-up and closure.
- Recognize audit limitations.
Executive Summary
A vendor audit is a structured evaluation of a supplier’s systems, facilities, records, and practices against defined requirements.
Audits support supplier qualification but do not replace:
- lot testing,
- incoming inspection,
- ongoing monitoring,
- quality agreements,
- performance review.
The audit should be proportionate to supplier risk and focused on evidence rather than presentation quality.
Audit Objectives
Audits may evaluate:
- quality-system implementation,
- manufacturing control,
- analytical testing,
- documentation,
- traceability,
- data integrity,
- change control,
- complaints,
- CAPA,
- training,
- subcontractor oversight.
Audit Types
On-Site Audit
Provides direct observation of facilities, operations, and records.
Remote Audit
Uses video, document sharing, interviews, and remote system review.
Desktop Audit
Relies primarily on questionnaires and records.
For-Cause Audit
Triggered by a serious issue, recurring failure, or significant concern.
Audit Planning
The audit plan should define:
- objective,
- scope,
- criteria,
- date,
- duration,
- audit team,
- supplier contacts,
- documents requested,
- areas to review.
Auditor Competence
Auditors need:
- technical understanding,
- interviewing skill,
- evidence evaluation,
- independence,
- report-writing ability,
- knowledge of the applicable requirements.
Opening Meeting
The opening meeting confirms:
- scope,
- schedule,
- communication,
- confidentiality,
- safety expectations,
- access arrangements.
Evidence Collection
Audit evidence may include:
- procedures,
- records,
- logs,
- interviews,
- observations,
- electronic data,
- physical conditions,
- traceability exercises.
Evidence should be objective and traceable.
Sampling
Audits rely on sampling.
A clean sample does not prove that every record is acceptable.
Sampling should focus on risk and process significance.
Traceability Exercises
A traceability exercise may follow a lot backward and forward through:
- raw materials,
- production records,
- testing,
- release,
- shipping,
- complaints.
Data Integrity Review
Review may include:
- unique user accounts,
- audit trails,
- data backup,
- raw data retention,
- integration changes,
- electronic approvals,
- access controls.
Audit Findings
Findings should include:
- requirement,
- objective evidence,
- observed gap,
- potential impact.
Finding Classification
Organizations may classify findings as:
- critical,
- major,
- minor,
- observation or opportunity.
Classification should reflect risk, not wording alone.
Closing Meeting
The closing meeting summarizes:
- scope completed,
- key findings,
- unresolved questions,
- response expectations,
- next steps.
Audit Report
A report should include:
- supplier identity,
- scope,
- criteria,
- attendees,
- evidence reviewed,
- findings,
- conclusion,
- required actions,
- timelines.
Corrective Action Response
The supplier response should address:
- immediate correction,
- root cause,
- corrective action,
- responsible owner,
- due date,
- effectiveness check.
Audit Closure
Closure requires evidence that actions were implemented and effective.
A written promise alone is not always sufficient.
Audit Frequency
Frequency may depend on:
- supplier criticality,
- prior findings,
- performance,
- change history,
- complaint history,
- alternative controls.
Audit Limitations
An audit is a time-limited sample.
It cannot guarantee future performance or detect every hidden problem.
Science Makes Sense
A vendor audit is like inspecting a bridge.
You review design, maintenance records, observed condition, and structural evidence. A good inspection reduces uncertainty, but it does not eliminate the need for ongoing monitoring.
Common Misconceptions
“No findings means no risk.”
Audit sampling can miss problems.
“Remote audits are always inferior.”
Their value depends on scope, evidence access, and supplier risk.
“An audit checklist is the audit.”
Checklists support consistency, but auditors must follow evidence and risk.
Laboratory Best Practices
- Define risk-based scope.
- Use competent auditors.
- Request documents in advance.
- Trace actual records.
- Review data integrity.
- Write evidence-based findings.
- Require root-cause responses.
- Verify effectiveness.
- Link findings to supplier status.
Frequently Asked Questions
When is an on-site audit appropriate?
For higher-risk suppliers or when direct observation is important.
What is objective evidence?
Verifiable information supporting an audit conclusion.
Why classify findings?
To align response urgency and supplier decisions with risk.
What closes an audit finding?
Evidence that corrective action was implemented and effective.
Can an audit replace incoming testing?
No.
Key Takeaways
- Audits are structured, evidence-based assessments.
- Scope should reflect risk.
- Sampling is a limitation.
- Findings require objective evidence.
- Corrective action should address root cause.
- Audit outcomes influence supplier status.
Suggested Figures
- Audit lifecycle.
- Audit-type comparison.
- Evidence-trail map.
- Finding classification matrix.
- Corrective-action follow-up.
- Supplier status decision tree.
Knowledge Check
- Why is audit scope risk-based?
- What is objective evidence?
- Why are audits based on sampling?
- What should a supplier corrective-action response include?
- Why does audit closure require effectiveness evidence?
References
- ISO 19011. Guidelines for Auditing Management Systems.
- ISO 9001. Quality Management Systems — Requirements.
- ICH Q9. Quality Risk Management.
- ICH Q10. Pharmaceutical Quality System.
Editorial Note
Version 1.0 establishes the evidence-based audit framework used in supplier oversight.
Evidence records
Structured registry entries linked to this lesson. Imported records may still await metadata verification.
- ISO 19011. *Guidelines for Auditing Management Systems*.imported unverified
- ISO 9001. *Quality Management Systems — Requirements*.imported unverified
- ICH Q9. *Quality Risk Management*.imported unverified
- ICH Q10. *Pharmaceutical Quality System*.imported unverified
Related
Related monographs
- Supplier Qualification
Understand how organizations assess, approve, monitor, and requalify suppliers using risk, documentation, performance history, quality agreements, testing evidence, and change-notification controls.
- Raw Material Qualification
Understand how raw materials are specified, sampled, tested, released, monitored, and linked to supplier controls, traceability, change management, and scientifically justified acceptance criteria.
Public ID TSMS-QMS-083 · Version 1.0