Outsourced activities in the GDP environment Part I: Supplier Management
Excerpt from the GMP:KnowHow Pharma Logistics (GDP), Chapter 1.3, Management of Outsourced Activities
4 min. reading time | by Simone Ferrante, Director of Quality at Fisher Clinical Services
Published in LOGFILE 17/2026
Supplier management is the systematic management of a company's relationship with its suppliers. It encompasses supplier qualification and customer audits as described in the following excerpt from GMP:KnowHow Pharma Logistics (GDP).
Which Regulations Must be Followed?
The basic requirements for systematic supplier management are set out in the standard ISO 9001:2015. It follows a risk-based approach and primarily includes the following activities:
- evaluation and selection of the suppliers (supplier assessment)
- monitoring and development of supplier performance.
Logistics services for the distribution of medicinal products (MP) and active pharmaceutical ingredients (API) additionally require compliance with the relevant EU GDP guidelines. Manufacturing activities (e.g., secondary packaging) and importation of pharmaceuticals require compliance with EU GMP guidelines. The handling of medical devices requires compliance with ISO 13485. If activities are outsourced within this scope, additional requirements must be taken into account:
- approval of the supplier by the quality management department
- qualification and monitoring of the supplier (risk-based)
- contractually regulated limitations of liability (Quality Assurance Agreement, QAA): definition of responsibilities and communication processes for activities related to quality assurance of the parties involved.
As a general rule, all outsourced GxP-relevant activities must be precisely defined, coordinated, controlled, and documented, to ensure that such activities remain under the control of the client's quality assurance system.
Qualification of Suppliers
Pharmaceutical manufacturers and companies, as well as brokers, outsource many activities that could directly or indirectly influence the quality of medicinal products to external companies, such as
- suppliers of pharmaceutical ingredients, excipients, packaging materials or equipment;
- service providers, e.g. for qualification or maintenance of premises and equipment, cleaning, pest control, microbiological monitoring, archiving or IT services;
- contract manufacturers and contract laboratories conducting manufacturing or packaging operations or analytics on behalf of customers;
- logistics companies handling storage and transportation of starting materials and products.
Although in each case it must be contractually agreed what the contract giver (client) and acceptor (contractor) are responsible for in detail, the overall responsibility always remains with the contract giver.
Before a task is assigned to a contractor, the contract giver must ensure that the contractor is able to perform the intended task, i.e., that necessary expertise and experience is present and compliance with the relevant legal regulations are known and followed (contractor qualification).
Depending on how important the outsourced activity is for product quality, this verification of suitability can vary in intensity, e.g., by evaluating self-disclosures, audit reports, and non-conformance statistics, up to and including the contractor's own audits or contracted audits.
It is the contractor's duty to perform the tasks exactly as agreed in the contract. If any changes are planned that could have an impact on product quality, the changes must be approved by the client beforehand (change control).
The client monitors the compliance with the requirements agreed in the contract. Contractor qualification is therefore not completed when the contract is signed. It must be monitored and promoted throughout the entire business relationship. The contractor's performance must be evaluated regularly. Collecting quality KPIs can reveal deviations or trends. Depending on the existing risk, customer audits must be carried out regularly.
Customer Audits
Audits of service providers or suppliers do not always have to be carried out by the customer itself. It is also possible to appoint external auditors, to merge with other interested parties to form a joint audit, or to make use of a current audit report from another company.
If an external auditor is engaged, a conflict of interest declaration must be made in addition to a contract for this activity. This is to ensure that the audit result is not dependent on whether the auditor has a personal interest in the company concerned. This would be the case if the auditor owned shares in the company.
If third parties carry out the audit, it is even more important to check whether all areas and activities of interest to the client have been in scope of the audit, and the results are satisfactory for the client.
Such an assessment and any resulting measures must be documented.
Remark: An audit does not necessarily have to be conducted on site. The Covid-19 pandemic in particular has promoted the acceptance of so-called remote audits.
Read more soon: Part II: Contractual Agreements for Outsourced Activities
Do you have any questions or suggestions? Please contact us at: redaktion@gmp-verlag.de