At a glance
- A vendor audit is a risk-based decision, not a calendar ritual. You audit because a vendor’s risk warrants it, not because a year has passed.
- The regulation frames audit as proportionate to trial risk, independent of routine monitoring, and run by auditors independent of the work they examine.
- There are three audit types, each triggered differently: qualification (before or early), in-process (during), and for-cause (when a signal demands it).
- An audit only matters if its findings close the loop: documented findings, corrective and preventive actions, and a feed back into the vendor’s qualified status.
- A small sponsor with limited audit days wins by spending them on the vendors whose failure would actually threaten safety or data, and documenting why the rest were not audited.
This article is the audit layer of vendor management in clinical trials. It works hand in hand with vendor qualification and feeds vendor oversight.
What an audit is, and what it is not
An audit is an independent, systematic examination of whether a vendor’s processes are capable of producing compliant, reliable work. ICH E6(R3) draws the line precisely: the purpose of a sponsor’s audit, which is independent of and separate from routine monitoring or quality control functions, is to evaluate whether the processes put in place to manage and conduct the trial are appropriate to ensure compliance with the protocol, GCP, and the applicable regulatory requirements.
Two words in that sentence carry weight. Independent: an audit is not your study team checking its own vendor, and ICH E6(R3) requires the sponsor to appoint auditors who are independent of the process being audited and who are qualified by training and experience. Separate: an audit is not monitoring. Monitoring tracks the conduct and data of the trial as it runs; an audit steps back and examines whether the vendor’s system is sound. Conflating the two leads sponsors to believe a heavily monitored vendor does not need auditing, which misunderstands what each is for.
Audit also sits alongside quality assurance more broadly. ICH E6(R3) treats quality assurance and quality control as part of the sponsor’s oversight of service-provider activities, with audit as the independent, periodic check within that system. The audit is the deepest assurance you have that a vendor’s processes are real, which is exactly why it should be aimed where assurance is most needed.
When to audit: risk sets the trigger
The instinct to “audit every vendor annually” feels safe and is usually wrong. It spreads a scarce resource evenly across vendors whose risks are not even, which under-audits the dangerous ones to fund audits of the harmless ones. The regulation points the other way. ICH E6(R3) states that, when performed, audits should be conducted in a manner that is proportionate to the risks associated with the conduct of the trial, and ties this to the sponsor’s identification of the risks that may have a meaningful impact on the factors critical to quality. FDA’s risk-based monitoring guidance reflects the same philosophy across oversight generally: focus assurance on the most critical parameters rather than applying uniform effort everywhere.
So the trigger for an audit is risk, expressed three ways: the inherent risk of the vendor’s activity (does it touch the primary endpoint, participant safety, or critical data?), the assurance you already hold (a vendor with a recent clean audit and strong performance data needs less than a new, unproven one), and any signal that something is wrong. A risk-based audit schedule is therefore not a fixed grid. It is a defensible set of decisions about which vendors get audited, how deeply, and how often, with the rationale written down so the gaps are choices rather than oversights.
The three audit types
A mature program uses audit type deliberately:
- Qualification audit. Performed before a high-risk vendor starts, or early in the engagement, to confirm the provider’s quality system is fit for the work. This is the audit that gives a qualification its highest assurance.
- In-process (periodic) audit. Performed during the engagement to confirm the vendor is still operating to standard, timed to the vendor’s risk tier. A common and sensible pattern is a qualification audit up front, an in-process audit somewhere in the middle of a multi-year relationship, and longer intervals thereafter when performance and a robust vendor management plan justify it.
- For-cause audit. Triggered by a specific signal: a serious quality event, a pattern of performance failures surfaced by oversight, a regulatory finding elsewhere, or a major change at the vendor. A for-cause audit is targeted at the problem rather than the whole system.
Choosing the type is itself a risk decision. A clean, well-performing vendor may move from qualification audit to a longer in-process interval; a vendor throwing quality signals may earn a for-cause audit well ahead of any schedule.
What a GCP vendor audit checks
The scope follows the vendor’s activities, but a vendor audit checklist generally covers: the quality management system and SOPs relevant to the transferred work; staff qualifications, training, and experience in the relevant area; the provider’s own internal quality control and quality assurance activities; data handling and integrity across each stage the vendor performs; computerised system validation where applicable; subcontractor management, since the sponsor’s oversight extends to work the vendor further subcontracts; and the provider’s handling of deviations, CAPAs, and prior audit findings. A written audit plan, scoped to the specific vendor and the stages of work it performs, keeps the audit focused on what actually carries risk rather than a generic sweep.
How the audit is conducted matters as much as what it covers. An on-site audit gives the deepest view and is the default for the highest-risk vendors, but a well-run remote audit, combining document review with live system walkthroughs and interviews, is a legitimate and proportionate choice for moderate risk or where travel is impractical. A desktop review of documentation alone is the lightest form, suitable for low-risk vendors or as an interim check between fuller audits. The depth of method should track the same risk tier that drove the decision to audit in the first place, and the method you chose should be recorded in the audit plan so the level of assurance is clear later.
Findings have to close the loop
An audit that produces a report and nothing else is wasted effort. The value is in the loop that follows: findings are documented and risk-rated, the vendor commits to corrective and preventive actions with owners and dates, and the closure of those actions is verified rather than assumed. Critically, audit outcomes feed back into the vendor’s qualified status and risk tier. A serious finding may shorten the requalification interval, narrow the scope of work the vendor is trusted with, or, where significant noncompliance persists despite remediation, lead the sponsor to consider terminating the vendor’s participation and to notify the regulatory authorities and IRB/IEC, as ICH E6(R3) requires. The audit is only as good as the action it drives.
For a sponsor with only a handful of audit days a year, this comes down to a kind of arithmetic: you cannot audit everyone, so you audit where a failure would do the most harm, and you document the rationale for the vendors you chose not to audit this cycle. That documented rationale is not an admission of weakness. It is the evidence that your coverage was a deliberate, risk-based plan rather than whatever happened to fit the calendar. An inspector is far more comfortable with a sponsor that audited the three vendors that mattered and explained the rest than with one that audited everyone shallowly and caught nothing.
Where audit programs go wrong
- Calendar-driven, not risk-driven. Auditing everyone on the same annual cycle burns days on low-risk vendors and starves the high-risk ones.
- No independence. An audit run by the team that manages the vendor is a self-assessment wearing an audit’s clothes.
- Findings with no closure. Reports pile up; CAPAs are not verified; the same finding recurs next year.
- Audit disconnected from qualification. When audit outcomes never update the vendor’s qualified status or tier, the program generates paperwork instead of assurance.
How VendorVigilance helps. A risk-based audit program needs the audit, its findings, and the vendor’s qualification and risk profile to live together, not in separate files. In VendorVigilance, audits run within the Qualifications module, audit findings and CAPAs are tracked as one of the six clinical risk types in RIM, and both attach to the vendor’s record alongside its tier and qualified status, all on a 21 CFR Part 11-compliant audit trail. So a finding does not just get logged; it visibly changes the vendor’s risk picture and the oversight that follows. Explore the product.
The bottom line
Build the audit program around risk, not the calendar. Decide which vendors warrant which audit type and depth, keep auditors independent of the work they examine, scope each audit to what actually carries risk, and close every finding through to a verified CAPA that updates the vendor’s status. Audit days are scarce; spend them where a failure would hurt, and write down why you spent them there.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
