At a glance
- The vendor management SOP and the vendor management plan are different documents doing different jobs. Inspectors expect both.
- The SOP is your standing procedure: how your organisation manages any vendor. The plan is study-specific: how you manage the vendors on this trial.
- “Process” is the third word people confuse with these two; it is the workflow the SOP describes, not a separate controlled document.
- Each document has required contents. A plan that does not name vendors, owners, oversight activities, and escalation is a template, not a plan.
- The documents must cross-reference the oversight and audit activities they govern, so the paper and the practice match.
This is the documentation layer of vendor management in clinical trials; the activities these documents govern are described in vendor oversight.
Plan, SOP, and process: three words, three jobs
The confusion between these three terms is not pedantic. It causes real gaps, because a team that thinks it has “the vendor management document” usually has one of the three and is missing the others.
- The SOP (standard operating procedure) is your standing, organisation-level procedure: how you select, qualify, oversee, and close out vendors in general, regardless of trial. It is owned by quality, version-controlled, and applies across studies. It answers “how do we do vendor management here.”
- The vendor management plan is study-specific. It applies the SOP to a particular trial: which vendors this trial uses, their risk tiers, who oversees each, what activities and cadence apply, and the escalation path for this study. It answers “how are we managing the vendors on this trial.”
- The process is the actual workflow, the sequence of steps, that the SOP describes. It is not usually a separate controlled document; it is what the SOP documents.
The relationship is simple once stated: the SOP defines the method, the plan applies it to a study, and the process is the method in motion. ICH E6(R3) supports the split implicitly by expecting both documented procedures and study-specific planning. Its risk-management provisions, for instance, ask the sponsor to document and communicate the identified risks and the control measures, which is exactly the kind of study-specific content a plan carries on top of a standing SOP.
What the vendor management SOP must contain
A vendor management SOP is the durable procedure, so it covers the method rather than any one study’s vendors. At minimum it should define: the vendor lifecycle stages your organisation follows (selection, qualification, contracting, oversight, performance, close-out); how vendors are risk-tiered and how the tier sets oversight depth; the qualification and requalification approach, including audit triggers; roles and responsibilities for vendor management across functions; how oversight activities are documented; and how noncompliance and escalation are handled. The SOP is where your organisation’s standard lives, and it is what an auditor reads to understand how you intend vendor management to work before checking whether a given study did it.
A good SOP resists two temptations. It should not bloat into a study-specific document by naming particular vendors or trials, because that is the plan’s job and it makes the SOP brittle. And it should not be so generic that it provides no actual method, the “manage vendors appropriately” SOP that says nothing. The test is whether a new team member could read the SOP and know how your organisation tiers a vendor, what triggers a requalification, and who owns an escalation. If the SOP only makes sense to the person who wrote it, it is not yet a procedure.
What the vendor management plan must contain
The study vendor management plan is where the SOP meets reality. A workable plan, for one trial, names:
- The vendors and their scope. Each vendor on the trial, the activities transferred to it, and a pointer to the agreement that transferred them. ICH E6(R3) expects agreements with service providers to be documented before activities begin, so the plan should reference, not duplicate, those agreements.
- Risk tier per vendor. The risk rating that sets how closely each vendor is overseen, consistent with the trial’s critical-to-quality factors.
- Oversight activities and cadence. What oversight each vendor receives, the metrics tracked, and how often, tailored to risk. ICH E6(R3) requires oversight to be fit for purpose and proportionate to the trial’s risks, and the plan is where that proportionality is written down per vendor.
- A named owner per vendor. Accountability that is a person, not a function.
- Escalation and decision rights. What triggers escalation, to whom, and who can act.
- The link to the monitoring plan. Where vendor oversight intersects monitoring, the plan should connect to the monitoring plan, which ICH E6(R3) and FDA’s risk-based monitoring guidance both expect to be tailored to identified risks and to describe monitoring approaches, communication of results, and management of noncompliance.
A plan that contains those elements can actually be run. A plan that is a generic template with the trial name pasted on top cannot, and an inspector can tell the difference in about a minute.
In practice the plan is short and living, not long and static. A useful pattern is a two-to-four page document with a vendor table at its core: one row per vendor, with its transferred scope, risk tier, owner, oversight activities and cadence, and escalation contact. The narrative around the table explains the trial-specific reasoning, why a vendor is tiered as it is, and what changes during the study would trigger a re-look. Kept that way, the plan is something the study team opens during the trial, not a document written once for a binder and reopened only when an audit forces it.
Close-out deserves its own line in both documents, because it is the stage most often left undocumented. The SOP should define how a vendor relationship ends in an orderly way, the return or transfer of data and records, the revocation of access, and the final reconciliation, and the plan should record that it happened for each vendor on the trial. An inspection late in a trial’s life often finds vendor management strong at the start and silent at the end, precisely because no document made close-out a required, evidenced step.
Make the documents cross-reference reality
The most common documentation failure is not a missing document; it is a set of documents that do not connect to each other or to what actually happened. The plan should reference the SOP it implements, the agreements that transferred obligations, the monitoring plan, and the risk assessment that set the tiers. The oversight records generated during the trial should trace back to the activities the plan specified. When those links exist, the documentation tells a coherent story: here is our method, here is how we applied it to this trial, and here is the evidence we followed it. When they do not, you have a folder of documents that each look fine and collectively prove nothing.
A concrete example helps. Suppose your plan tiers the EDC vendor as high-risk and specifies monthly metric review and an annual audit. The cross-references should let an inspector walk from that line in the plan to the risk assessment that justified the tier, to the agreement that defined the vendor’s obligations, to the actual records of the monthly reviews and the audit report, and to any escalations those reviews triggered. That walk, from plan to evidence and back, is what a coherent document set makes possible, and it is one of the most convincing things an oversight programme can put in front of an inspector.
Where the documents go wrong
- One document doing two jobs. A single “vendor management document” that is neither a true standing SOP nor a real study plan, so both roles are half-done.
- A plan that is a template. Generic contents with no named vendors, owners, or cadence. It satisfies a checklist and governs nothing.
- No cross-references. Plan, SOP, agreements, and monitoring plan that do not point at each other, so the paper trail does not connect.
- Documents that drift from practice. A plan that describes oversight nobody performed, which is worse than no plan, because it documents a gap.
Where VendorVigilance fits. The plan-versus-SOP distinction is really about turning a standing method into per-study, per-vendor application without rebuilding it each time. VendorVigilance is configured, not coded: template libraries for qualifications, selections, risk assessments, KPIs, and vendor types, all customisable in the application, so your standing method is encoded once and applied to each study through the global study filter. The oversight activities the plan specifies are then recorded against each vendor on a 21 CFR Part 11-compliant audit trail, so the document and the evidence stay connected rather than drifting apart. Explore the product.
The bottom line
Keep the SOP and the plan distinct and make each do its job: the SOP is your standing method, the plan applies it to a specific trial with named vendors, tiers, owners, activities, and escalation. Connect them, and connect both to the agreements, the risk assessment, and the monitoring plan. Done that way, the document set is not paperwork you produce for inspection; it is the operating manual your team actually runs the trial’s vendor oversight from.
Sources
Dejan Murko
Dejan is the co-founder of Mayet, building software for biotech and pharma teams.
