Computerized systems are widely used in the pharmaceutical industry. An important step in implementing them in a company is to make sure that the solutions:

Before selecting a computerized system supplier, the user should evaluate the parameters of the system proposed by the provider and its ability to ensure quality. Particularly important is the evaluation of how the supplier develops the software, the process of testing the system and an effectively functioning quality scheme during software production.

Typically, this type of vendor assessment is carried out through an audit, which, depending on the risk, complexity and innovation of the system, is carried out by the user.

The selection of a product or service provider should be based on diagnostics of its competence and reliability, and the need for an audit should be the result of a risk analysis, according to the GMP guidelines – Annex 11.

During the inspection, the user should evaluate the supplier and obtain properly formalized evidence of:

When evaluating a supplier and conducting an audit, there are different types of evaluation:

The decision to choose the above form of assessment should be based on a risk assessment determining the most appropriate form of supplier assessment.

computerized system supplier

For postal audit

A postal audit (using a questionnaire) can be used mainly in:

A supplier postal audit is conducted based on a system-approved questionnaire. This is a standard list of questions that, depending on the needs, can cover both general and specific issues for a particular process or product. This type of form is sent by mail to the supplier with a request to answer the questions it contains and complete the required information.

The questionnaire may include information such as

The questionnaire should be completed and returned. If discrepancies are found, corrective and preventive actions should be developed with feedback to the supplier who completed the form.

Physical on-site audit

An on-site audit of a supplier’s computerized system is not very different from methodologies conducted in-house for other suppliers and for GxP-regulated companies.

The audit process includes:

Planning and organization

  1. Defining the scope and purpose. For audits of computerized systems, the most common scope is to address: product improvement and procurement, software development, equipment manufacturing, support services or software integration, supplier’s ability to produce a quality product or service.

  2. Development of a schedule
    This involves defining several factors: the tasks and responsibilities of the auditee, describing the methods and tools for conducting the audit (document analysis, interviews with employees, observation of processes), identifying the areas to be evaluated, reviewing documentation, and preparing resources.
  1. Appointment of the audit team
    This is the selection of an appropriate team and the appointment of a lead auditor who will be responsible for planning, conducting the audit and preparing the report. The team may also include a technical expert, such as an IT specialist, who has detailed knowledge of the area in which it operates. Such support can be crucial in situations where the auditor lacks expertise in a particular area, such as IT.

An important point is to notify the audited side in advance of the place and time of the activities. These topics should be agreed upon to avoid misunderstandings and time conflicts on both sides. The lead auditor presents the action plan to the audited side.

This plan should include:

This plan must be agreed with people who are responsible for the audited area.
This avoids unnecessary repetition while maintaining clarity in the text.

 GMP - Annex 11


Supplier audit during system implementation

1. Opening meeting

The opening meeting is the first part of the audit of the computerized systems provider, which is conducted by the lead auditor.

It includes the following stages:

2. Conducting an audit

This is the most important part of the process of evaluating a vendor of computerized systems. In this stage, the team verifies the correctness of the supplier’s activities according to the agreed terms and plan.

The auditors use a checklist, prepared before the physical visit. However, it is important to remember that the questions are only meant to support the collection of evidence, not to be rigidly followed, as this can lead to missing the main objectives of the assessment and exceeding the planned time.

audits of computerized systems

During the site visit, it is important for the auditor to be flexible, adapting the approach to changing circumstances. A competent specialist is able to change work techniques according to needs and new information. Effective time management and the ability to identify relevant aspects during evidence collection are also key. They are gathered through observation, interviews with staff and verification of documentation.
The auditor should take clear notes, including references to documents and locations.

When auditing a supplier of computerized systems, it is often verified:

supplier audit ecvalidation

3. Closing meeting

During this meeting, the lead auditor (after consulting with the team) presents to the supplier (auditee) the observations that were noted during the assessment. It is important not to focus solely on problematic issues, but also to include positive aspects of the process.

This meeting is also intended to remind the purpose and scope of the assessment, present the findings with their prioritization, and inform about the deadline for sending the final report.

The auditor should thank them for the opportunity to conduct the assessment, for their cooperation and for providing the necessary information.
Identified nonconformities and observations should be classified according to the criteria contained in the audit procedure or other relevant document, in accordance with company policy. It is important that all noted nonconformities are discussed and recorded before the final meeting. This will ensure that only those issues that were clearly identified and agreed upon with the audited team will be included in the report.

Audit Report

The audit report, a key document after the assessment, should be based on facts and provide a detailed summary of the results, addressing the evidence gathered. Its main purpose is to support the decision-making process for signing a contract with a supplier.

This document is prepared by the lead auditor, who may delegate its preparation to members of the audit team, retaining oversight of the report development process.

The report contains accurate information summarizing the audit of the supplier of computerized systems carried out.

The following is a list of items that should be included in the document:

computerized systems

Corrective and Preventive Actions

Corrective and Preventive Actions (CAPA) resulting from an audit report are intended to clarify, correct and prevent deviations observed supplier of computerized systems.

This process includes identifying the problem, determining corrective actions, analysing the root cause, implementing preventive actions and documenting them. It is usually carried out by a CAPA team that includes the system owner, the quality department and, if necessary, a subject matter expert. These actions must be documented and supervised according to established responsibilities, as well as company procedures, instructions or standards. An audit is ineffective if it does not lead to corrective or preventive actions, which are central to the auditing process.

Note that the supplier’s audit procedure and audit reports are part of the system’s validation documentation – so their importance and documentation is often emphasized.

The selection of the right supplier has a tremendous impact on further work related to the proper implementation of the computerized system. Suppliers play an important supporting role: as part of the contract, suppliers take responsibility for providing key documentation, provide direct technical support as external SME’s, and perform initial system/application testing.

Vendor support is very important not only at the design, implementation stage but also during servicing, achieving and maintaining the system in a validated state throughout the system/application life cycle.

Stable systems designed, developed and implemented in accordance with good engineering practices and regulatory requirements (such as GMP – Annex 11) by suppliers are the backbone in the process of manufacturing and controlling products in GxP companies. In view of the above, it is extremely important to take a serious approach to meticulously preparing and effectively conducting audits of suppliers of computerized systems.

Kamil Melson
Professional Validation Specialist

Request a consultation

Do not hesitate to contact us to get the best services! Call us or you can leave your number below and we will contact you.

Michał Mroczkiewicz CONTACT FORM

Marianna Demczuk-Ignys CONTACT FORM

Julia Janowska CONTACT FORM