What this domain asks
Risk that suppliers, laboratories, contract manufacturers, service providers, and other external parties are selected, qualified, monitored, changed, and governed without sufficient evidence or connection to product and process risk.
The domain should retain its own evidence, decision owner, materiality criteria, exception path, and consequence even when it shares organization identity, workflow, or technology with adjacent domains. Aggregation can support oversight; it should not erase the evidence behind different risks or operating outcomes.
Buyer questions
- Can the system distinguish a commercial supplier record from the approved-site, material, service, component, and quality-agreement relationships that matter?
- How are qualification, audits, certificates, performance, deviations, complaints, changes, and corrective actions linked over time?
- Can external parties submit evidence or respond to actions without receiving inappropriate access to internal records?
- How are critical suppliers and outsourced processes identified using product and patient risk rather than spend alone?
- How do supplier changes trigger quality, validation, regulatory, labeling, inventory, and market-impact assessments?
- Can buyers retain the full supplier evidence and decision record if the relationship or software platform ends?
Mapped workflows
Controlled Documents
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for controlled documents within this domain.
Quality Events And Deviations
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for quality events and deviations within this domain.
CAPA
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for CAPA within this domain.
Change Control
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for change control within this domain.
Audit And Inspection Management
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for audit and inspection management within this domain.
Supplier Quality
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for supplier quality within this domain.
Quality Risk Management
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for quality risk management within this domain.
Regulatory Activity And Commitment Tracking
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for regulatory activity and commitment tracking within this domain.
Analytics And Management Review
A demonstration should show the trigger, source, accountable role, decision, exception, evidence, and downstream handoff for analytics and management review within this domain.
Authority context
FDA QMSR
The QMSR amends FDA's device current good manufacturing practice requirements in 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, while retaining FDA-specific statutory and regulatory requirements. FDA began using a new device inspection process when the rule became effective.
FDA drug CGMP
Parts 210 and 211 establish current good manufacturing practice requirements for drug manufacture, processing, packing, and holding, including organization, facilities, equipment, components, production controls, laboratory controls, records, reports, returned products, and complaints.
ISO 13485:2016
ISO 13485 specifies quality-management-system requirements for organizations involved in one or more stages of the medical-device lifecycle and emphasizes regulatory requirements, risk-based processes, supplier control, documentation, and product realization.
ICH Q10
ICH Q10 describes a pharmaceutical quality-system model across development and commercial manufacturing, including management responsibilities, process and product monitoring, CAPA, change management, management review, knowledge management, and quality risk management.
ICH Q9(R1)
ICH Q9(R1) provides principles and examples for systematic quality risk management across the pharmaceutical product lifecycle and addresses formality, risk-based decision-making, subjectivity, product availability, and managing risk through assessment, control, communication, and review.
EU GMP Annex 11
Annex 11 applies GMP principles to computerized systems and addresses lifecycle risk management, personnel, suppliers, validation, data, accuracy checks, storage, printouts, audit trails, change control, incident management, periodic evaluation, security, signatures, continuity, and archiving.
Relevant operating models
- Enterprise Life-Sciences EQMS
- Growth-Stage Life-Sciences EQMS
- Medical-Device Quality And Product-Lifecycle Platform
- Configurable QMS With Life-Sciences Offering
- Integrated Quality And Regulatory Platform
Evidence boundary
RegQuality Review is not a regulator, certification body, law firm, or validation authority. Its records support research and decision review; they do not establish compliance for an organization, system, release, configuration, or intended use. A provider's documented capability can identify a research candidate but cannot establish buyer-specific adequacy for this domain.