Vendors & Audits¶
Small pharma operations depend on a network of suppliers and service providers — contract manufacturers, contract labs, raw-material suppliers, calibration vendors, and IT vendors handling GxP data. This module keeps your approved-supplier list and your audit program together, because they share so much workflow that splitting them would just duplicate effort.
You'll use this module as Procurement/Operations proposing a new vendor, a QA Owner running qualifications and audits, an Auditor conducting an audit and logging findings, an Auditee responding to findings, a CAPA Owner closing out what an audit turned up, or a Quality role holder approving vendor status and signing the summary report.
Add a vendor¶
-
Click New Vendor and enter the vendor name, scope of supply, and criticality tier.
Tier Typical example Default audit interval Tier 1 — Critical Active substance supplier, contract manufacturer, GxP IT vendor 12 months Tier 2 — Significant Excipient supplier, contract lab, GxP-adjacent IT 24 months Tier 3 — Minor Non-GxP-impacting vendor, office supplies 36 months or on-demand -
The vendor starts with approval status On Hold until qualification is complete (see below). Your tenant's tier definitions and default intervals are set at onboarding and can be overridden per vendor.
Once added, the vendor record tracks linked records (CoAs, CoCs, calibration certificates), linked audits, and a derived next audit due date.
Qualify a vendor¶
Before a vendor can be marked Approved:
- Send the vendor your standard qualification questionnaire.
- Upload the completed questionnaire as an external record (see Quality Records).
- Attach any supporting evidence — the vendor's quality manual, certificates, or prior audit reports.
- Optionally, conduct an initial audit. Sometimes a paper-only qualification is sufficient, especially for Tier 3 vendors.
- A Quality role holder signs the Qualification Decision with meaning Authorised for release. The vendor's status moves to Approved or Conditionally Approved.
Schedule an audit¶
Audits run through a fixed lifecycle: Plan → Schedule → Conduct → Report → Findings Review → Close.
Every Tier 1 vendor must appear on your rolling annual audit plan every year; Tier 2 vendors appear at their cadence; internal functions are typically audited once a year. The plan is signed off annually by a Quality role holder, and entries can be added mid-year — for example, a for-cause audit triggered by a deviation.
To schedule a planned audit:
- Set the confirmed date and duration.
- Assign a lead auditor — an internal user, or a named external auditor. QStack tracks external auditors by name even though they don't have a system login.
- Set the auditee — the vendor or the internal function owner.
- Define the scope: which processes, products, or systems are covered.
- Attach a pre-audit document request list.
Conduct an audit and log findings¶
During the audit, the auditor uploads supporting evidence — interviews, photos, document samples — as external records, logs observations as draft findings, and captures the closing meeting outcome.
Once the audit wraps, the auditor produces the Audit Report: a structured document covering scope, methodology, sampling, and the list of findings. QStack generates the report PDF from the structured data and attaches it as a record.
Each finding captures:
| Field | What it means |
|---|---|
| Reference | Auto-assigned per audit, e.g. AUD-2026-014-F-03 |
| Description | The observation in plain language |
| Severity | Critical / Major / Minor |
| Linked process / equipment / SOP | What the finding is about |
| Auditor recommendation | Advisory only |
| Linked CAPA | Filled in once a CAPA is opened |
| Response (auditee) | The auditee's response |
After the auditor publishes findings, the auditee responds, and the QA Owner reviews each one:
- Accepted, CAPA required → opens a CAPA in Deviations & CAPA, owned by the appropriate person.
- Accepted, no CAPA required → the low-impact finding closes with rationale.
- Rejected with justification → the finding is downgraded or removed, with a Quality role signature.
Once every finding has a determined disposition, the audit moves to the final stage.
Close an audit with the Vendor Summary Report¶
Warning
No supplier audit can close without a signed Vendor Summary Report. Internal audits require the equivalent Internal Audit Summary Report — same shape, different title.
The report contains a header (vendor name, audit number, report date, prepared by), scope, methodology, a summary of findings, a findings snapshot, linked CAPAs with current status, an overall rating, a rationale, a next-audit recommendation, and the required signatures.
To generate and sign it:
- Click Generate Summary Report. QStack pre-fills every section from the audit data — the findings snapshot is frozen as of this moment, linked CAPAs are listed with their current status, and a proposed next-audit date is calculated from criticality.
- Edit the summary, rationale, and overall rating: Approved, Conditionally Approved, or Disqualified — the same scale used for vendor approval status, so the rating maps directly onto the vendor master.
- Click Send for Signature. The report enters the signature workflow with meaning Authorised for release — Quality role plus Procurement by default, configurable per tenant.
- When the last signature lands, the report becomes permanent and read-only, and the audit moves to Closed.
Why the snapshot is frozen
The Vendor Summary Report is a permanent regulatory artefact. If new evidence later causes QA to re-classify a finding, that's handled by a follow-up audit — the original report stays unchanged so the audit trail honestly reflects what was known at the time.
Scheduling the next audit¶
Setting the next audit date is part of closing the current one. QStack proposes a date; the QA Owner can accept or override it.
| Path | Used when | How the date is set |
|---|---|---|
| Criticality default | Most vendors, most of the time | Today plus the tenant's tier-default interval |
| Vendor override | A vendor needs a different ongoing cadence | The vendor's custom_audit_interval_months is used instead of the tier default |
| Custom one-off | A specific reason, e.g. an open Major finding needs a sooner recheck | A one-off date; the next cycle reverts to the criticality default unless the vendor override is also changed |
Whichever path you take, QStack records the recommended date, the cadence source, and a rationale (mandatory for custom one-off dates). All of this appears on the Vendor Summary Report, so the reasoning is permanently auditable. Afterward, the vendor's next-audit-due date updates, a placeholder appears on the next annual plan, and you get a reminder 90 days before the date to confirm and schedule.
Reporting¶
- Vendors by status and tier
- Vendors with overdue audits
- Qualifications expiring in the next 90 days
- Findings by severity by year
- Audits closed vs. planned, by quarter
- Top vendors by CAPA volume
What an inspector sees¶
QA shows the vendor master filtered to Approved, picks a critical supplier, and walks the inspector through the qualification record, audit history, and most recent Vendor Summary Report. From a CAPA in that report, the inspector can follow into Deviations & CAPA and see the effectiveness check. Asked when the next audit is, QA shows the audit plan with the recommended date and its rationale source.
What this module doesn't do¶
- It doesn't run e-questionnaire sessions — vendors fill the questionnaire offline and the QA Owner uploads it as an external record.
- It doesn't integrate directly with procurement or ERP systems.
- It doesn't generate audit travel plans, expense reports, or scheduling logistics.
- It doesn't create system accounts for external auditors — they're recorded by name, and the QA Owner uploads their evidence and reports on their behalf.