DEV Community

Priya Nair
Priya Nair

Posted on

Supplier qualification and audit sharing for SME medtechs — what actually works

I started running supplier qualification projects the week before a notified-body audit. Nothing sharpens your priorities like a looming audit and three suppliers that insist “our ISO certificate is enough”. To be fair, certificates are useful — but they are not a substitute for risk-based supplier control.

Below I write from four years of juggling Class IIa/IIb Technical Files, supplier audits, and the inevitable supplier CAPAs that follow. These are practical steps that have saved me time and given auditors what they actually ask for.

Why supplier qualification is not just bureaucracy

ISO 13485:2016 clause 7.4 requires purchasing controls proportionate to the product risk. In practice this means:

  • If a supplier touches a safety-critical part, you must be able to show you assessed their capability and control them.
  • If they provide a service that affects your device’s performance (sterilisation, software development, reprocessing), documentation and oversight are non-negotiable.
  • Certificates (ISO 13485, CE declarations) are a starting point, not an endpoint.

Granted, not every bolt needs an audit. The art is deciding which suppliers do.

Risk-based supplier segmentation (the most useful first step)

I segment suppliers into three buckets and treat them differently:

  • Critical: parts/processes that directly affect safety or performance (implants, sterile processes, software modules). These get full qualification: on-site audit, technical review, incoming inspection plans, contractual KPIs.
  • Important: parts that could escalate into a safety issue if they fail (connectors, housings). These get document review, remote audit or questionnaire, and periodic sampling.
  • Low: commodity items with low hazard. These get supplier certificates, receipt inspection sampling, and change-notification clauses.

A short checklist I use for the segmentation decision:

  • Does the component enter the body or contact sterile field?
  • Does the supplier perform a process you cannot audit easily later (e.g. custom moulding)?
  • Could failure reasonably create a death or serious deterioration?

If the answer to any is yes, move the supplier towards "Critical".

The audit you actually need: scope, not theatre

An audit is not an endurance test. Define the scope before you send auditors or accept shared reports.

Key scope points:

  • Processes: Which specific processes do you need evidence for? E.g. brazing, software development lifecycle, sterilisation validation.
  • Outputs: Which records prove the process? (batch records, validation protocols, release criteria)
  • Sub-suppliers: Does the supplier itself rely on subcontractors you must know about?
  • Time window: Are you reviewing a current state or historical compliance?

Remote audits and documentation reviews are acceptable for many suppliers — especially if you have strong incoming inspection and supplier KPIs. To be fair, some notified bodies still prefer on-site evidence for very critical processes. In those cases, audit sharing becomes valuable.

Audit sharing — realities, not the brochure

Audit sharing works but it has friction:

  • Confidentiality: Suppliers worry about commercial secrets. NDAs and redactions are normal — expect to remove price lists, IP schematics, and unrelated customer names.
  • Scope mismatch: A supplier audit performed for another OEM will often miss the processes you care about. Don’t accept a generic statement of “compliant” without attachments.
  • Timeliness: Shared audits older than 12–18 months often raise questions. Ask for evidence of ongoing controls (KPIs, non-conformance trend, recent change notifications).
  • Notified bodies: They may accept shared audits if you can show you reviewed the report, performed a gap analysis, and have follow-up controls under your QMS.

In short: audit sharing saves time, but you must document why the shared audit is sufficient for your device’s risk profile.

Practical checklist for accepting a shared audit

Before you rely on a supplier’s audit report, complete and file:

  • A supplier-specific risk assessment and rationale for accepting the shared audit.
  • A redaction log (what you removed and why).
  • A gap analysis mapping the shared-audit findings to your required scope.
  • Evidence of recent monitoring: incoming inspection records, lot release checks, trending of supplier non-conformances.
  • A contract clause that gives you change-notification and right-to-audit for critical processes.

This paperwork is the part auditors really read. Put it in the Technical File folder called "Supplier Controls" and link it to the change control and CAPA records — connected workflow is not optional here.

Make your eQMS do the heavy lifting

You do not need heroic spreadsheets. The features that matter:

  • Supplier Management: hold qualification records, certificates, audit reports and change notifications in one place.
  • Audit Module: one audit framework for all audit types (on-site, remote, shared) so reports are comparable.
  • Traceability: link supplier audits to incoming inspection records, change requests, and CAPAs so an auditor can see the chain.
  • Supplier KPIs and non-conformance tracking: automated CAPAs and CAPA-driven risk assessment alerts when supplier performance degrades.

To be fair, vendors will promise magic. I care about two things: can I run a single supplier report that shows history and links to CAPAs, and can I see change-impact mapping from a supplier change to the Technical File? If yes, that tool pays for itself.

A few negotiation tactics that work

  • Offer a redaction protocol template — many suppliers accept this because it saves legal time.
  • Present a short scope document before requesting the audit report. Suppliers often redact more when they don’t know what you need.
  • Use remote audit as a stepping stone: ask for a short video or live walkthrough of the process area if they won’t agree to an on-site visit.

Final thought

Supplier qualification is not a one-off project. It’s a continuous thread through change control, incoming inspection, and CAPA. If your QMS makes those threads hard to follow, you will spend audit time proving you’re in control rather than being in control.

How have you balanced accepting shared audits versus insisting on your own on-site audits — and what evidence convinced a notified body in your last audit?

Top comments (0)