Skip to content
Entourage
Article20 min read

Quality Agreements With Critical Suppliers

A quality agreement is not an extended purchase order. It is the operating interface between two quality management systems. Which audit, change and cost rules it has to carry so that it gives a clear answer when it matters.

DH

Diana Hohage

Principal Consultant

In brief

Rights, obligations and control mechanisms for critical suppliers and outsourced processes: audit types and notified body access, change categories A to D, cost models, and the line between outsourced execution and manufacturer responsibility.

A quality agreement is not an extended purchase order. It is the operating interface between the manufacturer's quality management system and the supplier's quality management. The more critical the product, the service or the outsourced process, the more precisely responsibilities, change rights, audit and access rights, documentation duties, escalation paths and cost rules have to be defined.

1. Summary

A manufacturer may transfer activities and processes to suppliers or external service providers. What it cannot transfer is overall regulatory responsibility for the conformity of the medical device, the effectiveness of the quality management system or the adequacy of the risk controls. The MDR explicitly requires the quality management system to cover the selection and control of suppliers and subcontractors. Where design, manufacture, final verification, testing or parts of them are carried out by third parties, the manufacturer has to define and demonstrate the type and extent of its control over those parties.

For critical suppliers and outsourced processes, a quality agreement is therefore regularly required. It has to be risk based and supplier specific. A universal standard form with generic audit and information duties is not sufficient where a supplier runs a validated special process, produces documentation with regulatory relevance, develops software, performs testing or influences essential product characteristics.

Guiding principle: Outsourcing may change who performs the work, not who is accountable. The supplier can take over activities; the manufacturer's decision authority and regulatory accountability remain in place.

TopicRecommendation
Need for an agreementFor all critical suppliers and outsourced processes; for less critical suppliers only where the required extent of control cannot be covered adequately by purchase order, specification and general purchasing terms.
Audit rightsRegulate qualification, routine, for cause, follow up and regulator audits separately. Rights of the notified body and authorities must not be blocked by notice periods, cost approvals or effort caps.
CostsDefine up front who bears travel, personnel, translation, data provision and third party costs. Caps may be agreed for routine audits; for authority or notified body audits, caps may only affect commercial consequences, never the access required by regulation.
ChangesNot simply "notify every change". Categories are needed: administrative or formal, process or QMS related without expected impact, potentially product or performance relevant, and emergency change. For each category, define the deadline, the information package and whether consent is required.
ResponsibilitiesFor specifications, test plans, validations, releases, deviations, complaints, CAPA, vigilance, documentation and retention it must be unambiguous who prepares, reviews, approves, informs and decides.

2. Regulatory starting point

2.1 Manufacturer responsibility and supplier control

Under Article 10(9) MDR, the quality management system has to cover all parts of the manufacturer's organisation that influence the quality of processes and products. This expressly includes the selection and control of suppliers and subcontractors. The MDR does not prescribe a contract labelled "quality agreement", but it does require documented and effective control of externally provided work.

Annex IX MDR makes this concrete: where design, manufacture, final verification, testing or parts of them are carried out by another party, the manufacturer has to describe the type and extent of its controls over that party. A purchase order alone is regularly insufficient where critical activities, specialised processes or regulatory evidence are outsourced.

2.2 Access for the notified body and competent authorities

The notified body may include suppliers or subcontractors in its audit planning. Supplier audits are particularly relevant where the conformity of the finished device is materially influenced by the supplier's activity, or where the manufacturer cannot otherwise demonstrate its control sufficiently. The MDR also provides for periodic and, where appropriate, unannounced audits at suppliers or subcontractors.

Consequence for the agreement: The supplier has to accept contractually that not only the manufacturer, but to the extent required by regulation also its notified body and competent authorities, may be granted access to relevant premises, processes, records, systems and personnel. An agreement that permits audits only "by mutual scheduling" is regularly inadequate for critical suppliers.

2.3 ISO 13485 as the QMS framework

ISO 13485:2016 provides the central QMS framework for medical devices. For quality agreements, the requirements on outsourced processes, risk based supplier control, purchasing information, verification of purchased product, process validation, control of records and handling of nonconforming results are particularly relevant. The agreement translates those requirements into concrete interfaces that bind both parties.

3. A risk based approach: when is an agreement required?

Not every supplier needs a comprehensive quality agreement. The extent of control should be derived from the criticality of the supplied product, the service provided and the outsourced process. Internal labels such as "critical supplier", "high risk supplier" or a company specific supplier class are management instruments of the manufacturer and not in every case regulated terms in their own right.

Assessment criterionGuiding question
Impact on safety and performanceCan a failure of the supply or service affect the safety, clinical performance, essential performance characteristics or risk controls of the device?
Verifiability at goods receiptCan the manufacturer verify conformity completely and non destructively, or does it have to rely on process control and supplier evidence?
Regulatory functionDoes the supplier produce or maintain regulated evidence, test reports, software, validation data, technical documentation or QMS records?
Validated or special processIs the result not fully verifiable by downstream inspection, for example in sterilisation, coating, cleanroom processes, heat treatment or software development?
Change riskCan an internal change at the supplier silently affect specification, validation status, test methodology, traceability or approval status?
Supply and concentration riskIs there single source dependency, a long replacement lead time or a material impact on the ability to supply?

Recommended internal rule: For all suppliers classified internally as critical or high risk, and for all outsourced processes, an approved quality agreement is required before series production or service start. Deviations have to be justified, approved on a risk basis and limited in time.

4. Minimum content of a robust agreement

  • Contracting parties, sites, products, part numbers, services and outsourced processes in scope
  • Document hierarchy and precedence rule in case of contradictions between supply contract, quality agreement, specification, drawing, purchase order and test plan
  • Roles, responsibilities and approval authority
  • Applicable regulatory, normative and customer specific requirements
  • Specifications, inspection and release criteria as well as the required quality evidence
  • Change management including categorisation, deadlines and consent requirements
  • Deviations, concessions, nonconformities, traceability and blocking measures
  • Complaints, root cause analyses, CAPA, vigilance and FSCA support
  • Audit and access rights of the manufacturer, the notified body and competent authorities
  • Cost rules for audits, additional effort, investigations and regulatory support
  • Control of critical sub suppliers and flow down of the agreement's obligations
  • Documentation, retention, data integrity and release obligations
  • Business continuity, emergency management, termination and handover in case of supplier change

Document architecture: The agreement should not repeat every individual technical requirement. A stable main contract with general quality rules plus supplier specific annexes works better, for example scope, responsibility matrix, approved specifications, change matrix, audit and cost matrix as well as contact and escalation paths.

5. Audit rights: scope, cause, notice and costs

5.1 Regulate audit types separately

Audit typeTypical causeNote on notice
Qualification auditBefore initial approval or on material scope extensionUsually plannable; scope based on criticality
Routine or surveillance auditPeriodic, based on risk class, performance or audit programmeReasonable notice, typically several weeks
For cause auditSerious deviation, repeated quality problems, complaint, safety or conformity signalShortened notice; immediate where the situation is acute
Follow up auditEffectiveness check after findings, CAPA or escalationPlannable; limited to the effectiveness check
Regulator auditAudit by the notified body or an authority, including unannounced auditsNo contractual minimum notice as a precondition of access

5.2 What may be audited?

The scope should be limited to the areas relevant to the supplied product, the service or the outsourced process. This may include QMS processes, production and test equipment, validation documentation, qualifications, traceability, sub supplier control, deviations, CAPA, change records and relevant quality records. The supplier may protect legitimate confidentiality interests, but not in a way that makes the evidence required by regulation impossible to produce.

5.3 Costs and effort caps

The MDR does not regulate how manufacturer and supplier allocate the commercial cost of a supplier audit between them. That question therefore belongs expressly in the quality agreement or the supply contract. Unclear cost clauses regularly lead to audit rights being blocked in practice or negotiated only once escalation has already happened.

Audit or serviceRecommended cost modelPossible limitation
Routine auditEach party bears its own personnel cost as a matter of principle; travel and third party costs according to a rule defined in advance.A maximum number of auditors, audit duration or budget may be agreed, provided the necessary scope remains achievable.
For cause auditWhere there is legitimate cause, differentiate first by root cause. Where a supplier side deviation is confirmed, reasonable additional cost may be allocated to the supplier.No rigid cap where scope and risk only become apparent during the audit.
Follow up auditLink the cost rule to the outcome of the initial audit and to responsibility for the findings.Limit the scope to the effectiveness check.
Notified body or authorityInternal cost of participation with the supplier as a matter of principle; external notified body or authority fees according to the applicable contract and fee model. Recharging only under a rule defined in advance.No effort cap may limit the required access, the audit depth or the duration of the regulatory review.
Special servicesRegulate translation, data reconstruction, laboratory testing, expedited provision or work outside normal hours separately.Prior cost estimate, provided the regulatory purpose is not delayed by it.

Important: For audits by the notified body or competent authorities, the agreement must not make prepayment, a purchase order, cost approval, a maximum number of auditors or a maximum audit duration a precondition of access. Commercial questions may be settled afterwards; access required by regulation has to remain possible.

6. Change management: notification is not consent

The wording "the supplier informs the manufacturer of all changes" is too vague. It creates neither a clear review duty nor a reliable prohibition on implementation. An agreement should categorise changes by their possible impact and define, for each category, whether subsequent notification, prior notification or express written consent is required.

Caution: A "formal change" is not automatically a safe low risk category. Changes of company name, legal form, manufacturing site, certificate, ownership structure or critical personnel can be significant in regulatory or quality terms and regularly belong at least in a prior notification or consent category.

CategoryExamplesNotificationRelease principle
A: purely administrative or formalChange of contact persons; internal format or numbering change without effect on traceability; editorial correction without change of meaningSubsequent notification or collective report within a defined periodNo consent required, provided the absence of impact is documented
B: process or QMS related without expected impactInternal process change; replacement of non critical equipment; organisational change; adjustment of a test sequence with unchanged criteriaPrior notification with documented impact assessmentManufacturer may request evidence or object; consent before implementation for critical processes
C: potentially product, performance or specification relevantMaterial, formulation, dimension, tolerance, software, algorithm, process parameter, test method, acceptance criterion, production site, validated equipment, sterilisation, packaging, shelf life, critical sub supplierPrior full change notificationExpress written consent before implementation and before delivery of affected goods
D: emergency changeUnplanned change to avert an acute quality, safety or supply situationImmediate notification, initial risk assessment, containment and affected batchesNo delivery until the manufacturer decides, unless an emergency rule has been approved in writing

6.1 Minimum content of a change notification

  • Description and justification of the change
  • Affected products, part numbers, processes, sites, sub suppliers and documents
  • Planned implementation date and first affected batch or version
  • Technical, regulatory and risk related impact assessment
  • Assessment of specification, validation status, test methods, biocompatibility, sterility, software, shelf life and traceability, where relevant
  • Required verification, validation, samples, comparative data or requalification
  • Transition rule, remaining stock, dual sourcing and identification of affected deliveries

7. Responsibilities: what can be outsourced and what stays with the manufacturer?

A quality agreement has to distinguish between performing an activity and holding regulatory responsibility. Many operational activities may be carried out by a supplier. Decision authority, oversight and responsibility for conformity remain with the legal manufacturer.

TopicExecution that can be outsourcedManufacturer responsibility that cannot be transferred
Intended purpose, claims, classification and conformity strategyCan be supported technicallyDefinition and approval by the manufacturer
Technical specification and acceptance criteriaSupplier may provide draft and feasibility inputManufacturer approves product and risk relevant requirements
Design and development workExecution possible in whole or in partDesign authority, design release, risk assessment and regulatory involvement stay with the manufacturer
Process validationSupplier may prepare, execute and report the protocolManufacturer defines the required extent of evidence and approves suitability for its device
Testing and release at the supplierOperational testing and certificate issuance possibleManufacturer determines the acceptance and monitoring model and remains responsible for product conformity
Deviation or concessionSupplier assesses and proposes dispositionUse of nonconforming critical supply only after a documented manufacturer decision
Complaint investigation and root cause analysisTechnical investigation and data provision by the supplierRegulatory classification, reporting duty, CAPA and FSCA decision by the manufacturer
PMS, vigilance and authority communicationSupplier provides information and supportSystem responsibility and regulatory reporting remain with the manufacturer
Document retentionPhysical or electronic custody possibleManufacturer has to ensure access, legibility, integrity and regulatory availability

Not outsourceable in practical terms: The manufacturer may purchase advice, preparation and operational execution. It has to remain able, however, to judge the adequacy of the results, approve decisions, meet regulatory obligations and account for them to the notified body and authorities. An agreement must therefore not create a black box.

8. Specifications, documents and data ownership

8.1 Specification responsibility

The agreement should define which specification describes the binding target state, who prepares it, who reviews it and who approves changes. The manufacturer should control the product and regulatory relevant requirements. The supplier remains responsible for the technical control of its process and for the consistency of its internal working documents with the approved specification.

DocumentPreparationApproval and controlPurpose
Manufacturer specification or drawingManufacturerManufacturerBinding product or service requirement
Supplier specification or manufacturing instructionSupplierSupplier; manufacturer receives the relevant extent of evidenceInternal process control
Test plan or control planJointly or by the supplier, depending on the modelManufacturer approves critical characteristics and acceptance criteriaVerification of the delivery
Validation protocol and reportSupplier or jointlyManufacturer approves suitability for the outsourced processEvidence of reproducible process performance
CoC, CoA or test reportSupplierSupplier releases; manufacturer defines required content and useBatch or delivery related conformity evidence
Risk related interface documentsJointlyManufacturerTranslation of product and process risks into controls

8.2 Retention and access

  • Retention periods have to match the product life cycle and the regulatory deadline; "according to the supplier's internal rules" is not sufficient.
  • The manufacturer needs a right to timely release of legible copies, including after end of contract, site closure or insolvency.
  • Electronic records have to secure integrity, version, release status, change history and retrievability.
  • The supplier must not destroy, migrate or archive regulated original data in an illegible form without consent.
  • Confidentiality and IP protection have to be regulated, but must not prevent regulatory access.

9. Nonconformities, complaints, CAPA and field actions

For critical supplies it has to be clearly regulated when the supplier informs the manufacturer and which decisions it may not take on its own. Blanket supplier rights to rework, to substitute material or to use "equivalent" components without prior consent are particularly problematic.

EventNotificationExpected initial measures
Critical deviation or possible safety or conformity riskImmediately, typically within 24 hoursStop shipment, containment, affected batches, initial risk assessment, contact person
Material deviation without immediate safety riskWithin a defined short period, for example 2–3 working daysDescription, extent, affected deliveries, planned disposition
Minor deviationAccording to the agreed reporting or escalation modelTrendable recording and periodic evaluation
Complaint or field informationImmediately upon becoming awareAll available technical data; no independent external communication without alignment, as far as legally permissible
  • No use, rework, repair or concession for nonconforming critical goods without documented consent of the manufacturer.
  • Duty to identify all potentially affected batches, serial numbers, versions and delivery periods.
  • Agreed deadlines for root cause analysis, correction, CAPA plan and evidence of effectiveness.
  • Support with authority enquiries, vigilance reports, FSCA, recalls and customer communication.
  • Right of the manufacturer to have its own tests performed where the investigation is inadequate, and to pass on reasonable cost under the agreed rule.

10. Sub suppliers and business continuity

10.1 Critical sub suppliers

The direct supplier must not move critical activities into a supply chain that is invisible to the manufacturer. The agreement should therefore define which sub suppliers require prior approval, which changes have to be notified and how audit and access rights are passed on.

  • Prior consent for new or changed critical sub suppliers
  • Flow down of the relevant quality, change, documentation and audit obligations
  • Transparency about manufacturing and test sites as well as outsourced special processes
  • Traceability down to the critical sub supplier
  • Right of the manufacturer or the notified body to direct or mediated access

10.2 Security of supply and termination

  • Emergency and restart planning for critical processes, equipment, IT systems and sites
  • Duty to report fire, cyber attack, natural event, loss of certificate, insolvency risk or regulatory action
  • Minimum stock, safety stock or agreed last time buy rules, where required
  • Handover of tooling, data, validation documentation and quality records at end of contract
  • Continued application of confidentiality, retention, complaint and authority support obligations after end of contract

11. A recommended modular model

Instead of writing a completely new agreement for every supplier, a modular approach is advisable. The general main body contains stable ground rules. Supplier specific and product related content is maintained in annexes. This keeps the agreement manageable without diluting critical detail.

Building blockContent
Main bodyGeneral quality principles, audit, changes, nonconformities, CAPA, sub suppliers, retention, term and termination
Annex 1: scopeProducts, part numbers, services, sites, critical processes and certificates
Annex 2: responsibility matrixRACI or comparable allocation for specification, testing, release, validation, complaint, CAPA and documentation
Annex 3: quality evidenceCoC, CoA, test reports, validation documentation, batch documentation and submission deadlines
Annex 4: change matrixChange categories, examples, deadlines, data package and consent requirement
Annex 5: audit and cost matrixAudit types, notice, scope, cost allocation and effort limits
Annex 6: KPIs and escalationQuality, delivery performance, complaints, CAPA, audit findings, escalation levels and review frequency
Annex 7: contactsOperational, technical, quality, regulatory and emergency contacts

12. Typical weaknesses of existing agreements

WeaknessRisk
"Audit subject to prior alignment"Does not cover for cause and unannounced regulator audits.
"Changes are to be notified"No definition of change, deadline, data scope or consent requirement.
"The supplier meets all statutory requirements"Shifts responsibility wholesale, without concrete interfaces and evidence.
No cost ruleAudit or investigation rights are blocked in an emergency by after the fact price negotiation.
No sub supplier ruleCritical processes can be moved on without the manufacturer's knowledge.
Unclear specification ownershipContradictions between drawing, supplier data sheet, purchase order and test plan remain unresolved.
No rule for open complaints after end of contractThe supplier can stop support while regulatory deadlines continue to run.
Agreement without risk based supplier classificationIdentical clauses for office supplies, a calibration laboratory and a critical contract manufacturer lead to over or under control.

13. Concrete next steps

  • Review the supplier classification and the criteria for critical or high risk suppliers and document them bindingly.
  • Compile a list of all critical suppliers and outsourced processes; review existing agreements for coverage and currency.
  • Anchor a binding requirement for agreements with critical suppliers and outsourced processes in the purchasing or supplier management process.
  • Restructure the standard agreement into a main body and supplier specific annexes.
  • Introduce the audit and cost matrix and the risk based change matrix as mandatory annexes.
  • Prepare a responsibility matrix for every critical supplier and reconcile it with specification, test plan and risk management.
  • Review existing supply contracts for contradictions with audit, cost, liability, IP and termination provisions.
  • Review agreements periodically and on cause, in particular on changes of scope, site, certificate, process or sub supplier.

A good agreement is detailed, but not unnecessarily long. Its quality shows in whether it gives an unambiguous answer in a concrete situation: may the supplier change something? Does it have to ask first? Who decides on a deviation? Who pays for a for cause or notified body audit? Which documents have to be available? Who supports a complaint, CAPA or FSCA? Where those questions stay open, the agreement exists formally but does not hold up operationally.

14. Regulatory references

  • Regulation (EU) 2017/745 (MDR), in particular Article 10(9) as well as Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4.
  • Regulation (EU) 2017/745, Annex VII, section 4.5.2 on audit planning and the possible audit of suppliers and subcontractors.
  • European Commission Notice 2021/C 8/01 on the use of supplier and subcontractor audits within the QMS assessment.
  • ISO 13485:2016, Medical devices, quality management systems, requirements for regulatory purposes.
  • Note on citing standards: the specific clause allocation and wording should be checked against the licensed version of the applicable standards and against the manufacturer's certification and contract model.

Relevant for your project?

Similar questions in your current project?

In a first call we clarify what is specifically relevant for your situation, without obligation.

Request a call

Life Science Journal

Regulatory updates, straight to your inbox.

New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.

Regulations & standards considered

  • Regulation (EU) 2017/745 (MDR), Art. 10(9) (QMS, selection and control of suppliers and subcontractors)
  • Regulation (EU) 2017/745 (MDR), Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4
  • Regulation (EU) 2017/745 (MDR), Annex VII, section 4.5.2 (notified body audit planning)
  • ISO 13485:2016 (quality management systems for medical devices, outsourced processes)
  • European Commission Notice 2021/C 8/01 (supplier and subcontractor audits)
Sources
  • Regulation (EU) 2017/745 (MDR): primary text, in particular Art. 10(9) and Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4
  • Regulation (EU) 2017/745 (MDR), Annex VII, section 4.5.2 on audit planning and the possible audit of suppliers and subcontractors
  • European Commission Notice 2021/C 8/01 on the use of supplier and subcontractor audits within the QMS assessment
  • ISO 13485:2016, Medical devices, quality management systems, requirements for regulatory purposes
  • First published by the author on LinkedIn on 30 July 2026: https://www.linkedin.com/pulse/qualit%C3%A4tssicherungsvereinbarungen-qsv-diana-hohage-spsaf/

Your project

Have a concrete project?

Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.

Prefer direct? +39 02 8904 1000
info@theentourage.it

  • Reply usually within one working day
  • 4 offices: DE · CH · IT · US
  • 100% life sciences