Quality Agreements With Critical Suppliers
A quality agreement is not an extended purchase order. It is the operating interface between two quality management systems. Which audit, change and cost rules it has to carry so that it gives a clear answer when it matters.
Diana Hohage
Principal Consultant
In brief
Rights, obligations and control mechanisms for critical suppliers and outsourced processes: audit types and notified body access, change categories A to D, cost models, and the line between outsourced execution and manufacturer responsibility.
A quality agreement is not an extended purchase order. It is the operating interface between the manufacturer's quality management system and the supplier's quality management. The more critical the product, the service or the outsourced process, the more precisely responsibilities, change rights, audit and access rights, documentation duties, escalation paths and cost rules have to be defined.
1. Summary
A manufacturer may transfer activities and processes to suppliers or external service providers. What it cannot transfer is overall regulatory responsibility for the conformity of the medical device, the effectiveness of the quality management system or the adequacy of the risk controls. The MDR explicitly requires the quality management system to cover the selection and control of suppliers and subcontractors. Where design, manufacture, final verification, testing or parts of them are carried out by third parties, the manufacturer has to define and demonstrate the type and extent of its control over those parties.
For critical suppliers and outsourced processes, a quality agreement is therefore regularly required. It has to be risk based and supplier specific. A universal standard form with generic audit and information duties is not sufficient where a supplier runs a validated special process, produces documentation with regulatory relevance, develops software, performs testing or influences essential product characteristics.
Guiding principle: Outsourcing may change who performs the work, not who is accountable. The supplier can take over activities; the manufacturer's decision authority and regulatory accountability remain in place.
| Topic | Recommendation |
|---|---|
| Need for an agreement | For all critical suppliers and outsourced processes; for less critical suppliers only where the required extent of control cannot be covered adequately by purchase order, specification and general purchasing terms. |
| Audit rights | Regulate qualification, routine, for cause, follow up and regulator audits separately. Rights of the notified body and authorities must not be blocked by notice periods, cost approvals or effort caps. |
| Costs | Define up front who bears travel, personnel, translation, data provision and third party costs. Caps may be agreed for routine audits; for authority or notified body audits, caps may only affect commercial consequences, never the access required by regulation. |
| Changes | Not simply "notify every change". Categories are needed: administrative or formal, process or QMS related without expected impact, potentially product or performance relevant, and emergency change. For each category, define the deadline, the information package and whether consent is required. |
| Responsibilities | For specifications, test plans, validations, releases, deviations, complaints, CAPA, vigilance, documentation and retention it must be unambiguous who prepares, reviews, approves, informs and decides. |
2. Regulatory starting point
2.1 Manufacturer responsibility and supplier control
Under Article 10(9) MDR, the quality management system has to cover all parts of the manufacturer's organisation that influence the quality of processes and products. This expressly includes the selection and control of suppliers and subcontractors. The MDR does not prescribe a contract labelled "quality agreement", but it does require documented and effective control of externally provided work.
Annex IX MDR makes this concrete: where design, manufacture, final verification, testing or parts of them are carried out by another party, the manufacturer has to describe the type and extent of its controls over that party. A purchase order alone is regularly insufficient where critical activities, specialised processes or regulatory evidence are outsourced.
2.2 Access for the notified body and competent authorities
The notified body may include suppliers or subcontractors in its audit planning. Supplier audits are particularly relevant where the conformity of the finished device is materially influenced by the supplier's activity, or where the manufacturer cannot otherwise demonstrate its control sufficiently. The MDR also provides for periodic and, where appropriate, unannounced audits at suppliers or subcontractors.
Consequence for the agreement: The supplier has to accept contractually that not only the manufacturer, but to the extent required by regulation also its notified body and competent authorities, may be granted access to relevant premises, processes, records, systems and personnel. An agreement that permits audits only "by mutual scheduling" is regularly inadequate for critical suppliers.
2.3 ISO 13485 as the QMS framework
ISO 13485:2016 provides the central QMS framework for medical devices. For quality agreements, the requirements on outsourced processes, risk based supplier control, purchasing information, verification of purchased product, process validation, control of records and handling of nonconforming results are particularly relevant. The agreement translates those requirements into concrete interfaces that bind both parties.
3. A risk based approach: when is an agreement required?
Not every supplier needs a comprehensive quality agreement. The extent of control should be derived from the criticality of the supplied product, the service provided and the outsourced process. Internal labels such as "critical supplier", "high risk supplier" or a company specific supplier class are management instruments of the manufacturer and not in every case regulated terms in their own right.
| Assessment criterion | Guiding question |
|---|---|
| Impact on safety and performance | Can a failure of the supply or service affect the safety, clinical performance, essential performance characteristics or risk controls of the device? |
| Verifiability at goods receipt | Can the manufacturer verify conformity completely and non destructively, or does it have to rely on process control and supplier evidence? |
| Regulatory function | Does the supplier produce or maintain regulated evidence, test reports, software, validation data, technical documentation or QMS records? |
| Validated or special process | Is the result not fully verifiable by downstream inspection, for example in sterilisation, coating, cleanroom processes, heat treatment or software development? |
| Change risk | Can an internal change at the supplier silently affect specification, validation status, test methodology, traceability or approval status? |
| Supply and concentration risk | Is there single source dependency, a long replacement lead time or a material impact on the ability to supply? |
Recommended internal rule: For all suppliers classified internally as critical or high risk, and for all outsourced processes, an approved quality agreement is required before series production or service start. Deviations have to be justified, approved on a risk basis and limited in time.
4. Minimum content of a robust agreement
- Contracting parties, sites, products, part numbers, services and outsourced processes in scope
- Document hierarchy and precedence rule in case of contradictions between supply contract, quality agreement, specification, drawing, purchase order and test plan
- Roles, responsibilities and approval authority
- Applicable regulatory, normative and customer specific requirements
- Specifications, inspection and release criteria as well as the required quality evidence
- Change management including categorisation, deadlines and consent requirements
- Deviations, concessions, nonconformities, traceability and blocking measures
- Complaints, root cause analyses, CAPA, vigilance and FSCA support
- Audit and access rights of the manufacturer, the notified body and competent authorities
- Cost rules for audits, additional effort, investigations and regulatory support
- Control of critical sub suppliers and flow down of the agreement's obligations
- Documentation, retention, data integrity and release obligations
- Business continuity, emergency management, termination and handover in case of supplier change
Document architecture: The agreement should not repeat every individual technical requirement. A stable main contract with general quality rules plus supplier specific annexes works better, for example scope, responsibility matrix, approved specifications, change matrix, audit and cost matrix as well as contact and escalation paths.
5. Audit rights: scope, cause, notice and costs
5.1 Regulate audit types separately
| Audit type | Typical cause | Note on notice |
|---|---|---|
| Qualification audit | Before initial approval or on material scope extension | Usually plannable; scope based on criticality |
| Routine or surveillance audit | Periodic, based on risk class, performance or audit programme | Reasonable notice, typically several weeks |
| For cause audit | Serious deviation, repeated quality problems, complaint, safety or conformity signal | Shortened notice; immediate where the situation is acute |
| Follow up audit | Effectiveness check after findings, CAPA or escalation | Plannable; limited to the effectiveness check |
| Regulator audit | Audit by the notified body or an authority, including unannounced audits | No contractual minimum notice as a precondition of access |
5.2 What may be audited?
The scope should be limited to the areas relevant to the supplied product, the service or the outsourced process. This may include QMS processes, production and test equipment, validation documentation, qualifications, traceability, sub supplier control, deviations, CAPA, change records and relevant quality records. The supplier may protect legitimate confidentiality interests, but not in a way that makes the evidence required by regulation impossible to produce.
5.3 Costs and effort caps
The MDR does not regulate how manufacturer and supplier allocate the commercial cost of a supplier audit between them. That question therefore belongs expressly in the quality agreement or the supply contract. Unclear cost clauses regularly lead to audit rights being blocked in practice or negotiated only once escalation has already happened.
| Audit or service | Recommended cost model | Possible limitation |
|---|---|---|
| Routine audit | Each party bears its own personnel cost as a matter of principle; travel and third party costs according to a rule defined in advance. | A maximum number of auditors, audit duration or budget may be agreed, provided the necessary scope remains achievable. |
| For cause audit | Where there is legitimate cause, differentiate first by root cause. Where a supplier side deviation is confirmed, reasonable additional cost may be allocated to the supplier. | No rigid cap where scope and risk only become apparent during the audit. |
| Follow up audit | Link the cost rule to the outcome of the initial audit and to responsibility for the findings. | Limit the scope to the effectiveness check. |
| Notified body or authority | Internal cost of participation with the supplier as a matter of principle; external notified body or authority fees according to the applicable contract and fee model. Recharging only under a rule defined in advance. | No effort cap may limit the required access, the audit depth or the duration of the regulatory review. |
| Special services | Regulate translation, data reconstruction, laboratory testing, expedited provision or work outside normal hours separately. | Prior cost estimate, provided the regulatory purpose is not delayed by it. |
Important: For audits by the notified body or competent authorities, the agreement must not make prepayment, a purchase order, cost approval, a maximum number of auditors or a maximum audit duration a precondition of access. Commercial questions may be settled afterwards; access required by regulation has to remain possible.
6. Change management: notification is not consent
The wording "the supplier informs the manufacturer of all changes" is too vague. It creates neither a clear review duty nor a reliable prohibition on implementation. An agreement should categorise changes by their possible impact and define, for each category, whether subsequent notification, prior notification or express written consent is required.
Caution: A "formal change" is not automatically a safe low risk category. Changes of company name, legal form, manufacturing site, certificate, ownership structure or critical personnel can be significant in regulatory or quality terms and regularly belong at least in a prior notification or consent category.
| Category | Examples | Notification | Release principle |
|---|---|---|---|
| A: purely administrative or formal | Change of contact persons; internal format or numbering change without effect on traceability; editorial correction without change of meaning | Subsequent notification or collective report within a defined period | No consent required, provided the absence of impact is documented |
| B: process or QMS related without expected impact | Internal process change; replacement of non critical equipment; organisational change; adjustment of a test sequence with unchanged criteria | Prior notification with documented impact assessment | Manufacturer may request evidence or object; consent before implementation for critical processes |
| C: potentially product, performance or specification relevant | Material, formulation, dimension, tolerance, software, algorithm, process parameter, test method, acceptance criterion, production site, validated equipment, sterilisation, packaging, shelf life, critical sub supplier | Prior full change notification | Express written consent before implementation and before delivery of affected goods |
| D: emergency change | Unplanned change to avert an acute quality, safety or supply situation | Immediate notification, initial risk assessment, containment and affected batches | No delivery until the manufacturer decides, unless an emergency rule has been approved in writing |
6.1 Minimum content of a change notification
- Description and justification of the change
- Affected products, part numbers, processes, sites, sub suppliers and documents
- Planned implementation date and first affected batch or version
- Technical, regulatory and risk related impact assessment
- Assessment of specification, validation status, test methods, biocompatibility, sterility, software, shelf life and traceability, where relevant
- Required verification, validation, samples, comparative data or requalification
- Transition rule, remaining stock, dual sourcing and identification of affected deliveries
7. Responsibilities: what can be outsourced and what stays with the manufacturer?
A quality agreement has to distinguish between performing an activity and holding regulatory responsibility. Many operational activities may be carried out by a supplier. Decision authority, oversight and responsibility for conformity remain with the legal manufacturer.
| Topic | Execution that can be outsourced | Manufacturer responsibility that cannot be transferred |
|---|---|---|
| Intended purpose, claims, classification and conformity strategy | Can be supported technically | Definition and approval by the manufacturer |
| Technical specification and acceptance criteria | Supplier may provide draft and feasibility input | Manufacturer approves product and risk relevant requirements |
| Design and development work | Execution possible in whole or in part | Design authority, design release, risk assessment and regulatory involvement stay with the manufacturer |
| Process validation | Supplier may prepare, execute and report the protocol | Manufacturer defines the required extent of evidence and approves suitability for its device |
| Testing and release at the supplier | Operational testing and certificate issuance possible | Manufacturer determines the acceptance and monitoring model and remains responsible for product conformity |
| Deviation or concession | Supplier assesses and proposes disposition | Use of nonconforming critical supply only after a documented manufacturer decision |
| Complaint investigation and root cause analysis | Technical investigation and data provision by the supplier | Regulatory classification, reporting duty, CAPA and FSCA decision by the manufacturer |
| PMS, vigilance and authority communication | Supplier provides information and support | System responsibility and regulatory reporting remain with the manufacturer |
| Document retention | Physical or electronic custody possible | Manufacturer has to ensure access, legibility, integrity and regulatory availability |
Not outsourceable in practical terms: The manufacturer may purchase advice, preparation and operational execution. It has to remain able, however, to judge the adequacy of the results, approve decisions, meet regulatory obligations and account for them to the notified body and authorities. An agreement must therefore not create a black box.
8. Specifications, documents and data ownership
8.1 Specification responsibility
The agreement should define which specification describes the binding target state, who prepares it, who reviews it and who approves changes. The manufacturer should control the product and regulatory relevant requirements. The supplier remains responsible for the technical control of its process and for the consistency of its internal working documents with the approved specification.
| Document | Preparation | Approval and control | Purpose |
|---|---|---|---|
| Manufacturer specification or drawing | Manufacturer | Manufacturer | Binding product or service requirement |
| Supplier specification or manufacturing instruction | Supplier | Supplier; manufacturer receives the relevant extent of evidence | Internal process control |
| Test plan or control plan | Jointly or by the supplier, depending on the model | Manufacturer approves critical characteristics and acceptance criteria | Verification of the delivery |
| Validation protocol and report | Supplier or jointly | Manufacturer approves suitability for the outsourced process | Evidence of reproducible process performance |
| CoC, CoA or test report | Supplier | Supplier releases; manufacturer defines required content and use | Batch or delivery related conformity evidence |
| Risk related interface documents | Jointly | Manufacturer | Translation of product and process risks into controls |
8.2 Retention and access
- Retention periods have to match the product life cycle and the regulatory deadline; "according to the supplier's internal rules" is not sufficient.
- The manufacturer needs a right to timely release of legible copies, including after end of contract, site closure or insolvency.
- Electronic records have to secure integrity, version, release status, change history and retrievability.
- The supplier must not destroy, migrate or archive regulated original data in an illegible form without consent.
- Confidentiality and IP protection have to be regulated, but must not prevent regulatory access.
9. Nonconformities, complaints, CAPA and field actions
For critical supplies it has to be clearly regulated when the supplier informs the manufacturer and which decisions it may not take on its own. Blanket supplier rights to rework, to substitute material or to use "equivalent" components without prior consent are particularly problematic.
| Event | Notification | Expected initial measures |
|---|---|---|
| Critical deviation or possible safety or conformity risk | Immediately, typically within 24 hours | Stop shipment, containment, affected batches, initial risk assessment, contact person |
| Material deviation without immediate safety risk | Within a defined short period, for example 2–3 working days | Description, extent, affected deliveries, planned disposition |
| Minor deviation | According to the agreed reporting or escalation model | Trendable recording and periodic evaluation |
| Complaint or field information | Immediately upon becoming aware | All available technical data; no independent external communication without alignment, as far as legally permissible |
- No use, rework, repair or concession for nonconforming critical goods without documented consent of the manufacturer.
- Duty to identify all potentially affected batches, serial numbers, versions and delivery periods.
- Agreed deadlines for root cause analysis, correction, CAPA plan and evidence of effectiveness.
- Support with authority enquiries, vigilance reports, FSCA, recalls and customer communication.
- Right of the manufacturer to have its own tests performed where the investigation is inadequate, and to pass on reasonable cost under the agreed rule.
10. Sub suppliers and business continuity
10.1 Critical sub suppliers
The direct supplier must not move critical activities into a supply chain that is invisible to the manufacturer. The agreement should therefore define which sub suppliers require prior approval, which changes have to be notified and how audit and access rights are passed on.
- Prior consent for new or changed critical sub suppliers
- Flow down of the relevant quality, change, documentation and audit obligations
- Transparency about manufacturing and test sites as well as outsourced special processes
- Traceability down to the critical sub supplier
- Right of the manufacturer or the notified body to direct or mediated access
10.2 Security of supply and termination
- Emergency and restart planning for critical processes, equipment, IT systems and sites
- Duty to report fire, cyber attack, natural event, loss of certificate, insolvency risk or regulatory action
- Minimum stock, safety stock or agreed last time buy rules, where required
- Handover of tooling, data, validation documentation and quality records at end of contract
- Continued application of confidentiality, retention, complaint and authority support obligations after end of contract
11. A recommended modular model
Instead of writing a completely new agreement for every supplier, a modular approach is advisable. The general main body contains stable ground rules. Supplier specific and product related content is maintained in annexes. This keeps the agreement manageable without diluting critical detail.
| Building block | Content |
|---|---|
| Main body | General quality principles, audit, changes, nonconformities, CAPA, sub suppliers, retention, term and termination |
| Annex 1: scope | Products, part numbers, services, sites, critical processes and certificates |
| Annex 2: responsibility matrix | RACI or comparable allocation for specification, testing, release, validation, complaint, CAPA and documentation |
| Annex 3: quality evidence | CoC, CoA, test reports, validation documentation, batch documentation and submission deadlines |
| Annex 4: change matrix | Change categories, examples, deadlines, data package and consent requirement |
| Annex 5: audit and cost matrix | Audit types, notice, scope, cost allocation and effort limits |
| Annex 6: KPIs and escalation | Quality, delivery performance, complaints, CAPA, audit findings, escalation levels and review frequency |
| Annex 7: contacts | Operational, technical, quality, regulatory and emergency contacts |
12. Typical weaknesses of existing agreements
| Weakness | Risk |
|---|---|
| "Audit subject to prior alignment" | Does not cover for cause and unannounced regulator audits. |
| "Changes are to be notified" | No definition of change, deadline, data scope or consent requirement. |
| "The supplier meets all statutory requirements" | Shifts responsibility wholesale, without concrete interfaces and evidence. |
| No cost rule | Audit or investigation rights are blocked in an emergency by after the fact price negotiation. |
| No sub supplier rule | Critical processes can be moved on without the manufacturer's knowledge. |
| Unclear specification ownership | Contradictions between drawing, supplier data sheet, purchase order and test plan remain unresolved. |
| No rule for open complaints after end of contract | The supplier can stop support while regulatory deadlines continue to run. |
| Agreement without risk based supplier classification | Identical clauses for office supplies, a calibration laboratory and a critical contract manufacturer lead to over or under control. |
13. Concrete next steps
- Review the supplier classification and the criteria for critical or high risk suppliers and document them bindingly.
- Compile a list of all critical suppliers and outsourced processes; review existing agreements for coverage and currency.
- Anchor a binding requirement for agreements with critical suppliers and outsourced processes in the purchasing or supplier management process.
- Restructure the standard agreement into a main body and supplier specific annexes.
- Introduce the audit and cost matrix and the risk based change matrix as mandatory annexes.
- Prepare a responsibility matrix for every critical supplier and reconcile it with specification, test plan and risk management.
- Review existing supply contracts for contradictions with audit, cost, liability, IP and termination provisions.
- Review agreements periodically and on cause, in particular on changes of scope, site, certificate, process or sub supplier.
A good agreement is detailed, but not unnecessarily long. Its quality shows in whether it gives an unambiguous answer in a concrete situation: may the supplier change something? Does it have to ask first? Who decides on a deviation? Who pays for a for cause or notified body audit? Which documents have to be available? Who supports a complaint, CAPA or FSCA? Where those questions stay open, the agreement exists formally but does not hold up operationally.
14. Regulatory references
- Regulation (EU) 2017/745 (MDR), in particular Article 10(9) as well as Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4.
- Regulation (EU) 2017/745, Annex VII, section 4.5.2 on audit planning and the possible audit of suppliers and subcontractors.
- European Commission Notice 2021/C 8/01 on the use of supplier and subcontractor audits within the QMS assessment.
- ISO 13485:2016, Medical devices, quality management systems, requirements for regulatory purposes.
- Note on citing standards: the specific clause allocation and wording should be checked against the licensed version of the applicable standards and against the manufacturer's certification and contract model.
Relevant for your project?
Similar questions in your current project?
In a first call we clarify what is specifically relevant for your situation, without obligation.
Request a call →Life Science Journal
Regulatory updates, straight to your inbox.
New requirements, authority decisions and practice notes. Once a month, unsubscribe any time.
Regulations & standards considered
- Regulation (EU) 2017/745 (MDR), Art. 10(9) (QMS, selection and control of suppliers and subcontractors)
- Regulation (EU) 2017/745 (MDR), Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4
- Regulation (EU) 2017/745 (MDR), Annex VII, section 4.5.2 (notified body audit planning)
- ISO 13485:2016 (quality management systems for medical devices, outsourced processes)
- European Commission Notice 2021/C 8/01 (supplier and subcontractor audits)
Related expertise
Supplier Development & Qualification →
Classification decides which supplier needs a quality agreement at all.
GxP Audits (GMP, GLP, GCP) →
Audit types, cause and notice periods belong in the agreement, not in scheduling talks.
ISO 13485 Certification →
The standard requires control of outsourced processes, the agreement turns that into duties.
MDR Conformity →
Art. 10(9) and Annex IX require evidence of supplier control.
CAPA Management →
Without agreed deadlines for root cause analysis and effectiveness checks, supplier CAPA stays non binding.
Related projects
All case studies →Sources
- Regulation (EU) 2017/745 (MDR): primary text, in particular Art. 10(9) and Annex IX, sections 2.2, 2.3, 3.2, 3.3 and 3.4
- Regulation (EU) 2017/745 (MDR), Annex VII, section 4.5.2 on audit planning and the possible audit of suppliers and subcontractors
- European Commission Notice 2021/C 8/01 on the use of supplier and subcontractor audits within the QMS assessment
- ISO 13485:2016, Medical devices, quality management systems, requirements for regulatory purposes
- First published by the author on LinkedIn on 30 July 2026: https://www.linkedin.com/pulse/qualit%C3%A4tssicherungsvereinbarungen-qsv-diana-hohage-spsaf/
Related insights
All insights →Your project
Have a concrete project?
Briefly outline your situation. We'll respond with an initial assessment, usually within one business day.
Prefer direct? +49 89 4161170-0
info@theentourage.de
- Reply usually within one working day
- 4 offices: DE · CH · IT · US
- 100% life sciences




