Making Headway

The moment that defines your vendor risk (and it’s not the audit)

March 31, 20264 min read

When does vendor or service provider risk actually get decided?

Most organisations would point to the audit. The qualification visit. The report. The CAPA plan. But in practice, the level of risk you carry is usually set much earlier, often before QA is even aware a decision has been made. And by the time the audit happens, there is often very little left to decide.

Over the past month, I’ve had several conversations with clients and colleagues across preclinical, clinical, and CSV environments. Different settings, different pressures, but a consistent pattern.

A vendor is identified. Sometimes informally. Sometimes quickly, driven by timelines or familiarity. Work begins, or is about to begin. Then QA is brought in to “complete the process”. At that point, the audit becomes less about should we work with this vendor? and more about how do we make this work?

That’s a very different question. And it changes the role of QA entirely.

In theory, most organisations understand that there are multiple ways to approach vendor oversight.

You can audit before selection.
You can audit early in the study using real data.
You can combine both for higher-risk scenarios.

These are not subtle differences. Each approach carries a different level of confidence, cost, and exposure.

But in practice, these choices are rarely made deliberately. Instead, the model of oversight is often inherited from circumstance:

  • The study needed to start quickly

  • The vendor was already known

  • The system had already been selected

  • The process felt too bureaucratic to slow things down

So the decision gets made first, and the oversight model is fitted around it afterwards.

This is where the problem starts. Because vendor audits are often treated as a control mechanism, when in reality they are more accurately a feedback mechanism. They tell you what is happening. They do not change what has already been set in motion.

If a vendor has already been selected, contracted, and integrated into a study, the organisation’s ability to act on audit findings is constrained.

Changing vendor may no longer be viable.
Delaying the study may not be acceptable.
Mitigation becomes the default response.

And in some cases, mitigation becomes compromise.

This isn’t a criticism of QA teams. In fact, most QA professionals recognise this dynamic immediately.

It’s a system design issue.

Decisions about vendors are often made locally, within operational teams, while the consequences of those decisions sit centrally with QA, regulatory, and ultimately the organisation’s leadership.

That disconnect creates a predictable outcome:

Risk is accepted implicitly, rather than explicitly.

What makes this particularly interesting is that it shows up in slightly different forms across the industry, but the underlying issue is the same.

In preclinical work, it might be the absence of a true pre-qualification audit, with reliance instead on early study oversight once data has already been generated.

In clinical research, it often appears in the way certain service providers are prioritised. Core CROs receive scrutiny, while laboratories or PK providers, despite generating critical data, are sometimes treated as lower risk.

In CSV, the pattern is even more visible. Systems are frequently selected, and sometimes even implemented, before QA is involved. Vendor qualification then becomes a retrospective exercise, with limited scope to influence the outcome.

Different functions. Same decision gap.

So the question is not simply how should we audit vendors?

It’s:

At what point do we want to make a real decision about risk?

Because there are only a few moments in any programme where you still have meaningful choice.

Before selection, you can choose between vendors.
Early in execution, you can still adjust course.
Later on, your options narrow rapidly.

After that, you are no longer deciding. You are managing consequences.

This month’s newsletter is built around that idea. Not how to audit better, but how to think more clearly about when and why we audit.

We’ll explore the three common oversight models and the trade-offs behind each. We’ll look at why audits so often happen too late to influence outcomes. And we’ll draw parallels across GLP, GCP, and CSV to show how consistently this pattern repeats.

More importantly, we’ll offer a simple way to make these decisions more deliberately, so that audit activity is aligned with the level of confidence you actually need.

If there’s one question worth holding as you read on, it’s this:

In your last study or system implementation, when was the last point you could have chosen a different vendor?

And did your oversight approach reflect that reality, or simply adapt to it?

Paul Davidson

Paul Davidson

Paul Davidson is a quality consultant, leadership coach, and founder of Headway Quality Evolution. With over a decade of experience in pharmaceutical R&D and regulatory compliance, he helps technical professionals bridge the gap from expert to impactful leader.

LinkedIn logo icon
Back to Blog