When we pull lessons from our audit work, they usually come from the observations and recommendations that make it into the report. An audit we ran earlier this year gave us almost none of those, but it’s still worth passing along since these clean results provide lessons just the same.
It was a periodic requalification audit of a contract testing lab, conducted on behalf of a sponsor organization.
The lab is one site within a larger multi-site organization. Our audit ran in two parts: two days reviewing the organization’s global quality systems remotely, followed by one day on-site at the facility. We assessed compliance with 21 CFR Parts 11, 58, and 820, as well as internal policies and procedures.
The result was zero critical, major, or minor observations and a single recommendation, and the lab was confirmed as an approved vendor for all services it provides to the client. That’s a good outcome! The report is also a useful picture of what a well-run vendor program looks like, and of where even a mature one has room to tighten.
Learn more and get in touch if you need audit support now or in the future. We’re getting into 2027 audit planning season right now. Get our free audit planning Excel workbook here.
1. Let a centralized review carry the shared material
The vendor’s corporate quality assurance function operates as we see some of the best firms organize themselves: a centralized audit program covering procedures common across all its sites.
That central program covered SOP harmonization, data integrity, CSV and IT security, training, vendor management, archiving and data retention, QA unit operations, and protocol and reporting standards. The program is built to complement individual site audits, not replace them. It front-loads the shared topics so site visits can concentrate on compliance verification and site-specific issues.
Our auditor found no observations in that review and described it as a very efficient way to cover the vendor’s quality systems in an organized manner.
The lesson we wanted to pull from this is that when a vendor operates multiple sites, ask whether it offers a centralized quality systems review. Covering the shared material that way (remotely) frees up your on-site time for what only the site can show you. It’s the sign of a thoughtful and well-organized company.
2. Know which SOPs are global and which are local
The vendor uses a smart three-tier SOP structure:
Fully harmonized SOPs that permit no site variation.
Aligned SOPs that allow limited site-specific adjustments.
Site-specific SOPs for unique functions.
Our report’s summary of the centralized review listed justified site-specific variations and legacy system transitions at some locations among its areas for ongoing attention. It also suggested requesting validation documentation for site-specific systems as needed.
A useful part of this kind of tiering structure is that the tier tells you where to look. Harmonized SOPs are a natural fit for a centralized review. Site-specific procedures and systems are where local variation lives, so they deserve a larger share of your document requests and on-site time.
3. “Within our procedure” isn’t the whole answer
Our audit’s one formal recommendation concerned SOP revision. Some procedures hadn’t been revised in more than five years. That was within the allowable interval under the vendor’s own procedures, but we still recommended establishing a stricter revision schedule unless the current practice could be fully justified without any lingering risks.
Under the sponsor’s audit program, that finding was classified as a recommendation rather than an observation.
Conforming to your own periodic review interval shows you followed the procedure, but doesn’t show that the interval is “right.” A five-year-old SOP may be perfectly sound, but the justification should exist before an auditor asks for it. Also, a grading scheme that keeps recommendations separate from observations lets auditors raise points like this without forcing a CAPA.



