It’s officially annual audit planning season for 2027. For the next few weeks and months, we take teams’ audit schedules and formally assign auditors to them.
With many companies kicking off their first audits in January, planning for those and the rest of the year’s audits should be done over the next 8 weeks, with everything ideally ready by October 1.
If that sounds early, run the math backward to see why we push for October:
A January audit needs an approved agenda.
The agenda needs a named auditor.
The auditor needs a CV that your team has reviewed and signed off on.
Getting to CV review needs a signed contract and a defined scope.
The scope needs your list: which sites, which GxP, which quarter.
Now consider where those steps land on a calendar. Agendas are often drafted and approved in November and December, when the people who have to approve them are out and many sites are closed. In our experience as the resourcing partner for teams needing to get great auditors into their sites throughout the year, January (and Q1) is hard precisely because everything that has to happen before it happens during the holidays.
Practically speaking, you can’t solve that with urgency in December. You solve it with a list in October, well before crunch time.
In this guide, we’re peeling back the curtain on what goes into effective annual audit planning, how resourcing actually works, and how to plan for next year now.
We’ve also built an Excel workbook you can download and use yourself. Download the file here:
It’s super easy to use! Just fill in each row in the “Audit schedule” sheet with details about your 2027 audits — one row per audit. Many of the columns have dropdowns that pull from the “Lists” tab. You can update that information to customize it however you want. I
If you need to resource those audits, just head to our contact form and let us know you’re interested. We’ll reach out, and you can send your planning sheet over so we can get started.
What we ask for, and like to have by October
Let’s talk about what goes into audit resourcing.
Below is what we ask our own clients to send us, ideally in that first week of October, to resource their next audit cycles. It’s necessary information to gather no matter how you run your program.
The sites you plan to audit, with locations
The audit type for each one: GMP, GCP, GLP, GCLP, CSV, pharmacovigilance, quality system, supplier qualification, routine surveillance
A site contact for each: name, phone, email
The quarter each audit falls in, at minimum
Any dates that are fixed rather than preferred. (If a site can only host an audit on June 12 and 13, we need that in October, not April of next year!)
The auditors from prior years you’d like to work with again if we’ve resourced with you before
Who is contacting the sites and booking dates, you or us
That usually comes together on one sheet, ideally one line per audit, with enough on each line that we can quote out the program, assign auditors, and start booking dates. (Download our Excel workbook and fill it out!)
That’s really the whole ask, but we realize there’s work involved to get there!
For most Quality teams, the real work sits upstream — for example, deciding which of your suppliers actually have to be audited in the next 12 months. That’s a risk-based judgment about frequency, supplier criticality, performance history, change activity, and whatever else your SOP commits you to. Sometimes that requires cross-functional input and can take some time.
The second workstream, if you’re coordinating dates yourself, is what we call calendar reality. The calendar presents all kinds of hurdles, some less obvious than others, especially if you’re planning internationally.
European sites shut down for stretches of August.
Chinese New Year moves every year.
Some sites won’t host an auditor during a campaign or a turnaround. You find all of this out one email at a time!
The key point is that both of these things should be August and September problems to solve. December is just too late to expect the same kind of result.
What follows is the sequence we’d run if we were building the list ourselves. Work through it, and you’ll have a schedule we can price and resource, and a documented record of how you decided what to audit. Do your future self a favor!
Building the audit planning list: a working sequence
Let’s run through this one step at a time.
1. Pull your “audit universe” into one sheet
Start wider than you’ll finish. Pull from your approved supplier list, your quality agreement register, your CMO and CRO contracts, your contract lab list, your prior audit schedule and reports, and your internal site list. If you run clinical programs, add TMF and eClinical vendors.
You might find that these sources sometimes “disagree” with each other. Some examples we’ve seen include:
Suppliers on the ASL with no quality agreement.
Quality agreements for suppliers nobody has audited in five years.
Vendors added in mid-2026 who never made it onto a schedule.
Finding those now is worth the afternoon it costs, because each one is a purchasing control or supplier evaluation observation waiting to happen.
2. Apply the intervals, then apply any “overrides”
Some companies have an SOP or a documented program that defines audit frequency by risk tier. Apply that first: anything whose interval expires in 2027 obviously goes on the audit list.
Then apply the “overrides,” which is where the judgment actually lives. A supplier might belong on the 2027 audit list regardless of where its interval sits if any of these happened since the last audit:
Quality events traceable to them: deviations, OOS results, complaints, rejected lots
A change in ownership, site, process, or a material’s manufacturing location
New material, expanded scope, or first commercial supply
Regulatory action against them, or an inspection that produced significant findings
Open CAPAs from the last audit that nobody verified as closed
No audit on record at all
Jot down the reason next to each line as you go. That column is the record of your risk-based decision. (It’s also what an investigator asks about when they want to know why the supplier behind your last three deviations wasn’t on the schedule!)
3. Classify each audit before you try to schedule it
Every line needs a type and a format.
Type is the GxP: GMP, GCP, GLP, GCLP, CSV, pharmacovigilance, quality system.
Format is on-site, remote, or hybrid, plus expected duration in days, plus whether it’s a first-time qualification audit or routine surveillance.
Duration is important too and is sometimes overlooked in initial planning. A two-day audit and a four-day audit are different resourcing projects, different budget lines, and different conversations with the site. Make sure you note the length of each audit.
4. Place the constraints first, then fill in around them
One mistake we sometimes see teams make is spreading audits evenly across the year and then discovering the constraints after the fact that force changes.
We suggest doing it the other way:
Mark every window you can’t move. Site shutdowns, which means most of August across much of Europe, Chinese New Year, Golden Week, and regional holidays wherever your suppliers sit. Campaign and turnaround windows. Year-end inventory freezes. Any site you already know is expecting a regulatory inspection.
Then add your own fixed points: submissions that could trigger a PAI, product launches, your internal audit cycle, and the weeks your own quality team is unavailable to host or travel.
Then place the rest on the calendar, with two rules in mind. Keep Q1 under about a third of the program, if possible, because January and February are the busiest months in the industry, and a slip there might have nowhere to go. And keep December nearly empty, because a December audit that slips doesn’t move to January. It falls out of the year, and a missed interval you can’t explain is a finding.
Here’s the recurring shape of the year in case you want to avoid problem windows based on your site locations:
January. Again, a busy audit month in the industry, for you and for every other program competing for the same top-tier auditors.
Late January into February. Chinese New Year is Saturday, February 6, 2027, with the mainland holiday running roughly from February 5 to 12. The practical shutdown is usually longer. Factories scale down for two to three weeks beforehand and ramp back up unevenly for weeks after. You might want to treat late January through late February as closed for China and Taiwan sites.
February into March. Ramadan is expected to begin around February 7 or 8, 2027, with Eid al-Fitr around March 9 to 11. Sites across the Middle East, Turkey, Pakistan, Bangladesh, Indonesia, and Malaysia run shortened days. You might be able to audit through it, but budget more days or move the audit.
Late March. Good Friday is March 26 and Easter Monday is March 29 in 2027, which takes the edges off that week across Europe.
April 29 to May 5. Japan’s Golden Week, on fixed dates, and effectively the entire week.
May and June. The clearest stretch on the calendar. Put your hardest-to-place audits and your hardest-to-get auditors here if you can.
July and August. A general time of showdown or shutdown in Europe. Japan’s Obon period runs mid-August and many businesses close.
September. The second-best window of the year. Everyone’s back and nothing major interrupts it.
October 1 to 7. China’s National Day Golden Week. Fixed every year.
Late October or November. Diwali. The date moves, so confirm it with your Indian sites rather than assuming. Expect a week of reduced activity around it.
Late November. U.S. Thanksgiving is November 25, 2027. That week is gone for US sites and consultants.
December. Christmas and New Year shutdowns, year-end inventory freezes, and everyone using any leftover PTO.
5. Get the right contacts, and read the quality agreement while you're there
You need the person who can approve an audit date, not the commercial contact or someone without actual authority. Name, title, direct phone, email, time zone. Note the working language and whether you’ll need an interpreter, because that can change who can run the audit.
While you’re in the file, confirm the quality agreement is current and says what you think it says about audit rights, notice periods, and how many audit days you get per year. Notice periods often drive scheduling. Some agreements require 60 or 90 days, which quietly rules out Q1 for anything you haven’t already asked for.
6. Mark every line as retain, rotate, or open
If you have audits from this year, pull the auditor names from those reports and add them to the sheet. Then decide line by line rather than as a policy.
Decide whether to retain the same person if available, rotate in someone else, or leave it open if you don’t have a preference and would rather we optimize for availability, location, and cost.
Then send the list over as complete as you can get it. A schedule with 30 lines and 6 unknowns is workable in October. A perfect schedule two days before Christmas is not!
Decide who you want back before someone else books them!
Some of the teams we manage audits for get attached to specific auditors for good reasons. An auditor returning to a site already knows the layout, the systems, the history, and what was still open at the end of last year’s report.
There’s no universal right answer here whether you want to keep the same auditors or rotate in new ones — every situation and perspective is different. Just decide this sooner rather than later, especially if you want to retain people.
The math of audit resourcing
With a large pool of vetted auditors around the world, we don’t encounter bench-depth issues. We can source auditors for a program of almost any size, just about anywhere you need them.
It’s more so a sequencing question, and it works like this:
If you sign in September or October and tell us you want the same three auditors you used in 2026, they’ll very likely be available.
Come to us in January with those same names, and they’re much more likely to be committed across other programs running 30, 40, 50 audits apiece. Their availability for April, for example, might already be gone.
The teams that feel it hardest are those with narrow requirements: a sterile injectables auditor who can work in Mandarin, someone qualified in both GMP and pharmacovigilance, a GCP auditor who can be in Seoul in February.
The takeaway is that the more specific your ask, the earlier it has to land.
What we run, and how the year works
Most annual programs are built from GMP, GLP, GCP, GCLP, and CSV audits, plus quality system audits, supplier and vendor audits, and gap assessments.
Pharmacovigilance audits are appearing in more programs than before. Beyond the standard set, we run data integrity, clinical site, MDSAP, ISO, QMSR, and REMS audits, along with mock FDA inspections, mock PAIs, mock BIMO inspections, and facility readiness reviews for teams that want a dry run before the agency arrives.
One proposal can cover the whole program if you want it to. Tell us in October that you have 30 audits and you get a single 2027 audit support proposal covering all 30. Add to it during the year if you need to, or drop audits that fall away. Adjust as your risk assessment moves. You aren’t papering a new agreement every time the plan changes.
How much of the running we do is up to you. In a fully managed arrangement, we contact the sites, negotiate and confirm dates, build and circulate agendas, manage CV review and approval, run the audits, deliver the reports, and keep the master schedule current.
In a more traditional audit vendor model, you own the site relationships, and we work through you: we tell you an auditor is available, say on January 14, you check with the site, we lock it in, and get the auditor in there on that date.
Either way, you get a named account manager and project manager rather than a shared inbox. Our auditors are former FDA investigators and industry professionals, and every engagement carries our Total Quality Guarantee.
The calendar, compressed
In a nutshell:
August and September. Work the sequence above. Pull the universe, apply intervals and overrides, classify, place constraints, chase contacts, mark retain or rotate. Get budget approved.
October. Send us the schedule. The proposal comes back. Contract signed. CV packets go out, and any new auditors get reviewed and approved on your side.
November and December. Agendas drafted, circulated, approved. Sites confirmed. Travel booked. These two months run entirely on what was decided in October.
January. Audits start running.
Get your 2027 planning cycle started
If you already work with us for audits, contact your project manager directly. If you ran audits with us in 2026, we can hand your own data back to you: the audits we supported, when they ran, and the auditors we assigned, so you can mark up what stays and what changes for next year.
If you haven’t worked with us before, get in touch and tell us roughly what you’re planning. You don’t need a finished schedule to start the conversation. A rough audit count, the GxP mix, and the geographies are enough for us to get started. We respond within one business day.
Everything about January gets decided in October. Start the list!
Who is The FDA Group?
The FDA Group helps life science organizations rapidly access the industry's best consultants, contractors, and candidates. Our resources assist in every stage of the product lifecycle, from clinical development to commercialization, with a focus on Quality Assurance, Regulatory Affairs, and Clinical Operations.
With thousands of resources worldwide, hundreds of whom are former FDA, we meet your precise resourcing needs through a fast, convenient talent selection process supported by a Total Quality Guarantee. Learn more and schedule a call with us to see if we’re a fit to help you access specialized professionals and execute your projects on time and on budget.




