Six areas to evaluate consistently
Record the vendor response, evidence reference, risk, owner and acceptance decision for every question.
1. Intended use and lifecycle coverage
- Can the vendor map the proposed configuration to the approved intended use?
- Which validation types and record classes are native, configured or out of scope?
- Can requirements link to risk, tests, results, deviations and final release?
- How are template versions, project copies and approved records controlled?
- Can the team export complete, readable records with metadata and relationships?
- What happens to records after contract termination?
2. Electronic records, signatures and audit trails
- How are identity, authentication, signature meaning and record linkage implemented?
- Which events are captured in the audit trail, and can entries be changed or deleted?
- How are audit trails reviewed, filtered, exported and retained?
- Does the system enforce sequencing, segregation of duties and approval authority?
- How are timestamps and time zones controlled?
- Which controls depend on customer configuration or procedure?
3. Supplier quality and validation evidence
- What quality system governs development, testing, release and change control?
- Which lifecycle documents and test evidence are available for customer review?
- How does the supplier classify, communicate and resolve defects?
- How are product changes assessed and communicated before release?
- What evidence supports the proposed GAMP category and risk-based approach?
- Can customers audit the supplier or obtain independent assurance reports?
4. Security, privacy and resilience
- Where is data hosted, processed and backed up?
- How are role-based access, privileged access and periodic access review supported?
- What encryption, vulnerability management and penetration-testing controls apply?
- What are the incident-notification and breach-response commitments?
- How are backup restoration, disaster recovery and business continuity tested?
- Which subprocessors handle customer data?
5. Implementation and operating model
- Which configuration, integration, migration and training activities are included?
- Who owns customer procedures, testing, deviations and release approval?
- What prerequisites determine implementation timing?
- How are administrator competence and ongoing support maintained?
- How are sandbox, test and production environments separated?
- What service levels and escalation routes are contractually available?
6. Commercial and exit criteria
- What is included in licence, onboarding, storage, AI usage, support and upgrades?
- Which implementation, validation or integration services cost extra?
- How do user, site and usage limits affect future cost?
- What price-change, renewal and termination terms apply?
- What export assistance and format are provided at exit?
- What is the total validated cost over three years?
Evaluation rule: Do not accept a simple yes/no for a critical control. Ask the vendor to demonstrate the requirement, identify the configuration dependency and provide the supporting evidence reference.