Processes: Vendor & Third-Party Management
No processes match the current filters.
Vendor Quality Assessment
Vendor & Third-Party Management
ID: P069
A structured process defined in SOP-0303271 to assess vendors of GxP-relevant computerized systems for Quality Management System maturity and regulatory compliance. The assessment spans scope definition, questionnaire-based data collection, report generation, and follow-up on vendor remediation acti
Source Documents (1)
Mapped Citations (51)
- 15.1 Establish and Maintain an Inventory of Service Provider...
- 15.3 Classify Service Providers
- 15.4 Ensure Service Provider Contracts Include Security Requ...
- 15.5 Assess Service Providers
- 15.6 Monitor Service Providers
- AS.164.308.b3
- Addressing information security within supplier agreements
- DE.CM-06
- Ensure Software is Supported by Vendor
- GV.AT-P4
- GV.OC-02
- GV.PO-P4
- GV.RM-05
- GV.SC-01
- GV.SC-02
- GV.SC-03
- GV.SC-04
- GV.SC-05
- GV.SC-06
- GV.SC-07
- GV.SC-09
- GV.SC-10
- ID.AM-04
- ID.DE-P2
- ID.DE-P3
- ID.DE-P5
- ID.RA-09
- ID.RA-10
- IPY-04 Data Portability Contractual Obligations
- IT Supplier Audit Reports
- IT Supplier Audits
- Information security for use of cloud services
- Information security in supplier relationships
- Managing information security in the information and communi...
- Monitoring, review and change management of supplier service...
- OS-1.A.4
- Only Use Up-to-date And Trusted Third-Party Components
- Outsourced development
- Quality Agreements with IT Supplier
- Quality Management System (supplier)
- SOC 1 Review
- STA-07 Supply Chain Inventory
- STA-08 Supply Chain Risk Management
- STA-09 Primary Service and Contractual Agreement
- STA-10 Supply Chain Agreement Review
- STA-12 Supply Chain Service Agreement Compliance
- STA-13 Supply Chain Governance Review
- STA-14 Supply Chain Data Security Assessment
- UEM-14 Third-Party Endpoint Security Posture
- Vendor Documentation
- Verify That Acquired Software is Still Supported