What Audit Support From Your Kit Manufacturer Should Actually Look Like

When your regulatory lead audits your contract manufacturer, the job is not to pass. It is to produce evidence fast enough that your timeline does not slip. What they should be able to hand over, how fast, and what real audit support looks like.
Supera Fulfillment card: Audit Support, practical guidance for regulated kit programs

When your regulatory lead audits your contract manufacturer, or when your own submission or inspection puts their records in scope, the manufacturer’s job is not to pass. It is to produce evidence fast enough that your timeline does not slip. Those are different jobs, and most buyers do not find out which one their manufacturer is set up for until the request is already sent.

Why your manufacturer’s quality system is your problem

If you are the specification developer, the device is yours. Outsourcing assembly does not outsource the obligation, and an auditor will not accept “our manufacturer handles that” as an answer.

FDA’s Quality Management System Regulation took effect on February 2, 2026. It amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, which means the supplier expectations in that standard now sit inside the US regulation. Two clauses do most of the work. Clause 4.1.5 says that when you outsource a process that affects product conformity, you have to monitor and control it in proportion to the risk, and that the control includes a written quality agreement. Clause 7.4 says you need documented criteria for evaluating and selecting suppliers, and that you re-evaluate them.

Read together, that is why your regulatory lead audits your manufacturer. They are discharging your obligation, not doing the manufacturer a favor. Whether any of this applies to your specific product, and what you may claim about it, belongs to your own regulatory lead and not to your manufacturer.

Five things your manufacturer should be able to produce

Ask for these before you schedule anything. What comes back, and how long it takes, tells you more than the audit will.

  • A reconciled controlled document index. Not a list of procedures. An index that has been checked against what actually exists, with owners and revision dates. In practice the index fails more often than the documents do, especially at any manufacturer that has changed quality systems in the last few years.
  • Program records retrievable by lot. Build records, component traceability back to the incoming lot, and the label and instructions-for-use proofs released for that run, all under document control. If retrieval means someone searching a shared drive, you have found your finding.
  • Equipment records for anything that touches your product. Calibration and preventive maintenance with dates and completion evidence, including the environmental controls serving the rooms where your kits are assembled and any liquid is filled. Equipment that works is not the same as equipment that can prove it worked on schedule.
  • Complaint and CAPA handling with a current named owner. Ask who owns it today, then check that against the procedure. The gap between those two answers is one of the most common findings in any quality system.
  • The quality agreement and a risk file scoped to your kit. A blanket FMEA written for the facility is not a risk assessment of your program. If the process FMEA and the quality agreement are not specific to your kit and your customer, they are not doing the job clause 4.1.5 asks of them.

Where drift actually shows up

Every quality system drifts. The four places it shows up are predictable enough that you can ask about them directly.

  • Ownership that no longer matches the org chart. Procedures name a department or a role that reorganized away. The work still happens. The document says someone else does it.
  • Equipment that works but cannot prove it. Preventive maintenance performed on judgment rather than on a logged schedule. The unit is fine. The record is missing.
  • Migrations that leave documents behind. A move between quality systems drops procedures out of the master index. They still exist and people still follow them, so nothing breaks and nobody notices, because the old and new systems both look complete from a distance.
  • Risk files written once. An FMEA and a quality agreement built at onboarding and never rescoped when the program changed.

When to run it

Not during your submission window. A supplier audit that surfaces a document index problem four weeks before a filing turns into a schedule problem, and the fix is rarely fast.

Run the first one during onboarding, before the first commercial lot. Re-evaluate on a fixed schedule after that, because clause 7.4 asks for re-evaluation and not a one-time approval. Then treat these as triggers for an unscheduled look: the manufacturer moves or adds a site, they change quality systems, a complaint trend points at assembly, their quality lead leaves, or your own intended use changes in a way that moves the risk.

The event-driven triggers matter more than the calendar ones. A migration between quality systems is the single most reliable predictor that something has fallen out of the index, and it almost never gets announced to customers as a change worth auditing.

What audit support should actually mean

Passing an audit is the low bar. Supporting one is the thing you are paying for. Set these expectations in writing before you need them.

  • One named contact who can pull records, not route requests. If every document request goes into a queue, your audit runs at the speed of their ticketing system.
  • The document list before the audit, not during. A manufacturer who knows their own system can tell you what they will hand over, and in what format, ahead of the opening meeting.
  • Answers in the auditor’s language. Records mapped to the clause being asked about, rather than a folder dump for your team to sort.
  • Their open items disclosed to you first. A manufacturer who tells you about a gap two weeks out is being a partner. One who lets your auditor find it is not.
  • Corrective action taken on their side, with closure evidence. Not a promise to fix it. The updated document, the completed log, the signed reconciliation.

If they cannot do this

Some manufacturers cannot, and you are better off knowing in a quiet week than in an audit week.

If your manufacturer cannot produce a current document index within a few days of being asked, the problem is not the audit. Escalate it to whoever owns the relationship, get a date, and start scoping a second source in parallel. That is unwelcome advice from anyone in this business and it is still the right call.

Size is not the signal here. A small manufacturer running a tidy, genuinely controlled paper-based system will hand you cleaner evidence than a large one running a sprawling system nobody has reconciled since the last migration. Ask to see the system, not the certificate.

Practical takeaways

  • Put the document request in writing before you schedule the audit, and treat the response time as data.
  • Ask who owns complaint handling today, then read the procedure and compare.
  • Require the process FMEA and the quality agreement to name your kit and your program, not the facility.
  • Ask when the last quality system migration was, and ask to see the reconciliation that closed it.
  • Name a single point of contact on both sides and put it in the quality agreement.
  • Confirm what applies to your product, and what you may say about it, with your own regulatory lead before anything reaches a submission, a label, or a web page.

Related reading: what FDA’s QMSR means for at-home test kit companies covers the rule this all sits under, and how to audit a specimen kit supplier is the criteria sheet to run the audit from.

Written by

Michael Brown

Michael Brown is Co-Founder and Chief Commercial Officer of Supera Fulfillment, an ISO 13485 certified contract manufacturer and kitting operation in Houston. He scopes and prices specimen collection kit programs, and works mostly on the parts buyers find out about late: bills of materials, regulatory labeling, return paths, and what a device choice does to a kit. He writes these guides to be useful whether or not you ever work with Supera.

Share:

More Posts

Supera Fulfillment card: Shipper Specs, practical guidance for regulated kit programs

How to Read a Cold Chain Shipper Spec Sheet

A temperature range, a number of hours, and a standard name. None of the three mean what buyers assume. What ISTA 7D, 7E and Standard 20 actually certify, why you set the acceptance criteria, and what to ask before you qualify a shipper for a lane.

Read More »

Send Us A Message

Contact Us
First
Last