When your regulatory lead audits your contract manufacturer, or when your own submission or inspection puts their records in scope, the manufacturer’s job is not to pass. It is to produce evidence fast enough that your timeline does not slip. Those are different jobs, and most buyers do not find out which one their manufacturer is set up for until the request is already sent.
Why your manufacturer’s quality system is your problem
If you are the specification developer, the device is yours. Outsourcing assembly does not outsource the obligation, and an auditor will not accept “our manufacturer handles that” as an answer.
FDA’s Quality Management System Regulation took effect on February 2, 2026. It amends 21 CFR Part 820 and incorporates ISO 13485:2016 by reference, which means the supplier expectations in that standard now sit inside the US regulation. Two clauses do most of the work. Clause 4.1.5 says that when you outsource a process that affects product conformity, you have to monitor and control it in proportion to the risk, and that the control includes a written quality agreement. Clause 7.4 says you need documented criteria for evaluating and selecting suppliers, and that you re-evaluate them.
Read together, that is why your regulatory lead audits your manufacturer. They are discharging your obligation, not doing the manufacturer a favor. Whether any of this applies to your specific product, and what you may claim about it, belongs to your own regulatory lead and not to your manufacturer.
Five things your manufacturer should be able to produce
Ask for these before you schedule anything. What comes back, and how long it takes, tells you more than the audit will.
- A reconciled controlled document index. Not a list of procedures. An index that has been checked against what actually exists, with owners and revision dates. In practice the index fails more often than the documents do, especially at any manufacturer that has changed quality systems in the last few years.
- Program records retrievable by lot. Build records, component traceability back to the incoming lot, and the label and instructions-for-use proofs released for that run, all under document control. If retrieval means someone searching a shared drive, you have found your finding.
- Equipment records for anything that touches your product. Calibration and preventive maintenance with dates and completion evidence, including the environmental controls serving the rooms where your kits are assembled and any liquid is filled. Equipment that works is not the same as equipment that can prove it worked on schedule.
- Complaint and CAPA handling with a current named owner. Ask who owns it today, then check that against the procedure. The gap between those two answers is one of the most common findings in any quality system.
- The quality agreement and a risk file scoped to your kit. A blanket FMEA written for the facility is not a risk assessment of your program. If the process FMEA and the quality agreement are not specific to your kit and your customer, they are not doing the job clause 4.1.5 asks of them.
Where drift actually shows up
Every quality system drifts. The four places it shows up are predictable enough that you can ask about them directly.
- Ownership that no longer matches the org chart. Procedures name a department or a role that reorganized away. The work still happens. The document says someone else does it.
- Equipment that works but cannot prove it. Preventive maintenance performed on judgment rather than on a logged schedule. The unit is fine. The record is missing.
- Migrations that leave documents behind. A move between quality systems drops procedures out of the master index. They still exist and people still follow them, so nothing breaks and nobody notices, because the old and new systems both look complete from a distance.
- Risk files written once. An FMEA and a quality agreement built at onboarding and never rescoped when the program changed.
When to run it
Not during your submission window. A supplier audit that surfaces a document index problem four weeks before a filing turns into a schedule problem, and the fix is rarely fast.
Run the first one during onboarding, before the first commercial lot. Re-evaluate on a fixed schedule after that, because clause 7.4 asks for re-evaluation and not a one-time approval. Then treat these as triggers for an unscheduled look: the manufacturer moves or adds a site, they change quality systems, a complaint trend points at assembly, their quality lead leaves, or your own intended use changes in a way that moves the risk.
The event-driven triggers matter more than the calendar ones. A migration between quality systems is the single most reliable predictor that something has fallen out of the index, and it almost never gets announced to customers as a change worth auditing.
What audit support should actually mean
Passing an audit is the low bar. Supporting one is the thing you are paying for. Set these expectations in writing before you need them.
- One named contact who can pull records, not route requests. If every document request goes into a queue, your audit runs at the speed of their ticketing system.
- The document list before the audit, not during. A manufacturer who knows their own system can tell you what they will hand over, and in what format, ahead of the opening meeting.
- Answers in the auditor’s language. Records mapped to the clause being asked about, rather than a folder dump for your team to sort.
- Their open items disclosed to you first. A manufacturer who tells you about a gap two weeks out is being a partner. One who lets your auditor find it is not.
- Corrective action taken on their side, with closure evidence. Not a promise to fix it. The updated document, the completed log, the signed reconciliation.
If they cannot do this
Some manufacturers cannot, and you are better off knowing in a quiet week than in an audit week.
If your manufacturer cannot produce a current document index within a few days of being asked, the problem is not the audit. Escalate it to whoever owns the relationship, get a date, and start scoping a second source in parallel. That is unwelcome advice from anyone in this business and it is still the right call.
Size is not the signal here. A small manufacturer running a tidy, genuinely controlled paper-based system will hand you cleaner evidence than a large one running a sprawling system nobody has reconciled since the last migration. Ask to see the system, not the certificate.
Practical takeaways
- Put the document request in writing before you schedule the audit, and treat the response time as data.
- Ask who owns complaint handling today, then read the procedure and compare.
- Require the process FMEA and the quality agreement to name your kit and your program, not the facility.
- Ask when the last quality system migration was, and ask to see the reconciliation that closed it.
- Name a single point of contact on both sides and put it in the quality agreement.
- Confirm what applies to your product, and what you may say about it, with your own regulatory lead before anything reaches a submission, a label, or a web page.
Related reading: what FDA’s QMSR means for at-home test kit companies covers the rule this all sits under, and how to audit a specimen kit supplier is the criteria sheet to run the audit from.



