In This Article
- Executive Summary
- A Paper-Era Document Governing a Digital Relationship
- What the Rules Actually Require of the Contract
- Clause 1: Record Ownership, Originals, and Contract End
- Clause 2: Audit Trail Access Rights
- Clause 3: Electronic Signature Acceptance Across Two Systems
- Clause 4: Data Transfer Format, Timing, and Validation
- Clause 5: System Change Notification
- Clause 6: Deviation and Investigation Visibility
- Clause 7: Retention, Retrieval, and Readability
- Clause 8: Subcontracting, Cloud Hosting, and Location
- The Clause-by-Clause Summary
- Renegotiating Without Reopening Everything
- Conclusion
- For Further Reading
- References & Sources
Executive Summary
Most quality agreements in force today were drafted for a world of paper batch records, scanned certificates of analysis, and email attachments. The regulatory texts they follow were written in the same world. EU GMP Chapter 7 on outsourced activities came into operation on 31 January 2013. FDA’s quality agreements guidance was issued in November 2016. Both are still correct. Neither anticipated that the sponsor and the supplier would each be running a validated cloud platform, holding different original records, applying different interpretations of 21 CFR Part 11, and upgrading their systems on release cycles the other party never sees.
The failure is rarely in the clause that is missing. It is in the clause that is present, reads sensibly, and cannot be performed. An agreement that says the supplier will “provide records upon request” is unobjectionable until the request is for a chromatography audit trail in the vendor’s native format, from a system the supplier retired eighteen months ago, covering a batch whose retention period runs for another nine years. The clause was fine. The operation behind it never existed.
This article works through eight clauses that break at the digital boundary: record ownership and access, audit trail access rights, electronic signature acceptance, data transfer format and timing, system change notification, deviation and investigation visibility, retention and readability across the full retention period, and subcontracting of data processing including hosting location. For each one it gives the failure mode, example wording you can put in front of your legal team, and the operational check that proves the clause actually works. It closes with a method for renegotiating an existing agreement without reopening the whole document.
A Paper-Era Document Governing a Digital Relationship
A quality agreement is a strange document. It is not the commercial contract, and in most companies the people who negotiate the commercial terms never read it. It is not a procedure, and it is not owned by the people who have to follow it day to day. It is written once, signed by two quality units, filed, and then referenced only when something has already gone wrong.
That is survivable when both parties work on paper. Paper has one useful property: it does not change format, it does not require a license to read, and it does not stop being readable because someone did not renew a support contract. A binder of batch records handed over at the end of an engagement is a complete transfer. Nothing is left behind in a database the receiving party cannot query.
Digitization removes that property. Once either party moves a GxP process into a validated system, the record acquires attributes the agreement never described: a native format, a schema, an audit trail that is separate from the record itself, an access control model, a hosting location, a vendor release cycle, and an end-of-life date that has nothing to do with the retention period. The quality agreement still says the supplier will maintain records and make them available. It just no longer describes anything specific enough to enforce.
The gap is not a gap in the regulations
It is tempting to read this as a regulatory lag problem, and to wait for the revised texts. That reading is wrong in a way that matters commercially. The regulators have already said, repeatedly and in plain terms, that the contract giver carries the responsibility whatever the agreement says. FDA has been unusually blunt about it in recent enforcement. A June 2026 warning letter to a Puerto Rico manufacturer states: “FDA regards contractors as extensions of the manufacturer. You are responsible for the quality of your drugs regardless of agreements in place with your contract facilities.”14 A March 2026 letter to a contract microbiology laboratory uses the same construction: “FDA considers contractors as extensions of the manufacturer’s own facility.”13
Read that carefully. The agreement does not transfer the obligation. It only determines whether you can perform it. A quality agreement is not a liability shield. It is an operating manual for a relationship in which you remain answerable for records you do not hold, generated in systems you do not control, by people you do not employ.
The practical test for any clause in a digital quality agreement: if an inspector asked you today to produce what this clause promises, in the format the clause names, within the timeframe the clause states, could you do it without calling the supplier and asking a favor? If the answer depends on goodwill, the clause is decorative.
What the Rules Actually Require of the Contract
Before working clause by clause, it is worth setting out what the source documents actually say, because the drafting habits in circulation are often looser than the guidance they claim to follow.
ICH Q10
ICH Q10 places management of outsourced activities inside the pharmaceutical quality system rather than beside it. Section 2.7 states that the pharmaceutical company is ultimately responsible for ensuring processes are in place to control outsourced activities, and lists four elements, including “defining the responsibilities and communication processes for quality-related activities of the involved parties,” which for outsourced activities should be included in a written agreement between the contract giver and contract acceptor.2 Note the phrasing. The written agreement is where responsibilities and communication processes are defined. Communication processes, not just responsibilities. Most agreements are heavy on the first and thin on the second.
EU GMP Chapter 7 and the PIC/S GMP Guide
Chapter 7 of EudraLex Volume 4 is mirrored in Part I of the PIC/S GMP Guide, with slightly different clause numbering. Three provisions carry most of the weight for digital work. The contract should describe clearly which party is responsible for conducting each step of the outsourced activity, with an explicit list that includes knowledge management and technology transfer. All records related to the outsourced activities should be kept by, or be available to, the contract giver, and any records relevant to assessing product quality in the event of a complaint, a suspected defect, or a suspected falsified product must be accessible and specified in the contract giver’s own procedures. And the contract should permit the contract giver to audit the outsourced activities performed by the contract acceptor or by mutually agreed subcontractors.3
That third element is stronger than most agreements make it. The audit right is not limited to the supplier’s own site. It extends to subcontractors the contract giver has agreed to. In a digital relationship, the subcontractor is very often a hosting provider or a software vendor, and the audit right usually stops at the supplier’s front door because nobody drafted it to go further.
The API guide adds a clause most people forget
Part II of the PIC/S GMP Guide, which follows ICH Q7, contains a provision with awkward implications for cloud systems: manufacturing and laboratory records should be kept at the site where the activity occurs and be readily available.4 It also states that changes in the process, equipment, test methods, specifications, or other contractual requirements should not be made unless the contract giver is informed and approves the changes.4 Both provisions were written with a physical site in mind. Neither has been withdrawn because records moved to a data center in another country.
Data integrity guidance is where the digital detail lives
The most usable requirements for a digital quality agreement are in data integrity guidance rather than in the GMP chapters. MHRA’s GXP data integrity guidance states that contract givers should ensure data ownership, governance, and accessibility are included in any contract or technical agreement with a third party, and that the contract giver should perform a data governance review as part of vendor assurance.6 Its section on IT suppliers and service providers goes further: responsibilities of contract giver and acceptor should be defined in a technical agreement or contract; that agreement should ensure timely access to data including metadata and audit trails, both for the data owner and for national competent authorities on request; contracts should define responsibilities for archiving and continued readability of the data throughout the retention period; arrangements must exist for restoring the software or system to its original validated state, including the validation and change control information needed to permit that restoration; and business continuity arrangements should be in the contract and tested.6
PIC/S PI 041-1 adds that quality agreements should carry specific provisions for ensuring data integrity across the supply chain, including expectations for data governance, transparent error and deviation reporting by the contract acceptor, and a requirement to notify the contract giver of any data integrity failures identified at the contract acceptor site.5 It also states that contract acceptors are expected to provide reasonable access to data generated on behalf of the contract giver during audits.5
Where this leaves you. Every clause discussed in the rest of this article has a regulatory hook. None of them requires you to invent an expectation. What they require is that you translate a general expectation (“timely access to data including metadata and audit trails”) into something a supplier’s IT function can actually build and a quality unit can actually verify. That translation is the work.
Clause 1: Record Ownership, Originals, and Contract End
The failure mode
The typical clause says the supplier will maintain records relating to the manufacture and testing of the product, and will provide copies to the sponsor on request. In a paper relationship this is complete. In a digital one it leaves three questions open, and all three surface at the worst moment.
First, who holds the original. If the supplier’s LIMS generates the result and the sponsor receives a PDF certificate of analysis, the original record is in the supplier’s database and the sponsor holds a copy. That is a legitimate arrangement, but it means the sponsor’s ability to reconstruct the result depends entirely on a system it does not own. If the agreement does not say which party holds the original for which record type, both parties will assume they do, and neither will have built the controls that ownership implies.
Second, what happens at contract end. Termination clauses in the commercial agreement usually cover the return of materials and confidential information. They rarely cover the export of records from a validated system, in a form that preserves the link between each data element and its metadata. FDA’s guidance on electronic systems in clinical investigations names this problem directly: when systems are decommissioned and cannot be recommissioned, or when a contract with a hosted system ends, sponsors should ensure that the metadata are obtained and retained and can be linked to each corresponding data element.8 That sentence describes a technical project, not a contractual formality.
Third, whether access survives the relationship. MHRA’s guide for marketing authorization holders contracting with pharmacovigilance service providers puts the requirement in one line: clarity of record and data ownership, and access to source data and the safety database by the marketing authorization holder.7 The same post recommends terms for transition periods, particularly for data transfers, alongside contract termination rules.7 The principle transfers cleanly to manufacturing and laboratory work.
Example wording
Record ownership and continuity of access. The parties agree the attached Record Inventory, which identifies for each GxP record type: the generating system, the party holding the original record, the party holding a true copy, the retention period, and the export format available at contract end. The Supplier shall not change the generating system for any listed record type without notification under the System Change clause.
On expiry or termination for any reason, and during any transition period, the Supplier shall provide the Sponsor with a complete export of all records listed in the Record Inventory, including associated metadata and audit trail entries, in a format that preserves the association between each data element and its metadata. The export shall be delivered within thirty days of the effective date and shall be verified against a record count and checksum agreed in advance. The Supplier shall retain its own copy for a further ninety days following the Sponsor’s written confirmation that the export is complete and readable.
The operational check
Do the export once, at the start of the relationship, on a small and non-critical batch. This is the single highest-value check in this article, and almost nobody does it. A first export at contract end is a first export during a dispute, when the supplier’s cooperation is at its lowest and your leverage is gone. A first export in month two is a technical exercise with a friendly counterpart.
What you are checking is not whether a file arrives. It is whether the file can be read without the supplier’s application, whether the audit trail entries can be matched to the results they belong to, and whether your own archive can ingest it. Record how long the export took, who at the supplier ran it, and what it produced. That record becomes the acceptance criterion for the real export later.
Clause 2: Audit Trail Access Rights
The failure mode
Audit trail language in quality agreements usually says one of two things. Either the supplier will maintain audit trails in accordance with applicable regulations, which commits to nothing the supplier was not already required to do, or the supplier will make audit trails available for review during audits, which sounds adequate until you try to use it.
The practical problems are specific. Audit trail review at a supplier is normally done by the supplier. What the sponsor receives is a summary report. MHRA’s guidance is direct about the limits of that arrangement: where data review is not conducted by the organization that generated the data, responsibilities for data review must be documented and agreed by both parties, and summary reports are limited because critical supporting data and metadata may not be included.6 It adds that where summary reports are supplied by a different organization, the receiving organization should evaluate the data provider’s data integrity controls before using the information.6
Then there is format. An audit trail viewed on a screen in a conference room during a two-day audit is not the same as an audit trail exported for analysis. Many systems will display an audit trail but will not export it in a form that supports pattern review across batches. If your agreement does not specify export, you will be reading on the supplier’s terms.
Then there is confidentiality. Suppliers routinely refuse audit trail export on the grounds that the trail contains other clients’ activity. This is usually a real constraint rather than an evasion, and it has a documented solution that most agreements never mention.
The de-identification route. PIC/S PI 041-1 sets out that contract givers may work with the contract acceptor to ensure all client-confidential information is encoded to de-identify clients, which allows review of source electronic data and metadata at the contract giver’s site without breaking confidentiality obligations to other clients. Reviewing the larger data set supports a more thorough assessment of the contract acceptor’s data governance and permits a search for indicators of data integrity failure such as repeated data sets or data that does not show the expected variability.5 This is a regulator-described technique, not an unusual demand. Very few quality agreements reference it.
Example wording
Audit trail access. For each system listed in the Record Inventory, the Supplier shall on written request provide the Sponsor with an export of the audit trail entries associated with the Sponsor’s batches, in a delimited or structured electronic format capable of being opened and queried without the Supplier’s application software, within ten business days of the request. Where the Supplier’s audit trail cannot be filtered to the Sponsor’s activity alone, the Supplier shall provide a de-identified export in which other clients’ identifying information is encoded, and shall describe the encoding method.
The Supplier shall perform routine audit trail review at the frequency and scope described in Appendix B, shall retain evidence of that review, and shall make that evidence available to the Sponsor. The Sponsor’s receipt of a summary report does not discharge the Supplier’s obligation to provide the underlying entries on request.
The operational check
Request one audit trail export before you need one. Time it against the clause. Then run three questions against what arrives. Can you tell who made each change, when, and why, without asking the supplier to interpret it? Can you match an audit trail entry to the result on the certificate of analysis you received? Does the export include entries for events the supplier’s summary report did not mention, such as method parameter changes, reprocessing, or account permission changes?
The third question is the important one. A summary report is a filtered view of the trail, and the filter is designed by the party being reviewed.
Clause 3: Electronic Signature Acceptance Across Two Systems
The failure mode
Two organizations, each Part 11 compliant, each with a validated signature capability, and no agreement on whether either will accept the other’s signature. This is more common than it sounds, and it produces a specific and avoidable waste: documents signed electronically in one system, printed, wet-signed by the other party, scanned, and attached to an email. The hybrid record that results is worse than either pure form, because the relationship between the electronic original and the paper artifact is undocumented.
21 CFR Part 11 sets the controls for electronic records and signatures, including the requirement that signature manifestations carry the printed name of the signer, the date and time, and the meaning of the signature.15 What Part 11 does not do is tell party A whether party B’s implementation is acceptable. That is a judgment each quality unit makes, and two quality units routinely reach different conclusions about the same control set. One will treat a single-factor login with a session timeout as sufficient for a signature within a session. The other will require re-authentication at each signing event. Neither is wrong. They are simply not the same, and the agreement almost never records which interpretation governs a jointly executed document.
The documents where this bites are the shared ones: batch disposition records, deviation approvals that require sponsor concurrence, change control approvals, and validation summary approvals. These are exactly the documents that most need an unambiguous execution record.
Example wording
Electronic signature acceptance. Each party represents that its electronic signature controls meet the requirements of 21 CFR Part 11 Subpart C and EU GMP Annex 11, and shall provide the other party with a summary of those controls, including the authentication method, the components of the signature manifestation, and the linkage between the signature and the signed record.
The parties agree that documents listed in Appendix C shall be executed in the system named for each document, and that a signature applied in that system is accepted by both parties without countersignature. Where a document requires signature by both parties and no shared system is available, the parties shall use the Sponsor’s system, and the Supplier shall be granted named user accounts for that purpose. Neither party shall require a wet signature on a document listed in Appendix C. Any change to a party’s authentication method for a listed system shall be notified under the System Change clause.
The operational check
Take one signed document from each direction and try to reconstruct the signing from the record alone. Does the manifestation show the signer’s printed name, the date and time, and the meaning of the signature? Can the receiving party’s quality unit determine, from the document, which authentication method was used? If the answer requires an email to the other party’s IT function, the acceptance clause is not operational, whatever it says.
A second check: count the wet signatures still occurring in the relationship. Every one of them is either a deliberate decision recorded somewhere, or a control gap that nobody has noticed.
Clause 4: Data Transfer Format, Timing, and Validation
The failure mode
Almost every quality agreement specifies what the supplier will send and when. Very few specify the form, and fewer still say who is responsible for confirming that the transfer preserved the data.
The form question is not cosmetic. A PDF scan of a chromatogram is a picture of a result. A structured export of the same result is a result. The two support entirely different downstream activities. If your intention is trend analysis across batches, comparison against the supplier’s certificate of analysis, or feeding a data lake that supports annual product quality review, a PDF is a dead end and you will discover that after the twentieth batch, not the first.
The validation question is worse, because both parties tend to assume the other has it. The supplier validates its export routine. The sponsor validates its import routine. Nobody validates the transfer, which is the part where a date format changes, a decimal separator moves, a unit is dropped, or a field is truncated. FDA’s guidance on electronic systems states that validation should be applied to system functionality, configurations, customizations, data transfers, and interfaces between systems.8 Data transfers are named explicitly and separately from the systems on either end.
Specify the artifact, not the activity
“The Supplier will provide analytical results” describes an activity. “The Supplier will provide a delimited file conforming to the schema in Appendix D, plus a signed PDF certificate of analysis” describes two artifacts, one of which is machine readable and one of which is the regulatory record.
Separate the deadline from the trigger
“Within five business days of batch completion” and “within five business days of the Supplier’s quality unit approval” are different clauses with different meanings. Name the event that starts the clock, and name who records that the event occurred.
Assign the reconciliation, not just the transfer
State which party reconciles the received data against the source, what the reconciliation compares (record count, checksum, a defined set of critical fields), and what happens when it fails. A transfer with no owner for reconciliation is an unverified transfer.
Version the schema
Treat the transfer schema as a controlled document with a version number and a change control path. A supplier system upgrade that adds a column is a schema change, and it should reach the sponsor as a notification, not as a failed load at three in the morning.
Example wording
Data transfer. The Supplier shall transfer the data elements listed in Appendix D in the format and schema version specified there, using the transfer method specified there, within the interval specified there measured from the trigger event named there. The Supplier shall provide a transfer manifest with each transfer stating the record count and a checksum for the transferred file.
The Sponsor shall reconcile each received transfer against the manifest within five business days and shall notify the Supplier of any discrepancy. The parties shall jointly qualify the transfer at implementation and following any change to the schema, the source system, or the receiving system, using the protocol at Appendix E. Neither party shall change the schema without written agreement and a documented change control record referencing this Appendix.
The operational check
Take the last transfer you received and pick five results at random. Trace each one back to the supplier’s source system value. Not to the certificate of analysis, which is itself a downstream artifact, but to the value in the instrument or LIMS record. Check the decimal precision, the units, the reported significant figures, and the associated date and time including its time zone.
Time zone is worth its own sentence. A supplier operating in a different zone, exporting timestamps without an offset, will produce a data set in which some events appear to occur before the events that caused them. This is a routine finding and it is invisible until somebody looks.
Clause 5: System Change Notification
The failure mode
This is the clause with the widest gap between what the agreement covers and what actually changes. FDA’s quality agreements guidance recommends the agreement address expectations for reporting and approving changes to components and their suppliers, establishment locations, manufacturing processes, products or product types sharing a production line or equipment train or facility, testing procedures, major manufacturing equipment, shipping methods, lot numbering scheme, container closure systems, tamper evidence features, and product distribution.1 That is eleven categories and it is a good list. It is also a list of physical things. A LIMS version upgrade, an eQMS migration to a new hosting tenant, a change of identity provider, or a switch from an on-premises historian to a vendor-managed service does not appear on it.
Some of those changes are covered by implication. A change to testing procedures may be triggered by a software upgrade that changes an integration algorithm. But implication is not notification, and in practice the sponsor learns about the supplier’s system upgrade when a report format changes or a field stops arriving.
The regulators are moving on this. The EMA and PIC/S concept paper on revising Annex 11, agreed in late 2022, states that the list of services in the suppliers and service providers section should include operating a computerized system, for example cloud services, and that for critical systems validated or operated by service providers the expectations should go beyond a requirement that formal agreements must exist. Regulated users should have access to the complete documentation for validation and safe operation of a system and be able to present it during regulatory inspections, with the help of the service provider where needed.10 The revised Annex 11 remains in development and there is no adopted final text; the concept paper tells you where inspector expectations are heading, not what is in force today.
Example wording
System change notification. The Supplier shall notify the Sponsor in writing of any of the following in respect of a system listed in the Record Inventory, no fewer than sixty days before implementation for planned changes and within two business days for emergency changes: a major or minor version upgrade of the application; a change of hosting provider, hosting tenant, or hosting region; a change of the authentication or identity provider; a change to the audit trail configuration or retention; a change to the data model, schema, or export capability; migration of data to a different system; or planned retirement of the system.
For each notified change the Supplier shall provide the change control record reference, the assessment of GxP impact, the validation approach, and confirmation of whether the change affects any artifact listed in Appendix D. The Sponsor shall have thirty days to request additional information or to require joint qualification of the transfer under the Data Transfer clause. Approval shall not be unreasonably withheld.
The operational check
Ask the supplier for the change control log for the named systems covering the last twelve months, filtered to GxP-relevant changes. Then compare it to the notifications you received. The delta is the true state of the clause.
This check is uncomfortable and it is the most informative thing in this article. It is also fair: run the same comparison in the other direction, because sponsors upgrade their systems without telling suppliers at least as often.
Clause 6: Deviation and Investigation Visibility
The failure mode
Almost every quality agreement contains a deviation notification clause, and almost every one of them is written around a monthly or quarterly quality report. That cadence was set by the effort of producing a report by hand. It has no other justification, and it survives in agreements signed long after both parties acquired systems capable of showing the other party a deviation the day it opens.
The consequence is a lag between when a supplier knows something and when the sponsor can act on it. For a minor deviation the lag is harmless. For a deviation that affects a batch already in transit, or a data integrity concern, the lag is the whole problem. PIC/S PI 041-1 is explicit that quality agreements should include transparent error and deviation reporting by the contract acceptor and a requirement to notify the contract giver of any data integrity failures identified at the contract acceptor site.5 It does not describe a monthly report.
There is a second failure that is subtler. Agreements set notification triggers by severity classification, and severity is classified by the supplier using the supplier’s own criteria. A supplier’s “minor” and a sponsor’s “minor” are not the same category, and the sponsor never sees the events the supplier classified below the notification threshold. The threshold is being applied by the party with the least incentive to escalate.
A note on real-time visibility. Read-only sponsor access to a supplier’s deviation system is now technically straightforward and is often refused for reasons that are commercial rather than technical. Where full access is not available, a scheduled automated extract of deviation headers, meaning identifier, date opened, product, classification, and one-line description, with the full record on request, delivers most of the benefit and is much easier to agree. Ask for the extract before you ask for the login.
Example wording
Deviation and investigation visibility. The Supplier shall notify the Sponsor within one business day of opening any deviation, discrepancy, out-of-specification result, or investigation that relates to the Sponsor’s product, materials, or records, irrespective of the Supplier’s severity classification. Notification shall include the record identifier, the date opened, the affected batch or record, and a factual description. The Supplier shall notify the Sponsor within one business day of identifying any suspected or confirmed data integrity issue affecting the Sponsor’s records, including issues identified through the Supplier’s own audit trail review.
The Supplier shall provide the Sponsor with a weekly extract of all open records meeting the above criteria, in the format at Appendix F. Classification of severity for the purpose of this clause shall follow the joint criteria at Appendix G. The Sponsor may request the complete investigation record at any point and the Supplier shall provide it within five business days of the request.
The operational check
Compare the deviation records you received over the last year against the supplier’s own count of deviations that touched your product. If the supplier will not give you the count, that is itself the finding. Where the numbers differ, look at what was classified below your notification threshold and ask whether you would have classified any of it the same way.
The FDA warning letter to the contract microbiology laboratory cited earlier records exactly this pattern, describing a discrepancy between the out-of-specification and out-of-limit investigations provided to FDA and those communicated to customers.13 The letter also states plainly that the laboratory must inform all its customers of any out-of-specification results or significant problems encountered during testing.13
Clause 7: Retention, Retrieval, and Readability
The failure mode
Retention clauses almost always name a period and stop. The period is the easy part. The hard parts are retrieval within a usable timeframe and readability at the end of the period, and neither is addressed by stating a number of years.
FDA’s quality agreements guidance is unusually specific here. It says the agreement should define the parties’ roles in making and maintaining original documents or true copies in accordance with CGMP, should explain how those records will be made readily available for inspection, and should indicate that electronic records will be stored in accordance with CGMP and will be immediately retrievable during the required record-keeping time frames.1 “Immediately retrievable” is a strong phrase and most agreements do not test it.
Readability across a long retention period is the requirement nobody owns. MHRA’s guidance states that contracts with providers should define responsibilities for archiving and continued readability of the data throughout the retention period.6 PIC/S PI 041-1 expects, when reviewing outsourced archived operations, that there is a quality agreement in place, that the storage location was audited, and that some assessment exists of whether documents will still be legible and available for the entire archival period.5
The exposure is real. A retention period of ten years covers roughly three major versions of most laboratory and quality applications, and at least one likely change of vendor. Clinical work is worse: EMA’s guideline on the clinical trial master file expects sponsors and investigators to archive trial master file content for at least twenty-five years after the end of the trial unless other law requires longer, and expects the trial master file including the audit trail for an electronic trial master file to be archived so that supervision remains possible after the trial ends.12 Twenty-five years is longer than the commercial lifetime of most software products.
Example wording
Retention, retrieval, and readability. The Supplier shall retain the records listed in the Record Inventory for the period stated there, and shall retrieve and provide any such record, with associated metadata and audit trail entries, within five business days of a written request and within two business days where the request states that it relates to a regulatory inspection or a suspected product defect.
The Supplier shall maintain the ability to render each retained record in human-readable form for the full retention period. Where a system holding retained records is upgraded, replaced, or retired, the Supplier shall either migrate the records with their metadata and audit trail entries to the successor system and requalify readability, or transfer the records to the Sponsor under the Record Ownership clause before decommissioning. The Supplier shall confirm in the annual quality review that a readability check has been performed on a sample of retained records from each system and each format in scope, and shall report the result.
The operational check
Once a year, ask for one record from the oldest year still in retention, from the system that has changed most since. Time the retrieval. Open the result on a machine that does not have the supplier’s software installed. This is a thirty-minute exercise that produces a defensible statement about a ten-year obligation.
Add a second check for legacy formats specifically. Ask what the supplier would do if asked for a record held in a system retired three years ago. If the answer is that they keep a virtual machine of the old application, ask who validated it and who holds the license.
Clause 8: Subcontracting, Cloud Hosting, and Location
The failure mode
Subcontracting clauses are usually strong on physical work and silent on data processing. The supplier may not subcontract manufacturing without approval, and then it hosts its eQMS with a software vendor, which hosts on a hyperscale cloud, which replicates across three regions the sponsor was never told about. Nobody considers this subcontracting because nobody manufactures anything.
The GMP texts do not make that distinction. The contract acceptor should not pass any of the work entrusted under the contract to a third party without the contract giver’s prior evaluation and approval of the arrangements, and arrangements between the contract acceptor and a third party should ensure information and knowledge, including from assessments of the third party’s suitability, are made available in the same way as between the original contract giver and contract acceptor.3 Operating the system that holds the GxP record is work entrusted under the contract.
Location matters for two separate reasons and they are often conflated. The first is regulatory: PIC/S Part II expects manufacturing and laboratory records to be kept at the site where the activity occurs and be readily available,4 and inspectors will ask where the record actually is. The second is legal: MHRA’s guidance says the physical location where data is held, including the impact of any laws applicable to that geographic location, should be considered.6 A data set replicated into a jurisdiction with different disclosure law is a different exposure from one held in a single named region.
FDA’s clinical guidance gives the most concrete list of what to ask of a system operator. It recommends a written agreement, which may be a master service agreement with an associated service level agreement or a quality agreement, that describes how the IT services will meet the regulated entity’s requirements, and that addresses at minimum the scope of the work and service, the roles and responsibilities of both parties including those related to quality management, and a plan that ensures the sponsor will have access to data throughout the regulatory retention period.8 It also states that FDA may inspect IT service providers who have assumed regulatory responsibilities, and may conduct focused inspections of IT service providers where there are concerns about data integrity regardless of whether regulatory obligations were transferred, and that in all cases the sponsor should have access to all study-related records maintained by IT service providers.8
Example wording
Subcontracting of data processing and hosting. The Supplier shall not engage any third party to host, operate, administer, back up, or archive a system holding the Sponsor’s GxP records without the Sponsor’s prior written approval. The Supplier shall maintain and provide on request a register of such third parties stating for each: the service provided, the hosting region or regions including any replication or backup region, the applicable quality or service agreement, and the date and outcome of the Supplier’s most recent assessment of that party.
The Supplier shall notify the Sponsor at least sixty days before adding a third party to that register or changing a hosting region. The Supplier shall ensure that its agreements with such third parties give the Supplier, and permit the Supplier to give the Sponsor, the access, audit, notification, and record retrieval rights required under this Agreement, including access for regulatory authorities. The Supplier shall make available to the Sponsor the validation and operational documentation for any system operated by a third party, obtaining it from that party where the Supplier does not hold it.
The operational check
Ask for the register. If one does not exist, ask three questions and see how long the answers take: which country holds the primary copy of our batch records today, which countries hold backups or replicas, and which third party has administrator access to that system. Suppliers with a mature IT function answer in a day. If the answer takes three weeks, the answer itself is less important than what the delay told you.
Then check the flow-down. Ask to see the clause in the supplier’s agreement with its hosting provider that gives the supplier the audit and access rights you have contracted for. A right you hold against a party that does not hold it against the party who actually has the data is not a right, it is an expectation.
The Clause-by-Clause Summary
The table below collects the eight clauses, the way each one fails once either party digitizes, and the check that proves the clause works. The checks are deliberately small. Each of them can be run by one person in under a day, and each produces evidence you can put in a supplier file.
| Clause | How it fails after digitization | Operational check |
|---|---|---|
| Record ownership and access | Agreement says records will be maintained and copies provided. Does not say who holds the original per record type, or how records leave a validated system at contract end with metadata intact. | Run a full export on a non-critical batch in month two of the relationship. Confirm it opens without the supplier’s software and that audit trail entries can be matched to results. |
| Audit trail access | Sponsor receives supplier-produced summary reports. No export right, no format, no route around multi-client confidentiality. | Request one export against the stated timeframe. Check whether it contains event types the summary report omitted. |
| Electronic signature acceptance | Two compliant implementations, two different interpretations, no agreement on whose signature governs a shared document. Result is hybrid print-sign-scan records. | Reconstruct one signing in each direction from the record alone. Count the wet signatures still occurring. |
| Data transfer | What and when are specified; format and reconciliation are not. PDF scans arrive where structured data was needed. Nobody owns transfer validation. | Trace five random results back to the source system value. Check precision, units, and time zone offset. |
| System change notification | Change control list covers physical changes only. Supplier upgrades its LIMS or eQMS and the sponsor learns from a broken report. | Compare the supplier’s twelve-month GxP change log against the notifications actually received. Run it in both directions. |
| Deviation visibility | Notification cadence set by the effort of a manual report. Severity threshold applied by the party with the least incentive to escalate. | Compare deviations received against the supplier’s own count of deviations touching your product. Review what fell below the threshold. |
| Retention and readability | A period is named. Retrieval time and end-of-period readability are not. Systems change three times inside one retention period. | Annually, retrieve one record from the oldest retained year and open it on a machine without the supplier’s software. Time it. |
| Subcontracting and hosting | Clause covers physical subcontracting only. Hosting, administration, and backup are treated as IT arrangements rather than as subcontracted work. | Request the third-party register. Check that the supplier’s own hosting contract flows down the access and audit rights you hold. |
Renegotiating Without Reopening Everything
The most common reason none of this gets fixed is that reopening a quality agreement is understood as reopening the commercial relationship. Somebody has to raise it with the supplier, legal gets involved, the supplier’s legal gets involved, and a document that took nine months to sign the first time goes back into the queue. Quality leaders make a reasonable judgment that the effort is not worth it, and the agreement stays as it is until a regulatory finding forces the issue.
There is a narrower route. The eight clauses above are technical rather than commercial. None of them changes price, allocation of liability, indemnity, term, or termination rights. That distinction is the whole basis of the approach below, and it is worth naming explicitly when you open the conversation with the supplier, because their first assumption will be that you are reopening the deal.
Run the checks before you draft anything
Work through the eight operational checks against your current largest supplier. Do not propose language yet. What you are building is a factual account of which clauses already work, which work informally through goodwill, and which cannot be performed at all. Most quality agreements turn out to be sound on three or four of the eight, which makes the ask much smaller than it first appears.
Put the detail in an appendix, not the body
The Record Inventory, the transfer schema, the notification triggers, the third-party register, and the joint severity criteria all belong in appendices that the agreement references. Appendices can be revised by agreement between the two quality units under a change control record. Body text usually cannot. Getting the structure right once means the next five years of changes are administrative rather than legal.
Use a technical addendum for the clauses themselves
Rather than amending the agreement, add a data and systems addendum that supplements it and states that in the event of conflict on the subjects it covers, the addendum governs. This is a familiar instrument to legal teams on both sides, it does not reopen the main document, and it can be negotiated by quality and IT with legal reviewing rather than drafting.
Time it to an event the supplier already has open
Periodic review of the quality agreement, a scheduled supplier audit, a product transfer, a change of the supplier’s own system, or a new product being added to an existing agreement are all moments when the document is already being touched. Attaching the addendum to an event the supplier initiated changes the conversation from a demand into a housekeeping item.
Offer the same terms in both directions
Every clause here is capable of being reciprocal, and most suppliers will accept faster if the sponsor accepts the same obligations. Sponsors change their systems too, and a supplier that has been surprised by a sponsor’s ERP migration has a legitimate grievance. Reciprocity also produces better clauses, because you will not agree to a two-day notification you cannot meet yourself.
Sequence by exposure, not by supplier size
Start with the relationships where the supplier holds the original record for something you would need in an inspection or a recall, not with the supplier who invoices the most. A small contract testing laboratory holding the only copy of your stability chromatography is a larger exposure than a large fill-finish partner whose batch records you already receive in full.
One caution on scope. An addendum that covers everything in one pass will be negotiated as though it were a new agreement. If the supplier relationship is difficult or the document is old, take the three clauses where your checks found real gaps and leave the rest. A short addendum signed this quarter is worth more than a complete one still in review next year. The Record Inventory is usually the right first clause, because the other seven all reference it.
What to do when the supplier says no
Some suppliers will refuse specific clauses, and some refusals are reasonable. A contract laboratory serving forty clients cannot give each of them read access to its LIMS. A software vendor may genuinely be unable to expose an audit trail export because the product does not support one.
Where a clause is refused, record the refusal and the reason, then treat the gap as a risk you own rather than a matter that has been settled. That means documenting a compensating control, which might be more frequent audits, a wider sample in your incoming data review, or an alternative source for the same assurance. It also means the gap appears in your own quality system as an open item, which is where an inspector would expect to find it. The regulators’ position leaves you no other option: the responsibility does not move, so an unclosed gap in a supplier’s capability is an unclosed gap in yours.
It also gives you something concrete for the next commercial cycle. A documented list of the assurances a supplier could not provide, with the compensating effort you carried as a result, is a far better input to a renewal negotiation than a general sense that the relationship is harder than it should be.
Conclusion
The quality agreements in force across the industry are not wrong. They are answering a question that has changed. When both parties worked on paper, defining responsibilities was enough, because the mechanics of moving a record between two organizations were obvious to everyone involved. Once both parties run validated systems, the mechanics stop being obvious, and an agreement that defines responsibilities without defining mechanics describes a relationship that cannot be performed as written. The eight clauses in this article are the places where that shows up first, and each of them can be tested in an afternoon with a request the supplier will consider ordinary.
What we would emphasize to anyone starting this work is the order. The instinct is to draft first and test later, because drafting feels like progress and testing feels like admitting you do not know. The opposite sequence produces better agreements and much shorter negotiations. Run the checks, find the three clauses that are genuinely broken, and take those three to the supplier with evidence rather than principle. Suppliers argue with proposed language. They rarely argue with a failed export you both watched.
Sakara Digital works with pharma and biotech organizations on the systems and data side of supplier relationships, including quality agreement content, record ownership across organizational boundaries, and the evidence that supports it during inspection. If you are looking at a portfolio of agreements written for a paper relationship and trying to work out where to start, we are happy to have that conversation.
For Further Reading
For Further Reading
- Data Quality SLAs in CRO and CDMO Contracts: Language That Actually Holds
- GxP Records Retention and Archiving: Designing for 30 Years
- Tech Transfer to a CDMO: The Digital Playbook
- Cloud Data Residency for Global Pharma: EU, US, and APAC Requirements
- Supplier Quality Management for Pharma: What Good Looks Like in 2026
References & Sources
- U.S. Food and Drug Administration. “Contract Manufacturing Arrangements for Drugs: Quality Agreements, Guidance for Industry.” CDER, CBER, CVM, November 2016. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/contract-manufacturing-arrangements-drugs-quality-agreements-guidance-industry
- International Council for Harmonisation. “ICH Guideline Q10 on Pharmaceutical Quality System, Step 5.” EMA/CHMP/ICH/214732/2007. https://www.ema.europa.eu/en/documents/scientific-guideline/international-conference-harmonisation-technical-requirements-registration-pharmaceuticals-human-guideline-q10-pharmaceutical-quality-system-step-5_en.pdf
- Pharmaceutical Inspection Co-operation Scheme. “Guide to Good Manufacturing Practice for Medicinal Products, Part I (PE 009-17),” Chapter 7 Outsourced Activities and Chapter 4 Documentation, 25 August 2023. Mirrors EudraLex Volume 4 Chapter 7, in operation since 31 January 2013. https://picscheme.org/docview/6606
- Pharmaceutical Inspection Co-operation Scheme. “Guide to Good Manufacturing Practice for Medicinal Products, Part II (PE 009-17),” Section 16 Contract Manufacturers (Including Laboratories), 25 August 2023. https://picscheme.org/docview/6607
- Pharmaceutical Inspection Co-operation Scheme. “Good Practices for Data Management and Integrity in Regulated GMP/GDP Environments (PI 041-1),” 1 July 2021. https://picscheme.org/docview/4234
- Medicines and Healthcare products Regulatory Agency. “‘GXP’ Data Integrity Guidance and Definitions, Revision 1,” March 2018. https://www.gov.uk/government/publications/guidance-on-gxp-data-integrity
- MHRA Inspectorate. “MHRA GPvP Inspectorate Guide to Marketing Authorisation Holder Considerations for Agreements with Pharmacovigilance System Service Providers,” 22 January 2018. https://mhrainspectorate.blog.gov.uk/2018/01/22/mhra-gpvp-inspectorate-guide-to-marketing-authorisation-holder-considerations-for-agreements-with-pharmacovigilance-system-service-providers/
- U.S. Food and Drug Administration. “Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers, Guidance for Industry,” October 2024. https://www.fda.gov/regulatory-information/search-fda-guidance-documents/electronic-systems-electronic-records-and-electronic-signatures-clinical-investigations-questions
- Federal Register. “Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers; Guidance for Industry; Availability,” 2 October 2024. https://www.federalregister.gov/documents/2024/10/02/2024-22562/electronic-systems-electronic-records-and-electronic-signatures-in-clinical-investigations-questions
- European Medicines Agency GMP/GDP Inspectors Working Group and PIC/S. “Concept Paper on the Revision of Annex 11 of the Guidelines on Good Manufacturing Practice for Medicinal Products: Computerised Systems,” EMA/INS/GMP/778340/2022, 19 September 2022. https://www.ema.europa.eu/en/documents/regulatory-procedural-guideline/concept-paper-revision-annex-11-guidelines-good-manufacturing-practice-medicinal-products-computerised-systems_en.pdf
- European Medicines Agency. “Guidance on Good Manufacturing Practice and Good Distribution Practice: Questions and Answers.” https://www.ema.europa.eu/en/human-regulatory-overview/research-development/compliance-research-development/good-manufacturing-practice/guidance-good-manufacturing-practice-good-distribution-practice-questions-answers
- European Medicines Agency. “Guideline on the Content, Management and Archiving of the Clinical Trial Master File (Paper and/or Electronic).” https://www.ema.europa.eu/en/documents/scientific-guideline/guideline-content-management-and-archiving-clinical-trial-master-file-paper-andor-electronic_en.pdf
- U.S. Food and Drug Administration. Warning Letter to Microbiological Testing & Consulting, LLC, 320-26-53, 16 March 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/microbiological-testing-consulting-llc-720374-03162026
- U.S. Food and Drug Administration. Warning Letter to Laboratorios Dr. Collado S.A., 320-26-87, 2 June 2026. https://www.fda.gov/inspections-compliance-enforcement-and-criminal-investigations/warning-letters/laboratorios-dr-collado-sa-723285-06022026
- Electronic Code of Federal Regulations. 21 CFR Part 11, Electronic Records; Electronic Signatures. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-A/part-11
- Electronic Code of Federal Regulations. 21 CFR 211.68, Automatic, Mechanical, and Electronic Equipment. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211/subpart-D/section-211.68
- Electronic Code of Federal Regulations. 21 CFR 211.194, Laboratory Records. https://www.ecfr.gov/current/title-21/chapter-I/subchapter-C/part-211/subpart-J/section-211.194








Your perspective matters—join the conversation.