| name | qualify-vendor |
| title | 資廠商 |
| description | 資 GxP 相關軟體或服務之廠商或供。含廠險分、評問卷設、案頭與現場審法、 質協評、SLA 審、續監節奏定。 GxP 關鍵系統擇新廠、為合規數納雲供、行定期重資、審發現需重評、 或 EU Annex 11 或 ICH Q10 要供資時用之。 |
| author | pjt222 |
| author_url | https://github.com/pjt222/agent-almanac/tree/main/i18n/wenyan/skills/qualify-vendor |
| license | MIT |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | life-sciences |
| language | zh |
資廠商
評並資供 GxP 相關軟體、基設、或服務之廠商,以確其達監管質標。
用時
- 為 GxP 關鍵電腦化系擇新廠
- 為合規數納雲服商
- 既廠之定期重資已到
- 審發現需重評
- 監管要求供資(EU Annex 11 §3.4、ICH Q10)
入
- 必要:廠名、品/服、欲 GxP 用
- 必要:廠險分準
- 必要:適監管所需
- 可選:廠供之質文(ISO 認證、SOC 報)
- 可選:往廠審報或資錄
- 可選:參客之經驗
法
第一步:分廠險
依 GxP 影定廠險級:
# Vendor Risk Classification
## Document ID: VRC-[VENDOR]-[YYYY]-[NNN]
### Risk Classification Criteria
| Factor | Weight | Critical | Major | Minor |
|--------|--------|----------|-------|-------|
| GxP impact | 40% | Directly processes GxP data or affects product quality | Supports GxP processes indirectly | No GxP impact |
| Data access | 20% | Accesses or stores GxP-regulated data | Accesses supporting data only | No data access |
| Substitutability | 15% | Sole source, no alternative | Limited alternatives | Multiple alternatives |
| Regulatory exposure | 15% | Subject to regulatory inspection | May be referenced in submissions | No regulatory exposure |
| Business criticality | 10% | System downtime stops operations | Downtime causes delays | Minimal operational impact |
### Vendor Classification
| Vendor | Product/Service | Risk Score | Classification | Qualification Approach |
|--------|----------------|------------|---------------|----------------------|
| [Vendor name] | [Product] | [Score] | Critical / Major / Minor | On-site audit / Desk audit / Questionnaire only |
### Qualification Approach by Risk
| Risk Level | Qualification Activities | Re-qualification Frequency |
|------------|------------------------|---------------------------|
| **Critical** | Questionnaire + desk audit + on-site audit | Annual |
| **Major** | Questionnaire + desk audit | Every 2 years |
| **Minor** | Questionnaire only | Every 3 years |
得:廠險分驅相稱之資力。
敗則:若險分爭議,默高級。低資關鍵廠為監管險。
第二步:設並送評問卷
# Vendor Assessment Questionnaire
## Document ID: VAQ-[VENDOR]-[YYYY]-[NNN]
### Section 1: Company Information
1. Legal name, address, and parent company (if applicable)
Number of employees (total and in quality/development)
Products and services relevant to this qualification
Key customers in the pharmaceutical/life sciences industry
Do you maintain a certified QMS? (ISO 9001, ISO 13485, ISO 27001 — provide certificates)
Describe your document control system
Describe your change management process
Describe your CAPA process
How do you handle customer complaints?
When was your last external audit? Provide the summary report.
Describe your software development lifecycle (SDLC)
Do you follow GAMP 5, IEC 62304, or other development standards?
Describe your testing methodology (unit, integration, system, regression)
How do you manage source code (version control, branching, code review)?
Describe your release management process
How do you handle bug reports and patches?
How do you ensure data integrity (ALCOA+ principles)?
Describe your audit trail capabilities
Describe your access control model (role-based, attribute-based)
Describe your data backup and recovery procedures
Have you had any data breaches in the last 3 years? If yes, describe.
Provide your most recent SOC 2 Type II report (if available)
Are your products used in FDA-regulated or EU-regulated environments?
Can you provide a 21 CFR Part 11 compliance statement?
Can you provide an EU Annex 11 compliance statement?
Do you provide validation support documentation (IQ/OQ/PQ packs)?
How do you notify customers of changes that may affect their validated state?
Describe your support tiers and response times
What is your system availability target (uptime SLA)?
Describe your disaster recovery and business continuity plan
What is your customer notification process for planned and unplanned downtime?
What is your end-of-life/end-of-support policy?