Assessment

Manufacturer Sponsor-Pack Audit

The documents a CRO needs on day one, assembled and gap-checked from the sponsor's side of the table — before the vendor audit, not after.

Fee quoted on scope
scoped per engagement
3–4 weeks
typical turnaround
7
perimeters assessed

A sponsor’s vendor audit tests your documentation, not your device.

A sponsor's vendor audit is not a test of your product. It is a test of whether your technical documentation, your quality system scope, your software lifecycle and your usability file answer the questions a sponsor is obliged to ask. A specification sheet does not answer them. Neither does a CE certificate on its own. The audit is usually the last step before a contract — the worst place to discover a gap.

What we assess

The seven perimeters of the DHT Readiness Scorecard, read as a sponsor's QA function reads them:

What you get

The deliverable is the pack, not just the findings. A sponsor receives a supplier who has done their homework, and the sponsor’s vendor audit has fewer findings to raise.

Scope

Three to four weeks. Document review; interviews with RA/QA, software and commercial leads; drafting of the two policies where absent; assembly of the pack. Handed back as a controlled document set with a version and a date. Re-audit scoped to the version that changed.

Request this assessment

Tell us about the device and the protocol. We come back with a written scope, price and date — no obligation.

Name, manufacturer and model if you have it. List every item if there is more than one.
The single most important field. Screening, primary endpoint, secondary endpoint, safety monitoring, engagement only?
Which specific endpoints, and whether any safety decision is informed by its output.
e.g. EU, US, UK, Japan, Canada, China.
Who supplies it, whether you relabel, reconfigure or assemble kits, and whether you import into the EU.
Firmware or app updates expected, protocol amendments planned, algorithm retraining, supplier changes.
Vendor declarations, CE certificates, validation reports, prior assessments, DPIAs.
A date or a milestone.

We treat everything you send as confidential and handle it in line with our Privacy Policy. Do not include patient-identifiable data — we never need it.