Assessment
Manufacturer Sponsor-Pack Audit
The documents a CRO needs on day one, assembled and gap-checked from the sponsor's side of the table — before the vendor audit, not after.
Fee quoted on scope
scoped per engagement
3–4 weeks
typical turnaround
A sponsor’s vendor audit tests your documentation, not your device.
A sponsor's vendor audit is not a test of your product. It is a test of whether your technical documentation, your quality system scope, your software lifecycle and your usability file answer the questions a sponsor is obliged to ask. A specification sheet does not answer them. Neither does a CE certificate on its own. The audit is usually the last step before a contract — the worst place to discover a gap.
What we assess
The seven perimeters of the DHT Readiness Scorecard, read as a sponsor's QA function reads them:
- Medical device: regulatory status, per market and intended purpose. Classification, CE marking, the FDA pathway and, where the device is used investigationally, its IDE status, current for the configuration a sponsor will deploy. EU MDR Art. 2(1), Art. 20, Art. 52, Annex VIII; 21 CFR 807, 812, 814, 860.
- GxP and computerised systems: quality system and software lifecycle. ISO 13485 scope covering the product in use; IEC 62304 safety classification recorded and justified; traceability from requirement to test.
- Data protection. What the product collects, your processing role, storage and transfers, and a DPIA a sponsor can use. GDPR Art. 28, Art. 32, Art. 35.
- Human factors: usability file scope. The populations it covers — and, stated plainly, the ones it does not. IEC 62366-1.
- Configuration and change: change control in the field. How a firmware, app or algorithm change is classified, validated and communicated to sponsors with devices already in a study; deprecation and end-of-support policy. IEC 62304 §6, §8; FDA DHT guidance (2023).
- Economic operator: manufacturer obligations that do not pause for a trial. Post-market surveillance, vigilance timelines, the authorised-representative mandate and the PRRC. EU MDR Art. 11, 15; Art. 83–86 (post-market surveillance); Art. 87–92 (vigilance).
- Endpoint and protocol: validation and its limits. What the device has been validated to measure, in which population, and what you will not support as an endpoint.
What you get
- A gap assessment of the technical documentation and QMS scope against what a sponsor's vendor audit asks for
- A software lifecycle review against IEC 62304, including the safety classification and its justification
- A usability file scope statement naming the populations covered and not covered
- A change-notification and end-of-support policy, drafted where absent
- A validation-limits statement — the populations, conditions and use cases the device has not been validated for
- The sponsor pack itself: the assembled document set to hand a CRO on day one
The deliverable is the pack, not just the findings. A sponsor receives a supplier who has done their homework, and the sponsor’s vendor audit has fewer findings to raise.
Scope
Three to four weeks. Document review; interviews with RA/QA, software and commercial leads; drafting of the two policies where absent; assembly of the pack. Handed back as a controlled document set with a version and a date. Re-audit scoped to the version that changed.