ICH Q10 - Pharmaceutical Quality System ICH-Q10-Section2-Outsourced-Ownership-Vendor-Supplier-CMO-CRO: ICH Q10 Section 2 - Outsourced Activities + Management of Materials + Change of Ownership + CMO + CRO + Supplier Management
Section 2.7 Management of Outsourced Activities + Section 2.8 Change in Product Ownership address external party arrangements which retain PQS responsibility with the marketing authorisation holder (MAH). Outsourced activities + materials (Section 2.7): selection + assessment + qualification of contract acceptors (Contract Manufacturing Organisations CMO + Contract Research Organisations CRO + service providers + material suppliers + carriers + laboratories); written agreement (Quality Technical Agreement QTA + Master Service Agreement MSA) defining roles + responsibilities + communication + decision-making + change control + deviation + investigation + complaints + audit right; ongoing oversight (audit + KPI + quality scorecard); regulatory submission of qualified suppliers + facilities. Supplier qualification: initial qualification (audit + sample testing + capability + risk assessment) + ongoing monitoring (incoming quality + performance + audit + change notification); risk-tiered approach + critical materials require enhanced oversight; supplier-related deviations + CAPA. Section 2.8 Change in Product Ownership: when product transferred between MAHs (acquisition + divestment + merger + license transfer): regulatory notification per market + change of MAH submission + transfer of PQS documentation + retention of records + continuity of supply + variations to commitments. Coordinates with FDA 21 CFR 211.84 (component supplier qualification) + EMA QTA Guidance + ICH Q7 (GMP for APIs) + ISO 9001 Section 8.4 (Externally Provided Processes Products and Services) + GAMP 5 supplier management + Risk-based supplier control + EU GMP Annex 16 (Certification by QP) + ICH Q12 lifecycle changes. ICH Q10 Section 2 + Outsourced + Ownership applies.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 90 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition