ICH Q10 - Pharmaceutical Quality System
ICH Q10 Section 2 - Outsourced + Ownership

ICH Q10 - Pharmaceutical Quality System ICH-Q10-Section2-Outsourced-Ownership-Vendor-Supplier-CMO-CRO: ICH Q10 Section 2 - Outsourced Activities + Management of Materials + Change of Ownership + CMO + CRO + Supplier Management

Section 2.7 Management of Outsourced Activities + Section 2.8 Change in Product Ownership address external party arrangements which retain PQS responsibility with the marketing authorisation holder (MAH). Outsourced activities + materials (Section 2.7): selection + assessment + qualification of contract acceptors (Contract Manufacturing Organisations CMO + Contract Research Organisations CRO + service providers + material suppliers + carriers + laboratories); written agreement (Quality Technical Agreement QTA + Master Service Agreement MSA) defining roles + responsibilities + communication + decision-making + change control + deviation + investigation + complaints + audit right; ongoing oversight (audit + KPI + quality scorecard); regulatory submission of qualified suppliers + facilities. Supplier qualification: initial qualification (audit + sample testing + capability + risk assessment) + ongoing monitoring (incoming quality + performance + audit + change notification); risk-tiered approach + critical materials require enhanced oversight; supplier-related deviations + CAPA. Section 2.8 Change in Product Ownership: when product transferred between MAHs (acquisition + divestment + merger + license transfer): regulatory notification per market + change of MAH submission + transfer of PQS documentation + retention of records + continuity of supply + variations to commitments. Coordinates with FDA 21 CFR 211.84 (component supplier qualification) + EMA QTA Guidance + ICH Q7 (GMP for APIs) + ISO 9001 Section 8.4 (Externally Provided Processes Products and Services) + GAMP 5 supplier management + Risk-based supplier control + EU GMP Annex 16 (Certification by QP) + ICH Q12 lifecycle changes. ICH Q10 Section 2 + Outsourced + Ownership applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 90 controls across 52 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures

IEEE 1686 · 3 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability
  • IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning

ISO/IEC 27003:2017 · 2 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-8.1 Operational planning and control
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • Mat 03 Responsible Sourcing of Materials
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-50001-8.3 Procurement

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)
  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • PASONE-3 Personnel Security, Vetting, Awareness, and Training
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management
  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets
  • 2.7.2 Food Fraud Plan
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 90 it maps to, and the evidence behind each claim, over MCP and REST.