PIC/S Guide to Good Manufacturing Practice for Medicinal Products
Outsourced Activities

PIC/S Guide to Good Manufacturing Practice for Medicinal Products PICSGMP-7: Chapter 7: Outsourced Activities and Supplier Management

Per PIC/S GMP Chapter 7: outsourced activities. Requirements include (a) implement Outsourced Activities controls including written agreement + Quality Agreement + (b) qualify contract acceptors including initial + ongoing assessment + audits + (c) maintain communication + change control between contract giver + acceptor + (d) maintain Material Management and Supplier Qualification for all categories of suppliers + (e) implement ongoing oversight including periodic audit + performance review + (f) maintain documentation of outsourcing arrangements + Quality Agreements + (g) ensure contract acceptor compliance with GMP.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 211 controls across 106 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.7 Service agreements
  • ISO-15189-6.8 Externally provided products and services
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning
  • NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria
  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

ISO/IEC 23894:2023 · 4 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria
  • ISO23894-A.6 AI System Security

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership
  • ACQ.4 Supplier Monitoring
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-3-5.3 Trigger events for information exchange

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO28001-PI-01 Personnel Security Screening
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system
  • ISO-41001-8.4 Control of outsourced processes and services

ISO/IEC 27003:2017 · 3 controls

  • ISO27003-4.2 Understanding the needs and expectations of interested parties
  • ISO27003-4.3 Determining the scope of the information security management system
  • ISO27003-8.1 Operational planning and control

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

  • CFR211-A-3 Section 211.3 - Definitions
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • 58.1 Scope
  • 58.3 Definitions
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-RES.2 Disaster Recovery
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 2 controls

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • ISMSP-SYS-04 Vulnerability Management
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AZ-DPA-2 Article 2 - Basic Concepts
  • Mat 03 Responsible Sourcing of Materials

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions
  • CJIS-19 Supply Chain Risk Management
  • FFIEC-05 Roles and responsibilities definition
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)

FedRAMP High · 1 control

  • CA-9 Internal System Connections

FedRAMP Moderate · 1 control

  • CA-9 Internal System Connections
  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • 62351-2 Glossary of terms
  • ISO-14064-1-5.1 Organizational boundaries

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices
  • ISO-26262-3-5 Item definition
  • ISO-50001-8.3 Procurement

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy

ISO/IEC 27043:2015 · 1 control

  • ISO27043-04 Roles and responsibilities definition
  • 27050-1.4 Terms and definitions

ISO/IEC 27400:2022 · 1 control

  • 27400-3 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions

ISO/SAE 21434 · 1 control

  • ISO21434-04 Roles and responsibilities definition

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity
  • BIPA-SEC5-1 Biometric Identifier Definition

NIST SP 800-190 · 1 control

OWASP SAMM · 1 control

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions

PCI DSS 4.0 · 1 control

  • 2.2.2 2.2.2 Vendor default accounts managed

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • PSPF24-1 Security Culture, Governance, Risk Management
  • EHDSREG-1 Mandatory Requirements for EHR Systems (Articles 14-29)
  • 2.7.2 Food Fraud Plan

SWIFT CSCF · 1 control

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • TEFCAREC-1 Common Agreement Conformance and Onboarding
  • OB-OPS.2 Performance Standards
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • W3CVCDM-1 Three-Party Ecosystem (Issuer, Holder, Verifier)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 211 it maps to, and the evidence behind each claim, over MCP and REST.