Outsourcing creates a governance problem
Many medical-device companies believe they have outsourced a development problem. What they have actually done is acquire a supplier-governance problem—often without assigning anyone to manage it.
Specialist partners can provide capabilities that would be uneconomic or impractical to maintain internally. A design house may develop the electronics, a software company may build the application, a laboratory may perform specialist testing and a cybersecurity consultancy may evaluate the connected system. Used well, this model can be fast, capable and entirely appropriate.
The mistake is to assume that paying a competent supplier transfers accountability. The legal manufacturer remains responsible for defining what is required, selecting and controlling suppliers, integrating their work, accepting the outputs and maintaining the complete product throughout its lifecycle.
A purchase order is not a control strategy
Commercial procurement answers questions about price, delivery and contractual scope. Medical-device supplier control must also address product risk, competence, evidence, change, configuration, regulatory responsibilities and long-term support.
The necessary level of control should be proportionate to the effect the supplied work could have on device safety, performance and regulatory compliance. A supplier writing safety-related software or designing a critical electronic assembly requires a different relationship from a supplier providing standard office materials.
- Is the supplier formally approved for the work it is performing?
- Has its criticality and associated risk been assessed?
- Are responsibilities, deliverables and acceptance criteria defined?
- Can the manufacturer review the supplier’s methods and objective evidence?
- Are changes, anomalies, vulnerabilities and obsolescence communicated?
- Does the arrangement cover maintenance, complaints, investigations and post-market support?
The manufacturer must remain an intelligent customer
Oversight does not mean duplicating every specialist activity. It means retaining enough competence to specify the work, challenge important assumptions, understand the evidence and decide whether the output is acceptable.
A manufacturer that cannot explain the architecture of its own product, the basis of its software safety classification, the origin of its risk controls or the adequacy of its verification evidence has lost more than technical detail. It has lost effective design authority.
This is particularly dangerous where several subcontractors contribute to one system. Each supplier may deliver its own component correctly while interfaces, system hazards, cybersecurity dependencies and end-to-end validation remain nobody’s explicit responsibility.
Quality agreements should describe the working relationship
A quality agreement should not be a ceremonial document produced immediately before an audit. It should define how the manufacturer and supplier will work together while decisions are still being made.
The agreement needs to complement—not merely repeat—the commercial contract. The exact contents depend on the supplied product or service, but critical arrangements commonly include:
- Applicable quality-system procedures and standards.
- Document, record and configuration ownership.
- Design-review, approval and release authority.
- Risk-management and traceability responsibilities.
- Verification, validation and acceptance evidence.
- Control and notification of changes and deviations.
- Problem reporting, CAPA and investigation support.
- Cybersecurity vulnerability disclosure, SBOM and update responsibilities.
- Audit rights and access to relevant records.
- Retention, continuity, obsolescence and termination arrangements.
Training must be relevant, not performative
Requiring every supplier employee to read the manufacturer’s entire QMS is unlikely to create useful control. Equally, assuming that the supplier’s own processes will automatically satisfy the manufacturer’s obligations is unsafe.
People performing outsourced work should understand the manufacturer procedures that govern their activities, the interfaces between the two quality systems, the records they must create and the points at which manufacturer review or approval is required. Competence and training evidence should demonstrate that understanding.
The practical test is not whether a training matrix contains a date. It is whether the people doing the work know which process applies, what evidence must be produced and when they must stop and involve the manufacturer.
Evidence cannot be reconstructed without loss
Supplier-control weaknesses often become visible shortly before an audit, submission or design transfer. Teams then try to recover months or years of decisions through retrospective plans, reconstructed reviews and newly assembled traceability.
Some gaps can be corrected. Missing records can sometimes be obtained, inconsistent documents reconciled and late reviews conducted honestly. But retrospective activity cannot recreate contemporaneous challenge or prove that information available at the time actually influenced the design.
A polished document created at the end of development is not equivalent to a controlled decision made when alternative solutions were still available. The later the problem is found, the more likely the organisation is to be defending the design it already has rather than selecting the design it needs.
Five questions reveal whether control is real
Senior management and project leaders do not need to inspect every supplier record personally. They should, however, be able to obtain clear answers to a small number of questions.
- Who within the manufacturer is accountable for the supplier and technically competent to accept its work?
- What exactly must the supplier deliver, and what objective evidence defines acceptance?
- Which product risks, interfaces and lifecycle obligations cross the organisational boundary?
- How will the manufacturer learn about changes, defects, vulnerabilities and loss of supplier support?
- Could the manufacturer maintain, investigate, modify or transfer the product if the supplier relationship ended tomorrow?
Independent review is most valuable before commitment
External support is frequently requested after an auditor identifies a gap or a submission reviewer asks for evidence. Qualified consultants can help with remediation, but by then the architecture, contracts, supplier behaviours and development records may already constrain the available options.
A short independent assessment before supplier selection or contract signature can examine the proposed responsibilities, quality arrangements, evidence model, technical governance and lifecycle obligations. Similar reviews at the first architecture and development-planning gates can identify omissions while they remain inexpensive to correct.
The purpose is not to insert a consultant permanently between the manufacturer and its suppliers. It is to help the manufacturer establish effective control, build internal competence and make important decisions before they become expensive to reverse.
The uncomfortable conclusion
Outsourcing does not reduce the need for product knowledge inside the manufacturer. For critical activities, it increases the need for clear ownership, competent oversight and disciplined integration.
A capable supplier can perform excellent work. Only the manufacturer can ensure that the work fits the intended purpose, risk-management process, complete system, regulatory strategy and supported product lifecycle.
The question is therefore not simply, ‘Do we trust our supplier?’ It is, ‘Can we demonstrate that we understand, control and accept what our supplier is doing on our behalf?’
Continue learning
Develop the subject in greater depth
Apply the thinking
Establish control before the evidence gap becomes a crisis
Medical Devices Done Right provides independent supplier-governance, development-readiness and evidence reviews before contracts, audits, submissions and design transfers make weaknesses expensive to correct.
Explore independent consulting support →Key takeaways
- The legal manufacturer remains accountable for outsourced processes and their results.
- Supplier control must be based on the risk and significance of the supplied work—not procurement value alone.
- The manufacturer needs sufficient internal competence to specify, challenge, integrate and accept specialist work.
- Quality agreements, relevant QMS training and access to objective evidence should shape the relationship from the beginning.
- Early independent review is substantially more valuable than retrospective evidence reconstruction.