You will only have 2 or 3 days on-site. Those months your supplier had in preparation were spent developing their SOPs and answering questions, timing facility tours to the minute.
What you decide in those days will determine the next several years of your ongoing API supply.
The usual practice is for buyers to trot out a generic template and neatly stack signed forms as evidence at the end of their visit.
The gap between an API vendor audit checklist and a courtesy visit is not effort; it is knowing where to look and what to expect.
A checklist shaped by the standard a site is actually regulated against, with an emphasis on where deficiencies actually exist, will uncover what a labour-intensive document-by-document review will miss.
This guide provides a step-by-step checklist that you can use on-site.
The Audit Is the Only Place You See the Truth
The terms “certificates,” “dossiers,” and “supplier questionnaires” all refer to stated intentions.
The only place that shows actual practice is the API supplier audit. And that is where real risk lies.
There is a GMP audit because there is a gap between documentation and reality.

Certificates of analysis, technical dossiers, and pre-qualification questionnaires all describe what a supplier states it does.
The only opportunity to observe what a supplier actually does is on a qualification visit:
How a real deviation is investigated, whether the operator can explain a signed SOP, whether the raw data underlying a certificate of analysis is available and has not been summarised, and many other critical aspects.
Everything that happens before the visit is a statement. The audit is the verification.
This is the reason regulators view this as a legitimate expectation rather than a favour to be accorded: EU GMP.

It states that, as a minimum requirement, audits of manufacturers and distributors of active substances must be conducted to confirm compliance with good manufacturing and distribution practices, and that such audits must be of sufficient duration and scope to permit an assessment to be made. European Commission – EudraLex Volume 4, Chapter 5.[1]
The single requirement of “sufficient duration and scope” is the standard against which every audit plan in this guide should be assessed.
Now that we understand why the audit is an irreplaceable component, let us explain why many audits are badly planned.
Why Most Audit Checklists Fail
Most checklists are designed to spread attention evenly and audit paper instead of systems.
Three failure modes are evident in most substandard API vendor audits, and each has a straightforward remedy.

Most templates fail in three predictable ways:
A data integrity gap buried inside a checkbox for laboratory controls will never surface during a document review.
It surfaces when you are at the terminal and get the analyst to walk you through the result.
The solution is to design a checklist based on the standard against which the site is regulated, weigh the checklist based on where deficiencies actually are, and probe data integrity in each unit instead of as a separate section at the end.
Having identified where generic checklists break down, let’s examine the enforcement data to see where findings actually occur.
Where Findings Actually Cluster
Enforcement data show that deficiencies occur in a few predictable areas. Weighting your API audit checklist to those areas is an evidence-based decision, not a guess.
Regulatory enforcement patterns are consistent from year to year and are in the public domain.

For the past four years, the most frequently cited Form 483 observation[2] has been failure to follow quality unit procedures under 21 CFR 211.22(d).
Failure to conduct identity testing was the single most common deficiency observed in the FDA’s 2025 review of drug warning letters, appearing in 49 of 85 drug warning letters.[3]
Data integrity is another major concern. Between 2017 and 2022, the FDA released over 160 Warning Letters[4] regarding data integrity, and in the meantime, data integrity issues spurred the selection of additional audit resources beyond a single checklist item.
| Deficiency Areas | Observations | Audit-Time Implications |
| Quality systems (investigations, CAPA, SOP adherence) | Approximately 34% | The largest single block. Start here and trace deviations end to end. |
| Data integrity | Approximately 24% | Conduct a dedicated session with the systems and raw data; not merely a document review. |
| Laboratory controls | Approximately 13% | Conduct a dedicated session with the analyst; review OOS and chromatographic data. |
| Production controls | Approximately 11% | Follow one batch record through execution and reconciliation of yield. |
Directional guide only: These proportions reflect an analysis of Form 483 observations for biologics manufacturers between 2010 and 2025. Use them to prioritise the agenda items; do not apply them to all gaps for active pharmaceutical ingredients.
Having identified the location of findings, we can now examine which end of the preparation-to-travel continuum empowers you to reach the findings sought.
Before You Travel: Preparation That Decides the Outcome
Most audit value is created or lost even before the team departs for the destination. Effective preparation can turn limited days into confirmation verification, instead of days for preparation.
Before your arrival:
Preparation speaks to the length of the audit, and site time must be spent verifying instead of reading.

Generally, simple sites require 1-3 days,[5] while audits for complex sites may extend up to 10 days.[6]
After extensive preparation, the scope and time allocated can now be moved to the checklist itself, which is the most important item to take to the field.
The API Vendor Audit Checklist
The API vendor audit checklist is patterned after ICH Q7 because it is structured the same way as the regulations that govern the inspection and regulation of active substance manufacturers.
Each line identifies the area to be checked, what to check, and what red flag should trigger a change in the way the risk is assessed.
Quality system, personnel and documentation
| Area (ICH Q7) | What to Verify | Red Flag |
| Quality Unit (§2) | Independence and written authority to approve or reject batches; review of batch and laboratory records for critical steps before approval; approval of specifications, procedures, and changes. | Quality reports informing production; release decisions overridden on a commercial basis. |
| Deviations & CAPA (§2) | Depth of investigations; use of a root-cause technique; verification of corrective-action effectiveness; timeliness of closure. | Deviations closed as operator error with retraining as the only action; overdue CAPAs; repetitive findings. |
| Self-Inspection (§2) | Schedule for internal audits; findings; management review. | Absence of self-inspection or findings that do not reach management. |
| Personnel & Training (§3) | Role-based training; GMP training records; contractor training; competency of personnel. | Training records signed by someone other than the employee; an operator who cannot explain their SOP. |
| Documentation (§6) | Document control; issue and accounting for blank forms; completeness of batch records; retention period. | Blank forms used without control; unbound record sheets; batch records completed in one hand in one sitting. |
| Change Control (§13) | Clarity of changes; assessment of the change’s impact on documented information; commitments to inform customers. | Changes implemented without prior customer notification or assessment of their impact on the dossier. |
Facilities, equipment, materials and production
| Area (ICH Q7) | What to Verify | Checklist for Red Flags |
| Facilities (Section 4) | Segregation of quarantine and released stock; flow of people and materials; cross-contamination concerns; pest control; utilities. | Poor segregation; no assessment for contamination in shared areas. |
| Equipment (Section 5) | Qualification status; preventive maintenance; last calibration; cleaning validation for worst-case scenarios; dedicated equipment vs. equipment shared among multiple functions. | Overdue calibration of critical equipment; cleaning validation for worst-case products missing. |
| Materials (Section 7) | Quarantine and release status of starting materials; supplier qualification; identity testing of starting materials. | Unable to identify the starting-material supplier for a key starting material. |
| Process Controls (Section 8) | Execution of batch records; controls and reconciliation at critical stages; yield; critical deviations. | Excessive yield variations with no investigations; controls performed after the batch has been completed. |
| Packaging & Labeling (Section 9) | Control and reconciliation of labels; correct classification of API vs. intermediates. | Uncontrolled label stock; reconciliation not performed. |
| Storage & Distribution (Section 10) | Appropriate storage conditions; justified retest and expiry dating; traceability of batches to shipments; management of returns. | No ability to trace a batch to the shipment provided to the customer. |
Laboratory, validation and lifecycle controls
| Area (ICH Q7) | What to Confirm | Warnings |
| Laboratory Controls (§11) | Method validation; reference standard management; investigation of OOS results; stability program. | OOS results invalidated without justification; replicate testing until the desired result is obtained. |
| Validation (§12) | Process validation; cleaning validation; analytical method validation; ongoing process verification. | Validation performed once on three batches with no subsequent follow-up. |
| Rejection & Re-use (§14) | Rules for reprocessing, reworking, and blending, with approval from the Quality Unit. | Unapproved reprocessing; blending performed to bring material within specification. |
| Complaints & Recalls (§15) | Complaint handling and trending; recall procedure; mock recalls. | Complaints and recalls have never been subject to trending analysis; recall procedure has never been challenged. |
| Contract Manufacturers (§16) | Approval of each contract manufacturer; audits; signed contracts. | Use of synthesis and/or milling subcontractors without adequate oversight or approval. |
| Agents, Brokers & Repackers (§17) | Traceability to the original manufacturer for all traded material. | The original manufacturing site cannot be identified from the documentation. |
These three tables are the set of this API vendor audit checklist that you will use on the floor, not just before the trip.
Let’s see some of the more detailed areas of the checklist. Speaking of the most serious findings, we’re talking about data integrity here.
The Data Integrity Deep-Dive
Data integrity is not a subset of the quality system. It flows through every single component of the quality system.

Really examining data integrity is what characterises a professional audit vs. a document check.
Ask for a live demo over a folder full of printouts. Sit with the analyst, open the chromatography system, and watch one sample be processed from injection to the resulting analysis and ultimately to the certificate of analysis.
This is the discipline of ALCOA+ being demonstrated in practice vs. being described.
The repeated failures the regulators cite are specific and repeatable.
Audit trail being disabled, shared user accounts, backdating, unreported results, “testing into compliance,” and weak investigations provide precise guidance to an auditor on what to examine vs. a generally stated objective.
| ALCOA+ Attribute | What to Check on Site | Red Flag |
| Attributable | Unique user accounts and appropriate access levels; signature logs. | Shared logins; routine use of generic administrator logins. |
| Legible / Enduring | Permanent controlled records; archiving and backups; tested data restoration processes. | Overwritten records; backups that have never been restore-tested. |
| Contemporaneous | Timing of entries versus the activity; control of system clocks. | Records entered retroactively; clocks that users can adjust. |
| Original | Retention of raw data, including chromatograms, printouts, and instrument files; documented true-copy processes. | Only summary reports are retained; access to raw data is not provided. |
| Accurate | Audit trails are enabled and reviewed as part of batch-record reviews; reasons for changes are captured. | Audit trails are disabled or never reviewed; changes are made without reason codes. |
| Complete | All runs are retained, including aborted runs and trial injections; sequential file numbering is maintained. | “Test” injections are missing from the sequence; unexplained gaps in file numbering. |
A supplier that can provide a complete, unaltered audit trail without any hesitation during a request is showing you their culture before you’ve even opened their dossier.

Now that we have contemplated how to analyse integrity in data, what do we do with the findings once the audit comes to a conclusion?
Classifying Findings and Closing Them Properly
The post-visit procedures are as important as the work conducted during the audit site visit.
Audits often lack honest classification or verified closure on their programs.
Close an audit with a presentation of key findings.

Wrap up with an audit report containing the findings of the audit team, the audit’s scope, the systems reviewed, and notably systems not reviewed, along with evidenced classification for each observation.
Critical audit findings must be communicated to the site management before the closing meeting.
| Meaning | Definition | Your Response |
| Critical | Result: Non-compliant product or an immediate or latent health risk. | Immediate action; approval will be denied until corrected. |
| Major | Result: Product may not consistently meet its registered requirements. | Approval postponed; granted only with CAPA closure documentation. |
| Minor | Result: Departure from GMP that poses low risk. | Closure tracked; evaluate for persistence. |
| Repeat Finding | Failed prior correction. | Escalate severity indicates failure of the CAPA system. |
Use the quality of a supplier’s response as evidence: analysis shows that firms that submit weak responses to Form 483 observations.
The number of FDA warning letters[7] has increased in FY-25. A defensive or generic response is a risk signal, regardless of the original finding.
Since findings are now classified and closed, what do we know that a well-run audit cannot tell us?
What an Audit Cannot Tell You
Audits do not eliminate risk. Customers who consider an audit as a final approval over all other inputs ultimately discover that audits do not provide that approval.
A site audit reviews a set of documents the customer has prepared.
Site audits are meant to be an additional input to the overall assessment of a supplier.
They are not a substitute for incoming tests, performance monitoring, or the requalification of a supplier.
| Audit Mode | Appropriate For | Not Adequate For |
| On-site | Assessing API supplier quality for the first time; observing the process; conducting facility, equipment, and utility assessments; evaluating quality culture. | – |
| Remote / Desktop | Regular surveillance of a supplier with a strong on-site history; document-centric assessments; low-risk assessments. | First qualification of a critical API source. |
| Third-party / Shared | Supplementing your audit programme and reducing the audit burden at frequently audited sites. | Replacing your own judgement – such reports are not certifications. |
This distinction is not about convenience.
According to EU GMP, on-site audits of active substance manufacturers are the only GMP-compliant audits, unless there’s a stated pandemic and travel restrictions make on-site audits completely impossible.
In these extraordinary circumstances, remote, distance, offsite, or virtual audits are permitted under EU GMP.
Now that we’ve confessed to the limitations of one single audit, what is an audit-ready API manufacturer in practice?
What an Audit-Ready API Manufacturer Looks Like
A supplier that is easy to approve would make this API vendor audit checklist less laborious.
It would involve having unlimited access to the production areas and the QC laboratory, the availability of raw data as opposed to only summary reports, investigations of deviations to go beyond the symptoms and find root causes, regular reviews of audit trails, and full traceability from starting materials to the customer shipment without any restrictions on the length of the trace.
This is the benchmark against which Actiza Pharma has built its operations: WHO-GMP certification and quality-assurance practices, a quality management system, and technical documentation which provides buyers the data and traceability that an audit needs, over the API portfolio that Actiza offers.
Should you be assessing APIs and wanting to observe this benchmark on the shop floor, you could schedule an audit or request Actiza’s audit pack.
Frequently Asked Questions
Q1. What should an API vendor audit cover?
The full scope of ICH Q7 should be audited, including quality systems, deviations and CAPA, facilities and equipment, materials management, production controls, laboratory controls, validation, and data integrity, as they apply through the various sections of the API vendor’s operations.
Emphasise quality system and data integrity audits, as enforcement data shows most deficiencies are in those areas audit individual batches and deviations as opposed to reviewing isolated documents.
Q2. How long should an API supplier audit take?
Typically, duration should be risk-based, as opposed to rigid. Industry averages for a routine audit of a simple, lower-complexity site range from one to three days.
More complex sites, and especially more complex manufacturers, can take ten or more days.
Conducting rushed audits at complex sites will result in most items of interest being missed.
Q3. Can I audit an API supplier remotely?
Remote and desktop audits can be an acceptable means to conduct routine, low-risk supplier surveillance, once the supplier has an established site.
However, where a critical API supplier is being evaluated for the first audit, per EU GMP, usual practice is to conduct an on-site audit.
Exceptions to the travel requirements associated with the on-site audit, i.e., due to a legal pandemic, would be acceptable to conduct a remote audit.
Q4. What are the biggest red flags during an API audit?
Here are the top red flags to watch out for during an API audit: disabled or unreviewed audit logs, shared logins, deviations resolved by retraining, batch records done retrospectively, and an inability to trace a starting material back to its original manufacturer.
These are all signs of a control system built to pass inspections rather than for real control.
Q5. What happens after the audit?
Audit records are graded for the impact to the business as either critical, major, or minor, with a provision for ‘other.’
These grades are reported and follow the CAPA process through closure. A CAPA is not considered closed until verified as such.
Critical findings delay approval. Poor supplier responses indicate a weak defence and, in turn,and signal an elevated risk of regulatory escalation.
Conclusion
You cannot simply include a checklist in an audit and expect it to have the right judgment.
Value is actually added by utilising days efficiently by going to the areas of the quality system, data, or laboratory where most deficiencies cluster.
It means tracing instead of reading and following one batch from starting material to release, one deviation to its effectiveness check, and one analytical result to its certificate.
Doing this consistently and honestly classifying findings will help the audit become what it should be, that is, the point at which you no longer take the supplier’s words for granted.
Suppliers making this process an easy project are typically the suppliers that deserve approval.
If you are ready to use this API vendor audit checklist, schedule an audit or request Actiza’s audit pack and see the standard in action.
- https://health.ec.europa.eu/medicinal-products/eudralex/eudralex-volume-4_en
- https://cgmpconsulting.com/avoiding-common-fda-483-observations/
- https://www.certaintysoftware.com/fda-warning-letters-2026-quality-system-failures/
- https://www.sciencedirect.com/science/article/abs/pii/S0378517322010584
- https://www.nsf.org/knowledge-library/the-importance-of-gmp-auditing-services
- https://www.nsf.org/knowledge-library/the-importance-of-gmp-auditing-services
- https://www.certaintysoftware.com/fda-warning-letters-2026-quality-system-failures/
