Sponsor oversight across the CRO and CDMO boundary: delegation an inspector can verify
Outsourcing moves the work. It does not move the liability. A sponsor remains answerable for decisions taken inside a partner's quality system, and the evidence supporting that answer currently consists of a quality agreement, an annual audit report and a set of monthly meeting minutes.
How does a sponsor evidence oversight across a CRO or CDMO boundary?
It cannot, from the partner's records alone. Regulators hold sponsors accountable for delegated GxP activities, and the partner's audit trail names the partner's employees, is written by the partner's systems and is produced by the party whose performance is in question.
- Quality agreements allocate responsibility contractually. No system enforces that allocation, so oversight is evidenced by periodic sampling rather than per-decision proof.
- A cross-boundary delegation names a sponsor human, a partner human, a decision class and an expiry — and verifies without either party accessing the other's systems.
- The commercial objection from partners is real and should be addressed directly rather than assumed away.
Part of Pharma and GxP identity
The protocol problem, stated in engineering terms
Two organisations need to establish that a decision taken by a human in organisation B was authorised by a human in organisation A, and that a third party — a regulator — can verify this without access to either organisation's infrastructure.
Stated that way it is a familiar distributed-systems problem with a familiar solution: a signed capability, issued by A, presented by B, verifiable by anyone holding A's public key. What makes it unusual is that the industry has solved it with paper instead.
What exists today
| Artefact | What it establishes | What it cannot establish |
|---|---|---|
| Quality agreement | Which party is responsible for which activity | That a specific decision was taken within that allocation |
| Annual audit report | That the partner's system met expectations on the audit dates | Anything about the 360 days not sampled |
| Person in plant | Continuous presence of a sponsor representative | Only available for the largest relationships; does not scale |
| Monthly quality review | That issues were discussed | No binding to individual decisions |
Each of these is useful. None of them is per-decision, and per-decision is what a regulator asks about when a specific batch or a specific deviation is in question.
The Cross-Boundary Oversight Chain
Three objects, each signed, each verifiable independently.
- The authority grant. A named sponsor quality officer signs a delegation: decision class (for example, minor deviation closure for product X), value or severity ceiling, validity period, and the named partner individuals it applies to.
- The decision. The partner's named individual signs a canonical statement of the decision, referencing the delegation.
- The escalation. Decisions outside the delegated scope produce no valid signature. The partner must obtain a fresh, narrower grant — which is the escalation the quality agreement already requires and which is currently enforced by memory.
The chain verifies to a sponsor human. A regulator can check it holding only published keys. Neither party needs an account on the other's system, which is what makes this deployable across a supplier base of dozens.
Worked example: a CDMO batch disposition
delegation:
issuer: [sponsor QA head, hardware credential]
delegate: [CDMO QA manager, named]
scope: disposition_decision, product=[X], site=[Y]
limits: minor_deviation_only, max_batches=unbounded
notAfter: [12 months]
depth: 1 # may not be re-delegated
decision:
actor: [CDMO QA manager, hardware credential]
under: [delegation reference]
render: ["Batch [id] disposition: released",
"Deviations: [n] minor, 0 major",
"Basis: [investigation refs]"]
Note depth: 1. Sub-delegation is the mechanism by which oversight silently evaporates in a multi-tier supply chain, and it is far easier to bound it cryptographically than to police it contractually.
The objection you will actually hear
Partners will not object on technical grounds. They will object on commercial ones: producing externally verifiable records of internal decisions creates exposure they have not priced, and sets a precedent every other client will demand.
That objection deserves a straight answer rather than a workaround. Three points usually land:
- The record protects the partner too. In a dispute about whether a decision was within scope, the partner currently has the same evidentiary problem the sponsor does.
- It reduces audit burden. A partner that can demonstrate per-decision authority is a partner that spends fewer days per year hosting audits.
- It is a differentiator in competitive tenders, and the first CDMO in a therapeutic area to offer it will say so in every bid.
Where to start, given a supplier base of forty
Do not attempt the whole base. Rank suppliers by the product of two factors: the consequence of a decision taken badly, and the frequency with which decisions are delegated. Start with the top two. Run a year. Publish the audit-day reduction internally.
If there is no audit-day reduction, the control has not paid for itself and you should say so. That is the falsification condition, and it is worth agreeing on it before the pilot rather than after.
What a sponsor can realistically ask for
| Option | Practicality |
|---|---|
| Full audit trail access | Rarely granted; contains other sponsors' data |
| Periodic audit | Point in time, expensive, not per-activity |
| Contractual attestation | What happens today — a statement |
| Receipts for defined decision points | Bounded, portable, verifiable by the sponsor |
Objections and honest limits
“The quality agreement covers this.” It allocates responsibility and specifies what the partner must do. It does not make any specific act verifiable by the sponsor.
“Partners will not instrument for us.” Some will not. Ask for a bounded set — batch certification, deviation approval, critical process decisions — rather than general logging, and the conversation changes.
Negotiating cross-boundary oversight
- Define the decision points you need evidence for. A short list, not general logging.
- Ask for receipts at those points only. Bounded asks get agreed.
- Require verification without contacting the partner. So evidence survives the relationship.
- Put retention in the quality agreement. Matching your regulatory period, not their policy.
Terms used here
- CRO / CDMO
- Contract research and contract development and manufacturing organisations performing delegated GxP activities.
- Quality agreement
- The document allocating GxP responsibilities between sponsor and partner.
- Delegated activity
- Work performed by a partner for which the sponsor remains accountable to the regulator.
Frequently asked questions
Does this replace auditing? No. Audits assess systems, culture and capability, none of which a signed decision record addresses. The claim is narrower: per-decision authority becomes verifiable between audits.
What if the partner refuses? Then you know something about the relationship. More constructively, most refusals soften when the reciprocal benefit and the audit-burden reduction are quantified in the next contract negotiation.
Does this require systems integration? No, and that is the design goal. Verification uses published keys; neither party grants the other access to its quality system.
How does it interact with ICH Q10? Q10 expects the pharmaceutical quality system to extend across outsourced activities. This provides an evidence mechanism for that extension; it does not alter the obligation.
Does a quality agreement solve this? It allocates responsibility. It does not make any specific act verifiable by the sponsor.
Why won't partners share audit trails? They contain other sponsors' data, reveal their systems, and extraction is unfunded work. The refusal is usually reasonable.
What is a realistic ask? Receipts at a defined set of decision points — batch certification, deviation approval, critical process decisions — rather than general logging.
Where this fits in Manav
Manav binds the signer to the exact record being certified, on a credential under their sole control, and produces a receipt an inspector or a partner can verify without access to the originating system.