Maturity model

Supplier quality maturity

Outsourcing an activity does not outsource accountability. Maturity here is mostly about whether the programme is tiered enough to be affordable, and therefore whether it actually runs.

In one line

Supplier quality maturity is whether qualification is current today, not whether it was once performed.

The five levels

What each level looks like here

Level 1

Reactive

The process runs when something forces it to.

Suppliers are approved on commercial terms, quality agreements are missing or generic, and qualification status is not tracked.

Typical weakness. No visibility of which suppliers are actually qualified.

Risk. An unqualified or overdue supplier is a finding in its own right.

Level 2

Controlled

Procedures exist and are followed, mostly.

Questionnaires are issued and filed, agreements exist for major suppliers, and audits happen when someone has capacity.

Typical weakness. Questionnaires are collected but not assessed.

Risk. Evidence of a programme without evidence of a conclusion.

Level 3

Systematic

The process is designed, resourced and measured.

Suppliers are tiered by what they can do to the product, scrutiny follows the tier, and re-qualification dates are owned and tracked.

Typical weakness. Change notification obligations are written but not enforced.

Risk. Unnotified supplier changes discovered during investigations.

Level 4

Integrated

It connects to the rest of the quality system.

Supplier performance data feeds the programme, agreements are current, and audit findings connect to the internal CAPA system.

Typical weakness. Sub-contracting by suppliers may be unmapped.

Risk. Dependency chains that are invisible until one link fails.

Level 5

Optimized

It improves itself, and the improvement holds.

Supplier risk is treated as an operational continuity matter, dual sourcing is considered for critical dependencies, and qualification depth is weighted into sourcing decisions.

Typical weakness. Commercial pressure to prioritise unit cost.

Risk. Cheapest supplier, most expensive failure.

Expected controlsWhat a site at level 3 or above should be able to show.
Risk-based tiering
Scrutiny proportionate to what the supplier can do to your product.
Current quality agreements
Roles, notification, audit rights, sub-contracting and testing responsibilities.
Assessed questionnaires
A recorded evaluation and conclusion, not a returned form on file.
Enforced change notification
The clause that matters most in practice, actively monitored.
Owned re-qualification schedule
Status visible and current, with a named owner.
Moving up

What actually shifts the level

  • Report how many suppliers are qualified today against current agreements, rather than how many have ever been qualified.
  • Tier the supplier base once, properly. Without tiering the programme is either unaffordable or fictional.
  • Audit the change-notification clause specifically: ask suppliers what they last notified you about.
  • Map sub-contracting so the dependency chain is known before a link fails.
Regulatory basis

Where the underlying requirements sit

Limits

This is a framework, not a classification

These five levels are a GMPConsultant.nl framework for structuring a conversation about capability. They are not an official regulatory classification, no authority recognises or issues them, and a maturity level is not a statement of GMP compliance.

Next step

Score this domain rather than estimate it

The GMP Health Index scores seven domains and maps each to a maturity level, in about ten minutes. It calculates in your browser and stores history on your device only.