A contract-manufacturing relationship does not remove the need for a clear quality and decision framework. Before contracting, the practical question is not simply whether a company has a licence or a listed platform. It is whether the specific legal entity and site can support the specific product, process, target market and responsibility model under applicable requirements.

1. Establish the audit scope before the visit

Set the decision that the audit must support: initial screening, technology transfer, commercial manufacture or a change assessment. Identify the legal entity, physical site, dosage form and project stage, the intended market, and the proposed division of regulatory and quality responsibilities. Without those anchors, an audit can become an unfocused collection of generic documents.

The National Medical Products Administration states that, before accepting commissioned production, a manufacturer should evaluate the marketing-authorisation holder and proposed product comprehensively, including the holder’s qualifications and quality-management capability, product risk, technology-transfer feasibility and feasibility of co-line manufacture; only after that evaluation should the parties sign the manufacturing and quality agreements.[1]

2. Verify legal entity, site and applicable scope

Confirm that the entity proposed in the contract is the entity responsible for the relevant site and activities. Review the current authorisation scope, address, dosage forms and any boundary that needs clarification. A brochure, a historic certificate or a third-party listing may support a preliminary screen, but it is not a conclusion about current scope or product-specific acceptance.

3. Review the quality system as operating evidence

Assess how quality assurance, quality control, deviations, CAPA, change control, complaints, recalls, suppliers, data and management escalation operate in practice. The focus is not whether a procedure exists, but whether roles, records, review cycles and risk decisions can be traced. The project’s risk profile should determine how deeply each area is assessed.

4. Test product and process fit

Map the proposed dosage form, formulation characteristics, process route, presentation, packaging, storage and scale range to the relevant manufacturing train, equipment, utilities, personnel, logistics and control strategy. A listed dosage form does not automatically demonstrate that every product in that category can be accepted. Product-specific assumptions must be confirmed through appropriate technical review.

5. Evaluate technology transfer and co-manufacturing risk

A transfer plan should identify accountable owners, gap assessment, training, protocol and report approval, change control, verification or validation, data review and decision gates. For shared facilities, examine how product and process risks are identified and controlled. For sterile or other higher-risk products, increase the depth of review of contamination-control arrangements, flows, utilities, monitoring, cleaning and verification evidence according to the actual project.

6. Define laboratory, release and data interfaces

Clarify who owns sampling, testing, OOS/OOT investigation, batch-record review, release support, stability, retains and original data. Confirm the expected access rights, timing and escalation route. A quality agreement should convert statutory and regulatory roles into a working responsibility matrix; it does not transfer away the responsibilities that remain with the relevant legal party.[2] [3]

7. Record findings as project decisions

A mature audit record does not stop at pass or fail. For each observation, record the observed fact, potential impact, affected project scope, accountable party, requested corrective evidence, due date and re-review method. This distinguishes gaps that can be responsibly closed before project start from risks that may change the cooperation route.

A safe first-contact checklist

Before an NDA, a prospective partner can prepare a concise non-confidential summary of the dosage form, presentation, stage, target market, requested model (CMO, CDMO or technology transfer), scale range, timing and key decision points. Do not send patient information, formulas, full dossiers, detailed process instructions or trade secrets before an NDA and controlled disclosure plan are in place.

Frequently asked questions

What should a pharmaceutical CMO audit cover?

It should test the named entity and site, current scope, quality system, product fit, transfer readiness, co-manufacturing risk, laboratory and release interfaces, and governance. The depth is risk-based and project-specific.

Can a licence or capability presentation replace a CMO audit?

No. Public materials support screening, but cannot establish product-specific fit, current operating evidence or project acceptance.

What is safe to share before an NDA?

Share only a non-confidential project brief: dosage form, stage, target market, requested scope, presentation, scale range and timing. Protect formulas, full dossiers, patient information and trade secrets.

Does an audit guarantee project acceptance?

No. Final decisions require product-, site-, market- and evidence-specific review, together with written quality and commercial arrangements.

Authoritative sources

  1. NMPA: Announcement on Strengthening the Supervision and Administration of Commissioned Production of Drugs (2025 No. 134)
  2. Hainan Medical Products Administration: Measures on strengthening MAH responsibility and quality supervision for commissioned production
  3. NMPA: Regulation on marketing authorisation holders’ implementation of drug-quality responsibilities

This article is general industry information, not legal, regulatory or medical advice. It is not an assessment of any company, facility, product, market or project. Project suitability must be determined by the responsible parties using applicable requirements, product risk, audit findings and controlled technical information.