
A CMO CRO quality agreement is a formal quality document that defines how a pharmaceutical, biotechnology, medical device, or other regulated organisation and an external service provider will manage quality responsibilities when work is outsourced. CMO refers to a contract manufacturing organisation, while CRO refers to a contract research organisation. The agreement establishes which party is responsible for specific activities, quality decisions, documentation, investigations, change control, deviations, audits, training, data integrity, and regulatory communication.
A quality agreement is not simply a commercial contract with additional quality language. Its purpose is to translate applicable Good Manufacturing Practice, Good Laboratory Practice, Good Clinical Practice, and other relevant quality requirements into clear operational responsibilities between organisations. This becomes particularly important when outsourced activities can affect product quality, patient safety, study integrity, or regulatory compliance.
Outsourcing does not transfer the legal or regulatory responsibility of the contracting organisation. A company may engage a CMO to manufacture active pharmaceutical ingredients, intermediates, or finished products, or use a CRO for laboratory testing, clinical research, bioanalytical work, or other specialised activities. The external organisation performs defined services, but the parties must still maintain effective oversight of those activities.
Without clearly documented responsibilities, gaps can occur. For example, both organisations may assume that the other is responsible for investigating a deviation, approving a change, retaining a particular record, or notifying a regulatory authority. A quality agreement reduces this ambiguity by establishing responsibilities before work begins.
The agreement also provides evidence that the parties have considered quality risks associated with outsourcing. Regulators generally expect regulated companies to maintain appropriate oversight of contracted activities and to have sufficient written arrangements defining responsibilities.
The exact content depends on the nature of the outsourced activity, applicable regulations, and the risks associated with the service. A manufacturing agreement will not necessarily contain the same provisions as an agreement covering clinical research or analytical testing.
Common subjects include:
responsibilities for quality management systems
applicable specifications and quality standards
batch documentation and records
sampling, testing, and laboratory controls
deviations, investigations, and corrective and preventive actions
change control
out-of-specification and out-of-trend results
complaints and product quality issues
stability studies
qualification and validation
equipment and facility controls
supplier and subcontractor management
document and record retention
data integrity
audits and inspections
regulatory inspections and authority communications
training and personnel qualification
release responsibilities
escalation and notification requirements.
The agreement should describe responsibilities with enough precision that personnel can determine what action is required when a quality event occurs.
A CMO quality agreement generally focuses on manufacturing and associated quality activities. Depending on the scope, this can include receipt and testing of materials, manufacturing operations, packaging, labelling, environmental monitoring, cleaning, validation, storage, release testing, deviation management, and batch record review.
A critical feature is the allocation of responsibility for changes. Changes to manufacturing processes, raw materials, analytical methods, facilities, equipment, suppliers, or specifications can potentially affect product quality. The quality agreement should therefore establish how proposed changes are communicated, assessed, approved, documented, and implemented.
The agreement should also distinguish manufacturing responsibilities from final product disposition responsibilities where appropriate. Contract manufacturing does not automatically mean that the CMO has authority to make every quality decision.
CRO quality agreements address a different risk profile. Depending on the services provided, they may cover clinical trial activities, laboratory testing, bioanalysis, data management, pharmacovigilance, statistical activities, or other research functions.
For clinical research, responsibilities can include study documentation, protocol compliance, safety reporting, data handling, monitoring, records, investigations, and inspection readiness. For laboratory services, the agreement may focus more heavily on sample management, analytical methods, results, equipment, reference standards, deviations, data integrity, and retention of raw data.
Because CRO activities vary considerably, the agreement should be proportionate to the services actually being performed rather than relying on a generic template.
A commercial contract and a quality agreement serve different purposes, although they may be related.
The commercial contract typically addresses matters such as pricing, payment, intellectual property, warranties, confidentiality, liability, delivery, and termination. The quality agreement defines the quality system and operational responsibilities associated with the regulated activities.
Keeping these functions distinct can make responsibilities easier to maintain. Commercial terms may change for business reasons, whereas quality responsibilities need to remain aligned with applicable regulatory requirements and the actual processes being performed.
The documents should nevertheless be consistent. Conflicting provisions can create uncertainty and should be resolved through appropriate contract governance.
Effective quality agreements avoid vague statements such as “the parties will ensure compliance.” Instead, responsibilities should be assigned to a specific party and, where necessary, a specific function or activity.
A responsibility matrix can be useful during development and review. Activities can be listed and assigned to the contracting organisation, the service provider, or both, with the agreement explaining where joint activities require defined interfaces.
Particular attention should be given to events requiring rapid communication. Deviations, critical laboratory results, suspected product quality defects, data integrity concerns, regulatory inspections, and significant changes may require notification within defined periods. A quality agreement should establish those expectations rather than leaving them to informal communication.
Deviation management is one of the most important areas in an outsourced relationship. The agreement should establish who initiates an investigation, who provides technical information, how root causes are assessed, who approves corrective and preventive actions, and how the contracting organisation is informed.
Change control requires similar clarity. A service provider may control its own operational change system, but the contracting organisation may need to review or approve changes that could affect a product, process, study, specification, validated state, or regulatory submission.
The agreement should therefore establish the interface between the two quality systems. This is often more important than simply stating that both organisations maintain change control procedures.
A quality agreement commonly defines audit rights and expectations for regulatory inspections. The contracting organisation needs sufficient access and information to exercise appropriate oversight of outsourced activities.
The agreement can establish how routine audits are conducted, how findings are communicated, how corrective actions are tracked, and how significant inspection findings are escalated. It can also address the responsibilities of each party when a health authority inspects the service provider.
These provisions should support transparency without attempting to replace the organisations' established quality systems.
Modern quality agreements must address data integrity explicitly where outsourced activities generate or manage regulated records. Data should be attributable, legible, contemporaneous, original or a true copy, and accurate, with appropriate controls for completeness, consistency, and availability.
Responsibilities should include generation, review, approval, storage, retention, access, and transfer of records. Electronic systems and interfaces may require additional clarification, particularly where records or data move between organisations.
The agreement should also identify which records must be made available to the contracting organisation and how records are protected against loss, unauthorised alteration, or inappropriate access.
A quality agreement should not be treated as a document that is signed once and then forgotten. Outsourced activities evolve. Manufacturing processes change, new analytical methods are introduced, responsibilities move between functions, regulations develop, and service scopes expand or contract.
Periodic review helps ensure that the written agreement continues to reflect actual operations. Significant changes to the relationship should trigger an assessment of whether the agreement requires revision.
A well-maintained agreement ultimately supports a clear division of responsibility between the contracting organisation and its CMO or CRO. It provides a practical framework for quality oversight, communication, escalation, and regulatory accountability. Most importantly, it turns the principle of oversight into documented responsibilities that personnel can follow in day-to-day operations.
Resources: QSN Academy · Blog · Webinars · eBooks · Scorecards · Book
Connect: LinkedIn (QSN) · LinkedIn (QSN Academy) · Linkedin (Dr Kathy Walsh) · Facebook · Email at info@qualitysystemsnow.com.au · Contact Us
Legal: Privacy Policy · Terms & Conditions · Complaints Procedure · Sitemap · QSN ABN 42 621 334 754