“Would I buy and implement VendorVigilance again? 100 per cent.”
Every CRO is accountable for work it does not do itself.
Some of it goes to a central lab. Some to a courier, an imaging provider, a data management company. The sponsor carries the regulatory obligation for all of it and cannot hand that obligation over, so the sponsor asks the CRO to show the chain is under control. The CRO holds the data. The sponsor holds the proof.
That is manageable with three vendors. It stops being manageable somewhere around fifteen, and nobody notices the day it happens.
Forschungsdock CRO knows the shape of this well. It is a German CRO based in Rellingen, near Hamburg, and it delivers full service through a network of specialist providers led by highly experienced senior in-house Project Managers. Its managing director, Dr Christoph Ortland, wrote down what changed for his team when the vendor work moved into one system. His words run through what follows, and the whole testimonial is reproduced at the foot of the page.
The question that goes round the houses
Qualification records live in a spreadsheet. Contract dates live in a different spreadsheet. Risk items sit in a shared drive that not everyone can open. The last audit finding is in an email thread from six months ago.
Nobody chose that arrangement. It accumulated, one reasonable decision at a time.
Clinical operations cannot start a study activity until a vendor or service provider is cleared for that service. Quality assurance owns the answer. There is nowhere to look it up, so somebody asks. Then asks again. Sourcing gets copied in because they hold the contract.
Three functions spend a morning on a question with one right answer. It never looks like a problem. It looks like people being helpful.
“Once all our vendors are in the system, I think that we save time, as people will spend less time talking and mailing between the functions to find out where we are with this or that vendor. No idea what that means in figures, but it definitely makes us more efficient.”
Software here is usually sold on a percentage nobody can trace. A customer who will not invent one is worth more than a customer who will.
What replaces the asking around is one record that every function can see, and trust.
“Thanks to the immediate access and centralisation of data which we have confidence in the quality of, VendorVigilance will continue to develop into one of our key platforms.”
Proving the chain to a sponsor
Under ICH E6(R3), a sponsor’s oversight duty reaches every provider carrying delegated work, not only the CRO. That includes the providers the CRO appoints itself.
So a sponsor looking at a CRO that delivers through a network is being asked to accept a chain rather than one organisation. The first question is who is in it. The second is how anyone would know if that changed.
A CRO that can answer both, on demand, is not defending its model. It is demonstrating it.
“VendorVigilance levels our disadvantage of not having everything in house, by reducing the risk for the sponsor.”
Oversight that only pays at an inspection is oversight nobody uses
Most vendor records are built for an auditor. They get assembled under pressure, filed, and not opened again until the next time somebody asks.
That wastes the best commercial information a CRO owns. The record that answers a sponsor’s audit is the same record that answers the question at the start of a bid: who can do this work, what did they charge, and how did they perform last time.
“The system is already proving extremely helpful in day-to-day operations, whether it’s preparing quotations or planning the operational implementation of the trials entrusted to us.”
Two jobs sit in that sentence. Preparing quotations is winning work. Planning operational implementation is delivering it. The same record serves both.
What we set out to build
Vendor oversight has never had a purpose-built home.
The eQMS was built for internal quality events and does that job well. The procurement platform was built for commercial onboarding and does that job well. Neither was built for the vendor lifecycle, and the gap between them is where the risk sits.
There is a second gap underneath it. Every study has a lifecycle: planning, activation, execution, closeout. Every vendor relationship has one: selection, qualification, contracting, oversight, offboarding. Both are usually run competently, in separate systems, by separate functions. Nobody owns the join. So qualifications finish after the vendor has started work, contracts get signed after study commitments are made, and risks surface after they have caused the delay.
VendorVigilance is a purpose-built vendor management platform for clinical trials, and it exists because our founder spent years running vendor oversight and inspection responses inside clinical trials, and kept rebuilding the same missing system at every organisation he joined. It is the product he wished he had.
What we want it to do is easy to say and hard to build. When an inspector arrives, the oversight programme should not need reconstructing. It should already be there, current and attributed, so that the inspection confirms what the organisation already knew.
What we did not get right
“Some of the initial timelines couldn’t be met, but I think that Mayet has also learnt and made many improvements through working with us. Overall, we’re extremely satisfied.”
He is being generous. We missed dates, and we learned more from that than from anything that went to plan.
The answer he gives
The last line of his testimonial is the question a buyer would put to him, and his answer to it.
“Would I buy and implement VendorVigilance again? 100 per cent.”
With thanks to Christoph and the team at Forschungsdock CRO.
Christoph’s testimonial, in full
Reproduced in full, exactly as he wrote and agreed it.
I know Tom Lazenby and Mayet because I got in touch with them via LinkedIn. As the managing director of a small but agile and, above all, highly experienced CRO, I deal with ICH E6(R3) and all related topics in my day-to-day work and in my seminars, and in this context I focus heavily on vendor management. I discussed this with Tom and immediately understood the value that VendorVigilance would offer. Having worked in clinical development for 33 years, and being just as familiar with the sponsors’ perspective as I am with that of CROs, we - as a small business with mainly small clients - utilise a wide variety of vendors in order to create and offer our clients the best possible set-up.
Working with Tom is a real pleasure because he knows what he’s talking about and has a vision that makes sense. He has realised this vision in VendorVigilance. We’re absolutely delighted to have VendorVigilance. As we were Mayet’s first client, much of what we now use was refined through dialogue. Mayet’s team is agile, client-focused and very cooperative. Some of the initial timelines couldn’t be met, but I think that Mayet has also learnt and made many improvements through working with us. Overall, we’re extremely satisfied.
Given the sheer number of our vendors, my team - primarily QA - is still busy mapping the work of the last nine years into VendorVigilance. The system is already proving extremely helpful in day-to-day operations, whether it’s preparing quotations or planning the operational implementation of the trials entrusted to us.
Once all our vendors are in the system, I think that we save time, as people will spend less time talking and mailing between the functions to find out where we are with this or that vendor. No idea what that means in figures, but it definitely makes us more efficient. With regard to sponsor discussions, I think that VendorVigilance levels our disadvantage of not having everything in house, by reducing the risk for the sponsor. It might even turn into an advantage over a ‘real’ full service CRO: with these, a department, let’s say Data Management, cannot quickly be replaced, while we can do that with our DM provider. So the de-central ‘quasi’ full service with VendorVigilance might turn into an advantage.
Thanks to the immediate access and centralisation of data which we have confidence in the quality of, VendorVigilance will continue to develop into one of our key platforms. We’re currently planning an interface with the CTMS to maximise the benefits. Would I buy and implement VendorVigilance again? 100 per cent.
Dr Christoph Ortland MRQA, Managing Director, Forschungsdock CRO GmbH
About the Author
Tom Lazenby
Tom has spent over a decade in Clinical Trials Operations and Quality Assurance and identified vendor oversight gaps that inspired Mayet's creation.
Want to discuss vendor oversight?
Book a consultation with Tom Lazenby to explore how Mayet can support your clinical QA needs.