DEV Community

Rajiv Iyer
Rajiv Iyer

Posted on

Questioning the medtech "partner program" — when a broker is just a broker

The pitch always sounds reasonable. A "partner program" promises vetted suppliers, shared audits, pre-negotiated terms, and faster onboarding. From a CMO perspective, that should be music. We sit on 40+ active suppliers, and the cost of qualifying a new sterilization partner is measured in months, not weeks. So when a broker approached us last year waving a curated network of "audited" medtech suppliers, I sat up. Then I read the contract. Then I asked questions. Then I started writing this down.

This is not a screed against partnership models. Some are genuinely useful. But a few of them are repackaged brokerages dressed in risk-sharing language, and the rosy rhetoric hides a real shift in who carries the QMS accountability. If you are a small manufacturer — two QA people, mounting CAPA backlog, next notified body visit in eight months — that shift can break you quietly.

What "partner program" actually means

In medtech, a partner program is usually one of three things:

  • A referral network — a broker introduces you to suppliers they have not audited, and disappears.
  • A managed supplier program — the broker claims ongoing qualification, monitoring, and re-audit on your behalf, often for a fee layered on each PO.
  • A license/white-label arrangement — the broker lets you resell or co-brand product from an OEM whose own QMS you do not see.

The middle one is the one with the most interesting compliance teeth. Because if a managed supplier program fails, the question your auditor will ask is not "did the broker do its job?" — it is "did you control your supplier?" That question lands on the legal manufacturer, not the broker.

I have also seen a fourth, quieter variant: a programme that on paper is managed, but in practice the broker sends you a one-page "summa form" — summa meaning "merely" or "just for show" in Tamil — to confirm supplier status, and calls that qualification. The form is the entire audit trail. That is the version to watch for.

Where the accountability gets fuzzy

I sat in a CAPA review where a non-conformance had travelled through a managed supplier, then through a sub-tier broker, then to us. The chain of custody was clean. The chain of responsibility was not — and with it, the traceability of who owned what. Three QMS managers from three companies tried to point at each other. The root cause analysis, when it finally landed on my desk, had been rewritten four times because nobody wanted to own it.

This is the heart of the risk. ISO 13485:2016 §7.4.1 and §7.4.2 are explicit: purchasing controls apply to the legal manufacturer, and the legal manufacturer must evaluate, select, monitor, and re-evaluate suppliers based on their ability to meet requirements. 21 CFR 820.50 says the same thing in different words. EU MDR 2017/745 Article 10(9) extends this to economic operators in the chain.

None of those clauses go away because you have a partner program. The oversight obligation does not transfer. A broker can do work on your behalf, but the burden of demonstrating control — at audit — stays with you. If a regulatory body later asks for the qualification evidence and the answer is "the broker has it," that is a finding waiting to be written.

The risks I've seen in practice

A few patterns worth naming, all from real incidents in our network:

  • Audit evidence lives in the broker's portal. When the supplier's quality documents are stored in a system you do not control, your own records become derivative. During an unannounced notified body follow-up, derivative evidence is a weak place to stand.
  • CAPA routing falls between stools. Suppliers assume the broker is tracking action items. Brokers assume the legal manufacturer is. CAPAs age out, root causes drift, and effective verification never quite happens.
  • Change control gets thinned. A broker mediates a process change at the supplier, but the impact assessment on your design history file is "the supplier confirmed no impact." That confirmation is not an impact assessment.
  • Confidentiality boundaries blur. You may be sharing your design inputs, your drawings, your COA templates with a partner who is also partnered with two of your competitors. Read the data terms carefully.

What I would ask before signing

If you are weighing one of these programs, here is the short list I now keep on my desk:

  • Does the contract explicitly state that the legal manufacturer retains supplier control responsibility under ISO 13485 §7.4 and 21 CFR 820.50?
  • Can I obtain the broker's raw supplier audit reports, not just summary scorecards?
  • Does the broker's QMS have a written interface agreement with each tier-1 supplier, and can I see it?
  • Who owns the CAPA record when a non-conformance crosses the broker boundary — the supplier, the broker, or me?
  • What is the change-control workflow when a supplier modifies a process, and where does my DHF get updated?
  • If the broker is dissolved or acquired, what happens to the supplier records and my access to them?

If the answers to any of those are vague, the partnership is not yet ready to bear the weight of a notified body visit.

What I would do differently

If I were starting over, I would not outsource my supplier quality oversight to a broker. I would consider outsourcing activities — pre-screening questionnaires, COA verification, scheduled re-audit calendars — and I would keep the QMS decision rights firmly on our side. The work the broker does is work I can review. The accountability the broker absorbs is accountability I cannot review, because I no longer hold it.

A partner program is a tool. Tools can extend reach or they can erode grip. The difference is whether the QMS accountability stays in your hands and is supported by a connected workflow you control, or whether it has quietly migrated into a contract clause that reads well and survives nothing.

Have you been through a managed supplier program that genuinely held up at audit? Or one that collapsed the moment a non-conformance crossed the boundary? I would like to hear how the CAPA routing worked in practice.

Top comments (0)