Pharma Engineering Insights

How to select an EMS supplier: from URS to RFP, bid evaluation and service agreement

How to turn the URS into a comparable request for quotation, which questions to ask suppliers, how to build a defensible evaluation grid, and what to define in the service agreement for an Environmental Monitoring System.

G GuideGxP 9 min read
✓ Official sources and references ✓ Practical approach ✓ For pharmaceutical professionals
GUIDEGXP · PRACTICAL GMP INSIGHTS
Illustrazione della valutazione comparativa di offerte per un sistema di monitoraggio ambientale

Selecting an EMS supplier is won or lost at tender stage, not in the final negotiation. If the request for quotation is well built, bids become comparable, differences emerge objectively and the choice is as defensible in inspection as any other project decision. If it is badly built, the comparison degenerates into a price contest across different scopes, and the decision ends up being made on what can be measured rather than on what matters.

The operating rule: the document sent to suppliers must ask for verifiable results, not describe a solution. And the scope of what the supplier must deliver — documentation, qualification support, training, spares, service — must be defined with the same precision as the technical supply, because that is exactly where the economic surprises of later years concentrate.

From URS to request for quotation

The RFQ is not the URS: it is the URS plus everything needed to make bids comparable and the contract governable. Minimum structure:

  • Context and scope: areas, indicative number of points, planned phases, site and schedule constraints.
  • User requirements: attached, expressed as verifiable results, with categories indicated (regulatory requirement, risk-based decision, good practice) as described in the article on the URS of an EMS.
  • Expected documentary deliverables: an explicit list of what the supplier must deliver, in what format and language, with timing.
  • Qualification support: what the supplier executes, what it supports and what remains with the company; whether and how activities at the supplier can be used to reduce on-site verification.
  • Data integrity requirements: expressed as verifiable functions, not as generic compliance statements.
  • Licensing model and recurring costs: requested in structured form, with the future expansion scenario stated by the company so that all suppliers price the same case.
  • Life cycle: support and update policy, declared obsolescence horizon, availability of spares and consumables, service conditions.
  • Exit strategy: how data is accessed at the end of the relationship, in what format, at what cost.
  • Mandated response format: more than anything else, this is what makes bids comparable. If each supplier answers in its own format, comparison will be largely impossible.

The regulatory frame

LevelWhat it establishes regarding supplier selection
Regulatory requirement (EudraLex Volume 4, Part I and Annex 11)Outsourced activities must be defined in written agreements setting out the responsibilities and activities of each party. For computerised systems, a supplier assessment is expected, with depth proportionate to risk and criticality.
Regulatory requirement (EudraLex Volume 4, Annex 15)The requirements specification is the reference for qualification: what the supplier delivers must be verifiable against it.
Regulatory requirement (EudraLex Volume 4, Annex 1)Sets the reference intended use: monitoring must be appropriate to criticality and embedded in the contamination control strategy.
Industry good practiceDocumented supplier assessment, supplier audit where justified by risk, verification of references.
GuideGxP operational recommendationDefine and approve the evaluation grid and its weights before receiving bids, and keep it as part of the project dossier.

The questions to ask at tender

These are the questions whose answers separate bids that otherwise look alike. They must be phrased so as to force a specific answer, not a generic statement.

AreaQuestion to askWhy it matters
Data integrityWhich events are logged in the audit trail, and can it be disabled from an administrative account?Separates systems that meet the requirement from those that claim it
Data integrityCan the audit trail be reviewed by the company without supplier involvement?Determines whether periodic review is sustainable
PermissionsAre user profiles freely configurable or predefined?Determines whether the site's segregation of duties can be reflected
DataIn what format can data and its metadata be exported?Drives archiving, migration and exit strategy
LicensingWhat drives cost: channels, workstations, users, subscription?Determines the cost of every future expansion
ExpansionPrice for adding N points in an already covered area and in a new areaMakes economic scalability comparable across bids
QualificationWhich qualification documents are delivered, and in what form?Determines how much work remains in-house
QualificationIs the FAT executed on the customer's final configuration?Drives the ability to reduce on-site verification
Life cycleWhat is the version support policy and the declared obsolescence horizon?It is the figure that foreshadows the next replacement project
ServiceHow are intervention and on-call organised, and with what geographic coverage?Determines real recovery times
Remote accessHow does it work, how is it authorised and how is it logged?It must be compatible with the site's security policies
ExitWhat happens to the data at the end of the contract?To be negotiated now, not at decommissioning
ReferencesComparable installations by criticality and size, contactableVerified references are worth more than presentations

Working tool: evaluation grid

The grid must be approved before bids are received. Weights are deliberately left blank: they are assigned by the project team according to intended use and documented together with the outcome.

CriterionWeight (to be set)How it is assessed
Coverage of user requirementsPoint-by-point comparison against the requirements matrix
Demonstrated data integrity capabilitySpecific answers and, where possible, demonstration
Documentary deliverables and qualification supportList and form of documents actually offered
Predictability of recurring costsLicensing model and pricing of the expansion scenario
Support and obsolescence policyWritten, verifiable statement
Service and sparesOrganisation, coverage, declared availability
Data exportability and exit strategyFormats and conditions offered
Experience on comparable installationsVerified references
Compatibility with site IT policiesJoint assessment with IT
Robustness of the proposed project planTiming, resources, interface management
Purchase costComparison on a normalised scope
Total cost over the defined horizonTCO model applied identically to all bids

The economic comparison must be made on a normalised scope: if one bid includes qualification support and another does not, the prices are not comparable until the scope is aligned. The method for building the multi-year comparison is described in the article on budget and total cost of ownership.

What to define in the service agreement

  • Scope of service: what is included, what is chargeable, what is excluded.
  • Service levels: response and restoration times, defined by the company according to system criticality and agreed; with how they are measured and reported.
  • Escalation: who is involved, after how long and with what decision authority.
  • Remote access: method, authorisation, logging, revocation.
  • Interventions on a qualified system: obligation to give notice, authorisation, recording and verification of state on completion.
  • Maintenance and calibration: activities included, with an explicit obligation to provide the as-found record in calibrations.
  • Spares and consumables: guaranteed availability, supply times, management of component obsolescence.
  • Version management: advance notice of updates, documentation of changes, support to impact assessment.
  • Confidentiality and data handling: who may access the customer's data, for what purposes, within what limits.
  • Periodic contract review: examining actual performance against agreed levels.
  • Exit: return of data, format, timing and cost, transition assistance.

A practical scenario

At a site we will call Site Delta — realistic but fictional — three bids arrive for a new EMS. The first is appreciably cheaper than the other two and is initially seen as the natural choice.

Normalising the scope changes the picture. It emerges that the cheapest bid does not include qualification support, that the licensing model is per channel with a cost for every point added, and that export of historical data is available only in a proprietary format. The other two include documentary support, use a per-workstation licensing model and provide export in an open format.

Brought to the same scope and projected over the horizon defined by the team — including the already planned expansion of some areas — the initial difference narrows appreciably, and the decisive criterion becomes another one: the demonstrated ability to allow independent audit trail review, which in the first bid required supplier involvement.

The final decision is not the point of the scenario. The point is that the grid had been approved before bids were received, so the choice was made on criteria set in advance, not on criteria that made the preferred bid win.

Common mistakes and red flags

  • Building the RFQ by copying one supplier's documentation. It makes the tender formally open and substantively closed, and prevents any real technical comparison.
  • Not mandating a response format. Without a common format, comparison between bids is largely impossible.
  • Comparing prices across different scopes. This is the mistake that leads to choosing the bid that excluded the most.
  • Defining criteria after seeing the bids. The decision loses defensibility, even when it is technically right.
  • Accepting generic compliance statements. “Annex 11 compliant” is not an answer: ask for verifiable functions.
  • Evaluating on the commercial demonstration. The configuration shown in a demo is not the one that will be installed and qualified.
  • Not clarifying the licensing model. The cost of expansion must be known before signature.
  • Neglecting the exit strategy. At decommissioning your negotiating position is nil.
  • Not involving IT in the evaluation. A system incompatible with the site's security policies creates problems no clause can solve.
  • Not verifying references. A phone call to a comparable customer is worth more than many pages of presentation.

How to document the decision

  • Approved RFQ with attached requirements and mandated response format.
  • Evaluation grid approved before bids, with criteria, weights and rationale.
  • Supplier assessment documented, with depth proportionate to risk.
  • Bid evaluation report: scores, supporting evidence, normalisation of the economic scope.
  • Records of clarifications exchanged with suppliers, which form part of the dossier.
  • Rationale for the choice and for the exclusions.
  • Contract and service agreement with responsibilities, levels and exit clauses.
  • Periodic review plan for supplier performance.

Key takeaways

  • The quality of the tender determines the quality of the choice: the RFQ asks for results, it does not describe solutions.
  • A mandated response format is what makes bids comparable.
  • The evaluation grid is approved before bids are received.
  • Prices are only comparable on normalised scopes and over the whole life cycle.
  • Licensing model, obsolescence and exit strategy are negotiated at tender.
  • Compliance statements are no substitute for verifiable functions.

Frequently asked questions

Is a supplier audit necessary?

It depends on the risk and criticality of the system. A supplier assessment is expected; its depth — from a documentary questionnaire to an on-site audit — must be determined and justified on a risk basis, and documented.

How do you compare bids with different scopes?

By bringing them to the same scope before comparing: define the complete set of items needed and ask every supplier to price them, or value the missing items internally using uniform criteria while declaring the assumptions.

Can price be the predominant criterion?

It can, if the company decides so and documents it, but it must be applied to cost over the defined horizon and on equivalent scopes. Purchase price in isolation is almost always a misleading indicator for a system that stays in service for many years.

What should be asked about qualification?

Which documents are delivered, in what form, who executes what, and whether the FAT is run on the customer's final configuration. How much work remains in-house depends on those answers, as described in the article on FAT, SAT, IQ, OQ and PQ.

How are service levels defined?

Starting from the criticality of the system and from what happens at the site when it is unavailable: those needs determine the times to be agreed, not the standard values proposed by the supplier. Measurement method and reporting must also be defined.

When is the exit strategy negotiated?

At tender. Data return format, timing, cost and any transition assistance must be defined while your negotiating position is strong, not at decommissioning. The topic connects to retrofitting and replacing existing systems.

Regulatory and technical references

Continue the project journey

This article is part of the GuideGxP Environmental Monitoring Systems pathway, which follows the life cycle of an EMS project from requirements definition through to operational management.

Want analysis like this straight to your inbox? Subscribe to The Pragmatic GMP, the GuideGxP newsletter for professionals working daily with GMP, qualification and data integrity.

THE PRAGMATIC GMP · EVERY MONDAY

The GMP topics that matter, in 7 minutes.

One GMP topic, one real-world example and one practical action, based on official sources and inspection trends.
Discover The Pragmatic GMP →