Cookie preferences

YARDtwin uses essential cookies for authentication and session management. We don’t currently set analytics or marketing cookies, but our cookie policy categorises them ahead of any future change. Read our Privacy Policy, GDPR Policy, and Cookie Policy.

YARDtwin
← All articles
Compliance & QualityJuly 27, 2026· 7 min read

We Published Our Entire Vendor Assurance Pack — Including What We Do Not Have

Here is how software procurement actually works in a regulated business. Operations picks the tool in week two. Quality and IT security start their review in week four. The questionnaire lands on the vendor in week six — forty tabs, and a request for a GAMP categorisation the vendor has never written down. Somewhere around week fourteen everyone agrees, and the thing that held it up was never the product.

We have been on the receiving end of that enough times to conclude the sequence is wrong. So we have published the answers up front.

PDF
FREE DOWNLOAD · NO FORM
YARDtwin Vendor Assurance Pack
PDF · 25 pages · no form, no email address required
  • Quality management system document index, GAMP 5 categorisation and validation approach
  • EU GMP Annex 11 and 21 CFR Part 11 mapped clause by clause, with evidence
  • ALCOA+ statement, retention schedule, GDPR and sub-processor register
  • Security architecture, secure-development evidence and a completed CAIQ-Lite
  • A complete open-items list — everything we have not yet done, with our own severity ratings
Download the PDF
No form, no email address, no follow-up. It opens in a new tab.

What is in it

Eighteen sections, organised so a reviewer can go straight to their own part. A quality reviewer needs the QMS index, the GAMP 5 categorisation and the Annex 11 and Part 11 mappings. IT security needs the hosting topology, the security architecture and the CAIQ-Lite. A DPO needs the controller-processor split, the sub-processor register and the AI governance section. Procurement needs the certification status, the continuity posture and the responsibility split. The pack opens with a table telling each of them which sections to read.

The clause mappings are the core of it. Every clause of Annex 11 — all seventeen — with what we do about it and where the evidence sits. Then 21 CFR Part 11: the §11.10 controls, the signature provisions of §11.50 and §11.70, and the electronic-signature requirements of §11.100, §11.200 and §11.300. Two of those rows are marked as *your* obligation rather than ours, because they cannot be discharged by a vendor, and pretending otherwise would leave a gap that only surfaces during an inspection.

And what is not in it

This is the part that made the document worth writing. §13 is a certification status table and §17 is a complete open-items list, and between them they say plainly:

  • We do not hold SOC 2 Type II. A combined programme with ISO 27001 is planned, with realistic target months, not a claim that an audit is underway.
  • We do not hold ISO 27001.
  • Our web application firewall has no rule set attached. The policy is in Prevention mode, which sounds reassuring and, without rules, filters nothing at layer 7. We found this while verifying claims for this document, and we would rather publish it than let a reviewer find it.
  • High availability is not enabled on the database, geo-redundant backup is off, and our RTO and RPO are internal targets rather than contractual commitments.
  • Our penetration testing was not performed by a CREST-accredited third party. The April 2026 test returned zero findings across ten OWASP categories; it was not an accredited independent test, and we say so where a reviewer looks.
Thirteen open items in total, each with a severity we assigned ourselves. Four are High. We would rather you assess that list against your own risk appetite than discover it in month three of a deployment.

On the difference between compliant and certified

One distinction the pack spends a paragraph on, because it is routinely blurred in this market. Annex 11 and 21 CFR Part 11 are regulatory expectations, not certification schemes. No body issues an "Annex 11 certificate", and a vendor offering one is selling something that does not exist. What can genuinely be evidenced is an implementation mapped clause by clause with artefacts behind each row — which is what the pack contains.

SOC 2 and ISO 27001 *are* certification schemes. We do not hold them. We therefore do not describe ourselves as certified, and our infrastructure provider's certifications are listed as theirs rather than quietly presented as ours.

Everything in it was verified, not copied

Compliance documents rot. A hosting region changes, a gap gets closed, a control gets renamed, and the document keeps asserting last year's architecture with this year's confidence. Ours had started to: an internal QMS document still described a hosting provider we migrated off, and a page on our own site described the wrong Azure regions.

So every status in the pack was checked against live production infrastructure and live source code on the day of publication — regions read from the subscription, the residency policy read from its assignment, the edge configuration read from live response headers, the audit-trail and signature behaviour read from the code that implements them. Where verification contradicted an existing document, the verification won. That is also how we found the firewall rule set.

The pack is dated and carries a review commitment: at least every six months, and reissued whenever a status in the certification table or the open-items list changes.

If you are the one who has to do the assessing

There is a companion piece to this. The Yard Operations GMP Audit Readiness Checklist is a 101-check self-inspection walk of the yard boundary — and its final domain is supplier qualification of your yard system vendor. This pack is written to answer that domain, whether or not the vendor you are assessing is us.

If you need something the pack does not contain — the full QMS set under NDA, executed test evidence, a software bill of materials for a nominated release, or a CAIQ completed in your own template — ask us at admin@yardtwin.com. The list of what is available on request is §18.

Assessing yard-management platforms for a regulated site? Start a free 30-day trial and put the product through the same scrutiny as the paperwork.

Hi there! Start your free trial in 2 minutes — I'll help you set everything up!