Back to Resources
    Articles
    ISO 9001

    ISO 9001 Supplier Audits: What Small Businesses Need to Know

    ByNicole Webb·
    Share:
    Infographic showing ISO 9001 supplier audit workflow: identify suppliers, define scope, create checklist, conduct audit, gather evidence, identify nonconformities, issue report, follow up.

    ISO 9001 requires you to control externally provided processes, products, and services. In plain terms: you are responsible for what your suppliers deliver, and an auditor will want to see evidence that you are managing that responsibility actively. For many small businesses, supplier management is one of the areas where gaps are most commonly found at certification audits, not because the underlying practices are poor, but because they have never been documented or formalised.

    This guide explains what ISO 9001 Clause 8.4 actually requires, how to build a supplier management process that is proportionate to your business size, and when and how to conduct supplier audits.

    What ISO 9001 Clause 8.4 Requires

    Clause 8.4 of ISO 9001:2015 is titled "Control of externally provided processes, products, and services." It applies whenever your organisation uses external suppliers, subcontractors, or partners whose output becomes part of what you deliver to your customers.

    The clause requires you to do four things. First, determine the controls to apply to external providers. Second, define criteria for evaluating, selecting, monitoring, and re-evaluating external providers. Third, communicate your requirements clearly to external providers. Fourth, retain documented evidence of evaluations and any necessary actions arising from them.

    Note that the clause says nothing about how many suppliers you should audit, how frequently, or by what method. You are required to apply controls appropriate to the risk that the external provision poses to your ability to consistently deliver conforming products or services to your customers.

    A Risk-Based Approach to Supplier Management

    The foundation of any sensible supplier management process is a risk assessment of your supply base. Not all suppliers carry the same risk. A supplier who provides your office coffee is very different from a supplier who manufactures a critical component that goes into a product you sell to aerospace customers.

    A practical way to classify suppliers is to assess two dimensions: criticality (how important the supplied product or service is to your output quality) and replaceability (how easily you could switch to an alternative supplier at short notice). Suppliers who are both critical and difficult to replace warrant the most active management. Suppliers who are low-criticality and easily replaced need only basic controls.

    Supplier Classification Example

    • Critical and sole-source (e.g. specialist subcontractor providing a bespoke process): full supplier evaluation, regular performance monitoring, annual review, on-site audit as required

    • Critical with alternatives available (e.g. key material supplier): thorough initial evaluation, regular performance scoring, periodic remote or desktop audit

    • Non-critical with multiple alternatives (e.g. standard consumables supplier): basic initial checks, monitor via delivery and quality performance data

    The Approved Supplier List

    ISO 9001 requires you to retain documented evidence of supplier evaluations. In practice, this means maintaining an approved supplier list (ASL): a register of the suppliers you have assessed and approved for use, along with the basis on which they were approved and their current status.

    Your ASL does not need to be complex. At minimum it should record the supplier name, what they supply, the date of their most recent evaluation, their approval status, and any conditions or restrictions on use. For many SMEs a spreadsheet is entirely adequate.

    It is common for businesses to maintain an ASL of active suppliers, graded as Critical, Approved, or Conditional. Critical suppliers are reviewed annually; Approved suppliers are reviewed every two years unless performance data prompts an earlier review. Conditional suppliers have a defined action plan to move them to Approved status or be removed from the list.

    Methods for Evaluating and Auditing Suppliers

    ISO 9001 does not require on-site supplier audits for all suppliers. The method you use should be proportionate to the risk the supplier represents. The table below summarises the main options.

    Method

    When to Use

    What It Involves

    Effort

    Supplier questionnaire

    All new suppliers as a minimum

    Written questions about quality systems, certifications, capacity, financial stability

    Low

    Desktop review

    Low to medium risk suppliers

    Review of certificates, accreditations, quality records, references

    Low to medium

    Remote audit

    Medium risk or when travel is impractical

    Video call review of processes, records, and documented procedures

    Medium

    On-site audit

    High risk, critical, or sole-source suppliers

    Physical visit to assess operations, observe processes, review records

    High

    Third-party certification check

    Suppliers holding ISO 9001 or equivalent

    Verify certificate is current and from an accredited body

    Very low

    What to Cover in a Supplier Audit

    Whether you conduct a supplier audit by questionnaire, remote review, or on-site visit, the core areas to assess are consistent.

    • Quality management system: does the supplier have documented processes? Do they hold relevant certifications (ISO 9001, sector-specific standards)?

    • Capacity and capability: can they meet your volume and technical requirements? Do they have the right equipment, staff, and processes?

    • Quality control: how do they inspect and test their outputs before delivery? What happens when they identify a defect?

    • Nonconformity management: how do they handle and report quality failures? Do they conduct root cause analysis?

    • Communication and responsiveness: are they easy to work with? Do they communicate proactively about issues or delays?

    • Financial stability: for critical suppliers, is there evidence of financial health that gives confidence in their continued operation?

    Communicating Requirements to Suppliers

    Clause 8.4.3 requires you to communicate your requirements to external providers before they begin work. This includes the processes, products, or services to be provided; required approvals and qualifications; how you will verify their output; and any relevant quality standards or specifications.

    In practice, this means your purchase orders, contracts, or statements of work should include quality requirements rather than just commercial terms. For a small business, this can be as simple as a standard set of quality requirements included in your purchase order terms, or a brief supplier requirements document issued to all approved suppliers.

    Monitoring Ongoing Supplier Performance

    Initial approval is not the end of supplier management. ISO 9001 requires ongoing monitoring and re-evaluation of external providers. The simplest approach for most SMEs is to track a small number of objective performance metrics for each supplier and review them at regular intervals.

    • On-time delivery rate: percentage of deliveries received by the agreed date

    • Defect or rejection rate: percentage of delivered items that fail your incoming inspection or are returned

    • Responsiveness to issues: how quickly and effectively the supplier responds when a problem is raised

    These metrics feed directly into your corrective action process when performance falls below the threshold and into your annual supplier review decisions. They should be reviewed at your management review meeting.

    About The Author

    Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.

    Frequently Asked Questions

    Does ISO 9001 require you to audit your suppliers?
    ISO 9001 Clause 8.4 requires you to control externally provided processes, products, and services, and to evaluate and monitor external providers. However, it does not specifically require on-site supplier audits for all suppliers. The controls you apply should be proportionate to the risk the supplier represents to your ability to deliver conforming products or services. For low-risk, easily replaceable suppliers, a basic questionnaire and performance monitoring may be sufficient. For critical or sole-source suppliers, more thorough evaluation including periodic audits is appropriate.
    What is an approved supplier list in ISO 9001?
    An approved supplier list (ASL) is a documented register of the external providers your organization has evaluated and approved for use. It is the primary evidence document for demonstrating compliance with ISO 9001 Clause 8.4. At minimum it should record each supplier's name, what they supply, the date and basis of their most recent evaluation, their approval status, and any conditions on use. The ASL must be controlled as part of your documented information and reviewed regularly as part of your management system.
    What should be included in a supplier questionnaire for ISO 9001?
    A supplier questionnaire for ISO 9001 should cover the supplier's quality management system (including any certifications held), their processes and technical capability, their quality control and inspection procedures, how they manage and report nonconformities, their capacity to meet your volume and delivery requirements, and their approach to corrective action. For suppliers processing personal data on your behalf, GDPR compliance should also be assessed. The depth of the questionnaire should reflect the risk and criticality of the supplier.
    How often should you re-evaluate suppliers under ISO 9001?
    ISO 9001 does not specify a required frequency for supplier re-evaluation. Your re-evaluation schedule should be based on the risk and criticality of the supplier and their performance history. As a practical guide, critical suppliers should be reviewed at least annually; other approved suppliers can be reviewed every one to two years unless performance data or significant changes in the supply relationship prompt an earlier review. Re-evaluation should be triggered automatically by significant quality failures, delivery problems, or changes in the supplier's business or ownership.
    Share:

    Need Help With ISO Certification?

    Get quotes from accredited registrars and ISO experts.