ISO 9001 requires you to control externally provided processes, products, and services. In plain terms: you are responsible for what your suppliers deliver, and an auditor will want to see evidence that you are managing that responsibility actively. For many small businesses, supplier management is one of the areas where gaps are most commonly found at certification audits, not because the underlying practices are poor, but because they have never been documented or formalised.
This guide explains what ISO 9001 Clause 8.4 actually requires, how to build a supplier management process that is proportionate to your business size, and when and how to conduct supplier audits.
What ISO 9001 Clause 8.4 Requires
Clause 8.4 of ISO 9001:2015 is titled "Control of externally provided processes, products, and services." It applies whenever your organisation uses external suppliers, subcontractors, or partners whose output becomes part of what you deliver to your customers.
The clause requires you to do four things. First, determine the controls to apply to external providers. Second, define criteria for evaluating, selecting, monitoring, and re-evaluating external providers. Third, communicate your requirements clearly to external providers. Fourth, retain documented evidence of evaluations and any necessary actions arising from them.
Note that the clause says nothing about how many suppliers you should audit, how frequently, or by what method. You are required to apply controls appropriate to the risk that the external provision poses to your ability to consistently deliver conforming products or services to your customers.
A Risk-Based Approach to Supplier Management
The foundation of any sensible supplier management process is a risk assessment of your supply base. Not all suppliers carry the same risk. A supplier who provides your office coffee is very different from a supplier who manufactures a critical component that goes into a product you sell to aerospace customers.
A practical way to classify suppliers is to assess two dimensions: criticality (how important the supplied product or service is to your output quality) and replaceability (how easily you could switch to an alternative supplier at short notice). Suppliers who are both critical and difficult to replace warrant the most active management. Suppliers who are low-criticality and easily replaced need only basic controls.
Supplier Classification Example
Critical and sole-source (e.g. specialist subcontractor providing a bespoke process): full supplier evaluation, regular performance monitoring, annual review, on-site audit as required
Critical with alternatives available (e.g. key material supplier): thorough initial evaluation, regular performance scoring, periodic remote or desktop audit
Non-critical with multiple alternatives (e.g. standard consumables supplier): basic initial checks, monitor via delivery and quality performance data
The Approved Supplier List
ISO 9001 requires you to retain documented evidence of supplier evaluations. In practice, this means maintaining an approved supplier list (ASL): a register of the suppliers you have assessed and approved for use, along with the basis on which they were approved and their current status.
Your ASL does not need to be complex. At minimum it should record the supplier name, what they supply, the date of their most recent evaluation, their approval status, and any conditions or restrictions on use. For many SMEs a spreadsheet is entirely adequate.
It is common for businesses to maintain an ASL of active suppliers, graded as Critical, Approved, or Conditional. Critical suppliers are reviewed annually; Approved suppliers are reviewed every two years unless performance data prompts an earlier review. Conditional suppliers have a defined action plan to move them to Approved status or be removed from the list.
Methods for Evaluating and Auditing Suppliers
ISO 9001 does not require on-site supplier audits for all suppliers. The method you use should be proportionate to the risk the supplier represents. The table below summarises the main options.
Method | When to Use | What It Involves | Effort |
|---|---|---|---|
Supplier questionnaire | All new suppliers as a minimum | Written questions about quality systems, certifications, capacity, financial stability | Low |
Desktop review | Low to medium risk suppliers | Review of certificates, accreditations, quality records, references | Low to medium |
Remote audit | Medium risk or when travel is impractical | Video call review of processes, records, and documented procedures | Medium |
On-site audit | High risk, critical, or sole-source suppliers | Physical visit to assess operations, observe processes, review records | High |
Third-party certification check | Suppliers holding ISO 9001 or equivalent | Verify certificate is current and from an accredited body | Very low |
What to Cover in a Supplier Audit
Whether you conduct a supplier audit by questionnaire, remote review, or on-site visit, the core areas to assess are consistent.
Quality management system: does the supplier have documented processes? Do they hold relevant certifications (ISO 9001, sector-specific standards)?
Capacity and capability: can they meet your volume and technical requirements? Do they have the right equipment, staff, and processes?
Quality control: how do they inspect and test their outputs before delivery? What happens when they identify a defect?
Nonconformity management: how do they handle and report quality failures? Do they conduct root cause analysis?
Communication and responsiveness: are they easy to work with? Do they communicate proactively about issues or delays?
Financial stability: for critical suppliers, is there evidence of financial health that gives confidence in their continued operation?
Communicating Requirements to Suppliers
Clause 8.4.3 requires you to communicate your requirements to external providers before they begin work. This includes the processes, products, or services to be provided; required approvals and qualifications; how you will verify their output; and any relevant quality standards or specifications.
In practice, this means your purchase orders, contracts, or statements of work should include quality requirements rather than just commercial terms. For a small business, this can be as simple as a standard set of quality requirements included in your purchase order terms, or a brief supplier requirements document issued to all approved suppliers.
Monitoring Ongoing Supplier Performance
Initial approval is not the end of supplier management. ISO 9001 requires ongoing monitoring and re-evaluation of external providers. The simplest approach for most SMEs is to track a small number of objective performance metrics for each supplier and review them at regular intervals.
On-time delivery rate: percentage of deliveries received by the agreed date
Defect or rejection rate: percentage of delivered items that fail your incoming inspection or are returned
Responsiveness to issues: how quickly and effectively the supplier responds when a problem is raised
These metrics feed directly into your corrective action process when performance falls below the threshold and into your annual supplier review decisions. They should be reviewed at your management review meeting.
About The Author
Nicole Webb is an ISO compliance specialist with extensive experience in ISO management systems, accreditation and internal auditing, providing a strong foundation for writing practical, expert-led articles on ISO topics. She has managed accredited management systems and supported Global compliance teams across ISO 9001, ISO 14001, ISO 45001, ISO 22301, ISO 27001 and ISO 13485, giving her a broad, cross-standard perspective that informs her writing. She now runs ISOLiteBites, an ISO-focused training company delivering both e-learning courses and bespoke training for businesses of all sizes.
