Supplier Audit in ISO 9001: Evaluating External Providers
External providers and suppliers play a critical role in the quality of your final product. If a supplier delivers substandard materials or services, your customers experience the failure – not the supplier. A supplier audit ISO 9001 programme helps organisations evaluate, select and monitor external providers in line with Clause 8.4 of the standard. This article explains the requirements, the audit process and how to manage supplier performance effectively.
Clause 8.4 Requirements: Control of Externally Provided Processes
ISO 9001 Clause 8.4 requires organisations to ensure that externally provided processes, products and services conform to specified requirements. The clause has three sub-sections:
- 8.4.1 General – The organisation must determine the controls to be applied to external providers and their outputs. The type and extent of control depends on the potential impact on product conformity and customer satisfaction.
- 8.4.2 Type and extent of control – The organisation must define and apply criteria for evaluation, selection, monitoring and re-evaluation of external providers. Records of these activities must be maintained.
- 8.4.3 Information for external providers – The organisation must clearly communicate requirements for products, services, processes, competence, interaction and any applicable quality or environmental management system requirements.
| Clause | Requirement | Key Evidence for Audit |
|---|---|---|
| 8.4.1 | Determine controls for external providers | Risk assessment of supplier impact |
| 8.4.2 | Define evaluation and selection criteria | Supplier evaluation records, approved supplier list |
| 8.4.3 | Communicate requirements to external providers | Purchase orders, contracts, specifications |
Supplier Evaluation Criteria
A robust supplier audit ISO 9001 programme begins with well-defined evaluation criteria. These criteria should be applied before selecting a new supplier and during periodic reviews of existing suppliers. Common evaluation criteria include:
| Criterion | What to Evaluate | Scoring Method |
|---|---|---|
| Quality management system | Is the supplier ISO 9001 certified? Do they have documented processes? | Certification status + process maturity rating |
| Product quality | Historical defect rates, non-conformance reports, customer returns | Defect parts per million (DPPM) |
| Delivery performance | On-time delivery rate, lead time reliability, backorder frequency | Percentage of on-time deliveries |
| Financial stability | Credit rating, revenue trends, dependency risk | Financial health score |
| Technical capability | Equipment, facilities, skilled personnel, R&D capacity | Capability assessment matrix |
| Regulatory compliance | Licences, permits, environmental and health & safety records | Compliance checklists |
Audit Types: On-Site, Desktop and Remote
Supplier audits can be conducted in different ways depending on the supplier’s risk level, location and the nature of the supplied product or service. The three main types are:
| Audit Type | Description | When to Use |
|---|---|---|
| On-Site Audit | Auditor visits the supplier’s premises to observe processes, inspect facilities and interview staff | High-risk suppliers, critical components, initial qualification, or when documentation alone is insufficient |
| Desktop Audit | Review of supplied documentation, records, certifications and quality data without visiting the site | Low-risk suppliers, established partners with strong track records, or interim reviews |
| Remote Audit | Live video conferencing, screen sharing and digital evidence review conducted in real time | Travel restrictions, routine monitoring, or when the supplier has a mature digital quality system |
Supplier Scorecard
A supplier scorecard is a quantitative tool used to track and compare supplier performance over time. Scorecards typically include weighted metrics across quality, delivery, cost and responsiveness. A well-designed scorecard provides objective data for supplier re-evaluation decisions.
A typical supplier scorecard might weight quality at 40%, delivery at 30%, cost at 20% and responsiveness at 10%. Suppliers scoring above 90% are classified as preferred, while those below 70% may trigger a corrective action plan or removal from the approved supplier list.
| Metric | Weight | Target | Score |
|---|---|---|---|
| Defect rate (DPPM) | 25% | < 500 | 95/100 |
| On-time delivery | 30% | > 98% | 90/100 |
| Cost competitiveness | 20% | Within 5% of benchmark | 85/100 |
| Incident resolution time | 15% | < 48 hours | 88/100 |
| Audit findings | 10% | Zero major non-conformances | 100/100 |
| Overall score | 100% | > 90% | 91/100 |
Nonconforming Supplier Management
When a supplier delivers nonconforming products or services, the organisation must take prompt action. ISO 9001 Clause 8.7 requires that nonconforming outputs are identified and controlled to prevent unintended use or delivery. The process typically involves:
- Identification – Tag, quarantine and document the nonconforming item with a non-conformance report (NCR).
- Notification – Inform the supplier with a formal corrective action request (CAR).
- Containment – Decide whether to reject, rework, accept with concession or scrap the nonconforming material.
- Root cause analysis – Require the supplier to investigate the cause and propose corrective actions.
- Verification – Confirm that corrective actions have been implemented and are effective.
- Re-evaluation – If non-conformance repeats, reassess the supplier’s status on the approved list.
Approved Supplier List
The approved supplier list (ASL) is a controlled document that records all suppliers who have been evaluated and deemed acceptable. The ASL should include the supplier name, scope of supply, evaluation date, classification rating and re-evaluation interval. Procurement must only purchase from suppliers on the approved list, except under defined emergency provisions with documented approval.
Frequently Asked Questions
How often should supplier audits be conducted?
The frequency depends on supplier risk. High-risk or critical suppliers may require annual on-site audits. Low-risk suppliers may be audited every two to three years or monitored through desktop reviews and scorecard data.
What is the difference between a supplier audit and a supplier evaluation?
A supplier evaluation is the initial assessment conducted before selecting a supplier. A supplier audit is a deeper, ongoing review of a supplier’s processes and performance. Both are required under ISO 9001 Clause 8.4.2.
Do we need to audit every supplier?
No. ISO 9001 requires that you determine the type and extent of control based on the supplier’s impact on product conformity. Low-impact suppliers may only need a desktop review, while high-impact suppliers require more rigorous audits.
Can a remote audit replace an on-site audit?
Remote audits can supplement on-site audits but should not fully replace them for high-risk suppliers. The ISO 19011 auditing guidelines support remote techniques but caution that physical observation of processes and facilities provides unique assurance value.
What happens if a supplier refuses to be audited?
Refusal to participate in an audit should trigger escalation. For a critical supplier, this may be a contractual breach. The organisation should consider alternative suppliers and document the risk acceptance if continued engagement is unavoidable.
How do we handle a supplier with repeated non-conformances?
Repeated non-conformances should result in a formal performance review, a corrective action plan with milestones, and potential removal from the approved supplier list if improvement is not demonstrated within an agreed timeframe.
Strengthen Your Supplier Management Programme
An effective supplier audit ISO 9001 programme protects your quality reputation and reduces supply chain risk. Our quality management consultants can help you design audit criteria, scorecards and evaluation processes tailored to your industry.
Contact us on WhatsApp for immediate assistance with your ISO 9001 supplier audits.
Tags: ISO 9001, supplier audit, external provider, supply chain, supplier evaluation, QMS, procurement