supplier-audit-iso-9001

By July 25th, 2026ISO Audit And Certificate6 min read

Supplier Audit in ISO 9001: Evaluating External Providers

External providers and suppliers play a critical role in the quality of your final product. If a supplier delivers substandard materials or services, your customers experience the failure – not the supplier. A supplier audit ISO 9001 programme helps organisations evaluate, select and monitor external providers in line with Clause 8.4 of the standard. This article explains the requirements, the audit process and how to manage supplier performance effectively.

Clause 8.4 Requirements: Control of Externally Provided Processes

ISO 9001 Clause 8.4 requires organisations to ensure that externally provided processes, products and services conform to specified requirements. The clause has three sub-sections:

  • 8.4.1 General – The organisation must determine the controls to be applied to external providers and their outputs. The type and extent of control depends on the potential impact on product conformity and customer satisfaction.
  • 8.4.2 Type and extent of control – The organisation must define and apply criteria for evaluation, selection, monitoring and re-evaluation of external providers. Records of these activities must be maintained.
  • 8.4.3 Information for external providers – The organisation must clearly communicate requirements for products, services, processes, competence, interaction and any applicable quality or environmental management system requirements.
ClauseRequirementKey Evidence for Audit
8.4.1Determine controls for external providersRisk assessment of supplier impact
8.4.2Define evaluation and selection criteriaSupplier evaluation records, approved supplier list
8.4.3Communicate requirements to external providersPurchase orders, contracts, specifications

Supplier Evaluation Criteria

A robust supplier audit ISO 9001 programme begins with well-defined evaluation criteria. These criteria should be applied before selecting a new supplier and during periodic reviews of existing suppliers. Common evaluation criteria include:

CriterionWhat to EvaluateScoring Method
Quality management systemIs the supplier ISO 9001 certified? Do they have documented processes?Certification status + process maturity rating
Product qualityHistorical defect rates, non-conformance reports, customer returnsDefect parts per million (DPPM)
Delivery performanceOn-time delivery rate, lead time reliability, backorder frequencyPercentage of on-time deliveries
Financial stabilityCredit rating, revenue trends, dependency riskFinancial health score
Technical capabilityEquipment, facilities, skilled personnel, R&D capacityCapability assessment matrix
Regulatory complianceLicences, permits, environmental and health & safety recordsCompliance checklists

Audit Types: On-Site, Desktop and Remote

Supplier audits can be conducted in different ways depending on the supplier’s risk level, location and the nature of the supplied product or service. The three main types are:

Audit TypeDescriptionWhen to Use
On-Site AuditAuditor visits the supplier’s premises to observe processes, inspect facilities and interview staffHigh-risk suppliers, critical components, initial qualification, or when documentation alone is insufficient
Desktop AuditReview of supplied documentation, records, certifications and quality data without visiting the siteLow-risk suppliers, established partners with strong track records, or interim reviews
Remote AuditLive video conferencing, screen sharing and digital evidence review conducted in real timeTravel restrictions, routine monitoring, or when the supplier has a mature digital quality system

Supplier Scorecard

A supplier scorecard is a quantitative tool used to track and compare supplier performance over time. Scorecards typically include weighted metrics across quality, delivery, cost and responsiveness. A well-designed scorecard provides objective data for supplier re-evaluation decisions.

A typical supplier scorecard might weight quality at 40%, delivery at 30%, cost at 20% and responsiveness at 10%. Suppliers scoring above 90% are classified as preferred, while those below 70% may trigger a corrective action plan or removal from the approved supplier list.

MetricWeightTargetScore
Defect rate (DPPM)25%< 50095/100
On-time delivery30%> 98%90/100
Cost competitiveness20%Within 5% of benchmark85/100
Incident resolution time15%< 48 hours88/100
Audit findings10%Zero major non-conformances100/100
Overall score100%> 90%91/100

Nonconforming Supplier Management

When a supplier delivers nonconforming products or services, the organisation must take prompt action. ISO 9001 Clause 8.7 requires that nonconforming outputs are identified and controlled to prevent unintended use or delivery. The process typically involves:

  1. Identification – Tag, quarantine and document the nonconforming item with a non-conformance report (NCR).
  2. Notification – Inform the supplier with a formal corrective action request (CAR).
  3. Containment – Decide whether to reject, rework, accept with concession or scrap the nonconforming material.
  4. Root cause analysis – Require the supplier to investigate the cause and propose corrective actions.
  5. Verification – Confirm that corrective actions have been implemented and are effective.
  6. Re-evaluation – If non-conformance repeats, reassess the supplier’s status on the approved list.

Approved Supplier List

The approved supplier list (ASL) is a controlled document that records all suppliers who have been evaluated and deemed acceptable. The ASL should include the supplier name, scope of supply, evaluation date, classification rating and re-evaluation interval. Procurement must only purchase from suppliers on the approved list, except under defined emergency provisions with documented approval.

Frequently Asked Questions

How often should supplier audits be conducted?

The frequency depends on supplier risk. High-risk or critical suppliers may require annual on-site audits. Low-risk suppliers may be audited every two to three years or monitored through desktop reviews and scorecard data.

What is the difference between a supplier audit and a supplier evaluation?

A supplier evaluation is the initial assessment conducted before selecting a supplier. A supplier audit is a deeper, ongoing review of a supplier’s processes and performance. Both are required under ISO 9001 Clause 8.4.2.

Do we need to audit every supplier?

No. ISO 9001 requires that you determine the type and extent of control based on the supplier’s impact on product conformity. Low-impact suppliers may only need a desktop review, while high-impact suppliers require more rigorous audits.

Can a remote audit replace an on-site audit?

Remote audits can supplement on-site audits but should not fully replace them for high-risk suppliers. The ISO 19011 auditing guidelines support remote techniques but caution that physical observation of processes and facilities provides unique assurance value.

What happens if a supplier refuses to be audited?

Refusal to participate in an audit should trigger escalation. For a critical supplier, this may be a contractual breach. The organisation should consider alternative suppliers and document the risk acceptance if continued engagement is unavoidable.

How do we handle a supplier with repeated non-conformances?

Repeated non-conformances should result in a formal performance review, a corrective action plan with milestones, and potential removal from the approved supplier list if improvement is not demonstrated within an agreed timeframe.

Strengthen Your Supplier Management Programme

An effective supplier audit ISO 9001 programme protects your quality reputation and reduces supply chain risk. Our quality management consultants can help you design audit criteria, scorecards and evaluation processes tailored to your industry.

Contact us on WhatsApp for immediate assistance with your ISO 9001 supplier audits.

Tags: ISO 9001, supplier audit, external provider, supply chain, supplier evaluation, QMS, procurement