iso-9001-purchasing-procurement

By July 25th, 2026ISO Audit And Certificate9 min read

ISO 9001 Purchasing and Procurement: Controlling External Providers

The quality of your product or service depends not only on what you do internally but also on what you buy from external providers. ISO 9001:2015 clause 8.4, “Control of externally provided processes, products and services,” sets out the requirements for managing procurement to ensure that purchased goods and services meet your quality standards. This guide explains the requirements and gives you a practical framework for supplier control within your QMS.

What Clause 8.4 Covers

Clause 8.4 applies when:

  • You purchase products or services from a supplier that become part of your own product or service.
  • You outsource a process to an external provider.
  • A product or service is provided directly to your customer by an external provider on your behalf.

The clause is divided into three sub-clauses:

  • 8.4.1 – General: Determine the type and extent of control to apply to each external provider.
  • 8.4.2 – Type and extent of control: Define the controls based on the risk and impact of the externally provided items on your QMS.
  • 8.4.3 – Information for external providers: Communicate your requirements clearly to suppliers.

Determining the Type and Extent of Control (8.4.1 / 8.4.2)

ISO 9001 does not require you to treat all suppliers the same. The type and extent of control must be proportionate to the potential impact of the purchased product or service on your ability to consistently deliver conforming products and services to your customers.

Supplier CategoryCriteriaType of ControlExamples
CriticalDirectly affects product quality or safety; difficult to replaceOn-site audits; detailed specifications; incoming inspection; performance scorecardsRaw material supplier for a manufactured product; key component supplier
SignificantModerate impact on quality; available alternatives existSupplier evaluation questionnaire; periodic review; certificate of conformance requiredPackaging supplier; logistics provider
RoutineLow impact on product quality; commoditised itemsApproved supplier list; basic purchase order with specificationOffice supplies; generic consumables

Supplier Evaluation and Selection

Before you place an order, you must evaluate the supplier’s ability to meet your requirements. Evaluation criteria should be objective and documented. Common evaluation methods include:

  • Questionnaires: Send a supplier capability and quality assurance questionnaire.
  • Audits: Conduct on-site quality audits for critical suppliers.
  • Certifications: Review the supplier’s ISO 9001 certificate or other relevant certifications.
  • References and track record: Check references, sample products, or past performance history.
  • Trial orders: Start with a small order to evaluate quality and delivery before committing to larger volumes.

Maintain an approved supplier list (ASL) and ensure that purchases are only placed with suppliers who have been evaluated and approved. The ASL should state the scope of approval (e.g. which products or services the supplier is approved to provide).

Information for External Providers (8.4.3)

Your communications with suppliers must clearly specify what you require. ISO 9001 requires that you communicate, before the purchase, the following information as applicable:

  • Specifications for the product, service, or process to be provided.
  • Approval requirements (e.g. sample approval, first-article inspection).
  • Competence requirements for personnel (e.g. certified welders, qualified inspectors).
  • Interaction and communication requirements (e.g. reporting, contact points).
  • Control and monitoring requirements (e.g. inspection at source).
  • Verification methods (e.g. incoming inspection, certificate of conformance).
  • Handling of nonconformities and corrective actions.
  • QMS or environmental management requirements (e.g. ISO 14001).

The purchase order or contract is the primary tool for communicating these requirements. Ensure your purchase orders include or reference the relevant specifications, acceptance criteria, and delivery terms.

Verification of Purchased Products (8.4.3)

You must verify that purchased products or services meet the specified requirements. The verification method depends on the criticality of the item:

Verification MethodWhen to UseExamples
Certificate of conformance (CoC)Low- to medium-risk items where the supplier has proven reliabilityRaw materials with standard specifications
Incoming inspectionCritical items or when supplier quality history is variableComponent dimensions, visual inspection, material testing
Sampling inspectionHigh-volume purchases where 100% inspection is impracticalBatch sampling per AQL standards
Source inspectionCritical, specialised items where inspection at the supplier’s site is more effectiveLarge custom equipment, high-value assemblies
Customer verificationWhen the customer requires the right to verify purchased items at the supplier’s siteCustomer-specified components in regulated industries

Records of verification must be retained. If verification occurs at the supplier’s premises, your purchase order should state the verification arrangements and the method for releasing the product.

Supplier Monitoring and Re-evaluation

Supplier control does not end with initial approval. You need a process for monitoring supplier performance and re-evaluating them periodically.

Typical performance metrics include:

  • Delivery performance: On-time delivery rate.
  • Quality performance: Defect rate, PPM (parts per million) defective.
  • Nonconformity rate: Number of nonconforming items or service failures.
  • Corrective action responsiveness: Time taken to address quality issues.
  • Cost performance: Price stability and adherence to quoted prices.

Document the re-evaluation frequency (typically annual for critical suppliers, biennial for others) and the criteria for removing a supplier from the approved list. Maintain supplier performance records as part of your QMS documentation.

Nonconforming Purchased Products

When a purchased product or service does not meet requirements, you must take action. Clause 8.7 (Control of nonconforming outputs) applies here. Actions may include:

  • Returning the product to the supplier for replacement.
  • Requesting a credit note.
  • Dispositioning the product for alternative use (where permitted).
  • Initiating a corrective action request (CAR) with the supplier.

Document the nonconformity, the action taken, and the communication with the supplier. Use nonconformity trends as input to supplier re-evaluation decisions.

Outsourced Processes

If you outsource a process that affects product or service conformity (e.g. heat treatment, assembly, testing, or delivery), you must control that process even though it is performed by an external provider. The control should include:

  • Defining the process requirements and acceptance criteria.
  • Specifying competence requirements for the provider’s personnel.
  • Determining how you will verify process outputs.
  • Assessing risks associated with the outsourced process.

Remember: you cannot outsource accountability. If an outsourced process results in a nonconforming product or service, your QMS is responsible.

Documentation and Records

Your QMS must retain documented information related to purchasing and procurement. Key records include:

  • Approved supplier list.
  • Supplier evaluation records.
  • Purchase orders and contracts (including specifications).
  • Verification records (inspection reports, certificates of conformance).
  • Supplier performance monitoring records.
  • Nonconformity and corrective action records related to suppliers.

Frequently Asked Questions

Do I need an approved supplier list in ISO 9001?

ISO 9001 does not explicitly require a document called an “approved supplier list,” but you must determine and apply the criteria for evaluation, selection, and monitoring of external providers. An approved supplier list is the most common and practical way to demonstrate this control. It helps ensure that purchases are only made from evaluated and approved providers.

Can I buy from a supplier who is not on my approved list?

If an urgent need arises and the supplier has not been pre-qualified, you can still purchase, provided you apply an appropriate level of verification. For example, you might perform 100% incoming inspection on the first batch. Document the justification and the verification results. If the supplier performs well, consider adding them to your approved list through the normal evaluation process.

How do I control a single-source supplier I cannot replace?

When a supplier is the only available source, your controls should focus on managing the risk. Increase the frequency of quality audits, tighten incoming inspection, agree on clear specifications and acceptance criteria, and build performance monitoring into the contract. Maintain a contingency plan for alternative sourcing should the relationship fail.

What if my supplier is not ISO 9001 certified?

ISO 9001 does not require your suppliers to be certified. You can qualify them through alternative means: quality questionnaires, audits, product samples, performance history, or third-party test reports. The level of evidence you require should match the risk that the supplier’s product or service poses to your quality.

How often should I re-evaluate suppliers?

The frequency depends on the supplier category. Critical suppliers should be re-evaluated at least annually. Significant suppliers can be evaluated every two years. Routine suppliers can be evaluated less frequently, provided you have a mechanism to track their performance and address issues. Performance issues should trigger an unscheduled re-evaluation regardless of the schedule.

What records must I keep for outsourced processes?

For outsourced processes, retain the contract or agreement that defines the process requirements, records of verification of the process outputs, performance monitoring records, and any nonconformity or corrective action records. You must be able to demonstrate that your control of the outsourced process is equivalent to the control you would apply if the process were performed internally.

How Bitrixme Can Help

Implementing a compliant purchasing and procurement process under ISO 9001 requires careful design of your supplier controls, evaluation methods, and documentation. Bitrixme provides ISO 9001 consulting services across Bahrain and the Middle East, helping organisations build QMS processes that satisfy certification requirements and improve supply chain quality.

We can assist with supplier evaluation criteria design, documentation of purchasing processes, internal auditing of procurement activities, and certification preparation. Our consultants bring practical experience across manufacturing, services, and regulated industries.

Contact Bitrixme today to discuss your ISO 9001 purchasing and procurement requirements. You can also send us a message on WhatsApp for a quick discussion.