iso-9001-customer-property

By July 25th, 2026compliant-growth5 min read

ISO 9001 Customer Property: Protection and Management

When a customer entrusts you with their materials, equipment, intellectual property, or data, you are responsible for protecting it. Clause 8.5.3 of ISO 9001:2015 – Property Belonging to Customers or External Providers – sets out exactly what you must do. This article explains the requirement in practical terms, including identification, verification, storage, and reporting.

What Clause 8.5.3 Requires

Clause 8.5.3 states that the organisation must exercise care with property belonging to customers or external providers while it is under the organisation’s control or being used by the organisation. The clause has four distinct obligations:

  • Identify – the property must be identifiable so you know what belongs to whom
  • Verify – you must check the property upon receipt for condition, quantity, and conformity
  • Protect and safeguard – you must store and handle the property appropriately
  • Report – if property is lost, damaged, or found unsuitable, you must report it to the customer and maintain records

Types of Customer Property Covered

Customer property is broader than many organisations realise. It includes physical items, intellectual property, and data. The following table gives examples across common industries.

CategoryManufacturing ExampleService Industry ExampleConstruction Example
Raw materialsCustomer-supplied steel for fabricationN/AClient-supplied cement or rebar
Tools and equipmentCustomer-owned dies and mouldsN/ACustomer-provided surveying equipment
Intellectual propertyProduct designs, CAD filesBrand guidelines, marketing collateralArchitectural drawings, specifications
Personal dataEmployee records processed on behalf of clientClient lists, medical records, financial dataN/A
Finished goodsCustomer products held for repackagingDeliverables awaiting approvalCompleted works before handover
Packaging and consumablesCustomer-supplied packagingN/AClient-supplied fixtures

Identification and Traceability Requirements

Clause 8.5.2 (Identification and Traceability) interacts closely with 8.5.3. Customer property must be uniquely identifiable throughout its lifecycle. The identification method depends on the nature of the property:

  • Physical items – use tags, barcodes, or RFID with a unique reference tied to the customer and purchase order
  • Digital assets – use filename conventions, metadata, or a document management system that links to the customer project
  • Data – use database keys, customer account references, and access control labels
  • Intangible property – register IP in a contracts register with customer name, date received, and permitted use

Verification on Receipt

You must verify customer property when it first comes under your control. This should be a documented process with defined acceptance criteria.

Verification StepPhysical PropertyIntellectual PropertyData
Quantity checkCount or weigh against delivery noteConfirm file count and completenessConfirm record count and fields
Condition checkInspect for damage, rust, expiryCheck file integrity and virus scanValidate data format and quality
Conformity checkMeasure against specificationVerify version matches contractTest sample records for accuracy
Documentation checkCross-reference certificate of analysisConfirm license or usage rightsReview data processing agreement

Protection and Storage Requirements

Once verified, customer property must be stored in conditions that prevent deterioration, loss, or damage. Your QMS should define storage requirements for each type:

  • Environmental controls – temperature, humidity, and cleanliness for sensitive materials
  • Segregation – physically or logically separate customer property from your own stock
  • Access control – restrict access to authorised personnel only
  • Handling procedures – define lifting, transport, and packaging methods
  • Insurance – ensure your coverage matches the value of customer property in your possession

Reporting Damage, Loss, or Unsuitability

If customer property is lost, damaged, or found to be unsuitable for its intended purpose, you must report it to the customer and retain documented information as evidence. The procedure should cover:

  • Immediate notification – inform the customer within a defined timeframe (e.g. 24 hours for critical items)
  • Formal report – document what happened, the extent of damage, and root cause
  • Photographic evidence – attach images for physical property
  • Corrective action – raise a non-conformance and corrective action under clause 10.2
  • Customer instruction – obtain written instruction on how to proceed (repair, replace, scrap, or continue)

Records Required by Clause 8.5.3

Documented information is mandatory. You must retain evidence that you have identified, verified, protected, and reported on customer property. Minimum records include:

Record TypeContentRetention Period
Receipt verification recordDate, customer name, item description, quantity, condition, inspector nameDuration of contract + 1 year
Storage and handling logLocation, environmental readings, handling events, access logDuration of contract + 1 year
Damage/loss reportDate, description, root cause, corrective action, customer acknowledgementMinimum 3 years
Return recordDate returned, condition upon return, customer sign-offDuration of contract + 1 year

Frequently Asked Questions

Does customer property include the customer’s intellectual property?

Yes. Designs, specifications, trade secrets, software, and brand assets all fall under clause 8.5.3. You must protect them as rigorously as physical property.

What if a customer does not want damaged property returned?

Obtain written instruction from the customer authorising disposal. Retain that instruction as documented information. Follow your waste management procedure and record the disposal.

Do we need a separate procedure for customer property?

Not necessarily. You can integrate it into your broader operational control procedures (purchasing, storage, production). However, many organisations find a dedicated work instruction helpful for clarity during audits.

How do we apply clause 8.5.3 to customer data processed in the cloud?

Your QMS must address data protection as customer property. Define access controls, encryption requirements, backup frequency, and data handling procedures in your IT service management or information security policy. Cross-reference ISO 27001 controls if your QMS is integrated.

Is clause 8.5.3 audited during ISO 9001 certification?

Yes. External auditors will ask to see your verification records, storage conditions, and any damage reports. It is a commonly raised finding when organisations fail to demonstrate they are tracking customer-supplied items.

What if we subcontract work that involves customer property?

You remain responsible. Your subcontractor management process (clause 8.4) must flow down the same identification, verification, protection, and reporting requirements to your subcontracted partners.


Need help tightening your ISO 9001 customer property controls? Bitrixme’s QMS consultants can review your procedures and prepare you for certification or surveillance audit. Book a free consultation.