ISO 9001 Customer Property: Protection and Management
When a customer entrusts you with their materials, equipment, intellectual property, or data, you are responsible for protecting it. Clause 8.5.3 of ISO 9001:2015 – Property Belonging to Customers or External Providers – sets out exactly what you must do. This article explains the requirement in practical terms, including identification, verification, storage, and reporting.
What Clause 8.5.3 Requires
Clause 8.5.3 states that the organisation must exercise care with property belonging to customers or external providers while it is under the organisation’s control or being used by the organisation. The clause has four distinct obligations:
- Identify – the property must be identifiable so you know what belongs to whom
- Verify – you must check the property upon receipt for condition, quantity, and conformity
- Protect and safeguard – you must store and handle the property appropriately
- Report – if property is lost, damaged, or found unsuitable, you must report it to the customer and maintain records
Types of Customer Property Covered
Customer property is broader than many organisations realise. It includes physical items, intellectual property, and data. The following table gives examples across common industries.
| Category | Manufacturing Example | Service Industry Example | Construction Example |
|---|---|---|---|
| Raw materials | Customer-supplied steel for fabrication | N/A | Client-supplied cement or rebar |
| Tools and equipment | Customer-owned dies and moulds | N/A | Customer-provided surveying equipment |
| Intellectual property | Product designs, CAD files | Brand guidelines, marketing collateral | Architectural drawings, specifications |
| Personal data | Employee records processed on behalf of client | Client lists, medical records, financial data | N/A |
| Finished goods | Customer products held for repackaging | Deliverables awaiting approval | Completed works before handover |
| Packaging and consumables | Customer-supplied packaging | N/A | Client-supplied fixtures |
Identification and Traceability Requirements
Clause 8.5.2 (Identification and Traceability) interacts closely with 8.5.3. Customer property must be uniquely identifiable throughout its lifecycle. The identification method depends on the nature of the property:
- Physical items – use tags, barcodes, or RFID with a unique reference tied to the customer and purchase order
- Digital assets – use filename conventions, metadata, or a document management system that links to the customer project
- Data – use database keys, customer account references, and access control labels
- Intangible property – register IP in a contracts register with customer name, date received, and permitted use
Verification on Receipt
You must verify customer property when it first comes under your control. This should be a documented process with defined acceptance criteria.
| Verification Step | Physical Property | Intellectual Property | Data |
|---|---|---|---|
| Quantity check | Count or weigh against delivery note | Confirm file count and completeness | Confirm record count and fields |
| Condition check | Inspect for damage, rust, expiry | Check file integrity and virus scan | Validate data format and quality |
| Conformity check | Measure against specification | Verify version matches contract | Test sample records for accuracy |
| Documentation check | Cross-reference certificate of analysis | Confirm license or usage rights | Review data processing agreement |
Protection and Storage Requirements
Once verified, customer property must be stored in conditions that prevent deterioration, loss, or damage. Your QMS should define storage requirements for each type:
- Environmental controls – temperature, humidity, and cleanliness for sensitive materials
- Segregation – physically or logically separate customer property from your own stock
- Access control – restrict access to authorised personnel only
- Handling procedures – define lifting, transport, and packaging methods
- Insurance – ensure your coverage matches the value of customer property in your possession
Reporting Damage, Loss, or Unsuitability
If customer property is lost, damaged, or found to be unsuitable for its intended purpose, you must report it to the customer and retain documented information as evidence. The procedure should cover:
- Immediate notification – inform the customer within a defined timeframe (e.g. 24 hours for critical items)
- Formal report – document what happened, the extent of damage, and root cause
- Photographic evidence – attach images for physical property
- Corrective action – raise a non-conformance and corrective action under clause 10.2
- Customer instruction – obtain written instruction on how to proceed (repair, replace, scrap, or continue)
Records Required by Clause 8.5.3
Documented information is mandatory. You must retain evidence that you have identified, verified, protected, and reported on customer property. Minimum records include:
| Record Type | Content | Retention Period |
|---|---|---|
| Receipt verification record | Date, customer name, item description, quantity, condition, inspector name | Duration of contract + 1 year |
| Storage and handling log | Location, environmental readings, handling events, access log | Duration of contract + 1 year |
| Damage/loss report | Date, description, root cause, corrective action, customer acknowledgement | Minimum 3 years |
| Return record | Date returned, condition upon return, customer sign-off | Duration of contract + 1 year |
Frequently Asked Questions
Does customer property include the customer’s intellectual property?
Yes. Designs, specifications, trade secrets, software, and brand assets all fall under clause 8.5.3. You must protect them as rigorously as physical property.
What if a customer does not want damaged property returned?
Obtain written instruction from the customer authorising disposal. Retain that instruction as documented information. Follow your waste management procedure and record the disposal.
Do we need a separate procedure for customer property?
Not necessarily. You can integrate it into your broader operational control procedures (purchasing, storage, production). However, many organisations find a dedicated work instruction helpful for clarity during audits.
How do we apply clause 8.5.3 to customer data processed in the cloud?
Your QMS must address data protection as customer property. Define access controls, encryption requirements, backup frequency, and data handling procedures in your IT service management or information security policy. Cross-reference ISO 27001 controls if your QMS is integrated.
Is clause 8.5.3 audited during ISO 9001 certification?
Yes. External auditors will ask to see your verification records, storage conditions, and any damage reports. It is a commonly raised finding when organisations fail to demonstrate they are tracking customer-supplied items.
What if we subcontract work that involves customer property?
You remain responsible. Your subcontractor management process (clause 8.4) must flow down the same identification, verification, protection, and reporting requirements to your subcontracted partners.
Need help tightening your ISO 9001 customer property controls? Bitrixme’s QMS consultants can review your procedures and prepare you for certification or surveillance audit. Book a free consultation.