Most supplier programs I see during gap assessments have a folder of certificates and not much else. A W-9, a signed quality agreement maybe, a certificate of insurance, and a purchase order history. That is not a supplier qualification program under any ISO standard I know of, and it is one of the fastest ways to draw a major nonconformity in a third-party audit.
Supplier qualification and monitoring is not a filing exercise. It is a live risk control, and ISO standards treat it that way. ISO 9001:2015 clause 8.4 requires you to determine the controls to apply to externally provided processes, products, and services based on their potential effect on conformity. ISO 13485:2016 clause 7.4 goes further for medical devices, requiring documented criteria for supplier evaluation, selection, and reevaluation before you ever place a purchase order. ISO 27001:2022 and ISO 42001:2023 extend the same logic into information security and AI risk, where the supplier might not be shipping you a physical part at all but a dataset, a model, or a cloud service that touches your customers' data.
In my view, the organizations that get this right stopped treating supplier qualification as a procurement task and started treating it as a quality and risk function that procurement happens to execute. That shift in ownership is usually the real fix, more than any template or software.
What Is Supplier Qualification Under ISO Standards?
Supplier qualification is the documented process of evaluating an external provider before you rely on them, using criteria tied to the risk that provider poses to your product, service, or management system. It answers one question before money changes hands: can this supplier consistently meet our requirements, and what happens to us if they don't?
ISO 9001:2015 clause 8.4.1 states the requirement plainly: the organization shall determine and apply criteria for the evaluation, selection, monitoring of performance, and re-evaluation of external providers, based on their ability to provide processes or products in accordance with requirements. That single sentence contains four separate obligations that auditors check independently: evaluation criteria, selection, ongoing monitoring, and periodic re-evaluation. A program that only has the first two is halfway built.
ISO 13485:2016 clause 7.4.1 tightens this considerably for medical device organizations. Suppliers must be evaluated and selected based on their ability to supply product in accordance with the organization's requirements, and the type and extent of control applied to the supplier must be proportionate to the effect of the purchased product on subsequent product realization or the finished device. That proportionality clause is where most of the audit trouble starts, because it means you cannot apply the same qualification depth to a critical component supplier and a janitorial contractor. Regulators expect to see the difference documented.
Which ISO Standards Require Supplier Controls?
Every major management system standard addresses external providers somewhere, but the depth and the language differ enough that a single generic "approved vendor list" rarely satisfies more than one standard at a time.
| ISO Standard | Governing Clause | Core Requirement | Typical Reevaluation Trigger |
|---|---|---|---|
| ISO 9001:2015 | Clause 8.4 | Risk-based criteria for evaluation, selection, monitoring, and re-evaluation of external providers | Scheduled interval, nonconformance trend, or scope change |
| ISO 13485:2016 | Clause 7.4 | Documented supplier evaluation proportionate to product risk; verification of purchased product | Supplier performance data, complaint linkage, or CAPA |
| ISO 14001:2015 | Clause 8.1 | Control or influence over outsourced processes affecting environmental performance | Change in outsourced scope or environmental incident |
| ISO 45001:2018 | Clause 8.1.4 | Procurement controls for contractors and outsourced work affecting worker safety | Incident, near-miss, or contractor safety audit finding |
| ISO 27001:2022 | Annex A 5.19–5.23 | Information security requirements agreed with and monitored in suppliers and their subcontractors | Security incident, access change, or contract renewal |
| ISO 42001:2023 | Annex A.10 | Supplier and third-party obligations for AI components, data sources, and outsourced model development | Model update, data source change, or AI incident |
The pattern across all six is the same: proportionality to risk, documented criteria, and a mechanism for re-checking the decision over time. What changes is what "risk" means in each context. Under 13485 it is patient safety. Under 45001 it is worker safety. Under 42001 it is the integrity, provenance, and bias profile of the data or model your supplier is handing you.
How to Build a Risk-Based Supplier Qualification Program
A defensible program has four layers, and skipping any one of them is the most common reason I find gaps in an audit.
First, tier your suppliers by risk, not by spend. A supplier that costs you very little but supplies a component that goes directly into a finished device or feeds training data into a customer-facing model deserves more scrutiny than a high-dollar supplier of office furniture. ISO 13485 explicitly requires this proportionality; ISO 9001 implies it through the phrase "potential impact on the organization's ability to consistently meet requirements." Build three tiers at minimum: critical, moderate, and low risk, and define what moves a supplier between tiers.
Second, set qualification criteria before you evaluate anyone. Common criteria include quality certifications held, on-site or remote audit results, sample or pilot lot performance, financial stability, regulatory standing (FDA registration, import alerts, warning letters), and for AI-related suppliers, data lineage and model documentation. Write the criteria down. An auditor will ask to see the criteria that existed before the supplier was approved, not criteria you reconstructed afterward to justify the decision.
Third, qualify before you rely, not after. I have seen organizations issue a purchase order, receive product, and only then start the supplier qualification file. That sequence inverts the entire purpose of clause 8.4 and is an easy nonconformity to write. The qualification decision has to precede reliance on the supplier for anything that reaches the customer.
Fourth, build monitoring into the relationship, not just the file. Incoming inspection results, on-time delivery, complaint and CAPA linkage, corrective action responsiveness, and recertification status all belong in a supplier scorecard that gets reviewed on a cadence, not just when something goes wrong.
How Often Should You Monitor and Requalify Suppliers?
ISO standards deliberately do not mandate a fixed interval, and I think that is the right call, because a fixed interval invites organizations to treat requalification as a calendar event instead of a risk response. That said, most mature quality systems I have reviewed settle on an annual review for critical suppliers, tied to a scorecard that pulls incoming inspection rejection rates, on-time delivery, and any CAPA or complaint linkage over the prior twelve months. Moderate-risk suppliers commonly get reviewed every eighteen to twenty-four months, and low-risk suppliers get a lighter-touch review, sometimes just a certificate and registration check, every two to three years.
The trigger-based approach matters more than the calendar approach. A single critical nonconformance, a customer complaint traced to a supplier's material, a change in a supplier's manufacturing site, or a lapsed certification should all pull a requalification forward regardless of where it sits on the schedule. Auditors specifically look for evidence that your monitoring data actually feeds a decision. A scorecard nobody reads is functionally the same as no scorecard.
Industry data backs up why this matters. The FDA has repeatedly identified purchasing controls and supplier evaluation among the most frequently cited deficiencies in 21 CFR 820 inspections of device manufacturers, and a weak supplier program is one of the most common root causes traced back through device-related CAPAs. The ISO Survey of Certifications has recorded more than 1.26 million active ISO 9001 certificates worldwide in recent years, which means well over a million organizations are formally on the hook for a documented clause 8.4 supplier evaluation process, whether their current program actually reflects that or not.
Common Supplier Qualification Findings in ISO Audits
Certain findings show up so often they are almost predictable. Approved vendor lists that include suppliers with no documented qualification rationale. Reevaluation dates that have quietly slipped past their own defined interval with no risk justification for the delay. Supplier agreements that never got updated after a standard's revision, so a 27001-certified cloud vendor is operating under a contract written before the 2022 Annex A control renumbering. Incoming inspection data that gets collected but never rolls up into the supplier's periodic review. And, increasingly, AI and software suppliers evaluated using a hardware-and-materials checklist that never asks about data provenance, model version control, or algorithmic bias testing.
That last one is where I have been spending most of my client time lately, because it is where the standards themselves are still catching up to the risk.
Supplier Qualification for AI Systems Under ISO 42001
ISO 42001:2023 is the first management system standard built specifically for AI, and its Annex A.10 control set on third-party and customer relationships extends supplier qualification into territory that 9001 and 13485 were never written to cover. If your organization licenses a foundation model, buys training data, or outsources model fine-tuning, that vendor is a supplier under 42001 in exactly the same sense a raw material vendor is a supplier under 13485. The obligations flow down: you need visibility into how the vendor sources and governs its training data, what testing it performs for bias and robustness, how it handles model updates and versioning, and what happens to your data once it enters their pipeline.
I have come to think this is the area where organizations are most exposed right now, because most procurement teams still evaluate AI vendors the way they evaluate a software-as-a-service tool: security questionnaire, SOC 2 report, done. That approach misses the questions 42001 actually requires you to be able to answer, including what training data underlies the model, whether the vendor has a documented AI risk management process of its own, and how model behavior changes get communicated to you before they hit production. A vendor who cannot answer those questions is not disqualified automatically, but the gap has to be documented as a risk you accepted, not a question nobody asked.
If your organization is building or updating an AI governance program, our ISO 42001 AI management system readiness work walks through exactly how supplier and third-party controls fit into the broader AIMS, alongside the rest of the clause 6 risk treatment plan.
Building the Documentation That Survives an Audit
Auditors are not grading your supplier relationships. They are grading your evidence. Three documents tend to make or break a supplier qualification audit finding: the supplier risk tiering rationale, the qualification record showing criteria applied before reliance began, and the monitoring log showing the data actually gets reviewed on the schedule you committed to. If those three exist and are internally consistent, most other gaps are minor. If any one is missing, expect a finding regardless of how good the supplier relationship actually is in practice.
I would rather see a smaller, simpler program that is followed exactly than an elaborate one that exists mostly on paper. A one-page risk tiering matrix, a two-page qualification checklist per tier, and a quarterly scorecard review meeting will pass an audit that a two-hundred-page supplier quality manual with no evidence of use will not.
For organizations that need a structured, outside look at where their current supplier program stands against clause 8.4 or clause 7.4 expectations, our supplier qualification and audit program is built around exactly this gap: closing it with documentation and process, not just paperwork.
Frequently Asked Questions
What is the difference between supplier qualification and supplier monitoring?
Qualification is the upfront decision to approve a supplier, based on documented criteria applied before you rely on them. Monitoring is the ongoing collection and review of performance data, such as incoming inspection results and complaint linkage, that determines whether the qualification decision still holds. ISO 9001 clause 8.4 requires both, and treats them as continuous rather than one-time activities.
Does ISO 13485 require on-site supplier audits?
Not automatically. ISO 13485:2016 clause 7.4 requires the type and extent of control to be proportionate to the effect of the purchased product on the finished device. For critical suppliers, that proportionality often justifies an on-site audit, but for lower-risk suppliers, a documentation review or certificate verification can satisfy the requirement if it is properly justified in your risk rationale.
How often should a critical supplier be reevaluated under ISO 9001?
ISO 9001 does not set a fixed interval. Most mature quality systems reevaluate critical suppliers annually and pull that timeline forward immediately after any major nonconformance, customer complaint, or change in the supplier's process or site. The interval should be justified by risk, not chosen arbitrarily.
What supplier obligations does ISO 42001 add for AI vendors?
ISO 42001 Annex A.10 requires organizations to flow AI-specific requirements down to suppliers of data, models, and AI components, including visibility into training data provenance, bias and robustness testing, and how model version changes are communicated before deployment. This goes well beyond a standard security questionnaire.
What happens if a supplier fails requalification?
The standards require a documented response, not a specific outcome. That can mean increased monitoring, a supplier corrective action request, reduced scope of what the supplier is approved to provide, or removal from the approved supplier list entirely. What auditors check is whether the failure triggered a documented, risk-based decision rather than being quietly carried forward.
Last updated: 2026-08-09
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.