How to manage suppliers under ISO 13485
ISO 13485:2016 · Clause 7.4 — purchasing controls and supplier governance
Quick answer
Clause 7.4 requires documented supplier evaluation, approval, monitoring, and purchasing controls proportionate to the risk the supplier presents to product quality and patient safety. Every organisation needs an approved supplier list (ASL), and quality agreements are required for suppliers performing regulated activities.
7.4.1 — The purchasing process
The purchasing process must ensure that externally provided products and services conform to specified requirements. The extent of supplier controls must be proportionate to the risk associated with the purchased product or service and the degree to which it affects the finished device's conformity. This risk-based approach means critical component suppliers receive more rigorous oversight than commodity suppliers of non-critical office supplies.
All approved suppliers must be listed on an Approved Supplier List (ASL) — a controlled document identifying the supplier, the products or services they are approved to provide, and the approval status. New suppliers must be evaluated and approved before purchase orders are placed.
Risk-based supplier classification
Most organisations classify suppliers into tiers based on the impact a supplier failure would have on device safety and performance:
| Classification | Description | Examples | Typical controls |
|---|---|---|---|
| Critical | Directly affects safety or performance of the finished device | Sterilisation service, ASIC manufacturer, clinical CRO, contract manufacturer | On-site audit, quality agreement, incoming inspection or CoC review, annual re-evaluation |
| Major | Significant component or service affecting product quality | Packaging supplier, PCB assembly, calibration service | Questionnaire assessment, quality agreement, CoC review, biennial re-evaluation |
| Minor | Low-risk commodity items or services with no direct quality impact | Office supplies, cleaning products, general IT services | Basic approval, spot-check monitoring, periodic re-evaluation |
7.4.2 — Purchasing information
Purchase orders (POs) must describe the product or service being purchased with sufficient clarity to ensure the supplier understands what is required. For regulated products this includes: product specifications or drawing revisions, applicable regulatory or quality requirements to flow down to the supplier, and any required approvals (e.g., first article inspection approval). Regulatory flow-down is particularly important — if your device must meet EU MDR requirements, relevant obligations must flow to contract manufacturers and critical suppliers through POs or quality agreements.
7.4.3 — Verification of purchased product
After receipt, purchased products must be verified to confirm they meet requirements. The method of verification must be risk-proportionate:
- Incoming inspection: Physical or dimensional inspection of received goods against specifications
- Certificate of Conformance (CoC) review: Supplier-provided documentation confirming conformity — acceptable for lower-risk items
- Test reports: Independent or supplier test data reviewed against acceptance criteria
- Supplier audits: On-site assessment of the supplier's processes — required for critical suppliers
Quality agreements
For suppliers who perform regulated activities on your behalf (contract manufacturing, sterilisation, testing laboratories, software development under IEC 62304), a Quality Agreement is required. A quality agreement is a binding contract that allocates responsibilities between your organisation and the supplier. Key clauses to include:
- Scope of the agreement and regulated activities covered
- Quality requirements and applicable standards
- Change notification obligations (the supplier must notify you before making changes to processes, materials, or facilities)
- Document and record control arrangements
- Your right to audit the supplier's facilities and records
- Nonconformance and CAPA escalation procedures
- Confidentiality provisions
Supplier audits vs questionnaires vs certifications
Choosing the right evaluation method depends on supplier criticality and available resources:
- On-site audit: Most thorough — required for critical suppliers. Allows review of actual processes, records, and facilities. Plan 1–2 days on-site per critical supplier.
- Remote/virtual audit: Increasingly accepted post-pandemic. Requires document sharing and video walk-throughs. Suitable for major suppliers.
- Questionnaire: Self-assessment by supplier. Lower resource requirement but relies on honesty. Suitable as initial screening or for minor suppliers.
- Third-party certification review: If supplier holds ISO 13485 or ISO 9001 certification from an accredited body, this provides evidence of QMS compliance. Review the certificate scope to confirm it covers the relevant activities.
MDSAP supplier expectations
Under the MDSAP audit model, auditors pay particular attention to how manufacturers control outsourced processes and manage their supply chain. Expect auditors to review your ASL, quality agreements, and supplier monitoring records. MDSAP auditors verify that risk-based classification is documented and that monitoring activities match the supplier's criticality level.
Post-market supplier monitoring
Supplier management does not end at initial approval. Ongoing monitoring includes: reviewing complaints and field CAPAs for supplier-related failures, tracking supplier performance KPIs (on-time delivery, CoC compliance, nonconformance rates), conducting periodic re-evaluations (annually for critical suppliers), and acting on changes suppliers notify you of. Post-market data from your PMS process is a key input to supplier re-evaluation decisions.
Supplier scorecard example
| Criterion | Weight | Rating method |
|---|---|---|
| Quality (CoC accuracy, incoming inspection failures) | 35% | % conforming lots per quarter |
| Delivery (on-time performance) | 25% | % orders delivered on schedule |
| Responsiveness (CAPA closure, query response time) | 20% | Days to close NCRs |
| Compliance (audit score, regulatory status) | 20% | Audit score out of 100 |