Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

External providers under ISO 9001 clause 8.4

External Providers: A Clear Guide to ISO 9001 Clause 8.4

External providers are what ISO 9001 calls suppliers, and clause 8.4 is the part of the standard most organizations under-implement. It covers everything supplied from outside — products, services, and processes you have outsourced — and it asks three questions: how did you choose them, how much control do you apply, and what did you tell them.

This guide covers the three sub-clauses, how to set the type and extent of control without treating every vendor identically, and the outsourced-process trap that produces findings.

ISO 9001 clause 8.4: the three requirements for control of external providers
Three sub-clauses: choose them, control them, tell them.

What clause 8.4 covers

Clause 8.4 covers external providers in three situations, and the third is the one people forget:

  • Products and services incorporated into your own. Components, materials, software, subassemblies.
  • Products and services provided directly to your customer on your behalf. Drop-shipping, subcontracted installation, field service by a partner.
  • Processes or parts of processes you have outsourced. Anything you used to do or could do yourself, now performed by somebody else — payroll is not it, but heat treatment, calibration, contract manufacturing, hosting and outsourced customer support all are.

Outsourcing a process does not outsource responsibility for it. The process remains inside your quality management system and must be controlled — that principle is what the third bullet exists to enforce.

The three sub-clauses on external providers

Sub-clause What it asks for Evidence
8.4.1 General Criteria for evaluation, selection, monitoring of performance and re-evaluation, based on ability to meet requirements Approved provider list, evaluation records, performance data, re-evaluation records
8.4.2 Type and extent of control Control proportionate to the effect on conformity and on the customer; verification activities defined Control banding, inspection and verification records, audit reports
8.4.3 Information for external providers What you communicate: requirements for the product or service, approval, competence, interactions, control and monitoring, and verification at their premises Specifications, purchase orders, agreements, communicated requirements

8.4.3 is the cheapest clause to satisfy and the most commonly failed. It requires you to ensure requirements are adequate before communicating them — which means somebody checks the purchase order before it goes out, and that check leaves a trace.

Setting the type and extent of control over external providers

The standard scales control over external providers by the effect on conformity, so a single supplier procedure applied to everyone is either wasteful or inadequate. Band providers on two axes — effect on product or service conformity, and the ease of detecting a problem after the fact:

  • High effect, hard to detect — special processes, contract manufacture, calibration, outsourced design. Approval before use, defined competence requirements, audits or on-site verification, and process evidence rather than end-item inspection.
  • High effect, easy to detect — components with measurable characteristics. Specification, receiving verification, performance monitoring.
  • Low effect — indirect goods and services. Simple approval, and a recorded rationale so the exclusion is deliberate rather than an oversight.

Write the banding criteria into the procedure and apply them at onboarding. Auditors rarely challenge the bands themselves; they challenge the absence of criteria and the vendor sitting in the wrong one because nobody re-evaluated after a quality problem.

Monitoring that is actually monitoring

Clause 8.4.1 asks for performance monitoring, not an annual survey. The measures that work are the ones you already generate: on-time delivery, quality acceptance rate, nonconformities raised, response time on issues, and the cost of poor quality attributable to that provider. Set thresholds, review on a cadence, and record the decision when a threshold is breached — including the decision to keep using them, which is a legitimate outcome if somebody owns it.

Where clause 8.4 findings come from

  1. Outsourced processes never identified. The organization lists suppliers of goods but has not recognized that hosting, calibration or a subcontracted service is an outsourced process inside its QMS.
  2. Criteria that exist only as a form. An approval form with tick boxes and no stated criteria is not evaluation against ability to meet requirements.
  3. No re-evaluation. Providers approved in 2019 and never revisited, including ones that have since moved sites or changed ownership.
  4. Requirements not communicated. A purchase order with a part number and no revision, no acceptance criteria and no reference to the specification.
  5. Performance data nobody reviews. The ERP holds delivery and reject data; the management review contains none of it.

Our guides to clause 8 operation and the ISO 9001 mandatory documents cover the surrounding requirements.

Frequently asked questions

Does ISO 9001 require an approved supplier list?
It requires criteria and records for evaluation, selection, monitoring and re-evaluation. A list is how most organizations hold that, but the list without the criteria and records satisfies nothing.

Are outsourced processes covered by clause 8.4?
Yes, explicitly. They remain within your quality management system and the type and extent of control has to be defined.

Do we have to audit our suppliers?
Not universally. Audit is one form of control, appropriate where the effect on conformity is high and verification after the fact is impractical.

How often should we re-evaluate?
On a defined cycle by band, and on trigger — a nonconformity, a site or ownership change, or a change in what they supply.

What if a customer mandates a provider?
You still control the interface: define requirements, verify what arrives and monitor performance. A customer-directed source changes the selection decision, not your responsibility for conformity.

Where this leaves you

Work clause 8.4 in its own order. List every external provider including outsourced processes, band them by effect on conformity and detectability, write the criteria down, and make sure purchase information carries the revision and acceptance requirements before it leaves the building. Then feed real performance data into the review and record the decision when a provider misses the threshold — that record is the difference between a controlled supply base and an approved-vendor list nobody has revisited since it was created.

References

More on ISO 9001

Supplier evaluation criteria, purchase-information templates and performance review records are in the ISO 9001 Quality Management Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.