Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

ISO 13485 purchasing and supplier controls

ISO 13485 Purchasing: A Clear Guide to Clause 7.4

ISO 13485 purchasing is where a medical device manufacturer’s quality system meets everybody else’s. Clause 7.4 makes you responsible for what your suppliers do — their evaluation, the information you give them, and the verification of what arrives — and it scales all three to the risk the purchased product carries into the finished device.

This guide covers the three parts of clause 7.4, the written agreement that catches most organizations out, and how to make supplier controls proportionate without making them meaningless.

ISO 13485 purchasing: the three parts of clause 7.4 and what each produces
Three sub-clauses, each scaled to the risk the purchased product carries.

The three parts of ISO 13485 purchasing

Sub-clause Requirement Records it produces
7.4.1 Purchasing process Criteria for evaluating and selecting suppliers, monitoring and re-evaluating them, proportionate to the effect on the device Approved supplier list, evaluation records, performance monitoring, re-evaluation
7.4.2 Purchasing information What you specify to the supplier — product, acceptance requirements, personnel qualification, quality system requirements Specifications, drawings, purchase orders and the change-notification agreement
7.4.3 Verification of purchased product Checks that what arrived meets the specification, with extent based on the supplier evaluation and the risk Goods-in inspection, certificates of analysis, test records, nonconformity records

The clause that catches people out

7.4.2 expects the purchasing information to include, so far as practicable, a written agreement that the supplier will notify you of changes to the purchased product before they are implemented. That single sentence is the difference between a controlled supply chain and a surprise.

Suppliers change resin grades, move a moulding tool to a second site, requalify a sub-supplier, or update firmware — all reasonable business decisions, none of which they will mention unless the contract says they must. For a device manufacturer, any of those can invalidate a validation, a biocompatibility position or a design verification. Get the notification clause into the agreement, and keep a record of the agreements you hold.

Making ISO 13485 purchasing controls proportionate

ISO 13485 purchasing scales the control to the effect of the purchased product on the medical device. In practice that means banding suppliers and applying a defined level of control to each band, rather than treating a sterile-barrier supplier and an office stationery vendor identically.

A workable three-band approach:

  • Critical — product-contacting materials, sterile barrier, active components, sterilization services, contract manufacturing, and any process you cannot fully verify on receipt. Full evaluation including audit, quality agreement, change notification, and verification on every lot until performance justifies otherwise.
  • Significant — components with a defined specification you can verify, calibration services, key logistics. Documented evaluation, agreed specifications, sampling on receipt, periodic performance review.
  • Standard — items with no effect on device conformity. Basic approval and monitoring, and the reasoning recorded once rather than per purchase.

Write the banding criteria down and apply them consistently. The audit finding is almost never “your banding is wrong”; it is that no criteria exist and the bands were assigned by whoever set up the vendor record.

Outsourced processes are not ordinary purchases

Where you outsource a process that affects product conformity — sterilization, contract manufacturing, some testing — the standard expects a quality agreement setting out the responsibilities of each party. Treat this as a distinct document rather than terms on a purchase order, because a regulator or notified body will ask which party is responsible for which control, and an inconsistent answer between you and your supplier is a finding on both sides.

Where ISO 13485 purchasing meets everything else

ISO 13485 purchasing does not stand alone, and the connections are where audits go badly:

  1. Risk management. Supplier banding should follow the device risk analysis, not procurement’s spend categories. A cheap component in a critical function is a critical supplier.
  2. Traceability. If you cannot trace a received lot to the devices it went into, a supplier nonconformity becomes an unbounded recall rather than a bounded one.
  3. CAPA. Recurring supplier nonconformities are a corrective action trigger, not a receiving problem to be dispositioned lot by lot.
  4. Design transfer. Specifications sent to suppliers must match the design output. Purchasing information drifting from the design file is a common and serious finding.

Our guides to ISO 13485 risk management and the mandatory documents cover those neighbours.

Frequently asked questions

Does ISO 13485 require supplier audits?
It requires evaluation and selection criteria proportionate to the effect on the device. For critical suppliers an audit is usually the only credible evidence; for standard items it would be disproportionate.

What has to be in the purchasing information?
The product requirements, acceptance requirements, requirements for personnel qualification and for the supplier’s quality system where applicable — and, so far as practicable, the agreement that the supplier notifies you of changes before implementing them.

Can we accept certificates of conformity instead of testing?
Yes, where the supplier evaluation supports it and the risk is understood. The extent of verification follows the evaluation, so the justification has to exist somewhere.

Do we need a quality agreement with every supplier?
No — with those performing outsourced processes affecting conformity, and with critical suppliers where responsibilities need to be explicit. For standard items it is overhead.

How often should suppliers be re-evaluated?
On a defined cycle by band, and on trigger: a nonconformity, a change notification, a site move, or an ownership change.

Where this leaves you

Treat ISO 13485 purchasing as three linked obligations rather than an approved-vendor list. Band suppliers using criteria derived from device risk, write the change-notification agreement into the purchasing information for anything that could invalidate a validation, and set verification depth from the evaluation rather than from habit. Then connect the outputs — nonconformities into CAPA, lots into traceability, specifications back to the design file — because that is where a notified body will test whether the process is real.

References

  • ISO 13485:2016 — Medical devices, quality management systems, requirements for regulatory purposes.
  • 21 CFR Part 820 — the US quality system regulation whose purchasing controls the same suppliers have to satisfy.

More on medical device quality

Supplier evaluation records, quality agreements and goods-in templates are in the ISO 13485 Documentation Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.