Supplier Controls for Medical Devices: ISO 13485 Requirements Explained (2026)

ISO 13485 supplier controls are among the most audited requirements in medical device QMS certifications. This guide covers Section 7.4 — evaluation criteria, purchasing document requirements, incoming inspection, re-evaluation, and the common audit findings that derail supplier programs before Stage 2.

How to build a compliant supplier qualification and monitoring program that holds up under notified body scrutiny

Affiliate Disclosure: Some links in this article are affiliate links. If you purchase through them, The Standards Navigator may earn a commission at no additional cost to you.


Your Supplier Is Now Your Risk — and Your Auditor Knows It

Supplier nonconformances are among the top findings in ISO 13485 audits. Not because manufacturers don’t care about their supply chain — but because most supplier controls for medical devices are built for appearance rather than function. They look complete on paper. They fall apart under scrutiny.

When a notified body or FDA investigator walks into your facility, they aren’t just looking at what happens on your production floor. They’re asking who made your components, how you selected them, what evidence you have that they’re capable, and what happens when they fail to deliver compliant product.

If your answers are “we have an approved vendor list” and “we send them a purchase order with our spec,” you’re in trouble.

I’ve audited supplier programs for a global manufacturer of many different types of valves and the gaps I found most often had nothing to do with the suppliers themselves. They had to do with how the manufacturer defined their requirements, communicated them, and verified compliance after the fact. A supplier can’t meet a requirement you never clearly documented. That’s your problem, not theirs, and it shows up in your audit findings.

Before you work through your supplier qualification process, run your current program through the ISO 13485 gap assessment checklist first.

👉 Download the ISO 13485 Gap Assessment Checklist → — free checklist for medical device manufacturers assessing their QMS against ISO 13485:2016 requirements, including supplier control clauses.


In This Guide

  • What ISO 13485 Section 7.4 actually requires for supplier controls
  • How to build a compliant supplier qualification and evaluation process
  • What your purchasing documents must include under 7.4.2
  • Verification of purchased product — incoming inspection and beyond
  • Common audit findings in supplier control programs
  • How supplier controls tie into your risk management process under ISO 14971
  • A quick audit checklist for your supplier control program


👉 Start Here: Top Resources for ISO 13485 Supplier Controls


What ISO 13485 Section 7.4 Requires

ISO 13485:2016 addresses purchasing and supplier controls in Section 7.4, which breaks into three requirements:

  • 7.4.1 — Purchasing process: You must establish criteria for evaluating, selecting, and monitoring suppliers. The criteria must be based on the supplier’s ability to meet your requirements. Records of evaluation results must be maintained.
  • 7.4.2 — Purchasing information: Purchasing documents must clearly describe the product or service being ordered, including applicable specifications, procedures, or quality system requirements you’re flowing down.
  • 7.4.3 — Verification of purchased product: You must establish and implement the inspection or other activities necessary to verify that purchased product meets requirements.

This is not a checkbox exercise. The standard requires documented procedures, records, and evidence that your program actually functions — not just that it exists.

One important distinction from ISO 9001: ISO 13485 is more prescriptive about what supplier evaluation must cover and what records must be maintained. If you’re coming from an ISO 9001 background, expect your notified body to go deeper on supplier documentation than you may be used to.

For a full comparison of how supplier control requirements differ between the two standards, see: ISO 9001 vs ISO 13485


Supplier Qualification: How to Evaluate and Approve Suppliers

Supplier controls for medical devices infographic showing a risk-based supplier evaluation framework, Approved Supplier List process, regulatory review, technical capability assessment, and periodic supplier re-evaluation for medical device manufacturers.
ISO 13485 supplier approval requires documented evaluation, risk classification, qualification records, and ongoing supplier monitoring before suppliers remain on the Approved Supplier List.

Your Approved Supplier List (ASL) is the foundation of your supplier control program. But the list itself isn’t the requirement — the process that populates and maintains it is.

Supplier Evaluation Criteria

Your procedure must define how you evaluate a new supplier before adding them to your ASL. At minimum, this should include:

Evaluation CategoryWhat to AssessEvidence Required
Quality systemISO 13485, ISO 9001, or equivalent QMSCertificate, audit report, questionnaire
Regulatory complianceFDA registration, CE marking, applicable regulationsRegulatory filings, declarations
Technical capabilityAbility to meet your specification requirementsCapability studies, sample approval
Delivery and financial stabilityRisk to supply continuityReferences, business history
Product/service risk classificationImpact on device safety and performanceRisk assessment (see Section 7 below)

Not every supplier gets the same level of scrutiny. A supplier providing sterile packaging components gets evaluated differently than a supplier providing cardboard shipping boxes. Your procedure must define those tiers — and the evaluation rigor that goes with each.

Most common finding: Approved Supplier Lists that include suppliers with no documented evaluation on file. The vendor was added years ago, the person who approved them is gone, and there’s no record of what they were evaluated on.


Purchasing Controls: What Your POs and Specs Must Cover

Section 7.4.2 is where many organizations have significant gaps. Purchase orders and specifications must be clear enough that a supplier knows exactly what’s expected — and clear enough that you can verify compliance on receipt.

What Purchasing Documents Must Include

At minimum, your purchasing documents should specify:

  • Product description, part number, and revision level
  • Applicable specifications (dimensional, material, performance)
  • Quality requirements you’re flowing down (e.g., certificate of conformance, first article inspection, CAPA notification requirements)
  • Any regulatory or standards requirements the supplier must meet
  • Change notification requirements — the supplier must tell you before they change anything that affects your product
ISO 13485 purchasing controls infographic comparing a weak purchase order to an audit-ready controlled purchasing package with specifications, quality requirements, and verification controls.
ISO 13485 purchasing documents must define specifications, quality flow-down requirements, and verification expectations to support compliant supplier controls.

That last point is critical and frequently missed. Supplier-initiated changes — new sub-tier suppliers, process changes, facility moves, material substitutions — must not reach your production floor without your review and approval. If your purchase order doesn’t require the supplier to notify you of changes, you have no contractual basis to enforce it.

If your purchasing documents and quality flow-downs aren’t documented in a controlled procedure, your QMS documentation requirements aren’t complete. See: ISO 13485 Documentation Requirements


Most teams don’t discover their purchasing document gaps until a notified body auditor requests three supplier files during a Stage 2 audit. Run the gap check now, while you still have time to fix it.

👉 Download the ISO 13485 Gap Assessment Checklist →


Verification of Purchased Product

Section 7.4.3 requires you to verify that purchased product meets requirements before it enters your production process. What that looks like depends on the product, the supplier, and the risk level involved.

Incoming Inspection Options

Verification MethodWhen to UseWhat to Document
100% incoming inspectionHigh-risk components, new suppliers, history of nonconformancesInspection records, acceptance/rejection criteria
Statistical samplingEstablished suppliers, lower-risk componentsSampling plan (AQL level), records of results
Certificate of conformance reviewEstablished, well-performing suppliersCOC receipt record, periodic verification
Supplier data reviewHigh-confidence qualified suppliers onlyData review records, approval basis
Skip-lot inspectionExtended high-performance track recordDefined criteria for skip-lot qualification

Your incoming inspection procedure must define the method for each supplier or product category — and your records must show you actually performed it.

What Auditors Look For

Auditors will ask to see incoming inspection records for specific lots. They will cross-reference the purchase order revision, the inspection criteria in your procedure, and the actual record. Discrepancies between any of these three are nonconformances.

They will also ask: what happens when incoming inspection finds a nonconformance? Your CAPA process must connect directly to your incoming inspection findings.

For how CAPA integrates with supplier nonconformances, see: CAPA Requirements in ISO 13485


Ongoing Supplier Monitoring and Re-Evaluation

Qualifying a supplier once is not enough. ISO 13485 requires ongoing monitoring and periodic re-evaluation of your suppliers.

What Ongoing Monitoring Looks Like

Your procedure should define what data you collect and at what frequency to assess supplier performance. Common metrics include:

  • Incoming acceptance rate — percentage of lots accepted without rejection
  • On-time delivery rate — consistently late suppliers are a supply risk
  • Nonconformance rate — corrective action requests issued per time period
  • Customer complaints attributable to supplied components
  • CAPA closure rate — how quickly suppliers respond to and close corrective actions you’ve issued

Re-Evaluation Requirements

Most organizations set an annual re-evaluation cycle. At re-evaluation, you’re reviewing the supplier’s performance data, confirming their certification is still valid, and deciding whether they remain on the ASL — or whether their approval level changes.

Re-Evaluation OutcomeAction
Strong performanceMaintain or upgrade approval level
Acceptable but issues notedIssue corrective action, increase monitoring frequency
Poor performanceProbationary status, increase incoming inspection
Failed or uncertifiedRemove from ASL, qualify replacement

If a supplier is removed from your ASL, your records must reflect that decision and any transition actions taken. An audit trail gap here — particularly if a product from a de-listed supplier made it into production — creates significant liability.

BSI Group offers ISO 13485 training that covers supplier management as part of QMS implementation — useful for quality managers building or rebuilding a supplier program from scratch.


How Supplier Controls Connect to ISO 14971 Risk Management

Risk-based supplier controls infographic showing ISO 13485 and ISO 14971 supplier tiering, supplier monitoring KPIs, risk classification, and supplier re-evaluation workflow for medical device manufacturers.
Risk-based supplier controls connect ISO 14971 risk analysis with ISO 13485 qualification, monitoring, verification, and supplier re-evaluation activities.

Your supplier tier system shouldn’t be arbitrary. It should be driven by a risk assessment.

ISO 14971 — the risk management standard for medical devices — requires you to identify hazards and estimate risks throughout the product life cycle. The components and materials your suppliers provide are part of that risk picture.

Risk-Based Supplier Tiering

Risk TierComponent ExamplesSupplier Control Level
CriticalSterile packaging, implantable components, direct patient-contact materialsFull qualification, audits, COC per lot
MajorElectronic subassemblies, precision machined partsQualification + periodic re-evaluation, sampling
MinorNon-product-contact materials, standard hardwareBasic approval, periodic review
AdministrativeCalibration services, software toolsContract review, credentials verification

Documenting the risk basis for each tier — and linking it to your ISO 14971 risk file — gives you a defensible rationale for your supplier control decisions. Auditors respond well to risk-based reasoning. They respond poorly to “that’s how we’ve always done it.”

For a full breakdown of how ISO 14971 and ISO 13485 work together: ISO 14971 vs ISO 13485


Common Audit Findings in Supplier Control Programs

These are the findings that show up repeatedly in ISO 13485 audits — and the ones your program should be specifically designed to prevent.

Most common finding #1: Suppliers on the ASL with no qualification records. Vendors added informally, without documented evaluation. No basis for their approval on file.

Most common finding #2: Purchase orders that don’t flow down quality requirements. The PO has a part number and a price. It does not reference a specification revision level, a certificate of conformance requirement, or any CAPA notification obligation.

Most common finding #3: Incoming inspection records that don’t match procedures. The procedure says AQL sampling on a specific plan. The records show visual inspection only. Or no records at all.

Most common finding #4: No re-evaluation records for suppliers on the ASL for more than 12 months. Annual re-evaluation is defined in the procedure. No evidence it was performed.

Most common finding #5: Supplier CAPAs not tracked or closed. A corrective action was issued to a supplier. There’s no record of their response or whether the root cause was resolved.

If any of those five sound familiar, your supplier control program has audit risk right now.


Quick Audit Checklist: Supplier Controls

Run through this before your next internal audit or notified body review:

✅ Documented supplier evaluation criteria based on product risk level

✅ Approved Supplier List with documented evaluation records for every supplier

✅ Procedure defines supplier tiers and the control requirements for each tier

✅ Purchasing documents (POs, specs) include product description, revision level, and quality flow-down requirements

✅ Change notification requirement communicated to and acknowledged by suppliers

✅ Incoming inspection procedure defines method by product/supplier category

✅ Incoming inspection records maintained and linked to purchase orders

✅ Nonconforming purchased product procedure exists and connects to CAPA

✅ Supplier performance data collected and reviewed at defined frequency

✅ Annual re-evaluation records on file for all active suppliers

✅ De-listed supplier records maintained with transition documentation

✅ Risk basis documented for supplier tier assignments (links to ISO 14971 risk file)


FAQ

What does ISO 13485 Section 7.4 require for supplier controls?

Section 7.4 of ISO 13485:2016 requires three elements: a documented process for evaluating, selecting, and monitoring suppliers (7.4.1); purchasing documents that clearly specify product requirements and quality flow-down obligations (7.4.2); and a defined process for verifying that purchased product meets requirements before use (7.4.3). All three require documented procedures and maintained records — not just policy statements.

How do I build an Approved Supplier List that satisfies ISO 13485 auditors?

Your Approved Supplier List must be backed by documented evaluation records for every supplier on it. The evaluation criteria should be defined in your procedure and applied consistently. Auditors will select suppliers from the list at random and ask to see their qualification records. If a supplier was added without documented evaluation, that’s a nonconformance regardless of how long they’ve been on the list.

Do all suppliers need the same level of evaluation under ISO 13485?

No. ISO 13485 supports a risk-based approach to supplier controls. Suppliers providing critical components — those that directly affect device safety or performance — require more rigorous qualification and monitoring than suppliers of low-risk or non-product-contact materials. Your procedure must define the risk tiers and the control requirements for each.

What must purchase orders include to satisfy ISO 13485 Section 7.4.2?

Purchase orders and associated documents must describe the product clearly enough to verify compliance on receipt. This includes the product description, specification revision level, applicable standards or regulatory requirements, quality requirements being flowed down (such as a certificate of conformance), and change notification obligations. A purchase order that only includes a part number and price is not compliant with 7.4.2.

How often do I need to re-evaluate suppliers under ISO 13485?

ISO 13485 requires periodic re-evaluation but does not specify a frequency. Most quality management systems set annual re-evaluation as the standard cycle. What matters is that your procedure defines the frequency, that re-evaluation is actually performed on schedule, and that records are maintained showing the outcome and any actions taken.

What happens if a supplier fails re-evaluation?

Your procedure must define the response to poor supplier performance. Options include issuing a corrective action request, increasing the incoming inspection level, placing the supplier on probationary status, or removing them from the Approved Supplier List. Whatever action is taken must be documented. If a supplier is removed from the ASL, records must reflect the decision and any transition activities.

How do supplier controls connect to CAPA in ISO 13485?

Any nonconformance associated with purchased product — identified at incoming inspection, during production, or through customer complaints — should trigger your CAPA process. CAPAs issued to suppliers must be tracked to closure, with evidence that the root cause was addressed. A CAPA issued to a supplier with no follow-up record is a frequent audit finding.

Does ISO 13485 require supplier audits?

ISO 13485 does not explicitly require supplier audits, but it requires you to evaluate and monitor suppliers — and for high-risk suppliers, a supplier audit may be the most effective and defensible method. Your procedure should define when supplier audits are required based on risk level and performance history.


📥 Free Resources


Not Sure What to Do Next?

🔹 Still researching whether your supplier program meets 13485 requirements? Start with the free ISO 13485 Gap Assessment Checklist to identify specific gaps before you invest in implementation.

🔹 Ready to build or rebuild your supplier control program? BSI Group’s ISO 13485 training covers supplier management as part of a full QMS implementation curriculum — practical, not academic.

🔹 Need the standard itself to verify clause requirements? Buy ISO 13485:2016 from the ANSI Webstore — use code CC2026 for 5% off through December 31, 2026.


Supplier controls are one of the most audited areas in ISO 13485 — and one of the most correctable. The common findings aren’t caused by complexity. They’re caused by supplier programs that were built fast, never formalized, and never tested against the actual clause requirements. The Standards Navigator covers ISO 13485 implementation from gap assessment through certification, with practical guidance built on real QMS and quality management experience.


Stay Ahead of ISO 13485 Supplier Control Requirements

Supplier nonconformances are consistently among the top audit findings in ISO 13485 certifications — not because the requirements are unclear, but because most programs were built to satisfy an initial audit and never updated to reflect actual supplier performance data.

Organizations that maintain clean supplier records and re-evaluate on a defined schedule rarely have corrective actions in this area. Organizations that treat supplier qualification as a one-time event get findings every surveillance cycle.

The Standards Navigator covers the full ISO 13485 implementation picture — from documentation requirements to CAPA processes to supplier controls — with guidance built for regulatory affairs and quality professionals who need to get it right, not just get it done.

👉 Get updates on ISO 13485 implementation requirements and audit readiness 👉 Be first to access new ISO 13485 compliance resources and checklists

Subscribe below to stay ahead.

Subscribe

* indicates required

The Standards Navigator — Industrial Compliance. Clearly Explained.