ISO 9001 · Clause 8 · 8.4, 8.4.1, 8.4.2, 8.4.3
External providers
In plain words
What you buy becomes part of what you deliver — and your customer does not distinguish whose fault it was. This clause therefore demands control beyond your own workbench, in three situations: purchased products and services that enter your product; services that land in your name directly at the customer’s; and outsourced processes — the classic: the hardening shop.
Three things are demanded: criteria for selecting, evaluating and re-evaluating your providers (8.4.1); control with a sense of proportion — kind and depth follow the effect on your product (8.4.2); and clear requirements — the provider must be able to know what applies: what is delivered, to which procedures, with which evidence (8.4.3).
For a company of 12 people this does not mean a purchasing department, but: a maintained supplier overview, complete purchase orders and a goods-in check that fits the criticality.
Why this requirement exists
Outsourcing moves work, never responsibility. The clause cuts off the most convenient escape in the quality world — “that was the supplier” — and replaces it with a question you must be able to answer: how do you know your providers deliver what your customer expects of you?
The sense of proportion in 8.4.2 has a deeper reason: with a catalogue part, goods-in shows you what you got. With an outsourced special process — hardening, coating — it does not: the microstructure is not written on the part’s face. Where final inspection is blind, trust must be built at the front — the provider’s qualification, a controlled process, solid evidence. That is why “treat all suppliers the same” is not fairness but a thinking error.
What good looks like
A supplier overview with classification: who is critical for product conformity, who is catalogue ware? New critical providers enter along a defined path — evidence, a trial batch, a visit where needed. The running evaluation feeds on real events — delivery performance, complaints, reaction to problems — instead of a grading ritual. Purchase orders carry everything needed: drawing revision, material, procedure, required certificates. And goods-in checks proportionally: a look and the delivery note for the catalogue part, dimensions and certificate against the order for the critical one.
The view reaches beyond material, too: the calibration laboratory, the carrier, outsourced IT are externally provided services as well. Whoever thinks only “parts” controls half.
What changes as you grow: From around 50 people: a defined approval path for new providers, a yearly evaluation round with consequences, and second sources for critical scopes. From 100–250 people: supplier audits, quality assurance agreements, supplier development — at the latest when your customers audit down the chain. The core stays the same at every size: criticality sets depth.
The minimum to pass
- You know which providers are critical to your product conformity.
- For every critical provider there is a traceable reason for trust — evaluation, history, evidence; not habit alone.
- Purchase orders are complete and unambiguous — including revision level and required certificates.
- Goods-in matches the criticality — and records what it checked.
- Re-evaluation is visible: anomalies have consequences you can see.
What an auditor asks for
- The supplier overview with date and classification — and the question behind it: what is “approved” based on?
- A purchase order to a critical provider: does it carry revision, procedure and the required evidence?
- Goods-in records — and the case of a rejected delivery: what happened, and did it flow into the evaluation?
- For the outsourced process, the core question: “how do you assure what you cannot check on the part?” — the answer separates understood from administered purchasing.
- The question customer auditors ask too: “how do you control your hardening shop?” — including the chain behind it: order, certificate, goods-in, traceability.
Common traps
- The grading ritual. The yearly evaluation says 1.8, the complaints list tells another story — because the evaluation runs beside the real events instead of growing out of them.
- “They’ve been doing it for twenty years.” Trust is a result of evidence, not a substitute for it. Exactly here is where customer audits drill first.
- The purchase order without a revision. The provider produces to an old drawing — correct by their state, wrong by yours. The counterpart of the repeat-order trap in order review (8.2).
- Special process as catalogue ware. Treating hardening like buying screws — and goods-in holds the blind spot. Where inspection cannot see the result, control must act up front.
- Requirements expected, never communicated. The provider is supposed to deliver what was written nowhere. 8.4.3 makes the completeness of your own requirements a duty — before sending.
- The invisible service provider. Calibration lab, transport, IT — externally provided, never controlled, because “no material”.
Worked example
For Berger Präzisionsteile GmbH the hardening shop is the most critical provider — an outsourced process whose result Berger cannot fully check on the part. Control therefore acts up front: every purchase order carries material and batch, procedure and target hardness with tolerance, drawing revision and the required 3.1 inspection certificate — the record in which the maker confirms the actual test values of the delivered batch (type 3.1 per EN 10204). Goods-in checks the certificate against the order and measures a distortion sample — the hardness values themselves come from the certificate, the trust from the qualification. When the risk overview (6.1) named the dependence on the single hardening shop, the second one was approved along exactly this path: evidence, a trial batch with traceable hardness tests, a visit on site.
The everyday test came with a delivery whose certificate belonged to the wrong batch: goods-in blocked it, one call, the corrected certificate arrived the same day — and both sit in the evaluation since: the error and the reaction time. When the medical-technology customer came for its supplier audit (4.2), Lea showed the whole chain — overview, order, certificate, goods-in, traceability through the batch into the hardening shop. The question “how do you control your hardening shop?” was answered by the chain, not by memory.
<!-- easo:worked_example profile=service -->
The most critical provider of Klarwerk GmbH delivers no parts: it is the most important of its two cloud platforms, the one the bulk of customer systems run on. An 8-person company cannot audit a global corporation — but it can control it: deliberate selection on published evidence (reading certificates instead of testing yourself), availability fixed in the contract, incident reports watched, a documented exit plan. The platform risk sits in the risk overview (6.1). Control here means: knowing what you cannot control — and providing for it. The movement of thought is the same as with the hardening furnace: criticality sets depth.
How easo covers it
Clause 8.4 is a row in the readiness denominator — the evidence is your described supplier control.
- Create from the gap links the clause; the starter template brings the structure: classification, selection and evaluation, requirements to providers, goods-in. The supplier overview itself you keep as a controlled document — versioned, signed, with history.
- The management review carries the performance of external providers as a fixed point of the walkthrough (9.3) — the yearly evaluation round has a date that cannot be forgotten.
- A rejected delivery with consequences becomes a corrective action (10.2) with trackable tasks — incident, action and effectiveness check hang together instead of living in three lists.
Stay in the loop
easo is available for macOS — the Windows version is coming soon. Leave us a note and we'll reach out the moment it lands.