- ISO 9001
- Scoring
ISO 9001 supplier evaluation: meeting clause 8.4 with an approved supplier list
Updated 5 min read
Clause 8.4 is where ISO 9001 audits most often find a gap in a small company, not because the controls are hard, but because the evidence is scattered across email, spreadsheets and the purchasing system. This guide sets out what the clause asks for, a scoring method you can defend, and the records that make the audit a ten-minute conversation.
What clause 8.4 asks for
| Clause | Requirement | The record |
|---|---|---|
| 8.4.1 | Criteria for evaluation, selection, performance monitoring and re-evaluation | Your written criteria and weights; each dated evaluation |
| 8.4.2 | Type and extent of control, based on risk | Supplier tier or criticality; incoming inspection plan |
| 8.4.3 | Information given to external providers | Purchase orders, specifications, flow-down clauses |
| 9.1.3 | Analysis and evaluation of supplier performance | Performance records per period |
| 10.2 | Nonconformity and corrective action | CAPA records with effectiveness verified |
A scorecard you can recompute by hand
The standard lets you choose your criteria. What it does not let you do is apply them inconsistently. A weighted scorecard with the formula written down solves both: every supplier is measured the same way, and anyone can check a rating. A sensible default:
| Criterion | Weight | Measured by |
|---|---|---|
| Quality | 40 | Defective parts per million, less a penalty for each NCR |
| Delivery | 30 | On-time delivery percentage |
| Service | 15 | Responsiveness rating, less a penalty for each overdue CAPA |
| Compliance | 15 | Share of the supplier's QMS questionnaire attested |
Score each criterion from 0 to 100, take the weighted mean, and set rating thresholds (for example A from 85, B from 70, C from 55, D below). A and B are approved, C is conditional, D is disqualified. When a person overrides the recommendation, and sometimes they should, say why in writing.
Corrective actions that close properly
An NCR raised against a supplier should become a corrective action with a root cause, an action and a due date. Closing it is not the end: clause 10.2 asks whether the action worked. Record who verified effectiveness, when, and on what evidence (for example “zero rejects in the next three lots”). An overdue CAPA should count against the supplier's score.
Selecting a new supplier
Selection is the part of 8.4.1 most often left undocumented, because it happens before anyone thinks of the supplier as a supplier. Send new suppliers a short QMS questionnaire mapped to the clauses you rely on: whether they are certified, how they control their own sub-tier suppliers, whether they will tell you before changing a process or material, how they keep nonconforming product from shipping, and how they handle corrective action. Score the answers the same way every time, and record the selection decision with the date and the name of the person who made it.
For a supplier with no delivery history yet, the questionnaire and the certificate are all you have, so treat the first evaluation as provisional: approve conditionally, and re-evaluate once a quarter or two of performance data exists. That turns the re-evaluation into something the data drives rather than a date on a calendar.
The approved supplier list
One list, every live supplier: its status (approved, conditional, disqualified), its latest rating and score, when it was evaluated and by whom, when it is next due, and its QMS certificate with expiry. Export it as CSV or PDF for the audit, filtered to what the auditor asks for. Re-evaluation dates should come from the same review cycle as the rest of your vendor programme, so a supplier cannot fall off the calendar.
For suppliers that also handle your data, pair this with ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence. For deciding how much control each supplier needs, see Vendor risk tiering: how to classify third parties and set a review cadence.
Frequently asked questions
- What does ISO 9001 clause 8.4 require for suppliers?
- Clause 8.4.1 requires you to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, based on their ability to supply to your requirements, and to keep documented information of those activities and of any actions arising from them. Clauses 8.4.2 and 8.4.3 cover the type and extent of control and the information you give providers.
- Is an approved supplier list mandatory under ISO 9001?
- The 2015 standard does not use the words approved supplier list. It does require documented evidence of evaluation, selection, monitoring and re-evaluation, and an approved supplier list with dated evaluations is the simplest way to show all four in one place. Most certification auditors will ask for one.
- How often should suppliers be re-evaluated?
- The standard leaves it to you, but you must define the interval and follow it. Annually is common for most suppliers, with critical or poorly performing suppliers reviewed more often. What an auditor checks is that the interval is written down and that no supplier is past its date.
- Does a supplier need to be ISO 9001 certified?
- No. Certification is evidence of a working QMS, and many organisations weight it in their criteria, but ISO 9001 does not require your suppliers to be certified. When you do rely on a certificate, check that the certifying body is accredited by a signatory to the IAF Multilateral Recognition Arrangement, and that the scope covers what you buy.
Related guides
- Questionnaires
- Scoring
Vendor risk assessment questionnaire: what to ask, and how to score the answers
The questions that matter by risk tier, mapped to the controls auditors recognise, with a scoring method you can explain.
8 min read
- Programme design
- Scoring
Vendor risk tiering: how to classify third parties and set a review cadence
Four tiers, three questions to assign them, and the review cadence each one earns — so effort goes where the risk is.
7 min read
- Fundamentals
- Checklist
Vendor due diligence: a practical guide for small and mid-sized businesses
The end-to-end process — scoping, questionnaires, evidence, scoring, review cadence — sized for a team of one.
9 min read