Purchasing & Supplier Control
Direct Answer
A purchasing and supplier control procedure has to do two things almost no organization does both of: decide the controls applied to the external provider, and decide the controls applied to what that provider delivers. ISO 9001:2015 Clause 8.4.2 b) asks for both. Most procedures record one. The second requirement is rating providers on the effect of what they supply rather than on what it costs — which is why the cheapest line on your purchase ledger is often the one carrying the most exposure.
There is a box of respirator cartridges sitting on a shelf somewhere in your organization. It cost thirty-eight dollars. It is below every threshold in your approved supplier process, below the value that triggers a quality review, below the number that would put it in front of anyone senior. It is also the only thing standing between a worker and whatever is in the air.
That box is the whole problem with how most organizations buy. Not carelessness, not incompetence — a structural mismatch between what the process measures and what actually matters. A purchasing and supplier control procedure that rates providers on spend will look at that box and see nothing worth controlling.
Capture. Rate. Control. Those three decisions, made in that order, are what separates a purchasing and supplier control procedure that works from one that merely exists.
This article covers what a purchasing and supplier control procedure has to contain across five ISO standards, the one clause almost everyone skips, why it gets skipped for reasons that have nothing to do with diligence, and what changes when you fix it. If you would rather score your own process first, the free Purchasing and Supplier Control Maturity Check takes about six minutes and gives you a band and a priority order before you read another word.
Where the requirement lives, and why it moves
The first practical difficulty is that purchasing does not sit in the same place twice. An organization running more than one standard cannot simply copy the clause reference across, and a purchasing and supplier control procedure written for one system will silently miss requirements in another.
| Standard | Where purchasing sits |
|---|---|
| ISO 9001:2015 | Clause 8.4, in three parts — 8.4.1 general, 8.4.2 type and extent of control, 8.4.3 information for external providers |
| ISO 13485:2016 | Clause 7.4. The numbering does not align with ISO 9001 because ISO 13485 predates the harmonized ten-clause structure |
| ISO 14001:2026 | No purchasing clause at all. The requirements are distributed across Clause 8.1, supported by 6.1.2 and the new 6.3 |
| ISO 45001:2018 | Clause 8.1.4 — the only one of the five with a dedicated procurement clause, split into procurement, contractors and outsourcing |
| ISO 7101:2023 | Clause 8.8, covering clinical and non-clinical externally provided services and products |
The ISO 14001 row is the one that catches people. An organization transitioning to ISO 14001:2026, published on 15 April 2026, goes looking for the purchasing clause, does not find one, and concludes the standard has little to say about external provision. It has a great deal to say. It says it in Clause 8.1, in language most readers pass straight over.
Direct Answer
Which clause governs a purchasing and supplier control procedure depends entirely on the standard: 8.4 in ISO 9001:2015, 7.4 in ISO 13485:2016, 8.1.4 in ISO 45001:2018, 8.8 in ISO 7101:2023, and no dedicated clause at all in ISO 14001:2026, where the requirements are distributed across Clause 8.1 with support from 6.1.2 and 6.3.
The requirement almost nobody implements
ISO 9001:2015 Clause 8.4.2 b) requires the organization to define both the controls it intends to apply to an external provider and the controls it intends to apply to the resulting output. Two determinations. One clause. In practice, one of them gets recorded.
Ask to see how an organization discharges this and you will usually be shown an approved supplier list, a folder of certificates, and a questionnaire. All of that is provider-side control. Ask what is checked when the material arrives and the answer is frequently a shrug, a delivery note, and a visual check for damage. The output-side determination was never made, so it cannot be found.
Here is the part worth understanding, because it explains why capable organizations with mature systems miss this: it is missed structurally, not carelessly. The approved supplier list belongs to purchasing. Incoming inspection belongs to quality, or to receiving, or on a hospital ward to whoever unpacks the box. No single document in most organizations asks for the pair. Each function does its half competently, and nobody notices that the pair was never decided together. A purchasing and supplier control procedure that asks the question in one place is often the only thing that surfaces it.
A purchasing and supplier control procedure closes this by asking for both determinations on the same page, for the same provider, at the same moment. The diagnostic question is simpler than the clause. For a significant provider, ask: which characteristics of what we receive does nobody verify, because each side assumes the other does? Most organizations have never asked it. The ones that do ask it usually find two or three answers within an hour, and the answers are almost always cheap to fix once visible.
Direct Answer
The requirement most often missed in a purchasing and supplier control procedure is ISO 9001:2015 Clause 8.4.2 b), which asks for the controls applied to the external provider and the controls applied to the resulting output as two separate determinations. It is missed structurally: supplier approval belongs to purchasing, incoming verification belongs to quality, and no single document asks for both.
Rate on effect, not on spend
The second structural error is rating providers by value. It is worth being precise about why this happens, because it is not stupidity — it is a correct habit imported from the wrong discipline. In procurement, rating by spend is exactly right. Spend is what procurement manages. Category strategy, negotiation leverage, payment terms and contract governance all scale with value, and a procurement function that spent equal effort on a thirty-eight dollar consumable and a two million dollar contract would be failing at its job.
Then the supplier process gets built on top of the procurement system, inherits its thresholds, and starts using value to decide how much quality, environmental or safety control a provider needs. The habit crosses a boundary where it stops being true. Every one of the five standards asks about effect. None of them mentions price.
ISO 13485:2016 is the most explicit: control must be proportionate to the effect of the purchased product on the medical device. ISO 45001:2018 routes procurement decisions through hazard and the hierarchy of controls. ISO 7101:2023 asks about the effect on the safety of both the workforce and service users. ISO 14001:2026 asks about relevance to the intended outcomes of the environmental management system. A purchasing and supplier control procedure with a dollar threshold in its rating criteria has a design fault, however well the rest of it reads.
Worked example one: the thirty-eight dollar box
Return to the respirator cartridges. Thirty-eight dollars, ordered on a corporate card by a supervisor who needed them that afternoon, from a supplier chosen because they had stock. No purchase order, no evaluation, no record, no rating — because every threshold in the system sits above thirty-eight dollars.
Now consider what those cartridges do. They are the last control in a hierarchy that has already failed to eliminate, substitute or engineer out the hazard. If they are the wrong grade, expired, counterfeit, or simply not the ones the risk assessment specified, the worker wearing them believes they are protected and is not. There is no downstream inspection that will catch it, because nobody inspects a sealed cartridge.
Under ISO 45001:2018 this is not a minor administrative lapse. Clause 8.1.4 exists precisely so that procurement decisions carry the organization's occupational health and safety requirements with them. A purchasing and supplier control procedure built on criteria rather than value catches this box on the first question — does a control measure depend on this item? — and routes it accordingly, regardless of its price. Criteria-based routing costs nothing extra to operate. It simply asks a different question.
Worked example two: the purchase that never happened
A healthcare organization receives four infusion pumps from a charitable foundation. They are new, they are in date, they are a recognized brand, and they cost nothing. There is no purchase order, no invoice, no supplier record, no procurement event of any kind. Not one threshold in any system in that organization can see them, because nothing was bought.
A purchasing and supplier control procedure that keys on effect rather than on a transaction would have stopped them at the door. They go into service. Six months later the consumable sets prove to be a proprietary line that the organization does not stock, the maintenance contract does not cover them, and the biomedical engineering team has never been trained on that model. None of those facts were established before acceptance, because acceptance was not a decision anyone was asked to make.
ISO 7101:2023 anticipates exactly this. Clause 8.8 reaches partnering stakeholders — governmental, non-governmental and intergovernmental organizations, and funding partners — and requires expectations to be documented, along with a pre-defined method for communicating a failure to meet criteria. Donations and grant-funded provision are inside the scope of a purchasing and supplier control procedure precisely because they bypass procurement entirely.
The two examples make the same point from opposite directions. One is a purchase too cheap for the process to see. The other is not a purchase at all. Both are invisible to a system that watches money, and both are visible to a system that asks what the provision does.
Direct Answer
A purchasing and supplier control procedure should rate providers on the effect of what they supply, never on spend or contract value. Rating by value is correct in procurement and wrong in supplier control: a thirty-eight dollar consumable that a safety control depends on, or a donated device that was never purchased at all, carry exposure that no financial threshold can detect.
What each standard asks that the others do not
A purchasing and supplier control procedure written to one standard will not transfer cleanly to another. Every one of the five contains at least one obligation relating to external provision that the others do not. These are consistently the requirements organizations have not discharged — and again for a structural reason. A supplier procedure carried across from another standard will not contain them, and no clause checklist from that other standard points at them, so no internal audit samples them.
ISO 9001:2015 — outsourced processes
Clause 8.4.2 a) requires externally provided processes to remain within the control of the quality management system. That is a different obligation from controlling a purchased product, and it is usually discharged by a sentence asserting it, with nothing behind it. A process is outsourced if you could perform it yourself and it forms part of your own realization — the contract type does not decide it, and neither does the invoice. Where the process is a special one whose result cannot be verified afterwards, such as heat treatment, welding, coating or sterilization, the only real control is the one applied while the process runs, on someone else's premises.
ISO 13485:2016 — obligations from regulation, not the clause
Two things separate device supplier control. Rating follows the effect on the device, and a set of obligations arises from regulation rather than from the standard. Since 2 February 2026 the FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820, which makes supplier records inspectable. The strongest single addition to a device purchasing and supplier control procedure is a written change-notification agreement with the change categories enumerated — material, formulation, method, site, subcontractor — and a recorded impact determination for every notification received, including the ones where the determination is no impact.
ISO 14001:2026 — the word everyone reads as an escape
Clause 8.1 requires externally provided processes, products and services relevant to the environmental management system to be controlled or influenced, and requires the type and extent of that control or influence to be defined within the management system. Organizations read “or” as an either/or, define the controls they already had, and leave influence undefined.
But for most environmental aspects, control is not available. You do not control the haulier's fuel mix, the smelter's energy source, or what happens to your waste after the second gate. Influence is the only thing left to define, which makes it the majority of the obligation rather than the optional half. A fully populated control column beside an empty influence column has documented the minority of the organization's footprint. This is also where the ISO 9001 and 14001 transition work most often uncovers something genuinely missing rather than merely renumbered.
ISO 45001:2018 — the requirement that lives outside Clause 8
Clause 5.4 requires emphasis on the consultation of non-managerial workers on determining applicable controls for outsourcing, procurement and contractors. It sits in the leadership clause, not the operational one, which is why purchasing procedures almost universally miss it — the author of a purchasing and supplier control procedure is reading Clause 8, and the requirement is four clauses earlier.
It is also the easiest requirement in the standard to test, and it cannot be satisfied on paper. The question put to a worker is whether anyone asked them what the controls should be before the contractor arrived. No document produces a yes if the conversation did not happen.
ISO 7101:2023 — the requirement no other standard contains
Clause 8.8 a) requires criteria for disqualifying external providers, defined alongside the criteria for evaluating, selecting and monitoring them. No other management system standard in common use asks this.
It is uncomfortable to write while entering a relationship, which is precisely why it belongs in a purchasing and supplier control procedure rather than in a conversation. At the moment a provider fails, the service is running, the alternative is unqualified, and there is real pressure to decide that this instance does not count. A criterion written a year earlier, by people not under that pressure, is the only thing that meets that moment honestly. Ask it of your most depended-upon provider first — that is the one where the answer is usually nothing.
Direct Answer
Each standard adds something a generic purchasing and supplier control procedure will miss: outsourced processes remaining inside the quality management system under ISO 9001 Clause 8.4.2 a); regulatory obligations and change notification under ISO 13485 with QMSR now in force; the influence half of “controlled or influenced” under ISO 14001:2026 Clause 8.1; worker consultation under ISO 45001 Clause 5.4; and disqualification criteria under ISO 7101 Clause 8.8 a).
The exception path is not an appendix. It is the procedure.
Every purchasing and supplier control procedure describes the normal case well and the abnormal case barely at all, which is precisely backwards. The normal case takes care of itself. Nothing goes wrong on the week when everyone is present, the approved provider has stock, and there is time to follow the process.
What happens on the other week? A line is down, the approved supplier cannot deliver until Thursday, and someone finds an alternative in twenty minutes. If the procedure has no route for that, the purchase still happens — it just happens with no rating, no controls, no authorization and no record. The absence of an exception route does not prevent exceptions. It prevents evidence of them.
Bound. Authorize. Log. A usable route names who can authorize, states which controls still apply, requires a log entry, and closes out afterwards. It also states the categories it is closed to, where no authorization can substitute for verification — high-hazard work, unlicensed waste carriers, unverified sterile or safety-critical items. An organization with no exception log has not eliminated exceptions; it has eliminated the record.
Contingency is the same argument in a purchasing and supplier control procedure on a longer timescale. If a significant provider stopped tomorrow, what stops, how quickly, and what is the alternative? Writing one page per significant provision now costs an afternoon. Working it out during the interruption costs considerably more, and the answers are worse.
Direct Answer
A purchasing and supplier control procedure needs a bounded exception path with named authority, applied controls, a log entry and a close-out, plus stated categories the route is closed to. Without one, urgent purchases still occur — with no rating, no controls and no record — and those are disproportionately the ones that cause incidents.
Eight elements every purchasing and supplier control procedure needs
In MSI's client experience across manufacturing, technology, medical device, government, healthcare and other regulated industries, a purchasing and supplier control procedure that works in practice tends to be strong on the same eight elements, and organizations that struggle tend to be weak on the same ones.
- Requirement capture — every route a need can arrive by, including verbal requests, card purchases and services arranged by other departments
- Impact determination — written criteria based on effect, with value deliberately excluded and anything unrated defaulting upward
- The two-control determination — provider-side and output-side controls decided and recorded separately
- Evaluation and selection — criteria that are applied rather than collected, with approval granted for a stated scope
- Agreed requirements — what reaches the provider, reviewed for adequacy before it is sent, and accepted by them
- Verification and release — defined per provision, recorded before release, with arriving documents read rather than filed
- Monitoring and re-evaluation — measures at a frequency set by the rating, with event triggers as well as intervals
- Exception and contingency — bounded, authorized, logged, and tested
A useful property of scoring a purchasing and supplier control procedure element by element is that it stops the improvement conversation from becoming a single verdict. Most organizations are not uniformly weak. They are strong on evaluation and weak on verification, or the reverse, and knowing which changes what you do on Monday. The free Purchasing and Supplier Control Maturity Check scores all eight, adds three questions specific to your standard, and gives you a band and a priority order without asking for anything first.
Where the process connects to everything else
A purchasing and supplier control procedure does not operate alone, and the interfaces are where implementations usually thin out. Supplier nonconformity has to enter the corrective action system rather than being handled by telephone. Provider performance has to reach management review as data rather than as impressions. Outsourced processes have to appear in the internal audit programme — and ISO 19011:2026, published on 27 May 2026, strengthened attention to supply chains and interconnected, outsourced operations for exactly this reason.
Records are the other dependency, and the one most often underestimated. Every determination described in this article produces a record, and those records only stay findable if the organization decided in advance where they live, who owns them and how long they are kept. That is a document and records control question rather than a purchasing one, but a purchasing and supplier control procedure written without those decisions made will produce evidence nobody can retrieve. Internal audit planning then samples into the process and finds the gap that the records would have shown.
Accreditation context matters to a purchasing and supplier control procedure too: Global Accreditation Cooperation Incorporated replaced IAF and ILAC on 1 January 2026, so certification-body oversight of how these clauses are assessed now sits with a single body.
How to build a purchasing and supplier control procedure
If you are writing a purchasing and supplier control procedure from scratch, the order that works is: capture routes first, then rating criteria, then the two control sets, then everything else. The first two are load-bearing — improvements to evaluation, verification or monitoring do not hold if requirements never enter the process or are rated on the wrong basis.
If you would rather start from a complete one, MSI's Purchasing and Supplier Control Procedure Template and Guide is a working procedure written as a filled-in example rather than an outline, in editable Word, with an evaluation record built to act as the approval gate, a provider register, a desk-level work instruction, a standard-specific fourth appendix, and the maturity ladder the check above scores against. One version per standard, 39 to 47 pages, at $149.
Score First. Fix Second. Buy Last.
Find out which of the eight elements is holding your score down
Twenty questions, about six minutes, five standard paths. You get your score, your band and the requirement your standard contains that the others do not — immediately, without entering anything.
If the result surprises you, or the priority order does not match what you expected, a conversation is usually quicker than a rewrite. MSI's ISO consulting practice has supported 80+ certifications and attended 200+ audits, and a planning session on 760-434-9141 will tell you in half an hour whether your process needs repair or replacement. You can also watch the ISO Executive Decision Briefs — short leadership-level videos on what a management system is supposed to produce — or read about The Portrait, MSI's independent operational assessment.
Frequently asked questions
What is a purchasing and supplier control procedure?
It is the controlled document that defines how an organization identifies what it needs from outside, decides how much control each provider and each delivery requires, evaluates and selects providers against written criteria, communicates requirements, verifies what arrives, monitors performance, and handles the cases where the normal route cannot be followed. Under ISO 9001:2015 it addresses Clause 8.4 in full, including the requirement in 8.4.2 b) to determine controls on both the provider and the output.
Does ISO 9001 require a documented purchasing procedure?
ISO 9001:2015 does not mandate a document with a particular name, but it does require documented information to be retained for the evaluation, selection, monitoring and re-evaluation of external providers, and requires controls to be determined and applied. In practice a purchasing and supplier control procedure is the most straightforward way to satisfy those requirements coherently, and organizations that try to spread them across a purchase-order workflow and an approved supplier list generally leave 8.4.2 undischarged.
Why should suppliers not be rated on spend?
Because none of the five standards asks about price. They ask about effect — on the product, on the device, on the environment, on worker and service-user safety. Rating by value is correct in procurement and imported incorrectly into supplier control, and it produces a system that watches the largest contracts closely while a low-cost consumable on which a control depends passes through unexamined.
How does ISO 13485 differ from ISO 9001 on purchasing?
The requirements sit at Clause 7.4 rather than 8.4, because ISO 13485:2016 predates the harmonized ten-clause structure, so the numbers do not map across. The substance differs too: control must be proportionate to the effect of the purchased product on the medical device, and a set of obligations arises from regulation rather than from the standard. Since the FDA Quality Management System Regulation took effect on 2 February 2026, incorporating ISO 13485:2016 into 21 CFR Part 820, supplier records are inspectable.
Does ISO 14001:2026 have a purchasing clause?
No, and that is why the requirements are so often missed. They are distributed across Clause 8.1, supported by 6.1.2 and the new Clause 6.3, and the operative wording is that external provision must be controlled or influenced, with the type and extent of both defined within the management system. Since control is unavailable for most environmental aspects, influence is the larger half of the obligation rather than the optional one.
What does ISO 45001 require that other standards do not?
Clause 5.4 requires emphasis on the consultation of non-managerial workers on determining applicable controls for outsourcing, procurement and contractors. It sits in the leadership clause rather than the operational one, which is why a purchasing and supplier control procedure written by reading Clause 8 alone will miss it. ISO 45001:2018 also carries the only dedicated procurement clause of the five, at 8.1.4, split across procurement, contractors and outsourcing.
How long should a purchasing and supplier control procedure be?
Length is the wrong measure; completeness against the clause and usability on a busy day are the right ones. A procedure that is trainable in one sitting, states thresholds rather than intentions, produces its records as a byproduct of the work, and defines what happens when the normal route fails will generally run to somewhere between thirty and fifty pages including its forms and a worked example. Considerably shorter usually means the exception path and the records are missing.
References
- ISO 9001:2015 — Quality management systems, Clause 8.4
- ISO 13485:2016 — Medical devices, Clause 7.4
- ISO 45001:2018 — Occupational health and safety, Clause 8.1.4
- FDA Quality Management System Regulation — effective 2 February 2026
- 21 CFR Part 820 — Quality Management System Regulation, eCFR
- Global Accreditation Cooperation Incorporated — replaced IAF and ILAC on 1 January 2026
- ASQ — supplier quality resources
- ANAB — ANSI National Accreditation Board
About MSI
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience, including extensive AS9100 implementation work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, ISO 45001, and ISO 7101. MSI is veteran-owned and female-owned.
To talk through your own process, call 760-434-9141 or visit msi-international.com.
This article is general guidance and does not replace ISO 9001:2015, ISO 13485:2016, ISO 14001:2026, ISO 45001:2018, ISO 7101:2023, any applicable regulation, or the judgement of a competent professional. Standards are revised, amended and withdrawn; confirm the current status of your standard at iso.org before relying on clause references. Clause references were verified on 19 July 2026.