Purchasing & Supplier Control
Direct Answer
A purchasing and supplier control procedure has to do two things almost no organization does both of: decide the controls applied to the external provider, and decide the controls applied to what that provider delivers. ISO 9001:2015 Clause 8.4.2 b) asks for both. Most procedures record one. The second requirement is rating providers on the effect of what they supply rather than on what it costs — which is why the cheapest line on your purchase ledger is often the one carrying the most exposure.
There is a box of respirator cartridges sitting on a shelf somewhere in your organization. It cost thirty-eight dollars. It is below every threshold in your approved supplier process, below the value that triggers a quality review, below the number that would put it in front of anyone senior. It is also the only thing standing between a worker and whatever is in the air.
That box is the whole problem with how most organizations buy. Not carelessness, not incompetence — a structural mismatch between what the process measures and what actually matters. A purchasing and supplier control procedure that rates providers on spend will look at that box and see nothing worth controlling.
Capture. Rate. Control. Those three decisions, made in that order, are what separates a purchasing and supplier control procedure that works from one that merely exists.
This article covers what a purchasing and supplier control procedure has to contain across five ISO standards, the one clause almost everyone skips, why it gets skipped for reasons that have nothing to do with diligence, what changes when ISO 9001:2026 publishes on 16 September 2026, and what to fix first. If you would rather score your own process before reading another word, the free Purchasing and Supplier Control Maturity Check takes about six minutes and returns a band and a priority order without asking you for anything.
Clause Location
Where a purchasing and supplier control procedure lives, and why it moves
Five standards. Five addresses. One document.
The first practical difficulty is that purchasing does not sit in the same place twice. An organization running more than one standard cannot simply copy the clause reference across, and a purchasing and supplier control procedure written for one system will silently miss requirements in another.
| Standard | Where purchasing sits |
|---|---|
| ISO 9001:2015 | Clause 8.4, in three parts — 8.4.1 general, 8.4.2 type and extent of control, 8.4.3 information for external providers |
| ISO 13485:2016 | Clause 7.4. The numbering does not align with ISO 9001 because ISO 13485 predates the harmonized ten-clause structure |
| ISO 14001:2026 | No purchasing clause at all. The requirements are distributed across Clause 8.1, supported by 6.1.2 and the new 6.3 |
| ISO 45001:2018 | Clause 8.1.4 — the only one of the five with a dedicated procurement clause, split into procurement, contractors and outsourcing |
| ISO 7101:2023 | Clause 8.8, covering clinical and non-clinical externally provided services and products |
The ISO 14001 row is the one that catches people. An organization transitioning to ISO 14001:2026, published on 15 April 2026 with a transition deadline of 30 April 2029, goes looking for the purchasing clause, does not find one, and concludes the standard has little to say about external provision. It has a great deal to say. It says it in Clause 8.1, in language most readers pass straight over — and that language is the subject of its own article, linked below.
The practical consequence for anyone writing one document to serve two or more systems is that clause mapping is the wrong starting point. Start from the obligations — capture, rating, the two control sets, verification, monitoring, exception — and cross-reference the clauses afterward. MSI's guidance on the order in which procedures should be written makes the same argument at system level: sequence by dependency, not by clause number.
Direct Answer
Which clause governs a purchasing and supplier control procedure depends entirely on the standard: 8.4 in ISO 9001:2015, 7.4 in ISO 13485:2016, 8.1.4 in ISO 45001:2018, 8.8 in ISO 7101:2023, and no dedicated clause at all in ISO 14001:2026, where the requirements are distributed across Clause 8.1 with support from 6.1.2 and the new Clause 6.3.
The Skipped Clause
The requirement almost nobody implements
Two determinations. One clause. Half recorded.
ISO 9001:2015 Clause 8.4.2 b) requires the organization to define both the controls it intends to apply to an external provider and the controls it intends to apply to the resulting output. Two determinations. One clause. In practice, one of them gets recorded.
Ask to see how an organization discharges this and you will usually be shown an approved supplier list, a folder of certificates, and a questionnaire. All of that is provider-side control. Ask what is checked when the material arrives and the answer is frequently a shrug, a delivery note, and a visual check for damage. The output-side determination was never made, so it cannot be found.
Here is the part worth understanding, because it explains why capable organizations with mature systems miss this: it is missed structurally, not carelessly. The approved supplier list belongs to purchasing. Incoming inspection belongs to quality, or to receiving, or on a hospital ward to whoever unpacks the box. No single document in most organizations asks for the pair. Each function does its half competently, and nobody notices that the pair was never decided together. A purchasing and supplier control procedure that asks the question in one place is often the only thing that surfaces it.
A purchasing and supplier control procedure closes this by asking for both determinations on the same page, for the same provider, at the same moment. The diagnostic question is simpler than the clause. For a significant provider, ask: which characteristics of what we receive does nobody verify, because each side assumes the other does? In MSI's client experience across 200+ audits attended, organizations that ask it usually find two or three answers within an hour, and the answers are almost always cheap to fix once visible.
Direct Answer
The requirement most often missed in a purchasing and supplier control procedure is ISO 9001:2015 Clause 8.4.2 b), which asks for the controls applied to the external provider and the controls applied to the resulting output as two separate determinations. It is missed structurally: supplier approval belongs to purchasing, incoming verification belongs to quality, and no single document asks for both.
Rating Criteria
Rate on effect, not on spend
Right habit. Wrong discipline. Real exposure.
The second structural error is rating providers by value. It is worth being precise about why this happens, because it is not stupidity — it is a correct habit imported from the wrong discipline. In procurement, rating by spend is exactly right. Spend is what procurement manages. Category strategy, negotiation leverage, payment terms and contract governance all scale with value, and a procurement function that spent equal effort on a thirty-eight dollar consumable and a two million dollar contract would be failing at its job.
Then the supplier process gets built on top of the procurement system, inherits its thresholds, and starts using value to decide how much quality, environmental or safety control a provider needs. The habit crosses a boundary where it stops being true. Every one of the five standards asks about effect. None of them mentions price.
ISO 13485:2016 is the most explicit: control must be proportionate to the effect of the purchased product on the medical device. ISO 45001:2018 routes procurement decisions through hazard and the hierarchy of controls. ISO 7101:2023 asks about the effect on the safety of both the workforce and service users. ISO 14001:2026 asks about relevance to the intended outcomes of the environmental management system. A purchasing and supplier control procedure with a dollar threshold in its rating criteria has a design fault, however well the rest of it reads.
Choosing the scoring approach matters less than applying it consistently, which is the argument MSI's comparison of risk assessment methodologies makes at length. A simple three-band effect rating that every buyer applies the same way beats a weighted matrix that only the quality manager understands.
Worked example one: the thirty-eight dollar box
Return to the respirator cartridges. Thirty-eight dollars, ordered on a corporate card by a supervisor who needed them that afternoon, from a supplier chosen because they had stock. No purchase order, no evaluation, no record, no rating — because every threshold in the system sits above thirty-eight dollars.
Now consider what those cartridges do. They are the last control in a hierarchy that has already failed to eliminate, substitute or engineer out the hazard. If they are the wrong grade, expired, counterfeit, or simply not the ones the risk assessment specified, the worker wearing them believes they are protected and is not. There is no downstream inspection that will catch it, because nobody inspects a sealed cartridge. OSHA's respiratory protection requirements put the selection decision on the employer, not on whoever happened to place the order.
Under ISO 45001:2018 this is not a minor administrative lapse. Clause 8.1.4 exists precisely so that procurement decisions carry the organization's occupational health and safety requirements with them. A purchasing and supplier control procedure built on criteria rather than value catches this box on the first question — does a control measure depend on this item? — and routes it accordingly, regardless of its price. Criteria-based routing costs nothing extra to operate. It simply asks a different question.
Worked example two: the purchase that never happened
A healthcare organization receives four infusion pumps from a charitable foundation. They are new, they are in date, they are a recognized brand, and they cost nothing. There is no purchase order, no invoice, no supplier record, no procurement event of any kind. Not one threshold in any system in that organization can see them, because nothing was bought.
A purchasing and supplier control procedure that keys on effect rather than on a transaction would have stopped them at the door. Instead they go into service. Six months later the consumable sets prove to be a proprietary line that the organization does not stock, the maintenance contract does not cover them, and the biomedical engineering team has never been trained on that model. None of those facts were established before acceptance, because acceptance was not a decision anyone was asked to make.
ISO 7101:2023 anticipates exactly this. Clause 8.8 reaches partnering stakeholders — governmental, non-governmental and intergovernmental organizations, and funding partners — and requires expectations to be documented, along with a pre-defined method for communicating a failure to meet criteria. Donations and grant-funded provision are inside the scope of a purchasing and supplier control procedure precisely because they bypass procurement entirely. The ISO 7101:2023 procedure templates treat that route as a named capture path rather than an exception.
The two examples make the same point from opposite directions. One is a purchase too cheap for the process to see. The other is not a purchase at all. Both are invisible to a system that watches money, and both are visible to a system that asks what the provision does.
Direct Answer
A purchasing and supplier control procedure should rate providers on the effect of what they supply, never on spend or contract value. Rating by value is correct in procurement and wrong in supplier control: a thirty-eight dollar consumable that a safety control depends on, or a donated device that was never purchased at all, carry exposure that no financial threshold can detect.
Standard-Specific Obligations
What each standard asks that the others do not
Carried across. Never checked. Rarely audited.
A purchasing and supplier control procedure written to one standard will not transfer cleanly to another. Every one of the five contains at least one obligation relating to external provision that the others do not. These are consistently the requirements organizations have not discharged — and again for a structural reason. A purchasing and supplier control procedure carried across from another standard will not contain them, and no clause checklist from that other standard points at them, so no internal audit samples them.
ISO 9001:2015 — outsourced processes
Clause 8.4.2 a) requires externally provided processes to remain within the control of the quality management system. That is a different obligation from controlling a purchased product, and it is usually discharged by a sentence asserting it, with nothing behind it. A process is outsourced if you could perform it yourself and it forms part of your own realization — the contract type does not decide it, and neither does the invoice. Where the process is a special one whose result cannot be verified afterwards, such as heat treatment, welding, coating or sterilization, the only real control is the one applied while the process runs, on someone else's premises.
ISO 13485:2016 — obligations from regulation, not the clause
Two things separate device supplier control. Rating follows the effect on the device, and a set of obligations arises from regulation rather than from the standard. Since 2 February 2026 the FDA Quality Management System Regulation incorporates ISO 13485:2016 by reference into 21 CFR Part 820, which makes supplier records inspectable. MSI's analysis of the QMSR alignment works through what that changes in practice.
The strongest single addition to a device-side purchasing and supplier control procedure is a written change-notification agreement with the change categories enumerated — material, formulation, method, site, subcontractor — and a recorded impact determination for every notification received, including the ones where the determination is no impact. Absent that record, the file shows a change arrived and nothing shows anyone thought about it.
ISO 14001:2026 — controlled or influenced
Clause 8.1 requires externally provided processes, products and services relevant to the environmental management system to be controlled or influenced, and requires the type and extent of that control or influence to be defined within the management system. Organizations read “or” as an either/or, define the controls they already had, and leave influence undefined — which documents the minority of the footprint, because control is unavailable for most environmental aspects in the first place.
That argument is worked through in full, with the evidence question and the 2015-to-2026 wording change, in MSI's article on ISO 14001 externally provided processes. For the purposes of a purchasing and supplier control procedure, the operative instruction is narrower. A purchasing and supplier control procedure needs an influence column beside the control column, and a blank influence column is a finding waiting to happen.
Transitioning To The 2026 Edition
Move a working ISO 14001:2015 system to 2026 in a week, not a quarter
If your environmental management system already works and only the documents need to catch up, the ISO 14001:2026 Procedure Templates and Guides were built for exactly that position. Written for experienced EHS managers: purchasing and supplier control, operational control, aspect identification, compliance obligations, and the new Clause 6.3 change process that mapping-table transitions quietly delete. Editable Word, the external-provision wording already resolved.
ISO 45001:2018 — the requirement that lives outside Clause 8
Clause 5.4 requires emphasis on the consultation of non-managerial workers on determining applicable controls for outsourcing, procurement and contractors. It sits in the leadership clause, not the operational one, which is why purchasing procedures almost universally miss it — the author of a purchasing and supplier control procedure is reading Clause 8, and the requirement is four clauses earlier.
It is also the easiest requirement in the standard to test, and it cannot be satisfied on paper. The question put to a worker is whether anyone asked them what the controls should be before the contractor arrived. No document produces a yes if the conversation did not happen. The ISO 45001 procedure set puts the consultation record inside the contractor approval route so it happens before mobilization rather than after an incident.
ISO 7101:2023 — the requirement no other standard contains
Clause 8.8 a) requires criteria for disqualifying external providers, defined alongside the criteria for evaluating, selecting and monitoring them. No other management system standard in common use asks this.
It is uncomfortable to write while entering a relationship, which is precisely why it belongs in a purchasing and supplier control procedure rather than in a conversation. At the moment a provider fails, the service is running, the alternative is unqualified, and there is real pressure to decide that this instance does not count. A criterion written a year earlier, by people not under that pressure, is the only thing that meets that moment honestly. Ask it of your most depended-upon provider first — that is the one where the answer is usually nothing.
Direct Answer
Each standard adds something a generic purchasing and supplier control procedure will miss: outsourced processes remaining inside the quality management system under ISO 9001 Clause 8.4.2 a); regulatory obligations and change notification under ISO 13485 with the FDA QMSR now in force; the influence half of “controlled or influenced” under ISO 14001:2026 Clause 8.1; worker consultation under ISO 45001 Clause 5.4; and disqualification criteria under ISO 7101 Clause 8.8 a).
The September Revision
What ISO 9001:2026 means for a purchasing and supplier control procedure
Settled. Unpublished. Write anyway.
ISO 9001:2026 publishes on 16 September 2026. The technical content was frozen when the Final Draft International Standard ballot closed, so the text is settled; what remains is publication and the start of a transition period expected to run roughly three years. Anyone writing a purchasing and supplier control procedure this quarter is therefore writing against a clause set that is about to be reissued, which raises a fair question: wait, or write?
Write. Two reasons, and the first is the more important one.
Every obligation described in this article is durable. The two-control determination, effect-based rating, criteria that are applied rather than collected, verification defined before release, an exception route with a named authority — none of these is an artefact of the 2015 numbering. They are what supplier control is, and no revision of any management system standard in the last thirty years has removed one of them. A purchasing and supplier control procedure built on those obligations survives a renumbering. A procedure built as a commentary on clause numbers does not.
The second reason is arithmetic. ISO 14001:2026 is already published and running to a hard deadline of 30 April 2029. When the quality revision lands in September, dual-certified organizations are running two clocks through one organization and one pool of auditor time — and auditor re-accreditation happens ahead of that queue. MSI's guide to running the ISO 9001 and 14001 transition as a single project works the sequencing out, and the companion analysis of when an ISO 9001:2026 consultant is actually warranted sets out the five conditions under which it is a documentation project rather than a consulting one. The documents you open anyway during a transition are the cheapest documents you will ever fix.
One caution, stated plainly because the temptation runs the other way: do not present 2026 expectations as requirements in force before publication. Clause numbering and exact wording for the sixth edition should be confirmed against the published text from ISO/TC 176/SC 2 on 16 September, not asserted from draft commentary. The mandatory 2026 work sitting on desks today is on the environmental side. What ISO 9001:2026 justifies right now is writing the quality-side procedure so that adopting the new edition is a cross-reference update rather than a rewrite — the same argument MSI makes for boardroom governance ahead of the revision and for multi-site networks rebuilding connective tissue while the documents are open.
Direct Answer
Do not wait for ISO 9001:2026 to write a purchasing and supplier control procedure. The standard publishes 16 September 2026 with a transition window expected to run about three years, and the obligations that make supplier control work — effect-based rating, the two-control determination, applied criteria, defined verification, a bounded exception route — are durable across revisions. Build on the obligations, cross-reference the clauses, and confirm the sixth edition's numbering against the published text rather than draft commentary.
The Abnormal Week
The exception path is not an appendix. It is the procedure.
Bound. Authorize. Log.
Every purchasing and supplier control procedure describes the normal case well and the abnormal case barely at all, which is precisely backwards. The normal case takes care of itself. Nothing goes wrong on the week when everyone is present, the approved provider has stock, and there is time to follow the process.
What happens on the other week? A line is down, the approved supplier cannot deliver until Thursday, and someone finds an alternative in twenty minutes. If the procedure has no route for that, the purchase still happens — it just happens with no rating, no controls, no authorization and no record. The absence of an exception route does not prevent exceptions. It prevents evidence of them.
A usable route names who can authorize, states which controls still apply, requires a log entry, and closes out afterwards. It also states the categories it is closed to, where no authorization can substitute for verification — high-hazard work, unlicensed waste carriers, unverified sterile or safety-critical items. An organization with no exception log has not eliminated exceptions; it has eliminated the record.
Contingency is the same argument on a longer timescale. If a significant provider stopped tomorrow, what stops, how quickly, and what is the alternative? Writing one page per significant provision now costs an afternoon. Working it out during the interruption costs considerably more, and the answers are worse. Sectors that have already been forced to formalize this — pharmaceutical supplier qualification is the clearest example — treat continuity as a qualification criterion rather than a business continuity afterthought.
Direct Answer
A purchasing and supplier control procedure needs a bounded exception path with named authority, applied controls, a log entry and a close-out, plus stated categories the route is closed to. Without one, urgent purchases still occur — with no rating, no controls and no record — and those are disproportionately the ones that cause incidents.
The Eight Elements
Eight elements every purchasing and supplier control procedure needs
Score them. Rank them. Fix one.
In MSI's client experience across manufacturing, technology, medical device, government, healthcare and other regulated industries, a purchasing and supplier control procedure that works in practice tends to be strong on the same eight elements, and organizations that struggle tend to be weak on the same ones.
- Requirement capture — every route a need can arrive by, including verbal requests, card purchases, donations and services arranged by other departments
- Impact determination — written criteria based on effect, with value deliberately excluded and anything unrated defaulting upward
- The two-control determination — provider-side and output-side controls decided and recorded separately
- Evaluation and selection — criteria that are applied rather than collected, with approval granted for a stated scope
- Agreed requirements — what reaches the provider, reviewed for adequacy before it is sent, and accepted by them
- Verification and release — defined per provision, recorded before release, with arriving documents read rather than filed
- Monitoring and re-evaluation — measures at a frequency set by the rating, with event triggers as well as intervals
- Exception and contingency — bounded, authorized, logged, and tested
A useful property of scoring a purchasing and supplier control procedure element by element is that it stops the improvement conversation from becoming a single verdict. Most organizations are not uniformly weak. They are strong on evaluation and weak on verification, or the reverse, and knowing which changes what you do on Monday. The free Purchasing and Supplier Control Maturity Check scores all eight, adds three questions specific to your standard, and gives you a band and a priority order without asking for anything first.
One caveat worth stating, because it is the most common failure that follows a good score: a correct document is not a working system. A purchasing and supplier control procedure can be complete against every element above while the program behind it has not re-evaluated a provider in two years. That distinction — and what breaks around month fourteen — is the subject of why supplier management programs fail in year two.
System Interfaces
Where a purchasing and supplier control procedure connects to everything else
Corrective action. Management review. Records.
A purchasing and supplier control procedure does not operate alone, and the interfaces are where implementations usually thin out. Supplier nonconformity has to enter the corrective action system rather than being handled by telephone. Outsourced processes have to appear in the internal audit program — and ISO 19011:2026, published on 27 May 2026, cancelled the 2018 edition outright with no transition period while strengthening attention to supply chains and interconnected, outsourced operations for exactly this reason. Internal audit planning that never samples an external provider is not testing the largest uncontrolled surface in the system.
Management review is where supplier data becomes a decision
Of all the interfaces, this is the one that decides whether the rest holds. Provider performance has to reach management review as data rather than as impressions — and the standards ask for it directly. ISO 9001 Clause 9.3.2 names the performance of external providers as a required input. ISO 13485 Clause 5.6.2 requires supplier-related information among its review inputs. ISO 14001:2026 Clause 9.3.2 requires information on environmental performance including audit results and compliance status, both of which reach into external provision. ISO 45001 and ISO 7101 carry their own equivalents. Management review is not an ISO 9001 exclusive, and a supplier program that reports to no one is a program that will drift.
In practice the failure is rarely refusal. It is that nobody decided what a supplier slide should contain, so it becomes a verbal summary from whoever attends — and a verbal summary cannot show a trend, cannot trigger a re-evaluation, and produces no traceable decision for the next audit to follow. The fix is to define the supplier inputs once, in the purchasing and supplier control procedure, and let the review agenda pull them: providers rated significant, re-evaluations due and overdue, exception log entries closed and open, nonconformities by provider, and the disqualification question asked out loud at least once a year.
Make The Meeting Produce Evidence
Supplier performance belongs on the agenda, with a record that survives the audit
MSI's ISO Management Review Toolkits give you the agenda, the input checklist, the data templates and the minutes structure — built per standard, so the required inputs are prompted rather than remembered. Supplier and external provider performance is one of them, which turns “how are our suppliers doing” into a tracked decision instead of a conversation.
Devices deserve a specific note here, because the review clause sits at 5.6 rather than 9.3 and its inputs differ: MSI's ISO 13485 management review guide sets out what a first-time review has to produce. On the environmental side, the ISO 14001:2026 management review is where a transition project is most efficiently governed.
Records, and the accreditation context
Records are the other dependency, and the one most often underestimated. Every determination described in this article produces a record, and those records only stay findable if the organization decided in advance where they live, who owns them and how long they are kept. That is a document and records control question rather than a purchasing one, but a purchasing and supplier control procedure written without those decisions made will produce evidence nobody can retrieve.
Accreditation context matters too: Global Accreditation Cooperation Incorporated replaced IAF and ILAC on 1 January 2026, so certification-body oversight of how these clauses are assessed now sits with a single body. In the United States, ANAB remains the accreditation body most MSI clients encounter, and ASQ's supplier quality resources are a reasonable free starting point for buyers building criteria from nothing.
Build Order
How to build a purchasing and supplier control procedure
Capture first. Criteria second. Controls third.
If you are writing a purchasing and supplier control procedure from scratch, the order that works is: capture routes first, then rating criteria, then the two control sets, then everything else. The first two are load-bearing — improvements to evaluation, verification or monitoring do not hold if requirements never enter the process or are rated on the wrong basis. The same dependency logic governs which procedure to write first across the whole system, which is what a genuinely effective ISO procedure gets right and a clause-restating one does not.
Start From A Working Document
The whole procedure library, written to one architecture, across five standards
The real cost of documenting a management system is not writing any one procedure — it is making them agree with each other. MSI's ISO Procedure Templates and Guides library covers ISO 9001, ISO 13485, ISO 14001:2026, ISO 45001 and ISO 7101, every procedure built to the same sixteen-section architecture so the set interlocks the day you download it. Editable Word, decisions already made and explained, records designed as a byproduct of the work.
If you want this one procedure rather than the library, the Purchasing and Supplier Control Procedure Template and Guide is a working procedure written as a filled-in example rather than an outline, in editable Word, with an evaluation record built to act as the approval gate, a provider register, a desk-level work instruction, a standard-specific fourth appendix, and the maturity ladder the check above scores against. One version per standard, 39 to 47 pages, at $149. Running more than one standard? The integrated ISO 9001, 14001:2026 and 45001 package writes one determination across three registers instead of three that quietly contradict each other, and the ISO 9001 procedure package covers the quality system end to end.
Score First. Fix Second. Buy Last.
Find out which of the eight elements is holding your score down
Twenty questions, about six minutes, five standard paths. You get your score, your band and the requirement your standard contains that the others do not — immediately, without entering anything. No email, no wait, no follow-up sequence.
If the result surprises you, or the priority order does not match what you expected, a conversation is usually quicker than a rewrite. MSI's ISO consulting practice has supported 80+ certifications and attended 200+ audits across 28 years, and a planning session on 760-434-9141 will tell you in half an hour whether your purchasing and supplier control procedure needs repair or replacement. If you would rather have the certification carried end to end, SurePath is the turnkey route and SureResults keeps the system current between audits. You can also read about The Portrait, MSI's independent operational assessment.
Common Questions
Purchasing and supplier control procedure: frequently asked questions
Asked. Answered. Actionable.
What is a purchasing and supplier control procedure?
A purchasing and supplier control procedure is the controlled document that defines how an organization identifies what it needs from outside, decides how much control each provider and each delivery requires, evaluates and selects providers against written criteria, communicates requirements, verifies what arrives, monitors performance, and handles the cases where the normal route cannot be followed. Under ISO 9001:2015 it addresses Clause 8.4 in full, including the requirement in 8.4.2 b) to determine controls on both the provider and the output.
Does ISO 9001 require a documented purchasing procedure?
ISO 9001:2015 does not mandate a document with a particular name, but it does require documented information to be retained for the evaluation, selection, monitoring and re-evaluation of external providers, and requires controls to be determined and applied. In practice a purchasing and supplier control procedure is the most straightforward way to satisfy those requirements coherently, and organizations that try to spread them across a purchase-order workflow and an approved supplier list generally leave 8.4.2 undischarged.
Why should suppliers not be rated on spend?
Because none of the five standards asks about price. They ask about effect — on the product, on the device, on the environment, on worker and service-user safety. Rating by value is correct in procurement and imported incorrectly into a purchasing and supplier control procedure, and it produces a system that watches the largest contracts closely while a low-cost consumable on which a control depends passes through unexamined.
How does ISO 13485 differ from ISO 9001 on purchasing?
The requirements sit at Clause 7.4 rather than 8.4, because ISO 13485:2016 predates the harmonized ten-clause structure, so the numbers do not map across. The substance differs too: control must be proportionate to the effect of the purchased product on the medical device, and a set of obligations arises from regulation rather than from the standard. Since the FDA Quality Management System Regulation took effect on 2 February 2026, incorporating ISO 13485:2016 into 21 CFR Part 820, supplier records are inspectable.
Does ISO 14001:2026 have a purchasing clause?
No, and that is why the requirements are so often missed. They are distributed across Clause 8.1, supported by 6.1.2 and the new Clause 6.3, and the operative wording is that external provision must be controlled or influenced, with the type and extent of both defined within the management system. Since control is unavailable for most environmental aspects, influence is the larger half of the obligation rather than the optional one.
What does ISO 45001 require that other standards do not?
Clause 5.4 requires emphasis on the consultation of non-managerial workers on determining applicable controls for outsourcing, procurement and contractors. It sits in the leadership clause rather than the operational one, which is why a purchasing and supplier control procedure written by reading Clause 8 alone will miss it. ISO 45001:2018 also carries the only dedicated procurement clause of the five, at 8.1.4, split across procurement, contractors and outsourcing.
Should I wait for ISO 9001:2026 before writing the procedure?
No. ISO 9001:2026 publishes on 16 September 2026 with a transition window expected to run about three years, and the obligations that make a purchasing and supplier control procedure work are durable across revisions — effect-based rating, the two-control determination, applied criteria, defined verification and a bounded exception route survive any renumbering. Build on the obligations, keep clause references in a cross-reference table that can be updated in an afternoon, and confirm the sixth edition's wording against the published text rather than draft commentary.
How long should a purchasing and supplier control procedure be?
Length is the wrong measure; completeness against the clause and usability on a busy day are the right ones. A purchasing and supplier control procedure that is trainable in one sitting, states thresholds rather than intentions, produces its records as a byproduct of the work, and defines what happens when the normal route fails will generally run to somewhere between thirty and fifty pages including its forms and a worked example. Considerably shorter usually means the exception path and the records are missing.
References
- ISO 9001:2015 — Quality management systems, Clause 8.4
- ISO/TC 176/SC 2 — the subcommittee responsible for ISO 9001, publishing the sixth edition 16 September 2026
- ISO 13485:2016 — Medical devices, Clause 7.4
- ISO 14001:2026 — Environmental management systems, Clause 8.1
- ISO 45001:2018 — Occupational health and safety, Clause 8.1.4
- ISO 7101:2023 — Healthcare organization management, Clause 8.8
- ISO 19011:2026 — Guidelines for auditing management systems, published 27 May 2026
- FDA Quality Management System Regulation — effective 2 February 2026
- 21 CFR Part 820 — Quality Management System Regulation, eCFR
- Federal Register — QMSR final rule amending the Quality System Regulation
- Global Accreditation Cooperation Incorporated — replaced IAF and ILAC on 1 January 2026
- ANAB — ANSI National Accreditation Board
- ASQ — supplier quality resources
- OSHA — respiratory protection standard and employer selection duties
- US EPA — hazardous waste generator requirements, including transporter and disposal facility obligations
- The ISO Survey — worldwide certificate counts by standard
About MSI
Diana Lynn is President and Principal ISO Consultant at Management Systems International (MSI), a consulting firm she co-founded in 1998. With 28 years of experience including extensive AS9100 implementation work in MSI's early years, MSI's track record includes 80+ certifications supported, 200+ audits attended, and 600+ professionals trained across manufacturing, technology, medical device, government, healthcare, and other regulated industries. Today MSI implements ISO 9001, ISO 13485, ISO 14001, and ISO 45001, with an expanding focus on ISO 7101 healthcare quality. MSI is veteran-owned and female-owned.
To talk through your own process, call 760-434-9141 or visit msi-international.com.
This article is general guidance and does not replace ISO 9001:2015, ISO 13485:2016, ISO 14001:2026, ISO 45001:2018, ISO 7101:2023, any applicable regulation, or the judgement of a competent professional. ISO 9001:2026 was not published at the time of writing; confirm its clause numbering and wording against the published text before relying on it. Standards are revised, amended and withdrawn; confirm the current status of your standard at iso.org before relying on clause references. Clause references were verified on 26 August 2026.