IATF 16949:2016 · clause 8.4 with ISO 9001
In the automotive chain your responsibility does not end at your supplier.
IATF 16949 requires you to select, monitor and develop your suppliers – and to ensure they govern their own suppliers in turn.
The standard applies together with ISO 9001 and sharpens its clause 8.4 considerably. It requires a documented selection process with defined criteria, continuous performance monitoring against metrics, and a programme to develop suppliers towards a certified management system.
Customer-specific requirements from the manufacturers come on top and differ substantially between groups. In practice that is what generates the administration: the same supplier must satisfy different customer rules, and you must evidence which applied when.
Where findings arise
- A selection process without documented criteria, or without evidence they were applied.
- Performance monitoring that counts complaints and knows no agreed metrics.
- No development programme for suppliers without a certified system.
- Sub-tier suppliers whose governance is described nowhere.
- Second-party audits without evidence of the auditor’s qualification.
What the standard requires
- 8.4.1.2
- A documented selection process with criteria and risk assessment.
- 8.4.2.3
- Development of suppliers towards a certified quality management system.
- 8.4.2.4
- Performance monitoring against defined metrics, with response to deviation.
- 8.4.2.5
- Second-party audits with criteria justifying scope and frequency.
- 8.4.1.1
- Ensure requirements are passed down to the sub-tier.
How SCRM covers it
Metrics on the supplier
Delivery and quality data where they feed the evaluation.
Development status
Where each supplier stands on the path to certification – a field, not a memory.
Customer requirements
Which manufacturer’s rule applies to which supplier, with dates.
Audit programme
Second-party audits justified from the risk class, with action tracking.
Frequently asked
Does this reach second-tier suppliers?
You must ensure requirements are passed on. How deeply you verify yourself is a reasoned risk decision – organising the pass-through is not optional.
What is a second-party audit?
An audit you conduct at your supplier as their customer. The standard requires criteria for scope and frequency and a qualified auditor.
Is ISO 9001 at the supplier enough?
Often as a starting point, depending on customer rules. The standard nevertheless expects a programme that carries the development further.