SCRM Supplier Compliance & Risk Management

Home

IATF 16949:2016 · clause 8.4 with ISO 9001

In the automotive chain your responsibility does not end at your supplier.

IATF 16949 requires you to select, monitor and develop your suppliers – and to ensure they govern their own suppliers in turn.

The standard applies together with ISO 9001 and sharpens its clause 8.4 considerably. It requires a documented selection process with defined criteria, continuous performance monitoring against metrics, and a programme to develop suppliers towards a certified management system.

Customer-specific requirements from the manufacturers come on top and differ substantially between groups. In practice that is what generates the administration: the same supplier must satisfy different customer rules, and you must evidence which applied when.

Where findings arise

  • A selection process without documented criteria, or without evidence they were applied.
  • Performance monitoring that counts complaints and knows no agreed metrics.
  • No development programme for suppliers without a certified system.
  • Sub-tier suppliers whose governance is described nowhere.
  • Second-party audits without evidence of the auditor’s qualification.

What the standard requires

8.4.1.2
A documented selection process with criteria and risk assessment.
8.4.2.3
Development of suppliers towards a certified quality management system.
8.4.2.4
Performance monitoring against defined metrics, with response to deviation.
8.4.2.5
Second-party audits with criteria justifying scope and frequency.
8.4.1.1
Ensure requirements are passed down to the sub-tier.

How SCRM covers it

Metrics on the supplier

Delivery and quality data where they feed the evaluation.

Development status

Where each supplier stands on the path to certification – a field, not a memory.

Customer requirements

Which manufacturer’s rule applies to which supplier, with dates.

Audit programme

Second-party audits justified from the risk class, with action tracking.

Frequently asked

Does this reach second-tier suppliers?

You must ensure requirements are passed on. How deeply you verify yourself is a reasoned risk decision – organising the pass-through is not optional.

What is a second-party audit?

An audit you conduct at your supplier as their customer. The standard requires criteria for scope and frequency and a qualified auditor.

Is ISO 9001 at the supplier enough?

Often as a starting point, depending on customer rules. The standard nevertheless expects a programme that carries the development further.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required