SCRM Supplier Compliance & Risk Management

Home

ISO 13485:2016 · clause 7.4

In medical devices, supplier evidence is part of the product file.

ISO 13485 requires defined criteria for selection, evaluation and re-evaluation, retained records of them, and verification of purchased product – proportionate to its effect on the device.

The standard is worded more strictly than ISO 9001 because it sits inside a regulatory framework. Authorities and notified bodies treat supplier documentation as part of the conformity evidence, not as an accessory.

For Switzerland, the medical devices ordinance closely follows European law, and manufacturers must evidence their supply chain to several bodies. Incomplete supplier evidence therefore delays not just an audit but potentially market access.

Who is affected

  • Manufacturers of medical devices and their representatives.
  • Contract manufacturers, sterilisation providers and test laboratories as suppliers.
  • Suppliers of components affecting safety or performance.
  • Providers of software used as part of a medical device.

What the standard requires

7.4.1
Define criteria for selection, evaluation and re-evaluation – graded by effect and risk.
7.4.1
Retain records of evaluations and any actions arising.
7.4.2
Specify purchasing information so that requirements are unambiguous.
7.4.2
Agree that the supplier notifies changes to the purchased product.
7.4.3
Verify purchased product to an extent proportionate to the risk.

How SCRM covers it

Effect classes

Suppliers graded by effect on safety and performance, with matching depth of scrutiny.

Change notifications

Change-notification commitments as a checked field with a named contact.

Unbroken history

Every evaluation with date, basis and person – as the file requires.

Evidence for authorities

Export of supplier documentation without assembling it from several stores.

Frequently asked

How does this differ from ISO 9001?

The structure is similar, but 13485 demands explicit grading by risk, more records and verification of purchased product. And oversight looks harder.

What if a supplier changes without notice?

That is precisely why the standard requires a change-notification agreement. Without one, the audit finding is near certain.

Does this cover software suppliers?

Once the software affects safety or performance, yes. It is treated like any other critical supplier.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required