ISO 13485:2016 · clause 7.4
In medical devices, supplier evidence is part of the product file.
ISO 13485 requires defined criteria for selection, evaluation and re-evaluation, retained records of them, and verification of purchased product – proportionate to its effect on the device.
The standard is worded more strictly than ISO 9001 because it sits inside a regulatory framework. Authorities and notified bodies treat supplier documentation as part of the conformity evidence, not as an accessory.
For Switzerland, the medical devices ordinance closely follows European law, and manufacturers must evidence their supply chain to several bodies. Incomplete supplier evidence therefore delays not just an audit but potentially market access.
Who is affected
- Manufacturers of medical devices and their representatives.
- Contract manufacturers, sterilisation providers and test laboratories as suppliers.
- Suppliers of components affecting safety or performance.
- Providers of software used as part of a medical device.
What the standard requires
- 7.4.1
- Define criteria for selection, evaluation and re-evaluation – graded by effect and risk.
- 7.4.1
- Retain records of evaluations and any actions arising.
- 7.4.2
- Specify purchasing information so that requirements are unambiguous.
- 7.4.2
- Agree that the supplier notifies changes to the purchased product.
- 7.4.3
- Verify purchased product to an extent proportionate to the risk.
How SCRM covers it
Effect classes
Suppliers graded by effect on safety and performance, with matching depth of scrutiny.
Change notifications
Change-notification commitments as a checked field with a named contact.
Unbroken history
Every evaluation with date, basis and person – as the file requires.
Evidence for authorities
Export of supplier documentation without assembling it from several stores.
Frequently asked
How does this differ from ISO 9001?
The structure is similar, but 13485 demands explicit grading by risk, more records and verification of purchased product. And oversight looks harder.
What if a supplier changes without notice?
That is precisely why the standard requires a change-notification agreement. Without one, the audit finding is near certain.
Does this cover software suppliers?
Once the software affects safety or performance, yes. It is treated like any other critical supplier.