SCRM Supplier Compliance & Risk Management

Home

ISO 9001:2015 · Clause 8.4

ISO 9001 does not ask whether you evaluate suppliers. It asks what proves it.

Clause 8.4 requires defined criteria, documented evaluation and recurring re-evaluation of your external providers. Audits rarely fail on a missing process. They fail on missing evidence.

ISO 9001:2015 covers suppliers under “externally provided processes, products and services”. The standard prescribes no particular method. It prescribes that you have one, apply it, and retain the results.

In practice the evaluation usually exists – in a spreadsheet updated once a year, shortly before the audit. Auditors notice. That is why findings rarely read “no evaluation”, and usually read “evaluation not traceable”, “criteria not defined” or “no evidence of re-evaluation”.

Who this concerns

  • Certified companies of any size – the requirement does not scale with headcount.
  • Manufacturing, medical devices, machinery and construction, where bought-in parts end up in the product.
  • Service firms that subcontract parts of their delivery and must evidence quality.

What the standard actually requires

8.4.1
Define and apply criteria for selection, evaluation, performance monitoring and re-evaluation of external providers.
8.4.1
Retain documented information on those activities and on any actions arising from them.
8.4.2
Determine the type and extent of control on a risk basis: a catalogue part does not need the depth of a single-source supplier.
8.4.3
Communicate requirements to the provider verifiably – qualification, release and changes included.
9.1
Analyse and evaluate the results and feed them into management review.

How SCRM covers it

Define criteria

Scoring schemes per supplier class, defined once, applied automatically from then on.

Monitor performance

Metrics, complaints and incidents attach to the supplier record instead of a separate document.

Re-evaluate

Cycles with automatic due dates and reminders. What is due appears on the dashboard.

Keep evidence

Every evaluation, change and document carries a timestamp and an author. The audit report is an export, not an all-nighter.

Frequently asked

Is a spreadsheet enough for ISO 9001?

Formally it can be, as long as criteria, evaluations and re-evaluations are documented traceably. In practice traceability is where it breaks: who changed what, when, and on what basis? That is exactly what the auditor asks.

How often must we re-evaluate?

The standard gives no interval. You define it on a risk basis and then keep to it. Annual cycles for critical suppliers and longer cycles for non-critical ones are common.

We are ten people. Isn’t this oversized?

Effort follows the number of suppliers, not the number of employees. A 15-person firm with 120 suppliers has precisely the same evidence problem as a corporation.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required