
Every audit includes a stop at the approved supplier list. And in a surprising number of otherwise healthy quality systems, that list is the least honest document in the building: forty suppliers, all marked “approved,” approval dates clustered suspiciously around the last certification audit, and a re-evaluation column that says “annual” next to entries nobody has looked at in three years.
The list isn’t the requirement. Clause 8.4 never mentions one. What it requires is harder and more useful: controls that match what each provider can actually do to your product, your process, or your customer.
What the clause actually asks for
Clause 8.4 breaks into three moves:
- Determine controls for externally provided processes, products, and services (8.4.1). You define criteria for evaluating, selecting, monitoring, and re-evaluating providers, based on their ability to supply to your requirements, and you keep documented information on those activities.
- Decide the type and extent of control (8.4.2). This is the proportionality clause: controls scale with the potential impact of what’s being provided and how effective the provider’s own controls are.
- Communicate requirements clearly (8.4.3). What you’re buying, how it will be accepted, competence requirements, what the provider must tell you, and whether you or your customer plan to verify anything at their site.
Notice the verbs: evaluate, select, monitor, re-evaluate. Two of those are ongoing. An approval decision made once, filed, and never revisited satisfies half the clause and fails the half that matters.
The proportionality most systems skip
The most common finding we raise against 8.4 isn’t a missing evaluation; it’s a flat one. Every supplier gets the same questionnaire, the same annual rubber stamp, the same row on the same list. The supplier of your one-source machined castings and the supplier of your break-room coffee get identical treatment, which means the castings supplier is under-controlled and the coffee supplier is generating paperwork for nothing.
Clause 8.4.2 is explicit that control should scale with potential impact. In practice that means tiers, and the tiers should be boring and defensible:
- Critical providers (single-source, product-touching, or providing a process you can’t verify afterward, like heat treat or sterilization): on-site or remote audits, defined performance metrics, first-article or lot-based verification, and a named owner.
- Standard providers (product-touching but replaceable, with verifiable output): receiving inspection or certificate review, performance tracked through NCR data, re-evaluation triggered by results rather than the calendar.
- Low-impact providers (nothing they ship can reach your customer): a purchase order and nothing else. Write down that this is deliberate. An auditor who sees a documented decision to apply minimal control to low-risk purchases reads it as risk-based thinking; an auditor who sees the coffee vendor scored on a 5x5 matrix reads it as a system nobody is actually using.
Monitoring is where the evidence lives
Selection evidence goes stale on the day it’s created. Monitoring evidence stays current by definition, and it’s the part auditors can trace end to end. The question we ask isn’t “show me the supplier’s approval record.” It’s “this receiving NCR from March names supplier X; show me where that fed their evaluation.”
That trace is the whole game. If receiving inspection failures, supplier corrective action requests, late deliveries, and the annual re-evaluation all live in separate files owned by separate people, the trace breaks, and with it the claim that you’re monitoring anything. The supplier’s score says 98 while the NCR log tells a different story, and the auditor is reading both.
A working system closes that loop mechanically: the NCR raised at receiving is linked to the supplier record, the supplier’s performance view is computed from those linked records rather than typed into a cell from memory, and a re-evaluation triggered by a bad quarter shows up as a dated decision with the evidence attached.
Communicating requirements: the quiet half of 8.4
Clause 8.4.3 gets less attention because it fails quietly. The purchase order says “per drawing.” The drawing is revision D. The supplier is building to revision C, because nobody’s document control reaches outside the building. Six weeks later there’s a receiving NCR, a disposition debate, and a supplier relationship strained by a failure that was structurally yours.
The requirement is to ensure adequacy of requirements before communicating them to the provider. Practically: purchase orders that reference document revisions explicitly, a controlled channel for getting revision changes to affected suppliers, and acceptance criteria the supplier saw before they built anything. If your document control system knows which suppliers hold which documents, a revision bump can notify them the same way it notifies your own shop floor. If it doesn’t, clause 7.5 and clause 8.4 fail together, and the finding will cite whichever one the auditor reaches first.
The test worth running before your next audit
Pick your three most consequential suppliers and walk each one through four questions. What were they evaluated against, and when? What events since then have fed their monitoring record? What would trigger a re-evaluation, and has anything come close? And if their last shipment failed receiving tomorrow, how many systems would you need to open to assemble the story?
If the answer to the last question is more than one, that’s the gap. Not because the auditor will count your open browser tabs, but because evidence that has to be assembled by hand is evidence that drifts, and supplier control that lives in five disconnected files isn’t control; it’s archaeology.
Clause 8.4 is ultimately a proportionality argument: prove you know which external providers can hurt you, and show the controls landing where the risk is. A short, honest, tiered system with live monitoring beats a long approved list every time, and it’s considerably less work to maintain.