Under ISO 13485, organizations are expected to apply controls to suppliers, contractors, and consultants based on the effect their products or services can have on the quality of the medical device. That sounds straightforward in theory. In practice, many companies struggle with how much qualification is enough, which suppliers require the most scrutiny, and how to build a process that is both compliant and workable.
At Avendium, we often see supplier qualification become more difficult as companies grow. New vendors are added quickly. Roles and responsibilities become blurred. Documentation is inconsistent. Critical suppliers are not always distinguished from lower-risk vendors. Over time, the process becomes reactive instead of risk-based.
This article provides a practical guide to supplier qualification under ISO 13485 and outlines the core elements companies should have in place to build a strong, sustainable supplier control process.
Why supplier qualification matters
A company’s quality system does not stop at its own walls. If a supplier provides materials, services, software, calibration, sterilization, testing, packaging, storage, or other support that can affect product quality or regulatory compliance, that supplier becomes part of the broader quality ecosystem.
Weak supplier qualification can lead to serious downstream issues, including:
• Product nonconformities
• Delays in manufacturing or release
• Inadequate traceability
• Inaccurate test results or calibration issues
• Software or data integrity risks
• Audit findings and inspection observations
• Increased complaint, CAPA, or change control activity
A well-designed supplier qualification process helps reduce these risks by ensuring suppliers are evaluated appropriately before approval and monitored over time based on the level of risk they present.
What ISO 13485 expects
From a practical standpoint, ISO 13485 expects organizations to evaluate and control suppliers in a way that is proportionate to their impact on product quality. This means companies should not treat all suppliers the same.
A supplier that provides office supplies should not be managed the same way as a contract manufacturer, sterilization provider, raw material supplier, critical software vendor, or calibration service provider. The qualification process should reflect that difference.
In practical terms, companies should be able to demonstrate that they:
• Define criteria for supplier evaluation and selection
• Evaluate suppliers before approval, as appropriate
• Determine the type and extent of control based on risk
• Maintain records of evaluation, qualification, and monitoring
• Reassess suppliers periodically or when issues arise
• Ensure purchasing information clearly communicates requirements
The goal is not to create unnecessary paperwork. The goal is to ensure supplier controls are appropriate, documented, and defensible.
Start with supplier classification
One of the most important steps in building an effective supplier qualification process is classifying suppliers according to risk.
Too often, companies attempt to use a one-size-fits-all approach. This either creates too much administrative burden for low-risk vendors or too little oversight for higher-risk suppliers.
A practical supplier classification model often includes categories such as:
Critical suppliers
These suppliers provide products or services that can directly affect product quality, safety, regulatory compliance, or released product.
Examples may include:
• Contract manufacturers
• Sterilization providers
• Critical raw material suppliers
• Calibration or metrology providers for critical equipment
• External laboratories performing product testing
• Software providers supporting GMP or quality system functions
• Key packaging or labeling suppliers
Critical suppliers typically require the highest level of qualification and ongoing oversight.
Major suppliers
These suppliers may affect operations or quality indirectly, but generally present less direct risk than critical suppliers. Examples may include:
• Secondary material suppliers
• Equipment maintenance providers
• Certain logistics or storage providers
• Some consulting or technical service providers
These suppliers still require documented evaluation, but the qualification depth may be less extensive.
Minor suppliers
These are vendors with low or no meaningful impact on product quality or compliance, such as office supply vendors or general administrative service providers.
These suppliers usually require minimal qualification controls.
Use a risk-based approach
ISO 13485 expects supplier controls to be proportionate to risk. That means supplier qualification should be guided by questions such as:
• Does this supplier affect product quality or patient safety?
• Does this supplier support regulated processes or records?
• Could a failure by this supplier impact compliance or released product?
• How easily could the issue be detected before it affects the product?
• Is the supplier providing a critical outsourced process?
• Does the supplier have a history of quality or delivery issues?
The answers to these questions should determine the qualification pathway.
For example, a critical supplier may require a more robust initial evaluation that includes a questionnaire, document review, risk assessment, and on-site or virtual audit. A lower-risk supplier may be qualified through a questionnaire, reference checks, business review, website review, or certificates alone, depending on the nature of the service.
The key is to be intentional and documented in your approach.
Core elements of supplier qualification
A practical supplier qualification process under ISO 13485 should include several core elements.
1. Defined qualification criteria
Before evaluating suppliers, the organization should define what it is looking for. Qualification criteria often include:
• Quality system maturity
• Certifications, where relevant
• Technical capability
• Regulatory understanding
• Ability to meet specifications
• Financial or business stability
• Delivery performance
• Data security or software controls, if applicable
• Responsiveness and communication
These criteria do not need to be identical for every supplier, but they should be consistent enough to support objective decision-making.
2. Initial supplier evaluation
Initial qualification should be performed before approval for use, where appropriate. Depending on risk, this may involve:
• Supplier questionnaire
• Review of certifications
• Review of quality agreements or terms
• Review of sample reports, specifications, or validation summaries
• Risk assessment
• Audit reports or third-party audit evidence
• On-site or virtual audit
• Reference checks or business history review
Companies should avoid relying on certifications alone without considering the supplier’s actual role and risk profile.
3. Supplier approval decision
Once the evaluation is complete, the company should make a formal decision regarding supplier status.
Common statuses may include:
• Approved
• Approved with restrictions
• Conditionally approved
• Pending additional information
• Disqualified or not approved
This decision should be documented and, where needed, limited to a defined scope. A supplier may be approved for one material, service, or site, but not for others.
4. Approved supplier list
An approved supplier list or equivalent controlled record is essential. This should clearly identify:
• Supplier name
• Supplier category or type
• Risk classification
• Approval status
• Date of qualification or approval
• Scope of approval
• Requalification or review date, if applicable
This record allows the organization to demonstrate control and avoid inconsistent supplier usage across departments.
5. Ongoing monitoring
Qualification is not a one-time event. Suppliers should be monitored over time based on their importance and performance.
Monitoring activities may include:
• On-time delivery performance
• Nonconformance trends
• Complaint history
• Audit findings
• Change notifications
• CAPA responsiveness
• Quality of service or deliverables
• Periodic review of certifications or documentation
A supplier that was acceptable at the time of approval may become higher risk later if performance declines or the scope of work changes.
6. Requalification or periodic review
Companies should define when suppliers must be reassessed. This may be based on time, risk, performance, or triggering events.
Triggers for requalification may include:
• Significant quality issues
• Repeated delivery failures
• Major process or site changes
• Changes in ownership
• Lapse of certification
• Expansion in service scope
• Regulatory issues or warning signs
• Extended inactivity followed by resumed use
The process should be practical and tied to actual risk, not just calendar-driven administration.
Common mistakes companies make
Even organizations with good intentions often fall into the same supplier qualification traps.
Treating all suppliers the same
This creates wasted effort on low-risk vendors and insufficient control over high-risk suppliers.
Over-relying on certificates
An ISO certificate or similar credential can be useful, but it does not replace a risk-based review of the supplier’s role, scope, and actual controls.
Failing to define scope of approval
A supplier may be acceptable for one service or material but not broadly approved for everything the organization purchases from them.
Weak documentation
If the rationale for supplier approval is not documented, it becomes difficult to defend during audits or inspections.
No clear ownership
Supplier qualification often falls between Quality, Procurement, Operations, and Technical teams. Without clear ownership, approval decisions and monitoring can become inconsistent.
No ongoing monitoring
A supplier should not disappear from oversight once added to the approved list.
How to make the process practical
A compliant supplier qualification system does not need to be overly complex. In fact, simpler systems are often more effective if they are clear, risk-based, and consistently followed.
A practical model usually includes:
• A supplier qualification SOP
• A risk-based classification method
• A standard questionnaire
• Defined criteria for when an audit is required
• An approved supplier list
• A periodic review process
• Clear roles between Quality and Procurement
• Templates for evaluations, risk assessments, and approvals
It is also helpful to separate the high-level policy from detailed work instructions. The SOP should explain the framework and expectations. Supporting forms or work instructions can handle operational detail without making the SOP unwieldy.
How Avendium helps
At Avendium, we help medical device, diagnostics, and life science companies design and improve supplier qualification programs that are practical, scalable, and aligned with regulatory expectations.
That support may include:
• Supplier qualification SOP development or revision
• Risk-based supplier classification frameworks
• Supplier questionnaires and assessment templates
• Approved supplier list structure
• Remediation of legacy supplier files
• Gap assessments tied to ISO 13485 or broader quality system requirements
Our goal is to help organizations build supplier controls that work in the real world, not just on paper.