What you will learn
By the end of this topic, you should be able to classify suppliers by risk, perform proportionate selection and evaluation, create effective purchasing and quality agreements, verify supplied outputs and maintain control of changes and performance.
Activity can be outsourced; accountability cannot
Suppliers may design components, write software, test devices, manufacture assemblies, sterilise product, host data or provide complete finished devices. The manufacturer still owns the requirements, regulatory consequences, risk decisions and adequacy of resulting evidence.
The extent of supplier control should reflect the effect of the supplied product or service on device safety, performance, compliance and continuity of supply.
Classify suppliers by consequence and detectability
Classification should consider what is supplied, whether failure could affect a critical requirement or risk control, whether the output can be fully verified on receipt, regulatory significance, access to sub-tier information and availability of alternatives.
Critical
Failure could directly affect safety, essential performance, sterility or regulatory conformity.
Significant
Failure could disrupt quality or performance but is detectable through practical controls.
Standard
Low-consequence outputs with readily verified requirements and substitutes.
Service
Laboratories, consultants, software platforms and logistics providers assessed for their actual influence.
Do not let spend value or supplier size substitute for product-risk evaluation.
Evaluate capability before approval
- Technical capability and understanding of the specification.
- Quality-system maturity and applicable certifications.
- Process capability, equipment, facilities and personnel.
- Validation, test, cybersecurity or data-integrity competence where relevant.
- Regulatory history, audit results and corrective-action performance.
- Capacity, resilience, obsolescence planning and financial stability.
- Control of sub-tier suppliers and outsourced activities.
Approval should define scope. A supplier capable of one component, site or process is not automatically approved for another.
Make purchasing information unambiguous
A quality agreement complements, but does not replace, a technically complete specification. Ensure commercial contracts do not contradict quality obligations.
Verify supplied outputs proportionately
Incoming inspection is one possible control, not the default answer. Verification may combine supplier validation, certificates, source inspection, audits, monitoring, independent testing and receiving checks.
Where output cannot be fully verified later—such as sterilisation, a critical coating or some software services—place greater emphasis on process definition, validation, supplier oversight and change control. Record the basis for any reduced inspection or supplier-data reliance.
Monitor performance and act on signals
Use measures that reflect risk: defect and escape rates, delivery, deviations, audit findings, change-notification compliance, complaints, response quality and corrective-action effectiveness. Review trends, not just monthly averages.
Define escalation, conditional approval, increased verification, corrective action, suspension and disqualification rules. Supplier development may be appropriate, but repeated acceptance of unexplained failure is not control.
Control changes, sub-tiers and continuity
Agreements should require timely notice of relevant material, process, site, equipment, software, sub-tier, test-method and quality-system changes. The manufacturer then assesses verification, validation and regulatory impact before approval.
Plan for single-source parts, obsolescence, disasters and loss of specialist services. Continuity controls must preserve configuration and quality, not merely find replacement supply.
Common misconceptions
“ISO 13485 certification proves the supplier is suitable.”
Certification is useful evidence, but does not establish capability for the specific output, process or risk.
“Purchasing owns supplier quality.”
Effective control requires engineering, quality, regulatory, operations and commercial input.
“A certificate of conformity replaces verification.”
Reliance on supplier evidence must be justified by requirements, capability and monitored performance.
Authoritative external references
- ISO 13485:2016 — Medical devices — Quality management systems
- FDA — Quality Management System Regulation (QMSR)
- Regulation (EU) 2017/745 on medical devices
Apply contractual, regulatory and quality-system controls appropriate to the supplied output and target markets.
Control the supplied outcome in proportion to its risk
Define what matters, select capable suppliers, verify objective evidence, monitor performance and retain authority over every consequential change.