A supplier management programme rarely collapses at the certification audit. More often, it withers quietly months later, after the auditor has gone, in a folder no one has opened and a spreadsheet no one has updated. The failure only becomes visible when a surveillance auditor, a customer or a regulator asks a simple question the programme was never built to answer: what has this supplier done for you lately, and where is the evidence?
That distinction matters. A purchasing pr...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
In practice, that is the most common weakness MSI says it sees across the standards it implements. The problem is not simply administrative. It has become more expensive because the regulatory and standards landscape has shifted. The FDA’s Quality Management System Regulation took effect on 2 February 2026, bringing medical device purchasing controls under ISO 13485 Clause 7.4. ISO 14001:2026, published on 15 April 2026, widened the wording around externally provided processes, products and services. ISO 9001:2026 is due on 16 September 2026. In each case, the pressure lands at the supplier interface.
The deeper issue is that many organisations confuse a procedure with a programme. Certification can reward a well-written document; it cannot prove that the document still governs real-world decisions two years later. That only becomes clear at surveillance, when the question is no longer whether the process exists, but whether it still works.
A functioning supplier management programme has four traits. First, its data are live rather than archival: every supplier record should show when it was last reviewed, not just when it was approved. Secondly, it runs on defined triggers, not vague habits. A change of ownership, a manufacturing move, a new sub-processor, a nonconformity, a delivery failure or a regulatory action should all force a fresh look. Thirdly, it uses weighted criteria rather than a single generic score. Finally, it stores evidence in a way that can be retrieved quickly, because if the record cannot be produced in minutes, it is not really controlled.
MSI’s view is that most programmes fail in the same way: a well-drafted procedure sits on top of an approved supplier list that has not changed in years. The list reflects the business at the point of certification, not the business as it exists now. New suppliers are added informally, emergency arrangements become permanent, and no one notices the drift until an audit sample exposes it.
The biggest fix is often the simplest. Re-evaluation should not depend on a calendar reminder alone. The standards all require re-evaluation, but none of them prescribes a single interval. The organisations that keep their programmes intact build in event-based triggers and make sure those triggers are tied to actual business processes. Annual review can remain a backstop, but it should never be the only mechanism.
The scorecard itself is another common point of failure. Many organisations rely heavily on what is easiest to measure: on-time delivery, price variance, defect rates. Those are useful, but they do not necessarily reflect the risk the standards care about. A supplier can be cheap and punctual while creating a major environmental exposure, safety hazard or product risk. A better model separates criticality from performance: criticality describes the supplier’s role and the consequences of failure, while performance measures behaviour over time. That distinction allows an organisation to spend its effort where the risk is greatest.
The records also need discipline. Certificates, corrective action replies and delivery discussions often live in email inboxes, which means the history disappears when people change roles. A supplier management programme should treat those exchanges as controlled records, not informal correspondence. Without that discipline, the organisation loses continuity precisely when it needs it most.
The standards approach the same interface from different angles, but they all demand sustained oversight. ISO 9001 Clause 8.4 requires evaluation, selection, monitoring and re-evaluation of external providers, with controls proportionate to their effect on conformity. ISO 13485 Clause 7.4 requires criteria proportionate to device risk and the supplier’s effect on product quality, alongside monitoring, re-evaluation and documented action where requirements are not met. Under the QMSR, that expectation is now directly relevant in the United States.
ISO 14001:2026 extends the environmental requirement beyond outsourced processes to externally provided processes, products and services, with a clear expectation that organisations determine what they can control or influence. It also brings in downstream considerations, including transport, use and end-of-life treatment, which many supplier programmes have historically ignored. ISO 45001 Clause 8.1.4 goes further into the safety relationship, requiring control of procurement, coordination with contractors and control of outsourced functions. ISO 7101 Clause 8.8, meanwhile, addresses partnering stakeholders in healthcare and requires documented expectations, including for donated or grant-funded provision.
Taken together, those clauses point to the same design rule: one supplier record, several determinations. Quality asks what the provider does to product conformity. Environmental management asks what it does to the aspect register. Safety asks how contractor risk is coordinated across a shared workplace. Healthcare asks what has been agreed and how failure will be communicated. A single generic questionnaire is usually too crude to handle all that properly.
The most effective re-evaluation triggers are straightforward. Ownership changes matter because they alter process and priorities. Site changes matter because they can alter the way a product or service is made. A new sub-processor matters because risk travels through the supply chain. Nonconformities, complaints and safety incidents should all feed back into the supplier record. So should changes in certification status, regulatory status or the organisation’s own risk profile. A supplier that was acceptable last year may be critical this year for reasons entirely outside the supplier’s control.
That is why notification clauses matter. Change of site, change of ownership and change of sub-processor should be written into contracts, particularly for critical suppliers. If the organisation is not told about the event, it cannot react to it in time.
Spending remains one of the most common but least useful ways to rank suppliers. The amount spent tells you little about the risk carried by the supplier. A low-cost component may be vital to patient safety; a high-value office supplier may be relatively low risk. Criticality should therefore be set by consequence, not invoice value. Performance can then be measured against thresholds appropriate to the criticality band.
The same logic applies to management review. Supplier performance should not arrive as a loose verbal update. It should come in as a clause-mapped input, showing trends, overdue re-evaluations, repeated failures and emerging risks. Only then can leadership make sensible resourcing decisions.
Digitisation can help, but it does not solve the underlying judgement calls. Software can consolidate supplier data, pull in audit findings, complaint information, incoming inspection results and performance measures, and make the history visible. It cannot decide which supplier is critical, which trigger applies or what level of influence the organisation can reasonably exert. Those decisions still belong to the management system.
For organisations whose supplier programmes have drifted, MSI suggests a ninety-day rebuild rather than a wholesale reinvention. First reconcile the approved supplier list against actual transactions. Then re-band suppliers by criticality. Next write the trigger list and notification clauses. After that, set thresholds by band and run one real cycle. Finally, bring the results to management review and decide whether the current data structure is sustainable. That sequence forces the programme back into alignment with the business.
The pattern across audits is consistent. Supplier ISO certificates are often mistaken for proof of control, but they only show that a supplier runs a management system of its own. They do not show that it addresses your requirements. Re-evaluation is frequently left to both purchasing and quality, with neither truly owning it. The strongest programmes are those that name a single owner, tie the process to real triggers and treat supplier engagement as a two-way relationship rather than a compliance exercise.
A supplier management programme that will still stand up in year three is not the one with the prettiest procedure. It is the one that reconciles its supplier list to reality, ranks suppliers by effect rather than spend, re-evaluates them when something changes, stores evidence where it can be found and reports meaningful trends to leadership. Everything else is support.
Source: Noah Wire Services



