Medical-device manufacturers are being pushed towards tighter oversight of suppliers just as the definition of a “critical” vendor is widening. The FDA’s Quality Management System Regulation took effect on 2 February 2026, aligning US device quality requirements with ISO 13485:2016, while an IMDRF consultation on new supplier-controls guidance ran from 6 May to 6 July and set out a far broader, lifecycle-based model for supervising outsourced products and services. Accor...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
That is the backdrop to Oliver Norman’s warning that device makers may be paying too little attention to the long tail of smaller vendors. In a commentary first published by Medical Device Network and republished by Yahoo Finance on 1 September, Norman, Nomia’s chief revenue officer, argued that low invoice values can hide suppliers whose work touches validated systems, controlled production areas, inspection equipment or quality records. The same article was also carried by Bull Markets Today later that day, with YahooFinance identified there as the original source, showing the argument spreading beyond a specialist device audience. (finance.yahoo.com)
Norman’s broader writing suggests this is not a marginal procurement problem. In a June article for ManufacturingTomorrow, he said roughly 20-30% of third-party spend in many manufacturing businesses sits in the tail: ad hoc, low-value buying across maintenance, repair and operations, logistics support, IT tools and other non-strategic purchases. He said those decisions are often taken close to the plant floor, especially when equipment fails or urgent maintenance is needed, and that the result is frequently supplier duplication, inconsistent pricing and weak visibility across sites. (manufacturingtomorrow.com)
In medical devices, those visibility gaps matter because accountability does not disappear when work is outsourced. Medmarc, in an August article on supplier oversight, said manufacturers remain responsible for the quality, safety and performance of the finished device, warning that a supplier’s mistake can quickly become an FDA inspection, a recall or litigation. It also noted that vendors such as software developers, sterilisation facilities, calibration laboratories and biocompatibility testing laboratories can materially affect compliance and patient safety even when they do not manufacture a finished product themselves. (medmarc.com)
That regulatory direction also helps explain why the old habit of leaning on certificates is coming under pressure. NSF said the IMDRF draft explicitly warns manufacturers not to rely on ISO certification alone, and instead to gather objective evidence such as audits, testing data, first articles, prototypes and subcontractor controls. The draft, as described by NSF, also calls for formal approval records that define the supplier, the approved scope, expiry dates, restrictions, evaluation results and the responsible authorised person. It broadens the list of relevant supplier types to include software, AI-related software, clinical and pre-clinical services, packaging, calibration, transport and storage. (nsf.org)
Norman’s proposed answer is less dramatic than a wholesale procurement overhaul and more administrative: build a single, dependable supplier record that joins up data usually split between finance systems, contract repositories, spreadsheets and quality files. In the Medical Device Network article republished by Yahoo Finance, he said that record should bring together ownership, location, services, spend, contracts, supported sites, qualification status, certificates, audit outcomes, incidents, corrective actions, performance history and review dates, so that controls can be calibrated to what a supplier actually does rather than how much it bills. That would mean, for example, that a cleanroom maintenance contractor or software vendor with access to quality data could receive closer scrutiny than a higher-spend but lower-risk indirect supplier. (finance.yahoo.com)
He is equally clear that software cannot settle the matter on its own. Norman has argued in both the medical-device piece and his broader manufacturing writing that AI can help reconcile duplicate supplier names, classify spend, extract information from contracts or certificates, and flag gaps or expiry dates at scale. But he has also said decisions still need judgement from procurement, quality, regulatory, engineering, cyber-security and operations teams, because the same service can present very different risks depending on whether it is being delivered in an office, on a warehouse floor or inside a validated production environment. (finance.yahoo.com)
His resilience argument has become sharper in more recent commentary. Writing for CPOstrategy on 2 September, Norman said extreme weather can turn obscure suppliers into essential ones very quickly. He pointed to Met Office warnings that heat can buckle rails, sag overhead cables and soften road surfaces, and said water companies can also face sudden demand spikes during hot spells. He added that during this summer’s European heatwave, low water levels on the Rhine cut diesel-barge loads through Kaub in Germany to about 45% of normal capacity at one stage. In that sort of disruption, he argued, organisations need fast visibility of which alternative vendors have already been approved and where they operate, rather than starting due diligence from scratch. (cpostrategy.media)
The consequence for device makers is that tail spend is becoming harder to dismiss as back-office clutter. Medmarc said oversight often weakens after onboarding, even though ownership changes, staffing churn, production expansion or declining CAPA responsiveness can alter a supplier’s risk profile over time. Its recommendation was for data-led monitoring of nonconforming material trends, complaints, audit findings and recurring deviations, while Norman’s version of the same argument is to fold smaller suppliers into ordinary quality governance instead of treating them as a procurement side issue. With QMSR now in force and IMDRF signalling tougher, risk-based expectations, that looks less like a nice-to-have clean-up project than preparation for the next inspection, disruption or supplier failure. (medmarc.com)
Source: Noah Wire Services



