Skip to main content

ISO 9001: keep your suppliers in order under clause 8.4

ChainSec keeps your suppliers in order — who is approved, which certificates are valid, when each one is due for re-evaluation and which nonconformities are open. When the auditor asks, the answer is an export.

Is ChainSec an ISO 9001 system?

No. ChainSec is not an ISO system and does not replace your management system — no document control, no process maps, no internal audit. We solve some parts. Your management system is the whole company, the suppliers are one tab in it, and that tab is the one the auditor asks about under clause 8.4.

ClauseWhat ISO 9001 requiresWhere it is done
8.4.1Criteria for the evaluation, selection, monitoring and re-evaluation of external providers, and documented information on each step.ChainSec
8.4.2Controls proportionate to how much the provider affects your ability to meet customer requirements.ChainSec — classification and re-evaluation interval per supplier
8.4.3Requirements communicated to the provider before a contract or purchase order.Partly — questionnaires and documents in ChainSec, the requirements in your contracts and purchase orders
10.2Nonconformities handled with action, root cause analysis and a check that the action worked.ChainSec for supplier nonconformities, your management system for internal ones
6.1Risks and opportunities are identified and addressed.The Risk and requirements add-on
7.5, 9.2, 9.3Document control, internal audit and management review.Your management system

What does ISO 9001 require of suppliers?

Clause 8.4 requires you to evaluate, select, monitor and re-evaluate the external providers that affect your ability to meet customer requirements. The criteria must be documented, the controls must be proportionate to the provider’s impact, and you must be able to show what was done.

An external provider is a broader concept than purchasing. It also covers outsourced processes such as IT operations, calibration and group companies outside the scope of your management system — and the responsibility stays with you even when someone else does the work.

Supplier register in ChainSec

Supplier work, from spreadsheet to audit export

Supplier follow-up is often someone’s job on the side of their real job. These are the steps, in the order most teams take them.

01

Keep the spreadsheet — it is the onboarding

Export your spreadsheet to CSV and import it. Imported suppliers are approved on arrival, and the history shows they came in through the import.

02

Classify and set a re-evaluation interval

Classify each supplier by how much it affects your delivery and choose how often it is re-evaluated: every three, six or twelve months. That makes the proportionate control in 8.4.2 visible per supplier.

03

Evaluate and collect evidence

Send questionnaires to the critical suppliers, score the answers and upload ISO 9001, 14001 and 45001 certificates with their expiry dates. A ready-made ISO 9001 template is on the way; until then you build the questionnaire yourself.

04

Review and re-evaluate with history

Every review is logged with date, outcome and who did it. Checklists per supplier keep track of the steps that need doing each time.

05

Export the approved supplier list

An export with status, latest review and certificate validity. It is the first document an auditor or a large customer asks for.

Supplier nonconformities and complaints

A complaint that only exists in an email does not hold up in an audit. The auditor wants to see that it was followed up: what happened, what the supplier replied, which action was taken and that someone verified it worked. In ChainSec the nonconformity belongs to the supplier, and open nonconformities stay in the to-do list until they are closed.

Record

What happened, the source — complaint, audit finding or questionnaire answer — severity and who is responsible. The responsible person can be someone in purchasing or production without a ChainSec account.

Follow up

Action, root cause and the supplier’s response in one place. A flagged questionnaire answer can become a nonconformity straight from the review.

Verify and close

Someone verifies that the action worked, and ChainSec records who and when. Closing an unfounded complaint without verification requires an explanation that is logged separately.

How often should suppliers be re-evaluated?

ISO 9001 sets no fixed interval. The requirement is that you have criteria for re-evaluation and can show that you follow them. A common approach is yearly re-evaluation of critical suppliers and less often for the rest, plus re-evaluation after events such as a serious nonconformity or a change of ownership.

A missed re-evaluation is one of the most common findings in a surveillance audit. The company evaluated the supplier at the start and never again. In ChainSec every supplier has its own interval and a history showing when it was last reviewed.

Three common objections

“We use Excel.”

Excel is not bad. It just does not tell you when a certificate has expired or a re-evaluation is overdue, and the auditor asks for history the spreadsheet overwrites. You keep the spreadsheet — it becomes the import file.

“Our management system already does this.”

Many management systems include a supplier evaluation form. The difference is a supplier register that keeps status, validity and history per supplier. If the complaint already lives in your system, you reference the case and keep the details there.

“Our consultant gave us a template.”

The template solves the first evaluation. It does not solve the fourteenth re-evaluation, or the question of who approved what and when.

See ChainSec in action

Book a demo and we'll show you how you can handle gap analyses and supplier reviews in one system – instead of Excel. After the demo, you can test the platform for free.

Book a 15-minute demo

By submitting the booking request you accept our terms.

We respond by the next business day at the latest.

Frågor och svar

Is ChainSec an ISO 9001 system?

No. ChainSec does not replace your management system and has no document control, process maps or internal audit. ChainSec does the supplier part: supplier register, classification, re-evaluation, certificates, approved supplier list and supplier nonconformities. The Risk and requirements add-on covers internal risks and requirements.

What does ISO 9001 clause 8.4 require of suppliers?

Clause 8.4 requires you to evaluate, select, monitor and re-evaluate external providers that affect your ability to meet customer requirements, with documented criteria and controls proportionate to the provider’s impact. Requirements must be communicated to the provider before a contract or purchase order.

How often should suppliers be re-evaluated under ISO 9001?

The standard sets no fixed interval. You decide the criteria and must be able to show that you follow them. A common approach is yearly re-evaluation of critical suppliers and less often for the rest, plus re-evaluation after events such as a serious nonconformity.

What do we show the auditor?

The approved supplier list as an export with status, latest review and certificate validity. Per supplier you have the review history, the certificates and the nonconformities — open and closed, with who verified the action and when.

Can we keep complaints in our ERP or management system?

Yes. A nonconformity in ChainSec can reference the case number in your ERP or management system. The details stay there, and ChainSec keeps the link to the supplier and the follow-up the auditor asks about.

Does ChainSec work for ISO 14001?

The same supplier register, classification and nonconformity handling work for environmental management, and there are certificate types for ISO 14001 and 45001. A ready-made ISO 14001 supplier questionnaire is on the way.