At a glance
ISO 9001:2026 supplier management guide: current Clause 8.4 controls, supplier evidence, and what to confirm when the next edition is published.
Direct answer
Supplier and external-provider controls should remain grounded in the current ISO 9001:2015 framework until the next edition is published. The appropriate control depends on the consequence of a provider failure and the organization’s ability to verify the supplied output.
- Identify the supplied output and consequence of failure.
- Select proportionate approval, monitoring, or verification evidence.
- Treat future-edition commentary as preparation context, not final criteria.
Primary source: ISO/FDIS 9001 project status
- Focus: Clause 8.4 · supplier management
- Read time: 10 minutes
- Updated: August 30, 2026
ISO 9001:2026 supplier management preparation should begin with the current published edition, ISO 9001:2015, which centers Clause 8.4 on controlling externally provided processes, products, and services. ISO lists ISO/FDIS 9001 as under development, with publication planned for September 2026; final Clause 8.4 wording and transition expectations must be checked against the published edition and applicable certification-body guidance.ISO/FDIS statusISO/FDIS statushttps://www.iso.org/standard/88464.html
A Decision-Led Approach to Supplier Control
The useful question is not whether every supplier receives the same treatment. It is whether the organization can explain the consequence of a provider failure, the controls selected in response, and the evidence showing those controls work. That reasoning is useful under ISO 9001:2015 now and gives the organization a sound evidence baseline for any later comparison with the published revision.
This guide explains the current Clause 8.4 control logic, the records that make the decision traceable, and the questions to revisit after final revision text is available.
What Clause 8.4 Actually Covers
Clause 8.4's scope is broader than many think. It covers three areas in three subclauses:
Clause 8.4.1 — General requirements addresses how organizations evaluate, select, monitor, and re-evaluate external providers. The key word is "re-evaluate" — not just qualify once and maintain a list, but actively assess whether suppliers continue to meet requirements over time.
Clause 8.4.2 — Type and extent of control establishes the risk-based principle that the controls applied to each supplier should be proportional to the risk that supplier represents. A critical single-source supplier of a key component requires materially different controls than an office supply vendor. Organizations that apply the same qualification process to every supplier regardless of risk profile are simultaneously over-managing low-risk relationships and under-managing high-risk ones.
Clause 8.4.3 — Information for external providers covers what organizations communicate to their suppliers before work begins — quality requirements, specifications, competence requirements, and the extent of control the organization intends to apply.
| Sub-clause | Focus | Common Gap |
|---|---|---|
| 8.4.1 General | Evaluate, select, monitor, re-evaluate | Approved supplier lists not reviewed annually |
| 8.4.2 Type and extent of control | Risk-proportionate controls | Same controls applied to all suppliers regardless of risk |
| 8.4.3 Information | Communicate requirements to external providers | Purchase orders that specify part numbers but not quality requirements |
What to Confirm When the Next Edition Is Published
Stay Current
ISO expects the next edition in September 2026. Get source-checked weekly briefings.
Do not build a supplier-control programme around commentary about an unpublished edition. Instead, retain a decision record that makes later comparison efficient:
| Question to resolve | Useful evidence now | Confirm against the published edition |
|---|---|---|
| Which providers can affect conforming output? | Process map, supplied output, consequence of failure, and responsible owner. | Whether the final text changes the relevant control or terminology. |
| How are controls selected? | Supplier criteria, risk rationale, approval and monitoring records, and evidence of effectiveness. | Whether any specific control expectation has changed. |
| What must the provider understand? | Purchase requirements, specifications, acceptance criteria, and change communication. | Whether final guidance alters the communication emphasis. |
| Does an external audit arrangement affect this organization? | Current certificate scope, audit-cycle context, and dated written communication from the certification body. | Whether published arrangements apply to this certificate and timing decision. |
[CALLOUT:key insight]
Decision rule: A supplier file is stronger when it links the supplied output, the consequence of failure, the selected control, and the review evidence. A list of approved names alone does not show why the control is proportionate.
[/CALLOUT]
A Current-Edition Clause 8.4 Evidence Framework
The current Clause 8.4 baseline is to determine and apply controls to externally provided processes, products, and services. ISO 9001:2015 does not prescribe one universal supplier scorecard, review interval, segmentation scale, or sub-tier audit model. The organization should be able to explain the selected control and show evidence that it is used.ISO 9001:2015ISO 9001:2015https://www.iso.org/standard/62085.html
| Decision | Useful evidence | Review question |
|---|---|---|
| Identify the external provision | Supplied output, process interface, customer or statutory requirements, and accountable owner. | Could a failure affect conforming output or the organization’s ability to meet requirements? |
| Determine the type and extent of control | Rationale for approval, monitoring, verification, validation, or other selected controls. | Is the control proportionate to the potential effect and the organization’s ability to verify output? |
| Communicate requirements | Specification, acceptance criteria, competence or approval needs, and change communication. | Can the provider understand what conforming output means in this engagement? |
| Monitor and re-evaluate | Performance evidence, review result, action decision, and retained record. | Does the record show what was reviewed and what changed as a result? |
| Consider dependencies | Relevant continuity, single-source, or subcontracting information where it affects conformity. | Is additional visibility justified by the organization’s own risk and verification needs? |
Evidence Checks an Internal Auditor Can Use Now
These prompts test the current process rather than predict a future transition audit:
- Select one externally provided output and trace the reason for its control level.
- Compare the communicated requirements with the specification, order, contract, or acceptance criteria actually used.
- Review a recent monitoring or re-evaluation record for a decision and follow-up, not merely a retained score.
- Test whether a changed provider, requirement, or performance result prompted an appropriate response.
Frequently Asked Questions: ISO 9001:2026 Clause 8.4 Supplier Management
Does ISO 9001:2026 require companies to audit their suppliers' suppliers?
Do not assume a future-edition sub-tier audit requirement before the final text is published. Under the current Clause 8.4 framework, select and document controls that are proportionate to the potential effect of external provision and the organization’s ability to verify it.
Do we need to update our supplier qualification process before September 16, 2026?
Use ISO 9001:2015 as the current control baseline. Improve weak current evidence where justified, but do not schedule changes around an assumed future deadline. Reassess when the final edition and applicable certification-body communication are available.
What evidence does Clause 8.4 require?
Keep evidence that supports the organization’s own evaluation, selection, monitoring, and re-evaluation decisions where the current Clause 8.4 process calls for it. A useful record links the provider and supplied output to the selected control, communicated requirements, review result, and any follow-up action. Additional dependency visibility should be justified by the organization’s ability to verify the external provision and its potential effect on conformity.
How does the 2026 revision change supplier evaluation criteria?
The final published edition will determine any change. Keep a dated comparison question and use the current Clause 8.4 evidence framework until the final text can be assessed.
Can we use the same supplier management process for all suppliers?
The current standard requires the organization to determine the type and extent of control to apply to externally provided processes, products, and services. A single method may be suitable only if the organization can show that it remains appropriate for the relevant external provision; selected controls should reflect the potential effect on conforming output and the organization’s ability to verify it.
Key Resources
Use ISO 9001:2015ISO 9001:2015https://www.iso.org/standard/62085.html as the current requirements source and the ISO/FDIS status recordISO/FDIS status recordhttps://www.iso.org/standard/88464.html for official revision status. These related resources support evidence-led supplier control:
- Corrective action guideCorrective action guide/article/iso-9001-corrective-action-guide — trace an external-provider issue from containment to effectiveness review.
- Internal audit guideInternal audit guide/article/iso-9001-2026-internal-audit-guide-checklist — current-process audit prompts and evidence discipline.
- Transition planning guideTransition planning guide/article/how-to-transition-iso-9001-2015-to-2026 — maintain current evidence and use final-text decision gates.
- Email-gated ISO 9001 Gap Analysis TemplateEmail-gated ISO 9001 Gap Analysis Template/resources/gap-analysis-template — capture current supplier-control evidence and questions for the final edition.

