The Workbench · Craft

An outsourced process is not a purchased part

A purchasing file tracks parts: a molded housing, a fastener, a subassembly bought from a qualified supplier and inspected on arrival. Some things a manufacturer sends outside its own walls aren't parts at all — sterilization, a coating step, a calibration service, a software build run on someone else's toolchain. ISO 13485:2016 gives that second category its own clause, separate from the purchasing controls this blog has already covered, and a quality system that only has a supplier file has only built half of what the standard actually asks for.

Clause 4.1.5 covers a process, not a product

Clause 4.1.5 requires that when an organization chooses to outsource any process that affects product conformity to requirements, it has to monitor and ensure control over that process. The clause sits in Clause 4.1, the quality management system's general requirements, not inside product realization where the purchasing controls in Clause 7.4 live. That placement is the point: a supplier qualification file is built to answer whether a part meets a specification. Clause 4.1.5 answers a different question — whether an activity the organization would otherwise perform itself, and stay accountable for, is still under control once someone else is the one performing it.

Responsibility doesn't transfer with the work

The clause is explicit that outsourcing a process doesn't outsource accountability for it: the organization retains responsibility for conformity to the standard and to customer and applicable regulatory requirements, whether the process was performed in-house or sent out. A finding traced to a contract sterilizer's cycle, or a contract manufacturer's assembly step, still lands on the file of the company whose name is on the device — the outsourced process's own quality record is evidence the organization has to be able to produce, not a boundary that stops an audit from reaching further.

The control has to scale with risk, and it has to be written down

Clause 4.1.5 ties the type and extent of control to the risk the outsourced process carries and to the external party's own ability to meet requirements, the same risk-based logic Clause 7.4.1 applies to purchased product. A process that determines a device's sterility carries a different control burden than one that anodizes a non-critical bracket, and a file that applies one boilerplate agreement to both hasn't made that distinction the clause requires. The control itself has to include a written quality agreement with the external party — not a purchase order, and not an informal understanding built on a long working relationship, however reliable that relationship has been so far.

A gap the old FDA rule never had to name

21 CFR 820.50, the purchasing-controls section the old Quality System Regulation carried, was written around purchased product — evaluating and selecting suppliers of product and services that affect quality. A process performed entirely by an outside party, with no physical component changing hands, sat closer to the edges of that language than the center of it. Since QMSR's compliance date folded Part 820's substance into ISO 13485:2016 the way this blog has already traced for the DMR, DHF, and DHR, Clause 4.1.5 closes that gap directly: it names the outsourced process itself as the thing to be controlled, independent of whether anything shipped alongside it.

Validation still applies to the process, wherever it runs

An outsourced process that can't be fully verified by inspecting its output afterward — sterilization is the standard example — still has to be validated under the same terms Clause 7.5.6 sets for a process run in-house. Sending the work outside the building doesn't change what kind of process it is or lower the bar for proving it works; it changes who's running the equipment, not what the equipment's own qualification has to demonstrate. A validation record filed only with the contractor, and never reviewed or referenced by the organization that outsourced the process, hasn't satisfied Clause 4.1.5's own monitoring duty — it's just moved the evidence somewhere harder to audit.

Where this meets the rest of the file

An outsourced-process control worksheet built around Clause 4.1.5's own scope, the retained-responsibility requirement, and the risk-scaled quality agreement it demands is previewed in the launch catalog. If your program controls outsourced work differently, the shelf takes that correction directly.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes