The Workbench · Craft

What a supplier qualification file has to prove

A supplier file is often built once, at onboarding, and then left alone until an audit asks for it. ISO 13485:2016 Clause 7.4 doesn't describe a one-time gate; it describes a purchasing process that keeps producing evidence for as long as the relationship runs. Since February 2, 2026, that clause is also the only place the requirement lives — FDA's Quality Management System Regulation reserved 21 CFR 820.50, the old purchasing-controls section, the same way it reserved the sections behind CAPA and design controls. A supplier file built only around the qualification decision, and not around what the standard asks for after it, is missing half the clause.

Selection is a risk decision, not a form

Clause 7.4.1 requires the organization to evaluate and select suppliers based on their ability to supply product that meets requirements, with criteria for evaluation, selection and re-evaluation, and the type and extent of control set according to the effect of the purchased product on the quality of the medical device and, where applicable, on risk. Two suppliers providing the same category of part — a molded housing and a critical electronic subassembly — don't automatically earn the same qualification rigor; the standard ties the depth of the check to what happens downstream if the part fails, not to a fixed onboarding checklist applied uniformly. A file that runs every supplier through the identical form is answering a different, easier question than the one Clause 7.4.1 asks.

Re-evaluation is the requirement most files quietly drop

The clause treats evaluation, selection and re-evaluation as criteria the organization has to define, and this is the part a one-time onboarding packet skips outright. A supplier qualified in 2022 against 2022 performance data doesn't stay qualified by default; the file needs a defined trigger — a scheduled re-evaluation, a performance threshold, a nonconformance rate — that reopens the qualification decision on its own, not only when someone happens to notice a problem. A qualification file with an approval date and nothing after it is documenting a decision, not running a process.

Purchasing information has to be adequate before it leaves the building

Clause 7.4.2 requires purchasing information to describe the product to be purchased, including, where appropriate, requirements for approval or qualification of the product, procedures, processes, equipment and personnel, and the quality management system requirements, and to ensure the information is adequate before it's communicated to the supplier. That's a check on the purchase order itself, not just on the supplier: a PO that says “per spec” without stating which revision of which spec has already failed the clause before the part ships, because the ambiguity that produces a nonconforming shipment is the ambiguity in the order, not something inspection can find afterward.

Verification has to scale, and the file has to show its math

Clause 7.4.3 requires the organization to establish and implement the inspection or other activities necessary for ensuring purchased product meets requirements, and — the part a thin file skips — to base the extent of that verification on the supplier evaluation results and the risk associated with the purchased product. A supplier file that applies the same incoming-inspection sampling plan to every part number, regardless of what the supplier scorecard shows or what the part does inside the finished device, hasn't made that determination; it's applied a default and called it a decision. The same tracing discipline a risk management file owes each hazard is what a purchasing file owes each supplier — a visible chain from the supplier's risk profile to the verification method chosen, not a uniform inspection plan applied because writing one plan is easier than justifying several.

What moved under the file, and what didn't

The purchasing-controls requirement itself hasn't gotten stricter under the QMSR; what changed is where it lives. 21 CFR 820.50 no longer states requirements of its own — it's one of the sections the QMSR reserved, pointing to ISO 13485:2016 instead, the same renumbering that retired the CAPA and complaint-record citations most quality engineers still reach for from memory. A purchasing SOP that still cites 820.50 for its requirements is citing a section that no longer states them.

A supplier qualification file built around these distinctions — risk-scaled selection criteria, a defined re-evaluation trigger, and a verification plan that traces to both — is previewed in the launch catalog. If your program tracks supplier risk differently, the shelf takes that correction directly.

The Regulatory Toolkit launches soon — a free shelf of source-mapped templates, checklists and browser-only tools for regulatory teams. Get one email when it opens, or contribute a template.

All Workbench notes