Section 2.4: Operation: Control of External Providers and Production (Clauses 8.4 - 8.7)
Key Takeaways
- Clause 8.4.1 defines three external provisions: incorporated inputs, direct delivery, and outsourced processes.
- Organizations must apply documented criteria for evaluation, selection, monitoring, and re-evaluation of external providers.
- Clause 8.5 requires validation and revalidation of processes where outputs cannot be verified subsequently (special processes).
- Clause 8.6 prevents product release until planned verification arrangements are completed, tracking the authorizer.
- Clause 8.7 requires retaining four specific details for nonconforming outputs: description, actions, concessions, and authority.
Section 2.4: Operation: Control of External Providers and Production (Clauses 8.4 - 8.7)
Control of Externally Provided Processes, Products, and Services (Clause 8.4)
Clause 8.4 governs the organization's supply chain and outsourcing. In today's globalized economy, organizations rarely perform all processes in-house. A lead auditor must understand that external providers can introduce significant risk to product conformity.
8.4.1 General and Types of External Provision
The organization must ensure that all externally provided processes, products, and services conform to requirements. There are three distinct categories of external provision:
- Incorporated Inputs: Raw materials, components, or sub-assemblies purchased from a supplier that become part of the organization's own product (e.g., steel sheet, microchips).
- Direct Delivery: Products or services delivered directly to the customer by an external provider on behalf of the organization (e.g., subcontracted delivery service, drop-shipped items).
- Outsourced Processes: Processes or parts of processes that the organization chooses to outsource (e.g., subcontracted heat-treatment, painting, welding, or calibration services).
The organization must determine and apply documented criteria for the evaluation, selection, monitoring of performance, and re-evaluation of external providers. Records of these evaluations must be retained. Auditors trace supplier folders to verify that suppliers are added and maintained on the approved supplier list based on objective performance data rather than personal preferences.
8.4.2 Type and Extent of Control
The controls applied to external providers must be risk-graded. In determining the control levels, the organization must consider the potential impact of the external provision on the organization's ability to consistently meet customer and regulatory requirements, and the effectiveness of the controls applied by the provider.
- Auditor Guidance: A critical safety component sourced from a new supplier requires rigorous control, such as source inspections or 100% incoming testing. Conversely, standard hardware from an established, ISO 9001-certified supplier may only require a review of the Certificate of Conformance (CoC). Under Clause 8.4.3, the organization must communicate specific requirements to suppliers, covering products/services to be provided, approval criteria, personnel competence, and any verification/validation activities planned at the supplier's premises.
Production and Service Provision (Clause 8.5)
8.5.1 Control of Production and Service Provision
Production and service delivery must occur under controlled conditions. This requires:
- Availability of documented information defining product characteristics and intended results.
- Availability and use of suitable monitoring and measuring resources.
- Implementation of monitoring activities at appropriate stages (e.g., in-process inspections).
- Use of suitable infrastructure and process environments.
- Appointment of competent persons.
- Validation and periodic revalidation of "special processes": These are processes where the resulting output cannot be verified by subsequent monitoring or measurement (e.g., welding, heat-treatment, plating, painting, or sterilization). If a process cannot be verified without destructive testing, the organization must validate the process parameters, equipment, and operator competence before production begins.
8.5.2 Identification and Traceability
The organization must identify its outputs to ensure conformity. This includes identifying the status of outputs (e.g., "waiting inspection," "passed," "rejected") throughout production. Where traceability is a requirement (e.g., aerospace, medical devices, automotive), the organization must control the unique identification of outputs and retain detailed records.
8.5.3 Property Belonging to Customers or External Providers
Organizations must safeguard property belonging to customers or external providers while it is under their control. Property includes raw materials, tooling, molds, intellectual property, and personal data. If customer property is lost, damaged, or found unsuitable, the organization must report this to the owner and retain records.
- Worked Scenario: A manufacturer stores customer-supplied circuit boards in an static-sensitive area, but does not ground the storage racks. Several boards are destroyed by electrostatic discharge. The lead auditor should cite a nonconformity against Clause 8.5.3 for failing to safeguard customer property.
8.5.4 Preservation, 8.5.5 Post-Delivery, and 8.5.6 Control of Changes
- Preservation (8.5.4): Organizations must preserve outputs during processing and delivery (packaging, contamination control, cold storage).
- Post-Delivery (8.5.5): Meet warranty, maintenance, and recycling obligations.
- Control of Changes (8.5.6): Review and control unplanned production changes. Records must identify the review results, the authorizing person, and actions taken.
Release of Products and Services (Clause 8.6)
Clause 8.6 mandates that products or services must not be released to the customer until planned verification activities are completed, unless approved by a relevant authority or the customer. Retained records must show:
- Evidence of conformity with acceptance criteria.
- Traceability to the person(s) authorizing the release (e.g., QC inspector's signature).
Control of Nonconforming Outputs (Clause 8.7)
Nonconforming outputs must be identified and controlled to prevent their unintended use or delivery. Clause 8.7.1 allows containment through correction (rework), segregation, return/suspension, informing the customer, or obtaining customer concession. Under Clause 8.7.2, the organization must retain documented information describing the nonconformity, actions taken, any concessions obtained, and the identity of the authority deciding the action. A lead auditor will check nonconformity logs to ensure all four items are recorded.
An auditor is auditing a chemical manufacturing company. During the audit of Clause 8.4, the auditor finds that the criteria used to select and re-evaluate raw material suppliers have not been documented or updated for five years, although supplier performance scorecards are reviewed quarterly. Which sub-clause is most directly violated?
During an audit of a metal fabrication shop, the lead auditor finds a pallet of custom steel brackets in the warehouse marked with a green tag stating "Ready for Shipment." However, the final quality inspection report for this batch has not yet been signed off by the quality manager, and there is no customer concession on file. What does this represent?
A manufacturing plant discovers that a batch of nonconforming plastic components was accidentally shipped to a customer. When auditing the records under Clause 8.7.2, which set of documented information must the auditor expect to find?