ISO 13485

Supplier Controls Under QMSR: How to Qualify and Audit Critical Suppliers Without Leaving FDA Gaps

By Andre Butler  ·  August 13, 2026  ·  ← All Insights

Supplier Controls Under QMSR: What Medical Device Companies Must Get Right

With the FDA's Quality Management System Regulation (QMSR) now in effect — aligning 21 CFR Part 820 with ISO 13485:2016 — supplier controls have moved from a back-office checkbox to a frontline regulatory priority. For medical device startups and small-to-mid-size manufacturers, gaps in supplier qualification and auditing are among the most cited observations during FDA inspections. If your supplier controls program isn't built on a defensible, risk-based framework, you're leaving your company exposed.

This post breaks down exactly what FDA expects under the QMSR, how to qualify critical suppliers, and what a credible audit program actually looks like in practice.

What QMSR Says About Supplier Controls

The QMSR, effective February 2, 2026, formally incorporates ISO 13485:2016 by reference. Section 7.4 of ISO 13485 — now the operative standard under 21 CFR Part 820 — establishes clear requirements for purchasing controls. Specifically, it requires manufacturers to:

  • Evaluate and select suppliers based on their ability to meet specified requirements
  • Define the type and extent of control based on the effect of purchased product on device quality
  • Establish documented criteria for supplier selection, evaluation, and re-evaluation
  • Maintain records of supplier evaluations and any necessary actions arising from those evaluations

This isn't new language, but the explicit alignment with ISO 13485 raises the bar. FDA investigators are now cross-referencing your supplier control procedures against a more detailed, internationally recognized standard. Vague procedures that passed muster under the old Part 820 may not hold up today.

Defining 'Critical Supplier' — And Why It Matters

Not every vendor needs the same level of scrutiny. Your regulatory and quality team must segment suppliers based on risk. A critical supplier is generally one whose product or service directly affects device safety, efficacy, or regulatory compliance. Think: contract manufacturers, sterilization providers, software development firms for SaMD components, component suppliers for life-sustaining devices, and test labs performing biocompatibility or electrical safety testing.

Your Approved Supplier List (ASL) should explicitly identify criticality tiers. A tiered approach might look like this:

  • Tier 1 (Critical): Suppliers providing components or services that directly affect device performance or patient safety — require full qualification, on-site or remote audits, and annual re-evaluation
  • Tier 2 (Significant): Suppliers whose failures could indirectly affect quality — require questionnaires, certificates of conformance, and periodic review
  • Tier 3 (Standard): Commodity or low-risk suppliers — standard purchasing controls and reactive monitoring

This risk stratification isn't just good practice — it's what ISO 13485 Section 7.4.1 explicitly calls for, and FDA investigators will ask to see it documented.

Qualifying a Critical Supplier: The Practical Framework

Qualification is not a one-time event. It's a structured process that should generate objective evidence. For Tier 1 critical suppliers, your qualification package should include:

  • Supplier questionnaire: Covering quality management system status (ISO 13485 or equivalent), regulatory history, change control processes, and sub-supplier management
  • Document review: Quality manual, relevant SOPs, certificates of conformance, and — where applicable — FDA establishment registration and device listing records
  • First article inspection or sample testing: Confirming the supplier can meet your incoming acceptance criteria before production-scale orders
  • On-site or remote audit: For contract manufacturers and sterilization providers especially, a desk audit alone is rarely sufficient for FDA scrutiny
  • Formal approval and ASL entry: Documented sign-off from quality leadership with defined scope of approval

Keep in mind that under 21 CFR Part 820.50 — and now under QMSR — you bear responsibility for the quality of purchased product. 'My supplier told me it was compliant' is not a defensible position during an inspection.

Auditing Critical Suppliers: Frequency, Scope, and Documentation

Supplier audits are where many small device companies fall short — either skipping them entirely or conducting superficial reviews that don't satisfy FDA expectations. Here's what a credible program includes:

  • Audit schedule driven by risk and performance data: Annual audits for critical suppliers, with more frequent reviews triggered by NCRs, complaints, or significant process changes
  • Defined audit scope: Tied to the specific product or service provided — don't audit a sterilization facility the same way you'd audit a printed circuit board manufacturer
  • Qualified auditors: Whether internal or third-party, auditors must have the technical and regulatory competency to evaluate the supplier's processes meaningfully
  • Formal audit reports with CAPA follow-up: Open findings must be tracked to closure. An audit report that sits in a folder with no corrective action follow-up is a liability, not an asset
  • Re-qualification triggers: Define in your procedure what events — ownership change, facility relocation, key personnel departure, FDA warning letter — trigger a re-qualification cycle

Common FDA 483 Observations Related to Supplier Controls

FDA Form 483 observations and warning letters consistently cite supplier control failures. The most common patterns include: failure to audit contract manufacturers, no documented criteria for supplier selection, ASLs that are out of date or missing criticality designations, and incoming inspection procedures that reference suppliers never formally qualified. Each of these is avoidable with a well-designed supplier controls program built before you scale — not after your first FDA inspection.

Build Your Supplier Program Before FDA Comes Knocking

Supplier controls under QMSR demand a level of rigor that many early-stage and growth-stage device companies underestimate. The good news: if you build your program correctly from the start, it becomes a competitive advantage — streamlining audits, reducing incoming failures, and demonstrating to FDA that your quality system is genuinely in control.

At ADB Consulting and CRO Inc., Andre Butler and the team work directly with medical device startups and established manufacturers to design, implement, and audit supplier control programs that meet FDA and ISO 13485 expectations — without the bureaucratic overhead that slows down lean organizations.

Ready to close the gaps in your supplier controls program before your next FDA inspection or audit? Book a free discovery call with Andre Butler at adbccro.com and get a candid assessment of where your program stands and what it will take to get it audit-ready.

Andre Butler

Principal Consultant — ADB Consulting & CRO Inc.

Andre Butler has 20+ years of hands-on FDA regulatory experience guiding medical device companies through 510(k), PMA, De Novo, AI/ML SaMD, and FDA 483 response engagements. He specialises in Section 524B cybersecurity compliance and ISO 13485 quality management systems, with a track record across cardiovascular, orthopedic, diagnostic, and software-as-a-medical-device categories.

Ready to Navigate the FDA Process with Confidence?

Book a free 30-minute discovery call with Andre Butler. No sales pitch -- just expert regulatory guidance on your specific device and situation.

Book a Free Pathway Call

Or call directly: (888) 450-8607

Explore our flat-fee FDA services →