Suche

Supplier Management in Medical Technology: How to Select and Monitor Your Suppliers in Compliance with Regulations

The MDR and ISO 13485 require manufacturers to have clear rules for selecting, evaluating, and monitoring their suppliers. Anyone who knows these obligations and implements them in a structured way protects themselves from non-conformities – and from unpleasant surprises during an audit.

Why Supplier Management Matters for Every Manufacturer

Hardly any manufacturer develops and produces everything entirely on their own. The moment you purchase something instead of making it yourself, your business partner becomes a supplier in the regulatory sense. Examples include:

  • Product development: An external partner develops a complete medical device for you.
  • Component development: A supplier develops part of your product.
  • Off-the-shelf components: You use an existing, ready-made part within your product.
  • Tools and software as a service: You purchase or rent tools, such as a document management system. In this case, computerised system validation (CSV) also applies.
  • IT services: You use hosting or cloud services – what matters is whether these become part of your product.

The same three-step principle applies to all of these situations: evaluate, select, and continuously monitor your suppliers. The criteria for the initial evaluation differ from those used for ongoing monitoring. Delivery reliability, for example, can only be assessed once deliveries have actually taken place.

What the MDR, ISO 13485, and the FDA Specifically Require

The MDR requires that your quality management system govern the selection and control of suppliers and subcontractors (MDR Art. 10 (9) d). Your Notified Body also assesses whether a separate supplier audit is necessary. If that assessment is positive, even your suppliers are subject to unannounced audits - at least once every five years (Anhang IX 3.4). Your technical documentation must also state which suppliers and subcontractors are involved in development and production (MDR Anhang II 3.c).

ISO 13485 and ISO 9001 specifically require you to

  • define criteria for suppliers and the products to be procured,
  • assess, select, monitor, and evaluate suppliers based on these criteria,
  • analyse the effects of the procured product on the safety and performance of your medical device, and
  • conclude written quality assurance agreements (QAAs) whose scope matches the associated risk.

Important: you define these criteria on a product-specific basis – a blanket list applied to all suppliers isn't sufficient.

The FDA imposes comparable purchasing controls in 21 CFR Part 820.50 , including the requirement that suppliers agree to notify you of changes to their product or service. The resulting data is subject to document control under 21 CFR Part 820.40.

The NBOG’s Best Practice Guide 2010-1offers further guidance: it explicitly names sole reliance on an ISO certification as an example of inadequate supplier control. A certificate alone, in other words, replaces neither a solid QAA nor – where necessary – a supplier audit.

Implementing Supplier Evaluation in Three Steps

Define your approach once in a documented procedure, rather than deciding anew for every supplier.

Step 1: Define criteria. Ask, for example: Does the supplier develop a medical device or parts of one? Are they ISO 13485 certified? How dependent are you on them – are there alternatives? Is the product business-critical? For software, additional questions arise, such as the safety classification or SOUP/OTS components.

Step 2: Define measures. Possible building blocks include a negotiated QAA (quality assurance agreements), restricting suppliers to those certified under ISO 13485, incoming goods inspection with a defined frequency and method, clear product specifications and acceptance criteria, and – where necessary – a supplier audit.

Step 3: Match criteria to measures. Not every supplier needs every measure. An audit of your office supplies vendor achieves little; for a software partner without its own QM system, however, it can be indispensable. A risk-based classification into critical and non-critical suppliers has proven effective. A supplier is considered critical if their products or services can influence the safety or performance of your medical device.

When a Supplier Audit Becomes Necessary

Whether an audit must take place depends on two factors: the criticality of the supplied product and whether the supplier has its own QM-System. .

If the supplier  has no QM system of its own, you declare your own processes binding for them and verify compliance – depending on the risk, through incoming goods inspection and an additional audit. In this case, your notified body's review obligation extends all the way through to the supplier.

If the supplier has its own certified QM system under ISO 13485, you can rely on it. Check carefully whether the scope of certification covers the processes relevant to you. An additional audit remains advisable regardless and should then be agreed contractually.

No supplier audit, on the other hand, is needed for pure off-the-shelf goods that weren't developed specifically for your product – such as standard monitors or power supplies. Here, your risk management ensures that these purchased components don't lead to unacceptable risks.

BEO BERLIN – Your Partner for Reliable Supplier Management

Robust supplier management protects your  conformity and makes every audit easier. You don't have to build this system alone. BEO BERLIN supports you with, among other things:

  • creating MDR-, ISO 13485-, and FDA-compliant procedures for supplier evaluation, selection, and monitoring,
  • drafting quality assurance agreements,
  • preparing and conducting supplier audits on your behalf,
  • integrating supplier management into your post-market surveillance processes.

Conclusion: Control Over Suppliers Means Control Over Conformity

Manufacturers who outsource development or production remain fully responsible for the conformity of their product. The MDR and ISO 13485 therefore require risk-based, documented supplier management – from the initial evaluation through to ongoing monitoring.

Want to put your supplier management on a solid footing? Contact us – together, we'll develop the right solution for your supplier management.



1 Sterne2 Sterne3 Sterne4 Sterne5 Sterne (1 Rating(s), average: 5.00 out of 5)

Loading...

More about this category