Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
    • ISO 13485 Medical Devices
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

ISO 9001 Clause 8.4 and ISO 45001 Clause 8.1.4: One Number Apart, One Purchasing Process

Short answer

ISO 9001 clause 8.4 and ISO 45001 clause 8.1.4 sit one number apart and do the same job: control what you buy in and who you bring in. One purchasing process can satisfy both. The difference is scope and slant. ISO 9001 8.4 is limited to what affects your customer: products and services that go into what you sell, delivery straight to your customer, and processes you outsource. Your stationery order is not in it. ISO 45001 8.1.4 looks at procurement through a safety lens, so that same order can be in scope if it brings a hazard onto site, and it adds specific requirements for contractors and outsourcing. In both standards, the requirement auditors test hardest is criteria: the basis on which you choose, monitor and review suppliers and contractors, applied and recorded.

Workshop supervisor checking a steel delivery against a purchase order while a contractor in hi-vis signs in, with an approved suppliers and contractor inductions whiteboard on the wall
ISO 9001 clause 8.4 and ISO 45001 clause 8.1.4 can run as one purchasing process: a quality filter for what reaches the customer, and a safety filter for what, and who, comes onto site.

One number apart

If you run an integrated system, the first thing to know is that these two clauses are siblings, not twins. Same purpose, same place in the standard, one extra digit, and a safety slant on top.

ISO 9001 clause 8.4ISO 45001 clause 8.1.4
TitleControl of externally provided processes, products and servicesProcurement
The question it asksWill what we buy in affect what our customer receives?Will what we buy in, or who we bring in, affect the health and safety of people?
ScopeIncorporation into your product, direct delivery to the customer, outsourced processesProcurement of products and services generally, plus contractors and outsourcing
Office suppliesOutCan be in, if they bring a hazard (a ladder, a chair, a chemical)
CriteriaEvaluation, selection, monitoring and re-evaluation of external providersCriteria for selecting contractors, with OH&S requirements met by contractors and their workers
ContractorsCovered as an outsourced process or serviceA sub-clause of their own (8.1.4.2): hazards in three directions, and coordination
OutsourcingMust stay within the control of your QMSMust be controlled, consistent with legal requirements (8.1.4.3)
What you tell providersSix areas of requirements (8.4.3)Your OH&S requirements, applied to contractors and their workers

The practical answer is one process with two filters. The quality filter asks whether a purchase affects what the customer receives. The safety filter asks whether it brings a hazard, or a contractor, onto your site. Most purchases pass through one filter. Subcontractors almost always pass through both.

What clause 8.4 covers, and what it does not

Clause 8.4.1 tells you when its controls apply. There are three triggers:

  1. Incorporation. Products and services from external providers that are intended for incorporation into your own products and services. The steel in your fabrication, the components in your assembly, the laboratory analysis that goes into your report.
  2. Direct delivery. Products and services an external provider delivers directly to your customer on your behalf. The courier delivering your product, the installer you send to the client’s site.
  3. Outsourced processes. A process, or part of a process, that an external provider runs because you decided they would. Heat treatment, calibration, payroll for a labour hire business, the subcontractor who does a stage of the job.

If a purchase does not meet one of those three, clause 8.4 does not reach it. The paper, pens and toner from your Officeworks run are not incorporated into what you sell, are not delivered to your customer, and are not a process you outsourced. Your accountant, your cleaner and your coffee machine lease generally sit outside it too.

That matters for two reasons. First, an approved supplier list that tries to cover everyone becomes too big to maintain, and the suppliers that genuinely affect your customer get the same light touch as the stationery shop. Second, it is the most common way small businesses overbuild clause 8.4. The standard asks for control where control affects conformity to your customer’s requirements, not a register of every invoice.

A quick test

SupplierIn 8.4?Why
Steel supplier to a fabricatorYesIncorporated into the product
Subcontract electrician on your projectYesOutsourced part of the process
Courier delivering to your customerYesDelivered directly to the customer on your behalf
Calibration laboratory for your test equipmentYesOutsourced process that affects the validity of your results
Stationery and office suppliesNoNot incorporated, not delivered to the customer, not outsourced
Your accountantUsually noSupports the business, does not form part of what you deliver

The test is not who you pay most. It is whether what they provide ends up in, or determines, what your customer receives.

Criteria: the requirement auditors test

Clause 8.4.1 asks you to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, based on their ability to provide what you need in accordance with requirements. It also asks you to keep documented information of those activities and of any actions arising from the evaluations.

Read that sentence slowly, because there are four activities in it and most systems only do one.

  • Evaluation and selection. How a supplier gets on the list in the first place.
  • Monitoring of performance. How you know they are still delivering.
  • Re-evaluation. When and how you decide whether they stay on the list.
  • Records. Evidence that the above happened, and what you did about the results.

The finding I write most often on clause 8.4 is not “no approved supplier list”. Almost everyone has one. It is a list with no criteria behind it: names that got there because someone used them once, with nothing to show why they were chosen, how they are performing, or when anyone last asked. The second most common is criteria that are written down and never applied: a prequalification form in the procedure that no recent supplier has filled in.

What good criteria look like

Criteria should be proportionate to the risk the supplier carries for your customer. A supplier of a critical material deserves more than the business that supplies your gloves. Typical criteria, chosen to suit the supplier:

CriterionEvidence you might hold
Capability to meet the specificationSamples, trial order, technical data sheets
Quality managementCertification to ISO 9001, or your own assessment or audit
Licences and competenceTrade licences, qualifications of the people doing the work
Delivery performanceOn-time delivery against purchase orders
Quality performanceRejects, returns and nonconformities raised against them
ResponsivenessHow complaints and corrective actions were handled
Commercial and continuity riskSingle source, financial stability, lead times

You do not need all of them for every supplier. You need to have decided which apply to which kind of supplier, applied them, and kept the result. A one-page supplier evaluation record and an annual re-evaluation at management review will satisfy most auditors for a small business. A subcontractor carrying out safety-critical work may justify a site audit.

How much control to apply

Clause 8.4.2 asks you to make sure externally provided processes stay within the control of your quality management system, and to define the controls you apply both to the provider and to what they deliver. The extent depends on the potential impact on your ability to meet customer and statutory requirements, and on how effective the provider’s own controls are.

In practice that is a sliding scale:

  • Low impact: check the delivery against the purchase order on receipt.
  • Medium impact: require certificates of conformity, inspect a sample, review their test results.
  • High impact: witness or hold points, first article inspection, audits at their premises.

The point most often missed is the third trigger. Outsourcing a process does not outsource the responsibility. If your customer’s product goes out with a defect introduced by your subcontractor, the nonconformity is yours.

What you tell your suppliers

Clause 8.4.3 asks you to communicate your requirements to external providers before they start. That covers:

  1. The processes, products and services to be provided.
  2. The approval of products and services, methods, processes and equipment, and the release of products and services.
  3. Competence, including any required qualification of persons.
  4. Their interactions with your organisation.
  5. How you will control and monitor their performance.
  6. Any verification or validation you or your customer intend to carry out at their premises.

Most of this belongs on the purchase order or the subcontract, not in a separate procedure. A well-written purchase order template does more for clause 8.4.3 than a policy nobody sends to suppliers.

What ISO 45001 clause 8.1.4 adds: the safety slant

Everything above applies to an ISO 45001 purchasing process too. Clause 8.1.4 then adds three things, and they all have a safety slant.

Procurement in general (8.1.4.1)

ISO 45001 asks you to control the procurement of products and services so that they conform to your OH&S management system. It does not limit this to what goes into your product. So the purchase that sits outside ISO 9001 can sit inside ISO 45001: the step ladder, the office chair, the cleaning chemicals and the new piece of plant all bring hazards into the workplace. The safety question is whether you considered that before you bought them, not after someone was hurt.

In practice that means the purchasing step, for anything that brings a hazard, checks things like the safety data sheet for a chemical, the relevant Australian Standard for PPE or ladders, guarding and risk assessment for plant, and whether the item needs training or a safe work procedure before use.

Contractors (8.1.4.2)

This is where the two clauses diverge most. ISO 45001 asks you to coordinate procurement with contractors so you can identify hazards and control risks in three directions:

  1. Their activities affecting you: the contractor’s work creating hazards for your workers.
  2. Your activities affecting them: your operations creating hazards for the contractor’s workers.
  3. Their activities affecting others: visitors, the public, other contractors on site.

It also asks you to make sure your OH&S requirements are met by contractors and their workers, and to define and apply criteria for selecting contractors. That is the same criteria requirement as ISO 9001, with a safety slant. Typical contractor criteria:

CriterionEvidence you might hold
Licences and competenceTrade licences, high-risk work licences, tickets for the plant they will operate
Safety managementTheir WHS system, or certification to ISO 45001
Safe work method statementsSWMS for high-risk construction work, reviewed before they start
InsuranceWorkers’ compensation and public liability, current
Safety performanceIncident history, notices received, how previous incidents were handled
Site rules acceptedInduction completed, site rules signed
On-site performanceInspections, observations and nonconformities raised while they worked

An insurance certificate on file is not contractor management. It is one line of it.

Outsourcing (8.1.4.3)

Outsourced functions and processes must be controlled, consistently with legal requirements. In Australia that lands squarely on WHS law. Where you and a contractor share a duty for the same work, you each have to consult, cooperate and coordinate with the other, so far as is reasonably practicable. A contract can allocate tasks. It cannot hand over the duty. We covered what that looks like when it goes wrong in the $230,000 contractor management case.

One process, two filters

PurchaseQuality filter (9001 8.4)Safety filter (45001 8.1.4)
Steel sections for fabricationIn: incorporated into the productIn if handling or storage brings a hazard
Subcontract electrician on siteIn: outsourced part of the processIn: contractor, hazards in three directions
Courier delivering to your customerIn: direct delivery on your behalfUsually limited to your site interface
Step ladder from the office supplierOutIn: brings a hazard onto site
Cleaning chemicalsOutIn: safety data sheet and storage
Your accountantOutOut

Build both filters into the same purchasing step and the same supplier record, and one process satisfies both standards. Run them as two separate procedures and you will be audited twice on the same supplier, and find the two records disagree.

What an auditor will ask

If I were auditing clause 8.4 tomorrow, this is the thread I would pull:

  1. Show me how you decided which suppliers are in scope. A rule, not a feeling.
  2. Show me your criteria. For each kind of supplier, what you assess them against.
  3. Show me a supplier you added this year. The evaluation record, dated before the first order.
  4. Show me how you monitor them. Delivery and quality performance, and where it is reviewed.
  5. Show me a re-evaluation. When it happened, the result, and what changed.
  6. Show me a purchase order to a critical supplier. Does it carry your requirements, or just a part number and a price?
  7. Show me a supplier problem. What was raised, what they did about it, and whether it affected their status.

And for ISO 45001 8.1.4, the same thread with a safety slant:

  1. Show me your contractor selection criteria. What a contractor must have before they start.
  2. Show me a contractor on site today. Their licences, their SWMS, their induction record, and who checked them.
  3. Show me how you coordinated with them. The hazards you identified together, in all three directions.
  4. Show me a hazardous purchase. A chemical, a ladder or a piece of plant, and where the safety check happened before it arrived.

Questions 3, 5 and 9 are where most systems come apart. The list exists. The evidence of choosing, checking and reviewing does not.

Where clause 8.4 comes unstuck

  • Everyone on the list. The stationery shop and the critical subcontractor treated the same, so the list is too big to keep current.
  • No criteria. Names on a list with no recorded basis for choosing them.
  • Criteria never applied. A prequalification form in the procedure that recent suppliers never completed.
  • No re-evaluation. Suppliers approved years ago and never looked at again.
  • Certificates as a substitute for monitoring. An ISO 9001 certificate is useful evidence at selection. It does not tell you how they performed on your last ten orders.
  • Integrated, but only on paper. One procedure claiming to cover ISO 9001 and ISO 45001, with no safety filter applied to purchases or contractors.
  • Contractor management as a folder. Insurance certificates collected, but no selection criteria, no SWMS review and no record of who checked the contractor before they started.
  • Hazardous purchases waved through. Chemicals and plant bought on price, with the safety data sheet or risk assessment arriving after the product.

Frequently asked questions

Does ISO 9001 clause 8.4 apply to all of our suppliers?

No. It applies to products and services incorporated into what you deliver, products and services delivered directly to your customer on your behalf, and processes you outsource. Office supplies and most general business services sit outside it.

Do we need an approved supplier list?

The standard does not use the words “approved supplier list”. It requires criteria for evaluation, selection, monitoring and re-evaluation, and records of those activities. A list is the usual way to show the outcome, but the criteria and the records behind it are what an auditor tests.

Is a supplier’s ISO 9001 certificate enough?

It is good evidence at selection, and many organisations use it as one criterion. It is not evidence of performance on your orders, so you still need to monitor and re-evaluate.

How often should we re-evaluate suppliers?

The standard does not set a frequency. Annually is common and easy to tie to management review. Re-evaluate sooner after a significant nonconformity, a change of ownership, or a change in what you buy from them.

Is ISO 9001 8.4 the same as ISO 45001 8.1.4?

They are one number apart and do the same job, and one process can cover both, but the scope differs. ISO 9001 8.4 is limited to provision that affects what your customer receives. ISO 45001 8.1.4 covers procurement through a safety lens, and adds specific requirements for contractors (8.1.4.2) and outsourcing (8.1.4.3).

Does ISO 45001 8.1.4 require contractor inductions?

The clause does not use the word. It requires your OH&S requirements to be met by contractors and their workers, and criteria for selecting contractors. An induction is the usual way to communicate those requirements and show it happened, which is why an auditor will almost always ask for the record.

Did ISO 9001:2026 change clause 8.4?

Not in substance. None of the six main changes listed in the 2026 edition’s foreword touch clause 8.4. Our ISO 9001:2026 changes guide covers what did change.

Getting clause 8.4 right

Clause 8.4 is one of the clearest examples of a clause that works when it is built into the way you buy, and fails when it sits in a procedure nobody in purchasing has read. Our clause 8 overview shows how it fits with the rest of operation, and the clause 4.4 process approach guide shows how to build requirements into the process itself.

Streamline designs, implements and audits ISO 9001 quality and ISO 45001 safety management systems for Australian businesses, including integrated systems where one purchasing process serves both, and you deal directly with a practising ISO Lead Auditor. If you need a supplier or contractor assessed before they go on your list, our supplier evaluation auditing service does exactly that. A gap analysis will show whether your criteria would survive an audit, and ISO mentoring suits businesses that want their own people to build it. If your approved supplier list has more names than reasons, or your contractor file is mostly insurance certificates, get in touch.

General information from an auditing and management system perspective, current at 6 October 2026. Clause references are to ISO 9001:2015 and ISO 9001:2026, which share the clause 8.4 requirements, and to ISO 45001:2018. WHS duties vary by jurisdiction; check the WHS Act and regulations that apply to you.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Tilt-shift miniature naval shipyard inspection bay with a submarine hull section on keel blocks and workers in hi-vis checking tagged components in a parts quarantine area
    ISO 19443: The Nuclear Supply Chain Standard, and…
  • Quality professional checking a barcoded sterile device pack against a batch record on a tablet in a clean medical device facility
    ISO 13485 Consulting, Internal Audits and Mentoring…
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Quality inspector in an Australian machining workshop checking a machined aluminium component against a tablet record, with CNC machines and Australian flags behind
    How Much Does ISO 9001 Certification Cost in…

Filed Under: Articles Tagged With: #certification, #iso45001, #iso9001, #qms

Quick Contact Form

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Citation Certification ISO 9001 certification mark, the JAS-ANZ accreditation symbol and the ASQ logo

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Trust Centre · Privacy Policy · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire