Short answer
ISO 9001 clause 8.4 and ISO 45001 clause 8.1.4 sit one number apart and do the same job: control what you buy in and who you bring in. One purchasing process can satisfy both. The difference is scope and slant. ISO 9001 8.4 is limited to what affects your customer: products and services that go into what you sell, delivery straight to your customer, and processes you outsource. Your stationery order is not in it. ISO 45001 8.1.4 looks at procurement through a safety lens, so that same order can be in scope if it brings a hazard onto site, and it adds specific requirements for contractors and outsourcing. In both standards, the requirement auditors test hardest is criteria: the basis on which you choose, monitor and review suppliers and contractors, applied and recorded.

One number apart
If you run an integrated system, the first thing to know is that these two clauses are siblings, not twins. Same purpose, same place in the standard, one extra digit, and a safety slant on top.
| ISO 9001 clause 8.4 | ISO 45001 clause 8.1.4 | |
|---|---|---|
| Title | Control of externally provided processes, products and services | Procurement |
| The question it asks | Will what we buy in affect what our customer receives? | Will what we buy in, or who we bring in, affect the health and safety of people? |
| Scope | Incorporation into your product, direct delivery to the customer, outsourced processes | Procurement of products and services generally, plus contractors and outsourcing |
| Office supplies | Out | Can be in, if they bring a hazard (a ladder, a chair, a chemical) |
| Criteria | Evaluation, selection, monitoring and re-evaluation of external providers | Criteria for selecting contractors, with OH&S requirements met by contractors and their workers |
| Contractors | Covered as an outsourced process or service | A sub-clause of their own (8.1.4.2): hazards in three directions, and coordination |
| Outsourcing | Must stay within the control of your QMS | Must be controlled, consistent with legal requirements (8.1.4.3) |
| What you tell providers | Six areas of requirements (8.4.3) | Your OH&S requirements, applied to contractors and their workers |
The practical answer is one process with two filters. The quality filter asks whether a purchase affects what the customer receives. The safety filter asks whether it brings a hazard, or a contractor, onto your site. Most purchases pass through one filter. Subcontractors almost always pass through both.
What clause 8.4 covers, and what it does not
Clause 8.4.1 tells you when its controls apply. There are three triggers:
- Incorporation. Products and services from external providers that are intended for incorporation into your own products and services. The steel in your fabrication, the components in your assembly, the laboratory analysis that goes into your report.
- Direct delivery. Products and services an external provider delivers directly to your customer on your behalf. The courier delivering your product, the installer you send to the client’s site.
- Outsourced processes. A process, or part of a process, that an external provider runs because you decided they would. Heat treatment, calibration, payroll for a labour hire business, the subcontractor who does a stage of the job.
If a purchase does not meet one of those three, clause 8.4 does not reach it. The paper, pens and toner from your Officeworks run are not incorporated into what you sell, are not delivered to your customer, and are not a process you outsourced. Your accountant, your cleaner and your coffee machine lease generally sit outside it too.
That matters for two reasons. First, an approved supplier list that tries to cover everyone becomes too big to maintain, and the suppliers that genuinely affect your customer get the same light touch as the stationery shop. Second, it is the most common way small businesses overbuild clause 8.4. The standard asks for control where control affects conformity to your customer’s requirements, not a register of every invoice.
A quick test
| Supplier | In 8.4? | Why |
|---|---|---|
| Steel supplier to a fabricator | Yes | Incorporated into the product |
| Subcontract electrician on your project | Yes | Outsourced part of the process |
| Courier delivering to your customer | Yes | Delivered directly to the customer on your behalf |
| Calibration laboratory for your test equipment | Yes | Outsourced process that affects the validity of your results |
| Stationery and office supplies | No | Not incorporated, not delivered to the customer, not outsourced |
| Your accountant | Usually no | Supports the business, does not form part of what you deliver |
The test is not who you pay most. It is whether what they provide ends up in, or determines, what your customer receives.
Criteria: the requirement auditors test
Clause 8.4.1 asks you to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, based on their ability to provide what you need in accordance with requirements. It also asks you to keep documented information of those activities and of any actions arising from the evaluations.
Read that sentence slowly, because there are four activities in it and most systems only do one.
- Evaluation and selection. How a supplier gets on the list in the first place.
- Monitoring of performance. How you know they are still delivering.
- Re-evaluation. When and how you decide whether they stay on the list.
- Records. Evidence that the above happened, and what you did about the results.
The finding I write most often on clause 8.4 is not “no approved supplier list”. Almost everyone has one. It is a list with no criteria behind it: names that got there because someone used them once, with nothing to show why they were chosen, how they are performing, or when anyone last asked. The second most common is criteria that are written down and never applied: a prequalification form in the procedure that no recent supplier has filled in.
What good criteria look like
Criteria should be proportionate to the risk the supplier carries for your customer. A supplier of a critical material deserves more than the business that supplies your gloves. Typical criteria, chosen to suit the supplier:
| Criterion | Evidence you might hold |
|---|---|
| Capability to meet the specification | Samples, trial order, technical data sheets |
| Quality management | Certification to ISO 9001, or your own assessment or audit |
| Licences and competence | Trade licences, qualifications of the people doing the work |
| Delivery performance | On-time delivery against purchase orders |
| Quality performance | Rejects, returns and nonconformities raised against them |
| Responsiveness | How complaints and corrective actions were handled |
| Commercial and continuity risk | Single source, financial stability, lead times |
You do not need all of them for every supplier. You need to have decided which apply to which kind of supplier, applied them, and kept the result. A one-page supplier evaluation record and an annual re-evaluation at management review will satisfy most auditors for a small business. A subcontractor carrying out safety-critical work may justify a site audit.
How much control to apply
Clause 8.4.2 asks you to make sure externally provided processes stay within the control of your quality management system, and to define the controls you apply both to the provider and to what they deliver. The extent depends on the potential impact on your ability to meet customer and statutory requirements, and on how effective the provider’s own controls are.
In practice that is a sliding scale:
- Low impact: check the delivery against the purchase order on receipt.
- Medium impact: require certificates of conformity, inspect a sample, review their test results.
- High impact: witness or hold points, first article inspection, audits at their premises.
The point most often missed is the third trigger. Outsourcing a process does not outsource the responsibility. If your customer’s product goes out with a defect introduced by your subcontractor, the nonconformity is yours.
What you tell your suppliers
Clause 8.4.3 asks you to communicate your requirements to external providers before they start. That covers:
- The processes, products and services to be provided.
- The approval of products and services, methods, processes and equipment, and the release of products and services.
- Competence, including any required qualification of persons.
- Their interactions with your organisation.
- How you will control and monitor their performance.
- Any verification or validation you or your customer intend to carry out at their premises.
Most of this belongs on the purchase order or the subcontract, not in a separate procedure. A well-written purchase order template does more for clause 8.4.3 than a policy nobody sends to suppliers.
What ISO 45001 clause 8.1.4 adds: the safety slant
Everything above applies to an ISO 45001 purchasing process too. Clause 8.1.4 then adds three things, and they all have a safety slant.
Procurement in general (8.1.4.1)
ISO 45001 asks you to control the procurement of products and services so that they conform to your OH&S management system. It does not limit this to what goes into your product. So the purchase that sits outside ISO 9001 can sit inside ISO 45001: the step ladder, the office chair, the cleaning chemicals and the new piece of plant all bring hazards into the workplace. The safety question is whether you considered that before you bought them, not after someone was hurt.
In practice that means the purchasing step, for anything that brings a hazard, checks things like the safety data sheet for a chemical, the relevant Australian Standard for PPE or ladders, guarding and risk assessment for plant, and whether the item needs training or a safe work procedure before use.
Contractors (8.1.4.2)
This is where the two clauses diverge most. ISO 45001 asks you to coordinate procurement with contractors so you can identify hazards and control risks in three directions:
- Their activities affecting you: the contractor’s work creating hazards for your workers.
- Your activities affecting them: your operations creating hazards for the contractor’s workers.
- Their activities affecting others: visitors, the public, other contractors on site.
It also asks you to make sure your OH&S requirements are met by contractors and their workers, and to define and apply criteria for selecting contractors. That is the same criteria requirement as ISO 9001, with a safety slant. Typical contractor criteria:
| Criterion | Evidence you might hold |
|---|---|
| Licences and competence | Trade licences, high-risk work licences, tickets for the plant they will operate |
| Safety management | Their WHS system, or certification to ISO 45001 |
| Safe work method statements | SWMS for high-risk construction work, reviewed before they start |
| Insurance | Workers’ compensation and public liability, current |
| Safety performance | Incident history, notices received, how previous incidents were handled |
| Site rules accepted | Induction completed, site rules signed |
| On-site performance | Inspections, observations and nonconformities raised while they worked |
An insurance certificate on file is not contractor management. It is one line of it.
Outsourcing (8.1.4.3)
Outsourced functions and processes must be controlled, consistently with legal requirements. In Australia that lands squarely on WHS law. Where you and a contractor share a duty for the same work, you each have to consult, cooperate and coordinate with the other, so far as is reasonably practicable. A contract can allocate tasks. It cannot hand over the duty. We covered what that looks like when it goes wrong in the $230,000 contractor management case.
One process, two filters
| Purchase | Quality filter (9001 8.4) | Safety filter (45001 8.1.4) |
|---|---|---|
| Steel sections for fabrication | In: incorporated into the product | In if handling or storage brings a hazard |
| Subcontract electrician on site | In: outsourced part of the process | In: contractor, hazards in three directions |
| Courier delivering to your customer | In: direct delivery on your behalf | Usually limited to your site interface |
| Step ladder from the office supplier | Out | In: brings a hazard onto site |
| Cleaning chemicals | Out | In: safety data sheet and storage |
| Your accountant | Out | Out |
Build both filters into the same purchasing step and the same supplier record, and one process satisfies both standards. Run them as two separate procedures and you will be audited twice on the same supplier, and find the two records disagree.
What an auditor will ask
If I were auditing clause 8.4 tomorrow, this is the thread I would pull:
- Show me how you decided which suppliers are in scope. A rule, not a feeling.
- Show me your criteria. For each kind of supplier, what you assess them against.
- Show me a supplier you added this year. The evaluation record, dated before the first order.
- Show me how you monitor them. Delivery and quality performance, and where it is reviewed.
- Show me a re-evaluation. When it happened, the result, and what changed.
- Show me a purchase order to a critical supplier. Does it carry your requirements, or just a part number and a price?
- Show me a supplier problem. What was raised, what they did about it, and whether it affected their status.
And for ISO 45001 8.1.4, the same thread with a safety slant:
- Show me your contractor selection criteria. What a contractor must have before they start.
- Show me a contractor on site today. Their licences, their SWMS, their induction record, and who checked them.
- Show me how you coordinated with them. The hazards you identified together, in all three directions.
- Show me a hazardous purchase. A chemical, a ladder or a piece of plant, and where the safety check happened before it arrived.
Questions 3, 5 and 9 are where most systems come apart. The list exists. The evidence of choosing, checking and reviewing does not.
Where clause 8.4 comes unstuck
- Everyone on the list. The stationery shop and the critical subcontractor treated the same, so the list is too big to keep current.
- No criteria. Names on a list with no recorded basis for choosing them.
- Criteria never applied. A prequalification form in the procedure that recent suppliers never completed.
- No re-evaluation. Suppliers approved years ago and never looked at again.
- Certificates as a substitute for monitoring. An ISO 9001 certificate is useful evidence at selection. It does not tell you how they performed on your last ten orders.
- Integrated, but only on paper. One procedure claiming to cover ISO 9001 and ISO 45001, with no safety filter applied to purchases or contractors.
- Contractor management as a folder. Insurance certificates collected, but no selection criteria, no SWMS review and no record of who checked the contractor before they started.
- Hazardous purchases waved through. Chemicals and plant bought on price, with the safety data sheet or risk assessment arriving after the product.
Frequently asked questions
Does ISO 9001 clause 8.4 apply to all of our suppliers?
No. It applies to products and services incorporated into what you deliver, products and services delivered directly to your customer on your behalf, and processes you outsource. Office supplies and most general business services sit outside it.
Do we need an approved supplier list?
The standard does not use the words “approved supplier list”. It requires criteria for evaluation, selection, monitoring and re-evaluation, and records of those activities. A list is the usual way to show the outcome, but the criteria and the records behind it are what an auditor tests.
Is a supplier’s ISO 9001 certificate enough?
It is good evidence at selection, and many organisations use it as one criterion. It is not evidence of performance on your orders, so you still need to monitor and re-evaluate.
How often should we re-evaluate suppliers?
The standard does not set a frequency. Annually is common and easy to tie to management review. Re-evaluate sooner after a significant nonconformity, a change of ownership, or a change in what you buy from them.
Is ISO 9001 8.4 the same as ISO 45001 8.1.4?
They are one number apart and do the same job, and one process can cover both, but the scope differs. ISO 9001 8.4 is limited to provision that affects what your customer receives. ISO 45001 8.1.4 covers procurement through a safety lens, and adds specific requirements for contractors (8.1.4.2) and outsourcing (8.1.4.3).
Does ISO 45001 8.1.4 require contractor inductions?
The clause does not use the word. It requires your OH&S requirements to be met by contractors and their workers, and criteria for selecting contractors. An induction is the usual way to communicate those requirements and show it happened, which is why an auditor will almost always ask for the record.
Did ISO 9001:2026 change clause 8.4?
Not in substance. None of the six main changes listed in the 2026 edition’s foreword touch clause 8.4. Our ISO 9001:2026 changes guide covers what did change.
Getting clause 8.4 right
Clause 8.4 is one of the clearest examples of a clause that works when it is built into the way you buy, and fails when it sits in a procedure nobody in purchasing has read. Our clause 8 overview shows how it fits with the rest of operation, and the clause 4.4 process approach guide shows how to build requirements into the process itself.
Streamline designs, implements and audits ISO 9001 quality and ISO 45001 safety management systems for Australian businesses, including integrated systems where one purchasing process serves both, and you deal directly with a practising ISO Lead Auditor. If you need a supplier or contractor assessed before they go on your list, our supplier evaluation auditing service does exactly that. A gap analysis will show whether your criteria would survive an audit, and ISO mentoring suits businesses that want their own people to build it. If your approved supplier list has more names than reasons, or your contractor file is mostly insurance certificates, get in touch.
General information from an auditing and management system perspective, current at 6 October 2026. Clause references are to ISO 9001:2015 and ISO 9001:2026, which share the clause 8.4 requirements, and to ISO 45001:2018. WHS duties vary by jurisdiction; check the WHS Act and regulations that apply to you.
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











