Open almost any quality system and you will probably find an Approved Supplier List: supplier name, address, status, maybe a category, maybe an approval date, maybe a checkbox that says Approved.
That’s useful. But it is not supplier management.
An Approved Supplier List tells you who is currently approved. A supplier management program should also help you answer:
- Why was this supplier approved, and on what evidence?
- What risk does the supplier create?
- What requirements were communicated?
- How is performance monitored, and what happens when it deteriorates?
- When is reevaluation required, and what triggers it?
- When should a supplier be placed on conditional status or removed?
Supplier quality is not a one-time purchasing decision. It is a lifecycle.
Approval is a decision. Supplier management is a process.
The core idea
An Approved Supplier List records the outcome of a qualification decision. It does not replace the controls that support that decision over time.
A supplier can be perfectly acceptable when approved and become a significant quality risk two years later. Ownership changes, production moves, a critical process or key sub-tier supplier changes, a certification lapses, quality failures recur, deliveries slip, complaints pile up, or corrective actions stop landing.
If the only question your QMS asks is “Are they on the Approved Supplier List?” you may miss the more important one: “Should they still be?”
A current FDA example: updating the ASL wasn’t the end of the CAPA
FDA Enforcement Example — 2026
In a July 24, 2026 warning letter to Nipro Renal Solutions USA Corporation, FDA discussed deficiencies involving supplier controls.[1] In response, the company had already reviewed and updated its Approved Supplier List and increased supplier oversight.
But the corrective-action plan went further. FDA described additional actions involving revision of the supplier-management procedure, stronger supplier-audit controls, an improved supplier corrective-action process, quality agreements for high-risk suppliers, and verification that corrective actions were effective.
That distinction is useful. Updating the supplier list was an action. It was not the entire supplier-management solution.
Source: U.S. Food and Drug Administration. Nipro Renal Solutions USA, Corporation — Warning Letter 732874, July 24, 2026. This is a medical-device enforcement example; supplier-control requirements differ by regulation, standard, product, and industry. It is cited to illustrate the broader principle that supplier oversight extends beyond maintaining a list.
Start with risk, not the same questionnaire for every supplier
One of the easiest ways to overcomplicate supplier management is to treat every supplier the same. Consider four vendors:
- Supplier A provides office furniture.
- Supplier B provides calibrated reference equipment.
- Supplier C provides a critical component incorporated into your product.
- Supplier D hosts electronic quality records used by your organization.
All four are suppliers. They do not create the same quality risk, so they should not automatically receive the same questionnaire, qualification evidence, approval level, monitoring, audit frequency, or reevaluation requirements.
A practical program starts by asking: what could happen to our product, service, data, customer, or compliance obligations if this supplier fails? The answer should drive the controls.
A simple risk-based supplier model
| Supplier risk | Example | Possible level of control |
| Low | Office supplies, general services | Basic commercial approval |
| Moderate | Noncritical production/service supplier | Defined qualification + performance review |
| High | Critical component, calibration, testing, key outsourced process | Formal qualification + ongoing monitoring |
| Critical | Supplier whose failure could directly affect safety, regulated quality, or an essential outsourced process | Enhanced qualification, monitoring, agreements, audits where justified |
These categories are examples, not regulatory classifications. Each organization should define supplier controls appropriate to its products, services, risks, customer requirements, and applicable regulations or standards.
The point is not to have four categories. It is to differentiate supplier controls based on risk.
What should supplier qualification actually establish?
Qualification should answer one question: do we have reasonable evidence that this supplier can consistently provide what we need? Depending on risk, that evidence might include certifications or accreditation, a questionnaire, technical capability, previous performance and references, a sample or first-article evaluation, a trial order, an on-site or remote audit, regulatory history, a quality-system review, a quality agreement, or verification and testing of supplied product.
Not every supplier needs every item. A packet with 40 questions is not automatically stronger than one with 10 meaningful questions. Qualification should gather information that actually influences the approval decision.
A certificate does not automatically qualify the supplier
An ISO certificate or laboratory accreditation can be valuable evidence, but it should not end the evaluation. Ask:
- Does the certification scope cover the service we are purchasing?
- Is it current, and is the issuing or accreditation body appropriate?
- Are there customer-specific requirements beyond certification?
- Does the supplier have the technical capability we actually need?
- Has performance supported continued confidence?
An ISO 9001 certificate tells you useful things about a supplier’s quality-management system, but it does not by itself prove that every shipment will meet your specification. Credentials are evidence, not a substitute for understanding the supplier’s role and risk.
The requirements have to reach the supplier
Even a highly capable supplier cannot meet requirements it never received. Purchasing and supplier controls should clearly communicate the applicable expectations—specifications and drawings, acceptance criteria, required certifications, calibration and test methods, documentation and traceability, change-notification and record-retention requirements, and packaging or shipping controls. For significant relationships, responsibilities may also be defined through contracts or quality agreements.
Qualification asks: can the supplier do the work? Purchasing controls also need to ask: have we told them clearly what we expect?
Approval should not be permanent
A common weakness is the supplier qualified years ago and never meaningfully evaluated again. The record still says Approved because nothing has caused anyone to change it.
Continued approval should be supported by ongoing evidence: incoming acceptance results, nonconformances, complaints, on-time delivery, certificate or documentation issues, calibration failures, audit results, corrective-action responsiveness, and regulatory or certification changes. Not every organization needs a complicated scorecard, but there should be a way to recognize when performance is deteriorating.
Don’t make reevaluation a calendar exercise
“All suppliers reevaluated annually” can work, but time is not the only meaningful trigger. Reevaluation may also be appropriate after significant or recurring quality failures, a location or ownership change, a critical process change, a certification or regulatory change, deteriorating performance, a major complaint, an expansion in the scope of purchased work, or a change in risk classification. A strong program combines periodic review with event-driven review where appropriate.
Your supplier scorecard should lead to a decision
Scorecards easily become another spreadsheet Quality updates every quarter: Quality 78%, Delivery 84%, overall 81%. Fine—what happens next? A useful monitoring program defines what declining performance means:
- Acceptable Continue normal monitoring.
- Watch Increase review or request improvement.
- Conditional Require corrective action or increased controls.
- Unacceptable Suspend approval, qualify an alternate source, or disqualify where appropriate.
The numbers themselves are not supplier management. The decision generated by the information is.
Supplier corrective action should be more than sending a form
When a supplier causes a significant or recurring problem, organizations commonly issue a Supplier Corrective Action Request, or SCAR. The weak version:
- Send supplier a form.
- Supplier enters “operator error.”
- Supplier says employees were retrained.
- SCAR closed.
Supplier corrective action deserves the same critical thinking as internal CAPA and effective root cause analysis: Is the investigation adequate? Does the cause make sense, and does the action address it? Was the issue scoped appropriately—could affected product already exist? Is additional incoming verification needed? Should supplier status change, and does effectiveness need monitoring?
Quality agreements: use them where they add control
Not every supplier needs a quality agreement. But for important outsourced activities, one can clarify responsibilities—specifications, change notification, deviations, complaints, CAPA, audits, records, testing, release responsibilities, subcontracting, and regulatory communication. It should clarify responsibilities, not become a 30-page document nobody uses. Use one when the complexity, regulatory environment, or risk of the relationship justifies it.
When should you audit a supplier?
Not simply because your SOP says critical suppliers are audited every year. Audits consume time for both organizations, so use them where they provide meaningful assurance: critical outsourced processes, high product or patient risk, persistent quality problems, inadequate remote qualification evidence, regulatory concerns, significant process changes, poor corrective-action performance, customer requirements, or a lack of alternative verification.
Other suppliers may be adequately controlled through documentation, performance monitoring, certifications, or testing. The question is not “Did we audit the supplier?” It is “Do our controls provide appropriate confidence in this supplier?”
When a supplier fails, your responsibility doesn’t disappear
Outsourcing work does not outsource accountability for your own product or service requirements. ISO 9001 auditing guidance emphasizes that externally provided processes, products, and services need appropriate controls, and that outsourcing a process does not remove the organization’s responsibility for conformity to applicable requirements.[3]
Source: ISO 9001 Auditing Practices Group, Guidance on External Providers. An informative auditing guidance document; it does not create certification requirements beyond the standard itself.
A useful principle
You can outsource the activity. You cannot outsource your responsibility to determine whether the result is acceptable.
Another current FDA example: qualification has to produce confidence
In an August 7, 2026 warning letter to Safrel Pharmaceuticals, FDA described inadequate oversight of suppliers and contract manufacturers.[2] The firm’s response included implementing a supplier-qualification program and quality agreements. FDA nevertheless said more detail was needed to show how the firm would:
- Determine whether suppliers and contract manufacturers were reliable and appropriately qualified
- Assess whether supplied products were consistently acceptable
- Detect and monitor CGMP noncompliance by contract manufacturers
- Define supplier selection, qualification, and disqualification controls
Source: U.S. Food and Drug Administration. Safrel Pharmaceuticals LLC — Warning Letter 730520, August 7, 2026. This is a pharmaceutical CGMP enforcement example, not a universal supplier-management checklist for every industry.
What should your Approved Supplier List actually show?
After all of that, the ASL still matters. A useful one may identify the supplier, approved scope, status, risk or category, approval date, relevant location, and last or next reevaluation where applicable.
Avoid turning it into the entire supplier record. Qualification evidence, monitoring history, corrective actions, agreements, and reevaluation decisions can live in linked records. The list should tell the organization who we can currently buy this from. The broader program should tell you why we still trust them.
A practical supplier lifecycle
- 1. Identify the supplier need
- 2. Determine supplier risk
- 3. Define qualification criteria
- 4. Evaluate and approve
- 5. Communicate requirements
- 6. Monitor performance
- 7. Manage quality issues
- 8. Reevaluate based on time, performance, or change
- 9. Continue, condition, suspend, or disqualify
The Approved Supplier List sits inside this lifecycle. It is not the lifecycle itself.
Quick self-check: do you have an ASL or a supplier program?
- Do we classify suppliers according to risk?
- Can we explain why each critical supplier was approved?
- Are qualification requirements defined before approval?
- Do purchase requirements clearly communicate quality expectations?
- Do we monitor supplier performance after approval?
- Do recurring supplier issues trigger escalation?
- Can supplier status become conditional or suspended?
- Are significant supplier changes evaluated?
- Is reevaluation based on risk and performance rather than just a date?
- Can we explain why each critical supplier should still be approved today?
If most of those answers require searching through emails or asking one person who “knows the suppliers,” the ASL may be more mature than the supplier-management process behind it.
The takeaway
The takeaway
Your Approved Supplier List answers: “Who is approved?”
Your supplier-management program should answer: “Why are they approved, how do we know they’re still performing, and what happens when they’re not?”
Supplier quality should not end when Purchasing adds a name to a spreadsheet. The strongest programs treat approval as the start of an ongoing relationship between risk, qualification, requirements, performance, issues, reevaluation, and decision.
You do not need to make supplier management complicated. You do need enough evidence to know that the external organizations your business depends on remain capable of meeting your requirements. More supplier paperwork does not automatically mean more supplier control.
References
- U.S. Food and Drug Administration. Nipro Renal Solutions USA, Corporation — Warning Letter 732874. July 24, 2026.
- U.S. Food and Drug Administration. Safrel Pharmaceuticals LLC — Warning Letter 730520. August 7, 2026.
- ISO 9001 Auditing Practices Group. Guidance on External Providers.