🏆 ISO 13485 & QMS

Subcontractors and service providers: what are the real obligations under ISO 13485?

Section 4.1.5 requires outsourced processes to be controlled in proportion to risk, without requiring the provider to be certified. Regulatory responsibility stays with the manufacturer under Article 10 of the MDR.

8 min read

The question comes up in almost every medical device manufacturing chain: does a subcontractor or service provider working for an ISO 13485 certified manufacturer have to be certified itself? The answer is not binary. Reducing it to a “yes” or a “no” creates problems in both directions: either you demand certification where control is enough, or you relax control where it becomes critical. The right question is never “is it certified?”, but “is control proportionate to risk and documented?”.

What section 4.1.5 says: control, not certification

Section 4.1.5 of ISO 13485:2016 addresses any outsourced process that has an effect on product conformity. It requires the manufacturer to monitor it and to maintain control over it. Nowhere does it say that the subcontractor must be ISO 13485 certified. It requires the elements of control to be proportionate to the associated risk and to the ability of the external party to meet the requirements, in accordance with clause 7.4 on purchasing.

In practice, this refers back to the criteria of 7.4.1: evaluation and selection of the supplier based on its capability, its performance and the effect of the product or service on the medical device. A subcontractor’s ISO 13485 certification is the most direct way to demonstrate this ability for a critical activity. It is not the only one.

The obligation many forget: the written quality agreement

Section 4.1.5 ends with a sentence that few manufacturers actually incorporate: the elements of control “shall include written quality agreements”. In other words, a written quality agreement is not an option reserved for non-certified providers. It is a baseline requirement, applicable to any outsourced process that affects conformity, whether or not the subcontractor is certified.

This agreement defines the applicable quality requirements, the allocation of responsibilities, the deliverables, the control arrangements and the notification of changes. An ISO 13485 certified subcontractor without a formalised quality agreement remains a 4.1.5 nonconformity. Certification proves ability, the written agreement proves control. The two do not substitute for one another.

When the subcontractor’s ISO 13485 certification is expected

For activities with a strong impact on the safety of the final device — outsourced sterilisation, critical assembly, performance testing, manufacturing of biocompatible components — a subcontractor’s ISO 13485 certification is the most robust solution. It demonstrates the existence of a complete QMS, audited by an independent third party.

When auditing the manufacturer, the notified body identifies the relevant suppliers and subcontractors and determines whether it is necessary to carry out a specific audit of one of them. Where the criticality justifies it, it may ask to audit the subcontractor directly or to consult its certification. This possibility is provided for by the requirements applicable to notified bodies in the MDR. Anticipating this reading avoids discovering a weak point in the middle of an audit.

Controlling a non-certified subcontractor: the levers

If the subcontractor does not hold ISO 13485 certification, the manufacturer must compensate with more active and documented control. Four levers, to be calibrated according to criticality.

Subcontractor audit

The manufacturer carries out, or has carried out, regular audits, with a documented report and follow-up of the non-conformities identified. It is the most direct lever for objectively establishing the ability of a non-certified provider.

Contractual requirements and quality agreement

Beyond the quality agreement required by 4.1.5, the contract specifies the applicable quality requirements, the expected deliverables, the performance indicators monitored and the control arrangements.

Reinforced incoming inspection

Systematic inspections upon receipt of products or services verify conformity. The extent of the verification is set by the result of the supplier evaluation and by the associated risk, in accordance with 7.4.3.

Periodic performance review

Regular meetings examine the indicators, address non-conformities and anticipate risks. They feed the supplier re-evaluation provided for in 7.4.1.

A point of proportionality, often overlooked: for a low-criticality process, an ISO 9001 certification of the provider, combined with incoming inspection, can constitute sufficient evidence of ability. Everything hinges on the actual effect of the process on the final device, not on the name of the standard displayed.

What the manufacturer can never delegate

Whatever the quality of the subcontractor and the rigour of the control exercised, the regulatory responsibility remains that of the manufacturer. Article 10 of the MDR is explicit: the manufacturer is responsible for the conformity of its devices, including when design or manufacturing activities are carried out by third parties. A subcontractor’s failure does not exonerate it. Section 4.1.5 puts it in the same terms: the organisation retains responsibility for conformity of the outsourced processes.

That is where the real decision lies. Outsourcing a process transfers execution, never responsibility. The manufacturer who has understood this does not seek to certify everything. It documents control proportionate to risk, and it maintains it.

Wondering whether the control of your subcontractors will hold up against your notified body’s audit? Talk to us.

Topics covered:

ISO 13485 subcontractor medical device QMS service provider ISO 13485 outsourced process