Technical GuideAugust 31, 2026 · 19 min read · VEMERIX

How to Review a Supplier's Purchasing Controls and Outsourcing File After QMSR: Why 21 CFR 820.50 Is Reserved, What ISO 13485 Clauses 4.1.5 and 7.4 Require, What Compliance Program 7382.850 Inspects, and a Buyer Acceptance Checklist

A practical buyer's audit guide for medical device purchasing and outsourcing files: why 21 CFR 820.50 is reserved under QMSR, how ISO 13485 Clauses 4.1.5 and 7.4 carry the legal duties, what FDA Compliance Program 7382.850 inspects, why supplier-audit reports are no longer exempt, and a 7-point incoming acceptance checklist.

QMSRPurchasing ControlsSupplier QualificationISO 13485
VEMERIX technical guide cover illustrating the 7-point buyer audit workflow for medical device purchasing controls, outsourced sterilization, QMSR 21 CFR Part 820 compliance under ISO 13485 Clauses 4.1.5 and 7.4, and CP 7382.850 inspection gates.

Is 21 CFR 820.50 Still the Law, or Is It Reserved, and Why Do Cornell LII and FDA's Own Purchasing PDF Still Rank?

For nearly thirty years—from the promulgation of the 1996 Quality System Regulation (QSReg) until 2 February 2026—the phrase '21 CFR 820.50' was the universal shorthand for medical device purchasing controls in the United States. Regulatory questionnaires, supplier audit checklists, and distributor RFQs routinely demanded: 'Please attach your 21 CFR 820.50 purchasing control procedure.'

As of 2 February 2026, that requirement is obsolete. Under the FDA Quality Management System Regulation (QMSR) final rule published in the Federal Register (89 FR 7523, document 2024-01709),2 Subparts C through O of 21 CFR Part 820 were entirely removed and designated as [Reserved].1 Subpart E, which housed section 820.50, no longer contains operative legal text.1

Instead, 21 CFR 820.7 incorporates by reference the 2016 edition of ISO 13485 (Medical devices — Quality management systems — Requirements for regulatory purposes) and Clause 3 of ISO 9000:2015.1 Section 820.10 explicitly mandates that finished-device manufacturers establish and maintain a quality management system that complies with the applicable requirements of ISO 13485.1 Failure to comply adulterates the device under Section 501(h) of the Federal Food, Drug, and Cosmetic Act (FD&C Act, 21 U.S.C. 351(h)).1

Despite this legal reality, international buyers frequently encounter supplier quality manuals and consultant whitepapers that continue to cite 21 CFR 820.50 as current law. This persistence is fueled by stale online search results:

  • Cornell Law School Legal Information Institute (LII): A top-ranking search result for '21 CFR 820.50' still presents the page titled 'Quality System Regulation', displays 'Subpart E—Purchasing Controls', and recites the legacy 1996 text ('Each manufacturer shall establish and maintain procedures...') without reflecting the QMSR revision.8 Relying on third-party aggregators rather than the official Electronic Code of Federal Regulations (eCFR) creates false audit baselines.
  • FDA's Legacy Purchasing Controls Presentation (media/94743): An FDA slide deck still hosted on fda.gov titled 'Purchasing Controls' still ranks prominently on search engines.9 While historically valuable for understanding regulatory intent, it cites 820.50(a) and 820.50(b) and discusses the 1996 preamble rather than QMSR mechanics.
  • MDSAP AU P0002.008 Chapter 7: The current Medical Device Single Audit Program (MDSAP) audit model document (AU P0002.008) hosted by FDA still lists 'FDA: 21 CFR 820.50(b)' in its country-specific requirements column for Purchasing.5 This is an administrative holdover in the MDSAP document; investigators conducting FDA inspections under QMSR do not cite 820.50(b).4

When reviewing a supplier's quality management documentation, seeing '21 CFR 820.50' in an active Standard Operating Procedure (SOP) revised after February 2026 is an immediate red flag. It indicates that the supplier copied legacy text without updating their QMS architecture to incorporate ISO 13485:2016 under 21 CFR Part 820.

Document / Record TypeGoverning Standard / AuthorityWhat It Actually ProvesCommon Overclaims & Audit TrapsBuyer Verification Action
ISO 13485:2016 CertificateISO 13485:2016 / Accredited Registrar (IAF MLA)The manufacturer has an audited QMS covering the facilities and product scopes listed on the certificate.Does NOT prove that purchasing controls were executed for the specific SKU, nor does it exempt the site from FDA QMSR inspections.Check certificate validity via how to verify the ISO 13485 certificate before you treat it as evidence of purchasing control; verify scope covers manufacturing and outsourced processes.
Approved Supplier List (ASL) & Risk TieringISO 13485:2016 Clause 7.4.1 / QMSR 21 CFR 820.10The manufacturer formally evaluated, approved, and assigned risk-based control levels to all component vendors and service providers.Does NOT prove ongoing compliance if the list contains unmonitored legacy vendors or lacks risk-based rationale.Verify that contract sterilizers, raw material suppliers, and packaging converters for your SKU are actively listed with explicit risk categories.
Quality Agreement (Technical Agreement)ISO 13485:2016 Clause 4.1.5 & 7.4.2 / QMSRDefines binding quality obligations, specifications, acceptance criteria, and mandatory pre-change notification rules.A generic commercial supply contract without technical quality clauses or change control protocols is NOT a Quality Agreement.Confirm agreement includes mandatory prior written notice before any supplier changes to materials, tooling, sub-tier suppliers, or processes.
Outsourced Process Validation (EO / Radiation)ISO 11135 (EO) / ISO 11137 (Radiation) / Clause 4.1.5Demonstrates that outsourced sterilization delivers Sterility Assurance Level (SAL 10⁻⁶) and acceptable residuals.An ISO 13485 certificate from the sterilizer is NOT a cycle validation report.Review the cycle-validation dossier, not only the sterilizer's ISO 13485 certificate. For EO see what EO validation evidence a contract sterilizer must sit behind in the purchasing file; for radiation see what radiation-sterilization evidence belongs behind an outsourced process.
Batch Incoming Verification & Release RecordsISO 13485:2016 Clause 7.4.3 / QMSR 21 CFR 820.10Objective evidence that components, raw materials, or sterilized finished lots met predefined acceptance specifications.A vendor Certificate of Analysis (CoA) without documented incoming verification or sampling rationale is insufficient.Inspect receiving inspection logs, test reports, and Certificate of Conformance (CoC) matching the specific lot shipped.
Supplier Audit & Performance Evaluation ReportsISO 13485:2016 Clause 7.4.1 / QMSR (Comment 55)Documents periodic audits, nonconformity tracking, corrective actions, and annual scorecards evaluating supplier performance.A one-time qualification questionnaire completed at onboarding in 2022 does NOT satisfy ongoing monitoring requirements.Request the most recent re-evaluation report; confirm supplier audit reports are complete and available for regulatory inspection.
FDA Establishment Registration & Listing21 CFR Part 807 / openFDA DirectoryConfirms the facility registered with FDA and listed device product codes (e.g., Contract Sterilizer or Contract Manufacturer).An FEI registration listing does NOT prove QMS compliance, device clearance, or effective purchasing controls.Cross-check FEI and establishment type as a baseline directory fact, but never substitute a registration screenshot for a purchasing file.
Table 1: Document Differentiation in Medical Device Supplier Purchasing & Outsourcing Reviews

What ISO 13485 Clauses Actually Carry Purchasing and Outsourcing After QMSR: 4.1.5 vs 7.4.1 vs 7.4.2 vs 7.4.3?

Because 21 CFR 820.50 is reserved, regulatory obligations for purchasing and outsourcing under QMSR flow entirely through the incorporated clauses of ISO 13485:2016.1 Auditors and buyers must navigate four primary clause areas across two distinct sections of the standard:

  • Clause 4.1.5 (Outsourcing): CP 7382.850 Attachment A maps the Outsourcing inspection element to Clause 4.1.5.4 Investigators are told to verify manufacturer oversight of processes outsourced to third parties. This article does not reproduce the paywalled ISO 13485 clause body; the inspection map and the Federal Register's risk-proportionate supplier-evaluation language are the public tests used here.2,4
  • Clause 7.4.1 (Purchasing Process): Attachment A maps Purchasing Process to Clause 7.4.1.4 The Federal Register states that Clause 7.4 requires evaluation of suppliers in terms of ability and performance, commensurate with the effect of the purchased product on finished-device quality and the proportionate risk associated with the finished device, plus monitoring and reevaluation.2 MDSAP AU P0002.008 Chapter 7 likewise treats supplier evaluation as not a one-time assessment.5
  • Clause 7.4.2 (Purchasing Information): Attachment A maps Purchasing Information and Purchased Product to Clauses 7.4.2 and 7.4.3 together.4 MDSAP Chapter 7 Task 8, a public FDA-hosted audit-model task, tells auditors to confirm that specified purchase requirements are adequate before they are communicated to the supplier and that a written agreement requires the supplier to notify the manufacturer about changes in the product.5 That leftover MDSAP column still prints 21 CFR 820.50(b); use CP 7382.850, not that leftover cite, as the QMSR inspection map.4,5
  • Clause 7.4.3 (Verification of Purchased Product): Attachment A places purchased-product verification with Clause 7.4.3.4 MDSAP Chapter 7 describes an appropriate combination of supplier controls and acceptance activities based on the effect of the supplied product on the finished device.5 A vendor Certificate of Analysis sitting unread is not, by itself, that verification record.

A common structural mistake during supplier evaluations is conflating Clause 4.1.5 (outsourcing a manufacturing or sterilization process) with Clause 7.4.1 (purchasing raw materials or off-the-shelf components). While both require risk-proportionate control, outsourced processes directly performing device manufacturing operations require deeper technical oversight, validated process control, and formal Quality Agreements under Clause 4.1.5.

What Compliance Program 7382.850 Tells Investigators to Open in the Outsourcing and Purchasing QMS Area

On 2 February 2026, FDA officially implemented Compliance Program 7382.850 (Inspection of Medical Device Manufacturers), superseding the legacy Quality System Inspection Technique (QSIT, CP 7382.845) and CP 7383.001.3,4

CP 7382.850 structures FDA inspections around six core QMS areas: (1) Change Control; (2) Design and Development; (3) Management Oversight; (4) Measurement, Analysis, and Improvement; (5) Outsourcing and Purchasing; and (6) Production and Service Provision.4 Named FDA officials, speaking at MedCon about inspections between 2 February and 31 March 2026, reported that the most Form 483s were issued in risk management, followed by outsourcing and purchasing.10 That ranking is secondary conference reporting of named officials about a short early window; it is not a published FDA 483 table and is not incidence. It is why this page owns the purchasing file after the ISO 14971 risk-management file review rather than a second 483 census.

Attachment A of CP 7382.850 (page 75) provides the explicit inspection map for the Outsourcing and Purchasing area. The declared purpose of this inspection area is:

To ensure outsourced processes, outsourced activities, and/or purchased product are effectively monitored and controlled, resulting in product that conforms to specified requirements.FDA Compliance Program 7382.850, Attachment A, page 75 of 78

Attachment A directly maps inspection activities to the specific ISO 13485:2016 clauses:

QMS Inspection Sub-ElementApplicable ISO 13485:2016 ClauseInvestigator Focus & Inspection Directives (CP 7382.850)What FDA Investigators Ask to Open
Outsourcing ControlClause 4.1.5Verify the manufacturer maintains oversight and documented control over processes outsourced to third parties (e.g., contract sterilization, contract assembly, testing labs). Ensure controls are proportionate to risk.Outsourced process procedures, written Quality Agreements, sterilization validation protocols, and evidence of manufacturer oversight.
Purchasing Process & Supplier EvaluationClause 7.4.1Evaluate criteria for supplier selection, initial qualification, ongoing monitoring, and re-evaluation. Confirm controls depend on the effect on finished device safety and quality.Approved Supplier List (ASL), supplier risk-tiering methodology, initial qualification records, and periodic re-evaluation files.
Purchasing Information & Change NotificationClause 7.4.2Confirm purchase orders and technical specifications accurately describe product requirements. Verify written agreements requiring suppliers to notify of changes prior to implementation.Current purchase orders, raw material specifications, signed supplier quality agreements, and supplier change notification logs.
Verification of Purchased ProductClause 7.4.3Assess inspection and verification activities for incoming materials and outsourced services. Ensure nonconforming incoming product is segregated and controlled.Receiving inspection SOPs, sampling plans, Certificates of Analysis (CoA) verification records, and incoming nonconformance reports (NCMRs).
Table 2: FDA Compliance Program 7382.850 Outsourcing & Purchasing Inspection Element Map

CP 7382.850 is more precise than the slogan 'FDA never inspects component vendors'. In the PMA inspection note, FDA states that it has the authority to inspect component manufacturers when necessary, but rarely performs those inspections outside of the PMA program. When inspecting a domestic component manufacturer, the investigator should issue an FDA 482 and should not issue an FDA 483 to the component manufacturer. Issues identified there should be handled through the finished-device manufacturer's outsourcing and purchasing activities under ISO 13485 Clauses 4.1.5 and 7.4 (and monitoring and measurement of product under Clause 8.2.6) and cited on the finished-device manufacturer's 483 during the PMA inspection.4 That is why a component FEI screenshot does not close the labelled manufacturer's purchasing file.

Does an ISO 13485 Certificate, an MDSAP Certificate, or a 2022 Supplier-Qualification Form Close the File?

In international procurement, suppliers frequently attempt to satisfy purchasing audits by providing one of three static documents: an ISO 13485 certificate, an MDSAP audit certificate, or a completed supplier qualification questionnaire dated two to four years prior. None of these documents closes the purchasing file.

First, holding an ISO 13485 certificate or an MDSAP certificate certifies that the organization has been audited against general QMS requirements by an auditing organization. However, FDA explicitly stated in the QMSR preamble that ISO 13485 certification is neither required by FDA nor does it exempt a manufacturer from FDA inspection.2,3 An ISO certificate proves the existence of a quality system; it does not prove that the specific incoming batch of medical laser fibers, surgical staples, or polyurethane dressing foam was purchased against approved specifications, received with verified CoAs, or sourced from an actively monitored vendor.

Second, a one-time onboarding qualification form (e.g., a vendor questionnaire filled out in 2022 when the supplier was first added to the ASL) is completely insufficient under ISO 13485 Clause 7.4.1 and QMSR. The Federal Register final rule preamble emphasizes:

Clause 7.4 of ISO 13485 specifies that an organization must evaluate suppliers of purchased products in terms of ability and performance of the supplier, commensurate with the “effect of the purchased product on the quality of” the final finished device and in terms of the “proportionate risk associated with” the final finished device. Additionally, monitoring and reevaluation of suppliers and the performance of purchased products is required.Federal Register 89 FR 7523, document 2024-01709, Comment 40 response

If a supplier's purchasing file shows an initial desktop audit from 2022 but no documented monitoring, reevaluation, or equivalent performance records across subsequent years, the file does not match that Federal Register description of Clause 7.4.2 MDSAP Chapter 7 is equally direct: supplier evaluation is not a one-time assessment.5 Ongoing monitoring is a continuing duty, not an onboarding event.

Can FDA Now Read Supplier-Audit Reports That Used to Sit Behind 21 CFR 820.180(c)?

One of the most consequential structural changes introduced by the QMSR is the complete elimination of the audit confidentiality shield previously found in 21 CFR 820.180(c).2

Under the legacy 1996 Quality System Regulation, 21 CFR 820.180(c) explicitly stated that FDA investigators would not review or copy reports of internal quality audits, management reviews, or supplier audit reports during routine inspections (unless requested under specific judicial or regulatory warrant procedures). This allowed manufacturers to conduct candid, highly critical audits of external component vendors and contract sterilizers without fearing that the audit findings would automatically become FDA Form 483 observations.

In the QMSR final rule (Federal Register 2024-01709), numerous industry stakeholders submitted comments urging FDA to retain the 820.180(c) exemption. In Comment 55, FDA rejected these requests:

FDA disagrees that it should maintain the exceptions set forth at § 820.180(c). One of the primary purposes for this rulemaking effort is to move as closely as possible toward global harmonization and alignment. From a global perspective, the exceptions the comment references are not available to manufacturers being inspected by other regulators or being audited by other entities (e.g., MDSAP auditing organizations), and thus, such manufacturers will not be additionally burdened by making these records available.Federal Register 89 FR 7523, document 2024-01709, Comment 55 response

21 CFR 820.35 adds complaint, servicing and UDI content on top of ISO 13485 Clause 4.2.5 (control of records). It does not recreate the former 820.180(c) exceptions.1 Because those exceptions were not carried into the QMSR, supplier-audit reports that the manufacturer already keeps as Clause 7.4 evaluation records are no longer shielded from routine FDA review.2 Comment 55 also notes that investigators already had access to data used to inform management reviews, such as nonconformances, complaints, and corrective actions resulting from internal and supplier audits.2

For buyers, this creates a vital audit principle: supplier audit reports cannot be hidden or redacted during buyer due diligence on the pretext of regulatory confidentiality. If a critical supplier audit identified major nonconformities (e.g., sterilization bioburden spikes or uncalibrated tooling), those findings must have documented corrective actions in the purchasing file, because FDA investigators will inspect those exact records.

Who Is the Manufacturer When EO Sterilization Is Contracted Out, and Does Part 820 Apply to a Component Vendor?

Regulatory accountability across medical device supply chains depends on precise statutory definitions under 21 CFR Part 820. A widespread error in international procurement is treating all external entities simply as 'vendors'.

Under 21 CFR 820.1 and 820.3, the QMSR establishes distinct legal statuses across supply chain participants:

  • Finished Device Legal Manufacturer: Any entity that manufactures, prepares, propagates, compounds, or processes a finished device. Fully subject to all applicable QMSR requirements, including ISO 13485 Clauses 4.1.5 and 7.4.
  • Contract Sterilizer of a Finished Device: Under 21 CFR 820.1, manufacturers subject to this part include those that perform contract sterilization.1 The contract sterilizer is subject to the QMSR for the operations in which it is engaged and may be inspected as a registered establishment. The finished-device legal manufacturer who contracts out sterilization still maintains Clause 4.1.5 and 7.4 oversight over that sterilizer.4 Outsource the operation, not the accountability — the same principle owned as a one-paragraph rule in who is the legal manufacturer before you review their purchasing file.
  • Specification Developer: An entity that develops specifications for a device that is manufactured by a contract manufacturer. Subject to QMSR (including design controls and purchasing controls over the contract manufacturer).1
  • Component and Raw Material Manufacturers: Under 21 CFR 820.1(a)(2), Part 820 does not apply to manufacturers of components or parts of finished devices, though such manufacturers are encouraged to consider the regulation as appropriate.1 A vendor of titanium staples, moulded polymer rings, tubing, or optical fiber as a component is not itself under Part 820. That exclusion does not mean FDA can never visit a component site. CP 7382.850's PMA note says FDA has authority to inspect component manufacturers when necessary, rarely does so outside the PMA program, and cites identified issues on the finished-device manufacturer's 483.4
Supply Chain Entity RoleStatutory Definition (21 CFR 820.1 / 820.3)Directly Subject to QMSR (Part 820)?Direct FDA Inspection Target?Purchasing & Outsourcing Duties
Finished Device Legal ManufacturerManufacturer of finished medical deviceYES — Full QMSR compliance required under 820.10YES — Direct inspection under CP 7382.850Must establish ASL, risk-tiering, Quality Agreements, incoming verification (7.4.3), and oversight of all outsourced processes (4.1.5).
Contract Sterilizer (EO / Radiation)Performs contract sterilization of finished device (820.1 / 820.3)YES — Subject to QMSR for sterilization operationsYES — as a manufacturer for the operations in which it is engagedMust control its own sterilization operations. The labelled finished-device manufacturer still holds 4.1.5 / 7.4 oversight and should point at ISO 11135 or ISO 11137 validation evidence, not only the sterilizer's certificate.
Specification DeveloperDevelops specifications for contract-manufactured deviceYES — Subject to QMSR as a manufacturerYES — Direct inspection for design and purchasing oversightMust maintain purchasing controls and Quality Agreements governing the contract manufacturing facility.
Component / Raw Material SupplierManufacturer of components or parts (820.1(a)(2))NO — 820.1(a)(2) excludes manufacturers of components or parts; they are encouraged to consider Part 820Rarely, and typically not outside PMA. CP 7382.850: 482 may issue to a domestic component site; 483 is cited on the finished-device manufacturerNo direct QMSR duty. The finished-device manufacturer must still run Clauses 4.1.5 / 7.4 over that vendor.
Table 3: Supply Chain Roles, Statutory QMSR Application, and Purchasing Control Duties

Understanding this split resolves a common industry misunderstanding: buyers cannot demand that a raw-material or component shop produce an 'FDA QMSR compliance certificate' as if Part 820 applied to that shop. The component vendor is excluded at 820.1(a)(2); the legal responsibility sits on the finished-device manufacturer's purchasing and incoming-verification file.1,4 Accessories that FDA treats as finished devices are a different case — the QMSR landing page notes that a manufacturer of accessories is subject to the QMSR.3

Did QMSR Create a Legal Definition of 'Critical Supplier', or Must the Manufacturer Risk-Tier Without That Term?

In many legacy quality systems, manufacturers categorized vendors into 'critical' and 'non-critical' suppliers based on arbitrary internal rules, often applying rigorous purchasing controls only to those labeled critical. When FDA drafted the QMSR, several industry stakeholders requested an explicit regulatory definition of 'critical supplier'.

In the preamble to the final rule (Federal Register 2024-01709), FDA explicitly declined to define 'critical supplier'.2 FDA explained that ISO 13485:2016 does not use a binary 'critical vs non-critical' definition, but instead establishes a comprehensive, risk-proportionate principle:

FDA disagrees with this comment and does not consider a definition of the term “critical supplier” to be needed in the QMSR. We acknowledge that purchased products and the suppliers of those products can be critical to ensuring safety and effectiveness throughout a medical device's life cycle. The QMSR describes a process of continuous evaluation to address products and suppliers.Federal Register 89 FR 7523, document 2024-01709, Comment 40 response

Under QMSR, risk-tiering must be continuous and granular, directly connected to the device's how to review the ISO 14971 risk-management file that purchasing controls must feed. Manufacturers must document risk-based rationales for every supplier category on their Approved Supplier List (ASL):

  • Higher-effect / sterility-assurance suppliers (illustrative manufacturer-defined tier, not a QMSR legal class): Contract sterilizers, sterile-barrier packaging converters, and patient-contact polymers or metals whose change would affect finished-device safety or performance. Typical documented controls: on-site or equivalent QMS audits, a quality agreement with change notification before implementation, and incoming or other verification commensurate with risk.
  • Moderate-effect suppliers (illustrative): External testing laboratories, non-sterile secondary packaging, and catalogue hardware that still feeds a specified requirement. Typical documented controls: qualification records, accreditation or method evidence where relied upon, and periodic re-evaluation — not a one-time 2022 form.
  • Lower-effect catalogue items (illustrative): Shipping cartons and off-the-shelf commodities whose failure mode does not reach the sterile barrier or patient-contact materials. Typical documented controls: receiving inspection against the specified requirement. Identical annual questionnaires for a contract sterilizer and a carton vendor remain a red flag.

An audit red flag is an Approved Supplier List where all suppliers receive identical treatment (e.g., a simple annual questionnaire) regardless of whether they supply shipping boxes or execute ethylene oxide sterilization cycles.

What MDR Article 10(9)(d) and Annex IX 2.3 Add for an EU File, and What GB/T 42061-2022 Adds for a China File

For medical device manufacturers supplying global markets, purchasing controls must simultaneously satisfy US FDA QMSR, European Union Medical Device Regulation (EU MDR 2017/745), and China National Medical Products Administration (NMPA) standards. While all three frameworks align around ISO 13485 principles, specific regional requirements govern how purchasing files are audited.

European Union (EU MDR 2017/745): Article 10(9)(d) of the MDR mandates that the manufacturer's Quality Management System address resource management, including the 'selection and control of suppliers and sub-contractors'.6 Furthermore, under MDR Annex IX, Chapter I, Section 2.3, the Notified Body assessing the manufacturer's QMS is required to:

identify relevant suppliers and/or subcontractors of the manufacturer, and consider the need to specifically audit any of those suppliers or subcontractors or bothRegulation (EU) 2017/745 (MDR), Annex IX, Chapter I, Section 2.3

Annex IX 2.3 is a duty to consider a targeted supplier or subcontractor audit; it is not a promise that every Notified Body will run unannounced visits at every contract sterilizer.6 If the EU technical file will be assessed under Annex IX, the quality agreement should not block that access. That MDR duty is additional to QMSR, not a substitute for the CP 7382.850 file.

China NMPA (GB/T 42061-2022): GB/T 42061-2022 (Medical devices — Quality management systems — Requirements for regulatory purposes) is the current national QMS standard: 现行 on the openstd card, published 14 October 2022, implemented 1 November 2023, competent department NMPA.7 The card states that the standard adopts an ISO/IEC organisation standard and withholds full text for copyright, so this article does not treat the card as a clause-level read or reprint ISO 13485 body text under a GB number.7 Use it as the China QMS wrapper for the same purchasing question, not as a substitute file. The site's ISO 13485 certificate guide still names YY/T 0287-2017; this page does not declare that document withdrawn.

Regulatory JurisdictionGoverning Legal / Standard CitationKey Purchasing & Outsourcing RequirementsRegulatory Inspection & Audit Authority
United States (FDA)21 CFR Part 820 (QMSR) / ISO 13485:2016 Clauses 4.1.5 & 7.4 (incorporated via 820.7 / 820.10)Outsourcing control (4.1.5); risk-based supplier evaluation (7.4.1); purchasing specs & change notification (7.4.2); incoming verification (7.4.3). Supplier audits inspectable per Comment 55.FDA Investigators using Compliance Program 7382.850 (Outsourcing & Purchasing QMS area).
European Union (MDR)Regulation (EU) 2017/745, Article 10(9)(d) & Annex IX Section 2.3Article 10(9)(d): QMS shall address selection and control of suppliers and sub-contractors. Annex IX 2.3: the notified body shall identify relevant suppliers/subcontractors and consider specifically auditing them.Notified body QMS assessment under Annex IX; supplier/subcontractor audit is a considered step, not an automatic unannounced visit at every vendor.
China (NMPA)GB/T 42061-2022 (现行; implemented 1 November 2023; NMPA competent department). Openstd withholds full text.China QMS wrapper for ISO 13485 clause numbering, including purchasing. Not a purchasing file. Do not treat YY/T 0287-2017 as withdrawn in this article.NMPA / provincial MPA as the China competent system; this page does not convert a GB card into an inspection checklist.
Global Harmonization (MDSAP)MDSAP AU P0002.008 Chapter 7 (Purchasing)Harmonized purchasing-process audit model. Chapter 7 still prints leftover 'FDA: 21 CFR 820.50(b)' — use CP 7382.850 for QMSR inspections. MDSAP as a Canadian licence condition is a different decision, owned by the Health Canada MDL/MDEL placement guide.Recognized Auditing Organizations (AOs) issuing MDSAP Audit Reports and Certificates.
Table 4: Multi-Jurisdiction Purchasing & Outsourcing Regulatory Requirements Matrix

Worked Examples: A CE-Marked Circumcision Ring with Contract EO, an NMPA-Only Laser Fiber, and an NPWT Dressing Kit

To understand how purchasing controls and outsourcing files function in practice, consider three worked examples from sterile minimally invasive surgery and wound care consumables:

Example 1: CE-marked circumcision device with outsourced EO sterilization.
The public Circumcision Device page describes a single-use, EO-sterilized, CE-marked self-detaching ring supplied sterile in individual blister packs, with adult and pediatric variants.13 If EO sterilization is contracted out, the labelled manufacturer's purchasing/outsourcing file — not the sterilizer's certificate hanging on the wall — is the QMSR test.

  • Clause 4.1.5 outsourced-process file: Point at the ISO 11135 cycle-validation evidence the EO validation acceptance guide already owns. A sterilizer ISO 13485 PDF is not that dossier.
  • Quality agreement / change notice: MDSAP Chapter 7 Task 8 looks for a written agreement that the supplier notify the manufacturer about changes in the product before they are treated as accepted purchasing information.5 Classify a sterilizer or process change using how to classify a sterilizer or component change after the purchasing file flags it.
  • Clause 7.4.3 batch release: Each shipped lot still needs incoming or other verification that the purchased sterilization service met the specified requirements for that lot — typically a certificate of processing plus the manufacturer's release decision — not a 2022 onboarding form.

Example 2: NMPA-registered disposable medical laser fiber (purchased optical fiber and connector as components).
The public laser-fiber page identifies an NMPA Class II single-use medical laser fiber (Lu Mech Reg. 20192010517) for 1470 nm endovenous workflows, paired with a partner-supplied diode laser source.14 No Medison CE claim is made for this SKU. The partner-supplied NOVACURE console is not a Medison-manufactured capital system.

  • Clause 7.4.1 component risk-tiering: Optical fiber and connector components that determine finished-fiber performance are high-effect purchased product. The component manufacturer is not subject to Part 820 per 820.1(a)(2), so the verification duty sits on the finished-device manufacturer.1
  • Clause 7.4.2 purchasing information: Purchase documents should specify the attributes that affect finished-device performance (core geometry, numerical aperture, connector interface, jacket biocompatibility). This page does not publish unpublished numeric tolerances for this SKU.
  • Clause 7.4.3 incoming verification: Incoming lots should be verified against those specified requirements by inspection or other activities the manufacturer has defined. A vendor CoA without a documented verification decision does not close 7.4.3.

Example 3: Negative-pressure wound therapy dressing kit (purchased foam, drape, and tubing).
The public NPWT dressing-kit page describes PVA/PU foam variants and a 400–600 µm pore structure.15 Those published attributes are purchasing information the quality agreement should lock, not a clinical superiority claim.

  • Purchased-material biological evaluation: Foam and drape suppliers should be able to point the finished-device manufacturer at ISO 10993 evidence appropriate to contact and duration, reviewed as in how to review the biocompatibility file for a purchased polymer or metal component.
  • Sterile-barrier packaging converter: The pouch or tray converter should sit behind ISO 11607 evidence as in what sterile-barrier evidence a packaging converter must supply.
  • Vendor change control: The quality agreement should require notification before implementation of changes that affect specified attributes (for this kit family, including the published 400–600 µm pore structure). This page does not invent a mandatory 180-day clock; the manufacturer sets a defined lead time and FDA inspects whether the agreement actually works.5

A string search of the public FDA Medical Device Recall database (snapshot export date 24 July 2026; 58,785 events) is a vocabulary check, not an incidence rate and not a QMSR 483 table.12 Among 985 events whose reason-for-recall or root-cause text matched supplier, vendor, purchasing, outsourcing, contract-sterilizer, component-manufacturer or subcontract language, the leading coded root-cause labels were Vendor change control (288) and Nonconforming Material/Component (220). Those labels are FDA-coded vocabulary on matching rows. They do not prove that QMSR caused the recalls, that sterile consumables dominate the set, or that an unannounced sub-tier change was the mechanism in a majority of cases.

Coded root-cause labels among supplier-string recall matches
Vendor change controlRecall Events: 288288Nonconforming Material/ComponentRecall Events: 220220OtherRecall Events: 149149Under Investigation by firmRecall Events: 110110Process controlRecall Events: 8787All other coded labels amongmatchesRecall Events: 131131
View chart data
CategoryRecall Events
Vendor change control288
Nonconforming Material/Component220
Other149
Under Investigation by firm110
Process control87
All other coded labels among matches131

FDA Medical Device Recall database snapshot, export date 24 July 2026: 58,785 events. 985 events matched a supplier/vendor/purchasing/outsourcing/contract-sterilizer/component-manufacturer/subcontract regex on reason_for_recall or root_cause_description. Bars are the leading FDA-coded root_cause_description values among those matching rows, plus the residual 'All other coded labels'. Counts are directory vocabulary, not incidence, not causality, and not QMSR inspection outcomes.

Source: FDA Medical Device Recalls public database, 24 July 2026 openFDA bulk snapshot. Independent recompute 2026-08-31. Regex matches 985 / 58,785. Vendor change control 288; Nonconforming Material/Component 220; Other 149; Under Investigation by firm 110; Process control 87; all remaining coded labels 131.

The useful buyer inference is narrow: 'Vendor change control' is a coded label the purchasing file is supposed to prevent, and it is the most common coded label among these string-matched rows (288 of 985).12 That is why a quality agreement without a working change-notification clause, and incoming verification that never looks past a vendor CoA, are send-back findings — not because this snapshot measures how often those failures occur in sterile single-use devices.

A Seven-Point Incoming Checklist, Red Flags, and the Pack to Request Before the First Commercial Lot

Before releasing or accepting the first commercial lot of a sterile medical device, the buyer's quality engineering team should execute a systematic 7-point audit of the supplier's purchasing and outsourcing dossier:

  1. Verify Regulatory & Standard Alignment: Confirm that the supplier's Quality Manual and Purchasing SOPs reference ISO 13485:2016 Clauses 4.1.5 and 7.4 under 21 CFR Part 820 (QMSR), MDR Article 10(9)(d), and China GB/T 42061-2022. Reject procedures that cite 21 CFR 820.50 as live law.
  2. Audit the Approved Supplier List (ASL): Cross-check every supplier of raw materials, primary packaging, subassemblies, and testing services for your specific SKU against the active ASL. Verify that risk tiers and approval dates are current.
  3. Inspect Ongoing Supplier Re-Evaluation Records: Request supplier performance files for the past 12–24 months. Verify continuous monitoring: quality scorecards, lot acceptance rates, nonconformance history, and formal periodic re-audits.
  4. Review Executed Quality Agreements: Ensure signed Quality Agreements exist for all Tier 1 critical suppliers (contract sterilizers, sterile-barrier packaging converters, critical component makers). Confirm mandatory prior written change notification clauses.
  5. Validate Clause 4.1.5 Outsourced Process Dossiers: If sterilization or packaging is outsourced, inspect the complete validation report (ISO 11135 for EO, ISO 11137 for radiation, ISO 11607 for packaging) with documented bioburden, sterility assurance (SAL 10⁻⁶), and residual data.
  6. Audit Clause 7.4.3 Incoming Verification Records: Review receiving inspection logs and test records for the specific production lot being shipped. Confirm raw material CoAs were independently verified against incoming acceptance criteria.
  7. Verify Multi-Jurisdiction Audit Rights: For EU MDR or US distribution, ensure Quality Agreements contain clauses granting access to regulatory authorities (FDA, Notified Bodies) to inspect subcontractor facilities.
Audit Finding / Red FlagRegulatory Failure MechanismInspection Risk LevelMandatory Buyer Action Before Lot Release
Purchasing SOP revised in 2026 still cites 21 CFR 820.50 as live lawFailure to incorporate ISO 13485:2016 under QMSR 21 CFR 820.7 / 820.10Moderate (Administrative / QMS gap)Issue audit finding; require supplier to update QMS citation structure to ISO 13485 Clauses 4.1.5 and 7.4.
Supplier on ASL qualified via a one-time 2022 questionnaire with no subsequent monitoringDoes not match Federal Register Comment 40 / Clause 7.4 monitoring and reevaluation, or MDSAP Chapter 7's 'not a one-time assessment'High (CP 7382.850 Outsourcing and Purchasing area)HOLD lot release. Request current supplier audit report, quality scorecard, and re-evaluation record.
Quality Agreement lacks mandatory prior change notification clauseViolation of ISO 13485 Clause 7.4.2; risk of unannounced raw material changesHigh (change notification is the MDSAP Task 8 written-agreement check; Vendor change control is the leading coded label among 985 string-matched recall rows, not an incidence rate)Require an executed amendment establishing prior written notification before implementation of specified product or process changes. Do not invent a universal 90–180 day clock.
Contract sterilizer has ISO 13485 certificate but no cycle validation report for the SKUViolation of ISO 13485 Clause 4.1.5 and ISO 11135 / ISO 11137 validation requirementsCritical (Product adulteration under FD&C Act 501(h))REJECT lot. Do not distribute until full sterilization validation dossier (IQ/OQ/PQ and residuals) is approved.
Incoming raw material lots accepted solely on vendor CoA without verification testingViolation of ISO 13485 Clause 7.4.3 verification of purchased productHigh (Nonconforming material escape risk)Require receiving inspection records, dimensional checks, and sampling rationale for the specific lot.
Supplier claims supplier audit reports are confidential under legacy 21 CFR 820.180(c)Misunderstanding of QMSR final rule (Comment 55 withdrew audit report exemptions)High (Regulatory disclosure gap)Clarify that FDA inspects supplier audits under QMSR; request documented audit findings and CAPA closure.
Table 5: Purchasing File Audit Red Flags, Failure Mechanisms, and Buyer Remediation Actions

Where VEMERIX Fits—and Where Due Diligence Still Begins

VEMERIX is the international brand of Weihai Medison Medical Equipment Co., Ltd., positioned as a Minimally Invasive Surgery Total Solution Platform serving urology, vascular surgery and perioperative care.13

For international supplier-qualification discussions, VEMERIX can walk a distributor or OEM buyer through the current technical pack for the sterile families this file typically touches — without claiming an FDA QMSR inspection outcome or that a PDF certificate closes purchasing controls:

  • Urology surgical consumables: The CE-marked Circumcision Device is publicly described as EO-sterilized and individually blister-packed; the circumcision stapler is NMPA Class II and factory EO-sterilized.13 The purchasing question for a buyer is still the labelled manufacturer's 4.1.5 / 7.4 file over sterilization, the blister converter, and any critical component — not a slogan that EO is 'covered'.
  • Vascular laser energy consumables: Medison's NMPA-registered single-use medical laser fiber is the registered consumable; it pairs with a partner-supplied diode laser source.14 Incoming specifications and verification for purchased fiber and connector components belong in the purchasing file. The partner-supplied NOVACURE console is not a Medison-manufactured capital system.
  • Perioperative care consumables: Disposable NPWT drainage dressing kits are publicly described with PVA/PU foam variants and a 400–600 µm pore structure.15 Those published attributes are examples of purchasing information a quality agreement should control.

VEMERIX does not claim that supplier qualification is closed by a sales conversation, an ISO 13485 PDF, or another company's FEI. Distributors, OEM buyers, and clinical-engineering teams can request the current technical pack, approved-supplier governance, quality-agreement terms, and batch-release records through the quality portal or technical enquiry channel, or review the portfolio at products overview. Due diligence still begins with the buyer's own QMSR, MDR and NMPA checks.

Frequently Asked Questions (FAQ)

1. Is 21 CFR 820.50 still in force after 2 February 2026?
No. As of 2 February 2026, 21 CFR 820.50 is formally [Reserved] under the QMSR.1 Purchasing controls are now legally mandated through 21 CFR 820.7 and 820.10, which incorporate ISO 13485:2016 Clauses 4.1.5 and 7.4 into federal regulation.1

2. Does an ISO 13485 certificate prove purchasing controls for the SKU I am buying?
No. An ISO 13485 certificate confirms that the manufacturer's overall quality management system was audited by an accredited registrar.1 It does not verify that specific purchasing controls, raw material specifications, CoAs, or incoming verification testing were executed for the specific SKU or batch being purchased.

3. Does FDA require my supplier to be ISO 13485 certified?
No. FDA's QMSR incorporates the requirements of ISO 13485:2016 into federal regulation, but FDA does not mandate third-party ISO 13485 certification.2,3 FDA enforces compliance through its own direct inspections under Compliance Program 7382.850.4

4. If we use a contract EO sterilizer, who holds the QMSR duty?
Both, for different operations. Under 21 CFR 820.1, a person who performs contract sterilization is a manufacturer subject to the QMSR for the operations in which it is engaged.1 The finished-device legal manufacturer still retains Clause 4.1.5 and 7.4 oversight over that sterilizer.4

5. Can FDA look at our supplier audit reports now?
Yes. Under the QMSR final rule (Federal Register 2024-01709, Comment 55), FDA declined to keep the former 21 CFR 820.180(c) exceptions for management review, quality audits, and supplier audit reports.2 21 CFR 820.35 does not recreate that shield.1

6. What is a 'critical supplier' under QMSR?
QMSR does not contain a statutory definition of 'critical supplier'.2 FDA declined to define the term because ISO 13485 Clause 7.4 requires continuous evaluation of all suppliers commensurate with the effect of the purchased item on finished-device quality and proportionate risk.2 Manufacturers must establish their own documented risk-tiering methodology.

7. Does another company's FDA establishment-registration listing cover my purchasing file?
No. An FDA establishment registration and device listing is an administrative directory record.11 On the 22 July 2026 openFDA snapshot, 419,651 listing rows collapse to 25,405 unique FEI, including 571 unique FEI whose type tokens include Contract Sterilizer. Those counts are directory facts, not Clause 7.4 performance and not VEMERIX listings.

8. Does VEMERIX already have an FDA-inspected purchasing file for these SKUs?
VEMERIX does not market a QMSR inspection outcome or substitute a marketing statement for a regulatory audit.13 The company provides technical documentation for buyer qualification. The buyer's file-review still has to be done.

Sources

  1. Electronic Code of Federal Regulations, 21 CFR Part 820, Quality Management System Regulation. Page current as of 24 August 2026; Title 21 last amended 19 August 2026. Source note 89 FR 7523, 2 February 2024. Subparts C–O reserved (former 21 CFR 820.50 is not operative text); 820.1 applicability including contract sterilization and the component-manufacturer exclusion at 820.1(a)(2); 820.3 manufacturer definition; 820.7 incorporation by reference of ISO 13485:2016(E) and ISO 9000:2015 Clause 3; 820.10 QMS requirement and 501(h) adulteration consequence; and 820.35 control of records (no 820.180(c)-style supplier-audit exemption). Extracted 2026-08-31.
  2. Federal Register, Medical Devices; Quality System Regulation Amendments, document 2024-01709, 2 February 2024, effective 2 February 2026. Preamble confirms Clause 7.4 of ISO 13485 requires evaluation of suppliers commensurate with the effect of the purchased product on the quality of the finished device and proportionate risk, plus ongoing monitoring and reevaluation. FDA declined to define 'critical supplier'. Comment 55: FDA disagrees with maintaining the former 21 CFR 820.180(c) exceptions for management review, quality audits, and supplier audit reports. Extracted 2026-08-31.
  3. US FDA, Quality Management System Regulation (QMSR). Content current as of 2 February 2026. The QMSR amends 21 CFR Part 820 and incorporates by reference ISO 13485:2016 and Clause 3 of ISO 9000:2015. On 2 February 2026 FDA began using Inspection of Medical Device Manufacturers Compliance Program 7382.850 and no longer uses QSIT or inspection documents 7382.845 and 7383.001. Extracted 2026-08-31.
  4. US FDA, Compliance Program 7382.850, Inspection of Medical Device Manufacturers. Implementation date 2 February 2026. 78 pages. Supersedes CP 7382.845 (QSIT) and CP 7383.001. Attachment A page 75 purpose: to ensure outsourced processes, outsourced activities, and/or purchased product are effectively monitored and controlled, resulting in product that conforms to specified requirements. Element map: Outsourcing Clause 4.1.5; Purchasing Process Clause 7.4.1; Purchasing Information and Purchased Product Clauses 7.4.2 and 7.4.3. The six QMS areas in Inspection Model 1 are Change Control; Design and Development; Management Oversight; Measurement, Analysis, and Improvement; Outsourcing and Purchasing; Production and Service Provision. PMA inspection note (pages 28–29): FDA has authority to inspect component manufacturers when necessary but rarely does so outside the PMA program; investigators should not issue a 483 to a domestic component manufacturer and should handle identified issues through the finished-device manufacturer's Clauses 4.1.5 and 7.4, citing the 483 on the finished-device manufacturer. Extracted 2026-08-31; PDF re-opened 2026-08-31.
  5. US FDA, MDSAP AU P0002.008 Audit Approach, Chapter 7 Purchasing (page 125). Intent: purchased, subcontracted or otherwise received products and services must conform to specified requirements; controls depend on the effect on quality, safety, and effectiveness. Chapter 7 still lists 'FDA: 21 CFR 820.50(b)' as a country-specific requirement. Use the intent text as MDSAP process description; do not copy 820.50(b) as current QMSR law. Extracted 2026-08-31.
  6. Regulation (EU) 2017/745 of the European Parliament and of the Council (MDR), consolidated text CELEX 02017R0745-20250110. Article 10(9)(d): QMS shall address resource management, including selection and control of suppliers and sub-contractors. Annex IX, Chapter I, section 2.3: notified bodies assessing the QMS shall identify relevant suppliers and/or subcontractors and consider specifically auditing them. Extracted 2026-08-31.
  7. Standardization Administration of China / State Administration for Market Regulation, GB/T 42061-2022, Medical devices — Quality management systems — Requirements for regulatory purposes. Openstd card: 现行; published 14 October 2022; implemented 1 November 2023; CCS C30; ICS 03.100.70 and 11.040.01; competent department NMPA; issued by SAMR and SAC. The card states the standard adopts an ISO/IEC organisation standard and withholds full text for copyright. It is not a clause-level read and is not, by itself, a purchasing file. This article does not treat YY/T 0287-2017 as withdrawn. Extracted 2026-08-31; card re-checked 2026-08-31.
  8. Cornell Law School Legal Information Institute, 21 CFR § 820.50 Purchasing controls. Extracted 2026-08-31: page still titles Part 820 as Quality System Regulation, still lists Subpart E, and still quotes the 1996 shall-text. Used as a SERP stale-citation failure example. Legal text stays on eCFR (s1).
  9. US FDA, Purchasing Controls training PDF (media/94743). Pre-QMSR presentation that cites 21 CFR 820.50 and the 1996 Quality System Regulation preamble. Ranking on the '21 CFR 820.50 purchasing controls' SERP. Historical teaching aid, not current law. Extracted 2026-08-31.
  10. Jeff Craven, 'MedCon: FDA officials say risk management is biggest hurdle for inspections under QMSR', Regulatory Focus / RAPS, 28 April 2026. Named FDA officials reported about 100 QMSR inspections between 2 February and 31 March 2026, with the most Form 483s in risk management, followed by outsourcing and purchasing. Secondary conference reporting of named officials, not a published FDA 483 statistical table. Extracted 2026-08-31.
  11. openFDA device registration and listing bulk extract used for unique-FEI directory analysis (export_date 22 July 2026; 419,651 rows / 25,405 unique FEI). Public search: FDA Establishment Registration & Device Listing. Directory snapshot, not an FDA inspection finding. Extracted 2026-08-31.
  12. openFDA device recall bulk extract used for vocabulary analysis (export_date 24 July 2026; 58,785 events). Public search: FDA Medical Device Recalls. Recall counts are manufacturer corrections across all device classes; they do not establish incidence, causality, or QMSR inspection outcomes. Extracted 2026-08-31.
  13. Public VEMERIX Circumcision Device product page, used only as worked-example identity: EO-sterilized, CE marked, adult and pediatric size codes, individually blister-packed. Not QMSR inspection evidence and not a named contract-sterilizer disclosure. Extracted 2026-08-31.
  14. Public VEMERIX Disposable Medical Laser Fiber product page, used only as worked-example identity: NMPA Class II (Lu Mech Reg. 20192010517), 1470 nm endovenous workflows, partner-supplied diode laser source. No Medison CE claim on this SKU. The partner-supplied NOVACURE console is not a Medison-manufactured capital system. Extracted 2026-08-31.
  15. Public VEMERIX Disposable NPWT Drainage Dressing Kit product page, used only as worked-example identity: PVA/PU foam variants and a stated 400–600 µm pore structure. Not independent clinical evidence and not a purchasing-file substitute. Extracted 2026-08-31.

Talk to VEMERIX

VEMERIX is the international brand of Weihai Medison Medical Equipment Co., Ltd., positioned as a Minimally Invasive Surgery Total Solution Platform serving urology, vascular surgery and perioperative care.