What Makes a Supplier "Critical" Under MDSAP?

In medical device manufacturing, suppliers are not just business partners — they are extensions of your quality management system. Their processes, controls, and decisions can directly affect patient safety, product performance, and regulatory compliance. Yet, while all suppliers matter, some matter more than others.

These are your critical suppliers, and understanding who they are — and how to audit them — can make the difference between a compliant, resilient QMS and one that fails under scrutiny.

One of the most common misconceptions I see in industry is that “critical supplier” is a universal regulatory term. It isn’t. The only regulatory framework that formally defines the concept of a critical supplier is the Medical Device Single Audit Program (MDSAP). Within the foreword of MDSAP, it specifies the following:

For the purposes of MDSAP, “critical suppliers” include, but are not limited to;

  • those entities that supply the organisation with finished devices, i.e. a device, or accessory to any device, that is suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized;

  • suppliers of products, including services, that impact design outputs that are essential for the proper functioning of the device; and

  • suppliers of products and services that require process validation.


This definition matters because it shifts the emphasis from simple purchasing control to risk-based evaluation. A supplier who provides sterile barrier systems, software used in safety-related functions, or validated sterilisation services is clearly “critical.” A printer supplying instruction-for-use leaflets may not be.

It means that many manufacturers create a scoring criteria for “critical” suppliers. Making it easier to communicate with NBs as they typically ask for this on registering.

Other regulatory frameworks do not use the term “critical supplier” explicitly. ISO 13485:2016 requires organisations to “establish criteria for the selection, evaluation, and re-evaluation of suppliers” (§7.4.1) and to control outsourced processes (§4.1.5), but leaves the terminology open. EU MDR 2017/745 and IVDR 2017/746 expect manufacturers to demonstrate adequate supplier control, particularly for suppliers in the context of Notified Body assessments under Annex IX, but the term itself appears only in guidance, not law. The upcoming FDA QMSR aligns with ISO 13485 language and similarly stops short of defining supplier criticality.

To identify which suppliers fall into this category in your own QMS, ask three key questions:

1. Does this supplier’s output directly affect the safety or performance of our device?
2. Does this supplier perform a process required by regulation or essential to conformity assessment?
3. Would a failure at this supplier result in a significant quality, regulatory, or patient safety impact?

If the answer to any of these is yes, that supplier is functionally critical — regardless of whether the term appears in your QMS.

Once identified, critical suppliers must be treated differently from general vendors. This applies not only to supplier qualification but also to ongoing oversight and auditing. The audit depth, frequency, and follow-up expectations should all scale with the risk they present.

Audits of critical suppliers typically require:

- On-site visits rather than purely remote assessments.
- Process witnessing — observing production, testing, or sterilisation steps directly.
- Validation evidence review, including equipment qualification, software validation, and process capability data.
- Change-control scrutiny, especially where changes could affect device conformity.
- Traceability checks, ensuring supplier documentation integrates cleanly into your device master records.

What should a supplier audit look like?

When auditing a critical supplier, the focus shouldn’t be on carrying out a broad, textbook-style quality management system audit — that’s rarely the most effective use of time. Instead, the most valuable audits are those that are specific, targeted, and product-focused.

In practice, that means concentrating on the elements that directly affect your product line. When I conduct a supplier audit, I’m not reviewing every single process in their QMS — I’m examining the areas that link directly to the manufacture, assembly, or handling of our specific medical device. I’d also be reviewing the terms and conditions set in our quality agreement and any environmental conditions we specify to assess the suppliers adherence to our purchasing information.

Opening Meeting

An often underlooked part of audits is the opening meeting. I’ve spoken about this before many times. But this is where you can sit with the senior management of the supplier, and ensure there are no issues with the audit plan in terms of staff availability, access and arrangements.

It also allows you to communicate your audit approach, this allows me to cover off the following type of items depending on the type of audit:

  • An auditee should never get to the end of an audit without knowing about how the findings that have been generated.

  • Inform your auditee that you will call out potential nonconformances as you see them and that you will cite the specific requirement you are looking for conformity to. This will give them a chance to demonstrate conformity. We’re auditing for conformity not nonconformity.

  • Inform the auditee that audits are based on a sample, and there may be nonconformances detected that were not done so previously, and vice versa.

  • Discuss pre-arranged confidentiality agreements relating to the audit.

Conducting the Audit

Since we are looking at critical supplier audits.

The absolute first thing I would typically look at would be following up on corrective actions relating to any Supplier Corrective Action Requests (SCARs) or nonconformities (NCRs) we’ve previously raised on the supplier. I want to see not only that these have been addressed, but that the actions taken are effective and sustained. This tells me whether the supplier has genuinely tackled the root cause or simply applied a quick fix. Furthemore, I’d also want to look at a list of internal NCs relating to my product in particular to understand any impact that I may need to consider.

If there are no NCs internally, I’d consider looking at scrap rates…lots of scrap, no NCs? What is going on here?

From here, depending on the scope of my audit, I would select some product serial numbers that the manufacturer has recently received from the supplier and utilise these as samples to go backwards with. This can be used to assess traceability, validation of software used within the production of the batch, training of operators, assess procedural compliance, check calibration of equipment used, control of suppliers that form part of the product, environmental conditions, cleaning controls as well as general document control and record management.

By keeping the audit focused on our product and its associated risks, the process becomes much more meaningful. Instead of a generic audit report that ticks off clauses, you walk away with real evidence about how well the supplier is controlling the parts of their operation that matter most to you — and ultimately, to the safety and performance of your medical device.

Wash Up Meetings

If a supplier audit is scheduled over a few days, it is extremely beneficial for all parties involved to have wash up meetings at the end of each day.

This is where the auditees and auditors come together to summarise the output from today, so we have found X number of nonconformances, or ideally 0 nonconformances have been detected. This is also where the auditor can go through what records we may be waiting on. Finally, we can use this moment to plan the next day of auditing to make it as smooth as possible and ensure we are on track to complete the audit objectives, or identify if we are not.

Closing Meeting

At the end of the scheduled audit time, the formal closing meeting shall be conducted.

These are essentially a more formal wash up meeting, that is attended by more senior management.

The auditor shall communicate whether the audit agenda and audit objectives were satisfactorily assessed.

The auditor shall communicate the level of conformance and nonconformance detected, or any other audit objectives.

Finally, the auditor shall specify any confidentiality requirements as well as a sampling disclaimer for audits as we discussed earlier and when the supplier shall deal with nonconformances and when they can expect to receive the audit report.

Auditing critical suppliers is more than a compliance requirement — it is a strategic exercise. These audits often reveal systemic weaknesses, hidden risks, and opportunities for improvement that would never emerge from a paper-based review. They also strengthen your regulatory position: demonstrating proactive supplier control is a key expectation under ISO 13485 and MDSAP.

In short, knowing which suppliers are truly critical — and auditing them accordingly — transforms supplier management from an administrative activity into a core part of risk management and product safety.

If you would like a hand conducting any supplier audits, or planning these audits, feel free to reach out!

Previous
Previous

PRRC Liability: What Happens If You Get It Wrong?

Next
Next

Should You Audit Your Own Technical Documentation?