ISO 9001 Outsourcing
Definition
ISO 9001 Outsourcing
ISO 9001 outsourcing is how the quality management standard treats the work you contract out to an external provider. Outsourced processes stay inside your system, so the standard requires you to control them rather than to delegate the responsibility away.
That principle catches organisations out regularly — certifying your own operation does not remove contracted work from scope, and an auditor will ask how you control what a supplier does on your behalf.
The requirement is proportionate rather than absolute. Control should match the risk the outsourced process carries to your product or service — a stationery supplier and a coding partner are not treated alike.
The standard is also changing this year, which makes the timing unusually relevant for anyone writing supplier requirements now.
Key takeaways
- Outsourced processes remain within the scope of your quality management system.
- The standard addresses them through its requirements on external provider control.
- The degree of control should be proportionate to the risk the process carries.
- A new edition is publishing in 2026, with a three-year transition period.
How it works
You identify which processes are performed externally, determine the controls needed for each, apply them, and keep evidence. Auditors then test whether the controls exist and whether they are actually operating.
The standard’s structure places this squarely in its operations clause. A published overview describes Section 8 as covering the service life cycle including external provider controls, alongside design, production and delivery.
The standard’s reach is considerable. The same overview records more than 1 million certified users, making it the most widely held ISO standard and the only one in its family to which organisations can certify.
| Control mechanism | What it involves | When it is proportionate |
|---|---|---|
| Supplier approval | Assessing capability before contracting | Any process affecting your output |
| Specified requirements | Documented quality criteria in the contract | Always, and the most commonly skipped |
| Performance monitoring | Ongoing measurement against those criteria | Recurring or high-volume services |
| Verification activity | Inspection, audit or testing of output | Where defects would reach your customer |
| Records | Evidence the above actually happened | Every case, since audits test evidence |
A new edition arrives shortly. A certification body records that publication of the 2026 edition is expected in September 2026, with a three-year transition period until September 2029, following a draft published in August 2025.
The honest caution is that a supplier’s certificate proves less than buyers assume. It shows that supplier runs an audited system within a stated scope — it does not show that your contract, your requirements or your site fall inside that scope.
Examples
The standard’s external provider requirements show up in supplier management routines far more than in the certificate itself. Every example here is ordinary, and ordinary is what you will most likely buy.
A manufacturer outsourcing a machining process applies incoming inspection and supplier audits, because a defect would reach its own customer directly.
A services firm contracting a payroll bureau relies on documented requirements and monthly performance review, judging inspection of every transaction disproportionate.
A buyer requests a supplier’s certificate and reads the scope statement, discovering the certified scope covers a different site from the one delivering its work.
An organisation preparing for the new edition reviews its quality assurance outsourcing arrangements early, using the transition period rather than waiting for its next audit.
Related terms
Quality standards, certification and improvement methods are distinct things, and the entries below mark the boundaries. The terms below get one meaning each, and the edges are drawn rather than assumed.
- ISO 9001: the quality management system standard itself, covered in its own entry.
- ISO certification: the audit process granting and maintaining a certificate against a standard.
- ISO 27001: the information security counterpart, audited separately and scoped separately.
- quality assurance outsourcing: contracting the quality function rather than certifying your own.
- Six Sigma: an improvement methodology, distinct from a certifiable management system.
- quality analyst: the role that usually operates monitoring and verification in practice.
- service level agreement (SLA): the contract instrument carrying the specified requirements.
FAQ
Does outsourcing remove a process from my scope?
No. Outsourced processes remain within your quality management system, and you must demonstrate that you control them appropriately.
How much control does the standard require?
Enough to match the risk. A process whose failure would reach your customer warrants verification; a low-impact service needs far less.
Is a supplier’s certificate sufficient evidence?
Not on its own. Read the scope statement, since it may not cover the site, service or contract delivering your work.
What changes in the 2026 edition?
A certification body cites sustainability and climate considerations, stronger leadership and quality culture requirements, and a restructured risk clause.
How long is the transition?
Three years from publication, running to September 2029 on the certification body’s stated timetable.
Where do outsourcing requirements sit in the standard?
In the operations clause, which covers the service life cycle including controls over externally provided processes, products and services.
Review verified partners in the Outsource Accelerator directory and read the scope statement on every certificate you receive.







Independent




