What to Put in a Supplier Quality Agreement for Parts
Share
A supplier quality agreement is useful when it turns recurring expectations into named responsibilities and traceable records. It should help a buyer and supplier answer who controls a requirement, what triggers action, which evidence closes it, and how an exception is resolved. A list of quality slogans cannot do that.
The agreement also has boundaries. Commercial terms belong in the contract or purchase order, technical acceptance belongs in drawings and specifications, and order-specific inspection points may belong in an inspection and test plan. The broader undercarriage-parts supplier overview addresses supplier choice. This article focuses on the standing quality responsibilities used across manufactured-parts orders.
Use the topics below as a review framework with quality, engineering, procurement, and legal input where needed. They are not signature-ready clauses or a conclusion about enforceability.
Define the agreement's job and document hierarchy
Identify the legal entities, supplier sites, buyer sites, part families, and activities in scope. Record the agreement title, revision, effective date, approved language, and controlled location. State which work is outside scope. If an affiliated plant, distributor, laboratory, or subcontract processor is involved, do not assume the agreement automatically covers it.
Map the document set. The purchase order usually carries order and commercial information; the drawing and specification define technical requirements; approved deviations or concessions authorize limited departures; and an order-specific quality clause or inspection plan may add evidence or hold points. The quality agreement should allocate recurring controls and interfaces without quietly rewriting those documents.
The official ISO 9001 overview describes a quality management system built around controlled processes, documented information, evaluation, and improvement. It does not provide a complete quality-agreement checklist, certify a particular supplier, or determine which document prevails in a transaction. Check the edition and status again before publication or use because standards can transition.
For every incorporated document, list its identifier, revision, owner, and how later changes become effective. Define a review path for contradictions. If a purchase order and quality attachment state different record-retention periods, do not guess which number controls. Log the conflict, its impact, the responsible technical and commercial reviewers, and the authorized resolution. Legal counsel should address enforceability and precedence language where the transaction requires it.
Assign quality obligations to named roles
Replace “supplier ensures quality” with rows that identify the supplier owner, buyer owner or approver, trigger, required evidence, timing source, and exception route. Name roles rather than individuals when staff changes are likely, then maintain a contact and escalation list separately.
Cover specification and contract review, process control, inspection and testing, measuring-equipment control, competence, packaging and preservation, certificate delivery, and supplier-performance review as applicable. State who communicates a revision, who confirms its receipt, who decides whether existing work is affected, and which record demonstrates closure. If access, audit, source inspection, or witness rights are intended, they must come from an agreed document; they are not universal rights created by a checklist.
An ISO 9001 Auditing Practices Group and IAF paper on external providers discusses defined provider criteria, current purchasing information, performance monitoring, and risk-based controls. Its publisher labels it non-normative guidance. Use it to ask better review questions, not as a contract requirement or fixed control level.
Buyer inspection or approval also needs a boundary. It may confirm that stated evidence was reviewed, but it should not be interpreted as erasing supplier responsibility unless the governing contract expressly says so. Likewise, a supplier's certificate does not make the buyer the process owner. Record delegation limits, authorization levels, and what happens when the assigned reviewer is unavailable.
Buyer-supplier responsibility swimlane
- Requirement: the governing document and revision define the obligation.
- Supplier control: a named role performs the activity and creates objective evidence.
- Buyer review: a named role reviews only what the agreement assigns to it.
- Exception: missing or conflicting evidence triggers hold, clarification, or authorized deviation.
- Closure: the resolution, approver, effective revision, and affected orders are recorded.
Each handoff should point to its authority and evidence; actual timing and legal effect require case-specific review.
Connect sub-tier control, traceability and records
Define which materials, outsourced processes, and sub-tier suppliers require approval or notification. State which drawing, specification, quality, regulatory, and customer requirements must flow down, and how the direct supplier verifies that the current requirements reached the performing source. The direct supplier remains the buyer's interface unless the agreement establishes another arrangement.
Build traceability from the delivered lot backward. Depending on the applicable requirement, records may connect the purchase order and line, part number and revision, supplier lot or batch, heat, serial number, material certificate, special-process source, inspection result, and shipment document. A certificate file is useful only when its identifiers map to the actual delivered population and governing revision.
A current Timken supplier requirements manual illustrates one manufacturer's approach to traceability, current-revision control, sub-tier management, change notice, and post-shipment nonconformance. It is evidence that buyers make these interfaces explicit, not evidence that Timken's requirements or deadlines apply to another relationship.
The NASA workmanship handbook's example traceability clause shows how heat, lot, part, serial, purchase-order, invoice, certificate, and test identifiers can be linked. It is explicitly an example in an aerospace context. Choose the depth of traceability for the actual product risk, regulation, customer flow-down, and contract; do not impose an aerospace scheme on ordinary undercarriage parts by default.
For each record type, name its creator, custodian, format, storage location, access controls, retrieval expectation, correction method, and loss-of-record notification. Negotiate retention according to risk and applicable requirements. Record the authority for the period rather than copying a number from another buyer's manual. Define confidentiality, secure access, and disposition at the end of retention.
Define change and nonconforming-product interfaces
Describe the change families that require communication: product design, material, process, manufacturing site, sub-tier source, tooling, test method, software, packaging, and other factors relevant to the part. For each family, identify the notification point, information package, affected parts and orders, proposed effective date, validation evidence, and buyer review or approval role. An emergency path should still preserve identity, authority, and later closure.
Keep planned change and nonconforming product as different workflows. A proposed heat-treatment subcontractor change needs risk and approval evidence before the intended implementation. A defect discovered after shipment needs affected-lot traceability, prompt notification through the agreed channel, containment, and disposition authority. One notice form may support both, but their decisions and timing are different.
Define how nonconforming material is identified, segregated, and prevented from unintended use. State who may request a concession or deviation and who may authorize it. Do not let the matrix itself authorize use-as-is. The agreement can require root-cause and corrective-action evidence when appropriate, but the applicable process should name the trigger, response content, verification, effectiveness review, and closure owner.
The JPL Supplier Quality Assurance portal illustrates a buyer managing individually identified quality clauses and revisions alongside purchase orders or subcontracts, with separate traceability and nonconformance resources. Its aerospace clauses and response terms do not transfer to another buyer. Use the example to verify that your own requirements are identifiable, current, and attached to the right order.
Costs, warranty responsibility, indemnity, cancellation, and other commercial or legal consequences belong in their governing documents and reviews. The quality agreement should point to the interface without inventing liability. Never copy a manufacturer's 24-hour, 30-day, or record-retention deadline as a universal rule.
Resolve conflicts and review before use
Create a conflict log before signature and whenever a governing document changes. Record the affected clause or matrix row, both document identifiers and revisions, the incompatible requirements, affected parts or orders, operational impact, temporary hold or control, responsible reviewers, and final authority. Undefined terms and impossible evidence or timing belong in the same log.
Review country, regulatory, and customer flow-downs with the people qualified to interpret them. Record supplier exceptions and buyer exceptions explicitly. Quality reviews whether controls and records are workable; engineering reviews technical impact; procurement reviews commercial and order interfaces; and legal review addresses wording and enforceability when needed. Authorized signatories should approve only the resolved version.
After approval, control the effective version, communication, training, and rollout. Confirm how open purchase orders and work in process are treated, and how order acknowledgment identifies the applicable revision. Maintain a change history and periodic review trigger. A signed document with an unresolved conflict is still operationally ambiguous; signature alone does not make two incompatible instructions agree.
Use the responsibility matrix to expose gaps
Build one row for each recurring obligation. Avoid a total score that hides a missing owner or conflicting authority. The row itself should show what prevents use and who can close it.
| Review field | Normal | Missing | Conflict |
|---|---|---|---|
| Obligation and scope | Part family, sites, activity, and governing revision are defined | Sub-tier or process falls between documents | PO and attachment describe different scope or revision |
| Owners and authority | Supplier owner, buyer reviewer, approver, and delegation limits are named | No owner for flow-down, records, or exception review | Two roles claim incompatible disposition authority |
| Trigger and evidence | Event, required record, and applicable timing source are traceable | Certificate or notification requirement has no delivery point | Documents demand different evidence or timing |
| Traceability and retention | Identifiers map the shipment to material, process, inspection, and retained records as required | Lot mapping or record custodian is absent | PO and agreement specify different retention periods |
| Exception and closure | Hold, review, authorized decision, affected orders, and closure record are visible | No path for a lost record or post-shipment defect | One document permits use while another requires hold |
For a normal certificate-delivery row, the governing revision, supplier quality owner, pre-shipment trigger, named record, buyer reviewer, and exception status all align. A missing sub-tier owner should remain open until responsibility and evidence are agreed. Conflicting retention periods should go to the named quality, procurement, and legal reviewers; the matrix should not choose a legally controlling document.
The completed matrix is a working index to the actual agreement, purchase order, specifications, and approved exceptions. It does not certify either party, demonstrate ISO conformity, or release product. Its value is that a buyer and supplier can see each obligation, handoff, record, and unresolved conflict before those gaps reach production or shipment.