FDA Quality Management System Regulation (QMSR)
QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

FDA Quality Management System Regulation (QMSR) QMSR-ISO13485-Sec7_Purchasing: Purchasing controls + supplier management (ISO 13485:2016 Section 7.4)

ISO 13485:2016 Section 7.4 (Purchasing) - the supplier-management framework. (7.4.1) PURCHASING PROCESS - documented procedures for evaluation + selection + monitoring + re-evaluation of suppliers based on supplier's ability to supply product meeting requirements; criteria for evaluation including impact on quality of medical device + risk associated with medical device; periodic monitoring + re-evaluation per planned intervals; records of evaluation + selection + monitoring + re-evaluation + actions arising. (7.4.2) PURCHASING INFORMATION - description of product to be purchased including: (a) product specifications; (b) requirements for acceptance + qualification of personnel; (c) QMS requirements; (d) regulatory requirements; the manufacturer must ensure that requirements are adequate. (7.4.3) VERIFICATION OF PURCHASED PRODUCT - inspection + verification activities for purchased product; the extent of verification activities based on supplier evaluation results + risk associated with the product; records of verification.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 68 controls across 38 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CFR211-C-48 Section 211.48 - Plumbing
  • CFR211-F-113 Section 211.113 - Control of Microbiological Contamination
  • CFR211-I-176 Section 211.176 - Penicillin Contamination
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures

IEEE 1686 · 3 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability
  • IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper
  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention

SWIFT CSCF · 3 controls

  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)
  • SWIFTCSCF-4 Prevent Compromise of Credentials (Objective 4)
  • SWIFTCSCF-7 Plan Incident Response (Objective 7)
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • GGAP-IFA-CropsBase-Production-PPP-IPM GLOBALG.A.P. IFA v6 Crops Base (CB): Propagation, Soil, Water, IPM, PPP, Fertilizer and Harvest
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing

PCI DSS 4.0 · 2 controls

  • 2.1.1 2.1.1 Requirement 2 policies and procedures governed
  • 2.1.2 2.1.2 Requirement 2 roles and responsibilities assigned
  • 2.1.3 Food Safety and Quality Culture
  • 2.7.2 Food Fraud Plan
  • 58.49 Laboratory Operation Areas
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • CJIS-19 Supply Chain Risk Management
  • FSSC-Additional-Requirements-v6 FSSC 22000 Additional Requirements v6 (Food Defense + Food Fraud + Allergen + Environmental + Culture)

FedRAMP Rev 5 · 1 control

  • FedRAMP-SupplyChain-SBOM FedRAMP supply chain risk management + SBOM (per EO 14028 + NIST 800-218 SSDF)
  • GAMP5-2nd-Edition-AI-Cloud-Agile-CSA 2nd Edition (2022) - AI/ML, Cloud, Agile, DevOps and Computer Software Assurance (CSA)
  • IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development
  • IEC62304-5.1 Software Development Planning
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe
  • A.1 Point-of-Care Testing Additional Requirements

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • AIGF-3.3 Repeatability and Traceability
  • IM8-TPM.4 Supply Chain Risk Management

South Korea ISMS-P · 1 control

  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in QMSR: Quality Management System Requirements (§820.10 incorporating ISO 13485:2016 Sec. 4-8)

Query this from an agent

The graph holds this control, the 68 it maps to, and the evidence behind each claim, over MCP and REST.