ISO 9001:2015
Operation – ISO 9001:2015

ISO 9001:2015 8.4.2: Type and extent of control

The organization makes sure that what external providers supply (processes, products and services) does not undermine its capacity to deliver conforming products and services to customers reliably. To that end it keeps outsourced processes under the control of its QMS; defines both the controls it will apply to the provider and those it will apply to what the provider delivers; takes into account how the external supply could affect its ability to meet customer, legal and regulatory requirements reliably, and how effective the provider's own controls are; and decides what verification or other activity is needed to confirm that what is supplied meets requirements.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 7 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

COBIT 2019 · 2 controls

  • APO10.03 APO10.03 Manage vendor relationships and contracts
  • APO10.05 APO10.05 Monitor vendor performance and compliance

ISO 21001:2018 · 1 control

  • 8.4.2 8.4.2 Type and extent of control

ISO 21001:2025 · 1 control

  • 8.4.2 8.4.2 Type and extent of control

ISO 22000:2018 · 1 control

  • 8.4.2 Handling of emergencies and incidents

ISO 22301:2019 · 1 control

ISO 27701:2019 · 1 control

  • 8.4.2 Return, transfer or disposal of PII

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Operation – ISO 9001:2015

Query this from an agent

The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.