Approved supplier list builder
Build an approved supplier list you can actually use. Add your suppliers, set approval status and certification, and the tool flags every certificate that has expired or expires within 90 days. Export it as CSV or paste it straight into Excel. Everything runs in your browser and nothing you type is uploaded.
Your suppliers
Edit the example rows or clear them and enter your own. Scroll the table sideways on a narrow screen.
| # | Supplier | Category | Status | Certification | Cert expiry | Scope supplied | Last audit | Remove |
|---|---|---|---|---|---|---|---|---|
| 1 | ||||||||
| 2 | ||||||||
| 3 |
The CSV adds a certificate status column worked out from today’s date, so the file you hand to a colleague already says which certificates need chasing.
Summary
How to build an approved supplier list that survives an audit
What an approved supplier list actually is
An approved supplier list is the controlled record of who you are allowed to buy from, and for what. It is the answer to a question a buyer asks every week and an auditor asks once a year: is this company cleared to supply this part or this service, and on what basis. Most teams keep it as a spreadsheet, and most of the time that spreadsheet started as an approved vendor list template someone downloaded years ago.
The list is not the control. The control is the process behind it: how a supplier gets on, what evidence puts them there, how their performance is watched, and what removes them. The list is simply where that process leaves its fingerprints. A list with names and nothing else is a phone book. A list that records the basis for each approval and when it was last checked is a record.
What ISO 9001 clause 8.4 requires
ISO 9001:2015 clause 8.4 is titled control of externally provided processes, products and services. It applies when what you buy is built into your own product, when an external provider delivers straight to your customer on your behalf, and when you outsource part of one of your own processes. That last case catches more than people expect: heat treat, plating, anodizing, non-destructive testing, sterilization, and calibration are all processes you own the results of even though somebody else performs them.
Clause 8.4.1 is the sentence that creates the list. It requires you to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, based on their ability to supply in line with your requirements, and to retain documented information of these activities and of any actions arising from the evaluations. Four verbs, and each one leaves a record: how you judged them, how you chose them, how you watch them, and how you re-check them.
Clause 8.4.2 adds that the type and extent of control has to be proportionate: the more the supplied item affects your ability to meet requirements, the tighter the control. That is your licence to treat a sole-source machined casting differently from a box of shop rags. Clause 8.4.3 covers what you have to tell the supplier before they start work, including processes to be provided, approval requirements, competence expectations, and the control and monitoring you intend to apply. A well-built ISO 9001 approved supplier list carries a pointer to that information, usually the quality clauses or the purchase order terms that apply.
What AS9100 adds
AS9100D keeps all of ISO 9001 clause 8.4 and then makes the list explicit. Clause 8.4.1.1 requires the organization to maintain a register of its external providers that records the approval status, using categories such as approved, conditional and disapproved, together with the scope of that approval, for example a product type or a process family. So in aerospace an AS9100 approved vendor list is not simply good practice, it is named in the standard.
The same clause requires a defined process with clear responsibility and authority for making approval status decisions, for changing that status, and for the conditions under which a supplier can still be used in a controlled way while their status is less than full approval. It requires risk to be considered when selecting and using external providers, periodic review of provider performance including conformity of product and on-time delivery, and defined actions when a provider fails to meet requirements. It also makes clear that you remain responsible for the quality of everything you buy, including from customer-designated sources.
Two more aerospace habits show up in the list itself. Scope of approval has to be specific enough to be useful, because a supplier approved for machining is not automatically approved for welding. And counterfeit part prevention, covered in clause 8.1.4, is one reason distributors and brokers are usually held to a separate approval route from original manufacturers, which is why many aerospace lists carry a supplier type column.
What IATF 16949 adds
IATF 16949:2016 is the most prescriptive of the three about how suppliers get selected and watched. Clause 8.4.1.2 requires a documented supplier selection process that includes an assessment of the risk the supplier presents to product conformity and to uninterrupted supply to your customer, the supplier’s quality and delivery performance, an evaluation of their quality management system, and multidisciplinary decision making. Selection is not a buyer acting alone.
Clause 8.4.2.3 sets an expectation that automotive suppliers develop their quality management system toward IATF 16949 certification, working up a defined sequence: compliance to ISO 9001 verified by second-party audit, then ISO 9001 certification through a third party, then ISO 9001 with additional customer-defined requirements, then full IATF 16949 certification. That progression is a genuine reason to record more than a yes or no in the certification column, because where a supplier sits on that ladder is part of your development plan for them.
Clause 8.4.2.4 then names the monitoring indicators: conformity of delivered product, disruptions caused at your receiving plant including yard holds and stop ships, delivery schedule performance, and occurrences of premium freight. Where the customer provides them, special status notifications and field concerns feed in too. Second-party audits are covered separately in 8.4.2.4.1. In practice an automotive list carries a performance rating column that is refreshed from real data rather than opinion, which is exactly what a supplier scorecard is for.
ISO 13485 and regulated supply
ISO 13485:2016 clause 7.4.1 requires criteria for the evaluation and selection of suppliers that are based on the supplier’s ability to meet your requirements, on their performance, on the effect the purchased product has on the quality of the medical device, and proportionate to the risk associated with that device. Monitoring and re-evaluation have to be planned, and records of evaluation, selection, monitoring and re-evaluation have to be kept. Where a supplier fails to meet purchasing requirements, the response has to be proportionate to risk and consistent with applicable regulatory requirements.
The practical consequence is that a medical device list usually carries a risk classification column and a written supplier agreement reference, because ISO 13485 expects agreements in which suppliers notify you of changes to purchased product before those changes are made. A supplier who quietly moves a molding tool to a second site is a real problem in this sector, so the list tracks not just approval but the agreement that constrains change.
Calibration and test suppliers are a special case
If you send gauges out for calibration, that calibration provider belongs on the list like any other external process. ISO/IEC 17025 clause 6.6 puts the same duty on laboratories for their own external providers: define requirements, review and approve providers, and monitor their performance, with records kept.
The trap is the word accredited. ISO/IEC 17025 accreditation is granted against a defined scope: specific measurement quantities, ranges, and calibration and measurement capabilities. A laboratory can be genuinely accredited and still be outside its scope for the exact measurement you need, in which case the certificate you get back does not carry the accreditation mark you assumed it would. This is why the scope column matters more for calibration suppliers than for almost anyone else: record the measurements you approved them for, not just the standard on their certificate, and check the scope document rather than the logo.
The columns a useful list has, and why
Most AVL templates fail in one of two directions. They are too thin to answer a question, or so wide that nobody keeps them current. These are the columns that earn their place.
- Supplier name. The legal entity, not the sales contact and not the trading name on the invoice. If you buy from two sites of the same group, list them separately, because approval follows the site that does the work.
- Category or commodity. What family of spend this is: machined parts, castings, electronic components, heat treat, calibration, logistics. This is the column that lets you filter the list and gives you a sane way to assign risk levels in bulk.
- Approval status. Approved, conditional, disqualified or pending. One field with a fixed set of values. Free text here is how lists rot, because nobody can filter on nine different spellings of on hold.
- Basis for approval. Third party certification, on-site audit, questionnaire and first article, historical performance, or customer directed. This is the column an auditor goes to first, because it explains why the status says what it says.
- Certification and expiry.Which standard they hold and when the certificate runs out. An expiry date turns a static record into something that can prompt you. It is the only field on a typical list that changes state on its own.
- Scope of supply. What they are approved to provide, specific enough to be enforceable. Turned steel parts up to 200 mm is a scope. Machining is a wish.
- Last evaluation and next review date. The date you last looked, and the date you next have to. Without the second date, re-evaluation happens when someone remembers, which in practice means the week before the audit.
- Approval owner. The named person who signed off. Approval is a decision, and decisions have owners.
- Risk level. High, medium or low, driven by what the supply does to your product and how easily you could replace them. Risk is what makes the proportionate control language in the standards operational rather than decorative.
- Quality clauses or agreement reference. The purchase order clauses, quality agreement or flow-down requirements that apply. This is the link to clause 8.4.3 and to any sub-tier control you expect.
The builder above uses the core seven so the export stays readable. Add the rest as extra columns in the CSV once you have it in a spreadsheet, and keep the column set stable afterwards, because a list that changes shape every quarter cannot be trended.
Approved, conditional, disqualified
These three words carry most of the weight on the list, so define them once and use them the same way every time.
Approved means the supplier met your criteria, the evidence is on file, and buyers can raise orders within the recorded scope without asking anyone. It is the default state you want most of the list to be in.
Conditional means you will keep buying, but with a named restriction and an end date. Typical triggers are a lapsed certificate, an open corrective action, a new process or site, or a quality escape under investigation. Conditional without a restriction and a review date is just approved with a worried face, and it is the status auditors probe hardest. Write down what the condition is, what has to happen to clear it, and by when: source inspection on every lot until three consecutive lots pass, for example.
Disqualified means no new orders. Keep these rows on the list rather than deleting them, because the record of why a supplier was removed is worth more than the row you saved by hiding it, and because it stops a buyer re-approving them by accident next year. Some teams add a fourth state,pending, for suppliers going through evaluation who cannot yet receive orders. That keeps the pipeline visible without polluting the approved set.
How often to re-evaluate
None of the standards names a frequency, and that is deliberate: they ask you to plan monitoring and re-evaluation, not to obey a calendar someone else set. A defensible baseline that most auditors recognize is an annual re-evaluation of every active supplier, with the cycle shortened for higher risk. Special process suppliers, sole sources, and anyone with an open corrective action are commonly reviewed every six months.
Two things should trigger a review regardless of the calendar. The first is an event: a quality escape, a missed delivery that hurt a customer, a change of ownership, a move to a new site, or a change to a process you approved. The second is a certificate reaching its expiry date, because on that day the evidence behind the approval stops being valid, whatever the supplier’s performance looks like.
Suppliers you have not bought from in the review period do not need a full re-evaluation. Mark them dormant, record that no orders were placed, and re-check them before the next order rather than doing paperwork for a relationship that is not currently running.
What an auditor actually asks
Supplier control audits tend to follow the same three steps, and they start from your data rather than your list. The auditor pulls a handful of recent purchase orders or receiving records, picks the suppliers off them, and then asks: show me how this one got approved, show me the evidence behind it, and show me when you last reviewed them. If the supplier on the purchase order is not on the list at all, the finding writes itself.
The two most common findings in this area are not conceptual, they are clerical. The first is a supplier still listed as approved on the strength of a certificate that expired months ago. The second is a re-evaluation date that has passed with no record of a review. Both are avoidable, and both are what the expiry flags in the builder above are aimed at. Print or export the list before an audit, but keep the live version somewhere that can tell you when a date has gone by.
Where the spreadsheet stops working
A spreadsheet is a perfectly good approved supplier list template for a small list. It stops being enough for a simple reason: a spreadsheet does not tell anyone that a date has passed. Certificates expire quietly, review dates go by, and the file only speaks when somebody opens it. Add a few dozen suppliers, several standards with different renewal cycles, and two people editing separate copies, and the list drifts away from reality without anyone doing anything wrong.
That is the gap worth closing first, and it is a small one: certificates, approval status and review dates held in one place that watches the calendar for you. Everything else on a supplier quality wish list can wait until that is solid.
Common questions
What is an approved supplier list?
An approved supplier list, often called an AVL or an ASL, is the controlled record of which external providers you have evaluated and cleared to supply you, and for what. A useful list names the supplier, the commodity or process they are approved for, their approval status, the evidence behind that status such as a certificate or an on-site audit, and the date the approval has to be looked at again.
Does ISO 9001 require an approved supplier list?
ISO 9001:2015 never uses the words approved supplier list. Clause 8.4.1 requires you to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, and to retain documented information of those activities and of any actions arising from them. A maintained list is the simplest way most organizations satisfy that requirement, which is why nearly every certified quality system has one.
What should an approved supplier list include?
At minimum: supplier name, what they are approved to supply, approval status, the basis for that approval such as a third-party certification or an audit, certificate expiry where a certification is the basis, the date of the last evaluation, the next review date, and who approved it. A good test is simple: anything you would have to go hunting for during an audit belongs on the list.
How often should the approved supplier list be reviewed?
No standard fixes a frequency. Common practice is an annual re-evaluation for routine suppliers and more frequent review for suppliers tied to higher risk, special processes, sole-source parts, or a recent quality escape. Certificate expiry dates set their own clock, so many teams run a quarterly sweep for expiring certificates on top of the annual performance review.
What is the difference between an AVL and an ASL?
In practice they are the same document under different names. AVL usually stands for approved vendor list and ASL for approved supplier list, and different industries simply prefer different words. An approved manufacturer list, or AML, is a different thing: it names who actually makes the part rather than who sells it to you, which matters when you buy through a distributor.
Do I need to audit every supplier on the list?
No. The type and extent of control is meant to be proportionate to the risk and to the effect the supplied product or service has on your own output. A third-party certification, a first-article inspection, a supplier questionnaire, historical performance data, or a full on-site audit are all valid bases for approval. What matters is that you defined the criteria up front, applied them consistently, and kept the records.
What happens when a supplier certificate expires?
An expired certificate does not automatically disqualify a supplier, but it does remove the evidence your approval was resting on. The usual response is to request the current certificate, move the supplier to conditional while you wait, and record the decision and the reason. The real risk with a spreadsheet is that nobody notices the lapse until an auditor does, which is why this builder flags certificates that are already expired or expiring within 90 days.
This builder is a starting point for your own approved supplier list, not a compliance document. It does not replace ISO 9001, AS9100, IATF 16949, ISO 13485 or your own purchasing procedure, and the clause summaries here are plain-language descriptions rather than quotations of the standards. Check any list you build against your own quality system before you use it. Everything runs in your browser and nothing you type is sent anywhere.
Let the expiry dates chase you
A spreadsheet will never tell you a supplier certificate lapsed last month. We are building supplier certificate and approval tracking that does, in the same place your calibration records already live. Take a look and tell us whether it fits how you work.