There is a precise reason why a supplier can hold a valid ISO 13485 certificate and still miss your delivery for the third month in a row. It has nothing to do with fraud. It has to do with what the standard was designed to measure — and what it was never designed to measure at all.

What the Audit Actually Confirms
ISO 13485:2016 is a quality management system standard. Its purpose is to verify that a supplier has documented, implemented, and consistently follows procedures that support medical device quality. Certification follows a three-year cycle: an initial two-stage audit, annual surveillance audits in years one and two, and a full recertification in year three — consistent across BSI, SGS, TÜV, and other bodies.
Surveillance audits are risk-based and use sampling. They confirm ongoing conformity to documented procedures. What they do not assess: current production load, recent staff turnover, machine downtime in the past 90 days, or whether a sub-supplier is running three weeks behind. None of those variables appear in the audit scope because none of them are certification criteria.
Clause 7.4 of the standard requires certified organizations to evaluate and select suppliers — but leaves the criteria entirely to the organization. On-time delivery is not a mandatory certification requirement. A supplier can document a quarterly review process that was last meaningfully executed eight months ago and still pass a surveillance audit. This is not a flaw in the standard. Management system standards cannot continuously monitor operational conditions — that is not what they do. The problem is the assumption that what the audit confirms equals operational health.
The Gap You’re Actually Managing
Visit a certified supplier on a regular operating day — not the week before an audit — and you often see a different facility than the one on the certificate. A production floor that is less organized. Walkways that are not clear. Everyone in manufacturing knows that before auditors arrive, things get cleaned up. The audit captures the supplier’s best day. The average day is something else.
The approved vendor list (AVL) reflects this same limitation. It is built on qualification events — audits, certifications, questionnaires — and it is static by design. A supplier earns their place on the AVL and stays there. Nothing in that process captures that two key engineers left in the past six months, or that the supplier took on a large new customer and your program is now lower in their capacity queue. That is how a supplier with a perfect audit history develops a delivery problem that comes as a surprise.
What Changes When You Add Continuous Monitoring
Tools like JAGGAER, Resilinc, and Coupa track financial health, delivery performance trends, adverse news events, and operational disruptions in real time — linked directly to your open purchase orders. They are not a replacement for the audit. They provide what the audit was never designed to provide: a signal between audits. An OTIF trend drifting down for two consecutive months. A news flag about a supplier’s key sub-supplier. A financial stress indicator surfacing before it becomes a missed delivery.
As of February 2026, the FDA’s updated Quality Management System Regulation (QMSR) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference — and explicitly framed the supplier monitoring obligation as continuous, not one-time. The direction regulators are moving matches where leading procurement teams already are.
The certificate on the wall tells you what the supplier looked like on their best day. Something else has to tell you what is happening right now.
At CRIL Tech, we maintain an active supplier network and track supplier health on an ongoing basis — not just at qualification time. If you’re navigating supplier reliability challenges in medical device or aerospace manufacturing, we’re glad to talk. Contact us at info@cril-tech.com.