A customer audit flagged our receiving inspection. What does ISO 9001 actually require for incoming material?
Verification proportionate to risk, defined in advance and recorded. Clause 8.4.2 does not require inspecting everything. It requires that you decided what to verify and then did it.
What to do now
Get the finding in writing with the evidence attached, then go stand at the dock.
Read what they actually wrote. Customer auditors write findings in their own format, and the useful version names the requirement, what they saw, and the gap. "Receiving inspection inadequate" is not actionable. Ask for the specific record they pulled and the specific expectation it missed.
Then work out which of the four usual causes it is. In practice, nearly every receiving finding is one of these:
- No defined criteria. Your procedure says incoming material is inspected, without saying what, how much, or against what.
- Criteria defined, records that do not match them. The procedure says dimensional verification of critical characteristics and the record is a checkmark.
- No control of unverified material. Received parts are physically available to production before anyone has released them.
- Results that go nowhere. Receiving inspection finds problems, and supplier performance under clause 8.4.1 never reflects them.
Check the customer's own flowdown before you respond. Defense and aerospace contracts often impose verification and traceability requirements beyond ISO 9001, and a response that satisfies the standard but not their contract will come back.
Look at the material on the floor today. Whatever the finding says, walk the receiving area and see whether you can tell, at a glance, what has been verified and what has not.
What it costs
Almost nothing to fix properly, and a great deal to leave alone.
Defining verification criteria is a document exercise measured in days, not a purchase. Segregating unverified material is usually a rack, a tag scheme, and a rule about who moves what. The expensive version is buying inspection equipment you do not need because nobody separated the parts that require measurement from the parts that require a certificate review.
The cost of leaving it is downstream. Material that reaches production unverified becomes a nonconformance three operations later, when the value added to it is highest, and it arrives with an extent-of-condition question attached: what else from that lot is already in product, and where did it ship. If the answer depends on traceability you do not have, a one-lot problem becomes a containment exercise across months of production.
On the customer side, a repeat finding on the same process is what moves a supplier from approved to conditional, and that decision is made by people you never meet.
What good looks like
A dock where an auditor can see the decision being made, not just the material moving.
Written criteria, proportionate to risk. Clause 8.4.2 requires you to determine and apply verification that ensures externally provided product meets requirements. It does not require inspecting every lot. A commodity fastener from a supplier with five years of clean history may be verified by certificate review. A critical dimension from a new supplier is not verified by paper. Both decisions are legitimate; what matters is that you made them deliberately and wrote them down.
Records that match the criteria. If the criteria say measure, the record shows measurements taken with calibrated equipment by someone the competence records cover.
Physical or system control of unverified material. A hold area, a system status that blocks issue, or both. The test is whether an operator in a hurry can pull unreleased material without anyone noticing.
A loop back to supplier evaluation. Receiving data is the evidence base for clause 8.4.1 monitoring. If your records show repeat problems from one supplier and your approved list never changes, an auditor will ask why, and so will your customer.
Consigned material handled as customer property. Material your customer supplies carries extra obligations on identification and on reporting damage or loss, and it should never sit in the same untagged bin as your own stock.
When to bring in outside help
When the finding is a repeat. A second finding on the same process means the first corrective action fixed a symptom. Repeats escalate with customers faster than with registrars.
When the problem is really traceability. Receiving findings often surface a break in the identification chain that runs much deeper into the plant. That is a bigger project than the finding suggests and it is worth scoping properly before promising a closure date.
When the customer's requirements exceed the standard. Aerospace and defense flowdown, first article requirements, and specific material certification formats are their own body of knowledge.
You do not need help to define criteria for your own parts. Your receiving staff usually know exactly which items cause trouble; the gap is that nobody wrote it down.
How ARG does it
We work this one from the dock inward, because that is where the evidence is.
The review covers what arrives and how it is identified, how verification is decided and recorded, how unverified material is controlled, what happens to nonconforming incoming product, and whether any of it reaches supplier evaluation. Where traceability is a customer requirement, we test it the way a customer auditor does: pick a finished unit, ask for the material certificate behind it, and see how long it takes.
The response package is built so your customer can verify it: correction, cause, the change to the process, and what will be examined afterward to show it worked.
James Wall leads this work. He is a quality engineer with a supply chain background from high-volume distribution, and receiving, inventory control, and customer-owned property are his part of the practice. We prepare you for the audits. Your registrar and your customer decide the outcome.
FAQ
Do we have to inspect every incoming lot?
No. You have to define verification proportionate to risk and follow what you defined. Skip-lot sampling, certificate review, and full inspection are all correct for different parts.
Is a certificate of conformance enough?
It is a supplier's assertion, and it can be sufficient verification for low-risk items from a supplier with history. For a critical characteristic, an assertion is not verification.
Does a supplier's own ISO 9001 certificate let us skip inspection?
It is one input into supplier evaluation under clause 8.4.1 and can justify reduced verification. It does not replace having decided what verification you perform.
What if we already used the material?
That is a nonconformance with an extent-of-condition question: what else from that lot is in product, and where did it ship. Contain first, then investigate.
How do we handle material the customer supplies?
As customer property under clause 8.5.3: identified as theirs, verified on receipt, stored so it cannot be mixed with your stock, and reported to them if it is lost, damaged, or unsuitable.
Sources
- ISO 9001:2015 clauses 8.4.1, 8.4.2, 8.5.2, 8.5.3, 8.6 and 8.7.
- ARG market research 2026, section 2.3 for defense sub-tier flowdown and critical-supplier checklist requirements, section 4.5 for common finding clusters.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.