What is customer property under ISO 9001?
Customer property is anything a customer or supplier gives you to use or build into their product. Clause 8.5.3 names intellectual property and personal data alongside material and tooling.
If you signed a confidentiality agreement over a customer's drawings and are not sure what you owe, start with We signed an NDA for a customer's drawings and data. Does ISO 9001 cover how we protect them?
What it is
Clause 8.5.3 says you shall exercise care with property belonging to customers or external providers while it is under your control, and that you shall identify, verify, protect, and safeguard it.
The note under the clause is the part most manufacturers have never read. Customer property can include materials, components, tools and equipment, premises, intellectual property, and personal data.
So the clause covers both halves of what a customer hands you. The consigned casting on the rack is customer property. So is the CAD model it was machined from, the process specification that came with it, the test data you generated against their part number, and the contact list you were given to coordinate delivery.
Most plants handle the first half well. Material is tagged, segregated, and counted, because it is physical and somebody notices when it is gone. The second half usually sits on a shared drive that half the company can open, gets emailed to a supplier when a quote is needed, and lives on a laptop that goes home at night.
When you will hear it
In your own contracts, long before it appears in an audit. Most manufacturers sign a confidentiality or proprietary information agreement at the start of a customer relationship and then never look at it again. That agreement usually specifies how the customer's information must be stored, who may access it, what happens on termination, and how fast you must report a loss.
In a customer audit, increasingly. Supplier quality teams that used to ask only about material control now ask where drawings are stored and who can reach them.
In a request to return or destroy. Programs end, and the contract usually requires you to return or certify destruction of the customer's information. Companies that never inventoried it cannot do either.
What the auditor expects to see
For physical property: identification that makes it obvious the material is not yours, verification on receipt, protection appropriate to what it is, and a record of the loss, damage, or unsuitability report that clause 8.5.3 requires you to send the customer when something goes wrong.
For information: the same four verbs, applied to files. Can you say which customer information you hold, and where. Can you show that access is limited to people who need it. Can you show it is backed up and recoverable. Can you show what happens when an employee with access leaves.
An auditor working only to ISO 9001 may not press hard on the digital half. Your customer's contract does, and so does any information security standard the customer asks for next.
Common mistakes
Reading the clause as being about consigned material only. The note says otherwise, and the contract almost always says more than the note.
No inventory of what you hold. If you cannot list whose data you have, you cannot protect it, return it, or report on it.
Access by default. A drawings folder open to everyone with a login is the normal state in a mid-market plant, and it is the first thing that fails a customer's security questionnaire.
Email as the transfer mechanism. Sending a customer's proprietary model to a supplier for quoting, unencrypted and unlogged, is a disclosure your agreement probably prohibits.
Nobody owns it. Quality owns the material. Nobody owns the file. That gap is where the obligation lives.
FAQ
Does ISO 9001 tell us how to secure customer data?
No. It tells you that you must protect and safeguard it, and it requires you to report loss or damage. How is set by your contract, and by an information security standard if your customer asks for one.
Is a signed confidentiality agreement enough?
Signing it creates the obligation. It does not meet it. The audit question, from a customer or an auditor, is what you actually do differently because you signed it.
Does this cover tooling the customer owns?
Yes, explicitly. Customer-owned tooling needs identification, controlled storage, maintenance to whatever the agreement says, and a report when it is damaged.
What about data our customer's customer owns?
It flows down. If your customer is a tier-one supplier passing you a prime's drawings, the prime's requirements usually flow to you through your customer's contract, and they can be stricter than anything in ISO 9001.
Tell us which audit is on your calendar.
A gap assessment is a flat-fee, on-site project led by a certified ISO 9001 lead auditor. Three founding-client spots are open for the quality practice.
We prepare you for certification. We never issue it. Your registrar's independence is the point.