What Clause 8.5.3 Actually Says
ISO 9001:2015 clause 8.5.3, "Property belonging to customers or external providers," is short as clauses go, but it's one of the more misunderstood ones I run into during gap assessments. Organizations tend to assume it only applies if they physically handle a customer's raw materials on a shop floor. It applies far more broadly than that, and the note attached to the clause makes that explicit.
The clause itself has three requirements. First, the organization shall exercise care with customer or external provider property while it is under the organization's control or is being used by the organization. Second, the organization shall identify, verify, protect, and safeguard that property when it's provided for use or incorporation into the products and services. Third, when that property is lost, damaged, or otherwise found unsuitable for use, the organization shall report this to the customer or external provider and retain documented information on what occurred.
Three sentences, three obligations: care, control, and communication. Most nonconformities against this clause trace back to a gap in one of those three, not all of them.
What Counts as "Property" — Broader Than Most Auditees Assume
The note to clause 8.5.3 states that customer or external provider property can include material, components, tools and equipment, premises, intellectual property, and personal data. That last item catches people off guard every time. If your organization stores, processes, or has access to a customer's employee records, CAD files, pricing data, or account credentials, that's customer property under this clause, whether or not you ever touch a physical object.
I've seen certification bodies write findings against companies that had a rock-solid process for tracking loaner tooling and fixtures but had never once considered that the customer's engineering drawings, sitting in a shared drive with no access controls, were also property subject to 8.5.3.
| Property Category | Typical Examples | Common Control Method | Frequent Failure Point |
|---|---|---|---|
| Materials & components | Customer-supplied raw stock, kit parts, packaging | Incoming inspection log, segregated storage, lot traceability | No verification on receipt; damage not caught until use |
| Tools & equipment | Customer-owned fixtures, dies, gauges, calibration masters | Asset tag/register, calibration schedule tied to clause 7.1.5 | Not included in the calibration program because "it's not ours" |
| Premises | Customer facility where you perform on-site work or install | Site access log, condition report at start/end of work | No documented condition baseline before work begins |
| Intellectual property | Drawings, specifications, proprietary formulas, source code | Confidentiality agreement, restricted access, marked documents | IP treated as a legal/contracts issue only, never entered into the QMS |
| Personal data | Employee records, customer contact lists, account data shared for service delivery | Access restriction, retention/deletion schedule, breach reporting procedure | Data privacy handled under IT policy with no link back to 8.5.3 |
If you're building out data privacy controls specifically, our guide on ISO 9001 and GDPR/CCPA considerations goes deeper into how personal data obligations intersect with clause requirements like this one.
The Four Verbs: Identify, Verify, Protect, Safeguard
Auditors will often ask you to walk through these four verbs in sequence, because each one maps to a distinct control point and a distinct type of evidence.
Identify
Before you can protect something, you have to know it exists and know that it belongs to someone else. That means a tagging or labeling convention that distinguishes customer-owned or external-provider-owned items from your own inventory. For physical goods this is usually a physical tag or a segregated bin location. For digital property, it's a naming convention or a folder structure that flags ownership, plus an inventory or register that lists what property you're holding, for whom, and since when.
Verify
Verification happens at the point of receipt. You're confirming the property is what it's supposed to be, that quantities match, and that it isn't already damaged when it arrives. This is functionally the same discipline as incoming inspection under clause 8.4 for externally provided processes, products, and services, just applied to items you don't own. Skipping this step is the single most common reason organizations can't prove, after the fact, whether damage happened on their watch or arrived that way.
Protect
Protection is about the conditions the property is kept in while it's in your custody: correct storage environment, handling procedures, restricted access for sensitive items, and calibration or preventive maintenance for tools and equipment you didn't buy but are responsible for while in use. A customer's die or fixture that gets run without maintenance and fails mid-production is a protection failure even if nothing was ever "lost."
Safeguard
Safeguarding is the ongoing custody discipline: periodic condition checks, secure storage, and a defined chain of custody for tracking movement of the item between departments, shifts, or subcontractors. This is where a lot of programs get thin — they do a great job at intake and then lose visibility on the item until it's needed again.
When Property Is Lost, Damaged, or Found Unsuitable for Use
This is the part of the clause with a hard, non-negotiable requirement: report it to the customer or external provider, and retain documented information on what happened. There's no materiality threshold written into the standard — the clause doesn't say "report significant damage" or "report loss above a certain value." It says report what occurred.
In practice, I recommend building a simple nonconformance-style record specifically for customer property incidents: what the item was, when the issue was discovered, what happened (lost, damaged, or found unsuitable), root cause if known, the date the customer or external provider was notified, and their response. This record does double duty — it satisfies the documented-information requirement in 8.5.3, and it typically feeds your broader nonconformity and corrective action process under clause 10.2.
One clarification worth making explicit: "found to be unsuitable for use" is not the same as "damaged by us." If a customer ships you components that are out of spec or contaminated before you ever touch them, that still triggers the reporting obligation. Auditors sometimes find organizations quietly scrapping or returning defective customer-supplied material without any record and without notifying the customer, on the theory that "it wasn't our fault so there's nothing to report." The clause doesn't distinguish fault. It requires reporting regardless of who caused the condition.
External Provider Property vs. Customer Property
Clause 8.5.3 deliberately covers both customer property and external provider property in a single requirement, and it's worth being precise about the distinction because the two show up differently in audits.
Customer property is usually something the customer gave you to use in producing their order: their materials, their tooling, their specifications, their data. External provider property is property belonging to your supplier that ends up in your custody — most commonly returnable packaging, pallets, totes, or loaned equipment a supplier provides so you can receive their goods. Reusable shipping containers are the classic example auditors probe on this front: are they tracked, are they returned, is there any record of condition when returned versus received?
If your organization runs a mature supplier evaluation and incoming inspection process, that infrastructure usually extends naturally to cover external provider property — the same receiving discipline that verifies a shipment's quality can verify condition of the container it arrived in. Our guide on purchasing controls, supplier evaluation, and incoming inspection covers how to structure that receiving process so it does both jobs at once rather than building a separate parallel system.
How Auditors Test This Clause
In my experience, auditors approach 8.5.3 through a handful of consistent questions, and it's worth rehearsing answers to each before a certification or surveillance audit:
- Can you show me a list or register of property currently in your custody that belongs to a customer or external provider?
- Walk me through what happens from the moment that property arrives to the moment it's returned or consumed.
- Show me a record of an incident where something was lost, damaged, or found unsuitable — and show me the customer notification tied to it.
- How do you handle customer-supplied tooling in your calibration or maintenance program?
- Where does customer data live, and who can access it?
If your organization has never had a customer property incident, that's not automatically a red flag, but the auditor will still expect you to describe what the process would be if one occurred. A process that only exists in someone's head, with no documented information behind it, is a nonconformity waiting to be written up — clause 7.5 requires documented information wherever the organization determines it's necessary for the effectiveness of the QMS, and most auditors treat a property-incident record as necessary by default given the explicit retention requirement in 8.5.3 itself.
Building a Customer Property Control Process — Step by Step
For organizations building this out from scratch, I'd structure it in this order:
- Inventory what property categories actually apply to you. Not every organization handles all five categories in the table above. A service company might only ever deal with customer data and premises access; a contract manufacturer might deal with materials, tooling, and IP but never premises.
- Assign ownership tagging or flagging. Decide how customer- or external-provider-owned items get physically or digitally marked as not your own.
- Build the intake verification step into your existing receiving process rather than creating a separate parallel system — this keeps the workload manageable and keeps the record in one place auditors can trace.
- Fold customer-owned tools and gauges into your existing calibration and maintenance schedule under clause 7.1.5, flagged by owner so they're never mistakenly treated as your own asset for disposal or reallocation decisions.
- Write the incident-and-notification procedure before you need it. Define who is authorized to notify the customer, what timeframe applies, and what the record must capture.
- Set access controls and a retention/deletion schedule for any customer or external-provider data you hold, and tie that schedule to whatever contractual or regulatory retention period applies.
- Review the register periodically — I'd suggest at minimum during your internal audit cycle — to confirm property has either been returned, consumed, or is still accounted for. Our internal audits guide has a broader framework for building clause-specific audit checklists like this into your existing internal audit schedule.
Common Nonconformities Against 8.5.3
The patterns I see most often, roughly in order of frequency:
- No register or list exists at all — the organization can describe what it does verbally but has nothing documented to show an auditor.
- Customer-supplied tooling is excluded from the calibration program because it's "not our asset."
- Damage or loss incidents are handled informally, with no record and no documented customer notification.
- Personal data is managed entirely as an IT or legal matter with no visibility inside the QMS, so it's absent from internal audits and management review entirely.
- Returnable supplier packaging (totes, pallets, reusable containers) is tracked for count but not condition, so damage claims from the supplier can't be substantiated either way.
Any one of these, caught during a certification audit, is typically written up as a minor nonconformity rather than major, because it's rarely systemic across the whole QMS. But minor nonconformities against the same clause repeating across audit cycles tend to get escalated, so it's worth closing the gap the first time it's flagged rather than treating it as a one-off correction.
FAQ
What counts as customer property under ISO 9001 clause 8.5.3?
The clause's note lists material, components, tools and equipment, premises, intellectual property, and personal data as examples. In practice this includes anything a customer or external provider gives you, or gives you access to, for use in delivering the product or service — physical or digital.
Does personal data count as customer property under ISO 9001?
Yes. The note attached to clause 8.5.3 explicitly names personal data as a form of property belonging to customers or external providers, which means it falls under the same identify, verify, protect, and safeguard obligation as physical materials or tooling.
What must you do if you lose or damage a customer's property?
Clause 8.5.3 requires you to report the loss, damage, or unsuitability to the customer or external provider, and to retain documented information on what occurred. There's no minimum severity threshold in the standard — the reporting obligation applies regardless of whether the condition was your fault.
Does clause 8.5.3 apply to external provider (supplier) property too?
Yes. The clause covers "customer or external provider" property in the same sentence, most commonly seen in practice as returnable packaging, pallets, totes, or loaned equipment supplied by a vendor for receiving their goods.
What documented information does clause 8.5.3 require?
At minimum, a record of what occurred any time customer or external provider property is lost, damaged, or found unsuitable for use, along with evidence that the customer or external provider was notified. Many organizations also maintain a running register of property currently in their custody, though the standard doesn't mandate that specific format.
Is clause 8.5.3 the same as calibration requirements under clause 7.1.5?
No, but they intersect. Clause 7.1.5 governs monitoring and measuring resources generally. When a customer-owned gauge, fixture, or measuring device is in your custody, it needs to satisfy both: 7.1.5's calibration and fitness-for-use requirements, and 8.5.3's identify/verify/protect/safeguard duty because it belongs to someone else.
Last updated: 2026-08-11
Jared Clark
Principal Consultant, Certify Consulting
Jared Clark is the founder of Certify Consulting, helping organizations achieve and maintain compliance with international standards and regulatory requirements.