Requirements for external providers
1. Validity, effectiveness and contractual incorporation
This document sets out the requirements of BD SENSORS s.r.o. (hereinafter referred to as the "Organization") for external providers, i.e. suppliers of products, materials, processes or services (hereinafter referred to as the "Supplier").
These requirements shall apply to the extent appropriate to the type of product or service supplied, its criticality, intended use, the risk of the supplier and the requirements of the customer, legal regulations or relevant standards.
These requirements are an integral part of any order of the organization, unless the order, contract or other written agreement expressly provides otherwise. The supplier accepts them in particular by means of a written confirmation of the order, the commencement of performance or the delivery of performance.
The organization recommends that the order contains the following arrangement: "By confirming the order, the supplier accepts the Requests for external providers BD SENSORS s.r.o., revision 000, effective from 6.8.2026, which are part of the order."
In the event of a discrepancy, the following shall prevail in the following order: (i) the individual written contract or its amendment, (ii) the order including its annexes, (iii) the technical documentation, specifications and customer requirements expressly adopted by the organization, (iv) these requirements. A derogation from these requirements is effective only if it has been agreed in advance in writing by an authorized representative of the organization.
For a specific order, the wording of these requirements effective on the date of its acceptance by the Supplier shall apply, unless otherwise specified in the order.
2. Purpose and scope
The purpose of the document is to establish minimum requirements for quality, compliance, product safety, traceability, documentation, change management, counterfeit product prevention, and supply chain risk management.
The requirements are set in accordance with the requirements of EN(AS) 9100, in particular in the areas of information for external providers, the management of outsourced processes, products and services, the prevention of counterfeit or unverified products, and the transfer of relevant requirements in the supply chain.
This document does not replace the requirements of the legislation, the contract, the order or the technical documentation. If a particular requirement is more stringent, the more stringent requirement shall apply, unless this violates the law or an express agreement of the parties.
3. Abbreviations and concepts
EN(AS) 9100 – Requirements for a quality management system for aerospace and defence organisations.
QMS – Quality Management System.
CoC – Certificate of Conformity / certifikát shody.
FOD – Foreign Object Debris / Damage; foreign objects or damage caused by foreign objects.
Counterfeit Product – counterfeit, unverified, unauthorized, mislabeled, or otherwise suspicious product or material.
Non-conformity – failure to comply with the requirements of the order, contract, technical documentation, legal regulation, standard or these requirements.
External Provider/Supplier – an organization or person providing a product, service, process, or other activity to an organization.
4. General requirements
The Supplier is obliged to comply with the requirements set forth in the order, contract, technical documentation, specifications and in this document.
In particular, the supplier is obliged to ensure:
1. delivery of the product or service in accordance with the order and the applicable technical documentation;
2. delivery of documentation demonstrating the conformity of the product or service, if required, in particular the EN 10204 3.1 certificate, CoC, measurement, test report, calibration certificate;
3. the identification and traceability of the product, material, batch, melt, batch or other relevant identifier;
4. maintaining a quality management system appropriate to the nature of the supply;
5. management of a nonconforming product or service, including timely notification to the organization;
6. the retention and availability of records for a specified period of time;
7. the transmission of relevant requirements to its subcontractors;
8. enabling the verification of a product, service or process by an organization, its customer or a competent authority;
9. ensuring the competence of persons carrying out activities related to the supply;
10. Fulfilment of other specific requirements specified in the order, such as packaging, labelling, cleanliness, FOD, testing, inspection, documentation, export restrictions or information security.
5. Supplier Quality Management System
The supplier shall maintain a quality management system appropriate to the nature and risk of the supply and, upon request of the organisation, shall demonstrate its adequacy, certification or other professional competence.
If the supplier is certified according to the quality management system, it shall immediately inform the organisation in writing, within 5 working days at the latest, of the suspension, restriction, withdrawal, termination or non-renewal of the certification, if this may affect its ability to meet the requirements of the organisation.
The supplier shall also immediately notify a circumstance that may materially jeopardise the continuity, quality, legality or timeliness of the supply, in particular the opening of insolvency proceedings, a significant production outage, a serious regulatory action or the loss of authorisation necessary for performance.
6. Supplier Approval and Evaluation
Suppliers are selected, approved, and evaluated according to the organization's internal rules. In approving and evaluating, the organization may take into account, in particular, the supplier's ability to meet the requirements, the quality of previous deliveries, delivery reliability, the results of incoming inspections, complaints, non-conformities, certification, proven competence, risk and substitutability of the supplier.
The organisation shall be entitled to verify, audit or review the supplier's documentation, proportionately to the nature of the supply and the risk. The approval of the supplier or its evaluation does not relieve the supplier of its responsibility for proper performance.
The organisation may restrict, suspend or revoke a supplier's approval, in particular in the event of a serious or repeated breach of requirements, failure to correct an identified non-compliance or loss of necessary competence.
7. Documentation and records
The Supplier is obliged to keep documented information related to the delivery to the extent appropriate to the type of product or service. These records include, but are not limited to, delivery notes, material and conformity certificates, measurement, test or calibration protocols, inspection records, materials used, batches, melts, production batches, nonconformities, repairs, rework, and corrective actions.
The retention period for records is governed by an order, contract or other written request of the organization. If the period is not specified, the supplier shall keep the records for at least 10 years from delivery in the case of a product, material or service with a traceability requirement, and for at least 5 years in other cases. If the law or the nature of the recording does not allow for such retention, the supplier shall notify the organization in writing in advance.
The contractor shall make the records available at the request of the organisation without undue delay, no later than 5 working days, unless a shorter reasonable period is required in view of the urgency of the case.
8. Technical documentation and specifications
The requirements for a product, process or service are set out in particular in an order, drawing, technical specification, model, standard, workflow or other documentation handed over.
The supplier shall verify that it has complete and valid documentation before the commencement of performance. If it finds an ambiguity, contradiction, inconsistency or obvious error, it is obliged to request a written explanation or supplement from the organization immediately, before the commencement of the performance in question. The supplier may not use invalid, replaced or unverified documentation in the performance and will introduce measures against its unintentional use.
Technical documentation, samples, models, software, production processes and other documents of the organization are confidential. The supplier may only use them for the performance of the order and may not disclose them to a third party without the prior written consent of the organization, except for the necessary disclosure to an approved subcontractor bound by at least the same confidentiality obligation. After the completion of the performance, the supplier will return them at the request of the organization or demonstrably safely destroy them, unless this is prevented by law.
9. Measuring and testing equipment
If the supplier demonstrates the conformity of a product or service by measuring, testing or inspection, it is obliged to use appropriate measuring and testing equipment. These devices must be controlled, maintained, protected from unauthorized modification and calibrated or verified to the extent appropriate to the requirements of the supply.
Calibration shall be linked to recognised national or international standards, where applicable. The supplier will provide valid calibration or verification documents upon request.
10. Change Management
The supplier shall inform the organization in advance in writing of any planned change that may affect the conformity, safety, functionality, service life, traceability of the product, service or process, as well as the fulfillment of customer requirements. This includes, in particular, a change in a production, control or special process, material, subcontractor, place of production or provision of a service, QMS certification status, technology, design, product or service used compared to an order or specification.
Such a change may only be made with the prior written approval of the organisations, if it is likely to have that effect. Approval does not relieve the supplier of responsibility for the conformity of the supply. An urgent change necessary to avert imminent damage must be notified to the organisation without delay, together with a justification and a proposal for further action.
11. Managing a nonconforming product or service
The supplier is responsible for managing nonconforming products, processes or services so as to prevent their unintentional use, mixing, shipment or delivery to the organization. A non-conforming product must be appropriately identified, separated and recorded.
If a supplier discovers a nonconformance concerning a product or service that has already been shipped or delivered, or if there is a reasonable suspicion of such a nonconformity, it shall notify the organization without delay, no later than 24 hours after the discovery. The notification shall include at least the identification of the product or service, the order number or delivery note, the quantity, batch, melting or other traceability identifier, a description of the non-conformity, an assessment of the extent concerned, immediate action and a proposal for further action.
Deviation from an order, drawing, specification or other requirement is permissible only with the prior written approval of the organization. The Supplier shall submit a proposal for a corrective measure no later than 5 working days from the organization's request or within another reasonable period specified by the organization.
12. Rework and corrections
Reprocessing of a non-conforming product may only be carried out in a way that brings the product into full conformity with the original requirements and must subsequently be verified to the appropriate extent.
Repair, use of an alternative procedure, change of design or acceptance of a product in a deviated state is only possible with the prior written approval of the organization. The supplier shall keep records of the rework, repair and the result of the subsequent verification, where relevant for the demonstration of conformity.
13. Prevention of counterfeit or unverified products
The Supplier is obliged to take effective measures to prevent the delivery of counterfeit, unverified or unauthorized products. In particular, it will ensure that purchases only from approved, authorized, or trusted sources, maintains the traceability of products and materials, provides authentic compliance documentation, verifies its authenticity and identification of the product, and prevents the reintroduction of a suspicious product into the supply chain.
In case of suspicion of a counterfeit, unverified or otherwise non-compliant product, the supplier shall immediately isolate the product and inform the organization no later than 24 hours after discovery. Without the prior written consent of the organization, the organization may not supply, repair, remanufacture or transfer such a product to the next supply chain.
14. Design and development
If the delivery includes design or development, the contractor is required to manage these activities, including planning, inputs, outputs, review, verification, validation, change management and record keeping. The scope and outputs of design and development are subject to the approval of the organization if this is stipulated in an order, contract or technical specification.
Unless otherwise agreed in writing, the Supplier shall provide the Organization with the authorization to use the outputs of the design and development created for the Organization to the extent necessary for the use, maintenance, repair, modification and other handling of the delivered Performance. Ownership of tools, documentation, samples and rights to results is governed by a contract or order; If not regulated, the supplier shall seek the written consent of the organization before using them for other persons.
15. Product packaging, labeling and protection
The supplier is responsible for ensuring appropriate packaging, labeling, protection and handling of the product so that it does not become damaged, confused, contaminated or lost in traceability during transportation, storage or handling. Different batches, melts or batches must be appropriately labelled and separated.
If a product has a limited shelf life, shelf life or shelf life, this information must be clearly stated on the packaging or in the delivery documentation, including the date of manufacture, the expiry date and the storage conditions, if relevant.
16. FOD prevention and product purity
If relevant to the nature of the delivery, the supplier is obliged to provide measures to prevent the occurrence of foreign objects and dirt. The product must be free of dirt, foreign objects, loose particles, or other elements that could negatively affect its function, safety, assembly, or further processing prior to shipment.
17. Product safety, competence and ethical conduct
The Supplier is obliged to ensure that the persons involved in the fulfilment of the order are to a reasonable extent competent and familiar with the importance of their work for the conformity of the product or service, the safety of the product, the fulfilment of the requirements of the organisation and the customer, and the importance of ethical conduct.
The Supplier complies with applicable legislation in the performance, including regulations relating to occupational safety, environmental protection, competition, prohibition of corruption, sanctions and export restrictions, if applicable to the supply. Upon request, the organisation shall provide reasonable cooperation to verify compliance with these requirements.
18. Delivery documentation
The delivery documentation shall include information allowing the delivery to be uniquely identified, in particular the order number, the identification of the product or service, the quantity, batch, melting or batch number, if relevant, and the required certificates, protocols or other documents demonstrating conformity.
If the required documentation is missing or if it is incomplete or illegible, the organisation is not obliged to consider the delivery as complete or accept it as compliant.
19. Right of access and audit
The Supplier shall allow the organization, its customers and the relevant supervisory or regulatory authorities access to relevant documented information, records, products and premises related to the fulfillment of the order, if such access is proportionate to the nature of the delivery, the risk, the customer's requirements, or legal and regulatory requirements.
As a rule, the audit is announced in advance within a reasonable period of time and is carried out during the normal working hours of the supplier, respecting its reasonable rules of security, protection of confidential information and operation. In an emergency, in the event of a reasonable suspicion of a serious non-conformity, or if the requirements of the customer or the competent authority so require, the audit or verification may be carried out without this preliminary period. An organization may request a remote review of documentation instead of or in addition to an audit.
The contractor shall remove the audit findings within a period set by the organization, which shall be proportionate to their severity. The contractor shall transfer this requirement to its subcontractors to the appropriate extent.
20. Subcontractors
The supplier is responsible for the performance of its subcontractors to the extent that it performs itself. The relevant requirements of the organisation, in particular those relating to quality, traceability, changes, non-conformities, counterfeit products, confidentiality, documentation and auditing, shall be transferred to subcontractors to the extent corresponding to their share of the performance.
If required by the order, technical documentation or the nature of the critical supply, the supplier may use a subcontractor, change a critical subcontractor or relocate the performance only with the prior written approval of the organisation.
21. Confidentiality, information security and personal data
The Supplier is obliged to protect the confidential information of the organization from loss, misuse, unauthorized access, alteration or disclosure. It shall take appropriate technical and organisational measures, in particular the management of access authorisations, the protection of electronic communications and backups, where appropriate to the nature of the information being processed.
The supplier shall promptly, no later than 24 hours after discovery, notify the organization of a security incident that may affect the confidentiality, integrity or availability of the organization's information, technical documentation, systems or personal data. It will provide the necessary cooperation to clarify the incident and limit its impact.
If a supplier processes personal data for an organization as a processor, the parties shall conclude a separate written agreement on the processing of personal data prior to the commencement of such processing. The Supplier may not commence such processing without documented instructions from the organization and without meeting the conditions set forth in legal regulations and this Agreement, including the rules for the involvement of other processors.
22. Consequences of Breaches
If an organisation finds a non-compliance or breach of these requirements, it shall be entitled, depending on the nature and seriousness of the case, to request in particular an explanation, corrective action, additional verification, replacement, correction or revision of the performance; refuse to accept or return the non-compliant delivery at the supplier's expense; suspend orders, supplier approvals or payments to the extent permitted by the contract and the law; and to assert damages and other claims arising from the contract or the law.
If the breach is substantial, repeated, if it is not remedied within a reasonable period of time specified by the organization, or if there is a serious threat to quality, safety, traceability, confidentiality or fulfillment of customer requirements, the organization is entitled to withdraw from the order or contract in question if this is agreed or permitted by law.
The exercise of these rights is without prejudice to the organization's right to compensation or other legal remedies.
23. Proportionality of requirements and final provisions
These requirements shall apply to the extent appropriate to the type of product or service, its criticality, intended use, the risk of the supplier and the requirements of the customer. The organisation shall establish and review the scope of the requirements before communicating them to the supplier.
The organization may supplement or specify the requirements in the purchase order, technical specification, contract or individual written agreement with the supplier.
If an organization changes this document for future orders, it will publish a new version with the revision designation and effective date. The change does not apply to orders already received without the express agreement of the Parties, except for a change caused by a binding legal regulation or an urgent request from the customer or the competent authority; In such a case, the organization shall notify the supplier in writing, and the parties shall discuss the reasonable impact of the change on performance.
Valid from 06.08.2026
Amendment No. 00
Settings