Order QMB externally: When an external quality management representative is the better choice
An external QMB provides ISO 9001 expertise, audit preparation and a documented QM system without a full-time position. The article clarifies responsibility, costs, selection criteria and the handover to permanent operation.
An external quality management representative (external QMB) takes on the tasks on behalf of a company that were previously anchored in ISO 9001:2008. The ISO 9001:2015 standard no longer formally requires a QMB because responsibility for the quality management system (QMS) has been transferred to top management. In practice, however, every certified company needs a person to maintain the QMS, accompany audits, track corrective measures and organise the interface to the certifier. This operational function remains in place, regardless of the formal deletion of the QMB in Section 5.3 of the current standard.
External solutions are widespread in medium-sized companies because an internal full-time position does not make economic sense with limited QMS effort. This article explains which tasks an external QMB actually takes on, how it is ordered, what it costs, how you choose it and how the handover to permanent operation is organised properly. The focus is on manufacturing companies, IT service providers and regulated industries such as medical technology and automotive suppliers. Supplementary standards such as ISO 13485 for medical devices, IATF 16949 for the automotive industry and ISO 17025 for testing laboratories are classified in their interface to the QMB role so that companies with multiple certifications also receive a basis for decision-making.
Key Takeaways
- ISO 9001:2015 no longer formally requires a QMB, but in practice every certification requires a designated person for QMS operation and audit support.
- An external QMB typically costs 600 to 2,400 euros per month, an internal full-time position costs 65,000 to 95,000 euros per year including additional wage costs.
- The SLA takeover of an external QMB mandate at CIVAC takes place in 2 working days, with an appointment certificate, reporting line to management and EU data residency.
What the QMB actually does: Tasks that go beyond the norm
Section 5 of ISO 9001:2015 requires top management to assume responsibility for the QMS. In practice, however, the operational maintenance of the system is delegated to a named person, internally or externally. This person takes on six core tasks. Firstly, the maintenance of the quality manual and the documented procedural instructions according to Section 7.5. Secondly, the preparation of the annual management review according to Section 9.3 with inputs on customer satisfaction, audit results, process performance, potential for improvement and risks. Thirdly, the planning and execution of internal audits in accordance with Section 9.2, including the audit program, audit plan, audit reports and tracking of measures.
Fourthly, the support of the external audits, i.e. surveillance audits, re-certification audits and, if necessary, special audits. Fifth, maintaining the risk and opportunity register in accordance with Section 6.1 with specific measures, responsible persons and deadlines. Sixth, training planning and proof of competency in accordance with Section 7.2, often in conjunction with human resources management. Anyone who neglects one of these six tasks risks a deviation in the external audit, which can jeopardize certification. CIVAC maps the tasks of the quality management representative as a module structure in the workspace, with templates for the audit program, management assessment, risk register and corrective measures. This makes it clear which task is due when and which evidence is stored in the system. Anyone who manages multiple locations or subsidiaries can maintain and consolidate the task matrix for each unit without having to create a central Excel table. This also makes it possible to have a group QMB function with multiple clients in an architecture in which the individual audit traces remain strictly separated from each other and can at the same time be evaluated in a consolidated manner. The connection to supplier audits and supplier evaluations, for example via the role of the supplier auditor, can also be mapped in the same workspace, so that the QMS is integrated into the supply chain view.
ISO 9001:2015 without QMB: What the standard really requires
The revision of ISO 9001:2015 has deleted the requirement for a named quality management representative in Section 5.3. Instead, the standard requires top management to assign responsibilities and authority to control the processes, maintain the QMS and ensure compliance with requirements. In practice, this responsibility is delegated to a person who is still referred to in common parlance as a QMB. The name is not relevant to certification, the function is.
External auditors usually expect a clear assignment: who documents the QMS, who coordinates the internal audits, who prepares the management assessment, who is the contact person for the certification audit? This assignment must be made in writing, for example in a job description, a function matrix or an appointment certificate. For an external QMB, the appointment certificate is the central proof. It contains the scope of tasks, the reporting line to top management, the deputy and the duration of the mandate. The appointment certificate, signed, filed, verifiable. CIVAC creates this appointment certificate in the workspace, with clear assignments to the sections of ISO 9001:2015. The external auditor immediately finds the formal basis and operational evidence in the client folder, such as the last three internal audit reports, the current management assessment and the risk register with follow-up action status, so that the fulfilment of obligations can be verified in a consolidated view. Even if the certification body changes, the documentation remains in the same architecture, so that a new team of auditors can be led to the relevant evidence without any research effort. The appointment certificate is also provided with a substitute provision so that a sudden absence of the QMB during the audit appointment does not lead to a postponement.
When an external solution is economically better
The decision between internal and external QMB follows a simple logic. An internal full-time position makes economic sense if the QMS volume requires at least 0.8 to 1.0 full-time equivalents. This is typically the case with 250 or more employees in manufacturing companies, at several locations or with combined certifications such as ISO 9001 plus IATF 16949 plus ISO 14001 plus ISO 45001. Anyone below this either creates a part-time QMB position or orders externally.
A part-time solution carries the risk that the employee will carry out the QMB tasks in addition to day-to-day business Audit-relevant activities are left on hold during peak times. An external order solves this problem structurally. The external QMB only has tasks from the QMS, a documented reporting line to management and a minimum hour limit per month, which is fixed in the mandate contract. Others run compliance like a filing cabinet. We run it like software. CIVAC offers the external QMB role in dual logic: Licence the workspace for your internal representatives, or have our representatives order it. Both models run in the same system with the same 490 audit templates and EU data residency. The SLA for the initial acceptance of the mandate is 2 working days, which can mean the difference between timely preparation and a postponement of certification in the event of a short-term audit date or a sudden change in personnel. The costs can be precisely indicated before the contract is concluded based on the number of employees and the certification landscape. This means that the typical uncertainty between a cheap offer with an hourly rate slip and a flat rate that is calculated in a non-transparent manner disappears. Anyone who reviews the mandate contract annually and adjusts the lower hour limit to the actual effort of the last twelve months will keep costs under control over the long term.
Costs and contract models for an external QMB
The costs for an external QMB depend on three factors: scope of certifications, number of employees and number of locations. Pure ISO 9001:2015 support in a medium-sized company with one location and 80 to 200 employees typically ranges between 600 and 1,200 euros per month, with a minimum hourly limit of 6 to 10 hours. A combined certification with ISO 9001 plus ISO 14001 plus ISO 45001 increases the effort to 1,200 to 2,400 euros per month. Industry-specific standards such as ISO 13485 or IATF 16949 are higher because the regulatory requirements are more stringent and the external audits take longer.
Contract models come in three variants. Firstly, the monthly mandate fee with a minimum hourly limit and additional expense regulations. Secondly, the flat-rate model with an annual fixed remuneration, which tends to be cheaper in subsequent certification years, but covers higher initial costs in initial certification or recertification years. Thirdly, the hourly model with pure billing based on work performed, which only makes sense for very small companies or clearly defined projects. At CIVAC, the standard model is the monthly mandate fee including a workspace licence. This eliminates the need to purchase separate tools and the audit templates, risk register and management review are available at no additional cost. The auditor calls, the evidence is ready. It is worth comparing the three options before signing a contract because the total costs can vary greatly over two to three years and a cheap hourly rate does not automatically result in a cheap annual bill. It is also worth taking a look at special costs for audit support in group subsidiaries or site audits, which are often not covered in the main contract and are billed at separate daily rates.
Selection criteria for an external QMB service provider
Anyone who selects an external QMB should systematically check seven criteria. First: What formal qualifications do you have? A recognised proof of qualification is training as a quality management representative according to the DGQ/EOQ standard or a lead auditor certificate according to ISO 9001:2015 from an accredited certification body. Secondly: What industry experience do you have? A QMB for automotive suppliers needs IATF 16949 knowledge, a QMB for medical device manufacturers needs ISO 13485 and MDR experience. Third: Where is the data stored and does the EU data residency principle according to the GDPR apply?
Fourth: What proxy regulation is there? An external QMB without a named deputy is unavailable due to illness or vacation, and a short-term audit appointment can no longer be covered. Fifth: What templates are included and are they versioned? Sixth: How is the response time to inquiries regulated? A documented SLA for responses within 24 or 48 hours is common. Seventh: What handover logic applies at the end of the mandate? Do the templates, the risk register and the audit reports remain with the client or with the consultant? CIVAC meets these seven criteria in a standardised manner. Audit-proof, documented, Section 130-proof. The data remains in the client's workspace, the templates are versioned, and the representative is part of the mandate. This ensures that a later change of the operational person does not reset the QMS and does not jeopardize the certification. A provider who cannot guarantee one of the seven criteria in writing will not be included in the final round. An eighth soft criterion is the personal accessibility of the QMB person and a predefined appointment rhythm model, because in reality audit support requires many short coordinations and does not work in large monthly blocks. Language and location proximity also play a role if the company operates several plants and audits take place on site.
Order and legal classification
The appointment of an external QMB is carried out by the management in the form of a written appointment certificate. This document contains the scope of tasks according to sections of ISO 9001:2015, the reporting line to top management, the deputy, the duration of the mandate, the termination options and, if necessary, references to other certifications that the QMB manages. Entry in the commercial register is not required. A contractual basis between the client and the external service provider regulates the remuneration, the minimum hour limit, liability and data processing in accordance with the GDPR.
Legally, the external QMB does not assume any legal responsibility of its own because ISO 9001:2015 no longer formally requires a QMB. Responsibility remains with top management. In fact, the QMB has operational responsibility for the correct execution of the tasks assigned to it, such as the timely preparation of audits, the completeness of the management assessment and the plausibility of the risk register. In the event of gross negligence or omissions, the contractual liability applies with the agreed financial loss liability. CIVAC stores the appointment certificate, the mandate contract and the liability information in the workspace. The role is commissioned, not the consultant day. This means that proof of the order is fully available in the external audit, together with the operational evidence of the activity, such as audit plans, reporting time stamps and action status, which offers the auditor a complete basis for evaluation in a data room. With integrated management systems, the appointment certificate can be expanded to include other representative roles, such as environmental officer or occupational safety function, without the need for additional contracts. This structurally eliminates duplication of work, reporting gaps and inconsistencies between the various areas of responsibility. The external provider's liability for financial loss is guaranteed in the amount in the contract so that in the event of a dispute it is clear which coverage applies.
From onboarding to continuous operation
The onboarding of an external QMB typically takes place in four phases. Phase one: inventory over two to four weeks. The current quality manual, the latest internal and external audit reports, the previous year's management assessment and the risk register are viewed here. Identified gaps are recorded in a list of measures with priorities and deadlines. Phase two: Closing the gap over four to eight weeks, depending on the depth of the deficits. Here, missing documents are created, outdated processes are updated and training plans are expanded.
Phase three: Building the routine. The external QMB plans the audit program for the current financial year, coordinates the dates with the certification body, prepares the management assessment and establishes regular reporting to the management. Phase four: Continuous operation with monthly status, quarterly reporting line and annual management review. Deadline begins as soon as we become aware of it. Those who carry out onboarding in a structured manner using the 490 CIVAC audit templates typically shorten the gap closure phase by 30 to 50 percent. This means that initial certification can be achieved in 14 to 20 weeks instead of the often communicated 9 to 12 months. In the case of recertifications or changes of mandate, the phase is shortened further because the database is already available in the workspace. A handover from an internal QMB to an external service provider takes place in the same workspace without the risk register or audit reports being lost in a migration. The reporting line to management is adjusted at the same time so that the external QMB can report immediately and no organisational gap arises. It is also possible to hand it back to an internal QMB in the same system without loss of data if the company later creates an internal position.
Common pitfalls and how to avoid them
In practice, five pitfalls arise regularly. First, the management review is compiled shortly before the audit date and contains outdated data on customer satisfaction, complaint levels and process performance. Auditors recognise this within 30 minutes and assign deviations. Second: The risk register is maintained as a static table without the measures being linked to those responsible, deadlines or effectiveness testing. Third: Internal audits are not planned according to a documented program, but according to the availability of internal auditors, which leads to gaps in coverage.
Fourth: Corrective actions are opened but not closed within the agreed deadlines. During the next audit phase it becomes clear that the effectiveness test is missing. Fifth: The interface between QMB and other officers, such as data protection officers, ISB, environmental officers, is not regulated. In integrated management systems, this creates duplication of work and inconsistencies. CIVAC addresses these five pitfalls structurally. The management assessment is filled with data status snapshots throughout the year, the risk register is linked to measures, responsible persons and deadlines, the audit program is a mandatory field in the workspace, corrective measures have an effectiveness check as a procedural step, and the interfaces to other representatives are configured as an authorisation model. This means that integrated management systems based on ISO's High Level Structure can be consistently managed in one architecture, which significantly reduces audit preparation time and at the same time improves the consistency of reports across all standards. The preparation for industry-specific extensions such as ISO 13485 or IATF 16949 also takes place in the same data architecture, so that a new certification does not lead to the creation of a parallel tool. This allows the maturity of the QMS to be objectively measured based on the corrective action closure rate, audit result trends and customer satisfaction metrics.
Order QMB externally: The next step
The decision for an external QMB is usually the more economically and operationally sensible choice in medium-sized companies, provided that the QMS volume remains below a full internal position and the audit activity can be planned. The external solution offers a professionalized routine, a clear reporting line, a representative and a faster response to special situations, such as a recertification or a new certification. The order is made with an appointment certificate, the reporting line goes to top management, the audit templates are stored in a versioned manner in the workspace.
CIVAC is structured as a compliance platform and officer-as-a-service in such a way that the QMB role can be selected in the dual logic. Licence the workspace for your internal representatives, or have our representatives order it. The SLA for the first order is 2 business days. The 490 audit templates, the risk register, the management review template and the corrective action module are part of the workspace. EU data residency is standard. Turn reading into a mandate.: info@civac.de or the contact form on civac.de. In the initial consultation, we clarify which model is suitable and what monthly costs will result from this based on the number of employees, number of locations and certification landscape. A written indication and a proposal for the appointment certificate follow. If a specific audit date is coming up, the preparation can be structured even under time pressure because the templates and reporting line are already standardised. The role is commissioned, not the consultant day. This changes audit preparation from an annual special situation to a documented routine. If necessary, the QMB function can be combined with other roles such as environmental officer, data protection officer or compliance officer in the same workspace, so that multiple duties converge on a single reporting line.
FAQ
Does ISO 9001:2015 still require a QMB?
ISO 9001:2015 no longer formally requires a QMB. Responsibility for the QMS lies with top management. In practice, however, auditors expect a named person who will take on operational tasks and be the contact person during the audit. This function can be filled internally or externally, but should be documented in writing, such as an appointment document, and reported to top management.
What are the annual costs for an external QMB?
The range is between 7,200 and 28,800 euros net per year, depending on the number of employees, number of locations and certification landscape. Pure ISO 9001:2015 support for one location and 80 to 200 employees typically costs 7,200 to 14,400 euros. Combined certifications with ISO 14001 and ISO 45001 or industry-specific standards such as IATF 16949 or ISO 13485 noticeably increase the effort.
How quickly can an external QMB be ordered?
In the classic market, selection, contract negotiation and ordering take between 4 and 8 weeks. CIVAC works with an SLA of 2 working days for the first order because the role, appointment certificate, templates and reporting line are standardised in the workspace. This means that short-term audit preparation or a sudden change in personnel can be covered without delay.
Can an external QMB manage several standards at the same time?
Yes, as long as you have the qualifications and industry experience. ISO High Level Structure integrated management systems typically include ISO 9001, ISO 14001 and ISO 45001 in a common structure. Industry-specific standards such as ISO 13485, IATF 16949 or ISO 17025 also require special auditor qualifications and, in some cases, approved lead auditors with a current certificate from an accredited body.
What data does the external QMB receive and how is data protection regulated?
The external QMB has access to the quality manual, procedural instructions, internal and external audit reports, management reviews, the risk register, training records and corrective actions. Personal data is limited to the necessary extent in accordance with Art. 5 GDPR. An order processing agreement in accordance with Art. 28 GDPR is standard. At CIVAC, data processing takes place in the EU with documented EU data residency and versioned access protocol.
What happens to templates and reports when the mandate ends?
With CIVAC, all templates, risk registers, audit reports and management reviews remain in the client's workspace, which continues to have access. The appointment certificate is formally terminated and the data is not migrated or deleted. This means that an internal successor or a new external QMB can take over without loss of data. This handover logic is part of the mandate standard and belongs in every serious provider contract.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.