ASPICE · ACQ.4 · Supplier Monitoring

ASPICE ACQ.4 Supplier Monitoring

Tracking and steering a supplier's technical and project performance against the agreements — joint reviews, information exchange, and acting on deviations.

In short

ASPICE ACQ.4 Supplier Monitoring tracks and assesses the performance of a supplier against agreed requirements: performing the agreed joint activities, exchanging the agreed information, reviewing technical development and project progress with the supplier, and acting to correct deviations.

ACQ.4 is the mirror of the V from the customer side — how an OEM or Tier-1 monitors its supplier. The evidence is joint reviews, exchanged information, and tracked actions on deviations.

Purpose & process outcomes

Purpose (per the ASPICE PAM): track and assess the performance of the supplier against agreed requirements.

The process is achieved when these outcomes hold:

Base practices

ACQ.4.BP1

Agree on and maintain joint processes and interfaces

Define the joint processes, interfaces and information to exchange.

ACQ.4.BP2

Exchange all agreed information

Exchange the agreed information regularly.

ACQ.4.BP3

Review technical development with the supplier

Joint technical reviews.

ACQ.4.BP4

Review progress of the supplier

Monitor schedule, cost, quality against the agreement.

ACQ.4.BP5

Act to correct deviations

Raise and track corrective actions on deviations.

Work products

The output work products ACQ.4 asks for (named per the standard):

Map it to your tools

This is where the standard meets reality. Each work product and outcome has a concrete home — an issue type, work-item type, or model element — in the tools you already run. Types are configurable, so treat this as the typical ASPICE setup:

Work product / outcomeJiraPolarionCodebeamerDOORS NextEnterprise ArchitectConfluence
WP: joint review record / minutesreview issue + linked minutesreview work itemreview tracker itemjoint-review minutes page
WP: supplier progress / status reportstatus issue / imported metricsstatus report / dashboardstatus reportsupplier status page
WP: information-exchange recordshared board / delivered artifacts as issuesshared project / delivered itemsshared trackershared moduledelivered modelexchange log / shared space
WP: deviation / corrective actionaction / risk issue tracked to closureaction work itemaction itemactions log
Outcome: monitored against agreementKPI dashboard vs agreed targetsLiveReport vs targetsreport vs targetsscorecard page

The trap isn't the tools — it's that the links between them are maintained by hand and decay the moment a requirement changes. (See best ASPICE tools.)

It only matures on one configuration-management data model

Here is the part almost everyone misses. ACQ.4 can never reach a mature capability level (CL2+) on its own — it can only be as mature as the configuration-management data model underneath it. SUP.8 Configuration Management is the secret enabling layer: the shared data model of items, versions, baselines and links that is the basis on which every other process group becomes provable. Scatter that data model across a Jira project, a Polarion space, a DOORS module, an EA model and a Confluence tree, and the model is fragmented by construction — the traceability that ACQ.4 depends on decays the moment anything changes, and no amount of process ceremony fixes it.

What actually unlocks maturity is a headless ALM — an API-first, tool-agnostic configuration-management data model that is the single source of truth for every work product and every link, readable and writable by both humans and agents — plus an agent/human workflow definition, coordination and traceability platform on top of it, so every change is planned, assigned (to a human or an agent), executed and traced against that one model. That is the layer that lets ACQ.4 be mature instead of theatrical.

Where teams fail ACQ.4

This is part of The Blueprint — our free template QMS

ASPICE deliberately gives you no blueprint. So we wrote one. This ACQ.4 guide is part of The Blueprint — our free, open template QMS for ASPICE: every VDA-scope process area, its outcomes and work products, mapped to concrete artifacts in your tools and grounded in one configuration-management data model. Take it, use it, no cost.

Agents reconcile the supplier's delivered artifacts and metrics against the agreement, keep the joint-review and action records current, and flag deviations early — turning supplier monitoring into continuous evidence rather than a meeting nobody minutes. And we offer to implement The Blueprint for you: our agentic solutions (Vera generates ACQ.4's work products and traceability as a byproduct of the build, each with a confidence score and audit trail) running on a partner headless ALM — the API-first configuration-management data model that makes the whole thing provable.

Frequently asked questions

What is ACQ.4 in ASPICE?

ACQ.4 Supplier Monitoring tracks and assesses a supplier's performance against the agreed requirements through joint activities, regular information exchange, technical and progress reviews, and corrective action on deviations.

What are the ACQ.4 work products?

Supplier monitoring/joint review records, supplier progress/status reports, information-exchange records, and deviation/corrective-action records.

Who is assessed against ACQ.4?

The acquiring side (an OEM or a Tier-1 buying from a sub-supplier). ACQ.4 evidences how the customer monitors and steers its supplier, complementing the engineering processes the supplier is assessed on.

How do you evidence supplier monitoring in tools?

Joint-review minutes in Confluence, tracked corrective actions and status in Jira/Polarion/Codebeamer, exchanged deliverables on a shared board, and a KPI scorecard comparing supplier performance to the agreed targets.

Part of the ASPICE explainer series

Grounded in the standard, honest about the theater: All VDA-scope process areas · MAN.3 Project Management · SPL.2 Product Release · SUP.1 Quality Assurance

Get The Blueprint. Have us implement it.

The Blueprint is our free template QMS for ASPICE. We implement it with our agentic solutions on a partner headless ALM — ACQ.4's work products and traceability generated in your tools, with a confidence score and audit trail on every artifact.or book a compliance teardown →

See Vera →