Summary
In short
- Certification and second-party audit answer different questions. Auditing a certified supplier against the same scheme duplicates work and finds nothing new.
- GFSI Benchmarking Requirements version 2024, published December 2024, require all recognised schemes to include food safety culture assessment and unannounced audits at least once every three years. Sites begin seeing this in audits from 2026.
- A traceability challenge is the single highest-yield hour of any supplier audit. Choose the batch yourself, set a time limit, and watch how the answer is assembled rather than accepting the answer.
- Findings should be graded consistently against a published scheme, so that a major means the same thing to you, to the supplier and to the next auditor.
- Under FSMA supply chain requirements, the verification activity must be appropriate to the hazard. An onsite audit is required for a hazard with a reasonable probability of serious adverse health consequences, unless a written determination supports otherwise.
- Audit closure is the part that fails. A supplier response letter is not a corrective action, and effectiveness is verified at the next audit or not at all.
What it is
What it is
What is a supplier audit?
A supplier audit is a second-party audit: your organisation auditing a supplier against your requirements, a recognised standard, or both. It differs from certification, which is a third-party audit against a scheme, and it exists to answer questions certification does not, particularly whether the supplier can meet your specific specification consistently.
Do we still need to audit a certified supplier?
Usually yes, but the scope should differ. Certification confirms a scheme-recognised body found the system compliant on the days they visited. It does not confirm the supplier can meet your specification, handle your allergen profile, or trace your batch. A second-party audit of a certified supplier should skip what the certificate already covers and concentrate on what it does not.
When to use it
When to use it, and when not to
A supplier audit is one verification activity among several. Choosing it where a document review would do, or a document review where an audit is required, is the common scoping error.
Use it for
- Approving a new supplier of a material where the hazard or commercial exposure warrants seeing the operation
- Periodic verification of an existing supplier, at a frequency set by risk and performance
- Following a significant quality failure, complaint pattern or recall involving that supplier
- Where the supplier is not certified to a recognised scheme, or is certified to a scope that excludes your material
- Where FSMA or a customer requires an onsite audit as the verification activity for a specific hazard
Not for
- Certification audit, which is third party against a scheme and cannot be performed by you
- Document and certificate review, which is a lighter verification activity appropriate to lower-risk materials
- Incoming inspection and testing, which verifies the delivery rather than the system that produced it
- Supplier approval itself, which is the decision the audit informs rather than the audit
- The supplier scorecard, which tracks ongoing performance between audits
Standards
What it is built against
Supplier auditing sits under an auditing methodology standard, a set of scheme requirements, and, for food sold in the United States, a statutory verification obligation.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.5 | Audit programme management: objectives, risks, resources, competence and programme review | Header |
| ISO 19011 cl.6 | Conducting the audit: planning, evidence collection, findings and conclusions | Sections audited |
| ISO 19011 cl.7 | Auditor competence and evaluation, including sector and process knowledge | Header |
| ISO 9001 cl.8.4.2 | Type and extent of control of external providers, based on their ability to meet requirements | Result |
| 21 CFR 117.410 | Supplier verification activities appropriate to the hazard, including onsite audit where consequences are serious | Header |
| 21 CFR 117.435 | Onsite audit conducted by a qualified auditor, with written results reviewed and retained | Result |
| GFSI BMR v2024 | Recognised schemes to include food safety culture assessment and unannounced audits at least triennially | Sections audited |
| SQF, BRCGS | Raw material and supplier approval with risk-based verification and documented approval before supply | Result |
What it does not cover
- Certification, which is third party against a scheme and cannot be substituted by your own audit.
- The supplier approval decision, which is informed by the audit and recorded separately with its own authority.
- Incoming inspection, which verifies what arrived rather than the system that produced it.
- The supplier scorecard, which measures performance continuously between audits.
- The corrective action record raised against findings, which is the supplier's document tracked by you to verified closure.
Filling it in
Filling it in well
Supplier audits are frequently well planned and poorly spent. Where the hours go determines what the audit is worth.
Certificates, scheme reports, specifications, HACCP plans and previous corrective actions can all be reviewed remotely. Spending the morning of an onsite audit reading documents converts a scarce opportunity, being physically present in the operation, into something that could have been done by email. Arrive having read, and use the day for what requires presence.
Select a finished batch from their records, or better a code from a delivery you received, and ask for full one-up one-back reconstruction with a time limit. Watch how the answer is assembled: whether it comes from a system or from three people and a spreadsheet, whether mass balance closes, and whether rework is included. It reveals more about the operation than any documented procedure.
The procedure states the reaction. The operator states the practice. Where they differ, the difference is the finding, and it will not appear in any document you were sent. This also tests culture directly, which the 2024 GFSI benchmarking requirements have now made an explicit assessment area for certification schemes.
A major from you should mean what a major means from anyone else, and the supplier should know the definition before the audit. Ungraded findings, or grading by auditor instinct, make the report unusable for comparison between suppliers and unusable for tracking a supplier's trajectory over time.
Audit findings
Common audit findings
Audit programme findings, as distinct from findings raised at suppliers, cluster around scope, competence and closure.
| Finding | Clause | What fixes it |
|---|---|---|
| Second-party audit duplicates the scope of the supplier's certification. | ISO 9001 cl.8.4.2 | Scope to what the certificate does not cover: your specification, your allergens, your traceability. |
| Auditor not competent in the supplier's sector or process. | ISO 19011 cl.7 | Match auditor competence to the process being audited; record the basis. |
| Findings not graded, or graded inconsistently between auditors. | ISO 19011 cl.6.4 | Publish grading definitions and calibrate auditors against worked examples. |
| Corrective actions accepted on a response letter with no evidence. | ISO 9001 cl.10.2 | Require evidence of the action and verify effectiveness at the next audit. |
| No traceability challenge performed. | SQF, BRCGS | Make it a standing agenda item with a batch chosen by the auditor and a time limit. |
| Audit frequency uniform rather than risk based. | 21 CFR 117.410 | Set frequency from hazard, material criticality and supplier performance history. |
| Onsite audit required by FSMA replaced with a document review without written justification. | 21 CFR 117.410 | Record the written determination where an alternative verification activity is used. |
| Audit report not reviewed by anyone with authority to act on it. | 21 CFR 117.435 | Route the report to the approver; an unreviewed audit changes nothing. |
| Previous audit findings not checked at the current audit. | ISO 19011 cl.6.3 | Open every audit with the previous findings; repeat findings are the strongest signal available. |
| Approval status not updated after an audit with major findings. | ISO 9001 cl.8.4.1 | Link audit outcome to approval status so a poor audit has a consequence. |
Worked case
Case in point: the trace that took two days
A manufacturer audited an ingredient supplier who held a current GFSI-recognised certificate with a good grade. The morning went on document review, all of which was in order. After lunch the auditor picked a batch code from a delivery note in her own bag and asked for one-up one-back within four hours.
The supplier could identify the raw material lots within an hour. The forward trace stalled: the batch had been partially reworked into two later batches, and the rework record was a handwritten book kept by the shift leader, reconciled monthly. Establishing where the product had gone took the rest of the day and a phone call the following morning.
Nothing in the certification report indicated this, because the scheme audit's traceability test had used a batch with no rework in it. The certificate was accurate. It had simply not tested the condition where the system broke.
Definitions
Definitions and key terms
- Second-party audit
- An audit conducted by a party with an interest in the organisation, typically a customer auditing a supplier against its own requirements.
- Third-party audit
- An audit by an independent certification body against a recognised scheme, resulting in certification.
- Qualified auditor
- Under FSMA, a person with the technical expertise from training or experience to perform the audit, whose qualification is recorded.
- Traceability challenge
- A timed exercise reconstructing one step forward and one step back from a chosen batch, testing the system rather than the procedure.
- Mass balance
- Reconciliation of input, output, waste and rework quantities, which is the arithmetic check on whether a trace is complete.
- Finding grade
- The severity classification applied to a nonconformity, meaningful only where the definitions are published and applied consistently.
- Food safety culture
- Shared values and behaviours affecting food safety, now an explicit assessment area under GFSI Benchmarking Requirements version 2024.
- Unannounced audit
- An audit with no notice beyond a general window, required at least once every three years under the 2024 benchmarking requirements.
FAQ
Frequently asked questions
Should we audit suppliers who already hold GFSI certification?+
Often yes, with a different scope. Certification confirms a scheme-recognised body found the system compliant when they visited. It does not confirm the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch. Scope your audit to those questions and it complements the certificate rather than repeating it.
What changed with GFSI in 2024?+
The Benchmarking Requirements version 2024, published December 2024, require all recognised certification schemes to include food safety culture assessment and unannounced audits at least once every three years. Certification programme owners had until September 2025 to seek recognition against them, and sites are seeing the changes reflected in audits from 2026.
When does FSMA require an onsite audit?+
Where a hazard requiring a supply chain control has a reasonable probability of causing serious adverse health consequences or death, the verification activity must be an onsite audit, unless there is a written determination that other activities provide adequate assurance. The written determination is the part most often missing when a document review is used instead.
How should audit frequency be set?+
From hazard severity, material criticality and the supplier's performance history rather than a uniform annual cycle. A supplier of a high-risk ingredient with a recent failure warrants more attention than a stable supplier of a low-risk material, and spending equal effort on both means under-auditing the first.
What makes a finding closed?+
Evidence that the action was taken and, at the next audit, evidence that it held. A response letter describing intent is not closure. Repeat findings across consecutive audits are the clearest signal available that closure is nominal, and they should affect approval status rather than simply being recorded again.
Who should conduct the audit?+
Someone competent in the supplier's sector and process, which is a higher bar than being competent in auditing. Under FSMA the auditor must be qualified, with technical expertise from training or experience. An experienced auditor without process knowledge will verify that documents exist and miss what is happening on the line.
The agents
What the agents do with it
The audit is a day. What fails is the scope that duplicated the certificate, the finding closed on a letter, and the repeat that nobody connected to last year.
Holds supplier approval, certification expiry and audit history together, so the audit is scoped against what the certificate already covers.
Surfaces repeat findings across consecutive audits and links complaint and rejection data to the supplier before the audit is planned.
Supplies the delivery and rejection record that lets you choose a real batch for the traceability challenge rather than accepting one offered.
Applies the same verification logic to service providers, where certification is rarer and second-party audit carries more of the load.
This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.
Sources
Sources
- ISO 19011:2018, guidelines for auditing management systems
- 21 CFR 117 Subpart G, supply chain program, FDA
- GFSI Benchmarking Requirements version 2024
- ISO 9001:2015 clause 8.4, control of externally provided processes, products and services
- SQF Edition 9 and BRCGS Food Safety Issue 9, supplier approval requirements