Knowella

Supplier Audit Template

A supplier audit is the one day a year you see the operation rather than the paperwork, and most of it gets spent in a meeting room reviewing documents you could have been sent. The findings that matter come from the floor, from asking a line operator what they do when a check fails, and from a traceability challenge run against a batch you chose rather than one they offered.

KnowQualityAuditQUA-040Pinned in navigation48 fields across 5 sectionsFull researchSee the form

Reviewed by Siddarth SinghCSPLast reviewed 16 August 2026

Basis
ISO 19011, SQF 2.3
Workspace
KnowQuality
Form type
Audit
Type
Second party, against your requirement
Best evidence
Floor observation and traceability challenge

The short version

  • Certification and second-party audit answer different questions. Auditing a certified supplier against the same scheme duplicates work and finds nothing new.
  • GFSI Benchmarking Requirements version 2024, published December 2024, require all recognised schemes to include food safety culture assessment and unannounced audits at least once every three years. Sites begin seeing this in audits from 2026.
  • A traceability challenge is the single highest-yield hour of any supplier audit. Choose the batch yourself, set a time limit, and watch how the answer is assembled rather than accepting the answer.
  • Findings should be graded consistently against a published scheme, so that a major means the same thing to you, to the supplier and to the next auditor.
  • Under FSMA supply chain requirements, the verification activity must be appropriate to the hazard. An onsite audit is required for a hazard with a reasonable probability of serious adverse health consequences, unless a written determination supports otherwise.
  • Audit closure is the part that fails. A supplier response letter is not a corrective action, and effectiveness is verified at the next audit or not at all.

What this is

What is a supplier audit?

What is a supplier audit?

A supplier audit is a second-party audit: your organisation auditing a supplier against your requirements, a recognised standard, or both. It differs from certification, which is a third-party audit against a scheme, and it exists to answer questions certification does not, particularly whether the supplier can meet your specific specification consistently.

Do we still need to audit a certified supplier?

Usually yes, but the scope should differ. Certification confirms a scheme-recognised body found the system compliant on the days they visited. It does not confirm the supplier can meet your specification, handle your allergen profile, or trace your batch. A second-party audit of a certified supplier should skip what the certificate already covers and concentrate on what it does not.

Scope

When is a supplier audit required?

A supplier audit is one verification activity among several. Choosing it where a document review would do, or a document review where an audit is required, is the common scoping error.

Use this template when

  • Approving a new supplier of a material where the hazard or commercial exposure warrants seeing the operation
  • Periodic verification of an existing supplier, at a frequency set by risk and performance
  • Following a significant quality failure, complaint pattern or recall involving that supplier
  • Where the supplier is not certified to a recognised scheme, or is certified to a scope that excludes your material
  • Where FSMA or a customer requires an onsite audit as the verification activity for a specific hazard

Do not use it for

  • Certification audit, which is third party against a scheme and cannot be performed by you
  • Document and certificate review, which is a lighter verification activity appropriate to lower-risk materials
  • Incoming inspection and testing, which verifies the delivery rather than the system that produced it
  • Supplier approval itself, which is the decision the audit informs rather than the audit
  • The supplier scorecard, which tracks ongoing performance between audits

Compliance mapping

Which ISO 19011 requirements does this satisfy?

Supplier auditing sits under an auditing methodology standard, a set of scheme requirements, and, for food sold in the United States, a statutory verification obligation.

ClauseRequirementWhere it lands
ISO 19011 cl.5Audit programme management: objectives, risks, resources, competence and programme reviewHeader
ISO 19011 cl.6Conducting the audit: planning, evidence collection, findings and conclusionsSections audited
ISO 19011 cl.7Auditor competence and evaluation, including sector and process knowledgeHeader
ISO 9001 cl.8.4.2Type and extent of control of external providers, based on their ability to meet requirementsResult
21 CFR 117.410Supplier verification activities appropriate to the hazard, including onsite audit where consequences are seriousHeader
21 CFR 117.435Onsite audit conducted by a qualified auditor, with written results reviewed and retainedResult
GFSI BMR v2024Recognised schemes to include food safety culture assessment and unannounced audits at least trienniallySections audited
SQF, BRCGSRaw material and supplier approval with risk-based verification and documented approval before supplyResult

What it does not cover

  • Certification, which is third party against a scheme and cannot be substituted by your own audit.
  • The supplier approval decision, which is informed by the audit and recorded separately with its own authority.
  • Incoming inspection, which verifies what arrived rather than the system that produced it.
  • The supplier scorecard, which measures performance continuously between audits.
  • The corrective action record raised against findings, which is the supplier's document tracked by you to verified closure.

How to complete it

How to complete a supplier audit, step by step

Supplier audits are frequently well planned and poorly spent. Where the hours go determines what the audit is worth.

Review documents before you arrive, not on the day

Certificates, scheme reports, specifications, HACCP plans and previous corrective actions can all be reviewed remotely. Spending the morning of an onsite audit reading documents converts a scarce opportunity, being physically present in the operation, into something that could have been done by email. Arrive having read, and use the day for what requires presence.

Run a traceability challenge on a batch you choose

Select a finished batch from their records, or better a code from a delivery you received, and ask for full one-up one-back reconstruction with a time limit. Watch how the answer is assembled: whether it comes from a system or from three people and a spreadsheet, whether mass balance closes, and whether rework is included. It reveals more about the operation than any documented procedure.

Ask operators, not managers, what happens when a check fails

The procedure states the reaction. The operator states the practice. Where they differ, the difference is the finding, and it will not appear in any document you were sent. This also tests culture directly, which the 2024 GFSI benchmarking requirements have now made an explicit assessment area for certification schemes.

Grade findings against a published scheme

A major from you should mean what a major means from anyone else, and the supplier should know the definition before the audit. Ungraded findings, or grading by auditor instinct, make the report unusable for comparison between suppliers and unusable for tracking a supplier's trajectory over time.

What auditors find

Most common supplier audit findings

Audit programme findings, as distinct from findings raised at suppliers, cluster around scope, competence and closure.

FindingClauseWhat fixes it
Second-party audit duplicates the scope of the supplier's certification.ISO 9001 cl.8.4.2Scope to what the certificate does not cover: your specification, your allergens, your traceability.
Auditor not competent in the supplier's sector or process.ISO 19011 cl.7Match auditor competence to the process being audited; record the basis.
Findings not graded, or graded inconsistently between auditors.ISO 19011 cl.6.4Publish grading definitions and calibrate auditors against worked examples.
Corrective actions accepted on a response letter with no evidence.ISO 9001 cl.10.2Require evidence of the action and verify effectiveness at the next audit.
No traceability challenge performed.SQF, BRCGSMake it a standing agenda item with a batch chosen by the auditor and a time limit.
Audit frequency uniform rather than risk based.21 CFR 117.410Set frequency from hazard, material criticality and supplier performance history.
Onsite audit required by FSMA replaced with a document review without written justification.21 CFR 117.410Record the written determination where an alternative verification activity is used.
Audit report not reviewed by anyone with authority to act on it.21 CFR 117.435Route the report to the approver; an unreviewed audit changes nothing.
Previous audit findings not checked at the current audit.ISO 19011 cl.6.3Open every audit with the previous findings; repeat findings are the strongest signal available.
Approval status not updated after an audit with major findings.ISO 9001 cl.8.4.1Link audit outcome to approval status so a poor audit has a consequence.

Case in point

Case in point: the trace that took two days

A manufacturer audited an ingredient supplier who held a current GFSI-recognised certificate with a good grade. The morning went on document review, all of which was in order. After lunch the auditor picked a batch code from a delivery note in her own bag and asked for one-up one-back within four hours.

The supplier could identify the raw material lots within an hour. The forward trace stalled: the batch had been partially reworked into two later batches, and the rework record was a handwritten book kept by the shift leader, reconciled monthly. Establishing where the product had gone took the rest of the day and a phone call the following morning.

Nothing in the certification report indicated this, because the scheme audit's traceability test had used a batch with no rework in it. The certificate was accurate. It had simply not tested the condition where the system broke.

The template

The template, field by field

The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.

48fields
5 sections
Reference
QUA-040
Archetype
Audit
Record ID
AUD-2026-000
Scoring
Weighted percent
Direction
High is good
Singleton
No
Basis
ISO 19011, SQF 2.3
Links
Links Vendor; feeds Finding
Tags
Supplier, Audit
Sections
5
Fields
48
Follow up fields
3
Repeating sections
2
Links out
3
Field typesOwn ID, generated on saveCase thread and parentPick list from a registryLinked to another templateFollow up, dashed outlineScored

Header

12 fields
Text

Audit ID*

Generated on save

Auto sequence. Format AUD-2026-00000.

The record's own ID. Other templates point at this value.

Single Choice

Status*

Scored

Drives who this goes to next.

  • Planned2 pts
  • In progress2 pts
  • Complete3 pts
  • Deferred0 pts
  • Open0 pts
  • Closed3 pts
  • Overdue0 pts
Date & Time

Date*

Users

Completed By*

Pick List

Supplier*

From FDN-005 Vendor NameFilter: Status is Approved
Text

Vendor ID*

Linked

Format VEN-0000.

Links to FDN-005 Vendor ID

Single Choice

Audit Type*

Scored

Announced, unannounced, desktop or follow up.

  • Announced1 pt
  • Unannounced3 pts
  • Penetration style test4 pts
Single Choice

Audit Standard*

BRCGSSQFFSSC 22000Customer specificInternal standard
Users

Lead Auditor*

Single Choice

Auditor Trained And Independent*

Scored
  • Yes3 pts
  • No0 pts
Text

Site Audited*

Numeric Answer

Duration Days

Optional

Sections audited

Repeats6 fields
Single Choice

Section*

Management system, HACCP, prerequisites, allergen, foreign body, traceability, site standards, personnel.

Management systemHACCPPrerequisitesAllergenForeign bodyTraceabilitySite standardsPersonnel
Numeric Answer

Requirements Checked*

Numeric Answer

Conformance Percent*

Scored
Single Choice

Evidence Sighted*

Scored
  • Pass2 pts
  • Partial1 pt
  • Fail0 pts
  • N/Aexcluded from denominator
Single Choice

Practice Matches Documentation*

Scored
  • Yes3 pts
  • Partly1 pt
  • No0 pts
Single Choice

Maturity Level*

Scored
  • 0 Absent0 pts
  • 1 Ad hoc1 pt
  • 2 Defined2 pts
  • 3 Implemented3 pts
  • 4 Measured4 pts
  • 5 Embedded and improving5 pts

Findings

Repeats8 fields
Text

Finding Description*

Single Choice

Section*

Management systemHACCPPrerequisitesAllergenForeign bodyTraceabilitySite standardsPersonnel
Single Choice

Finding Grade*

Scored
  • Critical0 pts
  • Major1 pt
  • Minor2 pts
  • Observation3 pts
Text

Evidence*

File Upload

Photo

Optional
Text

Finding ID

OptionalLinked

Links to FDN-015 Finding ID

Date & Time

Response Due Date*

Text

Supplier Owner

Optional

Traceability challenge

3 fields
Single Choice

Trace Exercise Performed*

Scored

Pick a batch on the day and trace it. This is the single most revealing part of a supplier audit.

  • Yes3 pts
  • No0 pts
Numeric Answer

Trace Time Minutes

OptionalScored
Single Choice

Mass Balance Achieved

OptionalScored
  • Yes, 100 percent3 pts
  • Partial1 pt
  • No0 pts

Result

19 fields
Numeric Answer

Items Assessed*

Excludes anything marked N/A.

Numeric Answer

Items Failed*

Numeric Answer

Score Percent*

Scored

Calculated on submission. High is good. N/A items leave the denominator.

Single Choice

Result Band*

Scored
  • Pass3 pts
  • Caution1 pt
  • Fail0 pts
Numeric Answer

Completeness Percent*

How much of the template was actually answered. A high score on a half completed form is not a high score.

Numeric Answer

Critical Findings*

Scored
Numeric Answer

Major Findings*

Scored
Numeric Answer

Minor Findings*

Single Choice

Audit Outcome*

Scored
  • Passed3 pts
  • Passed with actions2 pts
  • Conditional1 pt
  • Failed0 pts
Single Choice

Approval Status Affected*

Scored
  • No3 pts
  • Conditions applied1 pt
  • Suspended0 pts
Date & Time

Next Audit Due*

Single Choice

Action Required*

Scored

Raise the action record, then enter its reference here.

  • No2 pts
  • Yes0 pts
Single Choice

Priority

OptionalScoredShows if Action Required equals Yes
  • High0 pts
  • Medium1 pt
  • Low3 pts
Text

CAPA ID

OptionalLinkedShows if Action Required equals Yes

Format CAPA-2026-00000.

Links to FDN-014 CAPA ID

Users

Action Owner

OptionalShows if Action Required equals Yes
Users

Lead Auditor*

Signature

Signature*

Users

Quality Manager*

Signature

Second Signature*

QUA-040 · record IDs look like AUD-2026-000 · Links Vendor; feeds Finding

Open in Knowella

Run it with agents

From a document you fill in to a programme that runs itself

The audit is a day. What fails is the scope that duplicated the certificate, the finding closed on a letter, and the repeat that nobody connected to last year.

KnowQuality

Holds supplier approval, certification expiry and audit history together, so the audit is scoped against what the certificate already covers.

Ella
Ella

Surfaces repeat findings across consecutive audits and links complaint and rejection data to the supplier before the audit is planned.

KnowLogistics

Supplies the delivery and rejection record that lets you choose a real batch for the traceability challenge rather than accepting one offered.

KnowContractor

Applies the same verification logic to service providers, where certification is rarer and second-party audit carries more of the load.

This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.

Meet KnowQuality→

Glossary

Supplier Audit definitions and key terms

Second-party audit
An audit conducted by a party with an interest in the organisation, typically a customer auditing a supplier against its own requirements.
Third-party audit
An audit by an independent certification body against a recognised scheme, resulting in certification.
Qualified auditor
Under FSMA, a person with the technical expertise from training or experience to perform the audit, whose qualification is recorded.
Traceability challenge
A timed exercise reconstructing one step forward and one step back from a chosen batch, testing the system rather than the procedure.
Mass balance
Reconciliation of input, output, waste and rework quantities, which is the arithmetic check on whether a trace is complete.
Finding grade
The severity classification applied to a nonconformity, meaningful only where the definitions are published and applied consistently.
Food safety culture
Shared values and behaviours affecting food safety, now an explicit assessment area under GFSI Benchmarking Requirements version 2024.
Unannounced audit
An audit with no notice beyond a general window, required at least once every three years under the 2024 benchmarking requirements.

FAQ

Frequently asked questions about supplier audit

Should we audit suppliers who already hold GFSI certification?+

Often yes, with a different scope. Certification confirms a scheme-recognised body found the system compliant when they visited. It does not confirm the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch. Scope your audit to those questions and it complements the certificate rather than repeating it.

What changed with GFSI in 2024?+

The Benchmarking Requirements version 2024, published December 2024, require all recognised certification schemes to include food safety culture assessment and unannounced audits at least once every three years. Certification programme owners had until September 2025 to seek recognition against them, and sites are seeing the changes reflected in audits from 2026.

When does FSMA require an onsite audit?+

Where a hazard requiring a supply chain control has a reasonable probability of causing serious adverse health consequences or death, the verification activity must be an onsite audit, unless there is a written determination that other activities provide adequate assurance. The written determination is the part most often missing when a document review is used instead.

How should audit frequency be set?+

From hazard severity, material criticality and the supplier's performance history rather than a uniform annual cycle. A supplier of a high-risk ingredient with a recent failure warrants more attention than a stable supplier of a low-risk material, and spending equal effort on both means under-auditing the first.

What makes a finding closed?+

Evidence that the action was taken and, at the next audit, evidence that it held. A response letter describing intent is not closure. Repeat findings across consecutive audits are the clearest signal available that closure is nominal, and they should affect approval status rather than simply being recorded again.

Who should conduct the audit?+

Someone competent in the supplier's sector and process, which is a higher bar than being competent in auditing. Under FSMA the auditor must be qualified, with technical expertise from training or experience. An experienced auditor without process knowledge will verify that documents exist and miss what is happening on the line.

Keep going

Related templates and programmes

Siddarth Singh

Written and reviewed by

Siddarth Singh

Founder & Chief Executive Officer, Knowella

Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.

  • Certified Safety Professional (CSP), Board of Certified Safety Professionals
  • MBA, University of Chicago Booth School of Business
  • MS and BS, The Ohio State University, Industrial and Systems Engineering
  • Six Sigma Black Belt
Verify with BCSP →

Sources and last review. Reviewed 16 August 2026 against:

  • ISO 19011:2018, guidelines for auditing management systems
  • 21 CFR 117 Subpart G, supply chain program, FDA
  • GFSI Benchmarking Requirements version 2024
  • ISO 9001:2015 clause 8.4, control of externally provided processes, products and services
  • SQF Edition 9 and BRCGS Food Safety Issue 9, supplier approval requirements

This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.