What this is
What is a supplier audit?
What is a supplier audit?
A supplier audit is a second-party audit: your organisation auditing a supplier against your requirements, a recognised standard, or both. It differs from certification, which is a third-party audit against a scheme, and it exists to answer questions certification does not, particularly whether the supplier can meet your specific specification consistently.
Do we still need to audit a certified supplier?
Usually yes, but the scope should differ. Certification confirms a scheme-recognised body found the system compliant on the days they visited. It does not confirm the supplier can meet your specification, handle your allergen profile, or trace your batch. A second-party audit of a certified supplier should skip what the certificate already covers and concentrate on what it does not.
Scope
When is a supplier audit required?
A supplier audit is one verification activity among several. Choosing it where a document review would do, or a document review where an audit is required, is the common scoping error.
Use this template when
- Approving a new supplier of a material where the hazard or commercial exposure warrants seeing the operation
- Periodic verification of an existing supplier, at a frequency set by risk and performance
- Following a significant quality failure, complaint pattern or recall involving that supplier
- Where the supplier is not certified to a recognised scheme, or is certified to a scope that excludes your material
- Where FSMA or a customer requires an onsite audit as the verification activity for a specific hazard
Do not use it for
- Certification audit, which is third party against a scheme and cannot be performed by you
- Document and certificate review, which is a lighter verification activity appropriate to lower-risk materials
- Incoming inspection and testing, which verifies the delivery rather than the system that produced it
- Supplier approval itself, which is the decision the audit informs rather than the audit
- The supplier scorecard, which tracks ongoing performance between audits
Compliance mapping
Which ISO 19011 requirements does this satisfy?
Supplier auditing sits under an auditing methodology standard, a set of scheme requirements, and, for food sold in the United States, a statutory verification obligation.
| Clause | Requirement | Where it lands |
|---|---|---|
| ISO 19011 cl.5 | Audit programme management: objectives, risks, resources, competence and programme review | Header |
| ISO 19011 cl.6 | Conducting the audit: planning, evidence collection, findings and conclusions | Sections audited |
| ISO 19011 cl.7 | Auditor competence and evaluation, including sector and process knowledge | Header |
| ISO 9001 cl.8.4.2 | Type and extent of control of external providers, based on their ability to meet requirements | Result |
| 21 CFR 117.410 | Supplier verification activities appropriate to the hazard, including onsite audit where consequences are serious | Header |
| 21 CFR 117.435 | Onsite audit conducted by a qualified auditor, with written results reviewed and retained | Result |
| GFSI BMR v2024 | Recognised schemes to include food safety culture assessment and unannounced audits at least triennially | Sections audited |
| SQF, BRCGS | Raw material and supplier approval with risk-based verification and documented approval before supply | Result |
What it does not cover
- Certification, which is third party against a scheme and cannot be substituted by your own audit.
- The supplier approval decision, which is informed by the audit and recorded separately with its own authority.
- Incoming inspection, which verifies what arrived rather than the system that produced it.
- The supplier scorecard, which measures performance continuously between audits.
- The corrective action record raised against findings, which is the supplier's document tracked by you to verified closure.
How to complete it
How to complete a supplier audit, step by step
Supplier audits are frequently well planned and poorly spent. Where the hours go determines what the audit is worth.
Certificates, scheme reports, specifications, HACCP plans and previous corrective actions can all be reviewed remotely. Spending the morning of an onsite audit reading documents converts a scarce opportunity, being physically present in the operation, into something that could have been done by email. Arrive having read, and use the day for what requires presence.
Select a finished batch from their records, or better a code from a delivery you received, and ask for full one-up one-back reconstruction with a time limit. Watch how the answer is assembled: whether it comes from a system or from three people and a spreadsheet, whether mass balance closes, and whether rework is included. It reveals more about the operation than any documented procedure.
The procedure states the reaction. The operator states the practice. Where they differ, the difference is the finding, and it will not appear in any document you were sent. This also tests culture directly, which the 2024 GFSI benchmarking requirements have now made an explicit assessment area for certification schemes.
A major from you should mean what a major means from anyone else, and the supplier should know the definition before the audit. Ungraded findings, or grading by auditor instinct, make the report unusable for comparison between suppliers and unusable for tracking a supplier's trajectory over time.
What auditors find
Most common supplier audit findings
Audit programme findings, as distinct from findings raised at suppliers, cluster around scope, competence and closure.
| Finding | Clause | What fixes it |
|---|---|---|
| Second-party audit duplicates the scope of the supplier's certification. | ISO 9001 cl.8.4.2 | Scope to what the certificate does not cover: your specification, your allergens, your traceability. |
| Auditor not competent in the supplier's sector or process. | ISO 19011 cl.7 | Match auditor competence to the process being audited; record the basis. |
| Findings not graded, or graded inconsistently between auditors. | ISO 19011 cl.6.4 | Publish grading definitions and calibrate auditors against worked examples. |
| Corrective actions accepted on a response letter with no evidence. | ISO 9001 cl.10.2 | Require evidence of the action and verify effectiveness at the next audit. |
| No traceability challenge performed. | SQF, BRCGS | Make it a standing agenda item with a batch chosen by the auditor and a time limit. |
| Audit frequency uniform rather than risk based. | 21 CFR 117.410 | Set frequency from hazard, material criticality and supplier performance history. |
| Onsite audit required by FSMA replaced with a document review without written justification. | 21 CFR 117.410 | Record the written determination where an alternative verification activity is used. |
| Audit report not reviewed by anyone with authority to act on it. | 21 CFR 117.435 | Route the report to the approver; an unreviewed audit changes nothing. |
| Previous audit findings not checked at the current audit. | ISO 19011 cl.6.3 | Open every audit with the previous findings; repeat findings are the strongest signal available. |
| Approval status not updated after an audit with major findings. | ISO 9001 cl.8.4.1 | Link audit outcome to approval status so a poor audit has a consequence. |
Case in point
Case in point: the trace that took two days
A manufacturer audited an ingredient supplier who held a current GFSI-recognised certificate with a good grade. The morning went on document review, all of which was in order. After lunch the auditor picked a batch code from a delivery note in her own bag and asked for one-up one-back within four hours.
The supplier could identify the raw material lots within an hour. The forward trace stalled: the batch had been partially reworked into two later batches, and the rework record was a handwritten book kept by the shift leader, reconciled monthly. Establishing where the product had gone took the rest of the day and a phone call the following morning.
Nothing in the certification report indicated this, because the scheme audit's traceability test had used a batch with no rework in it. The certificate was accurate. It had simply not tested the condition where the system broke.
The template
The template, field by field
The form exactly as it installs. Every field, option, score and conditional rule is editable, and the links to other templates come with it.
5 sections
- Reference
- QUA-040
- Archetype
- Audit
- Record ID
- AUD-2026-000
- Scoring
- Weighted percent
- Direction
- High is good
- Singleton
- No
- Basis
- ISO 19011, SQF 2.3
- Links
- Links Vendor; feeds Finding
- Tags
- Supplier, Audit
- Sections
- 5
- Fields
- 48
- Follow up fields
- 3
- Repeating sections
- 2
- Links out
- 3
Header
12 fieldsAudit ID*
Auto sequence. Format AUD-2026-00000.
The record's own ID. Other templates point at this value.
Status*
Drives who this goes to next.
- Planned2 pts
- In progress2 pts
- Complete3 pts
- Deferred0 pts
- Open0 pts
- Closed3 pts
- Overdue0 pts
Date*
Completed By*
Supplier*
Vendor ID*
Format VEN-0000.
Links to FDN-005 Vendor ID
Audit Type*
Announced, unannounced, desktop or follow up.
- Announced1 pt
- Unannounced3 pts
- Penetration style test4 pts
Audit Standard*
Lead Auditor*
Auditor Trained And Independent*
- Yes3 pts
- No0 pts
Site Audited*
Duration Days
Sections audited
Repeats6 fieldsSection*
Management system, HACCP, prerequisites, allergen, foreign body, traceability, site standards, personnel.
Requirements Checked*
Conformance Percent*
Evidence Sighted*
- Pass2 pts
- Partial1 pt
- Fail0 pts
- N/Aexcluded from denominator
Practice Matches Documentation*
- Yes3 pts
- Partly1 pt
- No0 pts
Maturity Level*
- 0 Absent0 pts
- 1 Ad hoc1 pt
- 2 Defined2 pts
- 3 Implemented3 pts
- 4 Measured4 pts
- 5 Embedded and improving5 pts
Findings
Repeats8 fieldsFinding Description*
Section*
Finding Grade*
- Critical0 pts
- Major1 pt
- Minor2 pts
- Observation3 pts
Evidence*
Photo
Finding ID
Links to FDN-015 Finding ID
Response Due Date*
Supplier Owner
Traceability challenge
3 fieldsTrace Exercise Performed*
Pick a batch on the day and trace it. This is the single most revealing part of a supplier audit.
- Yes3 pts
- No0 pts
Trace Time Minutes
Mass Balance Achieved
- Yes, 100 percent3 pts
- Partial1 pt
- No0 pts
Result
19 fieldsItems Assessed*
Excludes anything marked N/A.
Items Failed*
Score Percent*
Calculated on submission. High is good. N/A items leave the denominator.
Result Band*
- Pass3 pts
- Caution1 pt
- Fail0 pts
Completeness Percent*
How much of the template was actually answered. A high score on a half completed form is not a high score.
Critical Findings*
Major Findings*
Minor Findings*
Audit Outcome*
- Passed3 pts
- Passed with actions2 pts
- Conditional1 pt
- Failed0 pts
Approval Status Affected*
- No3 pts
- Conditions applied1 pt
- Suspended0 pts
Next Audit Due*
Action Required*
Raise the action record, then enter its reference here.
- No2 pts
- Yes0 pts
Priority
- High0 pts
- Medium1 pt
- Low3 pts
CAPA ID
Format CAPA-2026-00000.
Links to FDN-014 CAPA ID
Action Owner
Lead Auditor*
Signature*
Quality Manager*
Second Signature*
QUA-040 · record IDs look like AUD-2026-000 · Links Vendor; feeds Finding
Open in KnowellaRun it with agents
From a document you fill in to a programme that runs itself
The audit is a day. What fails is the scope that duplicated the certificate, the finding closed on a letter, and the repeat that nobody connected to last year.
Holds supplier approval, certification expiry and audit history together, so the audit is scoped against what the certificate already covers.

Surfaces repeat findings across consecutive audits and links complaint and rejection data to the supplier before the audit is planned.
Supplies the delivery and rejection record that lets you choose a real batch for the traceability challenge rather than accepting one offered.
Applies the same verification logic to service providers, where certification is rarer and second-party audit carries more of the load.
This template lives in KnowQuality — quality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.
Meet KnowQuality→Glossary
Supplier Audit definitions and key terms
- Second-party audit
- An audit conducted by a party with an interest in the organisation, typically a customer auditing a supplier against its own requirements.
- Third-party audit
- An audit by an independent certification body against a recognised scheme, resulting in certification.
- Qualified auditor
- Under FSMA, a person with the technical expertise from training or experience to perform the audit, whose qualification is recorded.
- Traceability challenge
- A timed exercise reconstructing one step forward and one step back from a chosen batch, testing the system rather than the procedure.
- Mass balance
- Reconciliation of input, output, waste and rework quantities, which is the arithmetic check on whether a trace is complete.
- Finding grade
- The severity classification applied to a nonconformity, meaningful only where the definitions are published and applied consistently.
- Food safety culture
- Shared values and behaviours affecting food safety, now an explicit assessment area under GFSI Benchmarking Requirements version 2024.
- Unannounced audit
- An audit with no notice beyond a general window, required at least once every three years under the 2024 benchmarking requirements.
FAQ
Frequently asked questions about supplier audit
Should we audit suppliers who already hold GFSI certification?+
Often yes, with a different scope. Certification confirms a scheme-recognised body found the system compliant when they visited. It does not confirm the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch. Scope your audit to those questions and it complements the certificate rather than repeating it.
What changed with GFSI in 2024?+
The Benchmarking Requirements version 2024, published December 2024, require all recognised certification schemes to include food safety culture assessment and unannounced audits at least once every three years. Certification programme owners had until September 2025 to seek recognition against them, and sites are seeing the changes reflected in audits from 2026.
When does FSMA require an onsite audit?+
Where a hazard requiring a supply chain control has a reasonable probability of causing serious adverse health consequences or death, the verification activity must be an onsite audit, unless there is a written determination that other activities provide adequate assurance. The written determination is the part most often missing when a document review is used instead.
How should audit frequency be set?+
From hazard severity, material criticality and the supplier's performance history rather than a uniform annual cycle. A supplier of a high-risk ingredient with a recent failure warrants more attention than a stable supplier of a low-risk material, and spending equal effort on both means under-auditing the first.
What makes a finding closed?+
Evidence that the action was taken and, at the next audit, evidence that it held. A response letter describing intent is not closure. Repeat findings across consecutive audits are the clearest signal available that closure is nominal, and they should affect approval status rather than simply being recorded again.
Who should conduct the audit?+
Someone competent in the supplier's sector and process, which is a higher bar than being competent in auditing. Under FSMA the auditor must be qualified, with technical expertise from training or experience. An experienced auditor without process knowledge will verify that documents exist and miss what is happening on the line.
Keep going
Related templates and programmes
Industries this is written for
Programmes this belongs to
Used together in Supplier Quality Assurance
Modern Slavery and Labour Standards Assessment
Assesses the site and its labour supply chain for forced labour, debt bondage, withheld documents and unlawful deductions
Transport Provider Assessment
Assesses a haulier for licensing, driver management, vehicle standards, temperature capability and load security
Supplier Environmental Assessment
Assesses a supplier's environmental performance and certifications
Vendor and Contractor Register
Holds every supplier, contractor and service provider you work with, including their status and approval level
Material Rejection Report
Rejects incoming material that fails inspection
Supplier Approval Record
Records the decision to approve a new supplier, with the evidence behind it
More in Suppliers
Supplier Approval Record
Records the decision to approve a new supplier, with the evidence behind it
Supplier Questionnaire
Collects information about a supplier's systems, certifications and controls
Supplier Scorecard
Scores a supplier on quality, delivery, responsiveness and cost over a period
Supplier Corrective Request
Asks a supplier to investigate and fix a problem with their material or service
Material Specification Record
Holds the agreed specification for each material you buy, including tolerances and test methods
Certificate of Analysis Review
Checks the certificate supplied with a material against the agreed specification

Written and reviewed by
Siddarth Singh
Founder & Chief Executive Officer, Knowella
Certified Safety Professional and industrial and systems engineer with more than a decade inside food supply chain, freight and manufacturing operations. This page was written against the current text of the standards it cites, not against secondary summaries of them.
- Certified Safety Professional (CSP), Board of Certified Safety Professionals
- MBA, University of Chicago Booth School of Business
- MS and BS, The Ohio State University, Industrial and Systems Engineering
- Six Sigma Black Belt
Sources and last review. Reviewed 16 August 2026 against:
- ISO 19011:2018, guidelines for auditing management systems
- 21 CFR 117 Subpart G, supply chain program, FDA
- GFSI Benchmarking Requirements version 2024
- ISO 9001:2015 clause 8.4, control of externally provided processes, products and services
- SQF Edition 9 and BRCGS Food Safety Issue 9, supplier approval requirements
This page is general guidance, not legal advice. Confirm requirements with your jurisdiction’s regulator.