Knowella

Supplier Audit Template

A supplier audit is the one day a year you see the operation rather than the paperwork, and most of it gets spent in a meeting room reviewing documents you could have been sent. The findings that matter come from the floor, from asking a line operator what they do when a check fails, and from a traceability challenge run against a batch you chose rather than one they offered.

KnowQualityAuditQUA-040Pinned in navigationFull guide
Type
Second party, against your requirement
Best evidence
Floor observation and traceability challenge

Summary

In short

  • Certification and second-party audit answer different questions. Auditing a certified supplier against the same scheme duplicates work and finds nothing new.
  • GFSI Benchmarking Requirements version 2024, published December 2024, require all recognised schemes to include food safety culture assessment and unannounced audits at least once every three years. Sites begin seeing this in audits from 2026.
  • A traceability challenge is the single highest-yield hour of any supplier audit. Choose the batch yourself, set a time limit, and watch how the answer is assembled rather than accepting the answer.
  • Findings should be graded consistently against a published scheme, so that a major means the same thing to you, to the supplier and to the next auditor.
  • Under FSMA supply chain requirements, the verification activity must be appropriate to the hazard. An onsite audit is required for a hazard with a reasonable probability of serious adverse health consequences, unless a written determination supports otherwise.
  • Audit closure is the part that fails. A supplier response letter is not a corrective action, and effectiveness is verified at the next audit or not at all.

What it is

What it is

What is a supplier audit?

A supplier audit is a second-party audit: your organisation auditing a supplier against your requirements, a recognised standard, or both. It differs from certification, which is a third-party audit against a scheme, and it exists to answer questions certification does not, particularly whether the supplier can meet your specific specification consistently.

Do we still need to audit a certified supplier?

Usually yes, but the scope should differ. Certification confirms a scheme-recognised body found the system compliant on the days they visited. It does not confirm the supplier can meet your specification, handle your allergen profile, or trace your batch. A second-party audit of a certified supplier should skip what the certificate already covers and concentrate on what it does not.

When to use it

When to use it, and when not to

A supplier audit is one verification activity among several. Choosing it where a document review would do, or a document review where an audit is required, is the common scoping error.

Use it for

  • Approving a new supplier of a material where the hazard or commercial exposure warrants seeing the operation
  • Periodic verification of an existing supplier, at a frequency set by risk and performance
  • Following a significant quality failure, complaint pattern or recall involving that supplier
  • Where the supplier is not certified to a recognised scheme, or is certified to a scope that excludes your material
  • Where FSMA or a customer requires an onsite audit as the verification activity for a specific hazard

Not for

  • Certification audit, which is third party against a scheme and cannot be performed by you
  • Document and certificate review, which is a lighter verification activity appropriate to lower-risk materials
  • Incoming inspection and testing, which verifies the delivery rather than the system that produced it
  • Supplier approval itself, which is the decision the audit informs rather than the audit
  • The supplier scorecard, which tracks ongoing performance between audits

Standards

What it is built against

Supplier auditing sits under an auditing methodology standard, a set of scheme requirements, and, for food sold in the United States, a statutory verification obligation.

ClauseRequirementWhere it lands
ISO 19011 cl.5Audit programme management: objectives, risks, resources, competence and programme reviewHeader
ISO 19011 cl.6Conducting the audit: planning, evidence collection, findings and conclusionsSections audited
ISO 19011 cl.7Auditor competence and evaluation, including sector and process knowledgeHeader
ISO 9001 cl.8.4.2Type and extent of control of external providers, based on their ability to meet requirementsResult
21 CFR 117.410Supplier verification activities appropriate to the hazard, including onsite audit where consequences are seriousHeader
21 CFR 117.435Onsite audit conducted by a qualified auditor, with written results reviewed and retainedResult
GFSI BMR v2024Recognised schemes to include food safety culture assessment and unannounced audits at least trienniallySections audited
SQF, BRCGSRaw material and supplier approval with risk-based verification and documented approval before supplyResult

What it does not cover

  • Certification, which is third party against a scheme and cannot be substituted by your own audit.
  • The supplier approval decision, which is informed by the audit and recorded separately with its own authority.
  • Incoming inspection, which verifies what arrived rather than the system that produced it.
  • The supplier scorecard, which measures performance continuously between audits.
  • The corrective action record raised against findings, which is the supplier's document tracked by you to verified closure.

Filling it in

Filling it in well

Supplier audits are frequently well planned and poorly spent. Where the hours go determines what the audit is worth.

Review documents before you arrive, not on the day

Certificates, scheme reports, specifications, HACCP plans and previous corrective actions can all be reviewed remotely. Spending the morning of an onsite audit reading documents converts a scarce opportunity, being physically present in the operation, into something that could have been done by email. Arrive having read, and use the day for what requires presence.

Run a traceability challenge on a batch you choose

Select a finished batch from their records, or better a code from a delivery you received, and ask for full one-up one-back reconstruction with a time limit. Watch how the answer is assembled: whether it comes from a system or from three people and a spreadsheet, whether mass balance closes, and whether rework is included. It reveals more about the operation than any documented procedure.

Ask operators, not managers, what happens when a check fails

The procedure states the reaction. The operator states the practice. Where they differ, the difference is the finding, and it will not appear in any document you were sent. This also tests culture directly, which the 2024 GFSI benchmarking requirements have now made an explicit assessment area for certification schemes.

Grade findings against a published scheme

A major from you should mean what a major means from anyone else, and the supplier should know the definition before the audit. Ungraded findings, or grading by auditor instinct, make the report unusable for comparison between suppliers and unusable for tracking a supplier's trajectory over time.

Audit findings

Common audit findings

Audit programme findings, as distinct from findings raised at suppliers, cluster around scope, competence and closure.

FindingClauseWhat fixes it
Second-party audit duplicates the scope of the supplier's certification.ISO 9001 cl.8.4.2Scope to what the certificate does not cover: your specification, your allergens, your traceability.
Auditor not competent in the supplier's sector or process.ISO 19011 cl.7Match auditor competence to the process being audited; record the basis.
Findings not graded, or graded inconsistently between auditors.ISO 19011 cl.6.4Publish grading definitions and calibrate auditors against worked examples.
Corrective actions accepted on a response letter with no evidence.ISO 9001 cl.10.2Require evidence of the action and verify effectiveness at the next audit.
No traceability challenge performed.SQF, BRCGSMake it a standing agenda item with a batch chosen by the auditor and a time limit.
Audit frequency uniform rather than risk based.21 CFR 117.410Set frequency from hazard, material criticality and supplier performance history.
Onsite audit required by FSMA replaced with a document review without written justification.21 CFR 117.410Record the written determination where an alternative verification activity is used.
Audit report not reviewed by anyone with authority to act on it.21 CFR 117.435Route the report to the approver; an unreviewed audit changes nothing.
Previous audit findings not checked at the current audit.ISO 19011 cl.6.3Open every audit with the previous findings; repeat findings are the strongest signal available.
Approval status not updated after an audit with major findings.ISO 9001 cl.8.4.1Link audit outcome to approval status so a poor audit has a consequence.

Worked case

Case in point: the trace that took two days

A manufacturer audited an ingredient supplier who held a current GFSI-recognised certificate with a good grade. The morning went on document review, all of which was in order. After lunch the auditor picked a batch code from a delivery note in her own bag and asked for one-up one-back within four hours.

The supplier could identify the raw material lots within an hour. The forward trace stalled: the batch had been partially reworked into two later batches, and the rework record was a handwritten book kept by the shift leader, reconciled monthly. Establishing where the product had gone took the rest of the day and a phone call the following morning.

Nothing in the certification report indicated this, because the scheme audit's traceability test had used a batch with no rework in it. The certificate was accurate. It had simply not tested the condition where the system broke.

Definitions

Definitions and key terms

Second-party audit
An audit conducted by a party with an interest in the organisation, typically a customer auditing a supplier against its own requirements.
Third-party audit
An audit by an independent certification body against a recognised scheme, resulting in certification.
Qualified auditor
Under FSMA, a person with the technical expertise from training or experience to perform the audit, whose qualification is recorded.
Traceability challenge
A timed exercise reconstructing one step forward and one step back from a chosen batch, testing the system rather than the procedure.
Mass balance
Reconciliation of input, output, waste and rework quantities, which is the arithmetic check on whether a trace is complete.
Finding grade
The severity classification applied to a nonconformity, meaningful only where the definitions are published and applied consistently.
Food safety culture
Shared values and behaviours affecting food safety, now an explicit assessment area under GFSI Benchmarking Requirements version 2024.
Unannounced audit
An audit with no notice beyond a general window, required at least once every three years under the 2024 benchmarking requirements.

FAQ

Frequently asked questions

Should we audit suppliers who already hold GFSI certification?+

Often yes, with a different scope. Certification confirms a scheme-recognised body found the system compliant when they visited. It does not confirm the supplier can meet your specification, is compatible with your allergen profile, or can trace your batch. Scope your audit to those questions and it complements the certificate rather than repeating it.

What changed with GFSI in 2024?+

The Benchmarking Requirements version 2024, published December 2024, require all recognised certification schemes to include food safety culture assessment and unannounced audits at least once every three years. Certification programme owners had until September 2025 to seek recognition against them, and sites are seeing the changes reflected in audits from 2026.

When does FSMA require an onsite audit?+

Where a hazard requiring a supply chain control has a reasonable probability of causing serious adverse health consequences or death, the verification activity must be an onsite audit, unless there is a written determination that other activities provide adequate assurance. The written determination is the part most often missing when a document review is used instead.

How should audit frequency be set?+

From hazard severity, material criticality and the supplier's performance history rather than a uniform annual cycle. A supplier of a high-risk ingredient with a recent failure warrants more attention than a stable supplier of a low-risk material, and spending equal effort on both means under-auditing the first.

What makes a finding closed?+

Evidence that the action was taken and, at the next audit, evidence that it held. A response letter describing intent is not closure. Repeat findings across consecutive audits are the clearest signal available that closure is nominal, and they should affect approval status rather than simply being recorded again.

Who should conduct the audit?+

Someone competent in the supplier's sector and process, which is a higher bar than being competent in auditing. Under FSMA the auditor must be qualified, with technical expertise from training or experience. An experienced auditor without process knowledge will verify that documents exist and miss what is happening on the line.

The agents

What the agents do with it

The audit is a day. What fails is the scope that duplicated the certificate, the finding closed on a letter, and the repeat that nobody connected to last year.

KnowQuality

Holds supplier approval, certification expiry and audit history together, so the audit is scoped against what the certificate already covers.

Ella

Surfaces repeat findings across consecutive audits and links complaint and rejection data to the supplier before the audit is planned.

KnowLogistics

Supplies the delivery and rejection record that lets you choose a real batch for the traceability challenge rather than accepting one offered.

KnowContractor

Applies the same verification logic to service providers, where certification is rarer and second-party audit carries more of the load.

This template lives in KnowQualityquality and food safety. HACCP, nonconformance, traceability, laboratory and customer complaints.

Sources

Sources

  • ISO 19011:2018, guidelines for auditing management systems
  • 21 CFR 117 Subpart G, supply chain program, FDA
  • GFSI Benchmarking Requirements version 2024
  • ISO 9001:2015 clause 8.4, control of externally provided processes, products and services
  • SQF Edition 9 and BRCGS Food Safety Issue 9, supplier approval requirements

KnowQuality

Also in Suppliers

6Browse the whole library
Record

Supplier Approval Record

Records the decision to approve a new supplier, with the evidence behind it. Completed before the first order. Approved by quality and procurement together. No material is accepted from an unapproved supplier, which this record enforces.

Assessment

Supplier Questionnaire

Collects information about a supplier's systems, certifications and controls. Sent before approval and refreshed yearly. Completed by the supplier and reviewed by quality. Scored, so suppliers can be compared on the same basis.

Review

Supplier Scorecard

Scores a supplier on quality, delivery, responsiveness and cost over a period. Run quarterly. Compiled by procurement with quality. Gives you something concrete to take into a supplier review meeting.

Record

Supplier Corrective Request

Asks a supplier to investigate and fix a problem with their material or service. Raised after a rejection or repeated issue. Sent by quality. Requires root cause and evidence from the supplier, not just an apology and a credit note.

Register

Material Specification Record

Holds the agreed specification for each material you buy, including tolerances and test methods. Created before first order and updated when the specification changes. Owned by quality. Incoming inspection checks against this record, so both sides know the standard.

Review

Certificate of Analysis Review

Checks the certificate supplied with a material against the agreed specification. Run on each delivery that requires one. Carried out by the receiving inspector. Missing or non conforming certificates hold the material until resolved.

Start in Minutes, Not Weeks

Launch a Ready-Made Template and Customize It Your Way

Every template is fully editable. Adjust fields, workflows, and branding to match your processes, then deploy to your team instantly.