A supplier audit is a structured, evidence-based examination of a supplier’s quality system, processes, and records — conducted on-site or remotely by the purchasing organization (or its representative) to verify the supplier is actually operating the way it claims to. It is the audit event itself: opening meeting, document review, process walk-through, evidence sampling, findings, and a written report with corrective action requests. That makes it distinct from two related but different activities:
- Supplier qualification is the broader, often one-time-then-periodic program that decides whether a supplier is approved to do business with you at all — a supplier audit is frequently one input into that decision, not the whole program. See our vendor qualification process guide for the full framework, including risk tiering and requalification cadence.
- Vendor selection is the downstream commercial decision of choosing among already-qualified suppliers based on price, capacity, and service — covered in our vendor selection criteria guide.
This guide covers the supplier audit itself: the types of audits, when one is required, how to run the process end to end, what a supplier audit checklist should contain, and what a supplier audit report needs to document. It’s written for lab managers, quality assurance staff, and procurement/research-administration professionals who own an approved-supplier program in a research, clinical, or medical-lab setting. “Supplier audit” and “vendor audit” are used interchangeably in practice — this guide treats them as the same activity.
Types of supplier audits
ISO 19011 (Guidelines for auditing management systems), the reference standard most quality programs build their audit terminology from, distinguishes audits by who is conducting them and why:
- First-party (internal) audit — an organization audits its own processes. Not a supplier audit, but the same methodology underlies one.
- Second-party audit — the customer (or a party acting on the customer’s behalf) audits a supplier directly. This is what “supplier audit” almost always means in a procurement context: your organization, or a contracted auditor working for you, assesses the supplier.
- Third-party audit — an independent, accredited certification body audits the supplier against a standard (e.g., ISO 9001, ISO 13485) and issues a certificate. A supplier’s current ISO certificate is useful supporting evidence but does not replace a second-party audit scoped to your specific requirements — certification confirms a management system exists and functions; it doesn’t confirm the supplier can reliably meet the specifications of your particular products or services.
Within second-party supplier audits, programs typically further distinguish:
- Initial (qualification) audit — conducted before or during onboarding, feeding into the qualification decision.
- Periodic (surveillance) audit — a scheduled, risk-based re-audit of an already-approved supplier, at an interval set by risk tier (see below).
- For-cause audit — triggered by a specific event: a recurring nonconformance, a complaint trend, a recall, a failed certificate of analysis, or a change the supplier didn’t disclose in advance.
- On-site vs. remote (desk) audit — a physical visit to the supplier’s facility versus a document- and video-based review conducted remotely. Remote audits became far more common industry-wide from 2020 onward and remain a standard, accepted method for lower-risk suppliers or as a screening step ahead of an on-site visit; higher-risk suppliers (e.g., those manufacturing sterile products, active pharmaceutical ingredients, or Class II/III device components) are still generally expected to receive periodic on-site coverage.
When a supplier audit is required
Whether you’re formally required to audit a given supplier — and how often — depends on the regulatory and quality framework your organization operates under:
- ISO 9001:2015, Clause 8.4 (“Control of externally provided processes, products and services”) requires organizations to evaluate, select, monitor performance of, and re-evaluate external providers based on their ability to supply in accordance with requirements, and to keep documented information of that evaluation. An audit is one of the evaluation methods the standard contemplates, alongside supplier questionnaires, performance scorecards, and incoming inspection data.
- ISO 13485:2016, Clause 7.4 (Purchasing) imposes a more prescriptive version of the same requirement for medical device manufacturers, tied to the risk the purchased product poses to the device. As of February 2, 2026, FDA’s Quality Management System Regulation (QMSR) incorporates ISO 13485:2016 by reference in place of most of the legacy 21 CFR Part 820 text, so US device manufacturers’ supplier-control obligations now run substantially through ISO 13485:2016 rather than the older standalone Part 820 language.
- Drug cGMP (21 CFR Part 211) requires written procedures for approving suppliers of components, containers, and closures, and for qualifying and monitoring contract manufacturers and testing laboratories; supplier audits are the standard mechanism firms use to generate the objective evidence those procedures require.
- Clinical and research labs operating under CLIA or accredited to ISO 15189 face similar externally-provided-service expectations for reagent, calibration-service, and reference-lab suppliers, though the audit obligation is typically framed as part of the lab’s own accreditation-body assessment rather than a standalone regulatory mandate.
Even where no regulation explicitly mandates it, a supplier audit is the most direct way to verify claims a supplier makes on paper — a certificate of analysis, a certificate of conformance, or an ISO certification — actually reflect what happens on their floor. See our certificate of analysis (COA) guide for what that document does and doesn’t tell you on its own.
The supplier audit process, step by step
- Define scope and criteria. Decide what the audit covers (a single product line, the whole facility, a specific process) and against what standard or specification you’re auditing — your own purchasing specification, ISO 9001/13485, or a customer-specific quality agreement.
- Select and prepare the audit team. Internal quality/procurement staff, a contracted third-party auditor, or a combination. Auditors should not audit an area they’re directly responsible for, to preserve independence.
- Request advance documentation. Quality manual, relevant SOPs, organizational chart, prior audit reports and CAPA close-outs, certifications, and a facility layout. Reviewing these before the visit focuses the on-site time on verification rather than discovery.
- Opening meeting. Confirm scope, schedule, participants, and confidentiality expectations with the supplier’s team.
- Document and record review. Sample records against the supplier’s own procedures: batch/lot records, calibration logs, training records, change control, nonconformance and CAPA logs, incoming-material inspection records.
- Process walk-through. Observe the actual process — receiving, production, storage, packaging, shipping — and compare what’s happening to what the documentation says should happen. This step is what remote/desk audits substitute with live video or supplier-submitted footage.
- Evidence sampling and interviews. Talk to operators and supervisors, not just quality staff, to confirm procedures are followed in practice, not just on paper.
- Closing meeting. Present preliminary findings to the supplier before leaving (or ending the remote session), so nothing in the written report is a surprise.
- Audit report and corrective action requests. Issue the formal report (see the next section) with a deadline for the supplier’s corrective action plan.
- Follow-up and close-out. Verify corrective actions were actually implemented — via documentation, photos, or a follow-up visit — before closing findings, especially major/critical ones.
Supplier audit checklist: what to cover
A supplier quality audit checklist should be built around your specific product/service risk, but most programs cover the same core categories. Use this as a starting point for a supplier audit checklist or supplier audit template, not a substitute for one tailored to your own purchasing specifications:
- Quality management system — documented quality policy, management review, internal audit program, organizational structure and responsibilities.
- Document and record control — version control, approval workflow, retention periods, record retrievability.
- Incoming material/component control — how the supplier itself qualifies and monitors its own upstream suppliers and raw materials.
- Equipment calibration and maintenance — calibration records, traceability to a national metrology standard, preventive maintenance schedules.
- Personnel training and qualification — training records tied to specific job functions, evidence of competency verification, not just attendance logs.
- Change control — how the supplier evaluates and communicates changes to materials, processes, or sub-suppliers that could affect your product; whether you’re notified before the change, not after.
- Nonconformance and CAPA — how deviations are investigated, root-caused, and closed. See our CAPA (Corrective and Preventive Action) definition for the underlying framework this checklist item is assessing.
- Traceability and lot documentation — certificate of analysis / certificate of conformance practices, lot genealogy, ability to trace a shipped lot back to raw materials and forward to where it shipped.
- Storage, handling, and shipping — environmental controls, temperature monitoring where applicable, packaging validation.
- Data integrity — for suppliers generating electronic records (certificates, test data), basic ALCOA+ controls: attributable, legible, contemporaneous, original, accurate records with appropriate access control and audit trails.
- Business continuity and security — disaster recovery, single-source-of-failure risk, and, increasingly, basic cybersecurity posture for suppliers with system access into your environment.
The supplier audit report
A defensible supplier audit report should include, at minimum:
- Audit scope, date, standard/criteria audited against, and participants (auditors and supplier representatives).
- A findings list, each classified by severity — commonly critical (immediate risk to product safety/efficacy or a regulatory violation), major (a systemic breakdown in a required control), and minor (an isolated lapse or documentation gap) — with objective evidence cited for each (the specific record, observation, or interview that supports the finding, not just an assertion).
- Corrective action requests tied to each finding, with a due date for the supplier’s response.
- An overall disposition or rating: approved, conditionally approved (pending corrective action), or disqualified/suspended.
- A planned follow-up mechanism — a re-audit date, a documentation-only verification, or escalation path if corrective actions aren’t closed on time.
Keep completed reports and their corrective-action close-out evidence in the supplier’s file for the full record-retention period your quality system or funding agreement requires — they’re typically the first thing a customer audit or regulatory inspection asks to see when testing whether your own supplier-control program is more than a policy document.
How often to audit an approved supplier
Audit frequency should be risk-based rather than a fixed calendar interval applied uniformly. Programs commonly tier suppliers (for example, high/medium/low risk based on the criticality of what they supply, their audit/complaint history, and how difficult they’d be to replace) and set proportionally different re-audit intervals per tier — annual on-site for the highest-risk tier, down to a documentation-only review every two to three years for low-risk, low-impact suppliers. Our vendor qualification process guide covers this risk-tiering approach in more detail, since the same tiers usually drive both the initial qualification depth and the ongoing audit cadence.
Frequently asked questions
What’s the difference between a supplier audit and a vendor audit?
None in practice — “supplier audit” and “vendor audit” describe the same activity. Organizations tend to use “supplier” in manufacturing/quality contexts and “vendor” in procurement/IT contexts, but the process and checklist are the same.
How long does a supplier audit take?
It depends heavily on scope and supplier size: a focused on-site audit of a single product line commonly runs one full day; a comprehensive facility audit covering multiple processes can run two to three days. Remote/desk audits are often shorter in direct contact time but may take longer in elapsed calendar time waiting on requested documentation.
Who should conduct a supplier audit?
Trained internal quality or procurement staff, a contracted third-party audit firm, or a combination, depending on the technical complexity of what’s being audited and whether your organization has staff qualified to assess it. Auditor independence from the area being reviewed matters more than whether the auditor is internal or external.
What happens if a supplier fails an audit?
Outcomes typically range from conditional approval pending corrective action, to a defined probation period with increased monitoring, to suspension or disqualification for critical findings that go uncorrected. The response should be proportional to finding severity and documented in the same way the audit itself was.
Is a supplier’s ISO 9001 or ISO 13485 certificate enough on its own?
A current third-party certificate is useful supporting evidence that a management system exists and is independently assessed, but it’s scoped to the certification body’s audit plan, not to your specific product or specification. Most quality programs treat certification as a risk-reduction factor that can extend the interval between your own audits, not as a full substitute for a second-party audit.







