Why Supplier Audits Matter More Than Most Organisations Realise
A supplier audit is a structured, evidence-based examination of a supplier's operations, processes, and management systems. Its purpose is to verify that the supplier can consistently deliver products or services that meet your requirements, and to confirm that any commitments they have made, whether contractual, regulatory, or certification-related, are actually being kept in practice.
On this page
If your organisation is certified to ISO 9001, ISO 14001, or ISO 45001, supplier audits are not optional extras. They are a direct response to obligations under Clause 8.4, which requires you to control externally provided processes, products, and services. Ticking a supplier evaluation form once a year and filing it away does not satisfy that requirement. Auditing a supplier's system gives you a level of confidence that no questionnaire can match.
This article explains what a supplier audit is, how it differs from other types of audits, when you should conduct one, and what actually happens during the process. Whether you are a Quality Manager, an HSE professional, or someone building a supplier assurance programme from scratch, this guide will give you a practical foundation.
Where Supplier Audits Sit in the Audit Landscape
To understand supplier audits properly, it helps to know where they sit within the broader audit framework. ISO standards recognise three categories of audit based on the relationship between the parties involved.
First, Second, and Third Party Audits
A first party audit is an internal audit. Your organisation audits itself to check conformity with its own management system requirements.
A third party audit is conducted by an independent certification body. It results in a formal certification decision. The auditor has no commercial relationship with your organisation beyond the certification contract.
A supplier audit is a second party audit. You, as the customer, audit your supplier. You have a direct commercial interest in the outcome. The supplier is not independent of you, and you are not independent of them. This creates a different dynamic from both internal and certification audits, and it requires a different approach.
The second party audit framework is well-established under ISO 19011, which provides guidance on auditing management systems. Second party audits are governed by the same principles of evidence-based decision-making, impartiality, and systematic approach, but the commercial relationship between the parties adds complexity that internal auditors do not face.
How Supplier Audits Differ From Internal Audits
Internal audits happen within your own organisation. You have authority to access records, interview staff, and observe processes. People generally understand why you are there.
In a supplier audit, you are a guest. You have whatever access the supplier agrees to give you. You cannot demand to see records the way a certification auditor might. Your influence comes from the commercial relationship and any contractual audit rights you have negotiated. This is why preparation matters so much in supplier auditing. You need to be clear about what you need to see and why, before you arrive.
Exemplar Global Recognised Training ProviderRTP No. 310970The ISO 9001 Requirement That Drives Supplier Audits
ISO 9001 Clause 8.4 requires organisations to determine and apply criteria for evaluating, selecting, monitoring, and re-evaluating external providers. The type and extent of control depends on the potential impact of the externally provided product or service on your ability to consistently meet customer and regulatory requirements.
This is a risk-based requirement. Not every supplier needs a full audit. A supplier providing stationery carries different risk from a supplier providing a critical component in your product or a subcontractor performing work directly in scope of your certification. The higher the risk, the more rigorous your oversight needs to be.
For a detailed breakdown of what Clause 8.4 actually asks of you, the article on ISO 9001 Clause 8.4 and managing outsourced processes covers the requirements clause by clause. Understanding the standard's intent will help you design a supplier audit programme that satisfies your certification body and, more importantly, actually protects your business.
Types of Supplier Audits
Not all supplier audits look the same. The format depends on what you are trying to find out, the risk profile of the supplier, and the resources available.
System Audits
A system audit examines the supplier's management system as a whole. You are looking at whether they have a documented system, whether it is implemented in practice, and whether it is producing the results it is supposed to. This is the most comprehensive type of supplier audit and is appropriate for high-risk or high-value suppliers.
Process Audits
A process audit focuses on a specific process rather than the entire system. If you are concerned about a supplier's incoming inspection process, or how they control a particular manufacturing step, a process audit lets you go deep on that area without the time commitment of a full system audit.
Product Audits
A product audit examines the supplier's finished product or output against defined specifications. It is less about the system and more about the result. Product audits are useful when you have had quality escapes and want to understand what is being shipped before it reaches you.
Desktop or Document Reviews
Sometimes called a desktop audit, this involves reviewing the supplier's documentation, certifications, procedures, and records without visiting the site. It is a lower-cost option but provides less assurance than an onsite audit. It is appropriate for lower-risk suppliers or as a preliminary step before an onsite visit.
When Should You Conduct a Supplier Audit?
Supplier audits should be triggered by risk and evidence, not just by calendar dates. There are several situations where a supplier audit is clearly warranted.
Before Approving a New Supplier
For high-risk or strategically important suppliers, an audit before you place your first order makes sense. You want to verify that the supplier's system and capability match what they have claimed in their tender or quotation. A pre-approval audit gives you confidence before you become dependent on them.
Following Recurring Quality Issues
If a supplier keeps delivering nonconforming product, or if you are raising corrective action requests that never seem to get properly closed, an audit is often the most effective way to understand what is actually happening in their system. Questionnaires and phone calls rarely get to the root cause. Being on site does.
Significant Changes at the Supplier
If a supplier changes their key personnel, moves to a new facility, acquires new equipment, or changes their own supply chain, these are risk events. Any of these changes could affect their ability to meet your requirements. A targeted audit after a significant change is a reasonable and proportionate response.
Periodic Re-evaluation of Critical Suppliers
Even when things are going well, periodic audits of your most critical suppliers are good practice. They reinforce the message that you are an engaged customer, they often surface issues before they become problems, and they demonstrate to your own certification body that your supplier monitoring programme has substance.
What Happens During a Supplier Audit
The structure of a supplier audit follows the same general sequence as any other audit. There is a planning phase, an execution phase, and a reporting phase.
Planning the Audit
Good planning is where supplier audits succeed or fail. Before you contact the supplier, you need to define your audit objectives, scope, and criteria. What are you trying to find out? Which processes or clauses will you examine? What evidence will you need to see?
You also need to review any existing information you have about the supplier. Previous audit reports, corrective action records, delivery performance data, and any certificates they hold are all relevant inputs. This background review shapes your checklist and helps you allocate your time on site.
Once you have your plan, you notify the supplier, agree on the date and scope, and confirm what access you will need. If your contract includes audit rights, reference them. If it does not, this is a negotiation, and the supplier's willingness to cooperate is itself informative.
The Opening Meeting
The opening meeting sets the tone. You introduce yourself and your team, confirm the scope and objectives, explain the process, and give the supplier an opportunity to ask questions. Keep it brief and professional. The goal is to establish a working relationship for the day, not to intimidate anyone.
One practical point: confirm who your guide will be for the day. Having the right person walking you through the facility makes a significant difference. You want someone with operational knowledge, not just a receptionist who has been assigned to keep you company.
Gathering Evidence on Site
This is the core of the audit. You will typically combine document review, interviews with staff, and direct observation of processes. The mix depends on what you are auditing.
When reviewing documents, look for evidence that procedures are current, controlled, and reflect what actually happens. When interviewing staff, ask open questions and follow the answers. When observing processes, look for consistency between what the procedure says and what you can see happening on the floor.
Be specific in your note-taking. Record what you saw, heard, and reviewed, along with document numbers, revision levels, and names where relevant. Vague notes produce vague reports, and vague reports do not drive improvement.
The Closing Meeting
At the closing meeting, you present your findings to the supplier's management. Be clear about what you observed, what evidence supports each finding, and how you have classified each issue. Give the supplier an opportunity to respond. Occasionally they will have information that changes your assessment. More often, they will simply need time to digest the findings.
Agree on timelines for corrective action responses before you leave. If you leave without a clear understanding of what happens next, the findings may never get actioned.
The Audit Report
The audit report is the formal record of what you found. It should include the audit objectives, scope, criteria, a summary of findings, any nonconformities or observations, and the agreed corrective action timelines. The report should be factual, specific, and written in a way that the supplier can act on.
A good supplier audit report is not a weapon. It is a tool for improvement. Write it with that intent.
What Auditors Look for in a Supplier Audit
The specific focus of a supplier audit depends on the scope you have defined, but there are several areas that consistently matter regardless of the industry or standard involved.
Management Commitment and Leadership
Quality and safety outcomes depend heavily on what management actually prioritises. Look for evidence that leadership is engaged with the system, not just that a system exists on paper. Do senior managers attend management reviews? Are quality objectives meaningful and tracked? Does the quality team have the authority and resources they need?
Control of Processes and Documented Information
Are the supplier's procedures up to date and accessible to the people who need them? Are records being maintained as required? Are work instructions being followed on the floor, or are they sitting in a folder that nobody reads?
Nonconformity Management and Corrective Action
How does the supplier handle problems when they arise? Do they have a functioning nonconformity system? Are root causes being identified, or are they just applying band-aid corrections? A supplier who handles nonconformities well is far lower risk than one who has never raised a nonconformity, because the latter usually means problems are not being captured.
Competence and Training
Are the people performing critical tasks competent to do so? Are training records current? Has the supplier identified what competence is required for each role and verified that their people meet that standard?
Their Own Supplier Controls
If your supplier is outsourcing parts of the work they do for you, you need to understand how they control their own supply chain. A supplier who has no oversight of their own subcontractors is a risk that flows directly to you.
Supplier Audit Rights and Commercial Considerations
One of the practical differences between supplier audits and internal audits is that your right to audit is not automatic. It depends on your commercial relationship with the supplier.
If you want the ability to audit a supplier, the time to negotiate that is before you sign the contract. Audit rights clauses are standard in supply agreements for regulated industries, major infrastructure projects, and government contracts. If your current contracts do not include them, consider adding them at the next renewal.
Even where audit rights exist, the relationship matters. A supplier who feels that audits are being used to humiliate or penalise them will give you minimum cooperation. A supplier who understands that audits are part of a professional working relationship, and that findings will be handled constructively, will give you genuine access and honest answers.
Exemplar Global Recognised Training ProviderRTP No. 310970Building a Supplier Audit Programme
A single supplier audit is useful. A structured supplier audit programme is far more valuable. An effective programme includes a risk-based approach to prioritising which suppliers get audited and how often, clear criteria for supplier classification, standardised checklists and reporting templates, a process for tracking corrective actions to closure, and a mechanism for feeding audit outcomes back into your supplier evaluation and selection process.
For guidance on evaluating supplier performance systematically, the article on how to evaluate supplier performance under ISO 9001 covers the practical side of building that ongoing oversight capability.
Your supplier audit programme should be documented and reviewed periodically. Like any process, it needs to be evaluated for effectiveness. Are the audits finding real issues? Are corrective actions being closed? Are the right suppliers being prioritised? If the programme is not producing useful information, it needs to be redesigned, not just repeated.
Developing the Skills to Conduct Supplier Audits Effectively
Supplier auditing requires a specific set of skills. You need to be able to plan an audit against a defined scope, gather evidence through document review, interviews, and observation, classify findings accurately, write clear and actionable reports, and manage the interpersonal dynamics of auditing someone who is also a commercial partner.
These are skills that can be developed through formal training. An ISO Internal Auditor course gives you the foundational auditing skills you need for supplier auditing. A Lead Auditor course takes that further, covering audit programme management, team leadership, and the more complex scenarios you encounter when auditing external organisations.
At Audit Workshop, our internal auditor and lead auditor training courses are built around practical auditing skills, not just theory. Courses are available for ISO 9001, ISO 14001, and ISO 45001, in both live virtual and self-paced formats. If you are responsible for supplier assurance and want to conduct supplier audits with confidence, our training will give you the tools to do it properly.










