At a glance
- Definition: a supplier audit is a systematic, documented and traceable assessment of a third party's ability to meet quality, regulatory and operational requirements.
- Four types: documentary, on-site, product or process, and financial.
- Four steps: define the scope, collect evidence, audit and decide, then monitor actions.
- Eight categories of criteria: quality, food safety, traceability, upstream purchasing, production, risks, performance and contractual commitments.
- Common mistake: auditing without a written framework or traceable evidence. The audit then becomes an opinion rather than a decision-making tool.
- Trend: automation is shifting the annual audit towards continuous monitoring based on document extraction, scoring and alerts.
Supplier audit: what exactly does it mean?
A supplier audit is a systematic, documented and traceable assessment of a supplier's or subcontractor's ability to meet defined requirements: product quality, food safety, regulatory compliance, industrial capacity, organisation and risk management. It provides an objective snapshot based on evidence rather than impressions gathered during a visit.
It complements the supplier evaluation, which continuously monitors delivered performance, lead times, compliance rates, responsiveness and service levels. The audit is periodic and in-depth; the evaluation is continuous. Together, they make it possible to trigger the right controls at the right time and within the right scope.
The three characteristics of an audit
- It is based on a written set of criteria communicated before the audit.
- It relies on evidence: documents, records, measurements, interviews and on-site observations.
- It concludes with a formal report and an action plan including owners and deadlines.
What a supplier audit is not
It is not a satisfaction questionnaire: a supplier's answers remain declarative until they have been verified.
It is not a certification: certification demonstrates compliance with a specific standard, but it does not automatically prove compliance with your specifications.
It is not a punitive inspection. A useful audit aims to secure and improve the relationship with the supplier.
Why supplier audits secure your supply chain
A defect detected at the supplier costs less than a defect discovered after receipt or once production has started. Auditing shifts detection upstream: it reveals documentary, industrial and organisational weaknesses before they lead to scrap, delays, production line stoppages, withdrawals or recalls.
This approach extends a structured supplier compliance policy: requirements are known, evidence remains accessible and deviations support purchasing decisions based on actual risk.
Quality risks
Non-compliance can result in additional incoming inspections, rework, scrap, customer complaints or production interruptions.
Regulatory risks
In the food industry, requirements notably cover hygiene, allergens, traceability, labelling and contaminants. A supplier unable to provide the required evidence can undermine your own compliance.
Operational and financial risks
Dependence on a single site, insufficient capacity, poor maintenance or a fragile financial situation can threaten continuity of supply.
Hidden costs
The total cost includes time spent following up, searching for evidence, re-entering data, performing additional controls, managing delays and scrap, and urgently preparing for customer audits. To manage these costs effectively, calculate them using your own incidents rather than relying on generic averages that are rarely transferable.
The 4 types of supplier audits
| Audit type | Main objective | When to trigger it | Evidence reviewed |
|---|---|---|---|
| Documentary | Verify the compliance and completeness of the supplier file | Qualification, renewal or monitoring of a large supplier base | Certificates, procedures, analyses, insurance documents and declarations |
| On-site | Compare declared practices with operational reality | Critical supplier, new site, incident or repeated deviation | Observations, records, interviews, equipment and flows |
| Product or process | Validate a product, production line or process | New recipe, new equipment, site transfer or recurring issue | Control plans, tests, parameters and production data |
| Financial | Secure continuity of the relationship | High dependency, warning signal or critical investment | Financial statements, ratios, insurance, contracts and business continuity plan |
A proportionate approach applies documentary controls across the entire supplier base, while reserving on-site visits and specialised audits for suppliers classified as critical according to a formal risk assessment.
The 4 steps of a successful supplier audit
A robust approach must be reproducible from one supplier to another. Before launching your programme, formalise how to implement continuous supplier evaluation. Its results will help prioritise audits, determine their depth and measure improvements following corrective actions.
Step 1 — Define the audit scope
Define the site, product or process concerned, the objective, framework, auditors, stakeholders and decision rules. Communicate the schedule and list of required documents. Poor preparation almost always results in findings that are difficult to use.
Step 2 — Collect and prepare the evidence
Build a weighted audit grid, gather documents, check their version and validity, then identify the areas that require deeper investigation during interviews or the site visit. Disqualifying criteria and decision thresholds must be defined before the audit.
Step 3 — Conduct the audit and formalise findings
Follow the audit grid while allowing time for open observation. Link each deviation to a requirement, evidence and date. Classify deviations according to an explicit scale and give the supplier an opportunity to respond.
Step 4 — Manage the action plan
Assign each action to an owner, with a deadline and expected evidence. Then verify its effectiveness: an action that has been administratively closed may still be ineffective in practice.
Documents to review during an audit
The exact list depends on the industry, product and level of risk. It should demonstrate the third party's identity, control of its processes, product compliance, team competence and ability to trace the history of a batch. Effective supplier regulatory traceability links every piece of information used to its evidence, version and validity period.
The challenge is not simply receiving the documents. You need to know which ones are required, detect expirations and retain the correct version. A structured regulatory document management approach prevents an outdated certificate or incomplete scope from being used as proof of compliance.
- Company registration documents, insurance and contact details for the audited site.
- Certificates and audit reports, including scope and validity dates.
- Food safety management plan, HACCP study and hygiene procedures.
- Technical data sheets, specifications and allergen declarations.
- Analysis results and certificates of analysis by batch.
- Traceability, withdrawal, recall and crisis management procedures.
- Control, cleaning, maintenance and calibration plans.
- Register of non-conformities, complaints and corrective actions.
- Qualification of upstream suppliers and subcontractors.
- Business continuity plan, contractual commitments and training records.
Build an effective supplier audit grid
A robust audit grid covers eight categories of criteria. It should not reduce the audit to food safety alone, as documentary, industrial or contractual failures can create equally significant risks.
- Quality management system: policy, responsibilities, reviews, document management and corrective actions.
- Food safety and hygiene: HACCP, cleaning, pest control and training.
- Traceability and batches: upstream and downstream identification, traceability tests, withdrawals and recalls.
- Upstream purchasing: qualification of the supplier's own supplier base, incoming controls and subcontracting.
- Production resources: equipment condition, maintenance and control of measuring instruments.
- Risks and non-conformities: risk analysis, incidents, contingency plans and effectiveness of corrective actions.
- Performance and sustainability: service, delivered quality, responsiveness and relevant environmental or social criteria.
- Contractual commitments: insurance, confidentiality, administrative obligations and specifications.
Tip: weight each category and define disqualifying criteria before the audit. Without this rule, two very different deviations can result in the same score and make the conclusion difficult to justify.
Supplier audits and quality standards (IFS, BRC)
In the food industry, IFS Food version 8 and BRCGS Food Safety Issue 9 structure the assessment of systems, products and processes. For intermediaries that do not manufacture products themselves, IFS Broker certification notably covers the management of trading activities and associated suppliers.
When this standard is required by your customers or market, the scope, responsibilities, supplier management and evidence must be prepared before the audit. This guide explains how to achieve IFS Broker certification by turning the standard's requirements into an operational action plan.
The role of other standards and references
- ISO 9001 provides a quality management framework and notably requires organisations to control externally provided processes, products and services.
- ISO 19011:2026 provides guidelines on auditing principles, audit programme management, conducting audits and auditor competence. It replaces the 2018 edition.
- GFSI does not certify companies. The initiative recognises certification programmes benchmarked against its requirements.
A valid certificate remains one piece of evidence among others. Check its scope, the site concerned, the programme version, the certification body and its validity date. It does not replace verification of your own requirements.
Common pitfalls to avoid during an audit
Common supplier compliance mistakes also occur in audit programmes: implicit criteria, scattered evidence, unmonitored action plans and applying the same level of effort to every third party.
Auditing every supplier in the same way
Classify your supplier base by risk so that visits and in-depth audits focus on critical suppliers.
Treating the audit as an isolated event
Connect audits to incidents, performance indicators and continuous document monitoring. An annual audit does not provide visibility into changes that occur during the rest of the year.
Reporting a deviation without evidence
Specify the relevant requirement, the evidence observed, the context and the date. A finding that is too vague will be difficult to discuss and close.
Closing an action without verifying its effectiveness
Completing an action does not guarantee that the root cause of the deviation has disappeared. Verify the outcome after an appropriate period.
Confusing certification with compliance
An external standard does not automatically cover your product specifications, contractual commitments or your customers' specific requirements.
Neglecting the human factor
An audit conducted like an interrogation produces defensive responses. Present the framework, explain the shared objective and remain factual to support sustainable improvement.
Digitalise your supplier audit monitoring
A shared repository avoids rebuilding the supplier file before every visit. A supplier database connects suppliers, products, documents, validity dates, deviations and actions so that every team works from the same level of information.
Deploying supplier compliance software then makes it possible to automate collection, follow-ups, data extraction and alerts, while retaining human validation for decisions and ambiguous situations.
What artificial intelligence can automate
- Classification: recognise the document type and associate it with the correct supplier or product.
- Extraction: extract dates, scopes, certificate numbers, batches, scores or analysis results.
- Monitoring: flag an expiration, missing document or inconsistency requiring review.
- Prioritisation: update indicators that direct the audit programme towards the highest-risk cases.
Artificial intelligence replaces neither the auditor's judgement nor dialogue with the supplier. It reduces manual preparation and makes weak signals visible between audits.
Checklist to stay audit-ready
- A single supplier database with documented criticality levels.
- A written audit procedure known to the teams.
- A weighted and version-controlled criteria grid.
- An annual risk-based audit programme.
- Required documents defined by supplier category.
- Alerts triggered before each expiration date.
- A deviation register with owners and deadlines.
- Verification of corrective action effectiveness.
- Regular supplier performance reviews.
- Quick access to evidence and its history.
Frequently asked questions
The right questions.
Practical answers.
What is a supplier audit, in one sentence?
It is a systematic and traceable assessment, conducted according to written criteria, that uses evidence to verify a supplier's ability to meet your quality, regulatory and operational requirements.
What is the difference between a supplier audit and a supplier evaluation?
An evaluation monitors overall performance over time. An audit provides a periodic, in-depth verification of evidence within a defined scope. Evaluation results can be used to trigger or prioritise an audit.
How does a supplier quality audit work?
It follows four phases: scoping, evidence collection and preparation, the audit itself with formalised findings, followed by action plan monitoring and verification of effectiveness.
How do you audit a food industry supplier?
Give significant weight to food safety, traceability, allergens and process control. Check the scope and validity of certifications, analyses, cleaning plans, traceability tests and incident history.
Do all suppliers need to be audited on-site?
No. Documentary audits can cover the entire supplier base. Reserve on-site visits for critical suppliers or cases involving an incident, major change or signs of deterioration.
How often should suppliers be audited?
Frequency depends on risk, history and applicable requirements. A critical supplier may be audited annually; a stable, low-risk supplier every two or three years, with an off-cycle audit in the event of an incident or significant change.
How can audit preparation time be reduced?
Centralise evidence continuously, version-control documents, automate follow-ups and monitor deadlines. Preparation then becomes a review of exceptions rather than a search for missing documents.
Conclusion: make supplier audits a routine process, not a last-minute project
A supplier audit is neither a quality formality nor a box-ticking exercise. It helps transform a reactive supply chain into a controlled one through written criteria, traceable evidence, monitored deviations and data-driven decisions.
Start by classifying your suppliers by risk, formalising your audit grid and building a realistic programme. Then centralise documents and action monitoring to gradually move from an annual audit to continuous control.
Tracklab supports more than 150 companies and helps structure data from more than 40,000 suppliers and 70,000 products or ingredients.





