What a supplier audit is
A supplier audit is an audit your organisation conducts on a vendor — a structured, scored assessment of the supplier's quality system, process capability, controls and documentation against a set of criteria you define. It exists to answer one question a purchasing and quality team cannot afford to guess at: can this supplier consistently deliver conforming parts, and can we prove we checked? A supplier audit is conducted to qualify a new vendor before approval, to re-audit an approved vendor on a cycle, and to investigate a supplier after a quality escape or a run of rejections.
In the language of an audit management system, a supplier audit is simply another audit type — the same engine that runs your internal ISO 9001 process audits, pointed at a supplier and driven by a supplier checklist. The template, the plan, the competent auditor, the scored checklist entry, the graded non-conformance and the closure trail are all the same machinery; only the checklist and the auditee change. That is why a capable supplier audit software is not a separate tool but a profile of the same platform that runs the rest of your audit programme.
First, second and third-party audits
Supplier audits are the textbook example of a second-party audit, and it is worth placing them precisely, because the three audit parties are governed by different rules and serve different masters.
| Audit party | Who audits whom | Typical purpose |
|---|---|---|
| First-party (internal) | Your team audits your own processes | ISO 9001 / IATF clause-9.2 internal audit programme |
| Second-party (supplier) | Your team audits a vendor you buy from | Vendor qualification, surveillance and for-cause audits |
| Third-party (certification) | An independent registrar audits you | Certification and surveillance for ISO / IATF |
The practical consequence is that your supplier-audit programme is your programme — you set the criteria, the frequency and the grading, within the requirements your own standard imposes on you. IATF 16949, for instance, requires that you monitor supplier performance and manage supplier quality, which is why automotive suppliers run a formal second-party audit programme rather than relying on certificates alone. Hosting the third-party audit — when the registrar comes to you — is the mirror image of this, and is covered in hosting customer and certification-body audits.
Why a supplier-audit programme matters in India
For an Indian manufacturer feeding an OEM — whether in the Pune, Chennai or NCR auto belt, or in electronics, pharma packaging or engineering — the supply base is the risk. A single non-conforming component from a tier-two vendor becomes your rejection, your customer complaint and your 8D. Three reasons make a disciplined supplier-audit programme non-negotiable rather than a nice-to-have.
1. Your customer holds you responsible for your suppliers
Under IATF 16949 and most OEM supplier manuals, a defect from your sub-supplier is treated as your defect. When your customer audits you, they will ask to see how you qualify and monitor your own suppliers — the approved-vendor list, the audit schedule, the scores and the open NCs. A programme that cannot produce that evidence on demand is a finding waiting to happen.
2. Certificates are not capability
A supplier holding an ISO 9001 certificate tells you a system exists on paper; it does not tell you whether the specific process making your part is capable and controlled. A second-party audit against your own checklist — parameter controls, gauge calibration, traceability, containment discipline — is the only way to see the process that actually affects you.
3. The programme must be defensible, not anecdotal
"We know that supplier well" is not evidence. A supplier audit that raises graded NCs, issues them to the vendor, tracks corrective action to verified closure and flags repeat findings turns supplier management from a relationship into a record — one you can defend to a customer or registrar.
Managing vendor audits on a shared spreadsheet?
See a live supplier audit — planned on a risk-based cycle, scored on one checklist, with NCs issued to the vendor and driven to verified closure — in 30 minutes on your own criteria.
The supplier-audit lifecycle
A supplier audit runs the same six-stage lifecycle as any audit, with the vendor as the auditee. What changes is the checklist, the location — often the supplier's site — and the fact that findings are issued outward to a party you do not control.
The three moments that decide whether a supplier audit is credible are all controls the system enforces rather than the auditor remembering. First, auditor competency: only a person scored and authorised for supplier audits should be assigned, so the assessment carries weight. Second, a single checklist: every vendor is judged against the same reusable template, so scores are comparable across the supply base. Third, issued findings with due dates: an NC that leaves your building must come back closed, not drift. Miss any of the three and the programme becomes theatre.
What a supplier-audit checklist covers
The supplier template is a scored assessment, usually organised into sections that each carry a set of questions and a weight. The exact sections depend on the commodity and the risk, but a manufacturing supplier audit almost always spans these areas:
Quality system
Certification status, document and record control, internal audits, management review and corrective-action discipline — the system behind the process.
SystemProcess capability
Process controls, control plans, in-process checks, machine and tooling capability, and how the supplier reacts when a parameter drifts.
ProcessMeasurement & traceability
Gauge calibration, MSA where required, lot traceability and the ability to contain and trace a suspect batch quickly.
ControlAdd sections for incoming material control, storage and FIFO, handling and packaging, skill and training records, and — increasingly — sub-supplier management, because your supplier's supplier is now your risk too. Because each area is scored, the audit produces a number as well as a set of findings, and that number is what drives the rating and the re-audit frequency. When the checklist must change — a new commodity, a revised customer-specific requirement — it is revised under control so past audits stay tied to the version they were run against and future audits pick up the new one.
NCs, ratings and re-audit frequency
Every gap the auditor finds becomes a non-conformance carrying a requirement reference, a discrepancy description, a major-or-minor grade and a fresh-or-repetitive flag. The difference between a supplier NC and an internal one is direction: it is issued to the vendor, who owns the corrective action, while your team owns the verification. The closure loop is the same disciplined multi-role chain.
Two outputs make the programme run itself. The rating — derived from the score and the NC history — feeds the approved-vendor list and tells purchasing who is safe to buy from. The re-audit frequency is set per supplier by risk: a critical or safety-related part, a new supplier or a poor performer is audited more often; a stable, high-rated supplier of a low-risk part, less often. This risk-based cadence is exactly what IATF 16949 expects, and it beats a flat annual rotation that wastes audits on good suppliers and starves the risky ones of attention. A major supplier NC can escalate into Fast Quality's formal 8D / CAPA workflow when that module is licensed, and email and WhatsApp reminders chase overdue vendor actions automatically. For a step-by-step version aimed at the practitioner, see the supplier audit process guide on the blog.
How Fast Audit runs supplier audits
Fast Audit Software ships a dedicated supplier-audit type on the same engine that runs your internal and product audits, so a group with several plants runs one supplier-audit programme across the whole company rather than one per site. Mapping the cycle to the product:
Because it rides the shared platform, the supplier-audit programme sits alongside your ISO 9001 and IATF internal audits, your product and process audits and, for corporate teams, a multi-plant audit model — one auditor pool, one NC register, one source of truth. That is the difference between managing suppliers and merely knowing them.
Frequently asked questions
What is a supplier audit?
A supplier audit is a second-party audit in which a customer organisation audits a vendor's quality system, processes and capability against a defined set of criteria. It is used to qualify a new supplier before approval, to re-audit an approved supplier on a risk-based cycle, and to investigate a supplier after a quality escape. The auditor scores the supplier against a reusable checklist, raises non-conformances for gaps, and issues them to the supplier for corrective action and verified closure.
What is the difference between a first, second and third-party audit?
A first-party audit is an internal audit an organisation runs on itself. A second-party audit is one an organisation runs on an external party it has a contract with — most commonly a customer auditing a supplier. A third-party audit is one an independent body, such as a certification registrar, runs for accreditation or certification. A supplier audit is the classic second-party audit: your team, your criteria, the vendor's site.
How do you qualify a supplier through auditing?
Qualification runs the same lifecycle as any audit: author a reusable supplier-audit checklist covering quality system, process capability, controls and documentation; plan the audit; assign an auditor competent and authorised for supplier audits; conduct the assessment scoring each area; raise NCs for gaps with a requirement reference and a major or minor grade; issue them to the supplier; and approve the vendor only once the critical findings are closed with evidence. The score and rating then feed the approved-vendor list and the re-audit frequency.
How often should suppliers be re-audited?
Re-audit frequency should be risk-based rather than a flat annual rotation. Suppliers of critical or safety-related parts, new suppliers, and suppliers with a recent quality escape or a poor rating are audited more often; stable, high-rated suppliers of low-risk parts less often. IATF 16949 expects the supplier's performance and risk to drive the monitoring frequency, so the audit interval is set per supplier from the plan and adjusted as the rating and NC history change.
What happens to non-conformances raised in a supplier audit?
Each NC is logged against the requirement it fails, graded major or minor, and issued to the supplier, who submits containment, root cause and corrective and preventive action with a due date. Your team verifies the action against objective evidence before the finding closes, and repeat NCs are flagged fresh versus repetitive so a supplier that keeps failing the same requirement is visible. Overdue actions trigger reminders, and the whole closure trail is retained as evidence for your own certification audit.
Can Fast Audit issue NCs to a supplier and track their closure?
Yes. Fast Audit ships a dedicated supplier-audit type on the shared platform. It holds the scored supplier checklist, plans the re-audit cycle per vendor, restricts assignment to auditors authorised for supplier audits, records the audit and its score, and raises graded NCs that are issued to the vendor and driven to verified closure through the multi-role sign-off, with reminders on overdue actions and escalation into Fast Quality's 8D / CAPA where licensed.
