Industries — Supplier & Vendor Audits 12 min read

The supplier audit process — qualify and audit your vendors

A practical guide to the second-party audit programme — qualifying new vendors, scoring suppliers against one reusable checklist, rating and re-auditing them on a risk-based cycle, and driving every NC to closure. Grounded in how Indian OEM and IATF 16949 supply chains actually work.

Vidya Kathare · July 18, 2026 12 min read Updated July 2026
The supplier-audit cycle
01
Qualify
Score a new vendor before approval
Assessed
02
Plan the cycle
Risk-based re-audit frequency per supplier
Scheduled
03
Conduct & score
One checklist, on-site or remote
In progress
04
Issue NCs
Major / minor, sent to the vendor
Logged
05
Close & rate
Verify CAPA, update the vendor rating
Closed

What a supplier audit is

A supplier audit is an audit your organisation conducts on a vendor — a structured, scored assessment of the supplier's quality system, process capability, controls and documentation against a set of criteria you define. It exists to answer one question a purchasing and quality team cannot afford to guess at: can this supplier consistently deliver conforming parts, and can we prove we checked? A supplier audit is conducted to qualify a new vendor before approval, to re-audit an approved vendor on a cycle, and to investigate a supplier after a quality escape or a run of rejections.

In the language of an audit management system, a supplier audit is simply another audit type — the same engine that runs your internal ISO 9001 process audits, pointed at a supplier and driven by a supplier checklist. The template, the plan, the competent auditor, the scored checklist entry, the graded non-conformance and the closure trail are all the same machinery; only the checklist and the auditee change. That is why a capable supplier audit software is not a separate tool but a profile of the same platform that runs the rest of your audit programme.

The core idea
You cannot inspect quality into a part at goods-inward. A supplier audit moves the control upstream — you assess the process that makes the part, not just the box that arrives.
Incoming inspection catches the defect you already paid for. A supplier audit is how you stop the defect being made in the first place — and how you prove to your own customer and registrar that your supply base is under control.

First, second and third-party audits

Supplier audits are the textbook example of a second-party audit, and it is worth placing them precisely, because the three audit parties are governed by different rules and serve different masters.

Audit partyWho audits whomTypical purpose
First-party (internal)Your team audits your own processesISO 9001 / IATF clause-9.2 internal audit programme
Second-party (supplier)Your team audits a vendor you buy fromVendor qualification, surveillance and for-cause audits
Third-party (certification)An independent registrar audits youCertification and surveillance for ISO / IATF

The practical consequence is that your supplier-audit programme is your programme — you set the criteria, the frequency and the grading, within the requirements your own standard imposes on you. IATF 16949, for instance, requires that you monitor supplier performance and manage supplier quality, which is why automotive suppliers run a formal second-party audit programme rather than relying on certificates alone. Hosting the third-party audit — when the registrar comes to you — is the mirror image of this, and is covered in hosting customer and certification-body audits.

Why a supplier-audit programme matters in India

For an Indian manufacturer feeding an OEM — whether in the Pune, Chennai or NCR auto belt, or in electronics, pharma packaging or engineering — the supply base is the risk. A single non-conforming component from a tier-two vendor becomes your rejection, your customer complaint and your 8D. Three reasons make a disciplined supplier-audit programme non-negotiable rather than a nice-to-have.

1. Your customer holds you responsible for your suppliers

Under IATF 16949 and most OEM supplier manuals, a defect from your sub-supplier is treated as your defect. When your customer audits you, they will ask to see how you qualify and monitor your own suppliers — the approved-vendor list, the audit schedule, the scores and the open NCs. A programme that cannot produce that evidence on demand is a finding waiting to happen.

2. Certificates are not capability

A supplier holding an ISO 9001 certificate tells you a system exists on paper; it does not tell you whether the specific process making your part is capable and controlled. A second-party audit against your own checklist — parameter controls, gauge calibration, traceability, containment discipline — is the only way to see the process that actually affects you.

3. The programme must be defensible, not anecdotal

"We know that supplier well" is not evidence. A supplier audit that raises graded NCs, issues them to the vendor, tracks corrective action to verified closure and flags repeat findings turns supplier management from a relationship into a record — one you can defend to a customer or registrar.

Managing vendor audits on a shared spreadsheet?

See a live supplier audit — planned on a risk-based cycle, scored on one checklist, with NCs issued to the vendor and driven to verified closure — in 30 minutes on your own criteria.

Get a demo

The supplier-audit lifecycle

A supplier audit runs the same six-stage lifecycle as any audit, with the vendor as the auditee. What changes is the checklist, the location — often the supplier's site — and the fact that findings are issued outward to a party you do not control.

01
Supplier template
A reusable scored checklist for vendor assessment
02
Plan the cycle
Frequency per supplier by risk and rating
03
Assign auditor
Competent, authorised for supplier audits
04
Conduct & score
Answer each area, record the score
05
Issue NCs
Graded findings sent to the vendor
06
Close & rate
Verify CAPA, update rating and cycle

The three moments that decide whether a supplier audit is credible are all controls the system enforces rather than the auditor remembering. First, auditor competency: only a person scored and authorised for supplier audits should be assigned, so the assessment carries weight. Second, a single checklist: every vendor is judged against the same reusable template, so scores are comparable across the supply base. Third, issued findings with due dates: an NC that leaves your building must come back closed, not drift. Miss any of the three and the programme becomes theatre.

What a supplier-audit checklist covers

The supplier template is a scored assessment, usually organised into sections that each carry a set of questions and a weight. The exact sections depend on the commodity and the risk, but a manufacturing supplier audit almost always spans these areas:

Quality system

Certification status, document and record control, internal audits, management review and corrective-action discipline — the system behind the process.

System

Process capability

Process controls, control plans, in-process checks, machine and tooling capability, and how the supplier reacts when a parameter drifts.

Process

Measurement & traceability

Gauge calibration, MSA where required, lot traceability and the ability to contain and trace a suspect batch quickly.

Control

Add sections for incoming material control, storage and FIFO, handling and packaging, skill and training records, and — increasingly — sub-supplier management, because your supplier's supplier is now your risk too. Because each area is scored, the audit produces a number as well as a set of findings, and that number is what drives the rating and the re-audit frequency. When the checklist must change — a new commodity, a revised customer-specific requirement — it is revised under control so past audits stay tied to the version they were run against and future audits pick up the new one.

NCs, ratings and re-audit frequency

Every gap the auditor finds becomes a non-conformance carrying a requirement reference, a discrepancy description, a major-or-minor grade and a fresh-or-repetitive flag. The difference between a supplier NC and an internal one is direction: it is issued to the vendor, who owns the corrective action, while your team owns the verification. The closure loop is the same disciplined multi-role chain.

Closing a supplier NC
1
Raise and issue
The NC is logged against the failed requirement, graded major or minor, and issued to the supplier with a due date.
2
Supplier submits CAPA
The vendor records containment, root cause and corrective and preventive action — for a major NC this is where a formal 8D belongs.
3
Coordinator reviews
Your SQA coordinator checks the action plan is adequate before it advances — the second role in the sign-off.
4
Auditor verifies
The action is confirmed effective against evidence — often at the next visit — not merely marked done, before the finding closes.
5
Rate and reschedule
The score updates the vendor rating; a poor rating or repeat NCs shorten the next audit interval.

Two outputs make the programme run itself. The rating — derived from the score and the NC history — feeds the approved-vendor list and tells purchasing who is safe to buy from. The re-audit frequency is set per supplier by risk: a critical or safety-related part, a new supplier or a poor performer is audited more often; a stable, high-rated supplier of a low-risk part, less often. This risk-based cadence is exactly what IATF 16949 expects, and it beats a flat annual rotation that wastes audits on good suppliers and starves the risky ones of attention. A major supplier NC can escalate into Fast Quality's formal 8D / CAPA workflow when that module is licensed, and email and WhatsApp reminders chase overdue vendor actions automatically. For a step-by-step version aimed at the practitioner, see the supplier audit process guide on the blog.

How Fast Audit runs supplier audits

Fast Audit Software ships a dedicated supplier-audit type on the same engine that runs your internal and product audits, so a group with several plants runs one supplier-audit programme across the whole company rather than one per site. Mapping the cycle to the product:

1
Author the supplier checklist. Build a reusable, scored supplier-audit template — quality system, process capability, measurement, traceability and sub-supplier control — revised under control so every vendor is judged against the same criteria.
2
Plan the cycle by risk. Generate the audit schedule per supplier — frequency set by criticality, rating and NC history — and route it for the quality head's approval.
3
Assign a competent auditor. Only a person scored and authorised for supplier audits can be assigned, so the assessment is credible and defensible.
4
Conduct, score and issue NCs. The auditor answers each area on a mobile-friendly worklist, records the score, and raises graded NCs that are issued to the vendor with due dates and a fresh-or-repetitive flag.
5
Close, rate and report. Drive each NC to verified closure through the multi-role sign-off, update the vendor rating, and see the whole supply base on the dashboards and NC register — with reminders on overdue vendor actions.

Because it rides the shared platform, the supplier-audit programme sits alongside your ISO 9001 and IATF internal audits, your product and process audits and, for corporate teams, a multi-plant audit model — one auditor pool, one NC register, one source of truth. That is the difference between managing suppliers and merely knowing them.

Keep going — the internal-audit library
Related guides on the audit programme, plus the product pages that show how Fast Audit Software implements each part.

Frequently asked questions

What is a supplier audit?

A supplier audit is a second-party audit in which a customer organisation audits a vendor's quality system, processes and capability against a defined set of criteria. It is used to qualify a new supplier before approval, to re-audit an approved supplier on a risk-based cycle, and to investigate a supplier after a quality escape. The auditor scores the supplier against a reusable checklist, raises non-conformances for gaps, and issues them to the supplier for corrective action and verified closure.

What is the difference between a first, second and third-party audit?

A first-party audit is an internal audit an organisation runs on itself. A second-party audit is one an organisation runs on an external party it has a contract with — most commonly a customer auditing a supplier. A third-party audit is one an independent body, such as a certification registrar, runs for accreditation or certification. A supplier audit is the classic second-party audit: your team, your criteria, the vendor's site.

How do you qualify a supplier through auditing?

Qualification runs the same lifecycle as any audit: author a reusable supplier-audit checklist covering quality system, process capability, controls and documentation; plan the audit; assign an auditor competent and authorised for supplier audits; conduct the assessment scoring each area; raise NCs for gaps with a requirement reference and a major or minor grade; issue them to the supplier; and approve the vendor only once the critical findings are closed with evidence. The score and rating then feed the approved-vendor list and the re-audit frequency.

How often should suppliers be re-audited?

Re-audit frequency should be risk-based rather than a flat annual rotation. Suppliers of critical or safety-related parts, new suppliers, and suppliers with a recent quality escape or a poor rating are audited more often; stable, high-rated suppliers of low-risk parts less often. IATF 16949 expects the supplier's performance and risk to drive the monitoring frequency, so the audit interval is set per supplier from the plan and adjusted as the rating and NC history change.

What happens to non-conformances raised in a supplier audit?

Each NC is logged against the requirement it fails, graded major or minor, and issued to the supplier, who submits containment, root cause and corrective and preventive action with a due date. Your team verifies the action against objective evidence before the finding closes, and repeat NCs are flagged fresh versus repetitive so a supplier that keeps failing the same requirement is visible. Overdue actions trigger reminders, and the whole closure trail is retained as evidence for your own certification audit.

Can Fast Audit issue NCs to a supplier and track their closure?

Yes. Fast Audit ships a dedicated supplier-audit type on the shared platform. It holds the scored supplier checklist, plans the re-audit cycle per vendor, restricts assignment to auditors authorised for supplier audits, records the audit and its score, and raises graded NCs that are issued to the vendor and driven to verified closure through the multi-role sign-off, with reminders on overdue actions and escalation into Fast Quality's 8D / CAPA where licensed.

Bring your whole supply base under one audit programme

A 30-minute Fast Audit Software demo covers the supplier checklist, the risk-based re-audit cycle, vendor NCs issued and driven to verified closure, and the ratings and dashboards behind your approved-vendor list — live, on your own criteria.

Get a demo
No commitment. No slides. Your supplier-audit programme on screen.