<img src="https://secure.office-information-24.com/785669.png" style="display:none;">
Glossary

Supplier Audit

Also called: Vendor Audit
A supplier audit is an evaluation, conducted by a purchasing organization or its representative, of a supplier's quality management system, manufacturing processes and overall capability to reliably meet requirements. Supplier audits are commonly performed before approving a new supplier and periodically afterward, particularly for suppliers providing critical components, materials or services, or those with a history of quality issues. 

Quick facts

Category On-site or remote evaluation of supplier capability
Used by Manufacturing, medical devices, pharmaceuticals, aerospace, automotive and other regulated industries
Also called None widely standardized
Related standards ISO 9001, ISO 13485, AS9100, IATF 16949
Related processes Supplier evaluation, SCAR, external audit, audit management
Semantic match supplier audit, vendor audit, supplier qualification audit, on-site supplier evaluation

What is Supplier Audit?

A supplier audit evaluates whether a supplier's quality system, processes and practices are capable of reliably meeting the purchasing organization's requirements. It is a specific type of second-party external audit, conducted by, or on behalf of, the organization purchasing from that supplier.

Supplier audits are commonly conducted before a new supplier is approved, examining their quality management system, key manufacturing or service processes, and relevant certifications. They may also be conducted periodically afterward, particularly for suppliers providing critical or high-risk items, or in response to declining performance or recurring nonconformances.

A supplier audit typically results in a report identifying strengths, gaps and any required corrective actions, feeding directly into the broader supplier evaluation and approval process.

Why is Supplier Audit important?

A supplier audit provides direct, first-hand evidence of a supplier's actual capability, going beyond self-reported survey responses or historical performance data alone.

For critical or high-risk suppliers, an audit can uncover process weaknesses or gaps that might not yet be visible in performance metrics like on-time delivery or defect rates, allowing issues to be addressed proactively.

Regular supplier audits, particularly for key suppliers, demonstrate to customers and regulators that an organization actively verifies its supply chain rather than relying solely on paperwork or historical trust.

How does Supplier Audit work?

A typical supplier audit process includes:

  1. Scheduling. Identify which suppliers require an audit, based on risk, criticality or performance history.
  2. Scope definition. Determine what will be evaluated, such as the QMS, specific processes, or both.
  3. On-site or remote audit. Conduct the audit through interviews, observation and record review.
  4. Findings. Document strengths, gaps and any nonconformances identified.
  5. Corrective action. Route significant findings into a SCAR or corrective action process.
  6. Follow-up. Verify corrective actions and reassess the supplier's status as needed.

Supplier Audit vs. Internal Audit

Comparison Supplier Audit Internal Audit
Auditee An external supplier The organization's own processes
Purpose Evaluate supplier capability and qualification Verify conformance of internal processes and records

Real-world examples of Supplier Audit

A medical device company conducts a supplier audit before qualifying a new component manufacturer, reviewing their ISO 13485 certification, process controls and incoming inspection practices before final approval.

An automotive supplier conducts a periodic audit of a critical supplier following a recent quality decline, identifying a training gap and issuing a SCAR to address it.

An aerospace manufacturer performs remote supplier audits for lower-risk vendors while reserving on-site visits for suppliers providing safety-critical components.

Regulations and standards related to Supplier Audit

ISO 9001 Clause 8.4 requires organizations to determine and apply criteria for supplier evaluation, and supplier audits are a common, though not the only, method used to gather the evidence needed to apply those criteria for higher-risk suppliers.

ISO 13485, AS9100 and IATF 16949 place stronger emphasis on formal supplier audit programs given the criticality of components in medical device, aerospace and automotive supply chains, often expecting documented audit criteria, findings and follow-up.

Required by

How QT9 helps with Supplier Audit

QT9 QMS supplier audit capabilities

  • Schedule and track supplier audits alongside internal and external audits.
  • Build custom audit checklists tailored to supplier type and risk.
  • Auto-generate SCARs directly from supplier audit findings.
  • Link supplier audit results to broader supplier evaluation scorecards.
  • Maintain a complete, timestamped record of every supplier audit.
  • Prioritize audit scheduling using risk and performance trend data.

Request an Audit Management Demo Explore Audit Management Software →

See QT9 Software in Action

Discover how QT9 Software helps manufacturers improve efficiency, strengthen compliance and connect quality management and ERP processes within one integrated platform.

Common mistakes with Supplier Audit

Common mistakes include applying the same audit depth and frequency to every supplier regardless of risk or criticality, spreading limited audit resources too thin across low-risk vendors.

Other problems include failing to follow up on supplier audit findings with a formal corrective action process, and not connecting audit results to the broader supplier evaluation and scorecard data used for sourcing decisions.

Frequently asked questions

Supplier audits are commonly conducted before approving a new supplier and periodically afterward, particularly for suppliers providing critical items, high-risk components, or those with a history of quality issues.
A supplier audit evaluates a supplier's overall quality system and process capability. A SCAR is a formal request addressing a specific nonconformance, which may result from findings identified during a supplier audit.
Yes. Many organizations conduct remote supplier audits for lower-risk suppliers, reserving on-site visits for higher-risk or safety-critical suppliers where direct, in-person observation adds significant value.
Higher-risk or critical suppliers are typically audited more frequently, while lower-risk suppliers may be audited less often or evaluated through other methods, such as surveys or performance data review.
Significant findings are typically routed into a formal corrective action process, such as a SCAR, requiring the supplier to investigate root cause and implement corrective action before the finding is closed.
Supplier audit results are commonly incorporated into broader supplier evaluation scorecards, combining audit findings with other performance data such as on-time delivery and nonconformance rates for a complete supplier assessment.

Related quality management terms

Related content

Ready to Transform Your Business?

See how QT9 Software helps manufacturers simplify operations, improve traceability and drive continuous improvement with integrated quality management and ERP software.

Last reviewed: July 21, 2026