Supplier quality audit checklist, section by section
A supplier quality audit checklist is only useful if each line names the evidence the auditor must see and the score that evidence earns. Without scoring criteria, two auditors visit the same fabricator and come back with two different verdicts.
This checklist covers the ten sections that decide whether a supplier can hold quality at rate: management system, personnel competence, design and document control, purchasing and sub-tier control, incoming inspection, process control, measurement equipment, nonconformance and CAPA, traceability and preservation, and final release.
Each section carries a 0–4 score. The weighted total, together with mandatory-fail rules, converts the audit into one of three decisions — approved, approved with conditions, or rejected — and sets the surveillance frequency that follows.
- 01Score every section 0–4 against defined criteria; never leave a yes/no box.
- 02Mandatory-fail items override a good total score — no calibration, no approval.
- 03Sub-tier control is where most supplier audits find the real risk.
- 04The audit result must set surveillance frequency, not just an approval flag.
What a supplier quality audit covers
A supplier quality audit is a second-party audit: you, the buyer, assess a supplier's ability to consistently meet your technical, quality and delivery requirements. It differs from a certification audit in scope and intent — you are not testing conformance to ISO 9001 as an end in itself, you are testing whether this supplier can build your part, to your specification, at your rate, with evidence you can accept.
- Define the scope: the commodity, the process, the site and the shift being assessed.
- Send the checklist and document request list at least two weeks ahead.
- Desktop review first — quality manual, procedures, certifications, sub-tier list, performance data.
- On site: opening meeting, process walk, evidence sampling, closing meeting with preliminary scores.
- Trace one live order end to end, from purchase order through release documentation.
- Score each section, apply mandatory-fail rules, issue the decision and surveillance plan.
- Track findings to verified closure — an audit with an open finding log is not complete.
Ten sections — question, evidence, weighting
Copy these rows into your own audit template and add commodity-specific lines (welding, coating, electronics, castings) under the process control section.
| Section | Audit question | Objective evidence to sample | Weight |
|---|---|---|---|
| 1. Quality management system | Is there a documented QMS, certified or otherwise, with defined scope, current procedures and evidence of management review? | Quality manual, certificate and scope, management review minutes, internal audit programme and findings. | 10% |
| 2. Organisation and competence | Are quality roles independent of production, and is competence for special processes qualified and current? | Org chart, job descriptions, welder/NDT/operator qualification records with expiry dates, training effectiveness records. | 10% |
| 3. Contract and document control | Are customer drawings, specifications and revisions controlled and current at point of use? | Drawing register with revision status, contract review records, controlled copies at workstations, obsolete document handling. | 10% |
| 4. Purchasing and sub-tier control | How are sub-tier suppliers approved, monitored and flowed down customer requirements? | Approved supplier list, flow-down clauses in purchase orders, sub-tier audit reports, material certificates (EN 10204 3.1/3.2). | 15% |
| 5. Incoming inspection | Is purchased material verified against specification before release to production? | Goods-in inspection records, sampling plan, mill certificates matched to heat numbers, quarantine area for unverified stock. | 10% |
| 6. Process control | Are control plans, work instructions and in-process checks defined and followed at the workstation? | Control plan, work instructions at the station, in-process check sheets, special process parameter records (WPS/PQR, oven charts, plating logs). | 15% |
| 7. Measurement equipment | Is all inspection, measuring and test equipment calibrated, traceable and within due date? | Calibration register, certificates traceable to national standards, gauge R&R studies, out-of-calibration impact assessments. | 10% |
| 8. Nonconformance and CAPA | Are nonconformities recorded, dispositioned and corrected to verified root cause? | NCR log, concession/deviation approvals with customer sign-off, 8D or CAPA records, effectiveness verification. | 10% |
| 9. Traceability, handling and preservation | Can material be traced from heat/lot to finished part, and is product protected through storage and transit? | Job travellers, heat/lot traceability chain, storage conditions, packaging and preservation specification, shelf-life control. | 5% |
| 10. Final inspection and release | Is there objective evidence of conformity and authorised release for every shipment? | Final inspection reports, ITP sign-offs, certificates of conformity, dimensional and test reports, release authority matrix. | 5% |
The 0–4 scoring criteria
Score every section against the same definitions so results are comparable across auditors, commodities and regions.
| Score | Definition | What the auditor saw |
|---|---|---|
| 4 — Effective | Requirement is documented, implemented and demonstrably effective. | Procedure exists, records sampled across shifts all conform, and performance data shows the control working. |
| 3 — Conformant | Documented and implemented, minor gaps with no impact on product. | One record missing a signature; process otherwise consistent. |
| 2 — Partially implemented | Documented but inconsistently applied. | Procedure exists, but two of five sampled jobs skipped the required check. |
| 1 — Documented only | Written down, not practised. | A control plan exists in the binder; nobody on the floor uses it. |
| 0 — Absent | No system, or evidence contradicts the claim. | No calibration register; gauges in use with no due dates. |
≥ 85% — Approved
Added to the approved vendor list for the audited scope. Re-audit every 24 months with annual desktop review.
65–84% — Conditional
Approved for the scope subject to a corrective action plan with dated closure. Re-audit in 12 months; increase source inspection meanwhile.
< 65% — Rejected
Not approved for the scope. Re-audit only after a documented improvement programme and evidence of sustained change.
From score to decision
The audit report should state the scope audited, the evidence sampled, the score per section, every finding with its objective evidence, the overall decision and the surveillance regime that follows. Write the finding in three parts — the requirement, the evidence, the gap — and leave the corrective action to the supplier. A finding that prescribes the fix transfers ownership of the problem to you.
- Step 01At the closing meeting
Classify each finding
Major where the failure can reach your product or the system has broken down; minor for isolated lapses; observation for risks not yet realised.
- Step 02Within the audit
Agree dates, not just actions
Every finding needs a named owner and a closure date agreed before the auditor leaves site.
- Step 0330–90 days
Verify effectiveness
Close majors on evidence — records from after the change, not a revised procedure alone.
- Step 04Ongoing
Set surveillance
Feed the score into inspection level: approved suppliers on document review, conditional suppliers on witness or hold points until the trend proves out.
What supplier audits miss most often
- Sub-tier control: the supplier is capable, but the critical coating or heat treatment sits with an unaudited subcontractor.
- Flow-down: your specification, NDT requirement or certificate type never reaches the purchase order the supplier issues.
- Capacity versus rate: the process works for a sample and collapses at production volume across three shifts.
- Calibration of the gauge that matters: general calibration is in order, but the one fixture measuring the critical dimension is uncontrolled.
- Record integrity: inspection sheets completed in one hand, one ink, one sitting — signed after the fact rather than at the operation.
- Change control: process, tooling or sub-tier changed since approval with no notification to the customer.
One audit is a snapshot; a programme is control
Scoring one supplier tells you where they stood on the day of the visit. Control comes from the programme around it: risk-ranked audit frequency, pre-qualification before the first purchase order, surveillance and source inspection sized to the score, and performance data feeding the next re-audit. If your approved vendor list has no re-evaluation evidence behind it, the audit checklist is not the constraint — the programme is.
Need supplier audits run independently?
Our lead auditors run second-party supplier and sub-tier audits across North America — scored, reported and tracked to verified closure.
Auditing a supplier you haven't bought from yet?
Pre-qualification assesses capability, capacity and financial and technical standing before the first purchase order — and sets the AVL category and surveillance level.
Questions we get on this topic
What should a supplier quality audit checklist include?
It should cover the quality management system, competence of personnel, document and drawing control, purchasing and sub-tier control, incoming inspection, process control, calibration of measuring equipment, nonconformance and corrective action, traceability and preservation, and final inspection and release. Each line needs the audit question, the objective evidence to sample and a defined score — not a yes/no box.
How is a supplier audit scored?
The common approach is a 0–4 scale per section — 0 absent, 1 documented only, 2 partially implemented, 3 conformant, 4 effective — weighted by section importance and totalled as a percentage. Typical thresholds are approval at 85% or above, conditional approval between 65% and 84%, and rejection below 65%, with mandatory-fail items such as missing calibration or traceability overriding the total.
What is the difference between a supplier audit and a certification audit?
A supplier audit is a second-party audit performed by the customer to confirm a supplier can meet their specific requirements. A certification audit is a third-party audit by an accredited body assessing conformance to a standard such as ISO 9001. An ISO 9001 certificate is useful evidence in a supplier audit, but it does not replace one — it says nothing about whether the supplier can build your part to your specification.
How often should suppliers be audited?
Frequency should be risk-based rather than fixed. In practice, critical suppliers are typically audited every 12 to 24 months, with more frequent audits after a poor score, a major nonconformance, a process or ownership change, or a move of production to a new site or sub-tier.
Who should perform a supplier quality audit?
An auditor competent in both auditing technique and the supplier's process, and independent of the commercial relationship. Buyers auditing their own suppliers face an obvious conflict of interest, which is why many organisations use qualified independent auditors for critical commodities and sub-tier assessments.
What is a supply chain audit?
A supply chain audit extends beyond the direct supplier to the sub-tiers behind them — the mills, coaters, heat treaters and processors whose work reaches your product. It follows the same checklist structure but focuses on flow-down of requirements, traceability across tiers, and whether the direct supplier is genuinely controlling the parties they subcontract to.
Quality briefs, straight to your inbox
Field-tested guidance on inspection, audits and project quality systems — one issue on the first Tuesday of each month, written for people who have to make them work.
See past issues →- Vendor surveillance and inspection servicesWhat to do after the audit: ongoing surveillance at the supplier's shop floor.
- Factory acceptance testing: scope, checklist, witnessingScoping and witnessing FAT so equipment is proven before it leaves the works.
- What is a Non-Conformance Report (NCR)?How to raise, track and close the findings an audit produces.
Put a scored supplier audit programme in place
We design the checklist, run the audits, score the results and manage the approved vendor list — with surveillance sized to each supplier's risk.
