September 24, 2026

Our last post in this series talked about how to use different supplier performance monitoring tools, which give you data that show when a supplier is slipping.

Supplier audits are how you find out why it’s happening.

While most quality teams can run a supplier audit, what’s harder is knowing which kind the situation calls for, and what to do when you can’t trust a passing score.

A full audit, a focused process review, and a risk-mapped checklist each answer different questions, which is the focus of today’s installment in our Supplier Lifecycle Toolkit series.

See how AssurX Audit Management helps you plan, track, and close supplier audits in one connected system

What are the core elements of a supplier audit?

A supplier audit is a structured evaluation against specific criteria to verify your supplier is doing what they say they’re doing. The core elements of a supplier audit are:

  • Scope and criteria: These define what you’re evaluating and the standards and requirements you’re evaluating against.
  • An audit plan: This lays out the logistics, the schedule, and who’s responsible for what.
  • An audit checklist: A checklist keeps evaluations objective and consistent from one auditor and one cycle to the next.
  • Findings and observations: Findings are the actual nonconformances or deviations from requirements. Observations aren’t full violations, but they are early warning signs that could lead to violations if left unaddressed.
  • Follow-up steps: An audit closes when the corrective and preventive actions (CAPAs) have been verified as effective and sustainable.

Over several cycles, audits surface patterns that a single inspection or scorecard won’t. They’re also useful for confirming that a past fix actually held.

“Let’s say a supplier closed out a CAPA six months ago. An audit is how you verify that fix wasn’t just temporary,” says Stephanie Ojeda, AssurX VP of Product Management and a former quality manager herself.

How do you design supplier audit criteria?

Supplier audit criteria should be based on the specifics of the relationship rather than a generic template. Well-designed supplier audit criteria are built around four elements:

  • The product: Is what you’re buying from them a critical part from a quality or safety perspective? How would a defect impact the company and end users?
  • The process: Criteria should be weighted toward processes a finished-part inspection can’t confirm, like welding, heat treatment, and sterilization.
  • The supplier’s history: A repeat finding, overdue SCARs, or a defect category that keeps appearing are important signals of where to look.
  • The regulatory requirements: Regulations and standards like FDA’s Quality Management System Regulation (QMSR) and ISO 9001 require you to define and document criteria for evaluating, selecting, and re-evaluating suppliers. Purchasing controls ranked third among FDA inspection observations on device inspections in FY 2025, all 115 of them for procedures that were never adequately established in the first place.

How do you write supplier audit questions?

Note that supplier audit checklists shouldn’t just use yes-or-no questions like:

  • Do you have a change control process?
  • Do you have a quality manual?
  • Do you have scheduled management reviews?

A supplier could theoretically answer yes to all of these and still have serious issues, so start by rewriting yes-or-no questions as requests for evidence.

“Instead of asking whether they have a CAPA process, ask them to show you the last five times they had an issue and how they determined whether they needed a corrective action,” says Ojeda.

Another way to gauge the strength of a given process is to ask the supplier to walk you through it in their own words. Then listen for whether it sounds like they’re just rattling off their SOP straight from the page.

You can apply this same logic to evaluating their risk management practices. For instance, rather than confirming that a supplier has an FMEA, ask whether they have identified the failure mode you’re concerned about (and potential failure modes more generally).

Focused process reviews

A focused process review is a targeted evaluation of one process that carries higher risk or is critical to product quality. Instead of covering a whole quality system, you zero in on a specific set of activities.

It’s the tool for getting to root cause when a broad audit keeps coming back clean. Ojeda points to one pattern that tells her an investigation stopped too early.

“Too often, I see people blame a problem on operator error, and the corrective action is simply that they retrained the operator. I hate seeing that, because it means you didn’t dig deep enough to get to what’s actually causing the issue,” says Ojeda.

A focused process review asks why the error was possible in the first place. That means looking at the work instructions, the SOP, and the process validation work done back in design and development. Common candidates for a focused review include processes like:

  • Labeling and packaging accuracy: Mislabeling is a frequent source of recalls.
  • Calibration and equipment maintenance: Out-of-tolerance equipment produces defects that inspection catches late, if at all.
  • Change control: How a supplier evaluates and executes change determines whether a validated process stays that way.
  • Cleaning and sterilization steps: In regulated production, these steps carry direct patient or consumer risk.

The tradeoff with this tool is scope. A focused review is narrow by design, so problems in areas it doesn’t examine can go unnoticed.

Risk-mapped supplier audit checklists

A risk-mapped checklist takes a standard audit checklist and tailors it to a supplier’s specific risk profile, concentrating attention where it matters most. Questions get prioritized according to risk, severity, and likelihood.

The main benefit here is that you’ll see more uniform results across your audit program.

“A risk-mapped checklist gives you structure and removes subjectivity. Even if you had two different auditors performing that audit, they’re going to reach conclusions that are consistent,” Ojeda says.

How to build a risk-based supplier audit checklist

To turn a generic checklist into a risk-mapped checklist, you’ll want to focus on five steps:

  1. Risk ranking: Define what counts as a high, medium, and low risk area for that specific supplier.
  2. Tailored questions: Ask more questions, and more demanding ones, where risk is highest. A sterile fill step might warrant several questions that each require evidence, while a low-risk indirect material gets a single confirmatory check.
  3. Weighted scoring: Give high-risk areas more weight in the total score, so a failure there outweighs a minor gap in a low-risk area.
  4. Trigger points: Set the thresholds that escalate a failed question to a corrective action.
  5. Documentation: Ensure you keep complete records of why certain areas received more focus.

That last element becomes important during external audits, where you may be asked why you focused on specific areas. An automated quality management system (QMS) helps by keeping risk rankings and audit records in the same place, so the justification is already documented rather than reconstructed after the fact.

The drawback of risk-mapped checklists is upfront effort, as building the risk analysis takes work. The benefit is that risk-based supplier audits channel your limited audit time towards problems with the biggest impact.

Supplier audit tools at a glance

The supplier audit, the focused process review, and the risk-mapped checklist each answer a different question, which is why choosing the right tool for the situation is so important.

Supplier Audit Tools Chart

Supplier Audit Tools

 

How to know when your supplier audit is complete

An audit isn’t finished until you’ve confirmed that corrective action worked and is being held in place. These are two separate checks, and skipping either one means the same finding is likely to reappear in the next cycle:

  • Was the corrective action effective? Confirm that the corrective action actually addressed the cause the investigation found.
  • Has the supplier sustained the fix over time? Re-verify months later that the fix still holds under normal production volume.

Closing an audit with only “actions promised” listed leaves both checks undone. A connected supplier quality management system supports the follow-through by linking audit findings to corrective actions and effectiveness checks, so nothing closes until the audit is truly complete.

Case study: when a supplier passes every audit, but problems continue

One manufacturer had a critical supplier that kept passing formal audits while their supplier scorecard showed declining delivery performance. The problem was that audit checklists were too broad to catch what was happening.

The team selected scheduling and production planning for a focused process review, pulling together a cross-functional team to map the workflow end to end.

This approach uncovered problems at nearly every step:

  • Order intake: Manual entry errors were introducing mistakes from the start.
  • Production scheduling: Schedules were unstable, pushing variation downstream.
  • Material allocation: No buffer stock was in place to absorb that variation.
  • Production execution: Gaps in the process created problems of their own.
  • Delivery and feedback: Metrics weren’t tracked closely enough to catch problems in time.

Interestingly, none of this showed up in the broad audit. The review also opened up a joint problem-solving opportunity with the supplier, and the whole process took a fraction of the resources a full audit would have required.

What you ask determines what a supplier audit finds

The three audit and assessment tools discussed here answer different questions. What determines their ultimate value is the quality of the criteria and whether companies completely close the loop.

“A lot of checklists get part of the way there. Doing it right is about digging deeper and seeing true evidence, rather than just a checked box,” Ojeda says.

An audit or focused review tells you where the problem is. Getting the supplier to a permanent fix is the next step, which is the focus of our next post on supplier corrective action and improvement.

CTA: Learn more about the supplier quality lifecycle in our free on-demand webinar, From Onboarding to Auditing: The Right Tools for Supplier Quality

 

Colleen: Add link to cluster post #2 when it’s live

 

Colleen: Leaving a note here for you to add a link to the final post in the series when it’s live.

 

Download a free brochure to learn about the AssurX EHS Incident Management Solution 
 

About the Author

Stephanie Ojeda is Director of Product Management for the Life Sciences industry at AssurX. Stephanie brings more than 15 years of leading quality assurance functions in a variety of industries, including pharmaceutical, biotech, medical device, food & beverage, and manufacturing.