Back to Glossary

Entry · Business

Supplier Audit

A supplier audit is a structured check of a supplier against agreed requirements, using evidence such as records, interviews, process observation and tests. It can examine quality, safety, labour practices or security, depending on the goods and risks. Findings need follow-up, not just a score.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A food importer depends on a factory to keep production hygienic. A certificate or sales promise may help, but the importer may need to check how controls work in practice, so a supplier audit sets criteria and examines evidence.

Start by defining the purpose: a quality audit might examine production checks, traceability and handling of defects, while a software vendor audit might focus on access, incident response and subcontractors. Auditing rights should be understood before a visit or remote review, since the contract may specify notice, scope, confidentiality and access to records, and a buyer cannot assume it may inspect every document or employee without permission.

Select suppliers based on risk, weighing criticality, customer impact, past failures and the ease of replacement; a low-risk stationery vendor may not need the same depth of review as a sole-source ingredient supplier. ASQ describes supplier quality management as a continuing effort, from supplier selection through the relationship, with an audit as one tool alongside performance monitoring and corrective action, so a single visit is not a complete supplier programme.

Set criteria before asking questions, using the purchase specification, relevant contract terms and applicable standards, and avoid marking a finding against a rule that the supplier never agreed to and that law does not require. Gather more than one type of evidence by reviewing procedures, logs and training records and comparing them with work on site or a sample of transactions, because a well-written policy does not prove that staff follow it.

Remote audits can work for records and interviews but may be less effective for observing a production line or physical storage, so choose the method to fit the risk and access available, not merely the cheapest option. Auditors should understand the process and stay objective, since someone who approved the same work may struggle to challenge it, and a qualified internal reviewer or specialist should be used when the subject demands technical expertise.

Keep a clear trail of what was sampled: an audit rarely reviews every order or every day of production, so state the period, locations and records covered and avoid claiming that the whole supplier is safe from one sample. Classify findings by consequence and evidence, because a missing signature on one low-risk form differs from repeated failures of a critical control, and define severity criteria rather than giving every item the same label.

Agree on corrective actions with an owner and due date, ask for root cause, not merely a promise to retrain staff, and recheck that the fix was implemented and works before closing a significant finding. A repeated issue may require a wider decision such as increased inspection, an improvement plan, an alternate supplier or paused orders, balancing continuity needs with risk.

Communicate findings clearly and fairly, letting the supplier correct factual misunderstandings while keeping supported observations in the record, because good relationships improve when both sides know what must change and how success will be checked. An illustrative audit pass rate divides suppliers meeting defined criteria by suppliers audited in a period, so seventeen passes among twenty audits is 85%, but this can be misleading if the hardest suppliers were deliberately selected or criteria changed.

Track more useful measures too, such as repeat critical findings, overdue actions, defect rates and supplier delivery performance, because a high pass rate is not a goal if it encourages weak tests, so define the sample before celebrating the number. A certificate may show that a system was assessed to a standard at a point in time, so check scope, validity and whether it covers the relevant site and service, and remember that audit depth should follow the harm of failure, with the value lying in better assurance and decisions, not the number of visits.

In practice

Real-world examples.

1

Example

A food importer checks hygiene records and observes an agreed production process. The auditor compares the cleaning log with what happens on the line during the visit. Gaps between the two become findings with an owner and a due date.

2

Example

A retailer reviews evidence on a supplier labour standard within the audit scope. The team samples payroll and working-hours records for a stated period and interviews workers where the contract allows. The report states exactly which records and sites were covered.

3

Example

A software buyer checks whether a vendor follows its agreed access-control process. The review looks at user-access lists, leaver records and incident logs rather than the policy document alone. One significant finding is rechecked after the fix before it is closed.

Formula

Calculation

Illustrative audit pass rate = suppliers meeting defined criteria / suppliers audited x 100. 17 / 20 = 85%; selection and criteria affect interpretation. A companion measure is the overdue action rate = corrective actions past their due date / open corrective actions x 100. If 6 of 24 open actions are overdue, the rate is 6 / 24 x 100 = 25%. Read it alongside the pass rate, because a supplier can pass an audit and still be slow to fix the findings.

Case study

Seen in the real world.

This entirely fictional example follows Palm Foods, an invented importer that found inconsistent sanitation records at a critical supplier. It agreed a corrective plan, identified an action owner and checked evidence after the deadline. The importer also increased incoming checks while the issue remained open. The example does not claim annual audits alone prevent recalls.

Watch out

Common mistakes.

  • Relying on a certificate without checking site and service scope.
  • Closing findings when a plan is promised but no fix is verified.
  • Treating an audit pass rate as assurance without considering what was sampled.

Questions

People also ask.

What is a supplier audit?

A structured review of a supplier against agreed requirements using evidence.

What does it cover?

It depends on the supplier and contract; quality, safety, labour, environment and security may be relevant.

How often?

Set frequency by criticality, past performance and risk rather than using one interval for all suppliers.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.