Food supplier approval process flowchart (documentation to approved list)

Food supplier approval flowchart template: risk category, documentation request (specs, food-safety certification, insurance, allergen statement), review, risk-based audit or questionnaire, trial order and approved supplier list.

Use this template

What the food supplier approval process flowchart (documentation to approved list) process is

Food supplier approval is what happens between a new source being identified and that source being trusted with something that ends up in a finished product. The chart below follows one supplier end to end. A risk category is assigned first, because that single decision sets how much is asked for downstream: a raw material that carries an allergen or reaches the consumer with no further kill step earns a deeper file than a corrugated case supplier. Documentation is requested and submitted (specifications, food-safety certification, insurance, an allergen statement), checked for gaps, and reviewed against your own acceptance requirements. The risk category then routes the supplier to either an on-site audit or a questionnaire, findings that fall short trigger a corrective action plan and a re-check, and a trial or sample order is evaluated against spec before an approval decision is made. A critical or high-risk supplier picks up an extra layer of sign-off; every approved supplier is added to the list with the file that got them there, and a periodic trigger — not just a date on a calendar — reopens the record for reassessment.

This is the food-safety-specific overlay on supplier approval, not a replacement for the generic processes it sits on top of. Deciding how much scrutiny any third party deserves, scored on data access, spend and dependency rather than on what they manufacture, is the broader supplier risk assessment; this chart assumes that judgement already exists and adds the certification, allergen and trial evidence a food business specifically needs. Comparing two or three candidate suppliers against each other before either one reaches this gate is supplier selection; this chart starts once a single source has been chosen and asks whether that source is fit to use, not which of several is best. The recurring scorecard that follows an already-approved supplier through quality, delivery and cost over time is supplier evaluation, and the periodic, risk-based second-party audit cycle that keeps checking an approved supplier's system on their own site is the supplier audit process; the on-site audit branch here is the same kind of activity performed once, at the gate, and this chart hands the supplier off to that recurring cycle the moment they are listed. It is not the internal changeover and line-clearance controls that keep one allergen out of another product once ingredients are already on your floor — that is a separate, plant-side process. Treat this chart as a starting point to adapt under your own procedures, the regulations that apply to your product and site, and whichever certification scheme you hold.

Three decisions carry the process. "Audit or questionnaire route?" is where the risk category earns its keep: routing every supplier through the same depth of check, regardless of what they actually handle for you, is what turns a risk-based programme into an audit backlog nobody finishes. "Meets acceptance criteria?" is deliberately three-way rather than a pass/fail gate, because a trial order that is close but not there is common enough to need its own route — a second trial — rather than being forced into an early decline or a quiet pass. And "Reassessment due?" is what stops the approved supplier list from being a one-time judgement wearing a permanent-looking status: a certificate nearing expiry, a complaint or a change to what the supplier ships should reopen the record before the scheduled review date does.

What this flowchart covers

In this template

  • Four swimlanes (Procurement, Supplier, Quality / Food Safety and Management) across six phases: identify and categorize, request documentation, review and verify, audit or questionnaire, trial and decide, and list and reassess
  • A risk category assigned before anything is requested, so "Documentation complete and current?" and everything after it is checked against a file whose depth already matches what this supplier handles, rather than a fixed universal document set
  • A "Documentation complete and current?" loop that sends gaps or expired certificates back to Procurement to chase rather than letting a thin file drift into the audit stage unnoticed
  • "Audit or questionnaire route?" splitting the risk category into two real paths — an on-site audit with its own "Audit findings acceptable?" loop through a corrective action plan, or a questionnaire reviewed on paper — that reconverge once either one clears
  • A trial or sample order received, shipped and evaluated against spec and food-safety acceptance criteria, with "Meets acceptance criteria?" branching three ways: approve, request a second trial, or decline
  • A "Critical or high-risk supplier?" gate that adds a Management sign-off before listing, and a closing "Reassessment due?" decision that either confirms the supplier active under scheduled review or reopens the record and loops back to risk categorization

When to use this template

  • You are writing or revising a food supplier approval procedure and need one picture of how a new ingredient, packaging or co-packer source is categorized, documented, checked and listed.
  • Suppliers are being added to your approved list on the strength of a specification sheet alone, and the certification, allergen and trial evidence a food business needs is missing or inconsistent from one supplier file to the next.
  • You need the depth of due diligence to scale with risk, so a low-risk packaging supplier is not sent through the same audit as a high-risk allergen-carrying ingredient supplier.
  • A customer, certification body or auditor has asked how you approve food suppliers, and the honest evidence is a folder of certificates nobody checked for scope or expiry.
  • Suppliers stay on the approved list indefinitely once they are added, and you need a documented trigger — not just a renewal date — that pulls a supplier back through re-approval.

How it works

  1. Rename the lanes to your roles

    Replace Procurement, Supplier, Quality / Food Safety and Management with the roles you actually have. A smaller operation often merges Quality and Food Safety into one function and may not have a separate Management lane at all, in which case fold the sign-off step into Quality / Food Safety and note who within that role holds the authority.

  2. Write your risk categorization criteria onto the first step

    Put a real rule on "Assign a risk category" rather than a feeling. Typical inputs are whether the item carries an allergen, whether it reaches the consumer with no further kill step, how much of your product it goes into, and whether the supplier is single-source. Record what each category requires downstream: document depth, audit versus questionnaire, and reassessment interval.

  3. Define your accepted document set and certification schemes

    List what "Send the documentation request" actually asks for at each risk category, and name which certification schemes your review accepts as adequate evidence — a GFSI-recognized scheme such as BRCGS, SQF or FSSC 22000, a customer-specific standard, or none where your own inspection carries the weight instead. State what makes an allergen statement acceptable: every allergen your own labeling rules require you to declare, not just the ones on the supplier's label.

  4. Set the audit-versus-questionnaire threshold and the audit scope

    Decide which risk categories require an on-site audit and which are covered by a returned questionnaire, and put that rule on "Audit or questionnaire route?" directly. Separately, write what the audit itself actually checks for your products — hygienic design, allergen segregation, pest control, traceability — since a generic checklist run against every supplier regardless of what they handle produces findings that do not distinguish a real risk from a paperwork gap.

  5. Fix your trial order acceptance criteria

    Write down what "Meets acceptance criteria?" is actually testing: the certificate of analysis against limits from your own specification, whatever incoming tests your quality plan calls for, and whether the product, its lot coding and its packaging match the allergen statement already on file. Decide in advance what counts as marginal rather than a clear pass or fail, so the second-trial branch has a real trigger instead of becoming a way to avoid a decline.

  6. Name what makes a supplier critical or high-risk for sign-off purposes

    The Management gate only means something if it is reserved for suppliers where it matters. Typical triggers are a single-source dependency, an allergen-carrying ingredient with no available substitute, or a supplier feeding a product with prior recall history. Everything else should list without that extra step, or the sign-off becomes a rubber stamp applied to every file.

  7. Set your reassessment triggers, then walk it against a real supplier file

    Attach a review interval to each risk category and list the events that pull a supplier back through the chart early: a certificate approaching expiry, a complaint, a recall involving that supplier, or a change to what they ship you. Then take two supplier files, one that went smoothly and one that needed a corrective action plan or a second trial, and trace them through the chart to find what people describe that is not actually drawn.

Frequently asked questions

What are the steps in a food supplier approval process?

A new ingredient, packaging or co-packer supplier is assigned a risk category first, which sets how much is asked for downstream. Procurement sends a documentation request and the supplier returns specifications, food-safety certification, insurance and an allergen statement; gaps or expired items are chased before review continues. Quality or Food Safety reviews the file against its own acceptance requirements, then the risk category routes the supplier to either an on-site audit, where major findings trigger a corrective action plan and a re-check, or a questionnaire reviewed on paper. A trial or sample order is placed, shipped and evaluated against spec and food-safety acceptance criteria; the result is approved, sent for a second trial if marginal, or declined. A critical or high-risk supplier picks up a Management sign-off, the approval is recorded and the supplier is added to the approved list, and a periodic trigger later reopens the record for reassessment.

How is this different from a generic supplier risk assessment or supplier audit?

They answer different questions and sit at different points in time. A generic supplier risk assessment scores any third party — a software vendor, a logistics provider, a food ingredient supplier — on data access, spend and dependency to decide how much due diligence they warrant; this chart assumes that judgement is already in hand and adds the food-safety-specific evidence (certification scope, allergen statement, trial order) a food business needs on top of it. A supplier audit, in the generic sense, is the recurring second-party audit programme that keeps checking a supplier who is already approved and already shipping; the on-site audit branch in this chart is that same kind of activity performed once, at the gate, before the supplier is ever on the approved list, and this chart hands the relationship off to that recurring programme the moment approval is recorded.

What documents should a food supplier approval file contain?

There is no single universal list, because what a supplier needs to provide scales with what they actually supply and with the regulations and certification scheme that govern your own site. Common items are a current specification for the item, a food-safety certificate (from a GFSI-recognized scheme such as BRCGS, SQF or FSSC 22000, or another scheme your customers or regulator accept), proof of product liability insurance, and an allergen statement covering every allergen your labeling rules require you to declare. For a higher-risk supplier, a completed audit or questionnaire result and a certificate of analysis from a trial order are typically added. Define your own list against your own risk categories rather than adopting this one uncritically, and note the certificate scope and expiry date rather than just its existence.

Does approving a supplier through this process satisfy HACCP or FSMA requirements?

No single template can make that claim, because the requirement that applies depends on your product, your facility and where you operate. In the United States, facilities subject to FDA's Preventive Controls for Human Food rule with a hazard that needs a supply-chain-applied control fall under 21 CFR Part 117 Subpart G, and 117.420 specifically requires using approved suppliers and documenting the basis for approval — but Subpart G does not apply to every facility or every hazard, and importers carry a separate set of obligations under the Foreign Supplier Verification Program (21 CFR Part 1, Subpart L). Outside the US, Codex Alimentarius's General Principles of Food Hygiene sets out the broader expectation that incoming materials are controlled, without prescribing this specific procedure, and a GFSI-recognized scheme such as BRCGS, SQF or FSSC 22000 layers its own supplier-approval and monitoring requirements on top if you hold one. Treat this chart as an adaptable starting point and confirm what actually applies with whoever manages your regulatory and certification compliance.

What should trigger a supplier's reassessment or removal from the approved list?

Frequency by risk category is the baseline — a higher-risk supplier is reassessed more often than a low-risk one — but a fixed calendar interval alone misses most of the events that actually matter. A certificate nearing expiry, a customer or regulatory complaint traced to that supplier, a recall involving something they supplied, a change of ownership or manufacturing site, or a change to what they ship you should all reopen the record before the scheduled date arrives. Removal follows the same logic as the initial decline: a specific, recorded reason, and a route back to reapplication where the gap is one the supplier could plausibly close, such as an expired certificate, rather than a repeat food-safety failure.

Use this template

More in Food & beverage manufacturing process templates

More in Process flowchart templates

Browse all Food & beverage manufacturing process templates