Supplier audit process flowchart (second-party audit)

Supplier audit process flowchart template: risk-based audit programme, notification and agenda, pre-audit pack, opening meeting, evidence sampling, graded findings, corrective action plan and approved-list status.

Use this template

What the supplier audit process flowchart (second-party audit) process is

A supplier audit is a second-party audit: you are the customer, the supplier is the auditee, and the audit happens because something you buy matters enough to go and look at how it is made. The trigger in this chart is the audit programme rather than a defect. Suppliers are ranked by what the part can do to your product, which usually means safety and regulatory content, process complexity, how the supplier has performed and whether anyone independent has certified their management system, and only the ones the risk justifies are audited this cycle. From there the chart follows one audit end to end: the quality manager approving the scope and the audit team, the agenda going out, the supplier confirming access and returning a pre-audit pack, a checklist built from your own requirements, the opening meeting, sampling on the line, findings recorded against evidence, the closing meeting, a graded report, the supplier's corrective action plan, verification that the actions worked, and the effect all of that has on the supplier's approved status.

This is not supplier evaluation and it is not a corrective action request. Supplier evaluation is the recurring scorecard of quality, delivery, cost and service over a period, and it decides whether a supplier is performing; the Monitor only branch of the first decision leaves this chart for it rather than raising an audit nobody has time to do. A supplier corrective action request starts from one failed delivery and asks the supplier to fix one escape, while an audit starts from risk and examines the system that produced it. Whether a supplier may be used at all is vendor approval, and auditing your own processes with your own people is a first-party internal audit with a different independence problem. ISO 19011:2018 gives guidance on auditing management systems and covers second-party audits of external providers, but it is guidance rather than requirements: nothing here makes an audit official, accredited or certified, and the chart is a starting point to adapt under your own procedures, your customers' requirements and whatever sector regulation applies.

Four decisions carry the audit. 'Risk justifies an audit this cycle?' is the one most programmes skip, and skipping it produces an annual list nobody finishes and audits of the suppliers who are easiest to visit. 'Practice matches the documented method?' is where the audit is actually done, and it loops through 'More of the scope left to sample?' because one finding is an anecdote until the sample covers the scope you notified. 'Product already shipped at risk?' is the exception path a second-party audit needs and a first-party one rarely draws: the auditor is standing in a factory that has already despatched, and containment cannot wait for the report. 'Actions verified effective?' sits in the lead auditor's lane rather than the supplier's for the obvious reason, and its failed branch reaches an escalation with three real routes, a follow-up audit, an extended plan or removal from the approved list, because a verification with no consequence teaches suppliers that the plan is the deliverable.

What this flowchart covers

In this template

  • Five swimlanes (Supplier quality / lead auditor, Quality manager, Procurement, Supplier and Approved supplier list owner) across seven phases: audit programme, plan and notify, document review, on-site audit, findings and report, corrective action, and verification and status
  • A risk-based programme at the top, where "Audit programme built from supplier risk" ranks suppliers before anyone books a visit and "Risk justifies an audit this cycle?" routes the ones that do not clear the bar to "Cover the supplier by scorecard monitoring" rather than onto a list nobody finishes
  • Planning drawn as a two-sided exchange: the quality manager approves the scope, dates and audit team, the agenda goes out, and "Pre-audit pack complete?" loops back to "Confirm access and send the pre-audit pack" when the records do not arrive, so a thin pack delays the audit rather than wasting it
  • The sampling loop most audit charts leave out, where "Practice matches the documented method?" either records a finding or moves on and "More of the scope left to sample?" returns to "Sample records, walk the line and interview" until the notified scope is covered
  • An exception path for live product: "Product already shipped at risk?" pulls the supplier into "Contain suspect stock and flag shipments" during the audit, because stock already despatched cannot wait for the report, and the fix itself belongs to a supplier corrective action request
  • Graded findings with a consequence attached, so "Any major nonconformity raised?" can hold new orders while the plan is written, "Plan addresses root cause and escape?" sends a weak plan back for revision, and "Actions verified effective?" leads either to closure or to an escalation that can reach de-listing

When to use this template

  • You buy from a supplier whose process matters more than their paperwork, and you need one picture of how an audit of them is planned, run and closed.
  • Your audit programme exists as a spreadsheet of dates and nobody can explain why those suppliers were chosen and not others.
  • Audits are being carried out but findings die after the closing meeting, because nothing in the process verifies that the corrective action worked.
  • A customer, certification body or internal auditor has asked how you audit your own supply base, and the honest evidence is a folder of trip reports.
  • You are agreeing who may hold new orders and who may take a supplier off the approved list, and at what point that decision leaves the buyer.

How it works

  1. Rename the lanes to your roles

    Replace Supplier quality / lead auditor, Quality manager, Procurement, Supplier and Approved supplier list owner with the roles you genuinely have. Small organisations often merge the first two, and the approved supplier list is frequently kept by procurement or by master data rather than by quality. Keep the Supplier lane whatever you do: it marks the four steps that depend on somebody outside your organisation, which is where the cycle stalls.

  2. Write your selection rule onto the first decision

    Put a real rule on 'Risk justifies an audit this cycle?' rather than a feeling. Most programmes combine the criticality of the part, whether it carries safety or regulatory content, the supplier's recent performance and whether an independent body has certified their management system. Record the interval each risk band earns and what resets it, then note who signs off a supplier being skipped.

  3. State what the pre-audit pack must contain

    List it on 'Confirm access and send the pre-audit pack': the process map, control plan or equivalent, the last internal audit and management review outputs, calibration and training records for the relevant operations, and change history for your parts. Also record the deadline and what happens when it is missed, because the Gaps branch is otherwise a polite loop with no end.

  4. Define the finding grades before the audit

    Agree what makes a finding major, minor or an observation, write it into the audit plan and issue it with the agenda. Attach a response deadline to each grade and a consequence to the top one. Grading argued out at the closing meeting is grading the supplier negotiates, and it makes findings from different auditors impossible to compare across the programme.

  5. Set the containment and order-hold rules

    Decide who may trigger 'Contain suspect stock and flag shipments' from inside an audit and how far it reaches: the supplier's finished stock, material in transit, your own stores and work in progress. Then write the rule behind 'Hold new orders until the response lands', which is usually the affected part rather than everything the supplier makes, and name who can lift it.

  6. Fix the verification method and its window

    State how 'Actions verified effective?' is answered: evidence you nominate rather than evidence the supplier offers, over a defined window such as a number of deliveries or a return visit. Standards guidance treats a follow-up audit as one legitimate way to verify. Say who may close a major finding, and record that no finding closes on a promise.

  7. Walk it against a completed supplier audit

    Take two finished audits, one that closed cleanly and one that dragged, and trace them through the chart. Anything people describe that is not drawn, or drawn but skipped in practice, is worth fixing before you publish it. Pay particular attention to what actually happened between the report and closure, which is where most supplier audit processes turn out to be undocumented.

Frequently asked questions

What are the steps in a supplier audit process?

The programme is built from supplier risk, and a first decision settles whether that risk justifies an audit or whether scorecard monitoring covers the supplier. The quality manager approves the scope, dates and audit team, the agenda goes out, and the supplier confirms access and returns a pre-audit pack, which loops back if it arrives incomplete. The lead auditor builds a checklist from your own requirements, holds the opening meeting, then samples records, walks the line and interviews staff. Where practice does not match the documented method the gap is recorded against objective evidence, and if shipped product is at risk the supplier contains stock during the audit; sampling continues until the scope is covered. The closing meeting agrees the facts, the report grades each finding, a major one can hold new orders, and the audit closes only once the actions are verified effective.

What is the difference between first-party, second-party and third-party audits?

ISO 19011:2018 sets the terms out plainly. A first-party audit is an internal audit, conducted by or on behalf of the organisation itself. A second-party audit is an external audit conducted by a party with an interest in the organisation, typically a customer auditing an external provider, which is what this chart draws. A third-party audit is conducted by an independent auditing organisation, such as a certification body or a governmental agency. The practical difference is authority. In a first-party audit you can compel access, set the method and read any record you like. In a second-party audit you can ask, and what you get is governed by the contract and by what the supplier is prepared to show, with areas holding another customer's work commonly off limits. Your audit also certifies nothing: it is your own assessment for your own purposes, not accreditation.

Who should lead a supplier audit, and can the buyer do it?

The lead auditor should be competent in the process being audited and independent of the commercial relationship, which in most organisations means supplier quality rather than the buyer. That is not a slight on purchasing. The buyer owns the price, the delivery schedule and the relationship, and asking them to write a major nonconformity against a supplier they are mid-negotiation with puts two incompatible jobs on one person. Procurement still has a real part in this chart: chasing the pre-audit pack, holding new orders while a major finding is answered, and carrying the escalation if verification fails. The finding itself stays with the auditor. Where the same person genuinely does both, have the report reviewed by someone else before it is issued, and record who approved the scope and the audit team so the independence question has an answer.

What makes a finding a major nonconformity rather than a minor one?

There is no universal definition. ISO 19011:2018 is explicit that nonconformities can be graded depending on the context of the organisation and its risks, and that the grading can be quantitative, such as a scale of 1 to 5, or qualitative, such as minor and major. The grade is therefore yours to define, and the place to define it is the audit plan issued with the agenda rather than the closing meeting where the supplier is arguing about it. A common working split is that a major nonconformity is a systemic breakdown, an absent control or anything that puts conforming product at risk; a minor is a single lapse in a control that otherwise works; and an observation is a risk that has not yet produced a nonconformity. Write your own version down, attach a response deadline to each grade, and state what a major does to orders.

How often should suppliers be audited?

Risk sets the frequency rather than the calendar. ISO 9001:2015 clause 8.4.1 requires an organisation to determine and apply criteria for the evaluation, selection, monitoring of performance and re-evaluation of external providers, and to retain documented information of those activities and the actions arising, but it names no interval and does not require an audit at all. The automotive sector is more prescriptive: IATF 16949:2016 clause 8.4.2.4.1 requires a documented second-party audit process, with criteria for determining the need, type, frequency and scope of those audits from a risk analysis covering product safety and regulatory requirements, supplier performance and the level of quality management system certification. In practice a supplier making a safety-critical part with no independent certification earns a visit far more often than a distributor of catalogue items.

Use this template

More in Audit and inspection process templates

More in Process flowchart templates

Browse all Audit and inspection process templates