Vendor approval process flowchart template
A vendor approval process flowchart template: questionnaire, quality and financial checks, risk tiering, audit, trial order and the approved vendor list.
How it works
Open the template as a chart
Open the vendor approval process template and use it as a new chart. Nothing is locked: every lane, step and branch can be renamed, moved or deleted.
Rename the lanes to your roles
Replace Requester, Procurement, Quality, Finance and Approval authority with the roles that actually exist. If Quality and Procurement are the same person, merge the two lanes rather than leaving one empty.
Write down your risk tiering rule
Put the criteria behind "High risk tier?" into the step's note: spend, business criticality, regulatory exposure and how hard the supplier would be to replace. The tier drives both the audit and the re-approval interval, so it should not be re-judged twice.
Name the approval authority and its limits
Decide who signs off at each level, and what conditional approval means in practice — which conditions, who verifies them, and when they expire. Keep the person who ran the audit separate from the person who approves.
Fix the record points
Decide where the supplier approval file and the approved vendor list actually live, and what scope is recorded against each entry: categories, parts or services, supplier sites, and any conditions.
Circulate it and put it under change control
Share the chart with the people in each lane and collect their comments, then use the approval workflow and version history so the process document itself has a recorded approver and a trail of what changed.
Frequently asked questions
What is the difference between vendor approval and vendor onboarding?
Onboarding is administrative: creating the vendor record, agreeing the contract, verifying bank details and setting payment terms. Approval is an assessment: deciding whether the supplier may be used at all, and for which categories, parts or sites. Many organisations run them together, which is convenient until an active vendor record is treated as evidence that the supplier was assessed. Keeping them as two processes, with the approved vendor list as the output of this one, avoids that. If you need the administrative side as well, use the vendor onboarding template alongside this one.
Who should approve a new supplier?
Whoever carries the risk if the supplier fails. In practice that is usually a procurement lead for low-spend, low-risk suppliers, with Quality signing jointly for anything touching a product or a regulated process, and a named authority above a spend threshold set in your delegation of authority. Two rules matter more than the exact split: the approver should not be the same person who carried out the audit or assessment, and conditional approval should have a named owner for each condition.
When does a supplier need an audit before approval?
This is what the risk tier decides. Suppliers that are high risk — production parts, regulated or safety-critical processes, single-source, or high annual spend — are audited before they are approved, on site where the process has to be seen rather than read about. Remote audits against the same checklist are reasonable for document-heavy scopes, follow-ups and re-approvals. Lower-risk suppliers are usually qualified on questionnaire evidence, valid certificates and a trial order.
How often should approved suppliers be re-approved?
Set the interval by risk tier: commonly annual for high-risk or critical suppliers and every two to three years for the rest, recorded on the list entry itself rather than in someone's calendar. Add event triggers as well, since most problems do not wait for the review date — a failed batch or major complaint, a change of ownership, a move of manufacturing site, or an expired certificate should all pull the supplier back into this flow. ISO 9001:2015 requires re-evaluation of external providers but sets no interval, so the cadence is yours to justify.