Vendor approval process flowchart template

A vendor approval process flowchart template: questionnaire, quality and financial checks, risk tiering, audit, trial order and the approved vendor list.

Use this template

What the vendor approval process flowchart process is

Vendor approval is the decision to let a supplier be used. It is not the same as onboarding, which creates the vendor record, agrees the contract and sets up payment details. Approval answers a narrower question: has this supplier been assessed against your criteria, and what exactly is it approved to supply? Where the two are run as one flow, an active vendor record quietly starts to read as blanket approval, and buyers order a production part from a supplier that was only ever assessed for something else.

Most of the work is evidence gathering rather than deciding. A questionnaire and certificate pack comes back from the supplier, Finance looks at financial stability, Quality reviews the quality management system and its certificates, and higher-risk suppliers get an audit and a trial order before anyone signs anything. The decision itself takes minutes. What makes it defensible later is that the evidence, the risk tier and the approved scope were recorded in one place by the people accountable for each part.

ISO 9001:2015 clause 8.4 expects an organisation to define criteria for evaluating, selecting, monitoring and re-evaluating external providers, and to retain documented information on the results. It does not prescribe any particular flow, and this template is not a compliance system in itself. Treat it as a starting point and change the lanes, the risk tiering rule and the approval authority to match how your organisation actually decides.

What this flowchart covers

In this template

  • Five role lanes (Requester, Procurement, Quality, Finance and Approval authority) across five stages: request, screening, assessment, audit and trial, approval and listing.
  • The front end: a supplier proposed with a business case, a Procurement screen ("Proceed with qualification?") that closes weak proposals before anyone spends time on them, and a questionnaire pack that is issued, checked for completeness and chased until the gaps are filled.
  • Two assessment steps in separate lanes: Quality reviews the quality system and certificates (scope, accreditation, expiry), Finance assesses financial stability.
  • A risk-tier decision that sends high-risk suppliers to an on-site or remote audit, with a corrective action loop that returns closed-out findings to the same "Audit findings acceptable?" decision, and lets lower-risk suppliers go straight to trial.
  • A sample or trial order evaluated by the requester before any approval is granted, then a supplier approval file compiled by Procurement for the decision.
  • A three-way approval decision (approved, conditionally approved or rejected) where conditional approval records its conditions first, approval adds the supplier to the approved vendor list with a defined scope, and a scheduled re-approval review closes the loop.

When to use this template

  • You have an approved vendor list but no written rule for how a supplier gets onto it, or off it.
  • Quality, Procurement and Finance each hold part of the assessment and nobody owns the decision that pulls it together.
  • A customer or auditor has asked how you evaluate and re-evaluate suppliers, and the honest answer is an email trail.
  • You are separating approval from onboarding, so that having a vendor record no longer implies the supplier is approved to supply anything.
  • You need to agree who the approval authority is, and at what spend or risk level it changes.

How it works

  1. Open the template as a chart

    Open the vendor approval process template and use it as a new chart. Nothing is locked: every lane, step and branch can be renamed, moved or deleted.

  2. Rename the lanes to your roles

    Replace Requester, Procurement, Quality, Finance and Approval authority with the roles that actually exist. If Quality and Procurement are the same person, merge the two lanes rather than leaving one empty.

  3. Write down your risk tiering rule

    Put the criteria behind "High risk tier?" into the step's note: spend, business criticality, regulatory exposure and how hard the supplier would be to replace. The tier drives both the audit and the re-approval interval, so it should not be re-judged twice.

  4. Name the approval authority and its limits

    Decide who signs off at each level, and what conditional approval means in practice — which conditions, who verifies them, and when they expire. Keep the person who ran the audit separate from the person who approves.

  5. Fix the record points

    Decide where the supplier approval file and the approved vendor list actually live, and what scope is recorded against each entry: categories, parts or services, supplier sites, and any conditions.

  6. Circulate it and put it under change control

    Share the chart with the people in each lane and collect their comments, then use the approval workflow and version history so the process document itself has a recorded approver and a trail of what changed.

Frequently asked questions

What is the difference between vendor approval and vendor onboarding?

Onboarding is administrative: creating the vendor record, agreeing the contract, verifying bank details and setting payment terms. Approval is an assessment: deciding whether the supplier may be used at all, and for which categories, parts or sites. Many organisations run them together, which is convenient until an active vendor record is treated as evidence that the supplier was assessed. Keeping them as two processes, with the approved vendor list as the output of this one, avoids that. If you need the administrative side as well, use the vendor onboarding template alongside this one.

Who should approve a new supplier?

Whoever carries the risk if the supplier fails. In practice that is usually a procurement lead for low-spend, low-risk suppliers, with Quality signing jointly for anything touching a product or a regulated process, and a named authority above a spend threshold set in your delegation of authority. Two rules matter more than the exact split: the approver should not be the same person who carried out the audit or assessment, and conditional approval should have a named owner for each condition.

When does a supplier need an audit before approval?

This is what the risk tier decides. Suppliers that are high risk — production parts, regulated or safety-critical processes, single-source, or high annual spend — are audited before they are approved, on site where the process has to be seen rather than read about. Remote audits against the same checklist are reasonable for document-heavy scopes, follow-ups and re-approvals. Lower-risk suppliers are usually qualified on questionnaire evidence, valid certificates and a trial order.

How often should approved suppliers be re-approved?

Set the interval by risk tier: commonly annual for high-risk or critical suppliers and every two to three years for the rest, recorded on the list entry itself rather than in someone's calendar. Add event triggers as well, since most problems do not wait for the review date — a failed batch or major complaint, a change of ownership, a move of manufacturing site, or an expired certificate should all pull the supplier back into this flow. ISO 9001:2015 requires re-evaluation of external providers but sets no interval, so the cadence is yours to justify.

Use this template

Guides that use this template

More in Procurement and supplier process templates

More in Process flowchart templates

Browse all Procurement and supplier process templates