Skip to main content
Category: Third-Party and Supply Chain

Supplier Audit

Also known as: Vendor Audit
Simply put

A supplier audit is a formal, structured review that an organization conducts to check whether a supplier meets defined standards for quality, contractual terms, or regulatory requirements. It typically involves examining the supplier's processes, controls, facilities, records, or management practices against agreed criteria. Audits are generally arranged in advance so the supplier can prepare, and are used to confirm that a supplier can reliably meet expectations.

Formal definition

A supplier audit is an independent and objective assessment of a supplier's processes, products, controls, facilities, records, or management practices, evaluated against benchmarked or predefined criteria such as an organization's quality standards, contractual obligations, or applicable regulatory requirements. It is generally a planned engagement, scheduled in advance, in which the auditing organization gathers and evaluates evidence to verify whether the supplier conforms to the defined criteria. Supplier audits typically form part of a broader third-party or supply chain risk management and assurance activity; the specific scope, criteria, and applicable standards vary by sector, jurisdiction, entity type, and the nature of the supplier relationship. This entry is educational and does not constitute legal, audit, or compliance advice.

Why it matters

Suppliers and other third parties can introduce quality, operational, regulatory, and reputational risk into an organization, yet the organization often has limited direct visibility into how those suppliers actually operate. A supplier audit provides a structured, evidence-based way to test whether a supplier genuinely meets the standards it has committed to, rather than relying solely on the supplier's own representations. This matters because accountability for the goods and services an organization brings in generally cannot be fully outsourced along with the work itself; the organization typically remains answerable to its own customers, regulators, and stakeholders for outcomes.

Because supplier audits are generally arranged in advance and give the supplier time to prepare, they are well suited to confirming that a supplier can reliably meet defined criteria under expected conditions. Organizations should recognize, however, that a planned audit reflects performance at a point in time and under conditions the supplier has had an opportunity to ready itself for. Audits are therefore typically one component of a broader assurance and third-party risk management approach rather than a standalone guarantee of ongoing conformance.

The specific value and design of a supplier audit depend heavily on context. The scope, criteria, and applicable standards vary by sector, jurisdiction, entity type, and the nature of the supplier relationship, and what counts as a regulatory requirement in one setting may be a voluntary or contractual expectation in another. This entry is educational and does not constitute legal, audit, or compliance advice.

Who it's relevant to

Procurement and supplier management teams
Teams responsible for selecting, onboarding, and managing suppliers use supplier audits to verify that a vendor can reliably meet defined quality, contractual, and regulatory expectations. Audit findings help inform decisions about whether to engage, continue, or place conditions on a supplier relationship.
Quality assurance functions
Where an organization depends on external suppliers to meet its own quality standards, quality assurance functions rely on supplier audits to confirm that a supplier's processes and products conform to defined criteria before and during the relationship.
Compliance and third-party risk professionals
Compliance and third-party risk teams use supplier audits as one assurance mechanism within a broader supply chain risk management program, particularly where suppliers are subject to applicable regulatory requirements. The relevance and design of an audit will depend on the jurisdiction, sector, and specific obligations that apply.
Internal audit and assurance providers
Internal auditors and other assurance functions may be involved in designing, conducting, or evaluating supplier audit activity as part of the organization's overall assurance framework, helping to confirm that evidence is gathered and evaluated objectively against the defined criteria.

Inside Supplier Audit

Scope and Objectives
A defined statement of what the supplier audit will cover, such as quality systems, information security, labor and human rights, anti-bribery controls, financial stability, or regulatory compliance. The scope typically depends on the criticality of the supplier, the risk profile of the relationship, and any contractual or regulatory drivers, and should be agreed before fieldwork begins.
Risk-Based Supplier Selection
The process of prioritizing which suppliers to audit based on factors such as spend, criticality to operations, geographic and sector risk, prior performance, and inherent risk exposure. Not every supplier is generally audited; resources are typically directed toward those posing the greatest residual risk after existing controls are considered.
Audit Criteria and Standards
The benchmarks against which the supplier is assessed, which may include contractual terms, the buyer's own policies and supplier code of conduct, applicable laws and regulations in the relevant jurisdictions, and voluntary standards or frameworks (for example, quality or information security management standards). It should be clear which criteria are binding requirements and which are voluntary expectations.
Evidence Gathering and Fieldwork
The methods used to collect evidence, such as document review, self-assessment questionnaires, on-site inspection, remote assessments, sampling, and interviews. This step distinguishes between assessing whether a control is designed appropriately and testing whether it operates effectively in practice over time.
Findings, Ratings, and Reporting
The documented results of the audit, typically including identified gaps or nonconformities, their significance, and a report communicated to relevant stakeholders. Findings are generally distinguished by severity so that management can prioritize response.
Corrective Action and Follow-Up
The remediation plan agreed with the supplier, including responsibilities, timelines, and verification of closure. Follow-up confirms whether corrective actions were implemented and effective, and may feed into decisions about continued use, escalation, or contract terms.
Roles and Accountability
Clarity over who owns the supplier relationship and control environment (typically procurement or the business function within management, as part of first-line responsibility), who provides oversight or independent assurance (such as compliance, a second-line function, or internal audit), and how results are escalated. The board or a committee generally exercises oversight of significant third-party risk rather than performing audits directly.

Common questions

Answers to the questions practitioners most commonly ask about Supplier Audit.

Is a supplier audit the same thing as supplier due diligence or ongoing monitoring?
No. These are related but distinct activities within third-party risk management. Due diligence typically occurs before or at onboarding to assess a prospective supplier's suitability, while ongoing monitoring is a continuous or periodic surveillance activity. A supplier audit is generally a more formal, point-in-time examination of a supplier's controls, processes, or compliance against defined criteria. An audit may be one component of a broader monitoring program, but conducting an audit does not by itself satisfy the full scope of due diligence or continuous oversight obligations. The appropriate mix depends on the risk profile of the supplier, the nature of the goods or services, and any applicable jurisdictional or sector requirements.
Does the board itself conduct or own supplier audits?
Generally no. Executing supplier audits is typically a management or assurance-function activity, not a board duty. Management usually owns the supplier relationship and the associated controls (often described as first-line responsibility), while a compliance, procurement, or internal audit function may perform or coordinate the audit. Internal audit, where it performs such work, generally does so as an independent assurance function rather than as an owner of the supplier relationship. The board or a relevant committee typically exercises oversight, reviewing the adequacy of the third-party risk program and significant findings, rather than performing the audit itself. The precise allocation depends on the entity's governance structure and the three-lines model it has adopted.
How should the scope of a supplier audit be determined?
Scope is typically set by reference to the risk the supplier presents and the objectives of the audit. Relevant factors often include the criticality of the goods or services, the sensitivity of any data handled, applicable regulatory or contractual requirements, and prior findings or performance history. A risk-based approach generally focuses audit effort on higher-risk suppliers and the controls most relevant to identified exposures. Scope should be documented and agreed in advance, and it may be constrained by contractual audit rights, resource availability, and the professional judgment of those conducting the work. This is a matter of program design rather than a fixed standard.
What is the difference between assessing a supplier's control design and its operating effectiveness during an audit?
These are distinct evaluation objectives that are sometimes addressed in separate phases. Assessing control design examines whether a control, as structured, is capable of achieving its intended objective if it operates as intended. Assessing operating effectiveness examines whether the control actually functioned as designed over a defined period. A supplier may have well-designed controls that are not consistently operating, or informal controls that operate effectively in practice. Auditors typically clarify which objective applies, as the evidence, sampling, and testing approaches differ. Confirming design alone does not establish that a control operated effectively.
What audit rights are typically needed to conduct a supplier audit?
The ability to audit a supplier generally depends on rights established in the contract or applicable regulatory framework rather than an inherent entitlement. Audit clauses often address the scope, frequency, notice period, access to premises, personnel and records, use of third-party auditors, and treatment of confidential information. Without such provisions, a supplier may not be obligated to permit an audit. Where direct audit access is limited, organizations sometimes rely on independent third-party attestations or certifications as an alternative form of assurance. Because these arrangements are contractual and jurisdiction-dependent, the specific rights available should be confirmed with legal or contracting professionals.
How should supplier audit findings be handled after the audit concludes?
Findings are typically documented, rated or prioritized by significance, and communicated to the relevant parties, often including a corrective action plan agreed with the supplier. Management generally owns the remediation and tracks it to closure, while an assurance function may verify that agreed actions were implemented and effective. Significant or unresolved issues are commonly escalated through governance channels and may inform decisions about the ongoing relationship. The rigor of follow-up generally reflects the risk associated with each finding. These are program design and judgment matters; this entry is educational and not audit, legal, or compliance advice.

Common misconceptions

A supplier audit is primarily a compliance function activity performed independently of the business.
Ownership of supplier relationships and the associated controls typically sits with management in the first line, such as procurement or the sponsoring business unit. Second-line functions (compliance, risk) may set standards and monitor, and internal audit may provide independent assurance, but conflating these lines can obscure where accountability actually rests. The specific allocation depends on the organization's operating model.
Passing a supplier audit means the supplier is low risk and no residual risk remains.
An audit assesses controls against defined criteria at a point in time and, where sampling is used, does not test every transaction or location. Even a favorable result generally leaves residual risk, and conditions can change after the audit. Audits reduce and inform risk understanding rather than eliminate it.
Every supplier should be audited to the same depth to be thorough.
Auditing all suppliers identically is generally neither feasible nor efficient. A risk-based approach directs greater scrutiny toward critical, higher-risk suppliers, while lower-risk relationships may rely on lighter-touch methods such as self-assessment. The appropriate depth depends on facts, criticality, and the organization's judgment.

Best practices

Adopt a risk-based approach to selecting and scoping supplier audits, prioritizing suppliers by criticality, inherent risk, jurisdiction, and prior performance rather than applying a uniform depth to all.
Define and agree the audit criteria in advance, clearly separating binding contractual and regulatory requirements from voluntary standards or internal expectations, and note that applicable requirements vary by jurisdiction and sector.
Distinguish control design from operating effectiveness during fieldwork, using evidence such as documentation, sampling, interviews, and inspection to test whether controls both exist and function over time.
Clarify roles and accountability up front, keeping ownership of the supplier relationship with the responsible management function while preserving the independence of any assurance function and defining escalation paths.
Rate and document findings by severity and require corrective action plans with owners, timelines, and verification of closure, rather than treating the report as the end of the process.
Treat audit results as informing residual risk rather than eliminating it, and integrate outcomes into ongoing supplier monitoring, contract management, and re-assessment cycles, recognizing this guidance is educational and not legal, audit, or compliance advice.