TL;DR: A supplier audit checklist built around ISO 9001 and ISO 13485 requirements helps procurement teams verify that vendors can consistently meet quality, traceability, and documentation standards before awarding business. This guide walks through what to include in your checklist, how to prepare for and conduct the audit, how to score results, and how integrated tools bring audit data, supplier scorecards, and RFQ evaluation into one workflow. AuraVMS starts at $5/month.
Supplier Audit Checklist for ISO 9001 and ISO 13485: Complete Guide for Procurement Teams
When you are awarding a contract worth tens or hundreds of thousands of dollars, the last thing you want is to discover your supplier cannot meet basic quality standards halfway through production. A supplier audit checklist structured around ISO 9001 and ISO 13485 requirements gives you a systematic way to verify supplier capability before you commit and a repeatable framework for ongoing evaluation.
This guide covers everything procurement professionals need: what to include in an ISO 9001 supplier audit checklist, how ISO 13485 adds medical-device-specific requirements, how to prepare and conduct the audit, how to score results, and how to avoid the most common audit mistakes. We also show how connecting audit outcomes directly to your RFQ and supplier selection process closes the loop between quality and procurement.
What Is a Supplier Audit Checklist and Why It Matters
A supplier audit checklist is a structured document that procurement and quality teams use to evaluate whether a supplier meets defined quality, compliance, and operational standards. Rather than relying on gut feel or a factory tour walkthrough, the checklist ensures every auditor evaluates the same criteria across every supplier producing comparable, defensible results.
For procurement teams, the supplier audit serves three purposes:
- Risk reduction Verify that the supplier has the processes, controls, and documentation to deliver consistently before you commit spend.
- Compliance evidence Create an auditable record showing that your organization performed due diligence on suppliers, which matters for ISO 9001 Clause 8.4 (control of externally provided processes), FDA 21 CFR Part 820, and customer-specific quality requirements.
- Supplier development Identify gaps in the supplier's quality management system and work with them to close those gaps, turning a marginal supplier into a reliable one.
The checklist approach matters because ad hoc evaluations produce inconsistent results. Two different buyers visiting the same supplier can walk away with completely different assessments if they are not working from the same criteria. A standardized checklist eliminates that variability.
The right procurement tool supports this by letting you attach evaluation criteria and scoring rubrics directly to supplier records within your RFQ workflow, so audit results are not orphaned in a spreadsheet they live alongside the quotes and decisions that depend on them.
ISO 9001 Supplier Audit Checklist: Key Sections
ISO 9001 is the international standard for quality management systems. When auditing a supplier against ISO 9001, your checklist should cover these core areas:
1. Quality Management System Documentation
| Audit Item | What to Verify | Evidence Required |
|---|---|---|
| Quality manual | Exists and is current | Document control number, revision date |
| Quality policy | Documented and communicated | Posted in facility, known to staff |
| Scope of QMS | Clearly defined | Documented scope statement |
| Process approach | Key processes identified and mapped | Process flowcharts, turtle diagrams |
2. Management Responsibility
| Audit Item | What to Verify | Evidence Required |
|---|---|---|
| Quality objectives | Defined and measurable | Objective register with targets |
| Management review | Conducted periodically | Meeting minutes, action items |
| Customer focus | Customer requirements understood | Voice of customer data, complaint logs |
| Quality manager | Designated and competent | Job description, training records |
3. Resource Management
| Audit Item | What to Verify | Evidence Required |
|---|---|---|
| Infrastructure | Adequate for production | Facility tour, equipment list |
| Work environment | Conditions managed | Temperature, cleanliness, safety records |
| Competence and training | Staff qualified for roles | Training matrix, certifications |
| Calibration | Measuring equipment calibrated | Calibration certificates, schedule |
4. Product Realization
| Audit Item | What to Verify | Evidence Required |
|---|---|---|
| Production planning | Planned and controlled | Production schedules, capacity data |
| Design controls (if applicable) | Design inputs/outputs verified | Design review records |
| Purchasing controls | Suppliers evaluated | Approved supplier list, purchase data |
| Production controls | Process parameters monitored | Control plans, SPC data |
| Identification and traceability | Product traced through production | Lot/batch records, traceability matrix |
5. Measurement, Analysis, and Improvement
| Audit Item | What to Verify | Evidence Required |
|---|---|---|
| Internal audits | Conducted per schedule | Audit schedule, reports, corrective actions |
| Nonconformance management | NCRs raised and closed | NCR log, root cause analysis |
| Corrective actions | CAPA system operational | CAPA records, effectiveness verification |
| Customer satisfaction | Monitored and acted upon | Survey data, complaint trends |
| Continuous improvement | Metrics tracked and improved | KPI dashboard, improvement projects |
Each item should be scored on a simple scale for example, Conforms (3), Minor Nonconformance (2), Major Nonconformance (1), Not Applicable (0). Weight the scores based on criticality to your specific product and supply chain.
ISO 13485 Supplier Audit Checklist: Medical Device Specifics
ISO 13485 is the quality management system standard for medical devices. It builds on ISO 9001 but adds requirements specific to medical device manufacturing including stricter traceability, sterilization, biocompatibility, and regulatory reporting controls.
If you are in the medical device supply chain whether as a manufacturer, contract manufacturer, or component supplier your supplier audit checklist needs to cover these additional areas:
Additional ISO 13485 Audit Items
| Audit Area | What to Verify | Evidence Required |
|---|---|---|
| Risk management (ISO 14971) | Risk analysis conducted for product/process | Risk management file, FMEA |
| Design and development file | Complete DHF maintained | Design history file index |
| Device master record | DMR current and controlled | DMR document list |
| Device history record | DHR maintained per batch | Batch records, release sign-offs |
| Sterilization controls | Validated and monitored | Validation reports, dose audits |
| Biocompatibility | Materials evaluated per ISO 10993 | Biocompatibility test reports |
| Traceability | Component-to-finished device traceability | Traceability matrix, UDI records |
| Complaint handling | Procedures defined and followed | Complaint log, trending analysis |
| Adverse event reporting | MDR/vigilance procedures in place | Reporting procedures, training records |
| Software validation | Software used in QMS validated | Validation protocols, IQ/OQ/PQ |
| Cleanroom controls | Environment monitored per ISO 14644 | Environmental monitoring data |
| Supplier controls (sub-tier) | Sub-suppliers evaluated and controlled | Sub-supplier approval records |
The medical device supply chain demands a higher bar for documentation and traceability. A supplier that passes an ISO 9001 audit may still fail ISO 13485 requirements if they cannot demonstrate control over sterilization validation, biocompatibility data, or complaint handling procedures.
For procurement teams managing medical device suppliers, a centralized supplier evaluation framework lets you store audit scores, track corrective action deadlines, and link audit outcomes to RFQ award decisions ensuring that a supplier who failed an audit cannot quietly win a new contract.
How to Prepare for a Supplier Audit
Preparation is where most audits are won or lost. A well-prepared auditor gets meaningful answers; an unprepared one gets a factory tour and a brochure.
Step 1: Define the Audit Scope
Before anything else, determine what you are auditing. Are you evaluating a new supplier for initial approval? Re-auditing an existing supplier after a quality issue? Conducting a routine surveillance audit? The scope determines which checklist sections apply and how deep you go.
Document the scope in a formal audit plan that includes:
- Supplier name and site address
- Audit type (initial, surveillance, for-cause)
- Products or processes in scope
- Standards being audited against (ISO 9001, ISO 13485, or both)
- Audit dates and team members
- Checklist sections to be covered
Step 2: Review Supplier Documentation in Advance
Request and review these documents before the audit visit:
- Supplier quality manual
- ISO certification certificates (verify on the certification body's website do not accept a PDF at face value)
- Previous audit reports (if existing supplier)
- CAPA log and open nonconformances
- Organization chart and key quality personnel
- Process flowcharts for the products you purchase
Reviewing documentation ahead of time lets you focus the on-site audit on verification rather than discovery. You should arrive knowing what the supplier claims to do, and spend your time confirming they actually do it.
Step 3: Assemble the Audit Team
A supplier audit is not a solo procurement exercise. Depending on the complexity, your team might include:
- Procurement representative (commercial terms, capacity, lead times)
- Quality engineer (QMS documentation, process controls, CAPA)
- Subject matter expert (technical specifications, product-specific requirements)
- Regulatory specialist (for ISO 13485 audits, medical device compliance)
Brief the team on the checklist, assign sections, and agree on scoring criteria before you walk through the door.
Step 4: Notify the Supplier
Send a formal audit notification that includes the scope, dates, team members, and documents you need access to. For initial audits, request a facility map and production flow diagram in advance. For surveillance audits, request updates to previously identified nonconformances.
Conducting the Audit: Step-by-Step Process
Opening Meeting
Start with a brief opening meeting. Introduce the audit team, confirm the scope and schedule, and explain the scoring methodology. Set the tone this is a collaborative evaluation, not a gotcha exercise. Suppliers who feel defensive will be less forthcoming, and you need their cooperation to see how things actually work.
Document Review
Work through the checklist sections systematically. For each item:
- Ask to see the documented procedure
- Verify it is controlled (revision number, approval signature)
- Check that it is followed (look for evidence of actual use signed records, completed forms, system entries)
The gap between what is documented and what is practiced is where the most important findings live. A supplier may have a beautiful procedure on paper that nobody in production has ever seen.
Floor Walkthrough
Walk the production floor with the checklist. Observe:
- Are work instructions posted at workstations?
- Are measuring instruments calibrated and labeled?
- Is product identification and traceability maintained?
- Are nonconforming materials segregated?
- Is the work environment appropriate for the product?
Take photographs (with permission) of anything notable. These become valuable evidence when writing the audit report and comparing against future audits.
Employee Interviews
Talk to operators, not just managers. Ask them:
- What do you do if you find a defective part?
- Where is the procedure for this operation?
- When was your last training?
- How do you know this instrument is calibrated?
Frontline workers reveal whether the quality management system is lived or just laminated. A quality manager who can recite ISO clauses but operators who cannot find their work instructions tells you everything about implementation maturity.
Closing Meeting
Present preliminary findings conformances and nonconformances and allow the supplier to provide additional information or context. Agree on timelines for corrective action plans. Leave with a clear understanding of next steps.
Scoring and Evaluating Supplier Audit Results
A checklist without scoring is just a list. To make audit results actionable, you need a scoring system that produces a single, comparable rating per supplier.
Recommended Scoring Approach
| Rating | Score | Definition |
|---|---|---|
| Conforms | 3 | Requirement fully met, evidence provided |
| Minor nonconformance | 2 | Requirement partially met, gap does not affect product quality |
| Major nonconformance | 1 | Requirement not met, gap may affect product quality or compliance |
| Not applicable | 0 | Requirement does not apply to this supplier's scope |
Calculate a percentage score: (Total points earned / Total possible points) x 100.
Approval Thresholds
| Score Range | Action |
|---|---|
| 90-100% | Approved no conditions |
| 75-89% | Conditionally approved corrective action plan required within 30 days |
| 60-74% | Probationary re-audit required after corrective actions |
| Below 60% | Not approved do not award business |
Document the scoring rationale for each item. A number without context is useless when you review the audit six months later or when a different auditor needs to understand the finding.
This is where integrated procurement software adds value beyond a spreadsheet. By storing audit scores in the same system where you manage RFQs and supplier comparisons, you can automatically flag suppliers who fall below your approval threshold when they are invited to bid. A supplier on probation should not be receiving new RFQs, and the right platform enforces that link between audit status and procurement activity.
Common Supplier Audit Mistakes to Avoid
1. Treating the Audit as a Checkbox Exercise
The most common mistake is rushing through the checklist without genuinely evaluating the supplier's processes. If your auditor is ticking boxes without asking follow-up questions, the audit provides false assurance. Train auditors to probe every "conforms" should be backed by specific evidence.
2. Not Verifying ISO Certificates
Accepting a supplier's ISO certificate at face value is a risk. Certificates can be expired, revoked, or fabricated. Always verify the certificate through the certification body's online database or by contacting the registrar directly. The IAF (International Accreditation Forum) and ANAB (ANSI National Accreditation Board) both maintain searchable databases.
3. Ignoring Sub-Tier Suppliers
Your direct supplier may be ISO certified, but what about their critical sub-suppliers? A nonconformance in the sub-tier can affect your product quality. Include sub-supplier controls in your checklist, especially for critical components or materials.
4. Failing to Follow Up on Corrective Actions
An audit that identifies nonconformances but never verifies corrective actions is worse than no audit at all it creates a false sense of compliance. Build a CAPA tracking process with deadlines, responsibility assignments, and effectiveness verification. Re-audit the specific finding to confirm the corrective action actually resolved the root cause.
5. Using the Same Checklist for Every Supplier
A one-size-fits-all checklist either over-audits simple suppliers or under-audits complex ones. Tailor the checklist based on:
- Product criticality (does the supplier make safety-critical components?)
- Volume and value (high-spend suppliers warrant deeper audits)
- Risk classification (new supplier vs. established partner)
- Industry requirements (medical device vs. general manufacturing)
6. Not Connecting Audit Results to Procurement Decisions
The audit is not an end in itself. If audit results sit in a file and are never referenced when awarding RFQs, the effort is wasted. Audit outcomes should directly influence supplier selection, RFQ invitations, and contract terms. An integrated platform bridges this gap by connecting supplier evaluation data with the RFQ workflow so when you are comparing supplier quotes, you see their audit scores alongside their pricing.
How AuraVMS Streamlines Supplier Audits and RFQ Management
Supplier audits and RFQ management are often handled in separate systems quality teams use audit software or spreadsheets, while procurement uses email and spreadsheets for quotes. This separation creates blind spots: a supplier who failed an audit can still receive RFQs, and audit findings are not considered during quote evaluation.
AuraVMS brings these workflows together. Here is how:
- Centralized supplier records Store audit scores, certification details, and corrective action status alongside supplier contact information and quote history. One record per supplier, accessible to both quality and procurement teams.
- RFQ-linked evaluations When you create an RFQ and invite suppliers, their audit status is visible in the same interface. Suppliers below your approval threshold are flagged, preventing accidental awards to non-compliant vendors.
- Supplier scorecards Build weighted evaluation scorecards that combine audit results with RFQ response quality, pricing competitiveness, and delivery performance. Define scoring criteria that reflect what matters to your organization.
- Anonymous bidding Suppliers submit quotes without seeing each other's pricing, ensuring competitive responses. Combined with audit data, you get a complete picture: which compliant supplier offers the best value.
- Zero-signup for suppliers Suppliers do not need to create accounts or learn a new platform to respond to your RFQs. This removes friction that can reduce response rates, especially with smaller suppliers.
- Affordable pricing AuraVMS starts at $5/month, making it accessible for small and mid-size businesses that cannot justify enterprise procurement platforms like SAP Ariba or Coupa, which typically cost thousands per month.
For procurement teams that need to manage both supplier compliance and quote collection, an integrated platform eliminates the gap between these workflows. Instead of maintaining separate audit spreadsheets and RFQ email chains, you get one system where audit outcomes inform procurement decisions.
Building Your Supplier Audit Program
A single audit is a snapshot. A supplier audit program is a continuous process that builds institutional knowledge about your supply base. Here is how to structure it:
Audit Frequency
| Supplier Risk Level | Audit Frequency |
|---|---|
| Critical (safety, regulatory, high-spend) | Annual on-site audit |
| High (quality-critical, significant spend) | Annual on-site or biennial |
| Medium (standard components, moderate spend) | Biennial on-site or annual remote |
| Low (commodity, low spend) | Questionnaire-based, audit on exception |
Audit Calendar
Maintain a rolling audit calendar so audits are scheduled proactively, not triggered by a quality crisis. Plan audits during periods when the supplier has normal production running you want to see typical operations, not a staged demo.
Auditor Training
Invest in training your audit team. Internal auditor courses (typically 2-3 days for ISO 9001, longer for ISO 13485) provide the skills to conduct effective audits. Rotate auditors to prevent familiarity bias the same auditor evaluating the same supplier year after year may start to overlook issues.
Continuous Improvement
Track audit findings over time. If the same nonconformance appears across multiple suppliers, it may indicate an industry-wide gap or a problem with your requirements. Use trend analysis to focus your supplier development efforts where they will have the most impact.
An integrated procurement platform supports this continuous improvement loop by maintaining historical audit data alongside RFQ and supplier performance metrics. Over time, you build a data-driven picture of which suppliers are improving, which are stagnating, and where your supply chain has systemic weaknesses.
FAQ
What is the difference between ISO 9001 and ISO 13485 supplier audits?
ISO 9001 is a general quality management standard applicable to any organization. ISO 13485 is specific to medical devices and includes additional requirements for risk management (ISO 14971), design controls, sterilization validation, biocompatibility, traceability, and regulatory reporting. An ISO 13485 audit is more rigorous and requires auditors with medical device expertise.
How often should I audit my suppliers?
Audit frequency depends on supplier risk classification. Critical suppliers (safety-critical components, high-spend, regulatory impact) should be audited annually. Medium-risk suppliers can be audited biennially. Low-risk suppliers may only require a self-assessment questionnaire unless a quality issue triggers a for-cause audit.
Can I use the same checklist for initial and surveillance audits?
You can use the same base checklist, but the focus differs. An initial audit covers all checklist sections comprehensively. A surveillance audit focuses on areas where nonconformances were previously identified, changes to the QMS since the last audit, and any new products or processes. Tailor the depth, not the structure.
What should I do if a supplier fails the audit?
If a supplier scores below your approval threshold, do not award new business. Issue a formal corrective action request with a deadline (typically 30-90 days depending on severity). Require a root cause analysis and corrective action plan. Re-audit the specific findings to verify effectiveness before reinstating the supplier. For critical nonconformances affecting product safety, consider sourcing from an alternative supplier.
How does AuraVMS help with supplier audits?
The platform integrates supplier audit data with your RFQ workflow. You can store audit scores, track corrective actions, and build weighted supplier scorecards all in the same system where you collect and compare supplier quotes. When you invite suppliers to an RFQ, their audit status is visible, preventing awards to non-compliant suppliers. It starts at $5/month, making it accessible for SMBs that need professional supplier management without enterprise software costs.
Do I need to be ISO certified myself to audit suppliers?
No. You can audit suppliers against ISO 9001 or ISO 13485 requirements regardless of your own certification status. However, if you are ISO certified, your certification body will expect you to have a supplier evaluation process in place (ISO 9001 Clause 8.4, ISO 13485 Clause 7.4). Conducting structured audits demonstrates compliance with this requirement.
Ready to Streamline Your Supplier Audits and RFQ Process?
Managing supplier audits in isolation from your RFQ workflow creates blind spots that cost money and create risk. An integrated platform brings supplier evaluation, audit tracking, and quote comparison into one affordable system.
With AuraVMS, you can:
- Build weighted supplier scorecards that combine audit results with RFQ performance
- Flag non-compliant suppliers before they receive new RFQ invitations
- Collect anonymous supplier quotes with zero-signup for vendors
- Track corrective actions and audit history alongside supplier records
AuraVMS starts at $5/month. Create your first RFQ and supplier evaluation today at https://www.auravms.com