Supplier Audit Checklist for ISO 9001 and ISO 13485: Complete Guide for Procurement Teams

TL;DR: A supplier audit checklist built around ISO 9001 and ISO 13485 requirements helps procurement teams verify that vendors can consistently meet quality, traceability, and documentation standards before awarding business. This guide walks through what to include in your checklist, how to prepare for and conduct the audit, how to score results, and how integrated tools bring audit data, supplier scorecards, and RFQ evaluation into one workflow. AuraVMS starts at $5/month.

Supplier Audit Checklist for ISO 9001 and ISO 13485: Complete Guide for Procurement Teams

When you are awarding a contract worth tens or hundreds of thousands of dollars, the last thing you want is to discover your supplier cannot meet basic quality standards halfway through production. A supplier audit checklist structured around ISO 9001 and ISO 13485 requirements gives you a systematic way to verify supplier capability before you commit and a repeatable framework for ongoing evaluation.

This guide covers everything procurement professionals need: what to include in an ISO 9001 supplier audit checklist, how ISO 13485 adds medical-device-specific requirements, how to prepare and conduct the audit, how to score results, and how to avoid the most common audit mistakes. We also show how connecting audit outcomes directly to your RFQ and supplier selection process closes the loop between quality and procurement.

What Is a Supplier Audit Checklist and Why It Matters

A supplier audit checklist is a structured document that procurement and quality teams use to evaluate whether a supplier meets defined quality, compliance, and operational standards. Rather than relying on gut feel or a factory tour walkthrough, the checklist ensures every auditor evaluates the same criteria across every supplier producing comparable, defensible results.

For procurement teams, the supplier audit serves three purposes:

  1. Risk reduction Verify that the supplier has the processes, controls, and documentation to deliver consistently before you commit spend.
  2. Compliance evidence Create an auditable record showing that your organization performed due diligence on suppliers, which matters for ISO 9001 Clause 8.4 (control of externally provided processes), FDA 21 CFR Part 820, and customer-specific quality requirements.
  3. Supplier development Identify gaps in the supplier's quality management system and work with them to close those gaps, turning a marginal supplier into a reliable one.

The checklist approach matters because ad hoc evaluations produce inconsistent results. Two different buyers visiting the same supplier can walk away with completely different assessments if they are not working from the same criteria. A standardized checklist eliminates that variability.

The right procurement tool supports this by letting you attach evaluation criteria and scoring rubrics directly to supplier records within your RFQ workflow, so audit results are not orphaned in a spreadsheet they live alongside the quotes and decisions that depend on them.

ISO 9001 Supplier Audit Checklist: Key Sections

ISO 9001 is the international standard for quality management systems. When auditing a supplier against ISO 9001, your checklist should cover these core areas:

1. Quality Management System Documentation

Audit ItemWhat to VerifyEvidence Required
Quality manualExists and is currentDocument control number, revision date
Quality policyDocumented and communicatedPosted in facility, known to staff
Scope of QMSClearly definedDocumented scope statement
Process approachKey processes identified and mappedProcess flowcharts, turtle diagrams

2. Management Responsibility

Audit ItemWhat to VerifyEvidence Required
Quality objectivesDefined and measurableObjective register with targets
Management reviewConducted periodicallyMeeting minutes, action items
Customer focusCustomer requirements understoodVoice of customer data, complaint logs
Quality managerDesignated and competentJob description, training records

3. Resource Management

Audit ItemWhat to VerifyEvidence Required
InfrastructureAdequate for productionFacility tour, equipment list
Work environmentConditions managedTemperature, cleanliness, safety records
Competence and trainingStaff qualified for rolesTraining matrix, certifications
CalibrationMeasuring equipment calibratedCalibration certificates, schedule

4. Product Realization

Audit ItemWhat to VerifyEvidence Required
Production planningPlanned and controlledProduction schedules, capacity data
Design controls (if applicable)Design inputs/outputs verifiedDesign review records
Purchasing controlsSuppliers evaluatedApproved supplier list, purchase data
Production controlsProcess parameters monitoredControl plans, SPC data
Identification and traceabilityProduct traced through productionLot/batch records, traceability matrix

5. Measurement, Analysis, and Improvement

Audit ItemWhat to VerifyEvidence Required
Internal auditsConducted per scheduleAudit schedule, reports, corrective actions
Nonconformance managementNCRs raised and closedNCR log, root cause analysis
Corrective actionsCAPA system operationalCAPA records, effectiveness verification
Customer satisfactionMonitored and acted uponSurvey data, complaint trends
Continuous improvementMetrics tracked and improvedKPI dashboard, improvement projects

Each item should be scored on a simple scale for example, Conforms (3), Minor Nonconformance (2), Major Nonconformance (1), Not Applicable (0). Weight the scores based on criticality to your specific product and supply chain.

ISO 13485 Supplier Audit Checklist: Medical Device Specifics

ISO 13485 is the quality management system standard for medical devices. It builds on ISO 9001 but adds requirements specific to medical device manufacturing including stricter traceability, sterilization, biocompatibility, and regulatory reporting controls.

If you are in the medical device supply chain whether as a manufacturer, contract manufacturer, or component supplier your supplier audit checklist needs to cover these additional areas:

Additional ISO 13485 Audit Items

Audit AreaWhat to VerifyEvidence Required
Risk management (ISO 14971)Risk analysis conducted for product/processRisk management file, FMEA
Design and development fileComplete DHF maintainedDesign history file index
Device master recordDMR current and controlledDMR document list
Device history recordDHR maintained per batchBatch records, release sign-offs
Sterilization controlsValidated and monitoredValidation reports, dose audits
BiocompatibilityMaterials evaluated per ISO 10993Biocompatibility test reports
TraceabilityComponent-to-finished device traceabilityTraceability matrix, UDI records
Complaint handlingProcedures defined and followedComplaint log, trending analysis
Adverse event reportingMDR/vigilance procedures in placeReporting procedures, training records
Software validationSoftware used in QMS validatedValidation protocols, IQ/OQ/PQ
Cleanroom controlsEnvironment monitored per ISO 14644Environmental monitoring data
Supplier controls (sub-tier)Sub-suppliers evaluated and controlledSub-supplier approval records

The medical device supply chain demands a higher bar for documentation and traceability. A supplier that passes an ISO 9001 audit may still fail ISO 13485 requirements if they cannot demonstrate control over sterilization validation, biocompatibility data, or complaint handling procedures.

For procurement teams managing medical device suppliers, a centralized supplier evaluation framework lets you store audit scores, track corrective action deadlines, and link audit outcomes to RFQ award decisions ensuring that a supplier who failed an audit cannot quietly win a new contract.

How to Prepare for a Supplier Audit

Preparation is where most audits are won or lost. A well-prepared auditor gets meaningful answers; an unprepared one gets a factory tour and a brochure.

Step 1: Define the Audit Scope

Before anything else, determine what you are auditing. Are you evaluating a new supplier for initial approval? Re-auditing an existing supplier after a quality issue? Conducting a routine surveillance audit? The scope determines which checklist sections apply and how deep you go.

Document the scope in a formal audit plan that includes:

  • Supplier name and site address
  • Audit type (initial, surveillance, for-cause)
  • Products or processes in scope
  • Standards being audited against (ISO 9001, ISO 13485, or both)
  • Audit dates and team members
  • Checklist sections to be covered

Step 2: Review Supplier Documentation in Advance

Request and review these documents before the audit visit:

  • Supplier quality manual
  • ISO certification certificates (verify on the certification body's website do not accept a PDF at face value)
  • Previous audit reports (if existing supplier)
  • CAPA log and open nonconformances
  • Organization chart and key quality personnel
  • Process flowcharts for the products you purchase

Reviewing documentation ahead of time lets you focus the on-site audit on verification rather than discovery. You should arrive knowing what the supplier claims to do, and spend your time confirming they actually do it.

Step 3: Assemble the Audit Team

A supplier audit is not a solo procurement exercise. Depending on the complexity, your team might include:

  • Procurement representative (commercial terms, capacity, lead times)
  • Quality engineer (QMS documentation, process controls, CAPA)
  • Subject matter expert (technical specifications, product-specific requirements)
  • Regulatory specialist (for ISO 13485 audits, medical device compliance)

Brief the team on the checklist, assign sections, and agree on scoring criteria before you walk through the door.

Step 4: Notify the Supplier

Send a formal audit notification that includes the scope, dates, team members, and documents you need access to. For initial audits, request a facility map and production flow diagram in advance. For surveillance audits, request updates to previously identified nonconformances.

Conducting the Audit: Step-by-Step Process

Opening Meeting

Start with a brief opening meeting. Introduce the audit team, confirm the scope and schedule, and explain the scoring methodology. Set the tone this is a collaborative evaluation, not a gotcha exercise. Suppliers who feel defensive will be less forthcoming, and you need their cooperation to see how things actually work.

Document Review

Work through the checklist sections systematically. For each item:

  • Ask to see the documented procedure
  • Verify it is controlled (revision number, approval signature)
  • Check that it is followed (look for evidence of actual use signed records, completed forms, system entries)

The gap between what is documented and what is practiced is where the most important findings live. A supplier may have a beautiful procedure on paper that nobody in production has ever seen.

Floor Walkthrough

Walk the production floor with the checklist. Observe:

  • Are work instructions posted at workstations?
  • Are measuring instruments calibrated and labeled?
  • Is product identification and traceability maintained?
  • Are nonconforming materials segregated?
  • Is the work environment appropriate for the product?

Take photographs (with permission) of anything notable. These become valuable evidence when writing the audit report and comparing against future audits.

Employee Interviews

Talk to operators, not just managers. Ask them:

  • What do you do if you find a defective part?
  • Where is the procedure for this operation?
  • When was your last training?
  • How do you know this instrument is calibrated?

Frontline workers reveal whether the quality management system is lived or just laminated. A quality manager who can recite ISO clauses but operators who cannot find their work instructions tells you everything about implementation maturity.

Closing Meeting

Present preliminary findings conformances and nonconformances and allow the supplier to provide additional information or context. Agree on timelines for corrective action plans. Leave with a clear understanding of next steps.

Scoring and Evaluating Supplier Audit Results

A checklist without scoring is just a list. To make audit results actionable, you need a scoring system that produces a single, comparable rating per supplier.

Recommended Scoring Approach

RatingScoreDefinition
Conforms3Requirement fully met, evidence provided
Minor nonconformance2Requirement partially met, gap does not affect product quality
Major nonconformance1Requirement not met, gap may affect product quality or compliance
Not applicable0Requirement does not apply to this supplier's scope

Calculate a percentage score: (Total points earned / Total possible points) x 100.

Approval Thresholds

Score RangeAction
90-100%Approved no conditions
75-89%Conditionally approved corrective action plan required within 30 days
60-74%Probationary re-audit required after corrective actions
Below 60%Not approved do not award business

Document the scoring rationale for each item. A number without context is useless when you review the audit six months later or when a different auditor needs to understand the finding.

This is where integrated procurement software adds value beyond a spreadsheet. By storing audit scores in the same system where you manage RFQs and supplier comparisons, you can automatically flag suppliers who fall below your approval threshold when they are invited to bid. A supplier on probation should not be receiving new RFQs, and the right platform enforces that link between audit status and procurement activity.

Common Supplier Audit Mistakes to Avoid

1. Treating the Audit as a Checkbox Exercise

The most common mistake is rushing through the checklist without genuinely evaluating the supplier's processes. If your auditor is ticking boxes without asking follow-up questions, the audit provides false assurance. Train auditors to probe every "conforms" should be backed by specific evidence.

2. Not Verifying ISO Certificates

Accepting a supplier's ISO certificate at face value is a risk. Certificates can be expired, revoked, or fabricated. Always verify the certificate through the certification body's online database or by contacting the registrar directly. The IAF (International Accreditation Forum) and ANAB (ANSI National Accreditation Board) both maintain searchable databases.

3. Ignoring Sub-Tier Suppliers

Your direct supplier may be ISO certified, but what about their critical sub-suppliers? A nonconformance in the sub-tier can affect your product quality. Include sub-supplier controls in your checklist, especially for critical components or materials.

4. Failing to Follow Up on Corrective Actions

An audit that identifies nonconformances but never verifies corrective actions is worse than no audit at all it creates a false sense of compliance. Build a CAPA tracking process with deadlines, responsibility assignments, and effectiveness verification. Re-audit the specific finding to confirm the corrective action actually resolved the root cause.

5. Using the Same Checklist for Every Supplier

A one-size-fits-all checklist either over-audits simple suppliers or under-audits complex ones. Tailor the checklist based on:

  • Product criticality (does the supplier make safety-critical components?)
  • Volume and value (high-spend suppliers warrant deeper audits)
  • Risk classification (new supplier vs. established partner)
  • Industry requirements (medical device vs. general manufacturing)

6. Not Connecting Audit Results to Procurement Decisions

The audit is not an end in itself. If audit results sit in a file and are never referenced when awarding RFQs, the effort is wasted. Audit outcomes should directly influence supplier selection, RFQ invitations, and contract terms. An integrated platform bridges this gap by connecting supplier evaluation data with the RFQ workflow so when you are comparing supplier quotes, you see their audit scores alongside their pricing.

How AuraVMS Streamlines Supplier Audits and RFQ Management

Supplier audits and RFQ management are often handled in separate systems quality teams use audit software or spreadsheets, while procurement uses email and spreadsheets for quotes. This separation creates blind spots: a supplier who failed an audit can still receive RFQs, and audit findings are not considered during quote evaluation.

AuraVMS brings these workflows together. Here is how:

  1. Centralized supplier records Store audit scores, certification details, and corrective action status alongside supplier contact information and quote history. One record per supplier, accessible to both quality and procurement teams.
  2. RFQ-linked evaluations When you create an RFQ and invite suppliers, their audit status is visible in the same interface. Suppliers below your approval threshold are flagged, preventing accidental awards to non-compliant vendors.
  3. Supplier scorecards Build weighted evaluation scorecards that combine audit results with RFQ response quality, pricing competitiveness, and delivery performance. Define scoring criteria that reflect what matters to your organization.
  4. Anonymous bidding Suppliers submit quotes without seeing each other's pricing, ensuring competitive responses. Combined with audit data, you get a complete picture: which compliant supplier offers the best value.
  5. Zero-signup for suppliers Suppliers do not need to create accounts or learn a new platform to respond to your RFQs. This removes friction that can reduce response rates, especially with smaller suppliers.
  6. Affordable pricing AuraVMS starts at $5/month, making it accessible for small and mid-size businesses that cannot justify enterprise procurement platforms like SAP Ariba or Coupa, which typically cost thousands per month.

For procurement teams that need to manage both supplier compliance and quote collection, an integrated platform eliminates the gap between these workflows. Instead of maintaining separate audit spreadsheets and RFQ email chains, you get one system where audit outcomes inform procurement decisions.

Building Your Supplier Audit Program

A single audit is a snapshot. A supplier audit program is a continuous process that builds institutional knowledge about your supply base. Here is how to structure it:

Audit Frequency

Supplier Risk LevelAudit Frequency
Critical (safety, regulatory, high-spend)Annual on-site audit
High (quality-critical, significant spend)Annual on-site or biennial
Medium (standard components, moderate spend)Biennial on-site or annual remote
Low (commodity, low spend)Questionnaire-based, audit on exception

Audit Calendar

Maintain a rolling audit calendar so audits are scheduled proactively, not triggered by a quality crisis. Plan audits during periods when the supplier has normal production running you want to see typical operations, not a staged demo.

Auditor Training

Invest in training your audit team. Internal auditor courses (typically 2-3 days for ISO 9001, longer for ISO 13485) provide the skills to conduct effective audits. Rotate auditors to prevent familiarity bias the same auditor evaluating the same supplier year after year may start to overlook issues.

Continuous Improvement

Track audit findings over time. If the same nonconformance appears across multiple suppliers, it may indicate an industry-wide gap or a problem with your requirements. Use trend analysis to focus your supplier development efforts where they will have the most impact.

An integrated procurement platform supports this continuous improvement loop by maintaining historical audit data alongside RFQ and supplier performance metrics. Over time, you build a data-driven picture of which suppliers are improving, which are stagnating, and where your supply chain has systemic weaknesses.

FAQ

What is the difference between ISO 9001 and ISO 13485 supplier audits?

ISO 9001 is a general quality management standard applicable to any organization. ISO 13485 is specific to medical devices and includes additional requirements for risk management (ISO 14971), design controls, sterilization validation, biocompatibility, traceability, and regulatory reporting. An ISO 13485 audit is more rigorous and requires auditors with medical device expertise.

How often should I audit my suppliers?

Audit frequency depends on supplier risk classification. Critical suppliers (safety-critical components, high-spend, regulatory impact) should be audited annually. Medium-risk suppliers can be audited biennially. Low-risk suppliers may only require a self-assessment questionnaire unless a quality issue triggers a for-cause audit.

Can I use the same checklist for initial and surveillance audits?

You can use the same base checklist, but the focus differs. An initial audit covers all checklist sections comprehensively. A surveillance audit focuses on areas where nonconformances were previously identified, changes to the QMS since the last audit, and any new products or processes. Tailor the depth, not the structure.

What should I do if a supplier fails the audit?

If a supplier scores below your approval threshold, do not award new business. Issue a formal corrective action request with a deadline (typically 30-90 days depending on severity). Require a root cause analysis and corrective action plan. Re-audit the specific findings to verify effectiveness before reinstating the supplier. For critical nonconformances affecting product safety, consider sourcing from an alternative supplier.

How does AuraVMS help with supplier audits?

The platform integrates supplier audit data with your RFQ workflow. You can store audit scores, track corrective actions, and build weighted supplier scorecards all in the same system where you collect and compare supplier quotes. When you invite suppliers to an RFQ, their audit status is visible, preventing awards to non-compliant suppliers. It starts at $5/month, making it accessible for SMBs that need professional supplier management without enterprise software costs.

Do I need to be ISO certified myself to audit suppliers?

No. You can audit suppliers against ISO 9001 or ISO 13485 requirements regardless of your own certification status. However, if you are ISO certified, your certification body will expect you to have a supplier evaluation process in place (ISO 9001 Clause 8.4, ISO 13485 Clause 7.4). Conducting structured audits demonstrates compliance with this requirement.

Ready to Streamline Your Supplier Audits and RFQ Process?

Managing supplier audits in isolation from your RFQ workflow creates blind spots that cost money and create risk. An integrated platform brings supplier evaluation, audit tracking, and quote comparison into one affordable system.

With AuraVMS, you can:

  • Build weighted supplier scorecards that combine audit results with RFQ performance
  • Flag non-compliant suppliers before they receive new RFQ invitations
  • Collect anonymous supplier quotes with zero-signup for vendors
  • Track corrective actions and audit history alongside supplier records

AuraVMS starts at $5/month. Create your first RFQ and supplier evaluation today at https://www.auravms.com

Continue this topic

Collect structured quotes without supplier accounts.

Invite selected suppliers through private links and keep every response tied to the correct RFQ.