Supplier Audit Checklist for Manufacturing Companies: 50 Controls Before RFQ Award
TL;DR
Supplier Audit Checklist for Manufacturing Companies: 50 Controls Before RFQ Award
TL;DR
A supplier audit should answer one practical question: can this supplier repeatedly deliver the specified product, at the promised quality, quantity, cost, and lead time, without creating unacceptable compliance or continuity risk? A polished factory tour is not enough. Manufacturing procurement teams need a risk-based audit, objective evidence, clear scoring, named corrective actions, and an explicit decision about whether the supplier may receive an RFQ, receive a conditional RFQ, or remain blocked.
This guide provides a 50-control supplier audit checklist for manufacturing companies. It covers corporate legitimacy, quality management, process control, capacity, maintenance, traceability, supply continuity, environmental and labor controls, cybersecurity, commercial readiness, and RFQ handoff. Use it before onboarding a critical supplier, after a material quality event, when moving production, or before awarding a high-risk category. The final step is operational: place qualified suppliers into a controlled sourcing process. AuraVMS helps procurement teams send structured RFQs, collect quotes without requiring suppliers to create accounts, compare responses consistently, and preserve an audit trail from qualification through award.
1. Why supplier audits must happen before competitive sourcing
Manufacturing buyers often treat supplier qualification and quotation collection as separate activities. Quality audits the plant, procurement requests prices, finance checks the company, and engineering reviews a sample. Each function may do competent work, yet the award decision still rests on disconnected spreadsheets, email threads, and verbal assurances.
That separation creates three predictable failures.
First, an attractive price can outrun technical evidence. A supplier submits the lowest quote, becomes the commercial favorite, and only later reveals weak calibration, inadequate capacity, or no reliable change-control process. The sourcing team then either restarts the event or accepts risk because the schedule has become urgent.
Second, audit findings lose their commercial consequence. A report may identify weak preventive maintenance or incomplete lot traceability, but the RFQ scorecard does not reflect those risks. The quoted unit price looks precise while the cost of failure remains invisible.
Third, supplier approval becomes permanent by accident. Once a vendor code exists, future buyers assume somebody else validated the supplier. Audit scope, expiry dates, conditional approvals, and corrective actions disappear from operational view.
A better model treats the audit as an input to sourcing governance. The audit decides whether a supplier is eligible to quote, which categories and sites it may serve, what evidence must accompany its quotation, and which risk adjustments belong in the evaluation. The RFQ then tests commercial competitiveness only among suppliers that meet the required operating threshold.
This distinction matters most for direct materials, custom components, contract manufacturing, packaging that touches regulated products, tooling, maintenance-critical parts, and any category where late delivery can stop production. It is less useful to apply a full factory audit to low-value office supplies. Procurement should scale the work to the consequence of failure.
The audit is therefore not a ceremonial compliance exercise. It is a decision system with five outputs:
- Approved, with a defined scope and review date
- Conditionally approved, with restrictions and corrective actions
- Approved for prototype or low-volume work only
- Development supplier, not yet eligible for production RFQs
- Rejected or suspended
Those statuses should be visible when the next sourcing event starts. AuraVMS can support the downstream discipline by helping the buyer invite only the appropriate suppliers, issue the same specifications to all participants, and compare their commercial responses in one place.
2. Plan the audit using supplier risk, not a generic calendar
A yearly audit schedule looks orderly but can waste time. A supplier of standard labels and a sole-source producer of a safety-critical machined component do not deserve the same audit frequency or depth. Begin with inherent risk, then adjust for actual performance.
Use five dimensions to classify the supplier:
- Product criticality: What happens if the material is defective? Consider safety, regulatory impact, field failure, warranty exposure, and production interruption.
- Supply dependence: Is the supplier sole-source, single-source by choice, or one of several interchangeable sources? How long would qualification of an alternative take?
- Process complexity: Does production involve special processes, controlled environments, proprietary tooling, outsourced operations, or difficult measurement systems?
- Geographic and continuity exposure: Consider logistics routes, political concentration, utilities, natural hazards, currency, and reliance on one factory.
- Performance history: Review defect rates, corrective-action closure, on-time delivery, responsiveness, price stability, and unapproved changes.
Assign a simple low, medium, or high rating to each dimension. Any high rating in safety, regulatory impact, or sole-source dependence should normally trigger a deeper audit. A supplier with several medium ratings may also merit high-risk treatment because risks compound.
Choose the audit type after classification:
| Audit type | Best use | Typical evidence |
|---|---|---|
| Remote document review | Low-risk suppliers or initial screening | Certifications, procedures, sample records, capacity data |
| Desktop cross-functional review | Commercially important suppliers with standard processes | Financial, quality, logistics, security, and contract documents |
| On-site process audit | Critical parts, new factories, special processes, repeated failures | Live process observation, records, interviews, traceability test |
| Product or process audit | Specific defect, transfer, launch, or engineering concern | Control plan, work instructions, gauges, capability, sample build |
| Surveillance audit | Confirming sustained correction or ongoing compliance | Targeted records, trend data, closure evidence |
Define the scope in writing before the visit. State the legal entity, factory address, product family, processes, shifts, outsourced operations, standards, customer-specific requirements, and audit period. Ask the supplier to name owners for quality, operations, maintenance, supply chain, information security, human resources, and commercial matters.
Request a pre-audit evidence pack at least one week in advance. It should include an organization chart, site layout, certifications, product-flow diagram, key process list, recent internal audit, management review, major customer complaints, capacity summary, business-continuity plan, and a list of subcontracted processes. Reviewing these documents early lets the audit team spend on-site time testing reality instead of reading policy binders.
Build a cross-functional audit team. Procurement owns the commercial and sourcing decision. Quality tests the management system and process controls. Engineering checks technical capability and change management. Operations or planning validates capacity and delivery claims. Information security joins when the supplier will access designs, forecasts, customer data, or connected systems.
Finally, set decision thresholds before seeing the supplier. If scoring rules change after a charismatic plant manager explains a weakness, the audit has become negotiation theater.
3. The 50-control supplier audit checklist
The checklist below is designed for manufacturing procurement teams. It is deliberately evidence-based. A “yes” without a record, observation, or test should not receive full credit.
| No. | Control to test | Evidence to request | Failure signal |
|---|---|---|---|
| 1 | Legal entity and ownership are verified | Registration, tax records, ownership declaration | Names or addresses do not match |
| 2 | Required licenses and permits are current | Permit register and expiry dates | Expired or missing operating permit |
| 3 | Organization responsibilities are defined | Organization chart and role descriptions | Quality reports only through production |
| 4 | Relevant certifications are valid and scoped correctly | Certificate and certification-body record | Certificate excludes the audited site or process |
| 5 | Insurance matches contractual exposure | Policies and coverage limits | Product liability or interruption gaps |
| 6 | Customer and regulatory requirements are reviewed | Contract review procedure and recent records | Requirements accepted without feasibility review |
| 7 | Document control prevents obsolete instructions | Master list, revision history, floor copies | Old drawings visible at workstations |
| 8 | Records have defined retention and protection | Retention matrix and archived sample | Records are editable, missing, or unsearchable |
| 9 | Internal audits cover critical processes | Audit schedule, reports, closure evidence | Repeated findings or superficial checklists |
| 10 | Management reviews performance and risk | Minutes, actions, KPI trends | Meetings record data but no decisions |
| 11 | Incoming material is verified | Inspection plans and receipt records | Critical material accepted on supplier label alone |
| 12 | Supplier-approved sources are controlled | Approved sub-supplier list | Purchasing can change sub-suppliers informally |
| 13 | Material identity is preserved | Labels, segregation, status controls | Unidentified or mixed material on the floor |
| 14 | Lot and batch traceability works end to end | Trace exercise from finished item to input lots | Trace requires manual reconstruction or fails |
| 15 | Nonconforming material is contained | Quarantine area and disposition records | Rejected stock can return to production |
| 16 | Production uses approved work instructions | Current instructions at point of use | Operators rely on memory or unofficial notes |
| 17 | Critical parameters are defined and monitored | Control plan, logs, alarms | Limits exist but deviations are not reviewed |
| 18 | Process capability is known for critical features | Cp, Cpk, Pp, Ppk studies where appropriate | Capability claims use too little or selected data |
| 19 | First-piece or setup approval is controlled | Setup checklist and approval record | Production begins before verification |
| 20 | Special processes are validated | Validation protocols and revalidation triggers | Output cannot be verified yet validation is absent |
| 21 | Inspection methods match drawing requirements | Inspection plan and measurement method | Wrong gauge resolution or sampling logic |
| 22 | Measurement systems are suitable | Gauge R&R or equivalent study | Measurement variation masks process variation |
| 23 | Calibration is current and traceable | Calibration register, labels, certificates | Overdue gauges remain available for use |
| 24 | Test equipment failures trigger impact review | Out-of-tolerance investigation records | No review of product measured since last calibration |
| 25 | Final release is independent and documented | Release criteria and signed records | Shipment occurs before quality release |
| 26 | Preventive maintenance covers critical assets | Asset list, schedule, completion history | Maintenance is mostly breakdown-driven |
| 27 | Critical spares are identified | Spares list and stocking policy | One low-cost component can stop the line for weeks |
| 28 | Tooling ownership and condition are controlled | Tool register, maintenance, ownership labels | Customer tooling is mixed, damaged, or uninsured |
| 29 | Capacity claims use demonstrated rates | Run data, cycle time, yield, uptime | Capacity equals theoretical machine speed |
| 30 | Capacity includes constraints and competing demand | Load plan and bottleneck analysis | Supplier ignores changeovers, labor, or other customers |
| 31 | Production planning controls priority changes | Planning rules and schedule adherence | Expedites routinely displace committed orders |
| 32 | On-time delivery is measured consistently | OTD definition and 12-month trend | Supplier changes denominator to improve results |
| 33 | Packaging protects the product and traceability | Approved packaging standard and shipment sample | Damage, moisture, mixed lots, or unreadable labels |
| 34 | Logistics routes and lead times are validated | Route plan, carrier data, customs assumptions | Quoted lead time excludes border or consolidation time |
| 35 | Business-continuity risks are documented | BCP, risk assessment, recovery priorities | Plan is generic and has never been tested |
| 36 | Backup utilities and recovery resources are tested | Generator, water, IT recovery test records | Backup exists but cannot support critical processes |
| 37 | Alternate production options are qualified | Transfer plan, alternate site evidence | “Another plant” lacks tooling or approval |
| 38 | Key-person dependency is reduced | Skills matrix and cross-training records | One operator or programmer owns critical knowledge |
| 39 | Cyber access follows least privilege | Access matrix, joiner-mover-leaver records | Shared accounts or retained former-user access |
| 40 | Sensitive drawings and data are protected | Classification, encryption, transfer controls | Designs move through personal email or public links |
| 41 | Cyber incidents have response and notification rules | Incident plan and exercise record | No contractual notification path |
| 42 | Environmental obligations are monitored | Aspect register, permits, waste records | Hazardous waste or emissions records are incomplete |
| 43 | Worker safety controls are active | Risk assessments, incident trends, observations | Guards bypassed or PPE rules ignored |
| 44 | Labor and ethical sourcing expectations flow down | Code, training, sub-supplier clauses | No checks on labor brokers or high-risk sources |
| 45 | Corrective actions address root cause | Recent CAPA or 8D records | “Operator retraining” closes every issue |
| 46 | Effectiveness is verified after correction | Follow-up data and recurrence check | Closure occurs when an action is assigned |
| 47 | Engineering changes require approval | Change procedure and recent change record | Material, process, site, or tool changes go unreported |
| 48 | Quotation assumptions are explicit | Cost breakdown, MOQ, tooling, validity, lead time | Low price depends on hidden volumes or exclusions |
| 49 | Commercial terms match operational capability | Draft terms and exception list | Supplier accepts requirements it cannot demonstrate |
| 50 | Audit status controls RFQ eligibility | Approved scope, expiry, conditions, sourcing rule | Any vendor code can be invited to any RFQ |
Do not treat every line as equally important. A missing training signature and a failed traceability test are both findings, but they do not carry the same exposure. Mark critical controls in advance based on the product and category. For a food-contact package, hygiene and material compliance may be critical. For a precision-machined safety part, special-process validation, calibration, traceability, and change control may dominate. For an electronics contract manufacturer, component authenticity, configuration control, test coverage, and cybersecurity may deserve greater weight.
The strongest audit technique is sampling across systems. Pick one recently shipped lot and trace it backward through release, inspection, production, input material, sub-suppliers, operators, equipment, and calibration. Then pick one incoming material lot and trace it forward to every affected shipment. A system that works only when the supplier chooses the sample is not yet proven.
4. Score findings so the approval decision is defensible
Scoring creates consistency, but arithmetic must not conceal judgment. Use a scale that distinguishes existence from effectiveness:
| Score | Meaning | Evidence standard |
|---|---|---|
| 0 | Absent or fundamentally ineffective | No control, direct violation, or unacceptable exposure |
| 1 | Informal and unreliable | Practice depends on individuals; records are weak |
| 2 | Defined but inconsistently applied | Procedure exists; sampling finds material gaps |
| 3 | Implemented and generally effective | Current records and observations support the control |
| 4 | Effective, measured, and improving | Trends, prevention, ownership, and sustained results |
Weight controls by risk. A practical model assigns critical controls a weight of five, major controls a weight of three, and standard controls a weight of one. Calculate the weighted percentage, but add non-negotiable gates. A supplier should not pass merely because strong housekeeping offsets a failed safety, regulatory, traceability, or change-control requirement.
Example decision rules might be:
| Decision | Example threshold | Sourcing consequence |
|---|---|---|
| Approved | At least 85%, no critical failures, major findings controlled | Eligible for defined production RFQs |
| Conditional | 70% to 84%, no uncontrolled critical risk | Eligible only with restrictions or before-action conditions |
| Development | 55% to 69% or capability not yet demonstrated | Prototype, sample, or development work only |
| Rejected or suspended | Below 55% or any unacceptable critical failure | Not eligible for RFQ or award |
Document the reason behind the rating. “Control 14 scored 1” is not useful six months later. Write the sampled lot, the expected evidence, what was missing, the operational consequence, and the owner who confirmed the condition.
Procurement also needs an auditable exception process. A business may choose a conditionally approved sole source because stopping production is worse than controlled short-term exposure. That decision should state the risk, compensating controls, authorized approver, volume or time limit, monitoring plan, and exit route. Exceptions that lack expiry dates become policy through inertia.
For categories with several viable suppliers, reflect risk in the RFQ evaluation. Do not manipulate the quoted price. Add explicit weighted criteria for demonstrated capacity, lead-time confidence, quality performance, continuity, and open corrective actions. AuraVMS gives teams a structured place to compare supplier responses, while the audit score remains the eligibility and risk input behind the commercial decision.
5. Convert findings into corrective actions that actually close risk
An audit report is unfinished until findings have owners, dates, evidence requirements, and consequences. Avoid vague requests such as “improve maintenance” or “strengthen traceability.” A corrective action should define the observed failure, containment, root cause, permanent correction, affected scope, due date, and effectiveness test.
Classify findings by urgency:
- Critical: immediate safety, legal, regulatory, traceability, product integrity, or continuity exposure. Block award or shipment unless formally contained and approved.
- Major: systemic breakdown or repeated failure that can materially affect quality, delivery, data, or compliance. Require a time-bound plan and normally close before production approval.
- Minor: isolated lapse that does not indicate system failure. Track to closure without distorting the overall risk picture.
- Opportunity: a useful improvement that is not a requirement. Keep it separate so the supplier can distinguish obligation from advice.
Containment protects current operations. Correction fixes the observed instance. Corrective action removes the cause. These are not interchangeable. Relabeling one unidentified pallet is correction; redesigning material status controls, retraining affected roles, checking all work-in-progress, and verifying sustained compliance is corrective action.
Require evidence proportional to the issue. A revised procedure does not prove implementation. Ask for completed records, photographs with context, training competence checks, updated system permissions, capability data, maintenance history, or an observed repeat trace. For a critical issue, use an on-site or live remote verification rather than accepting an email attachment.
Link open findings to commercial conditions. Examples include a capped order quantity until capacity is demonstrated, no award for a regulated part until validation closes, additional incoming inspection charged into total cost, dual sourcing until continuity controls pass, or shorter contract duration with a review gate.
This is where procurement creates leverage without bullying suppliers. Requirements become predictable, evidence replaces opinion, and capable suppliers know exactly how to progress. Weak suppliers cannot bury risk beneath a discount.
AuraVMS can then carry the commercial side of the controlled process: the same RFQ requirements go to each eligible supplier, responses arrive in a comparable structure, anonymous bidding can reduce tactical influence, and the sourcing team retains the record used for award.
6. Hand approved suppliers into the RFQ process without losing evidence
Audit completion should trigger a controlled handoff, not an email saying “supplier approved.” Create a supplier qualification record containing:
- Legal entity and approved manufacturing site
- Approved product families, materials, and processes
- Audit type, date, scope, score, and lead auditor
- Critical findings and closure evidence
- Open actions, restrictions, and expiry dates
- Required certifications and their expiration dates
- Capacity assumptions and demonstrated production rate
- Approved sub-suppliers or outsourced special processes
- Risk tier and re-audit trigger
- Named procurement, quality, and engineering owners
Before launching an RFQ, the buyer should check five things. Is the exact legal entity approved? Is the quoted manufacturing site within scope? Is the product or process family approved? Are critical findings closed or formally contained? Will the approval remain valid through the expected award and production period?
Then translate audit evidence into RFQ requirements. If the audit found capacity risk, ask suppliers to quote committed weekly capacity, ramp assumptions, competing-load constraints, and recovery options. If traceability is critical, require the proposed lot scheme and record-retention period. If tooling creates lock-in, request ownership, maintenance, replacement, and transfer terms. If a special process is outsourced, require the named source and change-approval obligation.
Keep evaluation fair. Every invited supplier should receive the same specification, deadline, clarification answers, and commercial template. If a requirement changes, issue it to all participants. Score price alongside total landed cost, lead time, quality evidence, supply risk, payment terms, tooling, warranty, and implementation needs.
AuraVMS is designed for this operational step. Procurement can invite suppliers without forcing them through account creation, which reduces response friction. Quotes can be collected and compared centrally rather than reconstructed from inconsistent emails and spreadsheets. Anonymous bidding can support a cleaner competitive process when appropriate. At $5 per month, the system gives an SMB procurement team a focused alternative to enterprise suites whose implementation effort may exceed the RFQ problem being solved.
The audit does not tell procurement which compliant supplier offers the best commercial outcome. The RFQ does not prove the supplier can execute. Used together, they produce a defensible award.
7. Implement the checklist in 90 days
Do not launch a giant supplier-governance transformation. Start with the categories where failure hurts.
Days 1 to 15: define scope and ownership. Select one critical category or 10 high-risk suppliers. Agree on risk dimensions, audit types, scoring scale, critical gates, approval statuses, and exception authority. Nominate a procurement owner and cross-functional reviewers.
Days 16 to 30: configure the checklist. Tailor the 50 controls to the product, applicable regulations, customer requirements, and manufacturing process. Mark critical controls. Create the pre-audit request, evidence naming convention, finding template, corrective-action form, and qualification record.
Days 31 to 50: pilot two suppliers. Choose one known strong supplier and one problematic or new supplier. This exposes vague questions and unrealistic evidence demands. Run traceability samples, compare auditor scoring, and test whether the final status leads to a clear sourcing decision.
Days 51 to 65: calibrate decisions. Review score differences across auditors. Tighten definitions, remove duplicative controls, refine weights, and set practical closure deadlines. Confirm how conditional approval affects order value, duration, inspection, or sourcing eligibility.
Days 66 to 80: connect qualification to sourcing. Update the approved supplier list, category strategy, and RFQ invitation rules. Build standard RFQ questions for capacity, traceability, changes, continuity, tooling, and commercial assumptions. Set reminders for certificate expiry, action due dates, and re-audit triggers.
Days 81 to 90: measure the operating result. Track audit cycle time, overdue corrective actions, repeat findings, conditional approvals, supplier response rate, RFQ cycle time, quality escapes, and delivery performance. The objective is not more audits. It is fewer preventable awards to suppliers that cannot perform.
Keep governance lean. A monthly 30-minute review can cover critical open findings, expiring approvals, suppliers entering new categories, recent quality or delivery events, and upcoming RFQs. Escalate only exceptions and material risk.
Use triggers as well as calendar dates. Re-audit when the supplier changes its site, ownership, critical process, major equipment, sub-supplier, material, or quality leadership; after a serious defect or delivery disruption; before a major volume increase; or when performance declines beyond an agreed threshold.
Once qualification is stable, use AuraVMS to shorten the next stage. The goal is to reduce the manual three-to-four-day RFQ cycle toward a two-hour controlled workflow while preserving the evidence that made each supplier eligible.
8. Frequently asked questions
What is a supplier audit checklist for a manufacturing company?
It is a structured set of controls used to verify whether a supplier can consistently meet technical, quality, delivery, compliance, continuity, security, and commercial requirements. A useful checklist requires objective evidence and leads to a defined approval status. It is not merely a questionnaire completed by the supplier.
How many controls should a supplier audit include?
There is no universal number. This 50-control checklist provides a practical baseline, but procurement should tailor it by product criticality, process complexity, regulatory exposure, sourcing dependence, and performance history. A focused 25-control process audit can be stronger than a generic 200-question survey.
Who should conduct a manufacturing supplier audit?
Use a cross-functional team appropriate to the risk. Procurement should own sourcing consequences, quality should test management and process controls, engineering should validate technical capability, operations should challenge capacity and delivery assumptions, and information security should join when sensitive data or connected access is involved.
Should a supplier be allowed to quote before the audit is complete?
For market discovery or budgetary pricing, sometimes yes. For production award, critical suppliers should meet the defined qualification threshold first. If urgent conditions require an exception, document containment, approval authority, limits, monitoring, and expiry rather than silently bypassing the rule.
What is the difference between an audit score and an RFQ score?
The audit score measures whether the supplier is capable and eligible within a defined scope. The RFQ score compares eligible suppliers on commercial and execution criteria such as price, total cost, lead time, terms, capacity, and risk. A low quotation cannot compensate for an unacceptable critical audit failure.
How often should manufacturing suppliers be re-audited?
Base frequency on risk and performance. High-risk or sole-source suppliers may require annual review or targeted surveillance. Lower-risk suppliers may be reviewed every two or three years. Site moves, major process changes, serious defects, ownership changes, capacity expansions, and sustained performance decline should trigger an earlier audit.
What evidence proves that a corrective action is closed?
Closure requires more than a revised procedure. Look for implemented controls, completed records, competent operators, updated systems, affected-product review, trend data, and an effectiveness check after enough time or production volume has passed. Critical issues may require on-site verification.
How should procurement use supplier audit results during quote comparison?
Use the audit to determine eligibility, restrictions, and risk inputs. Convert material risks into explicit RFQ questions and weighted criteria. Account for additional inspection, dual sourcing, tooling, recovery inventory, or qualification work in total cost. Keep the supplier's quoted price unchanged so the evaluation remains transparent.
Can a small procurement team manage this without an enterprise suite?
Yes. Begin with a risk-tiered checklist, a controlled evidence repository, named owners, and simple approval rules. For the sourcing step, AuraVMS helps a small team send structured RFQs, receive supplier responses without mandatory signup, compare quotes, and preserve the decision trail without buying a large source-to-pay platform.
What should happen immediately after a supplier passes the audit?
Record the approved legal entity, site, product and process scope, expiry, restrictions, and owners. Then launch a controlled competitive event among eligible suppliers. Turn approved suppliers into comparable RFQssee AuraVMS in action at https://www.auravms.com.