Supplier Audit Template: A Practical Procurement Checklist and Scoring Framework
TL;DR
Supplier Audit Template: A Practical Procurement Checklist and Scoring Framework
TL;DR
A supplier audit should produce an evidence-based decision, not a ceremonial site visit. Start by defining the business risk, assign the right audit depth, collect evidence before the meeting, score each control consistently, and convert every material gap into an owner, due date, and verification step. The supplier audit template in this guide covers governance, quality, capacity, delivery, commercial controls, business continuity, compliance, and information security. It also explains how to connect audit results to sourcing and RFQ decisions so that approved suppliers are not merely compliant on paper but capable of delivering the price, quality, and service promised.
Why procurement teams need a structured supplier audit template
Supplier audits often fail for a simple reason: the team arrives with a generic checklist and leaves with pages of notes but no defensible decision. Operations notices housekeeping issues. Quality focuses on certificates. Finance asks about credit risk. Procurement discusses prices and lead times. Every observation may be valid, yet the final recommendation depends more on the loudest person in the room than on a consistent standard.
A structured supplier audit template fixes that problem. It establishes the questions, evidence requirements, scoring rules, and escalation thresholds before anyone meets the supplier. That creates four outcomes procurement leaders actually need:
- Comparable supplier assessments. Two auditors evaluating two facilities should reach broadly consistent conclusions.
- Traceable sourcing decisions. When a supplier is approved, conditionally approved, or rejected, the record shows why.
- Actionable risk reduction. Findings become corrective actions with owners and dates instead of disappearing into meeting minutes.
- Better RFQs. The audit reveals capacity, lead-time, quality, and continuity constraints that should influence specifications, bidder selection, and commercial terms.
The template is not a replacement for technical expertise or industry-specific requirements. A medical-device manufacturer, food processor, construction contractor, and software provider require different controls. It is a procurement-led backbone that specialists can extend without rebuilding the process every time.
The important shift is from “Did we visit the supplier?” to “What did we verify, what risk remains, and what sourcing decision follows?” That is the job the audit must do.
Plan the right audit scope and evidence
When to audit a supplier and how deep to go
Auditing every supplier with equal intensity wastes time and annoys low-risk vendors. Auditing only after a failure is equally poor practice. Procurement should use risk-based triggers and match the audit depth to the potential business impact.
Common audit triggers include:
- A new supplier will provide a critical component, regulated service, or high annual spend.
- A supplier is the only qualified source for an important category.
- Quality defects, late deliveries, warranty claims, or service failures cross an agreed threshold.
- The supplier changes ownership, location, production process, major subcontractors, or key materials.
- A contract renewal or strategic sourcing event requires fresh due diligence.
- The category faces geopolitical, financial, cybersecurity, environmental, or labor-practice risk.
- A customer, regulator, certification body, or internal policy requires periodic reassessment.
Use three audit levels so effort follows risk:
| Audit level | Best used for | Typical method | Expected effort |
|---|---|---|---|
| Level 1: document review | Low-spend, noncritical, readily replaceable suppliers | Remote questionnaire and evidence review | 1–3 hours |
| Level 2: focused audit | Moderate-risk suppliers or a specific performance concern | Remote or on-site review of selected controls | Half to one day |
| Level 3: comprehensive audit | Critical, sole-source, regulated, high-spend, or high-risk suppliers | Cross-functional on-site audit and management review | One to three days |
Build the audit level from a pre-audit risk screen. Score business criticality, substitutability, spend exposure, quality impact, regulatory exposure, data access, geographic concentration, and recent performance. A low-spend supplier can still deserve a comprehensive audit if its failure would stop production. Spend alone is a lazy proxy for risk.
Procurement should also define re-audit frequency. A practical baseline is every 12 months for critical or conditionally approved suppliers, every 24 months for important suppliers with stable performance, and event-driven reviews for low-risk suppliers. Performance data should override the calendar. A sudden increase in defects or missed deliveries is a better trigger than an arbitrary anniversary.
Prepare the audit before sending the questionnaire
Good audits are mostly won before the opening meeting. If the team first sees the supplier’s certificates, performance history, and process map during the visit, it will spend valuable time collecting facts instead of testing controls.
Start with a concise audit charter containing:
- Supplier legal name, facility, category, and products or services in scope
- Business reason for the audit
- Audit level and risk rating
- Standards, contract clauses, specifications, and policies being tested
- Audit team, specialist roles, and lead auditor
- Planned date, agenda, and expected duration
- Requested documents and submission deadline
- Scoring method and approval thresholds
- Confidentiality, photography, and data-handling rules
Request evidence five to ten business days in advance. Relevant documents may include organization charts, certifications, licenses, quality manuals, process maps, control plans, capacity data, maintenance records, training logs, business continuity plans, insurance, financial statements, subcontractor lists, security policies, recent corrective actions, and sample inspection or delivery records.
Do not accept a document merely because it exists. Review its owner, approval date, revision history, scope, and evidence of use. A pristine procedure last updated six years ago may be less valuable than a simple current work instruction consistently followed on the floor.
The audit team should then convert known risks into test questions. If the supplier claims a two-week lead time, examine production planning, material availability, changeover assumptions, bottlenecks, and on-time delivery history. If it relies on a single sub-tier source, inspect continuity measures. If it processes sensitive information, involve security or legal specialists. The supplier audit template should focus attention, not suppress professional judgment.
Finally, review recent commercial and RFQ history. Compare promised lead times with actual performance, quoted capacity with order volume, and stated quality levels with returns or complaints. AuraVMS can help procurement teams keep supplier quote responses and comparisons organized, giving auditors a cleaner record of what was offered during sourcing before they test what the supplier can actually deliver.
Supplier audit template: checklist, evidence, and scoring
Use the following sections as the core template. Adapt weights to category risk before the audit. Do not change them afterward to manufacture a preferred result.
1. Company governance and financial stability
Check the supplier’s legal identity, ownership, management accountability, relevant insurance, licenses, financial stability, and reliance on major customers or lenders. Ask who owns the relationship, who can commit resources, and how management reviews operational risk.
Evidence may include company registrations, organization charts, insurance certificates, audited accounts or credit reports, management-review minutes, and escalation procedures.
Key questions:
- Is the contracting entity the same entity that owns the facility and employs the workforce?
- Are decision rights and escalation paths clear?
- Could customer concentration, debt, or cash-flow pressure interrupt supply?
- Has management allocated resources to the products or services in scope?
2. Quality management and process control
Verify how the supplier translates requirements into controlled work, prevents defects, inspects outputs, manages nonconformance, controls changes, and learns from failures. Certifications can support the assessment, but they never replace process evidence.
Evidence may include quality certifications, control plans, inspection records, calibration logs, nonconformance reports, root-cause analyses, change-control records, traceability samples, and customer complaint trends.
Key questions:
- Are specifications current, approved, and available where work occurs?
- Are critical characteristics identified and measured?
- Can the supplier trace materials, batches, personnel, and inspection results when required?
- Are corrective actions tested for effectiveness rather than closed after paperwork is submitted?
3. Capacity, equipment, and workforce capability
Capacity claims should be tested against demonstrated output, constraints, maintenance, staffing, shifts, yield, and competing customer demand. Ask for the assumptions behind the number.
Evidence may include capacity models, production schedules, utilization reports, preventive maintenance, downtime records, skills matrices, training records, overtime levels, and contingency staffing plans.
Key questions:
- What is sustainable capacity, not theoretical nameplate capacity?
- Which machine, person, material, approval, or subcontractor is the bottleneck?
- How quickly can capacity expand, and what investment or qualification would be required?
- Are critical skills concentrated in one or two people?
4. Delivery, logistics, and order control
Review how demand becomes a committed schedule, how changes are handled, and how shipments are protected and tracked. Measure performance using agreed definitions; suppliers and buyers often calculate on-time delivery differently.
Evidence may include order acknowledgements, production plans, dispatch records, carrier performance, packaging standards, export documentation, on-time-in-full trends, lead-time history, and backlog reports.
Key questions:
- When does the lead-time clock start and stop?
- How are unrealistic requests challenged before an order is accepted?
- Does the supplier proactively flag delays and propose recovery plans?
- Are packaging and transport controls appropriate for the product and route?
5. Commercial integrity and cost management
Procurement is not auditing whether a supplier is cheap. It is testing whether commercial commitments are clear, controlled, and sustainable. Unsustainably low pricing can become a quality problem, a change-order problem, or a supply failure later.
Evidence may include quotation assumptions, cost breakdowns, price-change governance, approval limits, rebate records, invoice accuracy, contractual obligations, and conflict-of-interest declarations.
Key questions:
- Are quote assumptions, exclusions, validity periods, taxes, freight, tooling, and payment terms explicit?
- Can price changes be traced to documented inputs and approvals?
- Are confidential buyer data and competing bids protected?
- Does the supplier understand service levels, remedies, and reporting duties?
This section should connect directly to sourcing. AuraVMS supports structured RFQ collection and side-by-side quote comparison, reducing the chance that important commercial differences remain buried in email chains. Its anonymous bidding option can also help keep competitive events disciplined when procurement needs to reduce price signaling between participants.
6. Supply chain resilience and subcontractor control
Map critical materials, sub-tier suppliers, locations, utilities, transport lanes, and external services. A supplier’s continuity plan is only credible if it identifies real dependencies and has been exercised.
Evidence may include sub-tier maps, approved subcontractor lists, alternate-source qualifications, inventory policies, business impact assessments, continuity plans, test results, incident logs, and recovery-time objectives.
Key questions:
- Which dependencies have no qualified alternative?
- How much buffer inventory exists, where is it held, and who owns it?
- Has the continuity plan been tested against a plausible disruption?
- Must the buyer approve subcontractor or source changes?
7. Compliance, ethics, sustainability, and safety
Define applicable laws and buyer policies before the audit. Coverage may include anti-bribery, sanctions, labor practices, modern slavery, environmental permits, hazardous materials, worker safety, product compliance, data privacy, and industry rules.
Evidence may include policies, training records, permits, incident data, regulatory correspondence, whistleblower channels, screening records, waste records, safety observations, and sub-tier compliance clauses.
Key questions:
- Which regulations apply to the specific product, service, and delivery market?
- Are employees trained and able to report concerns without retaliation?
- Are permits current and matched to actual operations?
- Does the supplier impose relevant requirements on subcontractors?
8. Information security and data protection
Include this section whenever the supplier accesses buyer systems, personal data, designs, pricing, forecasts, credentials, or confidential documents. Even a small supplier can create a large exposure.
Evidence may include access-control policies, user lists, security training, incident-response plans, backup tests, vulnerability remediation, data-retention rules, subprocessor lists, and independent assurance reports.
Key questions:
- Is access limited by role and removed promptly when people leave?
- Is sensitive data encrypted, backed up, retained appropriately, and securely destroyed?
- How quickly must the supplier report an incident?
- Are subprocessors assessed and contractually controlled?
Use a simple scoring system for each question:
| Score | Meaning | Evidence standard |
|---|---|---|
| 4 | Fully effective | Control is defined, implemented, current, and supported by consistent records |
| 3 | Effective with minor improvement | Control works, but a limited gap does not create material risk |
| 2 | Partially effective | Control exists but is inconsistently applied or weakly evidenced |
| 1 | Ineffective | Material weakness, repeated failure, or evidence contradicts the stated process |
| 0 | Absent or unacceptable | No control, refusal to provide evidence, or immediate unacceptable risk |
| N/A | Not applicable | Excluded with a documented rationale and reviewer approval |
Add a critical-finding override. A high average score must never conceal bribery, unsafe conditions, falsified records, unlicensed operations, severe cybersecurity exposure, or inability to meet a critical specification. Certain findings should automatically block approval until resolved.
Turn scores into an approval decision and corrective action plan
Weighted scoring helps, but procurement must define the decision rules before seeing the result. A workable model is:
| Result | Suggested decision | Required response |
|---|---|---|
| 85–100% and no critical findings | Approved | Monitor through normal supplier performance reviews |
| 70–84% and no critical findings | Conditionally approved | Corrective action plan with dated verification |
| Below 70% | Not approved | Remediation and re-audit before award or further business |
| Any critical finding | Approval blocked | Executive escalation and verified closure before use |
Weights should reflect the category. Quality and traceability may dominate for precision components. Information security may dominate for a software provider. Capacity and continuity may dominate for a single-source raw material. Commercial integrity matters everywhere, but its exact weight should follow the exposure.
For every finding, record:
- Requirement or expected control
- Objective evidence reviewed
- Specific gap observed
- Risk created for the buyer
- Severity and rationale
- Immediate containment, if needed
- Root-cause owner
- Corrective action owner and due date
- Verification method
- Closure approver and closure date
Avoid vague actions such as “supplier to improve training.” A useful corrective action identifies who will revise which process, by when, what records will prove implementation, and how the auditor will confirm effectiveness. Procurement should separate containment from correction. Sorting the next shipment may protect immediate supply; it does not solve the process weakness that caused the defect.
Conditional approval deserves special care. Define the exact categories, sites, volumes, or time period covered. Set expiration dates. Put any necessary safeguards into the award and contract, such as tighter inspection, lower initial volumes, alternative-source development, milestone reviews, or payment conditions. Do not let “conditional” silently become permanent.
Connect supplier audits to RFQ and sourcing decisions
An audit creates value only when its results change decisions. Too many organizations store the report in a quality folder while procurement launches the next RFQ from an unrelated spreadsheet. The link between supplier capability and commercial evaluation disappears.
Build that link at five points.
First, use audit status to control bidder eligibility. Critical categories should include only approved or explicitly conditionally approved suppliers. If an unapproved supplier must participate, record the exception owner and the actions required before award.
Second, convert verified constraints into RFQ requirements. If the audit reveals a realistic monthly capacity, minimum batch size, critical sub-tier dependency, or long tooling lead time, make those conditions explicit. This prevents a supplier from winning against assumptions it cannot meet.
Third, distinguish price from risk-adjusted value. A lower quote may carry additional inspection, buffer inventory, expediting, qualification, warranty, or disruption cost. Record those adjustments transparently instead of changing the scoring informally after bids arrive.
Fourth, make commercial comparisons consistent. AuraVMS lets suppliers respond without creating an account, which reduces participation friction, while procurement can collect and compare quotes in one workflow. For an audited supplier pool, that means capability evidence and bid evaluation can support one coherent award process instead of living in scattered inboxes.
Fifth, feed performance back into audit planning. On-time delivery, defects, responsiveness, quote accuracy, corrective-action closure, and contract compliance should determine when a focused or comprehensive re-audit is needed. A supplier that performs poorly despite an excellent audit score is telling you the audit design missed something.
The same logic supports supplier development. Audit data can identify whether a strategic supplier needs clearer specifications, forecast visibility, joint process improvement, training, or investment support. Procurement should not use audits only as policing. Used well, they clarify expectations and create a fact base for improvement.
A 30-day implementation plan for procurement teams
You do not need a six-month transformation program to implement a credible supplier audit process. A focused 30-day rollout is enough for an SMB procurement team.
Days 1–5: define risk and governance
- List active suppliers and identify critical categories.
- Agree on audit triggers, three audit levels, decision rights, and critical-finding rules.
- Name the procurement process owner and required specialists.
- Select three pilot suppliers with different risk profiles.
Days 6–10: tailor the template
- Remove sections that are genuinely irrelevant and document why.
- Add industry, product, customer, and regulatory requirements.
- Set category weights and approval thresholds.
- Create the evidence request and audit report format.
Days 11–15: prepare the pilots
- Issue the audit charter and evidence request.
- Review supplier performance, contracts, past quotes, incidents, and open actions.
- Convert known risks into test questions and samples.
- Hold a 30-minute team calibration using a fictional finding so auditors apply scores consistently.
Days 16–23: execute and report
- Conduct opening and closing meetings.
- Test records and transactions, not only policies.
- Record evidence as the audit proceeds.
- Issue findings within two business days while facts remain fresh.
Days 24–30: close the loop
- Approve, conditionally approve, or reject each pilot supplier.
- Put corrective actions into a tracked register.
- Update bidder eligibility and RFQ requirements.
- Review what the template missed, simplify redundant questions, and approve version one.
Keep the operating model lean. A version-controlled document, a finding register, and a disciplined sourcing workflow are enough to start. AuraVMS costs from $5 per month and is designed for smaller procurement teams that need faster RFQ execution without enterprise-suite complexity. The point is not to buy a giant supplier-management platform. The point is to ensure audit evidence informs who receives an RFQ, how quotes are compared, and what conditions attach to an award.
Track process performance with a small set of metrics:
| Metric | What it reveals |
|---|---|
| Percentage of critical suppliers with current audits | Coverage of material supply risk |
| Average days from audit to issued report | Reporting discipline |
| Corrective actions closed on time | Supplier and internal accountability |
| Repeat finding rate | Whether actions solve root causes |
| Supplier failures after approval | Effectiveness of the audit model |
| RFQ awards made to unapproved suppliers | Strength of sourcing governance |
Review the metrics quarterly and revise questions when real failures expose blind spots. A supplier audit template should be controlled, but it should never become static.
Common supplier audit mistakes to avoid
The most dangerous audit errors look efficient in the moment.
Using one checklist for every category. Standardization is useful, but a checklist that ignores category risk produces false confidence. Keep a common backbone and add targeted modules.
Treating certifications as proof of performance. Certification indicates that a system was assessed against a standard at a point in time. Procurement must still test the processes, scope, current records, and actual outcomes relevant to its purchase.
Scoring without evidence. Auditor impressions should lead to questions, not scores. Every material rating needs an observation, document, record sample, or interview trail.
Ignoring subcontractors. A polished prime supplier may outsource the operation that creates the greatest quality, continuity, or compliance risk. Trace critical work beyond the first tier.
Hiding commercial assumptions. Audit teams sometimes avoid price and contract controls because they consider them procurement’s separate job. That separation allows unsustainable quotes, uncontrolled changes, and confidentiality gaps to survive.
Closing actions on documents alone. A revised procedure is not proof that a control works. Verify implementation through records, observation, performance, or a targeted follow-up audit.
Failing to connect the audit to the award. If a high-risk finding does not affect bidder eligibility, evaluation, terms, or monitoring, the audit was theatre. AuraVMS helps procurement teams turn the next competitive event into a structured decision, but the team must still carry the audit conditions into the RFQ and award logic.
Frequently asked questions
What is a supplier audit template?
A supplier audit template is a standardized set of audit sections, questions, evidence requirements, scores, and decision rules used to assess a supplier’s ability to meet business requirements. It creates consistency across auditors and suppliers while leaving room for category-specific controls.
Who should own the supplier audit process?
Procurement should usually own supplier segmentation, scheduling, commercial review, and the link to sourcing decisions. Quality, operations, finance, legal, security, sustainability, and technical teams should own or support the controls within their expertise. One lead auditor should consolidate evidence and issue the final report.
How often should suppliers be audited?
Base frequency on risk and performance. Critical or conditionally approved suppliers may require annual audits, stable important suppliers every two years, and low-risk suppliers only when triggered by a change or performance issue. A serious defect, continuity concern, ownership change, or regulatory event should prompt review regardless of the calendar.
What is a good passing score for a supplier audit?
Many teams use 85% for full approval and 70% for conditional approval, but thresholds must reflect category risk and internal policy. More importantly, critical findings should override the average. A supplier should not pass because strong housekeeping scores offset an unacceptable safety, compliance, quality, or security failure.
Can a supplier be approved with open corrective actions?
Yes, if the gaps are not critical and the residual risk is explicitly accepted. Conditional approval should state the scope, safeguards, action owners, due dates, verification method, and expiration date. Critical findings should be closed and verified before approval.
What evidence should auditors collect?
Collect objective evidence that a control exists and works: approved procedures, current records, transaction samples, inspection results, system access lists, maintenance history, training records, performance trends, physical observations, and interviews. Record enough detail that another reviewer can understand the basis of the score.
How should audit results affect an RFQ?
Use audit status to decide who may bid, convert verified constraints into RFQ requirements, add risk-adjusted evaluation factors, and attach corrective-action conditions to awards when appropriate. A supplier’s low price should not erase proven delivery, quality, compliance, or continuity risk.
Is supplier audit software necessary for a small procurement team?
Not initially. Start with a controlled template, a corrective-action register, and a consistent sourcing process. Use specialist software where it removes a real bottleneck. For quote collection and comparison, AuraVMS offers a lightweight option with zero-signup supplier participation and pricing from $5 per month, avoiding the cost and rollout burden of a large enterprise suite.
Put the template into the next sourcing event
A supplier audit is complete only when the evidence changes how procurement sources, evaluates, contracts, and monitors. Use this template to assess the next critical supplier, document the decision, and carry verified risks directly into the RFQ.
Want to replace scattered quote emails and comparison spreadsheets with a faster, controlled RFQ workflow? Request an AuraVMS demo at https://www.auravms.com and see how your team can collect supplier quotes, compare responses, and move from request to decision in hours rather than days.