Supplier audit: Definition, types, and process

- What is a supplier audit?
- Why supplier audits matter
- Types of supplier audits
- Who conducts a supplier audit?
- When to conduct a supplier audit
- How to conduct a supplier audit step by step
- How to build a supplier audit checklist
- Common issues found during a supplier audit
- How to mitigate a failed supplier audit
- Enhance your purchasing process with Ramp

Skipping thorough supplier audits can lead to quality problems, delivery delays, and even legal exposure, each of which can damage your reputation and your bottom line. A supplier audit evaluates a vendor's facilities, operations, and processes to confirm they meet your quality, contractual, and regulatory requirements.
It gives you the evidence you need to trust your supply chain and hold vendors accountable.
What is a supplier audit?
A supplier audit is a systematic evaluation of a vendor's facilities, operations, and processes to verify compliance with quality standards, contractual requirements, and industry regulations.
Supplier audits often involve on-site visits, document reviews, interviews with personnel, and direct observation of operations. They may be conducted before onboarding a new supplier (prequalification audit), at regular intervals (routine audit), or in response to performance issues (for-cause audit).
The main objectives are to confirm quality and consistency, ensure compliance with regulatory and contractual requirements, identify risks in the supply chain, and strengthen collaboration with vendors.
The terms "supplier audit" and "vendor audit" are often used interchangeably. In some contexts, supplier audits emphasize production and quality processes, while vendor audits focus more broadly on vendor compliance and financial considerations.
Why supplier audits matter
Supplier audits strengthen your supply chain by ensuring consistency, compliance, and accountability. Benefits include:
- Quality assurance: Confirm that suppliers meet agreed quality standards, helping you maintain product consistency and reliability
- Risk mitigation: Spot risks early to prevent production delays, defects, and reputational damage
- Regulatory compliance: Ensure suppliers meet legal and industry requirements, reducing exposure to penalties or lawsuits
- Efficiency improvements: Identify bottlenecks or inefficiencies that drive up costs
- Customer satisfaction: Ensure suppliers deliver reliably so you can reduce complaints and returns
- Continuous improvement: Encourage transparent communication and establish benchmarks for long-term growth
Supplier audits ultimately contribute to a more resilient, reliable supply chain that protects both operations and reputation. That structured oversight pays off, too. For example, Ramp Procurement customers save 16% on average each year on vendor spend.
Types of supplier audits
Each type of supplier audit targets a different aspect of the supplier relationship. Choosing the right type allows you to focus on the most significant risks and opportunities for improvement instead of running overly broad evaluations.
| Type | What is assessed | Ideal for |
|---|---|---|
| Quality system audit | Quality management system maturity; compliance with standards | Qualifying new suppliers; periodic supplier evaluations |
| Process audit | Workflow controls; material handling and storage practices | Evaluating high-risk suppliers; investigating recurring quality issues |
| Product audit | Finished goods, labeling, and packaging quality | Launching new products; responding to customer complaints |
| Environmental audit | Environmental management systems; waste handling, emissions, sustainability practices | Regulated industries; companies with ESG commitments |
| Compliance audit | Adherence to industry regulations; data security and privacy | Highly regulated industries; responding to legislative requirements |
Quality system audit
A quality system audit assesses the maturity of a supplier's quality management system and its compliance with standards such as ISO 9001. Sometimes called a supplier quality audit, it's best for qualifying new suppliers and running periodic evaluations .
Process audit
A process audit reviews specific workflow controls, material handling, and storage practices. Unlike a quality system audit, it zeroes in on how work actually gets done on the floor. This makes it the right choice for high-risk suppliers or when recurring quality issues point to a breakdown in execution.
Product audit
A product audit inspects finished goods, labeling, and packaging quality against your specifications. Run one when you're launching new products or when customer complaints suggest something is slipping through final inspection.
Compliance audit
A compliance audit verifies adherence to industry regulations along with data security and privacy requirements, so it's a priority in highly regulated industries. It often works alongside an environmental audit, which assesses environmental management systems, waste handling, and sustainability practices for companies with ESG commitments.
Announced, unannounced, and desktop audit formats
Supplier audits can be conducted in different ways, depending on your goals and context:
- Announced audits: Scheduled in advance, giving suppliers time to prepare. Useful for thorough, planned evaluations of systems and processes.
- Unannounced audits: Conducted without prior notice, offering a real-time snapshot of everyday practices and uncovering hidden issues
- Desktop audits: Performed remotely by reviewing documentation and records. Helpful for initial assessments, follow-ups, or when site visits aren't possible.
How to choose an audit type
Select an audit type based on your objectives and where risks are greatest:
- A quality system audit is best when you're concerned about a supplier's ability to consistently meet specifications and standards
- A process audit makes sense when you need to verify that workflows and methodologies align with your requirements or industry best practices
- Product and compliance audits should be prioritized when your suppliers operate under strict regulations or when their goods directly affect your product's safety or performance
- An environmental audit is most useful if your industry has sustainability or environmental compliance requirements, or if ESG performance is part of your procurement strategy
Who conducts a supplier audit?
Supplier audits are typically performed by teams with the right mix of technical knowledge and business insight. Some companies build internal audit teams that specialize in evaluating suppliers against company standards, while others hire third-party auditors for their objectivity and specialized expertise.
However you structure it, effective audits rely on contributors with complementary skills:
- Quality assurance professionals: Understand product quality standards and specifications, spotting potential issues before they escalate
- Procurement specialists: Bring deep knowledge of supply chain management and supplier relationships, and can assess whether contractual requirements are being met
- Subject matter experts: Join as needed depending on the supplier. For example, a food safety expert is invaluable when evaluating a food supplier.
Internal vs. external audits
Internal audits are often more cost-effective and can be tailored closely to company standards, but they may lack the objectivity needed to uncover blind spots. External audits bring impartiality, industry expertise, and added credibility with regulators and customers, though they typically require more time and expense.
Many companies rely on a mix of both approaches, balancing internal familiarity with external validation to strengthen oversight of their supply base.
When to conduct a supplier audit
Conduct a supplier audit whenever a supplier's performance, risk, or regulatory exposure could affect your business, and on a recurring schedule for your most critical vendors. Most supplier audits fall into one of four triggers:
- Initial qualification: Before onboarding a new supplier
- Routine intervals: To monitor ongoing performance over time
- For-cause: After a nonconformance, complaint, or regulatory action
- Follow-up: To verify that corrective actions have closed
How often you audit depends on supplier risk. Audit high-risk or critical suppliers typically every 1 to 2 years and low-risk suppliers roughly every 3 years, adjusting for regulatory requirements, compliance history, and previous audit outcomes.
How to conduct a supplier audit step by step
Conducting a supplier audit requires preparation, thorough onsite or remote work, and structured follow-up. The process typically unfolds in five key stages.
1. Prepare and plan
Preparation lays the foundation for a successful evaluation that yields actionable insights while maintaining positive supplier relationships. Choose the audit type and format, assemble a cross-functional team, develop a detailed plan and checklist, communicate expectations to the supplier, and coordinate dates so all relevant parties can participate.
2. Gather information
Strong preparation depends on good data. Review quality manuals, process flows, standard operating procedures (SOPs), and past audit reports. Reviewing financial records alongside operational documentation can also surface discrepancies worth investigating before you arrive onsite. Sending a pre-audit questionnaire helps you target high-risk areas before arriving onsite.
You can also spare your team much of this legwork instead of assembling it by hand. Ramp's Procurement Agent runs SOC 2 and ISO 27001 checks, security and compliance scanning, and contract term analysis, then attaches cited summary reports before an audit or approval so you walk in with the context already gathered.
3. Conduct the audit
The audit itself is where you validate how the supplier operates. Begin with a kickoff meeting to set scope and communication methods. Tour the facility to observe conditions and capacity. Interview staff, review records, and capture objective evidence. Wrap up with a closing meeting that shares balanced feedback on both strengths and improvement areas.
4. Analyze findings
After the visit, review all observations carefully. Organize notes and evidence, identify any nonconformances, and compare them against predefined standards. Then assess overall supplier performance, highlighting both compliance and risks that require attention.
5. Report and follow up
The last step ensures issues are resolved and improvements sustained. Create a detailed report with findings and supporting evidence. Share it with the supplier, develop a corrective action plan (CAP) with specific owners and deadlines, and monitor implementation through follow-ups until all items are closed.
How to build a supplier audit checklist
A supplier audit checklist is a standardized set of criteria you use to evaluate suppliers consistently, so every auditor measures the same controls the same way regardless of who runs the audit or which supplier they visit. Build one with a simple, repeatable framework:
- Define your audit objectives and scope
- Gather the requirements and standards the supplier must meet
- Review supplier documentation, including quality manuals, SOPs, certifications, and records
- Set objective, measurable audit criteria
- Tailor the checklist to the specific supplier and industry
- Pilot test the checklist, then finalize and distribute it
A practical checklist covers the areas where problems most often hide:
- Documentation and version control
- Process controls and work instructions
- Corrective-action history
- Calibration and equipment maintenance records
- Regulatory and industry compliance
Keep the checklist objective and measurable so results are comparable over time. A well-built checklist turns each audit into a repeatable benchmark rather than a one-off judgment call.
Teams that have already modernized their purchasing workflows—like those using AI-powered accounting software—often find it easier to maintain the documentation discipline a strong checklist requires.
Common issues found during a supplier audit
Even with strong preparation, audits tend to surface a familiar set of quality and compliance nonconformances.
- Documentation gaps or incomplete records: Missing SOPs, outdated procedures, and weak version control make it hard to validate a supplier's claims and raise questions about internal controls
- Process and quality-control failures: Workflow steps that aren't followed or inadequate in-process controls signal that stated procedures don't hold up on the shop floor
- Uncalibrated equipment or missing calibration logs: Equipment that's out of calibration, or logs that can't prove it isn't, undermines confidence in the supplier's measurements and output
- Inconsistencies between records and observed practice: When official documentation doesn't match what you see on-site, it's a sign that policies exist on paper but not in daily operations
- Resistance or lack of cooperation: Evasive answers, delays, or withheld records are a red flag that should prompt further investigation before you move forward
Watching for these patterns helps you separate minor administrative gaps from risks that demand immediate corrective action.
How to mitigate a failed supplier audit
A failed audit doesn't have to end the relationship. Treat it as a remediation project that requires transparency, clear ownership, and sustained follow-up.
- Communicate openly: Share findings in a fact-based, non-accusatory way. Ensure the supplier understands the issues and why resolving them matters for the partnership.
- Develop a corrective action plan (CAP): Outline steps for each issue, assign owners, set deadlines, and define measurable outcomes for success
- Set realistic deadlines: Balance urgency with practicality. Quick fixes may be possible, but complex changes often need more time.
- Offer support and resources: Provide training, templates, or best practices. Guidance from your team or external experts can accelerate progress.
- Conduct follow-up audits: Confirm corrective actions are in place and effective, focusing specifically on previously identified issues
- Consider probationary periods: For critical suppliers, use probation with closer monitoring to underscore seriousness while preserving the relationship
- Document everything: Keep records of reports, communications, and corrective actions to ensure accountability and provide future reference
- Prepare contingency plans: If major issues remain unresolved, identify alternative suppliers or backup processes to minimize disruption
A failed audit is a checkpoint, not an endpoint. With clear communication, disciplined follow-through, and contingency planning, most supplier relationships can recover and become stronger than before.
Enhance your purchasing process with Ramp
Ramp connects directly to your purchasing operations, giving your team the tools to simplify purchasing and vendor management. See how other finance teams are putting it to work with a look at how Ramp uses Ramp Procurement internally.
With Ramp's purchasing software, you can:
- Centralize purchase requests: Consolidate all purchasing requests into a single platform, eliminating the need for email chains or spreadsheets
- Gain real-time spending visibility: Access up-to-date spending data through a unified dashboard, enabling informed decisions about vendor relationships and budget allocation
- Customize approval workflows: Implement tailored approval processes to expedite routine purchases while maintaining appropriate controls and compliance
- Automate compliance reviews with AI agents: Run vendor due diligence, security checks, and contract risk analysis before a request ever reaches an approver
- Track every renewal automatically: Ramp surfaces pricing benchmarks, flags agreements worth renegotiating, and recommends whether to extend, renegotiate, or cancel
- Benchmark prices accurately: Use Ramp's Price Intelligence to compare contract rates against what other businesses are paying
- Connect to your existing tools: Set up integrations across CLM, eSignature, TPRM, and ticketing platforms
Explore an interactive demo to see how our purchasing solution can enhance your vendor management system.

FAQs
A supplier audit is a systematic evaluation of a vendor's facilities, operations, and processes to verify compliance with quality standards, contractual requirements, and industry regulations. It often combines on-site visits, document reviews, and interviews to confirm a supplier can consistently meet your requirements.
The three most common types are quality system audits, process audits, and product audits. Many programs also add compliance and environmental audits when suppliers operate under strict regulations or ESG commitments.
A supplier audit checklist is a standardized set of criteria auditors use to evaluate a supplier's documentation, processes, and controls consistently. It keeps evaluations objective and repeatable across different suppliers and auditors.
Audit high-risk or critical suppliers every 1 to 2 years and low-risk suppliers roughly every 3 years. Adjust the frequency based on regulatory requirements, compliance history, and previous audit outcomes.
“Invoices, cards, tokens. The categories change but the principle doesn't: know where the money is going, remove the work around it, and make sure the spend is worth it.”
Maciej Mylik. Finance
ElevenLabs

“There's just no surprises anymore. No more waiting two months to find out how a job did. We know how it's doing as it's happening.”
Erich Kuss
Financial Systems Manager, Infinity Home Services

“More token spend isn’t proof that AI is working. Less isn’t proof that it isn’t. What matters is whether we’re buying the right level of intelligence for the work. Ramp lets us make that judgment in the same place we manage every other type of spend.”
Cody Nutt
Senior Director of Business Systems, Daxko

“Most banks treat the back office as a cost to keep down. We treat ours as a return to compound, which is why we run it on Ramp. Now we put our clients on Ramp, too.”
Patrick Gaughen
President & COO, Hingham Institution for Savings

“Browserbase builds infrastructure so AI agents can do real work. Ramp is doing the same for finance. It’s not another tool. It’s a system purpose-built for AI-driven finance, and that’s why we chose Ramp as our financial operating system from day one.”
Paul Klein IV
Founder & CEO, Browserbase

“We used to pay up to $20k a year for our AP platform. With Ramp, we’re earning back well over that amount. That's money that belongs to the mission now, not to the back-office software.”
Heidi Coffer
Chief Financial Officer, Boys & Girls Clubs of San Francisco

“The tricky thing about corporate travel policy is timing. We didn't need a stricter policy. We needed the policy to show up earlier. With Ramp Travel, it finally does.”
Keith Frantz
Director of Enterprise Risk Management, Prosper

“We're accountable to our funders, our partners, and the families we serve. That accountability starts with how we manage every dollar. Ramp makes it easy for our team to spend wisely, track in real time, and keep overhead low so more resources reach the families navigating infertility.”
Rachel Fruchtman
CFO, Jewish Fertility Foundation


