Customer, Supplier and Internal Audits
Supplier Audit
Your suppliers' quality is part of your quality system. Supplier audits are one of the main tools for selecting, evaluating and monitoring them, and under the QMSR the records of those audits are open to FDA inspection.
At a Glance
- Conducted by
- The manufacturer's supplier quality or quality team, or a qualified third party acting for it
- Basis
- Purchasing controls under ISO 13485:2016, as incorporated by the QMSR
- FDA access
- Supplier audit records are open to FDA inspection under the QMSR
- Guidance
- ISO 19011 for auditing management systems
What It Is
Manufacturers have to control the suppliers and contract manufacturers whose products and services affect device quality. How tightly depends on risk: a contract sterilizer or a critical component supplier warrants far more scrutiny than a supplier of general office goods. On-site or remote audits are a common way to evaluate and monitor the higher-risk ones.
Under the old Quality System Regulation, the 820.180(c) exception kept supplier audit reports, along with internal audit and management review reports, out of routine FDA review. The QMSR removed that exception. Investigators can now read what you found at a supplier and check whether you did anything about it.
Supplier audits are also where risk management meets purchasing. Your risk file should tell you which suppliers matter most, and your audit program should show you acted on that. Outsourcing and Purchasing is one of the six QMS areas in FDA's Compliance Program 7382.850.
Who Conducts It
Your supplier quality engineers or quality auditors, sometimes with process specialists for technical areas such as sterilization or software. Auditors should be qualified for the processes they audit.
Some manufacturers use third-party auditors, especially for distant suppliers. You remain responsible for the conclusions and the follow-up, so review third-party reports critically.
What Triggers It
- Qualifying a new supplier or contract manufacturer for a critical product or service
- Periodic requalification based on supplier risk and performance
- Nonconforming product, complaints or CAPA traced to a supplier
- Significant supplier changes, such as a new site, process or ownership
- Preparation for an FDA inspection, where Outsourcing and Purchasing is one of the six QMS areas
What They Look At
Fit of Controls to Risk
Whether the supplier's controls match how much their product or service affects device safety and performance.
Process Validation at the Supplier
Validation and monitoring of special processes the supplier performs for you.
Change Control and Notification
Whether the supplier controls its own changes and tells you before anything affecting your product changes.
Traceability and Records
Lot traceability, certificates of conformance and the records you rely on for acceptance.
The Supplier's Own Supplier Controls
How the supplier controls the sub-suppliers that feed your product.
Nonconformance and Corrective Action
How issues are contained, investigated and corrected, and how the supplier communicates them to you.
How to Prepare
- 01
Rank Suppliers by Risk
Use your risk file and supplier performance data to decide who gets audited and how often.
- 02
Build Audit Plans From Requirements
Base each audit on your purchasing requirements, the quality agreement and the processes the supplier performs.
- 03
Use Qualified Auditors
Train auditors on ISO 19011 principles and on the technical processes they audit.
- 04
Write Reports You'd Show FDA
Assume an investigator will read the report. Record facts, findings and required actions clearly.
- 05
Close the Loop
Track supplier corrective actions to closure and feed the results into supplier ratings and requalification.
Common Pitfalls
- An approved supplier list with no evidence of how suppliers were evaluated.
- Audit reports that record serious findings with no follow-up or decision.
- Questionnaires used in place of audits for suppliers whose processes can't be verified on paper.
- Overdue requalification audits for critical suppliers.
- Quality agreements that don't require change notification or allow audit access.
How QMSAdvisor Helps
- An AI-assisted review of your supplier files, audit reports and quality agreements, with advisor-confirmed findings on gaps in evaluation and follow-up.
- Supplier findings tracked in the action plan with owners, due dates and evidence requirements.
- Help designing a risk-based supplier audit program whose records you'd be comfortable having FDA read.
- CAPA records for supplier-related issues, from correction through effectiveness verification.
Supplier Audits and Supplier Controls
Risk-based supplier selection, quality agreements, monitoring and supplier audits that hold up under QMSR.
Internal Audit Program
A risk-based internal audit program, run by your team or our advisors, with reports written for FDA to read.
CAPA System Remediation
Fixing a CAPA system auditors keep citing: the procedure, the records, root cause, effectiveness and backlog.
FDA Inspection Readiness (CP 7382.850)
FDA device inspection preparation built around Compliance Program 7382.850 and its risk-based approach.
Standards and Regulations Involved
Questions About the Supplier Audit
Can FDA read our supplier audit reports now?
Yes. Under the QMSR, supplier audit records are open to FDA inspection because the former 820.180(c) exception was removed. Write reports accordingly and make sure findings show follow-up.
Do we need to audit every supplier?
No. Controls should match risk. Many suppliers can be managed through other evaluation methods, while critical suppliers and contract manufacturers usually warrant audits. Document the rationale either way.
Can we rely on a supplier's ISO 13485 certificate?
A certificate is useful evidence, but it doesn't show how the supplier controls your specific product or process. Use it as one input, alongside your own evaluation and, for critical suppliers, audits.
Are remote supplier audits acceptable?
They can work for document-heavy reviews and follow-ups, but some processes are hard to assess without seeing them. Decide based on risk, and record why the method you chose was adequate.
Related Audits and Inspections
Customer Audit
A customer's audit of your quality system, often a device maker auditing a supplier or contract manufacturer.
Internal Audit
Audits your own team runs of your quality system, now open to FDA inspection under the QMSR.
Remote and Hybrid Audits
Audits and regulatory assessments run partly or fully through video, screen sharing and electronic records.
EU Notified Body Audit (Including Unannounced Audits)
Conformity assessment, surveillance and unannounced audits by an EU notified body under the MDR or IVDR.
Request an Assessment
Prepare for Your Supplier Audit With an Advisor
Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.


