QMSAdvisor

Customer, Supplier and Internal Audits

Supplier Audit

Your suppliers' quality is part of your quality system. Supplier audits are one of the main tools for selecting, evaluating and monitoring them, and under the QMSR the records of those audits are open to FDA inspection.

At a Glance

Conducted by
The manufacturer's supplier quality or quality team, or a qualified third party acting for it
Basis
Purchasing controls under ISO 13485:2016, as incorporated by the QMSR
FDA access
Supplier audit records are open to FDA inspection under the QMSR
Guidance
ISO 19011 for auditing management systems

What It Is

Manufacturers have to control the suppliers and contract manufacturers whose products and services affect device quality. How tightly depends on risk: a contract sterilizer or a critical component supplier warrants far more scrutiny than a supplier of general office goods. On-site or remote audits are a common way to evaluate and monitor the higher-risk ones.

Under the old Quality System Regulation, the 820.180(c) exception kept supplier audit reports, along with internal audit and management review reports, out of routine FDA review. The QMSR removed that exception. Investigators can now read what you found at a supplier and check whether you did anything about it.

Supplier audits are also where risk management meets purchasing. Your risk file should tell you which suppliers matter most, and your audit program should show you acted on that. Outsourcing and Purchasing is one of the six QMS areas in FDA's Compliance Program 7382.850.

Who Conducts It

Your supplier quality engineers or quality auditors, sometimes with process specialists for technical areas such as sterilization or software. Auditors should be qualified for the processes they audit.

Some manufacturers use third-party auditors, especially for distant suppliers. You remain responsible for the conclusions and the follow-up, so review third-party reports critically.

What Triggers It

  • Qualifying a new supplier or contract manufacturer for a critical product or service
  • Periodic requalification based on supplier risk and performance
  • Nonconforming product, complaints or CAPA traced to a supplier
  • Significant supplier changes, such as a new site, process or ownership
  • Preparation for an FDA inspection, where Outsourcing and Purchasing is one of the six QMS areas

What They Look At

  • Fit of Controls to Risk

    Whether the supplier's controls match how much their product or service affects device safety and performance.

  • Process Validation at the Supplier

    Validation and monitoring of special processes the supplier performs for you.

  • Change Control and Notification

    Whether the supplier controls its own changes and tells you before anything affecting your product changes.

  • Traceability and Records

    Lot traceability, certificates of conformance and the records you rely on for acceptance.

  • The Supplier's Own Supplier Controls

    How the supplier controls the sub-suppliers that feed your product.

  • Nonconformance and Corrective Action

    How issues are contained, investigated and corrected, and how the supplier communicates them to you.

How to Prepare

  1. 01

    Rank Suppliers by Risk

    Use your risk file and supplier performance data to decide who gets audited and how often.

  2. 02

    Build Audit Plans From Requirements

    Base each audit on your purchasing requirements, the quality agreement and the processes the supplier performs.

  3. 03

    Use Qualified Auditors

    Train auditors on ISO 19011 principles and on the technical processes they audit.

  4. 04

    Write Reports You'd Show FDA

    Assume an investigator will read the report. Record facts, findings and required actions clearly.

  5. 05

    Close the Loop

    Track supplier corrective actions to closure and feed the results into supplier ratings and requalification.

Common Pitfalls

  • An approved supplier list with no evidence of how suppliers were evaluated.
  • Audit reports that record serious findings with no follow-up or decision.
  • Questionnaires used in place of audits for suppliers whose processes can't be verified on paper.
  • Overdue requalification audits for critical suppliers.
  • Quality agreements that don't require change notification or allow audit access.

How QMSAdvisor Helps

  • An AI-assisted review of your supplier files, audit reports and quality agreements, with advisor-confirmed findings on gaps in evaluation and follow-up.
  • Supplier findings tracked in the action plan with owners, due dates and evidence requirements.
  • Help designing a risk-based supplier audit program whose records you'd be comfortable having FDA read.
  • CAPA records for supplier-related issues, from correction through effectiveness verification.

Standards and Regulations Involved

Questions About the Supplier Audit

Can FDA read our supplier audit reports now?

Yes. Under the QMSR, supplier audit records are open to FDA inspection because the former 820.180(c) exception was removed. Write reports accordingly and make sure findings show follow-up.

Do we need to audit every supplier?

No. Controls should match risk. Many suppliers can be managed through other evaluation methods, while critical suppliers and contract manufacturers usually warrant audits. Document the rationale either way.

Can we rely on a supplier's ISO 13485 certificate?

A certificate is useful evidence, but it doesn't show how the supplier controls your specific product or process. Use it as one input, alongside your own evaluation and, for critical suppliers, audits.

Are remote supplier audits acceptable?

They can work for document-heavy reviews and follow-ups, but some processes are hard to assess without seeing them. Decide based on risk, and record why the method you chose was adequate.

Request an Assessment

Prepare for Your Supplier Audit With an Advisor

Tell us what's coming and when, and an advisor will scope readiness work around it. Please don't send confidential documents yet: secure upload is set up after onboarding.