How to audit suppliers with second-party auditing

ISO 27001ISO 9001

Second-party auditing evaluates suppliers from the contracting organization's perspective. It is the most effective mechanism to verify that critical suppliers meet management system requirements.

1

Step 1: Classify suppliers by criticality and risk

Not all suppliers require auditing. Classify them by the impact a supplier failure would have on your operation, product quality, or regulatory compliance.

2

Step 2: Define audit criteria

Establish what requirements you will evaluate against: contractual clauses, normative requirements, technical specifications, or a combination. Criteria must be communicated to the supplier before the audit.

3

Step 3: Plan and execute the audit

Prepare an audit plan with scope, schedule, and audit team. During execution, combine document review, interviews, and direct process observation.

4

Step 4: Report findings and manage corrective actions

Classify findings by severity and agree with the supplier on a corrective action plan with verifiable deadlines. Follow up until effective closure.

5

Step 5: Integrate results into supplier management

Audit results should feed renewal, qualification, and supplier development decisions. Establish a re-audit cycle based on risk level.

Conclusion

Second-party auditing is the most effective mechanism for managing supplier risk. Classify suppliers by criticality before auditing. Integrate results into the supplier management cycle.

Want to know where your system stands?

Request diagnostic