TSMS-QMS-083Quality Management Foundations3 of 5

Vendor Audits

Learn how risk-based vendor audits are planned, executed, documented, classified, followed up, and connected to supplier qualification, corrective actions, and ongoing performance monitoring.

Difficulty
Intermediate–Advanced
Reading time
36–44 min
Study time
4–5 hours
Last reviewed
August 1, 2026
On this page

Vendor Audits

Scientific Snapshot

Discipline: Quality Management and Supplier Oversight
Difficulty: Intermediate–Advanced
Course position: Lesson 3 of 5
Core concepts: audit scope, evidence, sampling, findings, risk classification, corrective action, follow-up.

Learning Objectives

Readers should be able to:

  • Explain the purpose of a vendor audit.
  • Distinguish on-site, remote, and document-based audits.
  • Describe audit planning and execution.
  • Classify findings based on risk.
  • Explain follow-up and closure.
  • Recognize audit limitations.

Executive Summary

A vendor audit is a structured evaluation of a supplier’s systems, facilities, records, and practices against defined requirements.

Audits support supplier qualification but do not replace:

  • lot testing,
  • incoming inspection,
  • ongoing monitoring,
  • quality agreements,
  • performance review.

The audit should be proportionate to supplier risk and focused on evidence rather than presentation quality.

Audit Objectives

Audits may evaluate:

  • quality-system implementation,
  • manufacturing control,
  • analytical testing,
  • documentation,
  • traceability,
  • data integrity,
  • change control,
  • complaints,
  • CAPA,
  • training,
  • subcontractor oversight.

Audit Types

On-Site Audit

Provides direct observation of facilities, operations, and records.

Remote Audit

Uses video, document sharing, interviews, and remote system review.

Desktop Audit

Relies primarily on questionnaires and records.

For-Cause Audit

Triggered by a serious issue, recurring failure, or significant concern.

Audit Planning

The audit plan should define:

  • objective,
  • scope,
  • criteria,
  • date,
  • duration,
  • audit team,
  • supplier contacts,
  • documents requested,
  • areas to review.

Auditor Competence

Auditors need:

  • technical understanding,
  • interviewing skill,
  • evidence evaluation,
  • independence,
  • report-writing ability,
  • knowledge of the applicable requirements.

Opening Meeting

The opening meeting confirms:

  • scope,
  • schedule,
  • communication,
  • confidentiality,
  • safety expectations,
  • access arrangements.

Evidence Collection

Audit evidence may include:

  • procedures,
  • records,
  • logs,
  • interviews,
  • observations,
  • electronic data,
  • physical conditions,
  • traceability exercises.

Evidence should be objective and traceable.

Sampling

Audits rely on sampling.

A clean sample does not prove that every record is acceptable.

Sampling should focus on risk and process significance.

Traceability Exercises

A traceability exercise may follow a lot backward and forward through:

  • raw materials,
  • production records,
  • testing,
  • release,
  • shipping,
  • complaints.

Data Integrity Review

Review may include:

  • unique user accounts,
  • audit trails,
  • data backup,
  • raw data retention,
  • integration changes,
  • electronic approvals,
  • access controls.

Audit Findings

Findings should include:

  • requirement,
  • objective evidence,
  • observed gap,
  • potential impact.

Finding Classification

Organizations may classify findings as:

  • critical,
  • major,
  • minor,
  • observation or opportunity.

Classification should reflect risk, not wording alone.

Closing Meeting

The closing meeting summarizes:

  • scope completed,
  • key findings,
  • unresolved questions,
  • response expectations,
  • next steps.

Audit Report

A report should include:

  • supplier identity,
  • scope,
  • criteria,
  • attendees,
  • evidence reviewed,
  • findings,
  • conclusion,
  • required actions,
  • timelines.

Corrective Action Response

The supplier response should address:

  • immediate correction,
  • root cause,
  • corrective action,
  • responsible owner,
  • due date,
  • effectiveness check.

Audit Closure

Closure requires evidence that actions were implemented and effective.

A written promise alone is not always sufficient.

Audit Frequency

Frequency may depend on:

  • supplier criticality,
  • prior findings,
  • performance,
  • change history,
  • complaint history,
  • alternative controls.

Audit Limitations

An audit is a time-limited sample.

It cannot guarantee future performance or detect every hidden problem.

Science Makes Sense

A vendor audit is like inspecting a bridge.

You review design, maintenance records, observed condition, and structural evidence. A good inspection reduces uncertainty, but it does not eliminate the need for ongoing monitoring.

Common Misconceptions

“No findings means no risk.”

Audit sampling can miss problems.

“Remote audits are always inferior.”

Their value depends on scope, evidence access, and supplier risk.

“An audit checklist is the audit.”

Checklists support consistency, but auditors must follow evidence and risk.

Laboratory Best Practices

  • Define risk-based scope.
  • Use competent auditors.
  • Request documents in advance.
  • Trace actual records.
  • Review data integrity.
  • Write evidence-based findings.
  • Require root-cause responses.
  • Verify effectiveness.
  • Link findings to supplier status.

Frequently Asked Questions

When is an on-site audit appropriate?

For higher-risk suppliers or when direct observation is important.

What is objective evidence?

Verifiable information supporting an audit conclusion.

Why classify findings?

To align response urgency and supplier decisions with risk.

What closes an audit finding?

Evidence that corrective action was implemented and effective.

Can an audit replace incoming testing?

No.

Key Takeaways

  • Audits are structured, evidence-based assessments.
  • Scope should reflect risk.
  • Sampling is a limitation.
  • Findings require objective evidence.
  • Corrective action should address root cause.
  • Audit outcomes influence supplier status.

Suggested Figures

  1. Audit lifecycle.
  2. Audit-type comparison.
  3. Evidence-trail map.
  4. Finding classification matrix.
  5. Corrective-action follow-up.
  6. Supplier status decision tree.

Knowledge Check

  1. Why is audit scope risk-based?
  2. What is objective evidence?
  3. Why are audits based on sampling?
  4. What should a supplier corrective-action response include?
  5. Why does audit closure require effectiveness evidence?

References

  1. ISO 19011. Guidelines for Auditing Management Systems.
  2. ISO 9001. Quality Management Systems — Requirements.
  3. ICH Q9. Quality Risk Management.
  4. ICH Q10. Pharmaceutical Quality System.

Editorial Note

Version 1.0 establishes the evidence-based audit framework used in supplier oversight.

Evidence records

Structured registry entries linked to this lesson. Imported records may still await metadata verification.

Related

  • Supplier Qualification

    Understand how organizations assess, approve, monitor, and requalify suppliers using risk, documentation, performance history, quality agreements, testing evidence, and change-notification controls.

  • Raw Material Qualification

    Understand how raw materials are specified, sampled, tested, released, monitored, and linked to supplier controls, traceability, change management, and scientifically justified acceptance criteria.

Public ID TSMS-QMS-083 · Version 1.0