How to Conduct a Global Supplier Quality Audit

Automa.Net
Automa.Net
|Published:|8 min read

Why a Global Supplier Quality Audit Fails Without a Scope

A machine goes down, the OEM quotes 20 weeks for a replacement drive, and your buyer starts hunting for a verified alternative. That is the moment supplier quality matters most, and it is also the moment most audits were never designed to handle.

A supplier quality audit is a documented, evidence-based evaluation of whether a supplier can consistently deliver conforming parts and services against agreed criteria. Without a defined audit scope, that evaluation collapses into a plant tour with a clipboard.

Scope decides three things: which sites you visit, which processes you examine, and which parts of the quality management system you test. Get it wrong and you audit everything, learn nothing, and burn weeks of engineering time.

Risk-based planning has replaced blanket auditing. Industry practice now prioritizes suppliers by risk profile rather than auditing every vendor equally (Kodiak Hub on supplier quality audits). For a legacy PLC or discontinued servo drive, the risk is not the supplier's ISO certificate. It is whether the part is genuine, whether the firmware matches, and whether the supplier can prove where it came from.

The Supplier Quality Audit Checklist We Use on the Shop Floor

Auditor in safety gear inspecting a control cabinet during a supplier quality audit on the factory floor

A supplier quality audit checklist is a structured list of evidence items you verify on site, covering documentation, process control, traceability, and corrective action history. It keeps the audit consistent across sites and auditors.

On the floor, an audit typically works through five blocks. Each block has a pass condition, not just a tick box:

  • Documentation review: control plans, work instructions, SOP revisions. Pass condition: the revision on the shop floor matches the revision in the document control system on the day of the audit.
  • Traceability: lot numbers, date codes, incoming goods records, supplier batch mapping. Pass condition: a randomly picked finished unit can be traced back to a named incoming lot in under 15 minutes.
  • Process audit: test equipment calibration, ESD handling, storage conditions. Pass condition: every calibration sticker on the line is in date, and the ESD wrist strap tester log shows daily checks.
  • Inspection records: outgoing quality checks, non-conformance logs, scrap rates. Pass condition: the last 20 non-conformances each have a disposition, an owner, and a closure date.
  • Corrective action: open CAPAs, root cause analysis depth, closure evidence. Pass condition: no CAPA older than 90 days is still open without a documented reason.

Score each block 0-3 (0 = absent, 1 = documented but not practiced, 2 = practiced with gaps, 3 = practiced and evidenced).

Auditing every supplier with the same checklist wastes your best auditors on low-risk vendors. Score suppliers by risk first, then assign checklist depth. Uniform audits create uniform blind spots.

What changes when the part is obsolete

Standard checklists assume the manufacturer still controls the process. For obsolete and hard-to-find parts, the manufacturer is out of the loop. Add three items to the checklist when the part is discontinued:

  • Firmware and hardware revision match: the nameplate revision must match the revision the machine's BOM expects. A mismatched firmware revision on a VFD or servo drive can pass a visual inspection and still fail on commissioning.
  • Packaging integrity: original sealed packaging versus re-bagged stock. Re-bagged electrolytic capacitors past shelf life are a common failure source.
  • Test evidence per unit: not a batch certificate, but a per-unit test record against the original OEM specification.

How to Audit Surplus Parts Distributors and Legacy Stock

Auditing a surplus parts distributor is not the same as auditing a component manufacturer. The product is already built. Your job is to verify provenance, condition, and documentation.

Start with these questions:

  • Where did the stock originate: OEM overstock, line closure, or broker chain?
  • Can the distributor show the full chain of custody?
  • Are date codes and firmware revisions documented per unit?
  • How is stock stored: humidity, ESD protection, shelf life for electrolytic capacitors?
  • Is the part tested before dispatch, and against what specification?
Supplier TypeWhat to VerifyMain Risk
OEM overstockOriginal packaging, date codesStorage conditions
RefurbishedTest report, warranty termsHidden wear
Surplus brokerChain of custody, prior handlingUnknown provenance
Ask for the nameplate photo before the quote, not after. A part number on a label and a part number on a nameplate are different evidence. Tools like AutomaSnap read nameplates from a photo, which shortens the verification loop when a buyer is sourcing against a 20-week OEM lead time.

Best Practices for Remote Supplier Audits in a Hybrid Model

Remote supplier audits work when you split the audit by evidence type. Documents go remote. Physical verification stays on site.

Find it on Automa.Net →

In a hybrid model:

  • Remote: documentation review, pre-audit meeting, management interviews, audit report walkthrough
  • On site: process audit, on-site inspection, sample testing, witness points
  • Both: audit findings validation, corrective action agreement
Remote audits cut travel cost and time. They do not cut the need for one physical visit per high-risk supplier. Budget the site visit where the risk sits.

From Audit Findings to CAPA: Closing the Non-Conformance Loop

A non-conformance without a closed corrective action is a note in a folder. The audit only creates value when the loop closes. Most guides stop at the five-step list. The gap is the template that makes those five steps auditable.

  1. Containment action within 48 hours. What stops the defect reaching your line today? For a suspect batch of obsolete relays or contactors, containment means quarantine plus a written statement of how many units are affected and where they are.
  2. Root cause analysis using 5-Why or fishbone. The output must name a process failure, not a person. "Operator error" is not a root cause; "no poka-yoke on the connector orientation step" is.
  3. Corrective action with an owner and a date. One named person, one calendar date. Not a department, not "Q3".
  4. Preventive action that changes the process, not just the part. Re-testing the suspect batch is containment, not prevention. Updating the incoming inspection instruction is prevention.
  5. Verification evidence at the next audit. The CAPA stays open until the next audit confirms the process change held.

A CAPA record you can actually audit against

Use this structure as the minimum record for every finding. It is the template most audit guides omit.

FieldWhat goes in itWhat fails the audit
Finding IDSequential, tied to the audit report lineFree-text description only
ContainmentAction, date, quantity affected"Under review"
Root causeProcess failure named, method used"Human error"
Corrective actionOwner name, due date, change madeDepartment name, no date
Preventive actionDocument or process revised, revision number"Will monitor"
VerificationNext audit date, evidence checkedClosed on supplier's word
StatusOpen / verified closedClosed without verification
Track two numbers per supplier: CAPA closure time and repeat-finding rate. A short closure time with a rising repeat rate means the supplier is closing paperwork, not problems. For obsolete-part suppliers, add a third: how often a CAPA traces back to the same broker chain.

Common Audit Mistakes That Create a False Sense of Security

The biggest audit mistake is treating a passed audit as a guarantee. It is a snapshot, not a warranty.

Others we see repeatedly:

  • Auditing the paperwork instead of the process
  • Sending auditors who cannot read a control plan
  • Skipping the pre-audit meeting, then arguing about criteria on site
  • Accepting a certificate as evidence of compliance verification
  • Never re-auditing after a CAPA closes
A supplier with a clean audit report and no open findings is not low risk. It usually means the audit scope was too narrow to find anything.

What to Do Next When the Audit Is Done

The audit report is a starting document, not a filing. Turn findings into supplier performance metrics you track quarterly: non-conformance rate, CAPA closure time, on-time delivery, and repeat findings.

Frequently Asked Questions

How do you structure a quality audit for international automation component distributors?

Start with risk-based planning: rank distributors by the criticality of the parts they supply and the volume you buy. Define the audit scope around the quality management system, documentation review and on-site inspection of storage conditions. Then run a pre-audit meeting, gather evidence on the shop floor, and close with a CAPA-driven follow-up. The 2026 methodology from Kodiak Hub sets out five steps: risk-based planning, digital preparation, shop-floor execution, clear reporting, and corrective action follow-up.

What are the essential criteria for evaluating a supplier of legacy spare parts?

Check four things: traceability of the part number back to the original manufacturer, storage conditions for ESD-sensitive and moisture-sensitive components, the supplier's own incoming inspection records, and how they handle discontinued lines. A supplier quality audit checklist for legacy stock should also cover packaging integrity and whether the vendor can name the production batch. Surplus parts distributors often sit outside the OEM's quality management system, so documentation review matters more than brand reputation.

How often should you conduct quality audits for high-risk automation suppliers?

Industry practice now favours risk-based planning rather than auditing every supplier on the same cycle. High-risk suppliers, meaning those providing critical spares with no qualified alternative, typically warrant an annual on-site inspection plus remote checkpoints in between. Lower-risk vendors can move to a two- or three-year cycle with documentation review only. The Shift Project notes that audits alone create a false sense of security, so pair the schedule with performance metrics and continuous improvement tracking.

How do you verify the authenticity of obsolete components during an audit?

Photograph the nameplate and cross-check the part number, serial range and firmware revision against the manufacturer's records. Review the supplier's incoming inspection records and ask for the audit trail on the specific batch. For automation parts, check that the housing, terminal layout and labelling match the original. During a remote supplier audit, have the supplier walk a live video through the storage bin and the packing slip. Document every audit finding, including minor non-conformances.

Find it on Automa.Net →

Other Posts