13.2 External / Supplier Audit Program Management
Key Takeaways
- External/supplier audit program management (IV.A.6, Create) designs how the organization qualifies, monitors, and improves suppliers and other external providers through surveys, self-assessments, surveillance, and audits.
- Qualification surveys and questionnaires gather structured capability and QMS evidence before business award or for periodic re-qualification; they are not a full substitute for on-site audit when risk is high.
- Surveillance keeps approved suppliers under control via scorecards, incoming data, complaint rates, change notices, and periodic re-audits scaled to risk tier.
- Self-assessment lets suppliers evaluate against your criteria with evidence—efficient for lower risk or between on-site visits—but requires verification sampling and rules for when results trigger escalation.
- Supplier improvement closes the loop: SCAR/CAPA, joint projects, development plans, and de-source decisions; the program creates the triggers and methods, not only one-off audits.
13.2 External / Supplier Audit Program Management (CQA BoK IV.A.6 — Create)
/practice/cqaPractice questions with detailed explanations
Internal programs (IV.A.5) look inward. External programs look along the supply chain and other second-party relationships (sometimes customer-directed audits of you, but BoK IV.A.6 emphasis for program management is usually you as customer/auditor of suppliers). Purchasing, supplier quality, and audit functions share ownership; the CQA lens is whether the assurance design is coherent, risk-based, and improvement-oriented.
Why Supplier Programs Differ from Internal Programs
| Dimension | Internal program | External / supplier program |
|---|---|---|
| Authority | Organizational charter | Contract, quality agreement, purchase order, regulatory expectation |
| Access | Usually broader on-site rights | Limited to agreed rights; denial has commercial consequences |
| Criteria | Internal QMS + standards | Your requirements + standards + regulatory + product specs |
| Relationship | Same employer | Commercial leverage, dual sourcing, confidentiality |
| Outcome tools | Internal CAPA | SCAR, scorecards, new-business hold, development, exit |
Create-level design must respect contractual access. A beautiful audit plan that exceeds the quality agreement’s right-to-audit clause fails before fieldwork starts. Program procedures should require that agreements include audit rights proportional to risk (critical components, sterile packaging, software, regulated materials).
Building Blocks of the External Program
1. Supplier risk tiering (foundation for all tools)
Before surveys and audits, classify suppliers by impact on product/service quality and compliance.
| Tier (example) | Typical profile | Default assurance mix |
|---|---|---|
| Critical | Direct product impact; hard to replace; regulated process | Full qualification (survey + on-site/process audit), frequent surveillance, change-control oversight |
| Major | Significant quality impact; alternatives exist | Survey + periodic audit or strong self-assessment with sampling |
| Minor / catalog | Low impact; commodity | Questionnaire / certification review; data-driven monitoring |
Tiering criteria may include part criticality, process complexity, prior performance, single-source status, geographic/regulatory risk, and cybersecurity exposure for digital suppliers.
2. Qualification surveys and questionnaires
Qualification surveys (supplier questionnaires, capability surveys, quality system surveys) collect structured information before award or as re-qualification inputs.
Typical survey domains:
- QMS certification status and scope (ISO 9001, IATF, AS9100, ISO 13485, etc.) and certificate validity
- Process capabilities relevant to your commodity (special processes, cleanroom, software lifecycle)
- Traceability, change control, sub-tier control
- Calibration, training, CAPA, complaint handling
- Capacity, business continuity, conflict minerals / ESG as required by your policies
- Right-to-audit acknowledgment and key contacts
| Survey strength | Survey limitation |
|---|---|
| Scalable screening of many suppliers | Self-reported; optimistic bias |
| Standard comparable fields | Weak on actual process effectiveness |
| Good for minor tiers and pre-visit prep | Critical suppliers usually need deeper verification |
Create task: Design a two-stage survey—Stage A (mandatory legal/QMS fields, pass/fail gates) and Stage B (commodity-specific process questions with evidence upload requirements). Define scoring, minimum pass, and automatic triggers for on-site audit (for example, new critical supplier, expired certificate, prior major SCAR, or “no” on change-control questions).
Scenario — Survey only is not enough.
A new sterile barrier packaging supplier returns a perfect survey and holds ISO 13485. Product risk is critical and the process is special (validation-dependent). Create-level program rule: survey + certificate review + on-site process audit of validation, environmental control, and change notification before production release—not survey alone.
3. Surveillance (keeping approved suppliers under control)
Surveillance is ongoing monitoring after qualification. It mixes desktop data with periodic re-assessment so problems surface before your customer or regulator does.
Surveillance toolkit:
| Tool | What it monitors |
|---|---|
| Incoming quality / ppm / lot rejection rates | Product performance at your dock |
| On-time delivery & capacity alerts | Operational stability |
| Complaint / field failure linkage | Escape risk |
| SCAR aging and recurrence | CAPA effectiveness at the supplier |
| Change notifications & PPAP/FAI as applicable | Unauthorized process drift |
| Certificate surveillance & scope changes | QMS maintenance |
| Periodic re-audit or remote process review | Deep verification on schedule or risk trigger |
Risk-based surveillance cadence: Critical suppliers might face annual process audits or alternating full/partial surveillance; major suppliers every 2–3 years plus scorecard reviews; minor suppliers certificate-and-performance only unless data degrades.
Create example: Write a surveillance procedure that auto-generates a for-cause supplier audit when: (a) two related SCARs in 12 months, (b) customer escape attributed to supplier, (c) major process change without prior approval, or (d) scorecard red for two consecutive quarters.
4. Self-assessment
Supplier self-assessment asks the supplier to evaluate itself against your checklist or a standard, often with evidence attachments. It is efficient for mid-tier suppliers, multi-site networks, and years between on-site visits.
Design rules that keep self-assessment honest:
- Controlled criteria — same requirement set you would use on-site, version-controlled.
- Evidence requirements — procedures, records, photos, metrics—not “yes” boxes alone.
- Conflict of interest disclosure — who completed it and whether independent internal audit supported it.
- Verification sampling — your program samples a percentage for remote document review or short on-site confirmation.
- Escalation thresholds — material gaps convert to SCAR or full audit.
- Frequency — annual for major tier; optional for minor if performance is green.
| When self-assessment fits | When it does not replace audit |
|---|---|
| Mature supplier, stable performance, moderate risk | New critical process, history of dishonesty, high regulatory exposure, major change |
| Geographic or travel constraints with strong remote evidence | Need to observe process execution and culture |
| Between-cycle monitoring | Qualification of sole-source critical part |
Exam trap: Treating a glowing self-assessment as equivalent to an independent second-party audit. Create-level programs define when self-assessment is allowed and how it is verified—not assume it always equals on-site evidence quality.
5. Supplier improvement
Audits and surveys without supplier improvement become scorekeeping. Improvement methods the program should create:
| Method | Use when |
|---|---|
| SCAR / supplier CAPA | Nonconformity or performance breach with required root cause and verification |
| Joint corrective workshops | Systemic process issues spanning both parties (specs ambiguity, dual systems) |
| Supplier development plans | Strategic supplier with capability gaps but long-term value |
| New business hold / controlled shipping | Elevated escape risk until capability proven |
| Dual source / exit | Chronic failure despite support; risk exceeds tolerance |
| Recognition / preferred status | Sustained excellence—reinforces desired behavior |
Scenario — Create an improvement path.
A major electronic assembly supplier has rising defect rates. Surveillance scorecard is yellow; self-assessment claims strong SPC. On-site audit finds SPC charts filled retrospectively. Program response: major SCAR with systemic CAPA; temporary increased sampling at incoming; 90-day development plan with process audit follow-up; dual-source activation if effectiveness verification fails. That multi-tool response is program management, not a single finding letter.
End-to-End Supplier Assurance Lifecycle (Create Model)
- Identify & tier — commodity criticality and business risk.
- Pre-qualify — survey Stage A/B, certificate and financial viability checks as required.
- Deep qualify — on-site or hybrid process audit for critical/major as defined.
- Approve & contract — quality agreement with change control, audit rights, notification duties.
- Surveillance — scorecards, data, re-audits, self-assessments on cadence.
- React — for-cause audits, SCAR, holds.
- Improve or exit — development vs. de-source decisions with documented rationale.
- Program review — roll-up supplier risk, audit coverage gaps, recurring themes into management review (bridge to IV.A.9).
Integration with Internal Audits and Second-Party Reality
- Outsourced processes remain your responsibility under many QMS models—supplier program results should feed internal process audits of purchasing, incoming inspection, and supplier change control.
- Customer audits of you may scrutinize how you control suppliers; your external program evidence (schedules, SCARs, qualifications) becomes objective evidence in your second- or third-party audits.
- Confidentiality and IP procedures must define what auditors may photograph, how long records are kept, and how multi-customer lines are handled on the supplier floor.
Mini Case — Design the External Program
A consumer medical device company sources 40 suppliers: 5 critical, 12 major, 23 minor. Today: one questionnaire for everyone; on-site audits only when a VP travels; no SCARs—just angry emails.
Create redesign:
- Tier matrix owned by Supplier Quality + Purchasing.
- Critical: full survey + process audit before award; annual surveillance audit or alternating remote process review; mandatory change control in quality agreement.
- Major: survey + self-assessment annually; on-site every 2–3 years or on risk trigger.
- Minor: short survey + certificate; performance monitoring only.
- SCAR procedure with severity classes, due dates, and verification.
- Quarterly supplier risk board reviewing ppm, SCAR aging, and audit schedule adherence.
- Flex budget for three for-cause audits per year.
Exam Anchors
| Trap | Better view |
|---|---|
| Certification certificate = perpetual approval | Certificates help but do not replace risk-based surveillance and performance data |
| Survey = audit | Surveys screen; audits verify process effectiveness when risk warrants |
| Self-assessment always dishonest / always sufficient | Neither extreme—design verification and escalation rules |
| Improvement = polite suggestions only | Program needs teeth (holds, dual source) and support (development) |
| External program is only “supplier audits” | Full program includes qualification, surveillance, self-assessment, and improvement methods |
You are creating a supplier assurance program for a mix of critical sterile components and low-risk office supplies. Which design best reflects IV.A.6 Create-level risk-based tool selection?
A major-tier supplier completes an annual self-assessment claiming full SPC implementation. Your program’s Create-level design should primarily ensure which control?
Which set best describes core elements of supplier program surveillance after initial qualification?
After a critical supplier audit finds systemic CAPA weakness and rising escapes, which response best illustrates supplier improvement as part of the external audit program?