August 27, 2026
Download a food supplier audit checklist for planning, auditing food safety controls, recording findings, and managing supplier corrective actions.
A food supplier audit should answer a defined risk question. Can this supplier consistently provide the product or material within the food safety, legality, quality, and specification controls your business requires?
The audit is one possible input to approval. It does not replace the risk assessment, specification review, certification checks, or ongoing monitoring behind the final decision.
The Excel version includes status, owner, evidence, and notes fields. The printable PDF follows the same risk-based structure: planning, food safety systems, site and process controls, product controls, findings, and closeout.
A supplier approval checklist covers the whole decision: scope, risk, required documents, verification activities, approval status, and monitoring. A supplier audit checklist goes deeper into the systems and evidence assessed during a desktop or on-site audit.
Not every supplier needs an audit. Depending on material risk and your applicable requirements, approval might rely on recognized certification, a questionnaire, product testing, performance history, or another verification route. Document why the chosen route is sufficient.
Use this audit checklist with the broader food supplier approval checklist, not instead of it.
Record:
A precise scope prevents a common failure: receiving a valid audit report or certificate that covers the wrong site, category, or product.
Before the audit, review the supplier risk assessment, previous audit findings, complaints, recalls, withdrawals, rejected lots, specification deviations, late corrective actions, and significant changes.
Request the evidence needed to plan the audit, such as:
Use the supplier document review checklist to verify whether each record is current, complete, and correctly scoped.
Look for evidence that responsibilities are understood and controls operate between audits, not just that procedures exist.
Check:
Sample records across different dates and shifts. A single perfect example says less than a consistent pattern.
For an on-site or remote facility audit, follow product and people flow through the operation. Relevant checks can include:
Adapt the depth to the product and process risk. A packaging converter, broker, cold store, and ready-to-eat ingredient manufacturer should not receive identical audits.
Select at least one representative product or material and trace it through receipt, processing, release, and dispatch. Confirm that the supplier can connect:
Review how the supplier approves and monitors its own suppliers, particularly where brokers, subcontractors, or outsourced processes are involved.
Confirm that the current approved specification is easy to identify and that changes are controlled. Sample COAs, laboratory results, inspection records, label or artwork approvals, and deviations.
Check whether:
For a stronger operating model, keep approved specifications in a controlled specification management workflow rather than relying on filenames and folders.
Every finding should state:
Use a defined severity model consistently. Avoid vague findings such as “documentation could be improved.” A useful finding tells the supplier what control failed and gives your approver enough information to judge the impact.
At closeout:
The audit is not complete when the report is issued. It is complete when findings are evaluated, corrective actions are accepted, and the effect on supplier approval is documented.
Audit reports, findings, corrective actions, certifications, and approval decisions should remain connected to the supplier and scope they support. Evidash supplier management software keeps that context together, while expiry tracking helps ensure time-sensitive evidence does not lapse between audits.
For the wider decision, return to the food supplier approval checklist. For ongoing performance after approval, use the supplier scorecard.
No. The verification route should be justified by risk and applicable requirements. Some suppliers may be approved using recognized certification and supporting evidence; higher-risk or uncertified suppliers may require a desktop or on-site audit.
Set frequency from risk, performance, certification status, changes, and previous findings. Significant incidents or changes should trigger review instead of waiting for the scheduled date.
A desktop audit assesses submitted systems and records remotely. An on-site audit adds direct observation, interviews, process walkthroughs, and broader record sampling at the facility.
Put supplier certificates, specs, and COAs through the same audit-ready workflow you just read about.