Evidash logoEvidash
  • Supplier ManagementOnboard vendors and keep their compliance in one place
  • Expiry TrackingGet ahead of expiring certificates and insurance
  • Specification ManagementCentralize product specs and supplier requirements
  • Document ProcessingExtract data from documents automatically with AI

Everything you need to keep third-party compliance under control.

  • Food & BeverageSupplier approval and certification tracking for food teams
  • ConstructionManage subcontractor insurance and accreditations
  • BlogInsights on vendor risk and compliance operations

Evidash

AI-powered document and supplier data workflows for modern food and beverage teams.

Ask AI for a summary about this page

Company

  • About
  • Blog

Product

  • Supplier Management
  • Expiry Tracking
  • Spec Management
  • Document Processing

Solutions

  • Food & Beverage
  • Construction

Compliance

  • BRCGS
  • SQF
  • FSSC 22000
  • FSMA / FSVP

Legal

  • Privacy Policy
  • Terms of Use

© 2026 Evidash Ltd. All rights reserved.

71-75, Shelton Street, Covent Garden, London, WC2H 9JQ, UNITED KINGDOM

Evidash logoEvidash
  • Supplier ManagementOnboard vendors and keep their compliance in one place
  • Expiry TrackingGet ahead of expiring certificates and insurance
  • Specification ManagementCentralize product specs and supplier requirements
  • Document ProcessingExtract data from documents automatically with AI

Everything you need to keep third-party compliance under control.

  • Food & BeverageSupplier approval and certification tracking for food teams
  • ConstructionManage subcontractor insurance and accreditations
  • BlogInsights on vendor risk and compliance operations
Evidash logoEvidash
  • Supplier ManagementOnboard vendors and keep their compliance in one place
  • Expiry TrackingGet ahead of expiring certificates and insurance
  • Specification ManagementCentralize product specs and supplier requirements
  • Document ProcessingExtract data from documents automatically with AI

Everything you need to keep third-party compliance under control.

  • Food & BeverageSupplier approval and certification tracking for food teams
  • ConstructionManage subcontractor insurance and accreditations
  • BlogInsights on vendor risk and compliance operations
All articles

August 27, 2026

Food Supplier Audit Checklist (+ Free Excel & PDF Template)

Download a food supplier audit checklist for planning, auditing food safety controls, recording findings, and managing supplier corrective actions.

A food supplier audit should answer a defined risk question. Can this supplier consistently provide the product or material within the food safety, legality, quality, and specification controls your business requires?

The audit is one possible input to approval. It does not replace the risk assessment, specification review, certification checks, or ongoing monitoring behind the final decision.

Download the food supplier audit checklist

  • Download the Excel audit checklist
  • Download the PDF audit checklist

The Excel version includes status, owner, evidence, and notes fields. The printable PDF follows the same risk-based structure: planning, food safety systems, site and process controls, product controls, findings, and closeout.

Food supplier audit checklist vs supplier approval checklist

A supplier approval checklist covers the whole decision: scope, risk, required documents, verification activities, approval status, and monitoring. A supplier audit checklist goes deeper into the systems and evidence assessed during a desktop or on-site audit.

Not every supplier needs an audit. Depending on material risk and your applicable requirements, approval might rely on recognized certification, a questionnaire, product testing, performance history, or another verification route. Document why the chosen route is sufficient.

Use this audit checklist with the broader food supplier approval checklist, not instead of it.

1. Define the audit scope before requesting evidence

Record:

  • supplier legal name and manufacturing site,
  • products, materials, and processes in scope,
  • applicable standard, customer, regulatory, and specification requirements,
  • whether the audit is for initial approval, surveillance, reapproval, or incident follow-up,
  • audit date, auditors, supplier contacts, and expected outputs.

A precise scope prevents a common failure: receiving a valid audit report or certificate that covers the wrong site, category, or product.

2. Review the supplier history and document pack

Before the audit, review the supplier risk assessment, previous audit findings, complaints, recalls, withdrawals, rejected lots, specification deviations, late corrective actions, and significant changes.

Request the evidence needed to plan the audit, such as:

  • food safety plan or HACCP summary,
  • organization chart and responsibilities,
  • current certifications and audit reports,
  • product and process flow information,
  • allergen, traceability, recall, food defense, and food fraud controls,
  • recent internal audit, corrective action, and management review records,
  • current specifications and examples of release evidence.

Use the supplier document review checklist to verify whether each record is current, complete, and correctly scoped.

3. Assess management and food safety system controls

Look for evidence that responsibilities are understood and controls operate between audits, not just that procedures exist.

Check:

  • leadership responsibility and escalation,
  • hazard analysis and preventive controls,
  • document and record control,
  • internal audits and management review,
  • training and competency,
  • nonconformance, root-cause analysis, and corrective action,
  • traceability, withdrawal, and recall testing,
  • change management and customer notification.

Sample records across different dates and shifts. A single perfect example says less than a consistent pattern.

4. Inspect site and process controls

For an on-site or remote facility audit, follow product and people flow through the operation. Relevant checks can include:

  • hygiene zoning and personnel practices,
  • allergen segregation and changeover,
  • foreign-body and contamination controls,
  • cleaning and sanitation verification,
  • pest management,
  • maintenance and calibration,
  • intake, storage, production, release, and dispatch controls,
  • temperature, transport, and warehousing conditions,
  • security, food defense, and visitor controls.

Adapt the depth to the product and process risk. A packaging converter, broker, cold store, and ready-to-eat ingredient manufacturer should not receive identical audits.

5. Trace product and supplier controls

Select at least one representative product or material and trace it through receipt, processing, release, and dispatch. Confirm that the supplier can connect:

  • incoming materials to approved sources,
  • batches to production and inspection records,
  • results to the correct specification version,
  • release decisions to authorized reviewers,
  • finished product to customers or destinations.

Review how the supplier approves and monitors its own suppliers, particularly where brokers, subcontractors, or outsourced processes are involved.

6. Review specifications, testing, and release evidence

Confirm that the current approved specification is easy to identify and that changes are controlled. Sample COAs, laboratory results, inspection records, label or artwork approvals, and deviations.

Check whether:

  • limits match the approved specification,
  • methods and sampling plans are defined,
  • out-of-specification results are investigated,
  • concessions are authorized and traceable,
  • specification changes are communicated and approved.

For a stronger operating model, keep approved specifications in a controlled specification management workflow rather than relying on filenames and folders.

7. Record objective evidence and classify findings

Every finding should state:

  1. the requirement or expected control,
  2. the objective evidence reviewed,
  3. the gap or failure observed,
  4. the risk or potential impact.

Use a defined severity model consistently. Avoid vague findings such as “documentation could be improved.” A useful finding tells the supplier what control failed and gives your approver enough information to judge the impact.

8. Close the audit and connect it to approval

At closeout:

  • confirm each finding and supporting evidence,
  • agree corrective-action owners and dates,
  • define whether evidence review or a follow-up audit is required,
  • record any immediate approval restriction,
  • set the next review or reapproval date.

The audit is not complete when the report is issued. It is complete when findings are evaluated, corrective actions are accepted, and the effect on supplier approval is documented.

Common supplier-audit mistakes

  • Auditing without a product- and site-specific scope
  • Treating certification as proof that every relevant control is effective
  • Reviewing policies without sampling operating records
  • Recording observations without objective evidence
  • Closing findings because a document was submitted without checking implementation
  • Failing to update the supplier risk assessment or approval decision

Turn audit results into a controlled supplier record

Audit reports, findings, corrective actions, certifications, and approval decisions should remain connected to the supplier and scope they support. Evidash supplier management software keeps that context together, while expiry tracking helps ensure time-sensitive evidence does not lapse between audits.

For the wider decision, return to the food supplier approval checklist. For ongoing performance after approval, use the supplier scorecard.

Frequently asked questions

Does every food supplier need an on-site audit?

No. The verification route should be justified by risk and applicable requirements. Some suppliers may be approved using recognized certification and supporting evidence; higher-risk or uncertified suppliers may require a desktop or on-site audit.

How often should suppliers be audited?

Set frequency from risk, performance, certification status, changes, and previous findings. Significant incidents or changes should trigger review instead of waiting for the scheduled date.

What is the difference between a desktop and on-site supplier audit?

A desktop audit assesses submitted systems and records remotely. An on-site audit adds direct observation, interviews, process walkthroughs, and broader record sampling at the facility.

See Evidash on your own documents

Put supplier certificates, specs, and COAs through the same audit-ready workflow you just read about.

Request early accessTry the demo