Supplier Audit

A supplier audit is a planned, documented evaluation of a supplier’s quality management system, processes, and records to confirm they can consistently meet medical device requirements. In MedTech, it is a second-party audit conducted under ISO 13485 clause 7.4, used to qualify suppliers, monitor performance, and provide evidence for regulators.


What is a supplier audit?

A supplier audit sits inside a manufacturer’s purchasing controls. When a device company buys components, sterilization services, contract manufacturing, or software, it stays responsible for the quality of what it ships. The audit is how the manufacturer verifies, on the supplier’s site or remotely, that the supplier’s controls match that responsibility.

Auditors classify these as second-party audits: a customer auditing its external provider. That sets them apart from first-party (internal) audits and third-party audits run by a notified body or certification registrar. ISO 19011:2026 provides the methodology, while ISO 13485 sets the requirement to evaluate and monitor suppliers based on risk.


Why supplier audits matter in medical device development

A weak supplier can put a nonconforming part into a finished device, and the manufacturer carries the regulatory liability, not the vendor. Purchasing failures show up repeatedly in FDA inspection findings, which keeps supplier control under constant scrutiny.

The exposure grew in 2026. Under the FDA Quality Management System Regulation (QMSR), effective February 2, 2026, 21 CFR Part 820 now incorporates ISO 13485:2016 by reference, and the old exemption that shielded supplier audit reports from FDA review is gone. Investigators can ask to see them. EU MDR 2017/745 sets a parallel expectation: manufacturers must control suppliers and subcontractors across the supply chain and show that control in their technical documentation.

Beyond compliance, a qualified supplier base cuts scrap, line-down events, and recall risk, all of which affect cost and time-to-market.


How a supplier audit works

Most programs follow a risk-based cycle rather than auditing every supplier the same way. The typical sequence:

  • Classify and prioritize. Rank suppliers by criticality, component risk, and past performance. A sterilization provider or a Class III implant machinist gets more attention than a carton supplier.
  • Plan the audit. Set scope, criteria (ISO 13485, applicable regulation, the purchasing agreement), and audit type: on-site, remote, or hybrid. ISO 19011:2026 added formal guidance for remote and hybrid audits, now common for supplier assessments.
  • Conduct the audit. Review procedures, records, and process controls against the criteria. Trace a real part through the supplier’s system: incoming inspection, process validation, nonconformance handling, and change control.
  • Report findings. Document conformities and nonconformities with objective evidence, then grade findings by severity.
  • Corrective action and follow-up. Issue a supplier corrective action request (SCAR), verify the fix, and feed systemic issues into your own CAPA process.
  • Re-evaluate. Adjust audit frequency and the approved supplier list based on results.

The governing requirement is ISO 13485 clause 7.4, which covers purchasing information, supplier evaluation and selection, and verification of purchased product. Under QMSR, this same clause now carries the FDA purchasing-control expectation that previously sat in 21 CFR 820.50, including ongoing monitoring rather than one-time approval.


Common challenges and best practices

The most common mistake is treating qualification as a one-time event. A supplier approved three years ago on paper is not a monitored supplier, and regulators expect dated evidence that oversight continued after onboarding.

Teams also over-audit low-risk vendors and under-audit critical ones because the schedule is calendar-driven instead of risk-driven. Tie audit depth and frequency to component risk and supplier history.

Weak corrective-action loops are another gap. A finding with no verified closure, or a SCAR that never links to CAPA, reads as an open problem during an inspection. Close findings with objective evidence, and keep the approved supplier list current so purchasing cannot order from an unqualified source. For remote audits, define in your procedures how digital evidence is collected and secured, a point ISO 19011:2026 now stresses.


How SJML helps with supplier audits

SJML runs supplier audits as part of its Compliance-as-a-Service and regulatory sustenance work. The team supports supplier qualification, second-party audit planning and execution, and the corrective-action follow-up that closes findings, aligned to ISO 13485 and MDSAP expectations. On the manufacturing side, SJML operates supplier qualification, dual sourcing, and obsolescence management inside a SAP-integrated MES for traceability, so supplier controls connect to real production records. That lets device makers extend audit coverage across a complex supply base without building the program from scratch.

Talk to SJML’s QARA team →


Frequently asked questions

What is the difference between a supplier audit and supplier qualification?

Supplier qualification is the broader decision to approve a supplier, using questionnaires, samples, documentation review, and often an audit. A supplier audit is one input to that decision: an on-site or remote assessment of the supplier’s quality system and processes. Qualification happens at onboarding and is maintained over time, while audits recur on a risk-based schedule to confirm the supplier still meets requirements.

Are supplier audits required by ISO 13485?

ISO 13485 does not name an audit for every supplier, but clause 7.4 requires manufacturers to evaluate and select suppliers based on their ability to meet requirements, then monitor and re-evaluate them. For critical suppliers, an on-site or remote audit is the practical way to meet that requirement. The depth and frequency scale with the risk the supplier poses to the device.

Can a supplier audit be done remotely?

Yes. Remote and hybrid supplier audits became common after 2020 and are now formally addressed in ISO 19011:2026, which added guidance on remote methods, virtual locations, and digital evidence. Remote audits work well for document-heavy reviews and follow-ups. On-site visits still matter for process observation, cleanroom checks, and first-time qualification of high-risk suppliers, so most programs mix the two by risk.

Does the FDA review supplier audit reports?

Under the QMSR, effective February 2, 2026, yes. The QMSR removed the earlier exemption in 21 CFR 820.180© that kept supplier audit reports out of FDA review. Investigators can now request management review records, internal audit records, and supplier audit reports during an inspection. That change raises the bar on documenting audits properly and closing findings with objective evidence.


Related terms

  • Supplier Qualification
  • Purchasing Controls
  • Corrective and Preventive Action (CAPA)
  • Approved Supplier List
  • Internal Audit

Table of Contents

Free EU MDR Technical Documentation Compliance Checklist

Understand documentation gaps and use our single-window worksheet to prepare for Notified Body review.

Related Glossaries

Ask Sygma AI

AI-Powered Assistant

SJ Assistant