How Do You Prepare for a Supplier Documentation Audit?

MacLean Hawley

MacLean Hawley

Founder & CEO Published Mar 9, 2026

Prepare for a supplier documentation audit by running your own full gap analysis before the auditor arrives, not by assuming your last clean sample means you are ready. Auditors check that you can produce current, valid records for approved suppliers on demand. The companies that pass are not the ones with perfect suppliers. They are the ones with a system that knows exactly what they have, what is missing, and what they did about every gap.

Which documents must be current?

Requirements vary by industry and supplier classification. For medical device and life sciences, auditors typically expect:

Certificates and registrations:

  • ISO 13485, ISO 9001, ISO 14001 (each expires, usually every three years)
  • FDA establishment registration where applicable
  • CE marking / EU MDR records for EU-bound products
  • Industry certs: AS9100, IATF 16949, GMP as relevant

Quality records:

  • Signed quality agreements
  • CAPA closure records
  • First article inspection (FAI) reports
  • Your most recent supplier audit report and finding closures

Regulatory and ESG:

  • CMRT or conflict minerals declarations
  • RoHS/REACH declarations
  • ESG questionnaires or sustainability disclosures
  • Insurance certificates per contract

Every item has an expiration or review cycle. A cert valid at onboarding five years ago may have expired two years ago with nobody noticing.

How do you run a gap analysis?

Step 1: Clean the supplier list. Cross-reference your approved supplier list against PO history. Remove inactive suppliers before counting gaps. One SQE cut scope from 1,300 to 900: “We found out that some of the suppliers, we’ve not even issued them a PO in the last four years.”

Step 2: Map required documents per supplier. A contract manufacturer needs ISO 13485, a quality agreement, FAI, and CAPA records. An office supply vendor needs almost nothing. Build a matrix by supplier classification (critical, major, minor).

Step 3: Check what you actually have. For each cell in the matrix: Is the document on file? Current version? Expired? Properly signed?

This is where the real problem size appears. The number visible at a glance is almost never the actual number.

Why does “auditor found 3, team found 64” happen?

External auditors sample. A clean audit result can mask a much larger gap.

An SQE described the pattern: “The auditor only found three. But then you realize that out of the 116, you have 60 or 64 that doesn’t have the compliance certificates, because someone tried to reach out to maybe 20 of them and gave up.”

The auditor flagged 3 of 116 sampled suppliers. The team’s full review found 64 without valid certificates. The only way to know your real number is to run the full review yourself.

What quarterly review keeps you audit-ready?

Audit prep should not be an annual panic.

  1. Pull documents expiring in 90 days and request renewals now.
  2. Confirm new onboarded suppliers have complete files.
  3. Escalate open requests older than 60 days.

Annual deep review: Full gap analysis, remove inactive suppliers, verify classification requirements still match current regulations.

What happens when you fail?

Regulatory: FDA warning letters, 483 observations, import alerts or product holds in extreme cases.

Internal: Corrective action projects consuming team bandwidth, certification risk for your own ISO 13485, rapid VP-level escalation.

Failures in supplier documentation rarely stay at the team level. They surface quickly to leadership without fixing the underlying process.

How should you present files to auditors?

  • Centralized storage: One system (QMS, supplier platform, or consistent shared drive). Not scattered across personal inboxes.
  • Indexed by supplier: Auditor asks for “ISO 13485 for Supplier X” and gets it in 60 seconds.
  • Version control: Current cert is primary. Expired versions archived separately.
  • Process evidence: Request dates, follow-up logs, escalation records, quarterly review logs.

The documentation trail matters as much as the documents. A missing cert with six follow-ups and executive escalation reads differently than a missing cert with no outreach history.

Frequently asked questions

How far ahead should you start audit prep?

Run quarterly reviews continuously. Start intensive gap closure 90+ days before a known audit, not two weeks before.

Do auditors care about estimated vs. primary data for ESG?

They care that you have a documented process and honest data quality disclosure. Gaps with documented outreach effort are treated differently from silent gaps.

Should you remove suppliers with chronic gaps before the audit?

Follow your deactivation procedure and document the rationale. Do not quietly delete records. Auditors may ask why a supplier disappeared.

Where Bridgecurrent fits

Bridgecurrent closes the gaps your gap analysis reveals. It finds the right contact at each supplier, sends the document request, and follows up until the file arrives or escalation triggers. For audit prep with dozens or hundreds of open items, it replaces the manual email work that causes most remediation projects to stall.