Training module
Supplier Auditing
Plan and conduct supplier audits using contract-based criteria, defined evidence targets and disciplined audit documentation
Are your supplier audits failing to provide reliable assurance?
Execute disciplined supplier audits with clear criteria, targeted evidence, and robust documentation for defensible and usable results.
Overview
What this module is about
Supplier audits often navigate complex terrain, balancing contractual obligations with operational realities and limited access. Without a structured approach, these audits can devolve into superficial reviews or mere relationship management.
This module provides a professional, evidence-focused methodology for executing supplier audits. Participants will learn to define audit scope and criteria from contractual requirements, prepare specific evidence targets, conduct audits effectively within access boundaries, and produce clear documentation that supports internal use and downstream reporting, ensuring results are defensible and actionable.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
conduct supplier audits under contractual or access constraints.
struggle to define scope, criteria, and evidence expectations upfront.
experience supplier audits drifting into visits or relationship meetings.
need supplier audit results that are defensible and usable internally.
want to run supplier audits professionally under real-world limitations.
It may not be the best fit if you…
already execute supplier audits with clear scope and evidence targets.
are not involved in supplier audits or second-party assurance.
need contract negotiation, procurement, or supplier management training.
are looking for programme governance rather than audit execution.
Agenda
What is taught
8 parts01Supplier audits as assurance engagements
How supplier audits function as assurance engagements rather than performance discussions, and how purpose, boundaries, and typical constraints such as access, confidentiality, proprietary methods, and subcontractors shape audit execution
02Engagement-level planning
How to turn contracts, SLAs, and mandatory obligations into audit criteria, and define an auditable scope that matches what can realistically be assessed across sites, services, and interfaces
03Preparing supplier-specific evidence targets
How to prepare using available pre-reading materials and build evidence target matrices that align criteria with supplier-specific interfaces and constraints
04Executing supplier audits on-site, remote, or hybrid
How to structure the audit day, maintain control of time and access, and follow key service interfaces end-to-end across handovers, controls, and records
05Evaluating what you see under supplier constraints
How to triangulate evidence when direct access is limited, and recognise audit-relevant red flags such as restricted sampling or inconsistent records
06Managing challenging situations professionally
How to handle defensiveness, commercial pushback, and boundary disputes, and decide when to pause, rescope, or escalate based on clear decision points and internal alignment
07Audit documentation and handover
How to maintain workpapers that link evidence to criteria and support later reporting, and define handover packages that meet downstream reporting and follow-up needs
08Case-based workshop
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Define a supplier audit scope and brief using contractual and mandatory requirements as criteria
02
Translate audit criteria into supplier-specific evidence targets and an evidence request plan
03
Document audit workpapers that clearly link evidence to criteria and support downstream decisions
Choose and structure an on-site, remote, or hybrid supplier audit approach appropriate to access constraints
Run supplier audit activities in a controlled manner, managing timing, access, and interface tracing
Evaluate supplier evidence under real-world limitations using triangulation and consistency checks
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Supplier Auditing is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-AG-AC-05
- Discipline
- Cross-discipline
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.