A valid certificate can establish that a management system was assessed within a defined scope. It cannot prove that your job is understood, capable, controlled, or desirable to the supplier.

TL;DR

Verify a certificate's issuer, status, site, scope, standard, and exclusions. Then audit the workflow that would execute your job: contract review, configuration, purchasing, material identity, tooling, operator information, process control, inspection, nonconformance, outside processing, change control, delivery, and records.

The strongest audit follows one representative order from quote through shipment and then traces one delivered item backward. Avoid spending the day reading procedures in a conference room. Evidence at the point of work matters more than a polished quality manual.

Certification and Qualification Are Different

ISO explains that certification to management-system standards is not inherently mandatory [1]. When a supplier is certified, the certificate reflects an assessment of a defined management system and scope. It does not mean:

  • every product is approved;
  • every process is performed in-house;
  • every location is covered;
  • capacity is available;
  • every advertised tolerance is routine;
  • customer-specific requirements are understood;
  • the supplier is financially or operationally resilient.

The audit question is not “Does the supplier have ISO 9001?” It is “Can this establishment reliably execute this work under these requirements?”

Start With a Risk-Based Audit Objective

ISO 19011:2026 provides current guidance on audit principles, audit-program management, conducting audits, auditor competence, evidence-based practice, and risk-based practice [2]. A supplier assessment should therefore define:

  • objective;
  • criteria;
  • scope;
  • physical and organizational locations;
  • processes and product families;
  • audit methods;
  • team competence;
  • sampling plan;
  • report and follow-up.

Do not use the same audit depth for a catalog fastener distributor and a source performing safety-critical heat treatment.

Follow One Order Through the System

Select a recent job similar to the proposed work.

1. Quote and contract review

Verify how the supplier:

  • identifies technical and commercial requirements;
  • records assumptions and exceptions;
  • reconciles purchase order, drawing, model, and specification;
  • confirms capacity and outside-process lead time;
  • accepts changes.

2. Configuration and point-of-use information

At the workstation, ask the operator to show the current drawing, model, instruction, program, tooling, and inspection requirement. Compare revisions with the order.

3. Material and purchased product

Trace material identity from certificate and receiving record to storage, issue, work in process, remnants, and finished lot. Verify how substitution and commingling are prevented.

4. Production control

Observe setup approval, parameter control, tooling condition, first-piece decisions, in-process checks, status identification, and response to abnormal conditions.

5. Inspection and test

Verify that methods match characteristics, equipment is fit for use, sampling is defined, results are recorded, and acceptance is made against the authorized requirement.

6. Nonconformance and corrective action

Inspect actual segregation. Sample a recent nonconformance from discovery through containment, disposition, rework instruction, reinspection, root cause, corrective action, and effectiveness.

7. Shipment and records

Trace quantity, release status, certificates, packaging, preservation, labeling, and shipment evidence. Confirm retention and retrieval.

NIST MEP describes quality-management systems as a structure for meeting standards and technical specifications and identifies internal, supplier, and registration-audit support as distinct activities [3].

Process Audit Matrix

Process Evidence at the work Warning sign
Contract review Requirement checklist, reconciled files, recorded exceptions “Sales handles that” with no record
Document control Current revision at point of use, obsolete-file control Multiple uncontrolled printouts
Purchasing Flowed requirements and approved source scope Supplier chosen only by price
Material Physical identity linked to certificates and job Loose pieces with assumed identity
Production Approved setup, tooling, parameters, status, operator access Tribal knowledge as the primary control
Inspection Characteristic-method match and recorded results Calibrated tool used without a plan
Nonconformance Segregation, authority, reinspection, traceable disposition Red tag treated as final disposition
Outside processing Purchase flowdown, lot tracking, certificate review Parts leave and become “at vendor”
Change control Customer notification and internal implementation Quiet source, tool, or method changes
Delivery Release evidence, packaging, quantity reconciliation Final inspection detached from shipment

Test Capability Claims

If a supplier claims:

  • a tolerance, ask which geometry, material, size, process, and measurement method;
  • “full traceability,” perform backward and forward traces;
  • rapid capacity, ask for the constraint and demonstrated output;
  • in-house processing, walk to the department and inspect scope;
  • qualified outside suppliers, review one purchase order and returned certificate;
  • robust corrective action, sample an effectiveness review;
  • digital control, ask an operator to retrieve the current record.

Evidence should be representative, not staged. Respect confidentiality and safety boundaries.

Audit Capacity and Business Fit

Quality escape risk is only one reason a supplier can fail. Audit:

  • current backlog and quoted lead time;
  • dependence on one machine, person, tool, material source, or processor;
  • preventive-maintenance execution;
  • workforce coverage and training;
  • disaster and recovery planning;
  • willingness to support your volume and commercial model;
  • sub-tier transparency;
  • communication and escalation behavior.

FAA supplier-control guidance explicitly ties control depth to product risk factors such as safety classification, special processes, and design or manufacturing complexity [4]. That is a useful general principle even outside aviation.

Audit Deliverable

Do not end with a generic score alone. Produce:

  1. scope and sampled jobs;
  2. confirmed capabilities and boundaries;
  3. objective evidence;
  4. findings classified under the agreed method;
  5. unresolved risks and assumptions;
  6. required corrective actions with owners and dates;
  7. approval status by process and location;
  8. conditions for initial production;
  9. surveillance or re-audit triggers.

Separate “not observed” from “nonconforming.” An audit is a sample, not omniscience.

Supplier Audit Checklist

  • Certificate verified for issuer, status, site, scope, and standard
  • Representative job selected
  • Contract and revision trail reconciled
  • Material traced backward and forward
  • Actual production route observed
  • Tooling, programs, and setup control sampled
  • Inspection method matched to critical characteristics
  • Outside-process control sampled
  • Nonconformance and corrective-action records sampled
  • Capacity constraint and recovery plan understood
  • Findings tied to objective evidence
  • Approval scope and follow-up actions documented

A Restrained Next Move

Use the U.S. Manufacturing Directory to identify candidates, then audit the highest-risk workflow that would actually touch your product. A certificate can reduce the initial unknowns; it should never replace capability verification.

References

  1. International Organization for Standardization, Management System Standards.
  2. International Organization for Standardization, ISO 19011:2026 — Guidelines for Auditing Management Systems.
  3. National Institute of Standards and Technology, ISO and Quality Management.
  4. Federal Aviation Administration, AC 21-43 — Production Under 14 CFR Part 21. Used for the risk-based supplier-control principle; aviation requirements are not generalized to other sectors.