Supplier Audits
Supplier audit and vendor qualification Norway. Capability, quality system and contractual compliance assessed on site. Norway and Asia coverage.
A supplier audit answers a procurement question rather than a certification one: can this supplier actually do what it has committed to do. The criteria are yours — your contract, your specification, your quality requirements — not those of a standard, which is what distinguishes it from certification auditing.
What we audit against
- Contract terms and service level commitments
- Technical specifications and drawings
- Approved quality plans and inspection and test plans
- Customer-specific requirements imposed on you by your own clients
- Supplier codes of conduct, including ethical and labour requirements
- Your own supplier qualification criteria and scoring framework
What the audit examines
- Capability and capacityWhether the supplier has the equipment, facilities and throughput to meet your volume and schedule — assessed against what is actually installed and running, not what is listed in the company profile.
- Quality system in practiceWhether documented arrangements are implemented, sampled through records rather than accepted from a manual.
- Process controlControls at the stages that determine your product's conformity, including inspection points, calibration and traceability.
- Personnel competenceQualification of personnel performing special processes — welding, heat treatment, NDT — verified back to certificates rather than assumed.
- Sub-tier controlHow the supplier controls its own suppliers, which is where your requirement most often gets lost.
- Nonconformity handlingHow defects are identified, contained and corrected, and whether corrective action prevents recurrence or merely closes a form.
- Ethical and labour complianceWorking conditions, hours, wage payment, accommodation and documentation, where your code of conduct extends to these.
- Records and traceabilityWhether a finished item can be traced back to its material, process records and personnel — the test that reveals whether the system is real.
How the audit is conducted
ITMAD plans the audit against criteria agreed with you, then verifies implementation at the supplier's premises. Auditors examine documented arrangements, sample objective evidence from records, observe processes in operation, and interview personnel at the levels where requirements are actually met rather than only management. Audits are planned and conducted following the principles of ISO 19011, which governs auditor competence, the evidence-based approach and impartiality — but the criteria remain yours.
When supplier audits are used
- Before awarding a contract to a new supplier
- At agreed intervals through a long-term supply agreement
- Following a quality escape, defect recurrence or delivery failure
- As part of a vendor approval or qualification programme
- Where your own customer requires evidence that your supply chain is controlled
- Before increasing volume or extending scope with an existing supplier
- Where a supplier's certification is held by a body whose recognition you cannot verify
Auditing suppliers overseas
Most supply chains serving Norway extend into Asia, and an audit conducted by an auditor flown in for the purpose costs more and takes longer than one carried out locally. ITMAD operates through offices in China and Southeast Asia, so supplier audits at manufacturing sites in the region are conducted by auditors already there, in the supplier's language, and reported back to Norway time.
What you receive
- A report stating findings against each audit criterion
- Objective evidence recorded for every finding
- Non-conformities classified by severity for prioritised action
- Findings in your own vendor scorecard format, on request
- A view on whether the supplier is capable of the commitment being considered
- Follow-up verification of corrective action, where included in scope
Independence
ITMAD acts for you, not for the supplier, and has no commercial relationship with the organisations it audits on your behalf. Where ITMAD certifies a supplier's management system, we will tell you so before accepting the instruction rather than after the report is issued.
Second-party audits
Supplier audits are sometimes called second-party audits — first party being an organisation auditing itself, second party a customer auditing its supplier, and third party an independent certification body. The terms describe the same activity and this page covers it.