A supplier audit should answer one commercial question: can this shop repeatedly meet the requirements that matter to this program, under the controls and evidence your organization expects? A machine list or certificate can support that decision, but neither replaces process-level review.
Define the audit scope before the visit
Do not ask every supplier the same 200 questions. Scale the review to the product, process, data, documentation, delivery, and continuity risk.
| Scope decision | Question to settle before the audit |
|---|---|
| Program baseline | Which drawing revision, specifications, quality clauses, quantities, release pattern, and required dates govern? |
| Criticality | Which features, failure modes, special processes, documentation, or delivery interruptions create the highest consequence? |
| Required status | Is a specific certification, registration, customer approval, or approved-process source mandatory—or merely preferred? |
| Audit boundary | Will the review cover the whole quality system, one process, one program, cybersecurity, export controls, or a corrective-action follow-up? |
| Evidence and access | Which records may be reviewed publicly, under NDA, on-site, through a customer portal, or only after controlled-transfer approval? |
| Decision rule | Who can approve the supplier, which gaps are disqualifying, and which may close through a dated corrective-action plan? |
Eight-area CNC supplier audit checklist
1. Business identity and claimed scope
2. Contract, feasibility, and document control
3. Manufacturing process control
4. Inspection, calibration, and first article
5. Material, traceability, and sub-tier control
6. Nonconformance and corrective action
7. Capacity, delivery, and continuity
8. Technical data, cybersecurity, and export controls
Evidence pack to request
| Evidence | What it can verify | Scope caution |
|---|---|---|
| Capability statement and equipment list | Current processes, envelopes, inspection resources, contacts | Does not prove feature-level capability or available capacity |
| Certificate or audit roadmap | Current certification status, standard, site, scope, expiration | Verify with the issuing or authoritative source |
| Quality manual and process map | Responsibilities, core controls, interaction of processes | Confirm records show the system is operating |
| Calibration and inspection sample | Measurement control and example output | Match method and uncertainty to the actual characteristic |
| FAI or traceability sample | Record structure and linkage | Use redacted or approved examples; do not request another customer’s data |
| Sub-tier and special-process controls | Approval, flow-down, receipt, and certificate review | Confirm the actual order’s approved sources and responsibilities |
| Corrective-action example | Containment, root cause, action, effectiveness | Protect customer identity and confidential details |
| Capacity and continuity review | Planning assumptions, constraints, recovery ownership | Reconfirm at quote and order acceptance |
Turn findings into an approval decision
Record the requirement, objective evidence, finding, risk, owner, due date, and closure evidence. Avoid a score that lets many minor strengths hide one critical failure.
| Status | Meaning | Buyer action |
|---|---|---|
| Approved | Evidence supports the defined scope | Document scope, limits, and re-evaluation trigger |
| Conditional | Gap is understood and can close before affected work | Assign owner, due date, evidence, and interim containment |
| Not approved | Critical requirement is absent, contradicted, or unsupported | Do not release affected work until resolved |
| Not applicable | Requirement does not govern this scope | Record why; do not use N/A to avoid an open question |
CNC supplier-audit red flags
- A certification, registration, tolerance, capacity, or delivery claim cannot be tied to current evidence and the facility or scope being reviewed.
- The supplier cannot separate in-house processes from sub-tier work or explain how outside requirements are flowed down and accepted.
- Revision, program, setup, inspection, material, or nonconformance records cannot be traced through one representative job.
- Capacity is presented as a machine-hour total without setup, staffing, maintenance, inspection, material, tooling, or schedule assumptions.
- Controlled technical data is requested through an ordinary mailbox or general upload path before classification and access requirements are confirmed.
- Documentation is described as “included” without defining format, quantity, timing, retention, and price in the quote or order.
Use the checklist with Procut-CNC
Start with the public capability statement. Use the supplier-qualification request for quality-system materials, audit planning, current status, supplier IDs, NDA, secure transfer, or vendor onboarding. Move to the project RFQ when a drawing and commercial baseline are ready.
Current status is stated directly: Procut-CNC is ITAR registered. AS9100D and ISO 9001 certification is in progress, with Stage 1 planned; the company is not yet certified. Process fit, documentation, capacity, price, and lead time are confirmed program by program.
Authoritative reference points
This checklist is informed by publicly available guidance from the International Organization for Standardization, the IAQG Supply Chain Management Handbook, the U.S. Directorate of Defense Trade Controls, and NIST supplier due-diligence guidance. Apply the current governing standards and contract requirements for your program.
