DACH supplier audit checklist: template, test steps, evidence
Supplier audits rarely fail because of the audit methodology, but because of the presentation. This checklist structures preparation, on-site day, deviation tracking and evidence storage according to standard DACH requirements and makes the result audit-proof.
According to ISO 9001:2015 Section 8.4 and ISO/IEC 27001:2022 Control A.5.19, companies must control external providers and provide documented evidence of the result. In the DACH region, there are often additional requirements from the Supply Chain Due Diligence Act (LkSG, § 4 ff.) as well as industry-specific requirements such as IATF 16949 for automotive or EU-GMP for pharmaceuticals. An audit checklist is not a nice-to-have, but rather central evidence that your company systematically evaluates, documents and controls supplier risks. The template is at the same time a working tool for the auditor, evidence in the certification audit and the basis for the annual LkSG reporting at the Federal Office of Economics and Export Control (BAFA), which has been binding for companies required to report since the 2023 financial year.
This article shows how a reliable supplier audit template for the DACH region is structured: from risk-based pre-selection to on-site testing to action tracking and audit-proof storage. You will find out which 37 test points have proven themselves in practice, how deviations are classified according to materiality, which deadlines apply depending on the level of severity and how the entire documentation can be brought together in a system that can withstand an auditor, an ISO certifier and a BAFA inquiry at the same time. The article is aimed at purchasing managers, quality managers, compliance officers and external auditors who want to raise their current Excel-based approach to an audit-proof level. Audit-proof, documented, § 4 LkSG-proof.
Key Takeaways
- A DACH-ready supplier audit template covers preparation, on-site day, deviation report and resubmission in a coherent document stream with unique IDs.
- Deviations are classified into four categories (critical, significant, minor, observation) and are recorded with a deadline, who is responsible on both sides and the form of proof.
- The template must map interfaces to ISO 9001, ISO/IEC 27001, LkSG and, if necessary, IATF 16949 or GMP so that an audit appointment serves several standards at the same time.
Why a DACH-specific supplier audit template is necessary
Supplier audits in the DACH region are subject to a dense set of regulations that cannot easily be reproduced from an English-language standard template. At the group level, Section 8.4 of ISO 9001:2015 applies to controlling external providers. There are also ISO/IEC 27001:2022 Control A.5.19 for IT suppliers, the German Supply Chain Due Diligence Act (LkSG, in force since January 1, 2023) and industry-specific standards such as IATF 16949 for automotive, EU-GMP for pharmaceuticals or the EU Regulation 2017/745 (MDR) for medical devices. A generic audit template from the English-speaking region rarely reflects this stratification and regularly leads to additional demands in the certification audit.
A DACH-specific template also takes legal peculiarities into account: the written form according to Section 126 BGB for certain agreements, the ten-year retention requirement under commercial law according to Section 257 HGB, the GDPR-compliant processing of personal audit data and the requirements of the Trade Secrets Act (GeschGehG) for the treatment of supplier's sensitive information. Anyone who simply translates an international template runs the risk of providing incomplete evidence, setting retention periods incorrectly and receiving a significant deviation in the follow-up audit, which in turn can trigger escalation obligations towards customers.
CIVAC provides the supplier audit template as one of 490 ready-to-use audit templates in the workspace. The template is linked to the roles supplier auditor and LkSG representative, so that preparation, implementation and follow-up run in a single reporting line and the results are automatically included in the annual LkSG report, which must be submitted to BAFA no later than four months after the end of the financial year. The auditor calls, the evidence is ready. The template also takes into account the different requirements for confidentiality agreements in Germany, Austria and Switzerland, which quickly become ineffective without local adaptation, as well as the nationally applicable retention periods, which range between seven and ten years for tax-relevant documents.
Structure of the checklist: four phases, one document thread
A professional supplier audit template is divided into four phases, which are stored in a coherent document thread and reference each other. Phase 1 (preparation) includes the risk classification of the supplier according to volume, criticality and geographical location, the audit plan with scope and reference to standards, the formal request to the supplier and the dispatch of the preliminary documents, at least ten working days before the appointment. Phase 2 (implementation) covers the opening meeting, on-site inspection, sampling from processes and closing meeting. Phase 3 (reporting) records deviations, corrective actions and deadlines. Phase 4 (follow-up) checks the implementation, documents the evidence and closes the audit cycle.
Each phase creates its own artifacts: audit plan and risk classification (phase 1), audit log with time stamp for each check point and attendance list (phase 2), deviation report with classification and action plan (phase 3), resubmission and re-audit report with evidence files (phase 4). These artifacts must be linked in a referenceable manner: a deviation report without reference to the audit plan and the protocol is vulnerable in the follow-up audit because the connection between observation and evaluation cannot be traced. The CIVAC template enforces this link via unique audit IDs and automatic cross-references between documents.
It is important to separate mandatory and optional fields. Mandatory fields (audit number, date, auditor, supplier name, scope, reference to standards, type of audit) cannot be left empty and are technically enforced. Free fields (attendance list with photo, translation required, accompanying person from purchasing) are activated depending on the audit type. A Stage 2 certification audit has different mandatory fields than a monitoring audit of the existing supplier or a trigger audit after a quality incident. The template recognises the audit type from the audit plan and automatically activates the appropriate set of fields so that the auditor does not have to work with irrelevant mandatory fields and at the same time does not forget any relevant fields. This context-sensitive control is one of the reasons why Excel as an audit tool in the DACH region is increasingly being replaced by dedicated platforms.
37 check points: what the checklist specifically contains
The CIVAC supplier audit template includes 37 test points, divided into seven clusters, which are based on the requirements of the relevant standards. Cluster 1 (company data, 4 points) records the legal form, VAT ID, management and number of employees with a reference date. Cluster 2 (quality management, 6 points) checks ISO 9001 certificate with scope, management review frequency, complaint rate of the last twelve months, effectiveness of corrective and preventive measures, implementation of internal audits and proof of training of key personnel. Cluster 3 (information security, 5 points) assesses ISO/IEC 27001 status, access concept according to need-to-know, backup strategy, incident response plan and the control of the own supply chain.
Cluster 4 (LkSG and human rights, 5 points) records risk analysis according to § 5 LkSG, complaint mechanism according to § 8 LkSG, training status of employees, code of conduct and control from sub-suppliers. Cluster 5 (environment and ESG, 4 points) checks ISO 14001 status, CO2 balance according to Scope 1 and 2, waste management according to the Circular Economy Act and the handling of hazardous substances according to the Hazardous Substances Ordinance. Cluster 6 (occupational safety, 4 points) evaluates risk assessment according to Section 5 ArbSchG, regular instructions, personal protective equipment and emergency plan. Cluster 7 (contractual obligations, 9 points) checks delivery time, price stability, penalty regulations, confidentiality according to GeschGehG, GDPR order processing according to Art. 28, insurance coverage, force majeure clause, exit clause and audit law.
There are three fields for each of the 37 test points: target requirement (what is expected, with reference to standards), actual findings (what was found, with evidence) and assessment (compliant, minor, essential, critical). The evaluation is based on standards and is not subjective. Example: If a risk analysis according to Section 5 LkSG is missing, this is a significant deviation with a notice period of 30 days, not a minor deviation according to the auditor's discretion. This rigor is intentional and protects the follow-up audit because the assessment remains reproducible at any time. At the same time, it protects against accusations of arbitrariness if a supplier challenges the evaluation or an auditor questions the effectiveness of the supplier management.
Classification of deviations: four levels, clear deadlines
Assessing deviations is the most delicate part of a supplier audit. A classification that is too mild endangers your own compliance and leads to the question in the certification audit as to why the sub-supplier was not controlled. A classification that is too strict puts a strain on the supplier relationship and can lead to evasive reactions, such as relocating critical production steps to non-audited sub-suppliers. The CIVAC template therefore works with four clearly defined levels, which are based on ISO 19011:2018 (Guidelines for the auditing of management systems) and have been further refined in recent years through practical cases.
Level 1 (critical) refers to a deviation that represents an immediate risk to people, the environment or the company's own product quality, such as a lack of risk assessment on an actively operated machine, an open security vulnerability without a patch in a production-related system or a lack of approval according to the Federal Immission Control Act. Deadline: 24 to 72 hours, immediate action documented with photo or log file. Level 2 (essential) refers to systematic non-compliance with a standard requirement, such as a lack of ISO 9001 certification despite a contractual obligation or a lack of risk analysis in accordance with Section 5 LkSG. Deadline: 30 days, corrective action plan submitted and effectiveness proven within 90 days.
Level 3 (minor) refers to a selective deviation without a systematic character, such as an outdated procedural instruction, a missing signature on an otherwise compliant protocol or an expired copy of the certificate when there is a renewal. Deadline: 90 days. Level 4 (observation) is not formally a deviation, but rather an indication of potential for improvement, which will be presented again in the next audit. Each deviation is recorded with a deadline, who is responsible on the supplier side, who is responsible on our own side and the form of proof (photo, certificate, report, log file). This is the prerequisite for the resubmission to work and for the audit cycle not to get lost in the mailbox.
Risk-based selection: not every supplier needs to be checked on site
A common mistake in DACH companies is to treat all suppliers equally and to either audit everyone across the board (waste of resources) or to audit none across the board (compliance risk). Both are not standard compliant. ISO 9001:2015 Section 8.4.1 expressly calls for risk-based control of external providers, as does ISO/IEC 27001:2022 Control A.5.19 for IT suppliers. CIVAC's supplier audit template therefore integrates a pre-selection based on three main criteria: procurement volume per year, criticality for your own product or service, substitutability within a defined time horizon.
Suppliers in category A (high volume, high criticality, difficult to replace within twelve months) receive an on-site audit every two years, with a structured self-assessment in between using a questionnaire with a sample. Suppliers in category B (medium values in at least two of the three dimensions) receive an on-site audit every four years, with a self-assessment in between. Suppliers in category C (low values in all three dimensions) are controlled via self-assessment and selective sampling. This staggering must be documented and confirmed in the annual management review, otherwise it will not apply in the audit and can lead to complaints.
In addition, trigger audits are used, which are triggered independently of the regular cycle: in the case of quality incidents with complaints statistics that are noticeable, in the event of data protection violations by the supplier in accordance with Art. 33 GDPR, in the event of an application for insolvency or restructuring, in the event of a change of ownership or relocation of production to a high-risk country according to the Transparency International CPI or Heritage Foundation Index. These triggers are stored in the template as an escalation path and monitored automatically. For example, anyone who has appointed a LkSG representative has these triggers automatically monitored in the workspace and receives a notification as soon as a supplier falls into the escalation path. The appointment certificate, signed, filed, verifiable.
Remote audit vs. on-site audit: what the standard really allows
Since 2020, the remote audit has become an integral part of the method repertoire and no longer just an emergency option. ISO 19011:2018 explicitly allows this, provided the effectiveness of the audit methodology can be proven in the specific case and the audit objectives can be achieved. For existing suppliers in category B or C, a remote audit with video inspection, electronic document viewing and live interview is a valid option that saves travel costs and CO2 emissions and can increase the audit frequency without multiplying the audit days.
However, for initial audits and for category A suppliers with high criticality, the on-site audit remains the standard. Certain test points, such as inspecting production lines to assess hygiene zones, inspecting storage conditions for hazardous substances in accordance with the Hazardous Substances Ordinance, checking access control in data centres or verifying physical separation in rooms with customer data cannot be reliably recorded remotely. The CIVAC template therefore indicates for each test point whether it is suitable for remote use, has limited remote suitability or can only be tested on site. The auditor shall justify any exception to this designation in the audit plan.
For hybrid audits, a combination of on-site day and remote preparation and follow-up, the methodology must be justified in the audit plan. The supplier's technical equipment (bandwidth, camera quality, availability of the audit team) is also part of the preparation and is verified in a technology check before the audit begins. A remote audit that has to be canceled due to technical problems is considered not to have been carried out and can lead to a significant deviation in your own certification audit because the promised frequency was not met. For this reason, remote audits in the CIVAC template are always scheduled with a backup date that is no later than 14 days after the original date and can be used without another formal request.
Data protection and confidentiality in the audit
Supplier audits regularly touch personal data (attendance lists, proof of training, employee surveys as part of LkSG audits, photos of employees) and business secrets (recipes, source code, customer lists, price structures, procedural instructions). Both are legally protected: personal data by the GDPR and the BDSG, trade secrets by the Trade Secrets Act (GeschGehG, in force since April 2019). An audit methodology that does not actively address these two circles of protection is vulnerable and can lead to claims for damages and, in extreme cases, criminal consequences.
The CIVAC template requires a written confidentiality agreement (NDA) before the start of the audit with a clearly defined scope, retention period and contractual penalty in the event of a breach, and, if personal data is processed, an order processing agreement in accordance with Art. 28 GDPR or a joint controller agreement Art. 26 GDPR. In the audit log, personal data is recorded pseudonymously (employee A, employee B instead of first name and last name). Photos of people are only permitted with documented consent, which is stored in the workspace together with the photo. In the case of surveys in the LkSG context, the whistleblower's protection also applies according to the Whistleblower Protection Act (HinSchG), which requires confidential treatment of the identity and requires separate, access-restricted storage in the audit protocol.
The retention of the audit documents follows the ten-year period in accordance with Section 257 of the German Commercial Code (HGB) if they are tax-relevant documents, otherwise the three to six year retention period in accordance with the GDPR principles of storage limitation. In the CIVAC workspace with EU data residency, the retention period is set automatically for each document type and is either deleted or anonymized when it expires. Your own external data protection officer can inspect on request without the audit team having to export manually, which significantly increases the efficiency of the GDPR self-disclosure and at the same time clearly documents the separation of responsibilities between audit and data protection.
Evidence storage: how an audit is documented for auditors
The best audit implementation is worthless if the evidence base does not hold up. Three principles apply and are checked in every certification audit, in every BAFA sample and in every audit: completeness, immutability, findability. Completeness means: every mandatory field in the template is filled, every deviation has documented proof of measures, every resubmission date is entered and linked to a person responsible. Immutability means: after the closing meeting, all fields are locked, later changes are made exclusively as versioned additions with the reason and person responsible, the previous version remains preserved and visible.
Findability means: every audit has a unique ID, can be filtered by supplier, date, auditor, scope and standard and can be found in the follow-up audit within 60 seconds, even if the original auditor has left the company. An Excel spreadsheet in an individual employee's Outlook mailbox does not meet this requirement. A directory tree on a file server without versioning and without an access protocol does not fulfil this requirement. A Confluence page with edit rights for all auditors without a locking mechanism after completion also does not fulfil this requirement and regularly leads to complaints because the question of security against manipulation cannot be answered.
In the CIVAC workspace, audits are stored in an audit-proof storage with hash verification and a complete audit trail. Each change creates a new version with a timestamp and user ID without deleting the previous version. The export for external auditors (audit, ISO certifier, supervisory authority, customer audit) is done with one click and automatically contains the associated documents: audit plan, protocol, deviation report, status of measures, evidence files, communication with the supplier. Others run compliance like a filing cabinet. We run it like software. That is the difference between a good template and a compliance platform that remains comprehensible even in the fifth follow-up audit and can survive a change in those responsible for the audit without data loss.
From reading to order: CIVAC as a platform and as an officer-as-a-service
An audit template alone does not make supplier management work. It takes the combination of template, trained role (supplier auditor), clear reporting line to management, audit-proof filing and a re-audit cycle that does not get lost in day-to-day business. CIVAC is a compliance platform and officer-as-a-service that bundles exactly these five building blocks in a single system and links them to the 24 other officer roles that are relevant in a typical medium-sized company.
Licence the workspace for your internal officers, or have our officers appointed. In the first model, your own auditors get access to the 490 ready-to-use audit templates, including the DACH supplier audit checklist, as well as the reporting line for 25 representative roles, 93 controls according to ISO/IEC 27001:2022 and the EU data residency. In the second model, CIVAC provides an experienced supplier auditor who takes care of preparation, implementation and follow-up and is integrated into your reporting line. The appointment certificate is drawn up in the CIVAC SLA of two working days, instead of the industry standard two to six weeks.
Both models use the same platform, the same storage, the same templates, the same evaluation logic. If you later switch between models, for example because an internal position cannot be filled, all audit data is retained and the external auditor takes over seamlessly. Turn reading into a mandate.: write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment of your supplier portfolio with categorization into A, B and C and a suggestion for the appropriate audit frequency within five working days, without being bound by a contract and without having to export supplier data into our systems.
FAQ
As a medium-sized company, do you have to audit every supplier?
No. ISO 9001:2015 Section 8.4 requires risk-based management, not a comprehensive audit obligation for each individual provider. Categorize suppliers by volume, criticality and substitutability and audit Category A on-site every two years, Category B every four years, Category C via structured self-assessment with a sample. This graduation must be confirmed and documented in the management review, otherwise it will not apply in the certification audit.
How does an LkSG audit differ from an ISO 9001 supplier audit?
An LkSG audit checks human rights and environmental due diligence obligations in the supply chain in accordance with Section 4 ff. LkSG and also considers the sub-suppliers in the risk analysis. An ISO 9001 audit checks the quality capability according to Section 8.4. Both can be covered in one appointment as long as the template contains both clusters and the auditor is qualified in both areas. CIVAC integrates both standards in the DACH audit template and thus avoids double visits.
Is a remote audit legally equivalent to an on-site audit?
ISO 19011:2018 expressly allows remote audits, provided that the effectiveness of the audit methodology in the specific case can be proven and the audit objectives are achieved. For initial audits and for high-risk suppliers in category A, the on-site audit remains standard because certain inspection points (inspection, visual inspection, access control) cannot be reliably recorded remotely. Hybrid models are permitted, but must be justified in the audit plan.
How long do you have to keep audit documents?
The retention period is ten years according to Section 257 of the German Commercial Code (HGB) if the documents are relevant for tax purposes, for example because they serve as the basis for incoming invoices. For purely operational audit data, the GDPR storage limit in accordance with Article 5 Paragraph 1 Letter e applies, in practice three to six years, depending on the processing purpose. CIVAC sets the deadline automatically for each document type and deletes or anonymizes it after expiry.
Who is allowed to carry out a supplier audit?
There is no government approval for supplier auditors in the DACH region. Qualifications according to ISO 19011, training at DGQ, TÜV or DEKRA and industry certificates such as VDA 6.3 for automotive or GMP auditor for pharmaceuticals are common. The auditor must be independent of the area being audited. CIVAC provides auditors with documented qualifications and industry experience whose certificates are stored in the workspace.
How much does a supplier audit cost in the DACH region?
A one-day on-site audit with preparation and follow-up costs between 2,500 and 4,500 euros net for an experienced auditor, depending on travel costs, preparation effort and audit program. Remote audits are around 30 percent lower because there are no travel and accommodation costs. CIVAC offers audit packages per supplier portfolio, not per day, which improves predictability for annual LkSG reporting.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.