77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Supplier auditor: role, qualifications and obligation to provide documentation between ISO 9001, VDA 6.3 and LkSG
Audits & Suppliers

Supplier auditor: role, qualifications and obligation to provide documentation between ISO 9001, VDA 6.3 and LkSG

7 September 202613 min readBy Dr. Henrik Bauer
CIVAC

The supplier auditor decides whether procurement, quality and supply chain obligations come together. This guide explains qualifications, methodology, reporting line and the documentation requirement between ISO 9001:2015, VDA 6.3, IATF 16949 and LkSG.

ISO 19011:2018 defines the requirements for audit programs and auditor competence. Section 8.4 of ISO 9001:2015 requires the control of externally provided processes and products, including suppliers. Anyone who purchases in regulated industries is also familiar with VDA 6.3 (automotive process audit), IATF 16949 (automotive) and, since 2023, the LkSG, which indirectly makes supplier audits mandatory.

The supplier auditor is the person or function that operationally implements these requirements. He is not just an inspector with a checklist, but also a provider of documents for procurement, quality management, compliance and business management. This guide clarifies the task profile, qualifications, reporting line and which audit templates are now mandatory so that factory audits do not become an Excel graveyard.

Key Takeaways

  • According to ISO 9001:2015 Section 8.4, supplier audits are mandatory for critical suppliers, the methodology and depth must be documented and justified.
  • VDA 6.3 and IATF 16949 require certified auditors, ISO 19011:2018 defines the competency framework.
  • LkSG requires supplier audits indirectly via Section 6 as an appropriate preventive measure for identified risks.

What a supplier auditor does: task profile and boundaries

The supplier auditor checks the quality capability, process maturity, compliance status and risk profile of suppliers against defined standards and contractual requirements. He creates an audit plan, audit report and list of measures, tracks their implementation and suggests escalations if threshold values ​​are exceeded.

The role of three neighboring roles must be differentiated. The internal auditor audits the company (ISO 9001 Section 9.2). The certification auditor works for an accredited body and checks third-party management systems against standards. The supplier auditor examines third parties on behalf of the company.

The depth depends on the risk. An A-supplier for safety-relevant components requires a VDA 6.3 process audit before initial sample release and annual re-audits. A B supplier for standard parts is sufficient with self-disclosure plus a sample audit every three years.

The reporting line typically runs to purchasing, quality management and, in the case of LkSG-Trigger, to the supply chain representative. CIVAC maps this reporting line in the workspace, including escalation paths with deadlines and responsible persons.

Others run compliance like a filing cabinet. We run it like software. Audit reports, corrective measures and resubmissions are connected in the same system.

If you don't define the role clearly, you risk duplicating work between purchasing, QM and compliance. The appointment certificate specifies who is allowed to test, against which standards and with what reporting obligation.

Normative Grundlagen: ISO 19011, ISO 9001, VDA 6.3, IATF 16949

ISO 19011:2018 is the guideline for audit programs that applies across industries. It defines audit principles, the management of audit programs, the execution of audits and the competency requirements for auditors. Supplier audits fall under the second audit party category.

ISO 9001:2015 Section 8.4 requires that the organisation establish control mechanisms for externally provided processes, products and services. Depth must be risk-based. Audits are a possible control instrument, in addition to self-disclosure, certificate testing and delivery quality indicators.

VDA 6.3:2023 is the German industry standard for process audits in the automotive industry. The auditor requires certification according to VDA 6.3, which typically includes a multi-day course and an examination. Re-certification every three years.

IATF 16949:2016 requires auditors to meet specific IATF competency requirements, documented in the company's training matrix. The following applies across industries: The auditor's competence must be proven in writing.

CIVAC delivers the supplier auditor role as an officer-as-a-service with documented qualifications or as a workspace licence for its own certified auditors. The appointment certificate, signed, filed, verifiable.

Anyone who audits without documented competence risks having the audit results recognised by the certification body. This can jeopardize certification in IATF audits.

Supplier auditor qualifications: competency matrix and evidence

ISO 19011:2018 Section 7 lists the competency requirements. Personal behaviour, knowledge and skills in auditing, subject-specific knowledge, regulatory knowledge and industry knowledge. The combination of these areas must be documented and demonstrated through training, audit experience and mentoring.

Typical minimum requirements for a supplier auditor in industry: technical or commercial training with three years of professional experience, completed basic auditor training according to ISO 19011, at least five accompanied audits, knowledge of the relevant standards (ISO 9001, ISO 14001, ISO 45001, as applicable Scope).

Certifications are added for specific industries. VDA 6.3 for automotive, EN 9100 for aerospace, ISO 13485 for medical devices, IFS or BRC for food. The certificates are listed in the competency matrix and renewed before expiry.

The competency matrix documents per auditor: training, certificates, training courses, audits carried out with date and area, assessment results. It is part of the audit program according to ISO 19011 Section 5.

CIVAC maintains the competency matrix in the workspace with automatic resubmission before the certificate expires. Audit experience is automatically updated with each completed audit. The auditor calls, the evidence is ready.

With Officer-as-a-Service, the competency matrix lies with the service provider, who confirms the suitability to the contracting company on an annual basis. Both models are permitted according to ISO 19011 if the documentation is correct.

Audit program: planning, frequency, depth according to risk classes

The audit program determines which suppliers are audited, at what frequency and in what depth. ISO 19011:2018 Section 5 requires that the program is planned based on risk and defines objectives, scope, resources and criteria.

Risk classification is typically done according to spend, importance of the component for your own product, substitutability, supplier history, country and sector (relevant for LkSG). A suppliers receive annual on-site audits, B suppliers every two to three years, C suppliers receive self-disclosure with a sample.

Audit depth also varies. A system audit according to ISO 9001 typically takes two to three days and checks the entire management system. A process audit according to VDA 6.3 focuses on one or more processes and takes one to two days. A product audit checks specific components against the specification.

The program is updated at least annually by the audit program owner. Changes are documented with reasons and approval. The clock starts on awareness.

CIVAC models the audit program as a workflow with automatic scheduling, preparation checklists, audit report templates and action tracking. The chain of evidence between risk classification, audit plan and audit result remains traceable.

Audit templates include 37 preconfigured modules, including VDA 6.3, IATF 16949, ISO 9001, ISO 14001, ISO 27001 and LkSG-specific checklists. Audit-proof, documented, ISO-proof.

Implementation: From the audit plan to the report

ISO 19011:2018 Section 6 describes the process. Opening conversation with the audited supplier, checking against audit criteria, collecting and verifying evidence, forming findings, final discussion with preliminary results, audit report.

Findings are classified. Major deviation for systemic defects that jeopardize product quality or conformity. Minor deviation (secondary deviation) for specific defects that do not have a system character. Note (observation) if there is potential for improvement without violating standards.

The audit report contains scope, audit criteria, audit team, audit dates, findings with evidence, corrective action requirement and deadline. With VDA 6.3, an additional percentage point value is assigned that influences the supplier classification.

The list of measures is responded to by the supplier within a defined period of time with corrective measures, cause analysis and proof of effectiveness. Typical deadlines: 8 weeks for root cause analysis, 12 weeks for implementation, 6 months for proof of effectiveness.

CIVAC maps this workflow in the workspace. Determinations are recorded with ticket ID, person responsible, deadline and status tracking. Resubmissions are generated automatically. The auditor calls, the evidence is ready.

If you only store audit reports as PDFs in the folder, you will lose the connection to the tracking of measures. The chain of evidence between determination, measure and proof of effectiveness is mandatory, not legal.

Supplier audits and LkSG: Where quality meets human rights

The LkSG (Supply Chain Due Diligence Act, since 2023) requires appropriate preventive measures in the event of identified risks under Section 6. Supplier audits are a common instrument, especially for A-suppliers in high-risk countries or sectors.

The LkSG audit has a different focus than the classic quality audit. It examines human rights, working conditions, environmental regulations and complaint mechanisms. The auditors for this are usually not the classic QM auditors, but rather specialists or external service providers.

In practice, both types of audits can be combined. The integrated supplier audit checks quality, compliance and human rights in an on-site visit. The prerequisite is an auditor with advanced expertise or an audit team made up of QM and LkSG specialists.

BAFA auditors (Federal Office of Economics and Export Control) expect that supplier audits are incorporated into the LkSG risk analysis and that preventative measures are based on this. Audit reports are referenced in the LkSG report.

CIVAC connects QM audit and LkSG audit in one data structure. The supplier auditor and the LkSG representative work on the same supplier master record.

Anyone who manages both disciplines separately creates duplication of work and risks contradictory statements in the audit. Compliance platform and Officer-as-a-Service bring both into one workflow.

Remote audit, hybrid formats and digital audit trail

Since 2020, remote audits have been permitted in many schemes. IAF MD 4:2018 regulates the use of information and communication technology in audit processes. On-site audits remain dominant for initial certifications and critical suppliers; Re-audits and spot checks are increasingly becoming hybrid.

Requirements for remote audits: stable connection, screen sharing of the relevant systems, live video of the relevant work areas, identification of the conversation partners. The auditor must justify why remote is sufficient in this case.

Hybrid formats combine remote preparation (document review, interviews with managers) and on-site day (production, warehouse, workshop discussions). Audit duration is often reduced; The depth of documentation must remain the same.

Digital Audit Trail means that all audit artifacts (audit plan, reports, evidence, photos, measures) are stored in an audit-proof manner. EU data residency is mandatory for many clients, especially for suppliers with sensitive production data.

CIVAC offers EU data residency for all audit artifacts and is set up according to ISO/IEC 27001:2022 with 93 controls. Audit templates and photos are in the same workspace as the risk matrix and list of measures.

If you keep audit data in different tools (Sharepoint, Excel, email), you will lose the chain of receipts. The appointment certificate, signed, filed, verifiable also applies to digital document management.

Costs, time requirements and SLA: What a supplier auditor really costs

Costs depend on audit type, supplier location and auditor qualifications. An on-site system audit according to ISO 9001 in Germany typically costs 1,500 to 3,000 euros per audit day plus travel costs. VDA 6.3 with a certified auditor is more like 2,000 to 3,500 euros per day.

With your own auditors, there are personnel costs, training, certification and travel costs. A full-time auditor position, including overhead, costs 100,000 to 140,000 euros per year and manages 40 to 60 audits, depending on the amount of travel and audit depth.

Officer-as-a-Service combines flexibility and cost control. CIVAC offers the supplier auditor role with an appointment certificate, reporting line and defined audit volumes per year. The SLA is 2 working days for onboarding, instead of the classic 2 to 6 weeks.

Audit depth vs. time: A thorough process audit according to VDA 6.3 including preparation and follow-up takes a total of 5 to 8 person-days. Anyone who squeezes this into 2 days risks superficiality that the certification auditor will see.

CIVAC documents the audit effort in the workspace so that capacity planning can be run against the audit program. Bottlenecks become apparent early on and escalations are triggered.

Anyone who only awards audits based on price is buying into risk. The competency matrix and the audit report decide whether the audit is suitable as evidence. Compliance platform and officer-as-a-service in one hand.

CIVAC: Supplier auditor as a platform role and officer-as-a-service

CIVAC is a compliance platform and officer-as-a-service for supplier auditing, supply chain obligations, quality management and 22 other officer roles. The audit program, competency matrix, audit reports, list of measures and LkSG reference are in one workspace.

Licence the workspace for your internal auditors, or have our auditors appointed. Both models share the same data structure: 93 controls according to ISO/IEC 27001:2022, 490 ready-to-use audit templates, appointment certificate, reporting line, EU data residency.

Specifically for the supplier auditor role: pre-configured audit templates according to ISO 9001, VDA 6.3, IATF 16949, ISO 14001, ISO 45001, ISO 27001 and LkSG; Competency matrix with automatic certificate resubmission; Audit Plan Generator; audit report templates; Action tracking with ticket ID and escalation rules.

The CIVAC SLA is 2 working days for orders and onboarding, instead of the classic 2 to 6 weeks. The appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready.

The recommended start is a gap analysis: We map your existing audit program against ISO 19011, industry-specific standards and LkSG and provide a list of measures with effort and deadline.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. The gap analysis includes the audit program, competence matrix and reporting templates.

FAQ

What qualifications does a supplier auditor have to have?

ISO 19011:2018 requires documented competence in training, audit practice and subject area. Industry-specific certifications are also included: VDA 6.3 for automotive, EN 9100 for aerospace, ISO 13485 for medical devices. The competency matrix documents training, certificates, audits carried out and assessment results.

How often does a supplier audit have to be carried out?

The frequency is risk based. A suppliers usually annually, B suppliers every 2 to 3 years, C suppliers with self-disclosure and sample. ISO 9001 Section 8.4 only requires that the depth of control be justified. Industry standards such as IATF 16949 can specify fixed minimum frequencies.

How much does a supplier audit cost in Germany?

An on-site system audit according to ISO 9001 in Germany typically costs 1,500 to 3,000 euros per audit day, VDA 6.3 with a certified auditor costs 2,000 to 3,500 euros per day. Travel costs are added. Officer-as-a-Service models offer fixed prices per audit or annual volume.

Are remote audits of suppliers permitted?

Yes, IAF MD 4:2018 regulates the use of information and communication technology in audit processes. The prerequisites are a stable connection, screen sharing, live video and identification of the conversation partner. Initial certifications and critical suppliers usually remain on site.

How are supplier audits and LkSG obligations related?

LkSG Section 6 requires appropriate preventative measures when risks are identified. Supplier audits with a focus on human rights, working conditions and the environment are a common instrument. They can be combined with QM audits to form integrated audits, provided the auditor's competence covers both areas.

Can I outsource the supplier auditor role?

Yes, Officer-as-a-Service is permitted according to ISO 19011 if the competency matrix is ​​documented and the appointment certificate is signed. CIVAC offers the role with defined reporting line, audit templates and EU data residency. Responsibility for the audit program remains with the contracting company.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles