HomeResources › Supplier Audit Checklist

Procurement · Supplier quality · Engineering

CNC Machine Shop Supplier Audit Checklist

A practical way to test capability, quality controls, traceability, delivery risk, and controlled-data handling before a sourcing decision becomes a production problem.

A supplier audit should answer one commercial question: can this shop repeatedly meet the requirements that matter to this program, under the controls and evidence your organization expects? A machine list or certificate can support that decision, but neither replaces process-level review.

Use this as a starting framework. Map the final audit to the governing drawing, contract, customer flow-downs, regulatory obligations, and your own approved-supplier procedure. This checklist does not certify a supplier or replace a standard.

Define the audit scope before the visit

Do not ask every supplier the same 200 questions. Scale the review to the product, process, data, documentation, delivery, and continuity risk.

Scope decisionQuestion to settle before the audit
Program baselineWhich drawing revision, specifications, quality clauses, quantities, release pattern, and required dates govern?
CriticalityWhich features, failure modes, special processes, documentation, or delivery interruptions create the highest consequence?
Required statusIs a specific certification, registration, customer approval, or approved-process source mandatory—or merely preferred?
Audit boundaryWill the review cover the whole quality system, one process, one program, cybersecurity, export controls, or a corrective-action follow-up?
Evidence and accessWhich records may be reviewed publicly, under NDA, on-site, through a customer portal, or only after controlled-transfer approval?
Decision ruleWho can approve the supplier, which gaps are disqualifying, and which may close through a dated corrective-action plan?

Eight-area CNC supplier audit checklist

1. Business identity and claimed scope

2. Contract, feasibility, and document control

3. Manufacturing process control

4. Inspection, calibration, and first article

5. Material, traceability, and sub-tier control

6. Nonconformance and corrective action

7. Capacity, delivery, and continuity

8. Technical data, cybersecurity, and export controls

Evidence pack to request

EvidenceWhat it can verifyScope caution
Capability statement and equipment listCurrent processes, envelopes, inspection resources, contactsDoes not prove feature-level capability or available capacity
Certificate or audit roadmapCurrent certification status, standard, site, scope, expirationVerify with the issuing or authoritative source
Quality manual and process mapResponsibilities, core controls, interaction of processesConfirm records show the system is operating
Calibration and inspection sampleMeasurement control and example outputMatch method and uncertainty to the actual characteristic
FAI or traceability sampleRecord structure and linkageUse redacted or approved examples; do not request another customer’s data
Sub-tier and special-process controlsApproval, flow-down, receipt, and certificate reviewConfirm the actual order’s approved sources and responsibilities
Corrective-action exampleContainment, root cause, action, effectivenessProtect customer identity and confidential details
Capacity and continuity reviewPlanning assumptions, constraints, recovery ownershipReconfirm at quote and order acceptance

Turn findings into an approval decision

Record the requirement, objective evidence, finding, risk, owner, due date, and closure evidence. Avoid a score that lets many minor strengths hide one critical failure.

StatusMeaningBuyer action
ApprovedEvidence supports the defined scopeDocument scope, limits, and re-evaluation trigger
ConditionalGap is understood and can close before affected workAssign owner, due date, evidence, and interim containment
Not approvedCritical requirement is absent, contradicted, or unsupportedDo not release affected work until resolved
Not applicableRequirement does not govern this scopeRecord why; do not use N/A to avoid an open question

CNC supplier-audit red flags

  • A certification, registration, tolerance, capacity, or delivery claim cannot be tied to current evidence and the facility or scope being reviewed.
  • The supplier cannot separate in-house processes from sub-tier work or explain how outside requirements are flowed down and accepted.
  • Revision, program, setup, inspection, material, or nonconformance records cannot be traced through one representative job.
  • Capacity is presented as a machine-hour total without setup, staffing, maintenance, inspection, material, tooling, or schedule assumptions.
  • Controlled technical data is requested through an ordinary mailbox or general upload path before classification and access requirements are confirmed.
  • Documentation is described as “included” without defining format, quantity, timing, retention, and price in the quote or order.

Use the checklist with Procut-CNC

Start with the public capability statement. Use the supplier-qualification request for quality-system materials, audit planning, current status, supplier IDs, NDA, secure transfer, or vendor onboarding. Move to the project RFQ when a drawing and commercial baseline are ready.

Current status is stated directly: Procut-CNC is ITAR registered. AS9100D and ISO 9001 certification is in progress, with Stage 1 planned; the company is not yet certified. Process fit, documentation, capacity, price, and lead time are confirmed program by program.

Authoritative reference points

This checklist is informed by publicly available guidance from the International Organization for Standardization, the IAQG Supply Chain Management Handbook, the U.S. Directorate of Defense Trade Controls, and NIST supplier due-diligence guidance. Apply the current governing standards and contract requirements for your program.

CallStart Review