SCRM Supplier Compliance & Risk Management

Home

Core topic · planning, execution, actions

An audit without a tracked action is an expensive visit.

The effort rarely sits in the audit itself. It sits in the planning before it, and in making sure the findings do not quietly evaporate afterwards.

A supplier audit checks, on site or remotely, whether a supplier actually meets the agreed requirements. It adds first-hand observation to self-disclosures and certificates – making it the strongest and also the most expensive instrument in supplier assurance.

Which is why selection decides everything. An audit programme sets out which suppliers are audited at what rhythm and on what grounds: criticality, past performance, incidents, regulatory demands. Without that reasoning, any audit programme looks arbitrary in a certification audit.

Typical weak points

  • The audit programme is an annual list with no visible selection logic.
  • Findings live in the audit report but not in a tracked action plan.
  • Effectiveness is never checked; the next audit finds the same deviation.
  • Reports sit as PDFs on a drive rather than on the supplier record.

The sequence

Programme
Set and justify selection and rhythm on a risk basis.
Preparation
Assemble history, open points and evidence before the date.
Execution
Checklist, observations, evidence – structured rather than free notes.
Findings
Classified by severity, with a deadline and an owner.
Effectiveness
A follow-up check on whether the action actually fixed the problem.

How SCRM covers it

Programme from the risk class

Who gets audited follows from the data – and is therefore defensible.

Report on the supplier

Audit history where evaluations and certificates already live.

Actions with deadlines

Every finding becomes a task with a date and an owner.

Auditor access

External auditors see the slice they need, not the whole portfolio.

Frequently asked

How often must a supplier be audited?

No interval is prescribed. You set it on a risk basis and keep to it. More important than frequency is that deviations are followed through.

Is a remote audit enough?

For many objectives yes, particularly document and process checks. For manufacturing and working conditions it only partly replaces being there – and that decision should be recorded with reasoning.

Who may audit?

Technically competent and independent people. The auditor’s qualification is part of the evidence and does get asked about in certification audits.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required