Dhanu Audit
Food Safety Audit Operations

Insights

Supplier Approval Without the Paperwork Theatre

Dhanushka Kariyawasam · 13 September 2026 · 5 min read

Most supplier approval programs collect three things: a certificate, a completed questionnaire, and a specification. All three are filed. The supplier is approved. The folder is produced at audit as evidence of control.

A folder of PDFs is not assurance. It is documentation of an assurance process that may or may not have happened.

The question worth asking of any supplier approval program is simple: if this supplier's controls failed tomorrow, would anything in our approval process have given us warning? For most programs the honest answer is no, because approval measured whether the supplier could produce paperwork, not whether they could produce safe product consistently.

Read the certificate properly

A third-party certificate is genuinely useful information, but only if read rather than filed. Four things matter, and each is routinely missed:

  • Scope. Does the certified scope actually cover the product you buy and the process used to make it? A certificate covering a supplier's ambient product range does not cover the chilled line they added last year.
  • Exclusions. Many certificates carry explicit exclusions. These are where the assurance stops, and they are often precisely the area of interest.
  • Currency and grade. Expiry date, and where the scheme grades outcomes, the grade achieved and whether it was an announced or unannounced audit.
  • Verification at source. Verify the certificate on the scheme's public register rather than trusting the PDF the supplier sent. Certificates are edited more often than anyone likes to acknowledge.

Tier suppliers by the risk they carry

Applying the same approval process to every supplier wastes effort on low-risk ones and under-controls high-risk ones. Tier on a combination of:

  • Inherent hazard of the material — a ready-to-eat ingredient with no further lethality step in your process sits at the top, regardless of the supplier's size or reputation
  • Criticality — what happens to your operation if this material fails or stops
  • Substitutability — a sole-source supplier warrants closer control because you have less leverage and no fallback
  • Volume and frequency of supply
  • Performance history, including responsiveness to previous issues

Then differentiate the requirement. High tier justifies an on-site second-party audit. Middle tier might be a desktop review plus certificate verification plus periodic independent testing. Low tier may reasonably be certificate and specification only.

Document the tiering logic. An auditor's question is rarely "why did you not audit this supplier?" — it is "how did you decide not to?"

The specification is the control

An approved supplier delivering against a vague specification is not a controlled supply. The specification is where approval becomes operational, and weak specifications are common.

A usable specification states parameters with tolerances, the test method for each, sampling frequency, and what happens when a result falls outside. "Low microbial count" is not a specification. A stated organism, limit, method and sampling plan is.

Allergen status, country of origin, and any process claim you rely on (such as a validated kill step at the supplier) belong here explicitly, because these are the claims that turn into your label declarations.

Verify the certificate of analysis

Reliance on supplier CoAs is normal and reasonable. Reliance without verification is not.

If CoAs are accepted in place of your own incoming testing, the program needs periodic independent verification — your own testing of a sample, at a defined frequency, compared against the CoA for the same consignment. This is not about suspecting dishonesty. It is about confirming that the supplier's method, sampling point and limits mean what you assume they mean.

A CoA verification program is one of the most commonly missing controls in otherwise mature supplier systems, and one of the easiest to implement.

Require notification of change

This is the most frequently absent contractual control in supplier agreements, and it causes a disproportionate share of incidents.

Without an explicit obligation to notify, a supplier may change their own sub-supplier, reformulate, move production to a different site, change a process parameter, or alter packaging — all without telling you, and all potentially invalidating your hazard analysis, your allergen declarations, or your label.

The clause should require advance notification of any change to formulation, ingredient source, manufacturing site, process, or allergen status, with sufficient notice for you to assess it. Then monitor whether it is actually complied with, because an unenforced clause provides no protection.

Approval is not an event

The most consequential shift is treating approval as an ongoing status rather than a one-time gate. Monitor, per supplier:

  • Specification conformance rate and out-of-spec frequency
  • Complaint and rejection rate attributable to them
  • On-time and in-full performance, as a proxy for operational stability
  • Responsiveness and quality of corrective action when an issue is raised

That last one is the most predictive. A supplier who responds to a nonconformity with a real root cause and a verifiable action is a lower risk than one with a better certificate and a habit of replying "operator retrained."

Practical takeaways

  1. Verify certificates on the scheme register, and read scope and exclusions rather than filing the PDF.
  2. Tier suppliers on hazard and criticality, and write down the logic behind the tiering.
  3. Fix the specifications first. Approval built on a vague specification cannot control anything.
  4. Add CoA verification testing at a defined frequency if you rely on supplier CoAs.
  5. Put a notification-of-change clause in every agreement, and check it is being honoured.
  6. Score supplier corrective action quality. It predicts future performance better than any certificate.

Approval should tell you something you did not already know. If your process only confirms that a supplier can supply documents, it is measuring their administration, not their food safety.

Related service

Supplier Audits

Second-party assessment of supplier and supply-chain controls.

← All insightsNext: Environmental Monitoring: What Your Results Are Actually Telling You →