Supplier approval is one of the most important parts of a food safety management system. It influences every downstream program, from allergen control to labeling accuracy to micro verification. Most facilities already have some kind of supplier approval process, but the quality varies widely. Some supplier files are clean and predictable. Others contain expired certificates, outdated specs, and questionnaires that have not been updated for years. GFSI auditors review supplier approval carefully because it shows how well a facility controls materials coming into the plant.
A strong supplier approval checklist helps FSQA teams create a consistent, audit-ready program. It sets clear expectations for suppliers, reduces back-and-forth during onboarding, and makes it easier to evaluate risk. This guide outlines the essential items every FSQA team should require during supplier approval, how to assess each document, and how to avoid common gaps.
Supplier approval can become inconsistent when requirements vary by supplier or when documentation decisions are made informally. A checklist solves this problem by giving FSQA a structured baseline that applies to all suppliers based on risk.
A strong checklist helps teams:
Most importantly, it standardizes how suppliers are evaluated, which is a core expectation in all GFSI programs.
Before building the checklist, FSQA teams should define risk categories. The checklist should match the requirements for that category.
Common categories:
High Risk
Suppliers of raw ingredients, allergens, RTE materials, micro-sensitive materials, and anything that directly impacts CCPs or food safety.
Medium Risk
Suppliers of secondary ingredients, simple dry materials, or food-contact packaging.
Low Risk
Suppliers of non-contact packaging, office supplies, some chemicals, or service vendors.
Each risk category should define:
This ensures that FSQA does not demand the same level of documentation from a label printer as from a dairy powder supplier.
Below is a complete checklist FSQA teams can use for onboarding suppliers. Requirements may vary depending on risk, but this structure covers everything expected during GFSI audits.
This is the first and most important document. FSQA should request:
What FSQA should verify:
Common gaps:
This document provides the foundation for supplier risk evaluation.
The questionnaire helps FSQA understand the supplier’s programs and operations. A good questionnaire includes:
What FSQA should verify:
Common gaps:
A complete questionnaire helps FSQA identify risk before approving a supplier.
Every purchased material needs an up-to-date specification. Specs should include:
What FSQA should verify:
Common gaps:
Specs serve as the control point for COAs and receiving inspection.
Depending on the material, FSQA may need:
These support regulatory compliance and labeling accuracy.
What FSQA should verify:
Common gaps:
These documents support multiple FSMS programs, so accuracy matters.
If COAs are required, FSQA should:
What FSQA should verify:
Common gaps:
COAs link supplier documentation to daily operations.
Not all suppliers need to provide HACCP details, but for high-risk ingredients or RTE items, FSQA may need:
What FSQA should verify:
This is especially important for high-risk ingredients.
If the facility has purchased from the supplier before, include:
What FSQA should verify:
Past performance helps validate current risk level.
Many facilities require suppliers to acknowledge expectations around:
This sets clear expectations for the relationship.
Once all documents are collected, FSQA must review them as a complete package. The evaluation should consider:
A supplier should not be approved if any required documents are missing or if major conflicts exist between them.
High-risk suppliers should receive deeper review, including:
Consistency across documents is a key indicator of supplier control.
Purchasing, receiving, operations, and FSQA all influence supplier control. Approval should not occur in a vacuum.
Purchasing must ensure only approved suppliers are used.
Receiving must verify COAs and inspect materials.
Operations must understand changes that affect formulation or processes.
FSQA must manage documentation and risk.
A strong supplier approval process prevents cross-department confusion and aligns expectations early.
Supplier approval becomes more difficult when:
GFSI auditors notice these patterns quickly.
The checklist helps prevent these issues by providing clarity and structure.
The checklist itself must be reviewed periodically.
Update it when:
An outdated checklist leads to outdated supplier files.
How Certdox Supports Supplier Approval Programs
Certdox stores supplier certificates, questionnaires, specs, allergen statements, and COAs in one place. FSQA teams can track expirations, monitor supplier performance, and maintain predictable approval records without relying on shared drives or email folders. Certdox helps teams follow a consistent supplier approval checklist and stay audit-ready throughout the year.
Certdox helps FSQA teams stay aligned, accountable, and audit-ready every day with one centralized system for documentation, supplier records, and audit prep.
Book a Free Demo