Supplier Audit Tracker
Track supplier capability audits — score six sections per audit, record findings and corrective actions, and get an approval verdict per supplier; the companion to a supplier scorecard, which tracks ongoing delivery performance rather than audits. Nothing is uploaded.
Version 1.0.0 · Updated Aug 7, 2026
Overview
Frequently asked questions
How does the Supplier Audit Tracker licence work?
It is a one-time purchase for a downloadable tool — no subscription. You buy it once and the file is yours to keep and use.
Can I try the Supplier Audit Tracker before buying?
Yes. Use the Try online button for a fully interactive demo with sample data already loaded — nothing to install and nothing is saved.
Does my data stay private?
Yes. The tool is a single HTML file that runs entirely on your computer and makes no network requests, so nothing you enter is ever uploaded or shared.
Do I need Excel or any other software?
No. It replaces the spreadsheet template entirely: open the file in your browser (Chrome, Edge, Firefox or Safari) on Windows, Mac, Linux or a tablet, and start working.
How to use Supplier Audit Tracker
The complete in-tool guidance, reproduced here so you can read it before you download.
What this tool does
CM8-264 is a working record of your supplier capability audits. Each row is one section of one audit — supplier, date, audit type, auditor, section, a 0–5 score, the evidence you saw, the finding if there is one, and the corrective action with an owner, a due date and an approval impact. Six rows make a full audit. The tool turns those rows into a section profile for the latest audit, a ranking of suppliers by their most recent result, a view of which sections are weak across your whole supply base, and an approval board with an explicit verdict per supplier.
Everything runs inside this single file. There is no account, no upload and no network request of any kind — which matters, because an honest audit record says exactly what is wrong at a named company.
Why audit suppliers at all
The audit is the price of trust, paid once, before the purchase order. Every alternative is paid forever: incoming inspection on every delivery, safety stock against every late shipment, firefighting every quality escape at your own goods-in. A day spent at the supplier's premises before you commit tells you whether their system produces good parts by design or by luck — and it is far cheaper to find the missing traceability loop during an onboarding audit than in a recall meeting two years later.
The audit also changes the relationship. A supplier who has walked you through their CAPA log and had a finding accepted knows what you check and how you think. Corrective actions agreed at an audit get done in a way that complaints raised by email do not, because they gate the approval.
The four audit types
Onboarding is the approval audit for a new supplier, done before serious volume is committed. It covers all six sections, takes the most time, and is the one audit where you hold all the leverage — every finding closed before the first order is a finding you never have to chase.
Surveillance is the routine re-audit of an approved supplier, typically every one to three years depending on risk and spend. It is shorter and it should be targeted: re-check what was weak last time, sample what was strong. A supplier who knows surveillance is coming behaves differently all year — that is most of its value.
For-cause is triggered by problems: a quality escape, a run of late deliveries, a worrying credit report. It goes deep on the sections implicated by the trigger and it is the audit most likely to change an approval status. Arrive with the evidence that triggered it.
Desktop is a remote, documents-only review — certificates, procedures, filed accounts, a questionnaire. It is legitimate for low-risk commodity suppliers and as a screening step, but score honestly: a desktop audit can verify that documents exist, never that they are followed. Say so in the evidence field.
The six sections, and what to sample in each
Records beat presentations. In every section, ask for the last real example, not the procedure — the procedure tells you what should happen; the record tells you what does.
- Quality system — procedures, records, CAPA. Ask for the last nonconformance and follow it: was the cause found, the action closed, the effectiveness checked? A live CAPA log with a few overdue items is more credible than a spotless one.
- Production capability — equipment, capacity, maintenance. Look at the maintenance records for the machine that would make your parts, and ask what happens when it breaks. Ask how much headroom they have at current loading — a supplier at 98% capacity is a delay you have already bought.
- Material control — traceability, storage, FIFO. Pick a finished batch and trace it back to the raw-material certificate; then pick a certificate and trace it forward. Check the corners: rework loops, returns, free-issue material — traceability usually breaks off the main path.
- People & competence — training, skills coverage. Take the skills matrix to the shop floor and check it against who is actually running the machines. Count the people qualified on the process that makes your parts; if the answer is one, you have found a finding.
- Delivery & planning — scheduling, on-time history. Ask how orders are planned and what their on-time-in-full number is, then test it against a reference or your own receipts. A supplier who cannot state their OTIF is not managing it.
- Commercial & continuity — financial health, business continuity. Review filed accounts, insurance, and what happens if their biggest machine, building or customer disappears. A technically excellent supplier three months from insolvency is not an excellent supplier.
The 0–5 scale
Score what you saw done, not what the manual promises. 0 — absent: the process does not exist. 1 — ad hoc: it happens sometimes, undocumented, dependent on individuals. 3 — followed with gaps: the system works and the records mostly show it. 4 — effective and consistent. 5 — excellent and improving itself: they find and fix their own weaknesses before you do.
The classic score is the 2 — documented but not followed. The procedure is beautiful, the records say otherwise: the FIFO rule with undated stock in the racks, the calibration schedule with gauges out of date. A 2 is in some ways worse than a 1, because the supplier has already decided what good looks like and is not doing it — which is why this tool requires a written finding for any score of 2 or below.
Findings suppliers accept
A finding is a statement of fact against a requirement, with the evidence attached. "Reworked castings re-enter work-in-progress without a new batch record — batch 4471 rework, seen at the fettling bench" gets accepted and fixed. "Poor traceability culture" gets argued with, because it is an opinion wearing a judgement. No adjectives, no diagnosis of attitude — what you looked at, what you found, what requirement it fails. If the supplier's representative would agree the sentence is true while disliking it, it is written correctly.
The approval verdict
The Approval board gives one line per supplier based on their latest audit, and its rules are stated here so nobody has to reverse-engineer them:
Audit average = mean of the section scores in that audit (0–5) Not approved — any blocking finding open, or the average is below 2.5 Conditional — no blockers open, but conditional findings are open or the average is below 3.0 Approved — average 3.0 or better, no blocking findings open, no conditional findings open
The approval impact field on each finding is what drives this. A blocking finding says: we do not trade, or do not increase volume, until this is closed — and the tool will not let you record one without an action, because a blocker with no action blocks forever. A conditional finding permits trade with limits — reduced volume, extra inspection, a deadline — until it is closed. Open blockers and conditionals count against the supplier whichever audit raised them: closing the audit report does not close the finding.
Closing actions on evidence, not promises
An action is closed when the evidence arrives, not when the supplier says it is done. Write the closure evidence into the action itself — "procedure issued plus traceability records for the first three reworked batches" — so both sides know what done looks like. The action status "closed — evidence received" is worded deliberately: if you have a promise and no records, the action is still in progress. Date every action, name one owner (theirs or yours, but one person), and let the overdue flag do the chasing.
Audit vs scorecard — two tools, two questions
This tool answers: is this supplier capable? It is a point-in-time examination of their system, done on their premises or from their documents, a few times per relationship. The companion question — is this supplier performing? — is answered continuously from your own receipts: on-time delivery, rejected parts, response times, month after month. That is a supplier scorecard, and it is a separate tool (the Supplier Scorecard) fed by different data. They work as a pair: a slipping scorecard is the classic trigger for a for-cause audit, and a strong audit with a weak scorecard means the system is fine but the execution is not. Do not keep monthly delivery data here — one row per audit section is this register's grain, and it should stay that way.
FAQ
Do I have to score all six sections every time? Onboarding — yes. Surveillance and for-cause audits can legitimately cover fewer sections; the audit average is then the mean of the sections you scored, and the report says which they were. Be consistent enough that averages stay comparable.
Who should the action owner be? Whoever has to produce the evidence — usually someone at the supplier. Put your own name on actions only you can do, such as reviewing the evidence they send.
Can two auditors score the same audit? Yes — agree the score in the room and enter one row per section. If you cannot agree, the lower score with both views in the evidence field is the honest record.
What if a supplier refuses an audit? That is information. A desktop review may bridge a low-risk case; for anything critical, a supplier you cannot audit is a supplier you cannot verify.
How often should surveillance run? Risk-based: one to three years is common, shorter for single-source or safety-critical suppliers, and immediately after a major change — new site, new ownership, new process.
Saving your work
Scores, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.
Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work. Reset asks twice, then erases everything this tool has stored. There is no undo. Audit findings name companies and people — treat exports as confidential.
Accuracy & disclaimer
The arithmetic here is deliberately simple — section scores, their mean, and three stated verdict rules — and the tool applies it faithfully. Everything that matters sits underneath: whether the auditor sampled the right records, whether the scores reflect evidence or hospitality, and whether closed actions were closed on evidence. An audit is a sample of one day, and the frequency of surveillance matters more than any single score.
The verdicts are your own structured judgement, not a certification, an accreditation or a statement of conformity to any standard. Nothing here is legal or contractual advice, and this tool neither replaces the supplier development conversation nor has an opinion about who you should buy from.
Related tools
Link incoming material batches to the batches you make and the customers you send them to, so a recall can be scoped in minutes instead of days. Runs entirely in your browser — nothing is uploaded.
CAPA Tracker
Track corrective and preventive actions from problem to verified fix: root causes, owners, due dates, effectiveness checks and an aging view for management review. Runs entirely in your browser — nothing is uploaded.
Track customer complaints from intake to closure — acknowledgement and resolution times, justified rate, complaint costs and category trends, with a customer-ready report. Nothing is uploaded.
Log every delivery as it arrives, compare what turned up against what was promised and ordered, and measure on-time, in-full and on-time-in-full by supplier with the discrepancies still open. Runs entirely in your browser. Nothing is uploaded.