Supplier Audit Types Explained: QMS, Social, and Security
Not every supplier audit checks the same thing. This guide breaks down QMS, social compliance, security, environmental, and technical audits: what each one covers, which standards apply, and how to pick the right type for your product and order.
The term "supplier audit" hides at least half a dozen completely different exercises. One audit inspects a factory's quality management system. Another checks whether workers are paid legal wages. A third looks at fences, cameras, and container seals. Booking the wrong type wastes your money and answers the wrong question. So before you schedule anything, know which audit you actually need.
In short: the main types of supplier audits are QMS audits (can this factory make your product reliably?), social compliance audits (are labor and safety standards met?), security audits (is your cargo protected from tampering and theft?), environmental audits (does the factory handle waste and emissions responsibly?), and technical/process audits (does this specific production process meet your specs?). Each type answers one question, follows different standards, and is demanded by different buyers. CN Ally can arrange the right audit type for your order: our team works with factories across China and can coordinate both general quality audits and specialized compliance checks.
How the audit types break down at a glance
If you only have a minute, this table maps the main types of supplier audits:
Audit type · What it checks · Reference standards · Who typically demands it
- QMS audit: Quality management system, document control, corrective action · ISO 9001; IATF 16949 (automotive); ISO 13485 (medical) · Most importers placing first or large orders
- Social compliance audit: Working hours, wages, child/forced labor, health & safety · SA8000, amfori BSCI, SMETA · Apparel, footwear, retail, EU brands
- Security audit: Cargo and facility security, anti-tampering measures · C-TPAT (CBP), GSV, SCAN · US importers in regulated supply chains
- Environmental audit: Waste, emissions, energy, chemical handling · ISO 14001, RoHS · ESG-conscious brands, EU buyers
- Technical / process audit: A specific process or capability vs. your specs · VDA 6.3 (process), customer checklists · Complex products, new tooling, new processes
Notice something important: these aren't tiers of the same audit. A QMS audit won't tell you anything about worker overtime, and a social compliance audit won't tell you whether the factory can hold your tolerances. Mixing them up is one of the most common mistakes buyers make. It's also one of the reasons factory audits sometimes "pass" without preventing the problems they were supposed to catch.
QMS audits: can this factory actually make your product?
The QMS (quality management system) audit is the workhorse of supplier verification. It asks one central question: does this factory have a system that produces consistent quality, or does it just get lucky sometimes?
An auditor walks through the factory and checks how quality is managed as a system: quality manuals, incoming and in-process inspection procedures, handling of non-conforming products, equipment calibration, and whether corrective actions actually get implemented after problems. The reference framework is usually ISO 9001 (the international standard for quality management), though the audit doesn't require the factory to be ISO 9001 certified.
QMS audit vs. ISO 9001 certification. A certification audit is formal, multi-day, and conducted by an accredited certification body; it ends with a certificate you can show customers. A supplier QMS audit is shorter, buyer-commissioned, and ends with a report telling you whether the factory's system is real or decorative. Certification is a snapshot taken under ideal conditions; a second-party QMS audit tells you how the system works on an ordinary Tuesday. Neither guarantees zero defects. They tell you whether the factory has the machinery of quality, which matters more than any single inspection result.
Industry-specific variants exist where the stakes are higher. Automotive buyers use IATF 16949, which layers automotive-specific requirements onto ISO 9001. Medical device buyers use ISO 13485. Food buyers look at ISO 22000 and HACCP-based systems. If your product falls into a regulated industry, don't accept a generic QMS audit as a substitute for the industry-specific one. The checklists cover genuinely different ground.
When to book one: before your first order with a new supplier (especially above a few thousand units), when switching product categories, or after a quality failure that suggests systemic problems. For more on how factory audits work in practice (scheduling, the audit day, reading the report), see our companion guide to factory audits in China.
Social compliance audits: the people behind your product
A social compliance audit checks something a QMS audit never touches: the working conditions of the people making your product. Working hours and overtime. Wages and whether they meet local legal minimums. Whether child labor or forced labor exists anywhere in the chain. Health and safety conditions on the production floor. Freedom of association and non-discrimination policies.
This is the audit type that surprises buyers most, because it's driven less by your product and more by your market and your industry. Three forces create demand for it:
- Customer and brand requirements. Big retailers and brands, especially in apparel, footwear, toys, and consumer electronics, require social compliance audits of their supply chain. If you sell to or through such a buyer, expect this.
- Regulation. Import rules in the EU and US increasingly require evidence about labor conditions and supply chain due diligence. The EU's corporate sustainability due diligence rules are pushing buyers to document exactly what these audits document.
- Reputation risk. A labor scandal at a supplier attaches to your brand, not theirs. For consumer-facing products, this audit is cheap insurance.
The standards you'll hear about most:
- SA8000: a certifiable social accountability standard covering child labor, forced labor, health and safety, freedom of association, discrimination, disciplinary practices, working hours, and compensation.
- amfori BSCI: the Business Social Compliance Initiative, run by the trade association amfori. Very common in European supply chains; audits rate factories from A to E across thirteen performance areas.
- SMETA: the Sedex Members Ethical Trade Audit, one of the most widely used audit formats in the world. Not a pass/fail certification but a methodology for reporting labor, health and safety, environmental, and business ethics findings.
When to book one: if you sell consumer products in the EU or US, if your customers will ask for it, or if your order volume makes you a meaningful part of a factory's business, which makes you accountable for how it's run. Note that social compliance audits are almost always announced: the auditor needs payroll records, attendance records, and worker interviews, which can't happen without the factory's cooperation.
Security audits: protecting cargo, data, and intellectual property
A security audit asks whether your product can be stolen, tampered with, or substituted somewhere between the factory and your warehouse. It's the audit type most importers never think about until they need it, usually when a US-bound supply chain requires it.
The flagship program here is C-TPAT (the Customs-Trade Partnership Against Terrorism), run by U.S. Customs and Border Protection and launched in 2001. It's voluntary: importers and their supply chain partners agree to meet CBP's Minimum Security Criteria, covering physical security, personnel security, procedural security, IT/cybersecurity, and business-partner security. In return, members get benefits like fewer cargo examinations, front-of-line processing when exams do happen, and business resumption priority after disruptions. The criteria were overhauled in 2019 to add modern risk areas including cybersecurity and anti-money-laundering measures, per guidance from trade counsel such as Reidel Law Firm.
Related programs include GSV (Global Security Verification) and SCAN (Supplier Compliance Audit Network), both focused on cargo and supply chain security for factories shipping internationally.
Who needs this? If you import into the US at volume, especially electronics, high-value goods, or anything where counterfeiting is a risk, a C-TPAT-oriented security assessment may be required by your logistics partners or buyers. For everyone else, it's optional but worth considering once your volumes grow. A factory that can't control who walks into its loading dock is a factory where your molds, your packaging, and your product can walk out.
Environmental and health & safety audits
Environmental audits check how a factory handles its waste, emissions, energy use, and chemicals. The reference standard is usually ISO 14001, the international environmental management standard. For electronics, RoHS compliance (restriction of hazardous substances) matters at the product level and is worth checking at the factory level.
Health and safety audits overlap with both social compliance (worker safety conditions) and environmental (hazardous material handling). The standard here is ISO 45001 for occupational health and safety management.
When to book one: if you operate in an industry with real environmental footprint — textiles (dyeing and finishing), electronics (soldering, plating), plastics, or chemicals — or if your brand makes sustainability claims that need evidence. EU buyers increasingly require this documentation as part of standard supplier onboarding. For simple assembled consumer goods from a clean factory, this is usually lower priority than the QMS audit.
Technical and process audits: checking a specific capability
The audits above check systems. Technical and process audits check a specific thing: a new process, a new material, or an unproven capability the factory claims to have.
A process audit follows one production process from start to finish and verifies that reality matches the documented procedure: that operators follow the work instructions, that parameters are controlled, that deviations get flagged. The automotive industry's VDA 6.3 is the classic process-audit framework, and it's spreading to other industries because it's good at finding the gap between what a factory says it does and what it actually does.
A technical capability audit evaluates whether a factory can handle your product: the right equipment, the right engineering knowledge, and sufficient capacity at the right time. This is the audit to book when you're developing a new product and need to know whether the factory you're talking to can actually build it, as opposed to just wanting the order badly enough to say yes.
When to book one: for new product development, when switching to an unfamiliar process, or when a supplier's claimed capability (a new machine, a new material, a certification for a regulated market) is load-bearing for your order. If your question is "is this batch good?" that's a quality control inspection, not an audit.
Announced, unannounced, and who does the auditing
Beyond what an audit checks, two dimensions change what it reveals:
Announced vs. unannounced. Most audits are announced: the factory knows the date and prepares records. That's necessary for QMS and social audits, which depend on documents and interviews. Unannounced audits give a truer picture of daily reality but can only cover what doesn't require preparation. Some buyers do both: announced QMS audit for the systems, unannounced spot-checks for the reality.
First, second, and third party. A first-party audit is the factory auditing itself (internal audits are useful for them, not evidence for you). A second-party audit is commissioned by you, the buyer. This is what most importer-arranged audits are. A third-party audit is done by an independent accredited body, usually for certification. As a buyer, second-party audits give you the best combination of control over scope and independence of findings.
How to pick the right audit: a decision rule
Don't memorize the types. Match the audit to your risk. Run through these questions in order:
- Is this a new supplier or a large first order? Start with a QMS audit. It's the highest-information-per-dollar audit for most importers.
- Do you sell to consumers in the EU or US, or through brands that will ask? Add a social compliance audit (BSCI or SMETA, depending on your market).
- Do you import into the US at volume, or ship high-value/theft-prone goods? Add a security review aligned with C-TPAT criteria.
- Is your product in a regulated or high-footprint industry? Add the environmental and/or industry-specific variant (ISO 13485, IATF 16949, ISO 22000).
- Are you developing something new or relying on an unproven capability? Add a technical or process audit for that specific process.
And yes, audits can be combined. It's common to run a QMS audit with social-compliance elements added, or to book a QMS audit now and a SMETA audit later once the relationship grows. The wrong move isn't combining. It's paying for an audit type that answers a question you never asked.
Frequently asked questions
What's the difference between a factory audit and a supplier audit?
The terms overlap heavily. "Factory audit" usually means an on-site evaluation of a manufacturing facility; "supplier audit" is the broader term and can include audits of trading companies, document reviews, and non-manufacturing assessments. In practice, for China sourcing, people use them interchangeably. What matters is which type of audit you book, not which word you use.
How much does a supplier audit in China cost?
Cost depends on the audit type, the standard, the auditor's day rate, and how many days the scope requires. A one-day buyer-commissioned QMS audit is the most affordable option; multi-day certification audits to standards like SA8000 or ISO 13485 cost substantially more. Always ask for a per-man-day quote and a defined scope before booking. An audit priced without a scope is a red flag.
How long does a supplier audit take?
A standard one-day on-site audit covers a general QMS or social compliance review for a small-to-mid-size factory. Larger facilities, multiple standards, or certification audits take two to five days. Add a week or two of lead time for scheduling and the pre-audit document review.
Can one audit cover quality and social compliance together?
Yes. Combination audits are common, and many inspection firms offer a QMS review with social-compliance modules added. The tradeoff is depth: a combined one-day audit covers each area more shallowly than a dedicated audit would. For a first order, the combination is usually the right call; for an important long-term supplier, separate dedicated audits give you better information.
Should I tell the factory about the audit in advance?
For QMS and social compliance audits, yes. The auditor needs records and interviews that can't happen without preparation. Unannounced audits are a different tool for a different job: verifying that daily reality matches what the announced audit found. If a factory refuses an announced audit outright, that's your answer about the factory.
Your next step: match the audit to your risk
Write down the one question you need answered before booking anything. If it's "can they make my product consistently," book a QMS audit. If it's "are my customers going to ask about labor conditions," book a social compliance audit. If it's "is my US-bound cargo secure," look at C-TPAT-aligned security. One clear question produces one useful audit; a vague request for "an audit" produces a vague report.
If you'd like help choosing and arranging the right audit, that's exactly what CN Ally's factory audit service is for. Tell us your product, your order size, and your market at hi@cnally.com, and we'll recommend the audit type that answers your actual question, and skip the ones that don't.
Need help sourcing this kind of product?
Our team handles supplier verification, QC inspections, and logistics every day.
Get a Free Quote