Supplier Audit Requirements

Supplier Audit Requirements

Quality & Inspection Standards

PRODUCTS CENTER

Get Custom Quote

PRODUCTS CENTER

Supported formats: PDF, DWG, Gerber, Excel (Max 50MB)
Submit
GJB9001C Supplier Audit Second-Party Audit Implementation Guide

Supplier Audit Requirements Under GJB9001C

📅 Published: July 28, 2026  |  ⏱️ 18 min read  |  🏷️ #GJB9001C #SupplierAudit #SecondPartyAudit #ThirdPartyAudit #PCBManufacturing #ImplementationGuide

Supplier audit requirements under GJB9001C establish the framework for evaluating, selecting, monitoring, and re-evaluating external providers throughout the product lifecycle. Clause 8.4.1 requires organizations to "determine and implement criteria for the evaluation, selection, performance monitoring, and re-evaluation of external providers, based on their ability to provide processes, products, and services in accordance with requirements."Supplier audits — whether internal, second-party, or third-party — are the mechanism through which organizations verify that external providers meet these criteria and continue to deliver conforming products and services.

For PCB manufacturers serving military and aerospace programs, supplier audits are a critical control point. External providers of laminates, components, fabrication services, and assembly services must be systematically evaluated to ensure they can consistently meet GJB9001C requirements, military specifications, and program-specific quality standards. This guide provides a complete implementation roadmap covering the standard requirements, audit types, the supplier audit process, PCB-specific audit criteria, and audit preparation.

Engineering Summary

  • GJB9001C Clause 8.4.1 requires organizations to determine and implement criteria for evaluation, selection, performance monitoring, and re-evaluation of external providers.
  • Three audit types apply to supplier management: internal audits (first-party), customer audits (second-party), and certification audits (third-party).
  • Supplier evaluation criteria must consider quality system certification, product capability, delivery performance, financial stability, and risk factors.
  • Organizations must retain documented information of all evaluation, selection, monitoring, and re-evaluation activities.
  • Customers must be invited to participate in the evaluation and selection of external providers of interest to them.
  • Risk assessment is mandatory when selecting and evaluating external providers — organizations must effectively identify and control risks.
  • For PCB manufacturers, supplier audits cover laminate suppliers, fabrication houses, assembly subcontractors, and component distributors.

1. What Auditors Check — A Quick Overview

Audit Focus What External Auditors Verify Expected Evidence
Evaluation Criteria Are supplier evaluation, selection, monitoring, and re-evaluation criteria established and documented? Supplier evaluation procedure, criteria documentation
Supplier Evaluation Are suppliers evaluated against defined criteria before approval? Evaluation records, survey results, audit reports
Approved Supplier List Is an Approved Supplier List maintained and used as the basis for procurement? Approved Supplier List, scope of supply documentation
Performance Monitoring Is supplier performance monitored and re-evaluated periodically? Performance data, re-evaluation records, ranking results
Customer Involvement Are customers invited to participate in supplier evaluation and selection? Invitation records, customer participation records
Risk Assessment Are risks identified and controlled in supplier selection and evaluation? Risk assessment records, risk mitigation plans
Documented Information Are records of evaluation, monitoring, and re-evaluation activities retained? Documented information records, approval records, off-list procurement approvals

KEY INSIGHT:

Supplier audit and evaluation is one of the most frequently audited areas in GJB9001C. Auditors will verify that every external provider is properly evaluated, selected, monitored, and re-evaluated, and that the Approved Supplier List is current and used as the basis for all procurement decisions.

2. Standard Requirements for Supplier Audit

2.1 GJB9001C Clause 8.4.1 — General Requirements

GJB9001C-2017 Clause 8.4.1 establishes the foundational requirement for supplier evaluation and audit:

"The organization shall ensure that externally provided processes, products, and services conform to requirements. The organization shall determine the controls to be applied to externally provided processes, products, and services when external providers' products and services will form part of the organization's own products and services."

The organization shall:

  • Determine and implement criteria for the evaluation, selection, performance monitoring, and re-evaluation of external providers, based on their ability to provide processes, products, and services in accordance with requirements
  • Retain documented information of these activities and any necessary actions arising from evaluations
  • Compile an Approved Supplier List based on evaluation results, which serves as the basis for selecting external providers and for procurement
  • When selecting external providers outside the Approved Supplier List, follow approval procedures
  • Require external providers to implement appropriate controls over their direct and sub-tier external providers
  • Invite customers to participate in the evaluation and selection of external providers of interest to them
  • Ensure effective identification and control of risks when selecting and evaluating external providers

The Approved Supplier List shall specify the scope of processes, products, and services provided by the external provider.

2.2 Clause 8.4.2 — Control Types and Extent

Clause 8.4.2 requires organizations to ensure that externally provided processes, products, and services do not adversely affect the organization's ability to consistently deliver conforming products and services.The organization shall:

  • Ensure that externally provided processes remain within the control of its quality management system
  • Define the controls to be applied to external providers and their outputs
  • Consider the potential impact of externally provided processes, products, and services on the organization's ability to meet customer and regulatory requirements
  • Consider the effectiveness of controls applied by external providers
  • Determine necessary verification or other activities to ensure that externally provided processes, products, and services meet requirements
  • Define verification requirements, methods, and acceptance criteria, and implement verification with retained records
  • When delegating verification to external providers, define requirements and retain delegation and verification records

2.3 Clause 8.4.3 — Information for External Providers

Clause 8.4.3 requires organizations to communicate to external providers the following requirements:

  • The processes, products, and services to be provided
  • Approval requirements for: products and services; methods, processes, and equipment; and release of products and services
  • Capability requirements, including required personnel qualifications
  • Interaction between external providers and the organization
  • Controls and monitoring of external provider performance used by the organization
  • Verification or validation activities that the organization or its customers intend to perform at the external provider's site
  • Functional and performance requirements, quality assurance requirements, and support requirements for products
  • Requirement for external providers to report technical quality issues and resolution results
  • Requirement for external providers to notify the organization of technical state changes, production line or process changes, or equipment changes
  • Requirements for control of documented information that external providers produce and maintain

2.4 Documented Information Requirements

Organizations must retain documented information of supplier audit and evaluation activities, including:

  • Evaluation, selection, performance monitoring, and re-evaluation criteria
  • Approved Supplier List
  • Approval records for off-list supplier selection
  • Risk identification and control records related to external providers
  • Evaluation results and any necessary actions arising from evaluations

3. Supplier Audit Types — Internal, Second-Party, and Third-Party

Supplier audits fall into three primary categories, each with distinct objectives, auditors, and outcomes.

3.1 Internal Audit (First-Party Audit)

Internal audits are conducted by the organization itself or its authorized internal team to evaluate the conformity and effectiveness of its own quality management system.

  • Who conducts: The organization's own internal audit team or hired internal auditors
  • Purpose: Self-assessment to check whether the system meets standards and internal requirements; identify issues and drive continuous improvement; prepare for external audits
  • Characteristics: Flexible frequency (typically 1-2 times per year); auditors require internal training or certification (e.g., internal auditor certificate); results are used for internal management and not publicly disclosed
  • PCB Example: A PCB manufacturer conducts an internal audit of its procurement and supplier management processes, reviewing supplier evaluation records, Approved Supplier List maintenance, and performance monitoring documentation

3.2 Second-Party Audit (Customer Audit)

Second-party audits are conducted by customers, partners, or their representatives to assess whether a supplier's quality management system meets their specific requirements.

  • Who conducts: The customer (typically a military unit or large OEM) or their representatives
  • Purpose: Evaluate whether the supplier is reliable and can meet the customer's specific requirements; build trust and reduce supply chain risk
  • Characteristics: Audit standards are set by the customer (may exceed general standards); results directly affect partnership status (order allocation, supplier ranking)
  • PCB Example: A military prime contractor conducts a second-party audit of a PCB fabrication house, reviewing GJB9001C implementation, process control, traceability, and security controls
  • Customer involvement requirement: Organizations shall invite customers to participate in the evaluation and selection of external providers of interest to them. The customer is involved throughout the supplier lifecycle — from initial evaluation and selection through performance monitoring and re-evaluation — not just at final product acceptance.

3.3 Third-Party Audit (Certification Audit)

Third-party audits are conducted by independent, accredited certification bodies to verify that an organization's quality management system conforms to applicable military, national, or international standards.

  • Who conducts: Independent, accredited third-party certification bodies (e.g., China National Accreditation Service for Conformity Assessment, certification centers)
  • Purpose: Determine whether the quality management system meets GJB9001C or other standards; issue certification to enhance market competitiveness
  • Characteristics: Auditors must hold national registration qualifications (e.g., CCAA auditors); process is rigorous and standardized (initial audit → surveillance audit → re-certification); results are publicly available
  • PCB Example: A PCB manufacturer undergoes third-party certification audit for GJB9001C-2017 to qualify as a defense supplier

3.4 Special Audit Types

In addition to the three primary types, organizations may encounter special audit types:

  • Combined Audit: Simultaneous audit of multiple management systems (e.g., quality + environment + occupational health + military standards)
  • Joint Audit: Multiple audit parties (e.g., customer and certification body) conduct the audit together
  • Special-Purpose Audit: Focused audit targeting specific processes, issues, or changes (e.g., new processes, product recalls)

4. Supplier Audit Process — The Eight Steps

The supplier audit process ensures that external providers are systematically evaluated, selected, and monitored based on their ability to meet requirements.

Step Activity PCB Supplier Example
1 Plan the Audit — Define audit scope, objectives, criteria, schedule, resources, and team. Identify required participants and notify the supplier. Plan a second-party audit of a PCB fabrication house. Define scope: quality management system, process control, material traceability, and test capability. Schedule audit and notify supplier.
2 Define Evaluation Criteria — Establish criteria for evaluating the supplier based on their ability to meet requirements. Criteria should consider quality system certification, product capability, delivery performance, financial stability, and risk factors. Define criteria: GJB9001C certification; technology capability (layer count, impedance); production capacity; quality history (DPPM, yield); delivery performance; technical support capability.
3 Conduct Pre-Audit Review — Review supplier documentation including quality manual, procedures, certifications, and previous audit results. Conduct risk assessment. Review GJB9001C certificate, quality manual, process control documentation, and previous audit findings. Assess supply chain, financial, and technical risks.
4 Conduct On-Site Audit — Perform on-site audit of the supplier's facility. Assess quality management system, manufacturing capability, process control, material control, test/inspection capability, and security controls. Use standardized audit checklists. Conduct on-site audit of PCB fabrication facility; review quality system and process controls; verify equipment capability; assess material traceability and test records; use audit checklist.
5 Document Findings — Record all audit findings including nonconformances, observations, and opportunities for improvement. Classify nonconformances by severity. Initiate nonconformance reports as needed. Document findings: impedance control records incomplete (major nonconformance); equipment calibration records current (conformance); recommend improvement for material storage.
6 Report and Communicate — Prepare formal audit report summarizing audit scope, activities, findings, nonconformances, and corrective actions. Communicate results to supplier and relevant stakeholders. Issue audit report to PCB fabrication supplier; communicate findings; require corrective action plan for nonconformances.
7 Verify Corrective Actions — Review and verify supplier corrective actions. Conduct follow-up audit or review if required. Close out nonconformances when corrective actions are verified effective. Review PCB supplier's corrective action plan; verify implementation through follow-up review; close out nonconformance when verified.
8 Approve and Update AVL — Based on audit results, approve the supplier and add to the Approved Supplier List (or maintain/remove status). Define the scope of supply and classification. Retain documented information of all activities. Approve PCB fabrication supplier; add to AVL with defined scope; retain audit records and evaluation documentation.

CRITICAL RULE:

Organizations must retain documented information of all supplier evaluation, selection, monitoring, and re-evaluation activities. The Approved Supplier List must be based on evaluation results and serve as the basis for all procurement decisions.

5. PCB Supplier Audit Scenarios — Practical Examples

5.1 PCB Fabrication House Audit — Second-Party

Item Description
Audit Type Second-party audit (customer audit) of a PCB fabrication house
Scope Quality management system, manufacturing capability, process control, material traceability, test/inspection capability, and change management
Evaluation Criteria GJB9001C certification; technology capability (layer count, impedance, backdrill); production capacity; quality history (DPPM, yield); delivery performance; technical support; customer references
Verification Activities On-site audit of fabrication facility; review of quality system and process controls; equipment capability assessment; review of material certifications and traceability records; First Article Inspection (FAI) records review
Documentation Audit plan, audit checklist, audit report, nonconformance reports, corrective action records, Approved Supplier List entry

5.2 PCBA Assembly Supplier Audit — Second-Party

Item Description
Audit Type Second-party audit of a PCBA assembly subcontractor
Scope Quality management system, assembly capability (SMT, through-hole, BGA/CSP), process control, ESD control, material control, test/inspection capability
Evaluation Criteria GJB9001C certification; SMT capability (0201, BGA, CSP, micro-BGA); X-ray and AOI inspection; production capacity; quality history (DPPM, yield); delivery performance; counterfeit prevention program (AS5553)
Verification Activities On-site audit of assembly facility; review of process controls (soldering profile, cleaning, inspection); ESD control verification; equipment capability assessment; review of counterfeit prevention program
Documentation Audit plan, audit checklist, audit report, nonconformance reports, corrective action records, AVL entry

5.3 Supplier Evaluation Methods

Organizations may use multiple methods to evaluate suppliers:

  • Sample inspection and trial: Evaluate product samples from the supplier
  • Quality performance history: Review historical quality data and performance metrics
  • On-site or written survey: Conduct facility assessments or send questionnaires
  • Customer satisfaction survey: Gather feedback from the supplier's other customers
  • Second-party audit: Conduct on-site quality management system audit
  • Supplier reputation assessment: Evaluate social reputation and compliance history

6. Key Control Points in PCB Supplier Audit

6.1 Evaluation Criteria Development

  • Establish criteria for evaluation, selection, performance monitoring, and re-evaluation of external providers
  • Consider equipment qualification, quality management system certification, product capability, delivery performance, financial stability, and risk factors
  • Ensure criteria are based on the external provider's ability to provide processes, products, and services in accordance with requirements
  • Document criteria and retain as documented information

6.2 Approved Supplier List Management

  • Compile an Approved Supplier List based on evaluation results
  • Specify the scope of processes, products, and services for each supplier
  • Use the Approved Supplier List as the basis for selecting external providers and for procurement
  • Follow approval procedures when selecting suppliers outside the Approved Supplier List
  • Implement dynamic management of suppliers and promptly revise the Approved Supplier List

6.3 Performance Monitoring and Re-evaluation

  • Monitor supplier performance continuously using defined metrics
  • Key metrics: quality (DPPM, yield, customer returns), delivery (on-time delivery rate), cost, and service
  • Conduct periodic re-evaluation based on performance data
  • Communicate with suppliers identified for improvement and conduct follow-up management
  • Remove non-performing suppliers from the Approved Supplier List

6.4 Customer Involvement

  • Invite customers to participate in the evaluation and selection of external providers of interest to them
  • Document customer involvement and feedback
  • Obtain customer approval for critical supplier selections when required
  • Provide customers with access to supplier evaluation results when requested

6.5 Risk Management

  • Identify and control risks when selecting and evaluating external providers
  • Consider technical, schedule, and economic risks
  • Assess supply chain risks including single-source dependency, geopolitical factors, and counterfeit risk
  • Implement risk mitigation measures for high-risk suppliers
  • Document risk assessment results and mitigation plans

6.6 Sub-tier Supplier Control

  • Require external providers to implement appropriate controls over their direct and sub-tier external providers
  • Flow down applicable quality and security requirements to sub-tier suppliers
  • Verify that sub-tier suppliers meet required qualifications
  • Include sub-tier control requirements in supplier contracts and quality agreements

7. Supplier Audit Checklist — Key Areas to Verify

Audit Area Verification Points
Quality Management System GJB9001C certification status and scope; quality manual and procedures; management review records; internal audit records; corrective action system; customer complaint handling
Manufacturing Capability Process capability documentation; equipment list and maintenance records; production capacity; technology capabilities (layer count, component types, assembly technologies)
Process Control Process control documentation; SPC implementation; process monitoring and control records; equipment calibration records; environmental controls
Material Control Raw material/component supplier qualification; incoming inspection records; material traceability (lot-level); shelf-life management; counterfeit prevention program
Testing and Inspection Test capabilities (electrical, impedance, functional); inspection capabilities (AOI, X-ray, visual); test equipment calibration; test method validation; inspection records
Change Management Process change control procedure; material substitution approval procedure; PCN procedure; customer notification process; change records
Traceability Lot-level traceability from material receipt through shipment; serial number tracking (if required); traceability records retention; defective product identification and control
Security Security control program; classified information handling procedures; physical security controls; personnel security clearances (if applicable)

8. Audit Preparation Checklist for PCB Manufacturers

# Check Item Clause Status Notes
Evaluation Criteria
1 Supplier evaluation, selection, monitoring, and re-evaluation criteria are established and documented 8.4.1  
2 Criteria cover PCB/PCBA-specific requirements (technology, quality, delivery) 8.4.1  
Supplier Evaluation
3 Supplier evaluation records are maintained 8.4.1  
4 On-site audits are conducted for Class A suppliers 8.4.1  
5 Supplier classification is determined and documented 8.4.2  
Approved Supplier List
6 Approved Supplier List is maintained and current 8.4.1  
7 Approved Supplier List specifies the scope of supply for each supplier 8.4.1  
8 Off-list procurement approvals are documented 8.4.1  
Performance Monitoring
9 Supplier performance is monitored and records are maintained 8.4.1  
10 Supplier re-evaluation is conducted periodically 8.4.1  
Risk and Customer Involvement
11 Risk assessment is conducted for supplier selection and evaluation 8.4.1  
12 Customers are invited to participate in supplier evaluation and selection 8.4.1  
Documented Information
13 All supplier-related documented information is retained 8.4.1  
14 Audit records, evaluation records, and approval records are maintained 8.4.1  

9. Common Audit Findings and How to Avoid Them

Finding Why It Happens How to Avoid
"No supplier evaluation criteria established" Criteria not documented or not implemented Document and implement supplier evaluation criteria for all supplier types
"No Approved Supplier List" Approved Supplier List not maintained or not used Maintain current Approved Supplier List; use as basis for all procurement decisions
"Supplier evaluation records not maintained" Evaluations conducted but not documented Require documented evaluation records for all suppliers; retain as documented information
"No supplier performance monitoring" Suppliers not monitored after initial approval Implement performance monitoring for all suppliers; conduct periodic re-evaluation
"Customer not involved in supplier evaluation" Customers not invited to participate in supplier evaluation Invite customers to participate in evaluation of suppliers of interest; document involvement
"No risk assessment in supplier selection" Risks not identified or controlled in supplier selection Conduct risk assessment for all supplier selections; document risk mitigation plans
"Sub-tier suppliers not controlled" Requirements not flowed down to sub-tier suppliers Require suppliers to control their sub-tier suppliers; flow down applicable requirements
"Procurement from unapproved suppliers" Suppliers not on Approved Supplier List used without approval Follow formal approval procedures for off-list procurement; document approvals

10. Frequently Asked Questions

What is a supplier audit under GJB9001C?

A supplier audit is a systematic evaluation of an external provider's ability to provide conforming processes, products, and services. Under GJB9001C, supplier audits are part of the evaluation, selection, performance monitoring, and re-evaluation requirements of Clause 8.4.1.

What are the three types of supplier audits?

The three types are: internal audits (first-party — conducted by the organization itself), second-party audits (customer audits — conducted by customers or their representatives), and third-party audits (certification audits — conducted by independent certification bodies).

What is a second-party audit?

A second-party audit is conducted by a customer, partner, or their representative to evaluate whether a supplier's quality management system meets their specific requirements. Results directly affect partnership status, order allocation, and supplier ranking.

What must be included in supplier evaluation criteria?

Evaluation criteria should consider: quality management system certification (GJB9001C), product capability, delivery performance, financial stability, compliance with laws and regulations, social reputation, and customer satisfaction.

What is the Approved Supplier List?

The Approved Supplier List is a documented list of external providers that have been evaluated and approved based on their ability to provide conforming processes, products, and services. It serves as the basis for selecting external providers and for procurement.

Is customer involvement required in supplier evaluation?

Yes. Organizations shall invite customers to participate in the evaluation and selection of external providers of interest to them.

What documented information must be retained for supplier audits?

Organizations must retain: evaluation criteria, evaluation records, the Approved Supplier List, off-list procurement approval records, risk assessment records, and all performance monitoring and re-evaluation records.

What happens when a supplier underperforms?

Underperforming suppliers should be communicated with and provided improvement guidance. If performance does not improve, the supplier should be removed from the Approved Supplier List and procurement stopped.

PCB and PCBA Manufacturing for Military and Aerospace Programs

UltroNiu Electronics Group provides PCB and PCBA manufacturing services with GJB9001C-compliant supplier audit and qualification programs. Contact our engineering team for program-specific supplier audit and supply chain management requirements.

Request Engineering Review

References: GJB9001C-2017 Clauses 8.4, 8.4.1, 8.4.2, 8.4.3 (Central Military Commission Equipment Development Department). Supplier audit requirements sourced from GJB9001C-2017 Clause 8.4.1. Audit type definitions sourced from GJB9001C implementation guidance and industry practice. Supplier evaluation criteria sourced from GJB9001C-2017 Clause 8.4.1 and military procurement regulations. Approved Supplier List and documented information requirements sourced from GJB9001C-2017 Clause 8.4.1. Risk assessment requirements sourced from GJB9001C-2017 Clauses 8.1 and 8.4.1. PCB-specific supplier audit practices based on industry best practices for military and aerospace PCB manufacturing. Courtesy of UltroNiu Engineering Knowledge Center.

Get Custom Quote

PRODUCTS CENTER

Supported formats: PDF, DWG, Gerber, Excel (Max 50MB)
Submit