...
Split view contrasting a crowded Yiwu market trading booth with an organised plush sewing production line

Supplier Audit: What It Proves When Your Supplier Has No Factory

Джастин Aug 21, 2026

A supplier audit is a documented examination of a supplier against criteria you set in advance, producing findings supported by evidence you can point at afterwards. That is the whole of it. It is not an inspection of your goods, it is not a factory tour, and — this is the part that decides whether the money you spend on one is wasted — it is not automatically an examination of the place where your products are made.

Which matters enormously if you are buying in Yiwu. The counterparty on your proforma invoice is very often a booth in Futian District: a few square metres of display shelving, two staff, a stock room somewhere behind the market. There is no production line to walk. Every article ranking for this term at the moment is written for a corporate quality department auditing a contracted manufacturer, and it quietly assumes the auditee owns a plant. When that assumption fails, most of the standard advice fails with it.

This page covers what the audit instrument actually is, what it can and cannot establish when your supplier is a trading entity, the regulatory duty Chinese customs already places on your export agent to evaluate those suppliers, and how to tell whether you needed an audit or an inspection in the first place.

Who this is for

Importers and private-label buyers placing first orders through Chinese wholesale markets, and QA staff who have been handed a market-sourced supply chain and found their usual audit protocol does not fit it. If you are auditing a contracted manufacturer with its own ISO 9001 certificate and a fixed address, the enterprise-oriented guides on this query serve you better than this one does — this page is about the case they skip.

Key takeaways

  • A supplier audit examines a supplier and its systems against criteria you set. A product inspection examines one finished lot against a sampling plan. Buying the wrong one is the most common and most expensive mix-up on this topic.
  • Auditing your own supplier is formally a second-party audit (ISO 19011:2018). The criteria are yours to define — if you do not define them, the vendor’s template does.
  • Outside third-party certification work, nobody regulates the title “auditor”. Ask who is going and what they have audited in your product category.
  • In Yiwu the contracting party and the manufacturing party are routinely different legal persons. Fixing the audit object — trading entity, producing site, or lot — before you commission anything is the decision that determines whether the report is useful.
  • Your export agent may already owe you part of this work: under GACC Announcement 2019 No. 221, an operator exporting under market-procurement trade must maintain qualified-supplier, quality inspection-and-acceptance and traceability systems.
  • A report with no leverage behind it changes nothing. Decide who acts on a finding, and with what, before you pay for the finding.
Video explainer on how scheduled supplier audits work under an ISO 9001 quality management system

Background viewing: a management-systems training channel walks through how supplier audits are scheduled and run inside an ISO 9001 system. Useful for the vocabulary; it assumes, as most material on this subject does, that the supplier owns a factory.

What a supplier audit actually is (and what it is not)

Aisle of booths in a Yiwu wholesale market displaying hardware and tools, the trading-entity setting a supplier audit encounters first
Rows of display booths are what a supplier audit meets first in Yiwu. Nothing visible here is production.

Strip away the vendor language and an audit has three moving parts: a scope (what is being examined), criteria (the requirements you are examining it against), and evidence (what the auditor actually observed, recorded and can show you). Findings come from comparing the third to the second within the first. Change any one of them and you have a different audit, which is why “we audited them and they were fine” is not information.

The reference document for how this is done is ISO 19011:2018, Guidelines for auditing management systems. The ISO 9001 Auditing Practices Group — a joint ISO and IAF body — describes it as providing “guidelines for first, second and third-party auditing of management systems”, covering audit programme management, auditing methods and auditor competence. Its guidance, the same document notes, “is also useful for other audits such as supplier assessments”.

First, second, third party — and which one you are buying

The numbering is not jargon for its own sake; it tells you who the auditor answers to.

Party Who audits whom What it gets you as an importer
First party An organisation audits itself (internal audit) Nothing directly. A supplier’s internal audit records are evidence you can ask to see, not assurance you can rely on.
Second party A customer audits its supplier, directly or through someone acting for it This is what you are buying. Criteria are yours, scope is yours, and the report is yours.
Third party An independent certification body audits against a published standard A certificate against that standard’s scope only — never against your specification.

The APG document puts the supplier case plainly: “Auditing of suppliers is generally termed ‘2nd party’ audits.” So when a sourcing company offers you “a factory audit”, what you are commissioning is a second-party audit, and the criteria are yours to define. If you do not define them, the vendor’s template defines them for you, and you will get back a report about fire extinguishers and staff canteens when what you needed to know was whether anyone in that building has ever run your specific process.

Nobody regulates the word “auditor” here

This is the single most useful thing to know before you pay for one. Competence requirements for auditors are formally defined for third-party certification work: the APG document points to ISO/IEC 17021-1 clause 4.3 for generic competence criteria, with sector-specific criteria in complementary documents such as ISO/IEC 17021-3 for quality management systems. No equivalent gate stands between anyone and the title “auditor” on a second-party job you commission privately.

That is not an argument against buying one. It is an argument for asking two questions before you do: who specifically is going, and what have they audited in this product category before. ISO 19011 makes team competence a programme-level obligation — the APG summary lists, among the responsibilities of whoever manages an audit programme, that “the competence of an audit team matches the audit scope and objective for each audit in the audit program”. If you are the customer commissioning the audit, you are the one managing that programme, whether or not you think of it that way.

The seven principles of auditing in ISO 19011:2018 are integrity, fair presentation, due professional care, confidentiality, independence, evidence-based approach, and risk-based approach. Two of them do real work for an importer. Evidence-based approach means a finding has to rest on something verifiable — a record seen, a machine observed running, a measurement taken — not on an impression formed over tea. Independence means the auditor’s interest cannot sit on the same side as the supplier’s. Ask who pays the auditor and who introduced you to the supplier before you read a single page of findings.

The question page one skips: what exactly are you auditing?

Scope and criteria are meaningless until the object of the audit is fixed. Three quite different things get sold under the name “supplier audit”, and the difference between them is the difference between a useful report and an expensive photograph album.

Audit object What it can establish What it cannot
The trading entity
(the booth or company you contract with)
That it legally exists, what it is registered to do, who controls it, how long it has traded, what it holds in stock, how it handles a claim Anything at all about how your goods are made, by whom, or under what controls
The producing site
(the workshop or factory behind it)
Capacity, equipment, process controls, incoming-material handling, in-house testing, whether your process is actually run there That this site will be the one used for your order, unless that is written into your contract
The order itself
(a specific lot)
Whether the goods in front of the inspector conform, right now Anything about the next order — this is an inspection, not an audit at all

Read the middle column of the first row again. An audit of a trading entity is a genuinely useful thing — it is how you find out that the company you are about to wire money to was registered four months ago, or that its registered business scope does not cover what it is selling you. But it produces no evidence whatsoever about production, and a report that walks a booth and then describes “the supplier’s quality system” is describing something the auditor did not see.

The failure mode is specific and it is common: a buyer commissions “a factory audit”, the vendor visits the address on the business licence, that address is a market booth or a small office, and the report comes back full of photographs of shelving. Nothing in it is false. It just answers a question the buyer did not ask.

Notice that the object also decides what a clean result is worth to you. Clear the trading entity and you have reduced one category of risk — you are unlikely to be dealing with a shell company or a business trading outside its registered scope. That is real, and for a modest order of standard stock off the shelf it may be all the assurance the order justifies. Attach the same clean result to a custom-tooled or safety-relevant product and it covers almost nothing that can actually go wrong, because none of the risk in that order lives in the trading entity.

Same report, same conclusion, two completely different levels of protection — and the variable is not the quality of the audit. It is the object you chose before anyone left the office.

Auditing a Yiwu booth: the two-entity chain

Here is the structural fact that reorganises everything. In market-based sourcing the party you contract with and the party that manufactures are routinely different legal persons, and there is no document in the normal transaction that connects them. Your invoice names entity one. Your goods come out of entity two. Establishing that link is the actual work of a supplier audit in Yiwu, and it is why a protocol designed for a contracted manufacturer does not transfer.

Entity one is the easy half. A Chinese business licence carries an 18-character Unified Social Credit Code, structured according to national standard GB 32100-2015, and the registration behind it is publicly searchable through the National Enterprise Credit Information Publicity System at gsxt.gov.cn, operated under the market regulator. Registration date, registered capital, business scope, legal representative — all of it is checkable from your desk, and we have covered how to read those fields in detail in the guide to verifying a Yiwu supplier’s business licence. Do that first. It costs nothing and it disqualifies a meaningful number of counterparties before anyone gets on a plane.

Chinese business licence document bearing an official red company stamp, the desk-verification layer that establishes the contracting entity
The licence settles who you are contracting with. It says nothing about who manufactures.

Entity two is where the desk work stops dead.

Four things that must be observed rather than asserted

The producing entity cannot be established from documents the booth chooses to send you, because every one of those documents is selectable. A licence photograph proves a company exists somewhere; it does not prove that company made the sample in your hand. What has to be observed, in person, by someone standing in the building:

  • That the named factory runs your process. Not that it exists — that the specific operation your product needs (injection moulding at your part size, screen printing, ultrasonic welding, sewing at your fabric weight) is set up and running there.
  • That the goods in the booth and the goods in the factory are the same goods. Same tooling marks, same material, same finish. A booth carrying a wide range of unrelated categories is not the maker of most of them, and the range itself is the tell — we go through the trader-versus-manufacturer signals in the trading company vs factory guide.
  • Who controls the relationship. If your booth is one of several buyers for that factory and not a large one, its ability to make the factory fix your defect at short notice is limited, whatever it tells you.
  • That the factory knows your order exists. A surprising number of production problems are simply the factory learning about a specification the booth agreed to and never passed on.

None of those four can be settled by email, and none can be settled by a licence check. This is the point at which a remote buyer needs someone physically present, and it is the honest reason local presence is worth paying for in market sourcing specifically — the gap it closes is not language, it is the fact that entity two has no reason to talk to you at all.

Why the export paperwork will not close the gap for you

A reasonable next thought is to go around the problem: get the export documents and read the supply chain off them. It does not work, and the reason is worth knowing because it also explains why booths cannot produce documents you may be asking them for.

Most Yiwu consolidated exports move under market-procurement trade, customs supervision code 1039. Under the rules set out in General Administration of Customs Announcement 2019 No. 221, a single export declaration under this mode is capped at a value of USD 150,000, and declaration is simplified: the five highest-value commodities are listed individually in descending order of value, and everything else is merged by chapter of the Chinese customs tariff, with each chapter taking the HS code of its own highest-value item. Your fifty-SKU container is not fifty lines on that declaration. It is five lines and a handful of merged chapters.

Second, this mode is VAT-exempt without refund. Exemption rather than refund means there is no export tax-refund machinery pulling VAT invoices through the chain, which is precisely why a market booth often cannot hand you the invoice trail a conventional supplier audit would follow. The document is not being withheld. In this channel it frequently does not exist.

Got the licence, still cannot find the factory?For importers who hold a Yiwu booth’s business licence and still cannot establish who actually manufactures the goods. Our published sourcing process runs an RFP to 20+ factories, shortlists three, and visits or video-audits them against production capacity, ISO 9001 systems and social compliance, returning a written audit report.

See the audit process

The audit obligation Chinese customs already puts on your export agent

Now the part that no competing page on this query carries, and that changes the question from “should I commission an audit” to “who is already obliged to evaluate these suppliers, and can they show me the result”.

Market-procurement trade is not an informal arrangement. It is a supervised customs mode, piloted in Yiwu and since replicated — Customs Announcement 2020 No. 114 recorded the national total reaching 31 pilot markets after the fifth batch, and a district commerce portal publishing an operational guide in April 2026 puts the current figure at 39. Within that mode, Announcement 2019 No. 221 places a specific obligation on the foreign-trade operator who exports on your behalf.

Where inspection and quarantine is carried out at the place of purchase, that operator is required to establish qualified-supplier management, goods quality inspection-and-acceptance, and product traceability systems, to provide information on its business and warehousing premises, and to apply to customs at the place of purchase before export declaration. Separately, the operator bears responsibility for the authenticity and legality of the goods it exports as agent.

Read that as an importer and it is a second-party supplier-evaluation duty written into Chinese customs regulation — a qualified-supplier system, an incoming quality check, and traceability, imposed on the entity that handles your export. It sits on the agent, not on you, which is the point: someone in the chain is already required to have done a version of the work you are contemplating paying for.

What to ask your agent to show you

The regulation creates the duty. It does not hand you the file. What it does give you is a set of questions that a compliant operator can answer immediately and a casual one cannot:

  • Are you filed, and are my suppliers filed? The mode runs on platform filing for all three roles — supplier, agent and buyer — and an unfiled party cannot export under 1039 or receive the tax treatment. The Jimo district commerce portal states supplier filing at three working days and agent filing at five.
  • What do your qualified-supplier records for my booths look like? You are asking to see the output of a system the operator is required to maintain.
  • How does traceability work for my SKUs? Given that the declaration merges everything below the top five by tariff chapter, traceability lives in the platform records, not in the customs paperwork.
  • Is anything I am buying outside the mode? Goods the state prohibits or restricts from export, and goods not confirmed by the market-procurement commodity recognition system, cannot move this way at all.

What this does not cover is equally worth stating. The obligation is about supplier qualification, incoming checks and traceability within the export channel. It is not a workmanship inspection of your lot, it says nothing about whether your product meets your destination market’s safety rules, and it does not audit the producing factory to your specification. It narrows the gap. It does not close it.

Customs officer inspecting export goods at a wholesale market, the place-of-purchase supervision that market-procurement trade operates under
Market-procurement trade is supervised at the place of purchase, which is where the agent’s supplier-qualification duty bites.

Audit or inspection? Buying the wrong one is the common mistake

These two words get used interchangeably by buyers and, unhelpfully, by some vendors. They are different instruments aimed at different objects, and the money is genuinely wasted if you buy the one that does not answer your question.

  Supplier audit Product inspection
Object A supplier and its systems A finished lot of goods
Governed by Criteria you define; method guidance in ISO 19011:2018 A sampling plan — commonly ANSI/ASQ Z1.4, equivalent to ISO 2859-1
Answers “Should I work with them at all?” “Can this container ship?”
Timing Before you commit; periodically after Against a production milestone
Blind spot Says nothing about the carton on the pallet today Says nothing about the next order
Sourcing agent in Yiwu checking cartons of goods against a written checklist, the lot-level inspection that a sampling plan governs
An inspection asks whether this lot can ship. An audit asks whether this supplier should have been used at all.

A sampling plan is where the confusion usually bites. An AQL tolerance is an acceptance rule for a lot, not a promise about a supplier: it fixes how many units are drawn and how many defects of each class the lot may carry before it is rejected. On our own quality control and inspection service page the published defaults are zero tolerance for critical defects, AQL 2.5 for major and AQL 4.0 for minor, with pre-shipment inspection triggered when goods are 100% produced and 80% packed — those are our stated working defaults, not an industry law, and they are adjustable per order.

What no AQL number will ever tell you is whether the same supplier will perform the same way in November. That question belongs to an audit.

A worked sequence for a first Yiwu order

Put in order, for a buyer starting from a booth they met at the market or online, the instruments stack like this. This is a decision path, not a shopping list — most first orders do not need all of it.

  1. Desk verification, before any money moves. Licence and registration on the public registry; business scope consistent with what is being sold. Cost: nothing. If this fails, stop here.
  2. Decide your audit object. If the booth is reselling standard stock and your order is small, the trading entity is the right object and a producing-site audit is over-buying. If you are ordering anything customised, tooled, printed or safety-relevant, the producing site is the object and the trading-entity audit alone will not do.
  3. Fix criteria in writing before anyone visits. Name the process steps that matter for your product, the records you want sighted, and the questions that must be answered. Without this you receive the vendor’s template.
  4. Audit — once, before commitment. Findings should distinguish what was observed from what was stated by the supplier. If the report does not make that distinction, it is not an evidence-based report.
  5. First-article approval on your actual order. The audit cleared the supplier; the first-article inspection clears the specification, on the first units off the real tooling.
  6. Pre-shipment inspection against a sampling plan. The lot gate. Detail on stages and how AQL is applied sits in the guide to QC inspection stages and AQL.

One warning about step 4 that costs importers real money: a report on its own changes nothing. If the balance of payment has already left your account, a finding is a document describing a problem you now own. Whoever is enforcing quality on your behalf needs to be holding something — on our inspection service that leverage is explicit, with the final 70% of payment held and a “Do Not Ship” alert issued on failure. The mechanism matters more than the brand of it. Buy an audit from a party that has no leverage over the supplier and you have bought information, not protection.

Remote and video audits: what they can and cannot settle

Video auditing gets treated as the budget compromise. That framing is wrong on the standard’s own terms: ISO 19011:2018 addresses remote audit practices in its annex as distinct from on-site audits, with guidance on human and non-human interactive methods. A remote audit is a recognised method with its own rules, not a discount version of a real one.

What it does well is verify existence and scale, review documents live, and let you interview people who are visibly on site. What it does badly is everything that depends on controlling the frame. A camera goes where it is pointed. It does not wander into the material store, it does not show you the line that is idle, and it cannot confirm that the building it is walking is the building your goods will come from.

So use it where its limits do not bite: re-auditing a supplier you have already visited, checking a specific claim, or screening a shortlist before committing to travel. Our published sourcing process treats a visit and a video audit as alternatives at the shortlist stage for exactly that reason. For a first order with an unknown counterparty in a market environment, where the whole question is whether entity two is who they say it is, a camera controlled by the party you are checking is the wrong tool.

What to check before you accept an audit report

A report you cannot interrogate is a report you have to take on trust, which defeats the point of commissioning one. Read any audit report against these seven checks before you treat it as cleared. All seven are things you can verify from the document itself, without being in China.

  1. Does it name the audit object? A specific company name and a specific address, stated as what was audited. “The supplier” is not an object.
  2. Does the address match the licence? Cross-check against the registration on the public registry. A visit to an address that is not the registered one may be correct — many manufacturers register elsewhere — but it needs an explanation in the report, not silence.
  3. Does it separate observed from stated? An evidence-based finding says what the auditor saw. If the report cannot be read to tell “we watched this run” apart from “they told us they do this”, it is a record of a conversation.
  4. Is your process actually named? Not “production equipment in good condition” — the specific operation your product needs, with equipment counts.
  5. Are the photographs of your product category? Photos of an unrelated line prove the building exists and nothing more.
  6. Are non-conformities graded and assigned? A finding with no severity and no owner will not be closed.
  7. Is there a re-check? Findings without a verification date are findings that stay open.

If a report fails checks 1 or 3, the audit did not establish what you paid for it to establish, regardless of its conclusion.

Before you commission one

Three questions, answered in writing, decide whether an audit is worth commissioning at all.

  • What is the object? Trading entity, producing site, or lot. If your vendor will not put this in the scope statement, they are selling a visit, not an audit.
  • What are the criteria? Your specification and the records that evidence it — not a generic template.
  • Who acts on a finding, and with what leverage? A finding with no consequence attached is a paragraph.

On price: day rates are advertised across a wide range by third-party firms, and none of it is published as a verifiable market rate — our own service page states its inspection figure explicitly as an example rather than a quotation. Fix the scope, the object and the deliverable first; a rate is not comparable between two vendors until those three match. Where a number matters to your decision, ask for it in writing against a defined scope rather than reading it off a marketing page.

The risk you are actually carrying

The failure this article exists to prevent is not a supplier who lies to you. It is a buyer who commissions the right-sounding service against the wrong object, receives a clean report, and treats it as coverage it was never capable of providing.

A clean audit of a trading entity tells you the company is real and registered to do what it says. Pair that with an order for a customised, tooled or safety-relevant product and you are exposed on everything the report did not look at: who makes it, on what equipment, to whose specification, with what incoming-material control. The document in your inbox will not warn you about this. It is answering the question that was asked.

So fix the object, write the criteria, and know who is holding leverage when a finding lands. If your supply chain runs through a Chinese wholesale market, add one more: assume the contracting party and the manufacturing party are two entities until someone standing in the building has shown you otherwise. That assumption is uncomfortable, it is occasionally unfair to a good supplier, and it is a great deal cheaper than the alternative.

Frequently asked questions

What is a supplier audit?

A supplier audit is a documented examination of a supplier against criteria you define in advance, with findings supported by evidence the auditor actually observed. Auditing your own supplier is formally a second-party audit under ISO 19011:2018.

What is the difference between a supplier audit and a product inspection?

An audit examines a supplier and its systems: should you work with them at all? An inspection examines one finished lot against a sampling plan such as ANSI/ASQ Z1.4: can this shipment go? An audit says nothing about today’s cartons.

Can you audit a Yiwu market booth?

You can audit the booth as a trading entity — its registration, business scope, stock handling and claims process. What that cannot establish is anything about production, because the goods are usually made by a separate legal person at a separate site.

Is a second-party audit the same as a third-party certification audit?

No. A second-party audit is run for you against your criteria. A third-party audit is run by a certification body against a published standard, and its certificate covers that standard’s scope, never your specification.

Do I need a factory audit if my supplier already has ISO 9001?

A certificate shows a management system was assessed against ISO 9001 within a defined scope. It does not confirm the certified site will make your order or that your specification is controlled there. Check the certificate’s scope and issuing body first.

Does Chinese regulation require anyone to vet market suppliers?

Under GACC Announcement 2019 No. 221, an operator exporting under market-procurement trade (code 1039) must establish qualified-supplier, quality inspection-and-acceptance and traceability systems where inspection and quarantine is done at the place of purchase.

Is a video audit good enough?

ISO 19011:2018 treats remote auditing as a recognised method in its annex, so it is legitimate. Its limit is the frame: a camera goes where it is pointed. Weak for a first order with an unknown counterparty, reasonable for re-checks.

What does a supplier audit cost?

Day rates are advertised across a wide range and no authoritative source publishes a verifiable market rate. Fix the audit object, the criteria and the deliverable first, then ask vendors to quote against that scope — rates are not comparable until scopes match.

Вам также может понравиться