Second party audits

We audit your suppliers, on your protocol, in your name

This page covers ASC auditing a supplier in your name as your appointed auditor. If you want the full approval and re approval programme across your supply base, see supplier and vendor audits. A second party audit is a customer auditing its supplier. ASC performs that audit as your appointed auditor, on your protocol, against your specification and contract, and reports to you. ASC is not an accredited certification body for the GFSI recognised standards and issues no certificate against them. On a customer owned scheme, where the scheme owner appoints ASC to run it, ASC audits and grants certification under that scheme, as it does for McCain farmers. On your own protocol the approval, suspension or de listing decision stays with you.

Auditing is charged hourly and a full programme is quoted on scope once ASC has seen the site. ASC will tell you before the quote if the work is smaller than you think.

One dayOn site for a customer or second party audit
Two weeksFrom closing meeting to the full written report
AnnualBaseline supplier audit cycle, tightened by risk tier
SAATCA, Exemplar Global, IRCA registered lead auditorsFoodBev SETA Accredited Provider No. 587/00337/1900Gqeberha, Johannesburg, Cape Town and Durban
Talk to ASC, or start with the documentsWhatsApp ASCRequest a quoteSupplier risk templates
Audited to ISO 19011Findings rest on evidence rather than opinion, written so a certification body auditor could read the report cold and follow it.
Led by a working lead auditorThe person auditing your site is a lead auditor registered with SAATCA, Exemplar Global and IRCA who audits to these standards for a living, so a finding is graded at the severity its consequence justifies.
You are told the truth about the dateWhere a customer deadline is not achievable, ASC says so before the quote rather than after the audit.

A second party audit is a customer auditing its own supplier. The buyer sets the requirements, appoints the auditor, and receives the report. It sits between the first party audit a supplier runs on itself and the third party audit a certification body runs to decide certification. ASC performs it as your appointed auditor, on your protocol, against your specification and your contract.

The problem it solves is ownership of risk. When a private label line is withdrawn, when a foreign body reaches a consumer, when a consignment is rejected at port, the brand on the pack carries the consequence and the certificate does not. A purchase agreement moves material, not liability or reputation.

ASC already runs this work for McCain, and publishes a McCain supplier certificate status service where a McCain Certification Number returns the certificate details, issue date, validity date and audit status. ASC audits McCain farmers on the McCain protocol and grants certification under that customer owned programme, and maintains the register behind it. That is what a managed programme looks like: the people making buying decisions see a live position on every supplier rather than hunting a shared drive for the latest certificate.

Most buyers already own the raw material for a programme, in the specification, the supply agreement, the complaint file and the withdrawal history. What is missing is a protocol that turns those into questions an auditor can test on site.

What most supplier audit programmes get wrong

Almost every provider advertises a bespoke supplier audit. What usually arrives is a generic checklist with the client’s logo on the cover, built from a scheme’s clause structure rather than from the buyer’s specification. It audits the management system a second time, which the certificate already did, and never reaches what the buyer actually buys: the moisture specification, the allergen declaration on the artwork the buyer supplied, the metal detection sensitivity in the contract.

The second weakness is scoring. A score is only useful if the same question carries the same weight at every site and every auditor applies the same evidence threshold. Where it is invented audit by audit, a category manager ranking suppliers on those numbers is ranking auditor temperament.

The third weakness is closure. Many reports stop at the finding, and the corrective action column is completed from an email saying the procedure has been updated. That closes nothing. A finding stays open until the evidence it named is on file and verified, and where the failure was in execution, a document cannot close it.

The fourth is independence, which the market avoids discussing. A consultancy that designed a supplier’s system and trained its team cannot audit that supplier objectively for the buyer, because it would be auditing its own work and defending its own fee. ASC discloses any consulting relationship in writing before the audit is scheduled, and places no individual on the audit of a system that individual built.

Key facts at a glance

A second party audit is an audit of a supplier carried out by or for the customer that buys from that supplier, as distinct from a first party audit that an organisation runs on itself and a third party audit that an accredited certification body runs to decide certification.
ASC Food Safety Consultants performs second party supplier audits from Gqeberha, formerly Port Elizabeth, in Nelson Mandela Bay in the Eastern Cape, with teams in Johannesburg and Cape Town and on site teams in Durban and across South Africa.
ASC audits McCain farmers on the McCain protocol, grants certification under that customer owned programme, and publishes the McCain supplier certificate status service where a McCain Certification Number returns the certificate record with its issue date, validity date and audit status.
ASC second party audits follow ISO 19011, the international guidelines for auditing management systems, which concentrates on internal first party audits and on the second party audits an organisation conducts on its external providers, while the requirements for bodies running third party certification audits sit in the ISO/IEC 17021 series instead.
A customer or second party audit conducted by ASC runs one day on site, on an annual cycle, with findings presented at the closing meeting and the full written report issued within two weeks.
ASC is not a certification body and never certifies a management system, so a second party audit produces a report and a decision record for the customer, never a certificate.
The GFSI Global Markets Programme is a self assessment tool aimed at small and medium enterprises, and GFSI states that it is not a food safety standard and should neither be audited against nor certified, which is why buyers of uncertified suppliers need a second party protocol of their own.
South African food premises must hold a certificate of acceptability issued by the local authority under the general hygiene requirements published as R638 of 22 June 2018 in Government Gazette 41730 under the Foodstuffs, Cosmetics and Disinfectants Act 54 of 1972, a document a supplier audit can verify but cannot issue.

When a business calls ASC in

  • You are putting your brand on product made in someone else’s factory, and it is your specification rather than the scheme’s scope that must hold.
  • Your supplier holds a GFSI recognised certificate and you still cannot show a customer that the hazards in your product are controlled at that site.
  • Nobody can say which sites were audited, when, and what is still open.
  • A complaint, a withdrawal or a rejected consignment has told you something the certificate did not.
  • Some suppliers are small or new, hold no certificate, and no third party report on them exists.

How ASC does the work

1

Building the protocol, and scoring it so a supplier base is comparable

The protocol is built from documents you already own: the product specification, the supply agreement and its quality clauses, the approved artwork, the test schedule, the complaint file and any recent withdrawal. Legal duty goes in next, including the certificate of acceptability required under the general hygiene requirements published as R638 of 22 June 2018 in Government Gazette 41730 under the Foodstuffs, Cosmetics and Disinfectants Act 54 of 1972, and the labelling requirements of R146 of 1 March 2010 where the supplier applies the label. Where you export, the destination market’s rules enter as your requirements.

Severity is then defined before the first audit, by consequence rather than by auditor mood, with the evidence that closes each grade named at the same time. Weighting follows your risk, so if allergen segregation would end your brand it carries the weight, whatever share of the day it occupies. Auditors are calibrated against each other, because otherwise a ranking measures who audited rather than who performed.

2

Risk tiering and the annual programme

Tiering comes before scheduling, on the inputs that predict harm: the nature of the product, with ready to eat and allergen bearing material treated differently from shelf stable thermally processed goods; your exposure by volume; whether a certificate exists and whether its scope covers what you buy; complaint history; and how new the relationship is.

Frequency then follows tier rather than habit. The baseline is an annual audit with the report within two weeks. Higher tiers earn more frequent attendance, an unannounced element or a targeted return audit, and lower tiers can be held with desk verification between visits. Movement rules are written in advance, because a re tiering argued after an incident convinces nobody.

3

Unannounced and semi announced audits, and what they prove

An announced audit shows the site as it presents when prepared, which is the right way to test system design, documentation and validation. A semi announced audit names a window rather than a date, and an unannounced audit gives no notice beyond arrival at the gate.

Unannounced work is strong evidence of routine state: the hygiene of the line on an ordinary day, the staffing actually deployed, whether records are written as work happens or reconstructed afterwards. It is weak evidence of system design, because the people who own the system may not be there, and it can fail entirely at a seasonal packhouse not running product. Unannounced audits verify behaviour and announced audits verify design, so a serious programme uses both, with the right of access written into the supply agreement first.

4

On site: evidence over assertion

A customer or second party audit runs one day on site: a meeting fixing scope and protocol, a traceability and mass balance exercise on a batch the auditor chooses, a walk of the line during production, verification of every control the protocol named, and a sampling of records across a period. Findings are presented to management at the closing meeting.

Every finding carries the batch or record reference, the date, the quantity examined and, where site rules permit, a photograph, so a different competent auditor working from the report alone could return and find the same thing. Traceability remains the most revealing hour of the day, because a supplier that can move from finished pack back to raw material lot, packaging lot and dispatch record, and reconcile the quantities, has a system that works.

5

Corrective action verification, closed on evidence

Removing contaminated stock is a correction. Establishing why the control failed and changing what allowed it is corrective action. A response offering only the first leaves the failure in place, and it is sent back.

Closure follows the evidence the finding named when it was raised: a document control record where it was documentary, dated training records where it was about people, a revised specification where it was about specification drift, and verification records over a period where a control must hold over time. Where the supplier proposes another route, the substitution is recorded with the conditions under which the original burden revives. Status language stays exact: open, open with a route agreed, conditionally closed pending named evidence, or closed. A return visit is warranted where the finding was critical, where the failure was in execution, or where it has recurred.

6

Independence, competence and who may audit whom

ASC audits to ISO 19011, the international guidelines for auditing management systems, which sets the principles the audit runs on: integrity, fair presentation, due professional care, independence and evidence. ASC audits are led by lead auditors registered with SAATCA, Exemplar Global and IRCA. Competence changes what a finding is worth, because a competent lead auditor grades it at the severity its consequence justifies, holds that line when a supplier pushes back, and writes it so it survives that supplier’s certification body reading it.

Conflict of interest is managed by disclosure and separation rather than by assurance. No individual audits a system that individual designed or implemented, any consulting relationship with the supplier is disclosed to you in writing before scheduling, and where it is material you decide whether ASC audits that site at all. Ask every provider whether it consults to the supplier it is about to audit for you, and ask for the answer in writing.

How ASC helps, in practice

The scenarios below are illustrative composites. They name no client and report no measured outcome.

Private label supplier with a certificate that did not cover the product

A retailer buying a chilled private label line finds the certificate scope covers ambient production at that site, not the chilled ready to eat line it buys from.

ASC builds a protocol from the retailer’s specification, artwork and complaint file, then audits that line specifically, including allergen segregation, environmental monitoring and the cold chain.

The retailer holds a report on the product it buys rather than on the site in general, graded against its own severity definitions.

Manufacturer with a supplier base nobody can see

A manufacturer buying raw materials, packaging and co packed product keeps reports in three departments, with no common scoring and no way to say who is overdue.

ASC risk tiers the base, sets frequency by tier, writes one protocol with fixed severity definitions, and schedules seasonal suppliers while they run product.

Procurement gets a single view showing tier, last audit, score, open findings by severity and next due date.

Exporter whose growers and packhouses hold no certificate

An exporter sources from smaller growers and packhouses holding no certificate, and the destination customer wants evidence that hazards are controlled at source.

ASC writes a protocol from the exporter’s specification, the destination customer’s requirements and South African hygiene law, then audits each site on it annually.

The exporter holds verified evidence per site, in one format, and can show a customer what was checked, found and closed.

What you receive

Deliverable What it contains
Supplier audit protocol The audit document itself, built from your specification, contract, complaint history and legal duties, with every question traceable to its source and each severity defined.
Risk tiering and annual programme The base tiered by product risk, exposure, certificate scope and history, with frequency per tier, movement rules, and a schedule across the year.
Audit report per supplier Scope, protocol applied, personnel interviewed, evidence examined with batch and record references, every finding with its grade, and the traceability result. Issued within two weeks of the closing meeting.
Findings and corrective action register Every finding in one register, showing the evidence named when raised, the supplier response, the verification carried out, and the exact status: open, route agreed, conditionally closed or closed.
Supplier base summary view One line per supplier for the person making buying decisions: tier, last audit, score, open findings by severity, oldest open finding and next due date.
Approval decision pack The evidence behind an approval, conditional approval, suspension or de listing recommendation, each condition stated as verifiable evidence, so your decision is defensible.

The rest of the ASC audit programme

A supplier programme rarely stands alone. These are the other services buyers combine with it.

Who this work suits

ASC runs second party supplier work across the sectors that carry South Africa’s food supply: retail private label in chilled, frozen, ambient and bakery; growers, packhouses and citrus, deciduous fruit and table grape exporters; poultry, red meat and processed meat; dairy and ready to eat chilled; spices, dry ingredients and flavour houses; snack, confectionery and beverage manufacture; quick service restaurant central kitchens; contract manufacturers and co packers producing under another brand; and packaging converters supplying food contact material. Cold chain operators are audited on the same programme, because a control that holds in the factory and fails in the vehicle has still failed.

The work is delivered from Gqeberha, formerly Port Elizabeth, in Nelson Mandela Bay in the Eastern Cape, with teams in Johannesburg and Cape Town and on site teams in Durban and across South Africa. ASC audits are led by lead auditors registered with SAATCA, Exemplar Global and IRCA. ASC Food Safety Consultants is SAATCA registered and a FoodBev SETA Accredited Provider No. 587/00337/1900, and ASC Consultants SA is a member of the Sustainability Initiative of South Africa, membership number 20240910 112270.

Where ASC stops

ASC is not an accredited certification body and never certifies a management system against FSSC 22000, ISO 22000:2018, BRCGS, IFS Food, SQF or GLOBALG.A.P. A second party audit on your own protocol produces a report to you, a graded set of findings, verified closure evidence and a recommendation. It produces no certificate against those standards and cannot be presented to anyone as certification against them. That decision belongs to an accredited certification body after its own third party audit, and you should confirm the applicable scheme version and any transition dates directly with that certification body.

Two things sit outside that line, and both are worth stating plainly. ASC issues its own rating, written report and ASC certificate after a food hygiene audit, and lists the premises on the ASC hygiene audit client database. And on a customer owned scheme, where the brand owner appoints ASC to run its supplier programme, ASC audits against that scheme and grants certification under it, which is what ASC does for McCain farmers. Neither of those is accredited third party certification against a GFSI recognised standard, and ASC does not present them as such.

The commercial decision also stops with you. ASC reports what was found and recommends approval, conditional approval, suspension or de listing against the criteria you set. The buyer owns the contract, the commercial consequence and the risk, and an auditor who takes that decision has stopped being independent of it.

First, second and third party audits compared

Buyers use these three terms interchangeably and then discover at the certification audit that they bought the wrong one. This is the difference in plain terms.

Audit type Who runs it Who the report belongs to Does it lead to a certificate Typical ASC duration
First party, internal Your own organisation, or ASC on your behalf You No Two days for ISO 22000:2018, two and a half to three days for FSSC 22000 by site size, three days for BRCGS, one day for GLOBALG.A.P.
Second party, customer or supplier The buying customer, or ASC as its appointed auditor The customer who commissioned it No One day on site, full written report within two weeks
Third party, certification An accredited certification body The certification body and the certified site Yes Set by the certification body, not by ASC

ASC works in the first two columns only. ASC Food Safety Consultants is not a certification body and takes no part in the certification decision.

Frequently asked questions

What is a second party audit?

A second party audit is an audit of a supplier carried out by or for the customer that buys from it. A first party audit is one an organisation runs on itself, and a third party audit is one an accredited certification body runs to decide certification. The second party audit is the buyer’s: the buyer’s protocol, the buyer’s specification, and a report to the buyer.

Who can audit my suppliers for me?

Your own technical staff can, or you can appoint a competent independent auditor to act for you, which is what ASC does. The auditor need not be an accredited certification body, because a second party audit does not lead to certification. What the auditor needs is demonstrable competence, independence from the supplier, and a method that produces evidence rather than opinion.

Do I need to audit suppliers if they are already certified?

A GFSI recognised certificate tells you a management system passed an audit on a known date, against a scheme scope set by the certification programme owner. It does not tell you that the scope covers the product you buy, that your specification is met, or that your complaints have been acted on. Where a supplier holds no certificate, a second party audit is often the only verified evidence that exists.

How often should suppliers be audited?

Frequency should follow risk rather than the calendar. ASC works to an annual baseline for a customer or second party audit, with the report within two weeks, then adjusts by tier. Ready to eat and allergen bearing product, single sourced material, high volume exposure or a recent critical finding all earn more frequent attendance or an unannounced element.

Can a consultant audit a supplier they helped?

No. An auditor must not audit their own work, and a consultancy that designed a supplier’s system or trained its team cannot judge it objectively for the buyer. ASC manages this by disclosure and separation: any consulting relationship is disclosed in writing before scheduling, no individual audits a system that individual built, and the buyer decides whether ASC audits that site at all.

What does a supplier audit cost?

Consulting and auditing are charged hourly, and a full supplier programme is quoted on scope once ASC has seen what is involved. What moves the number is the size of the base, the frequency each tier earns, travel to the sites, whether an unannounced element is included, and whether closure requires return visits. A customer or second party audit runs one day on site.

Put your supplier base under one protocol

Send ASC your supplier list, your product specification and your supply agreement, and ASC will show you what a protocol built from those documents would test at each site. A scoping conversation costs you nothing and usually shortens the programme.

Not ready for a quote? Use Where Do I Start, or book a virtual consultation.

News & updates 5 new
4.9/5 what do you need today?