New: ASCloud, our paperless food safety system. Full document FSMS from R3,800 a month, R638 plans from R499. See pricing

Supplier approval records: from email chaos to a supplier portal

Ask any certification auditor which clauses produce the most minor non-conformances across food manufacturing and supplier approval and monitoring is always on the list. FSSC 22000 Version 7 requires control of externally provided processes, products and services under ISO 22000:2018 clause 7.1.6 and the FSSC additional requirements. BRCGS Issue 9 section 3.5 requires a documented supplier approval and monitoring procedure with risk assessment, approval evidence and ongoing performance review. Neither is complicated. The non-conformances come from one place: the evidence lives in email, and email does not tell you when a certificate expires.

What approval evidence looks like

For each supplier of a raw material, packaging or service that affects food safety, the site needs a risk assessment of the supplier and the material, a basis for approval such as a GFSI certificate, a completed questionnaire, an audit report or a third-party test, an agreed specification for each material, and a record of ongoing monitoring such as delivery performance, complaints and the renewal of certificates. On a site with 80 suppliers and 300 materials, that is several hundred documents with dates on them.

The inbox problem

The quality coordinator requests the certificate. The supplier sends it. It is filed in a folder, or saved from the email, or left in the email. Twelve months later it expires. Nobody is reminded because the only record of the expiry date is on the certificate itself. The auditor picks that supplier. On the day, the coordinator finds the expired certificate and emails the supplier, who sends the new one, which has been valid for three months. The non-conformance is still raised, because the approval evidence was not current at the time of the audit. Multiply by the number of suppliers and this is a predictable annual event.

What a supplier portal changes

ASCloud’s supplier portal gives each approved supplier a login to a page of their own, where they upload their certificates, completed questionnaires and specifications, and update them when they change. The system reads the expiry date, reminds the supplier in the weeks before it, and alerts the quality team when a certificate lapses or a supplier does not respond. The approval record for any supplier is a single page showing the risk assessment, the current evidence, the specifications and the monitoring history. Delivery checks recorded at receiving feed the supplier’s performance score automatically.

The result is that the work of keeping evidence current moves to the people who hold the evidence, which is the supplier, and the quality team’s job becomes reviewing exceptions rather than chasing documents.

Risk assessment that stays alive

Supplier risk assessments are often done once, at approval, and then filed. Both FSSC 22000 and BRCGS expect them to be reviewed when something changes, such as a complaint, a failed delivery or a change in the material’s intended use. On ASCloud the risk assessment is linked to the monitoring record, so a run of rejected deliveries or a customer complaint traced to a material prompts a review of that supplier’s risk rating, with the review recorded.

Specifications and the pack

The second most common supplier finding is a specification that does not match what arrives, usually because the supplier changed the product and the specification was not updated. With specifications held on the portal and version-controlled, a supplier’s update creates a new version that the quality team must accept, and the receiving check on the floor shows the current version. A mismatch is caught at the door rather than at the audit.

What it costs

The supplier portal is R1,450 per site per month on top of any ASCloud plan. For a site with more than about twenty food-safety-relevant suppliers, it typically pays for itself in the time saved on certificate chasing alone, before counting the audit findings it prevents.

Let suppliers keep their own evidence current

Portal logins for suppliers, expiry reminders, automatic performance scoring and one approval page per supplier. R1,450 per site per month.

See the supplier portal

Frequently asked questions

Will my suppliers use it?

Most do, because uploading a certificate once is easier than answering the same email request from every customer. For suppliers who will not, the quality team can upload on their behalf and the reminders still work.

Does it cover service providers such as pest control and laboratories?

Yes. Any externally provided service that affects food safety is a supplier on the portal, with its own evidence requirements.

Can I set different requirements for different risk levels?

Yes. High-risk suppliers can be required to hold a GFSI certificate and a current audit, low-risk suppliers a questionnaire and a specification.

Is supplier data secure?

Each supplier sees only their own page. Access is by individual login, and data is hosted in line with POPIA. See the security page for details.

Leave a Comment

I accept the Terms and Conditions and the Privacy Policy

News & updates 4 new
4.9/5 what do you need today?