What defence primes actually check in a supplier audit
Learn exactly what defence primes look for in a supplier audit, from document control to traceability and calibration, and how a small supplier can prepare without a dedicated quality department.
A supplier audit from a defence prime is not a conversation. It is a structured review of documented evidence. The auditor arrives with a checklist, a scoring matrix, and a limited window of time. They are not interested in verbal assurances or promises of future improvements. They want to see records: controlled, retrievable, and traceable. This article describes the evidence a prime or defence buyer typically expects, and explains how a small supplier can prepare without a full-time quality department.
Document Control: The First Thing They Open
Document control is almost always the first area an auditor examines. The reason is simple: if your documents are not controlled, nothing else in your quality management system can be trusted. Auditors check for the following:
A master list (or register) of controlled documents, showing document ID, title, revision level, approval authority, and effective date. Evidence that obsolete revisions are removed from points of use, or clearly marked as superseded. A defined approval process, meaning each document has a named individual (or role) responsible for review and release. Distribution records or an access-control mechanism showing that the correct revision reaches the people who need it.
Common failures include unlabelled Word files on shared drives, documents with no revision history, and procedures that staff have never seen. If you operate in a small team, a well-structured folder hierarchy with naming conventions (for example, PRO-007_Rev-C_Soldering-Procedure.pdf) can satisfy the requirement. But naming alone is not enough: you need a register that ties each document to its current revision and its approval record.
ComplyTrain's QMS module is structured around ISO 9001 requirements, including document control with revision tracking and approval workflows. If you need a starting point, see our overview at /product/qms.
Traceability: Following the Thread from Order to Delivery
Defence work almost always involves traceability requirements. The auditor will pick a finished item (or a batch) and trace it backwards. They want to see:
Purchase order or contract reference linked to the job. Incoming material certificates (mill certs, certificates of conformance) matched to the specific lot or batch. In-process inspection records tied to the production order. Final inspection or test records. Packing and shipping records, including any customer-mandated marking or labelling.
The auditor may also trace forwards: starting from a raw material certificate, can you show which finished items it ended up in? This is the recall scenario. If the answer is 'we would have to look through everything,' that is a finding.
For a small supplier, traceability does not require an enterprise resource planning system. It requires a consistent job-number convention and the discipline to attach every record (inspection, material cert, test result) to that job number. A folder per job, physical or digital, with a checklist of required records inside it, is a practical approach.
Corrective and Preventive Action: Proving You Learn from Mistakes
Auditors ask to see your corrective action log. They are checking three things. First, that nonconformities (internal rejects, customer complaints, audit findings) are recorded, not just fixed and forgotten. Second, that root cause analysis is performed, not a one-line description like 'operator error.' Third, that effectiveness is verified: after you implemented a fix, did you go back and confirm the problem did not recur?
A common audit question is: 'Show me your last three corrective actions.' If you cannot produce them, or if every root cause is listed as 'human error' with no systemic investigation, the auditor will record a finding. Defence primes view a mature corrective action process as an indicator of supplier reliability. They know that every supplier has problems. They want to see that you manage them.
Small suppliers often struggle here because corrective actions live in email threads or verbal conversations. A simple log (spreadsheet or database) with fields for description, root cause, containment action, corrective action, responsible person, target date, and verification of effectiveness will satisfy most auditors. Our standards guidance at /standards/iso-9001 outlines the corrective action requirements that map directly to what primes expect.
Competence Records: Can You Prove Your People Are Qualified?
The auditor will ask to see competence records for personnel performing critical work. This includes (but is not limited to):
Training records showing that each individual has been trained on the specific procedures relevant to their role. Qualification records for special processes (welding certifications, soldering qualifications, NDT operator certifications) where applicable. Evidence that training is refreshed at defined intervals, not a one-time event from 2017. Records of induction training, including quality policy awareness and any customer-specific requirements.
The auditor's approach is usually to pick a person on the shop floor, check which procedures apply to their work, and then look for the training record. If the record does not exist, or if the qualification has lapsed, that is a nonconformity.
For a small supplier, a training matrix (a table listing personnel against required competencies, with dates of completion and next review dates) is sufficient. The matrix must be maintained, meaning that when someone changes role, or when a procedure is revised, the training records are updated.
Calibration and Equipment Control
If your work involves measurement (and in defence it almost always does), the auditor will check your calibration records. They want to see a calibration register listing all measurement equipment, calibration intervals, calibration status, and the identity of the calibration provider. They will verify that calibration certificates are traceable to national or international standards. They may pick a gauge from the shop floor and ask you to produce its calibration record on the spot.
Out-of-calibration equipment found in use is a serious finding. If a gauge was overdue for calibration and was used to accept product during that period, the auditor may require you to recall or re-inspect that product. Label your equipment clearly (calibration sticker with due date), segregate equipment that is out of service, and keep certificates accessible.
Management Review and Internal Audit
Defence primes expect evidence that management reviews the quality system at defined intervals. Minutes or records of management review meetings should cover: audit results, customer feedback, process performance, corrective action status, and resource needs. The auditor is checking that leadership is actively engaged, not that quality is delegated entirely to one person with no authority.
Internal audits are similarly expected. You need a schedule, completed audit reports, and evidence that findings from internal audits feed into the corrective action process. If you are a five-person company, you can still conduct internal audits. The requirement is that the auditor is independent of the activity being audited (the production manager can audit purchasing, and vice versa).
How a Small Supplier Prepares Without a Quality Department
Most small suppliers in the defence supply chain do not have a dedicated quality manager. The owner, the operations lead, or a senior technician carries the quality responsibilities alongside their primary role. This is understood by auditors. What they will not accept is the absence of a system.
Preparation comes down to four steps. First, build a register of your controlled documents and verify every document has a current revision, an approval, and a distribution method. Second, pick three completed jobs and test your own traceability: can you follow each one from order to delivery with a complete set of records? Third, review your corrective action log and confirm that each entry has a root cause, a defined action, and a verification step. Fourth, confirm that competence records (training matrix, qualification certificates, calibration records) are current and retrievable within minutes.
A QMS platform structured around ISO 9001 can replace the patchwork of spreadsheets, shared drives, and filing cabinets that most small suppliers rely on. ComplyTrain provides document control, corrective action tracking, and training record management in a single system, hosted in AWS eu-central-1 (Frankfurt) with schema-per-tenant, Cognito-pool-per-tenant, and bucket-per-tenant isolation. If you want to see how it maps to the checklist above, request a walkthrough at /product/qms.
