EthicalHub

Feature · Supplier certificate tracking

A food supplier approval program that
holds up at audit

What your program must contain for HACCP and GFSI audits, where it usually fails, and how to keep every supplier certificate current without a spreadsheet.

The short answer

A supplier approval program is how you decide which suppliers can sell you ingredients, packaging and services, and how you keep checking them. For HACCP and GFSI audits it usually needs an approved supplier list, a risk assessment, a defined approval method, specifications, current certificates, ongoing monitoring and a regular review. The most common failure is simple: a certificate that expired and nobody noticed.

The building blocks

What a supplier approval program must contain

Schemes word it differently, but auditors look for the same seven things.

ElementWhat it meansThe evidence an auditor asks for
Approved supplier listEvery supplier of raw materials, packaging and food safety services, with their approval status.A current list, and proof you only buy from suppliers on it.
Risk assessmentA documented rating of the risk each material or service brings, such as allergens, ready-to-eat use or fraud risk.The assessment, and how it sets the level of checks.
Approval methodHow a supplier earns approval: a certification, your own audit, or a questionnaire where the risk allows it.The method you used for each supplier, and the result.
SpecificationsAgreed specifications for what each supplier provides.A current, agreed spec for each material.
Certificates and declarationsFood safety certificates, certificates of analysis (COAs) and allergen declarations, as your program requires.A current certificate for every approved supplier.
MonitoringChecks on what arrives, such as goods-in inspection, temperature and COA checks.Receiving records that match deliveries to approved suppliers.
ReviewA set method and frequency for reviewing supplier performance and status.Review records, and action taken on poor performers.

Summarised from SQF Food Manufacturing Code Edition 9 (element 2.3.4), BRCGS Food Safety Issue 9 (section 3.5) and ISO 22000:2018 (clause 7.1.6). Check the exact clauses in your scheme and edition.

Scheme by scheme

How SQF, BRCGS and FSSC 22000 phrase it

All three are GFSI-recognised and sit at the same level. Each expects a risk-based supplier approval program.

SQF

The Approved Supplier Program (element 2.3.4) is mandatory in Edition 9. It sets minimum contents, including specifications, risk level, approval method, monitoring and review of supplier performance. Edition 10 was published in March 2026; audits against it are not expected before January 2027.

BRCGS Food Safety

Issue 9 asks for a documented risk assessment of each raw material or group, including primary packaging. Suppliers are approved by valid certification, a supplier audit, or, for low-risk suppliers with a justification, a questionnaire. Issue 10 is in development.

FSSC 22000

Built on ISO 22000, which requires criteria for evaluating, selecting, monitoring and re-evaluating suppliers, with records kept. Incoming materials must be inspected, tested or covered by a COA. Version 7 was published in May 2026, with Version 6 audits allowed until 30 April 2027.

Outside certification, FSANZ Standard 3.2.2 expects food businesses to receive food from identifiable suppliers, protected from contamination. Your retailer may add its own supplier rules. Sources: FSANZ, FSSC, Food Safety Magazine on SQF Edition 10. Confirm the edition that applies to your audit with your certifier.

Where it breaks

Common supplier findings at audit

Most programs look fine on paper. The gaps show when an auditor picks a supplier and asks for proof.

01

Expired certificates

The certificate lapsed months ago. The supplier renewed, but the new copy never reached your file.

02

Wrong scope

The certificate is current, but it doesn’t cover the site or product you actually buy.

03

No risk assessment

Suppliers are on the list, but nothing shows how their risk was rated or why checks differ.

04

Goods from unlisted suppliers

A substitute or emergency supplier was used, with no approval record.

05

Out-of-date allergen declarations

A supplier changed a recipe. Undeclared allergens were the top cause of Australian food recalls in 2025.

06

Reviews that never happen

The program says “annual review”. There are no records of one.

Recall statistic source: FSANZ, 2025 food recall statistics.

How it works in EthicalHub

Every supplier certificate current, and findable in seconds

A supplier vault linked to your Approved Supplier Program, your goods-in checks and your audit pack.

Approved supplier register

Each supplier with their COAs, HACCP certificates, allergen declarations and insurance. Bulk upload when you set up.

Expiry alerts at 60, 30 and 7 days

Escalating reminders before a certificate lapses, so you chase the renewal before the auditor does.

Version history

Know which certificate was current on the day of any delivery, not only today.

Checked at goods-in

Each incoming lot is logged against the supplier and checked against current documents before use.

Linked to your PRPs

The Approved Supplier Program is one of 18 PRP templates, with a default monthly review. Expiring certificates show on your monitoring view.

In the audit pack

Supplier certificates, with expiry dates, go into your one-click audit pack.

What EthicalHub does

  • Holds the evidence for every approved supplier
  • Warns you before certificates expire
  • Records the monthly manager sign-off that certificates were reviewed

What stays with you

  • Your supplier risk assessment and approval decisions
  • Agreeing specifications with suppliers
  • Supplier audits, where your scheme needs them

On audit day

The auditor asks for a current certificate for every approved supplier. You filter your Approved Supplier Program records and export them, with expiry dates, in under a minute.

See the audit pack
Questions

Supplier approval: common questions

What should a food supplier approval program include?
Usually an approved supplier list, a risk assessment of each material or service, a defined approval method, agreed specifications, current certificates and declarations, ongoing monitoring of deliveries, and a set method and frequency for reviewing suppliers. Check the exact requirements in your scheme and edition.
Do my suppliers need GFSI certification to be approved?
Not always. BRCGS Issue 9, for example, accepts valid certification, a supplier audit, or, for low-risk suppliers with a justification, a questionnaire. SQF expects approval to reflect the risk of what they supply and how the supplier has performed. Your retailer may set stricter rules.
What happens if a supplier certificate has expired at audit?
It is likely to be raised as a finding, because you can’t show the supplier currently meets your approval criteria. How serious it is depends on the scheme, the auditor and the risk of the material. Tracking expiry dates and chasing renewals early avoids it.
How often should approved suppliers be reviewed?
The schemes expect you to set a method and frequency, based on risk and past performance, and to keep records that the reviews happened. EthicalHub’s Approved Supplier Program template defaults to a monthly review, which you can adjust to your plan.
Is a supplier approval program a legal requirement in Australia?
FSANZ Standard 3.2.2 requires food businesses to receive food from identifiable suppliers, protected from contamination. A formal supplier approval program is mainly a requirement of HACCP-based certification schemes and retailer programs. Check your obligations with your regulator or certifier.

No more expired certificates at audit.

See your own supplier list in EthicalHub, with every certificate and expiry date in one place.

Scroll to Top