That day, when the CPK report came out, the whole room fell silent for three seconds
I still remember several years ago, the yield of one of our factory's main product lines suddenly plummeted catastrophically. Back then, I was still new and only knew that everyone's faces looked grim, and then the production line stopped. Later, a veteran QA staff member threw out the supplier's CPK report, which conspicuously showed 1.08, and the DPMO had directly skyrocketed to 6210. The conference room instantly fell silent; you could hear a pin drop. The section chief just said, "How long has it been since anyone 'cared for' this supplier?"
Where the Problem Lies
Frankly, many times we treat "acceptance inspection" as the entirety of "quality management," which is a major misconception. Acceptance inspection can only catch "defects that have already occurred," but it cannot prevent "problems that have not yet happened." At this point, a supplier audit program becomes critically important. Simply put, it's about us proactively "confirming" whether the supplier's processes follow SOPs and if they have the capability to continuously and stably provide qualified materials/parts. This is much like a physical examination; you don't wait until you're sick to see a doctor, but rather have regular check-ups to ensure you remain healthy.
How It's Done in Practice
Supplier audit programs are typically divided into three types of audit methods; let's discuss them one by one:
1. First-Party Audit:
This is an audit conducted by the supplier "themselves" on their own operations. They will have internal QA or independent departments that regularly check their production processes, quality documentation, instrument calibration, and so on. Honestly, it's like looking in a mirror yourself; while you might see some issues, there's an unavoidable tendency to gloss things over, as it's your own people involved. However, a supplier committed to good management will certainly do this thoroughly.
2. Second-Party Audit:
This is when "we" audit "the supplier." Typically, an audit team consisting of our purchasing, QA, or relevant engineers will go directly to the supplier's site. We will audit items such as contractual requirements, product specifications, process capability (e.g., whether they can consistently achieve Cpk 1.67 or higher), and environmental safety. We will even directly review their production records and sample actual process parameters. For instance, our supplier with the CPK of 1.08 back then started to "let loose" precisely because we hadn't "cared for" them for too long.
3. Third-Party Audit:
This type of audit is even more independent, conducted by an "independent third-party organization." The most common examples are ISO certifications, such as ISO 9001 and IATF 16949 (for the automotive sector). These organizations dispatch professional auditors to assess the supplier's management system according to international standards. This is like finding an impartial third party to write your health check report; it has the highest credibility but is also the most expensive. Typically, we require suppliers to have at least basic ISO certification; this serves as a threshold.
The Most Common Pitfall
The biggest pitfall I've encountered is that some suppliers, to cope with second-party audits, will create "two sets of documents." One set consists of "perfect" documents for us to see, while the other is the "casual" set they actually use. Once when I went for an audit, their documents showed a certain process parameter as 250°C, but when I went to the production line, I found the temperature controller gauge was only 220°C! After exposing them on the spot, the supplier's face turned green. Therefore, during an audit, you must observe more, ask more questions, and move around, not just rely on written documentation.
One Thing You Can Do Today
Check the last second-party audit report for your key suppliers.