Food Supplier Approval and Verification: A Risk-Based Guide for Importers and Food Companies
Supplier approval is not just a purchasing formality. It is a food safety, regulatory, fraud-prevention and business-risk decision. When a supplier fails, the problem may become your recall, your border detention, your customer complaint, your allergen incident, your outbreak risk, your brand crisis, and your explanation to regulators and customers.
Supplier approval is not paperwork. It is risk control.
Many companies treat supplier approval as a questionnaire, a certificate, a specification, a COA, a price negotiation and a signature in an approved supplier list.
That is not enough.
A strong supplier approval program should answer a more important question:
"Can this supplier consistently provide safe, authentic, compliant and correctly represented food — and can we prove that with evidence?"
For importers and food companies, supplier approval is not only a purchasing decision. It is a food safety decision, a regulatory decision, a fraud-prevention decision and a business-risk decision.
"A supplier hazard can become your food safety incident. A supplier's undeclared allergen can become your recall. A supplier's adulteration can become your fraud crisis." — Fernando A Lopes
On this page
Jump directly to any topic.
- What is supplier approval?
- What is supplier verification?
- Approval vs verification
- FDA perspective
- What is FSVP?
- Is a certificate enough?
- Is a COA enough?
- Measurement uncertainty
- Food fraud & supplier risk
- Example: OJ & tropical
- Risk-based, not convenience
- When is an onsite audit needed?
- Supplier approval file
- Common approval failures
- FDA-style questions
- Brazil supplier context
- Five key questions
What is food supplier approval?
Food supplier approval is the formal decision that a supplier is acceptable to provide a food, ingredient, packaging material or service to your company.
A meaningful approval decision should not be based only on price, availability, certificates or commercial history. A strong supplier approval decision should consider the food supplied, the hazards associated with it, who controls those hazards, supplier food safety maturity, regulatory history, audit results, laboratory data, COA reliability, fraud vulnerability, allergen risks, corrective action history and transparency.
Weak approval logic
"Because we have bought from them for years."
Strong approval logic
"Because we identified the relevant hazards, determined who controls them, selected verification activities based on risk, reviewed evidence and documented the approval decision."
What is supplier verification?
Supplier verification is the ongoing process of confirming that an approved supplier continues to control the relevant food safety, regulatory and authenticity risks.
Approval is the decision to use the supplier. Verification is how the company proves that the decision remains valid over time.
Verification activities may include:
- Onsite audits
- Sampling and testing
- Review of supplier food safety records
- Review of COAs
- Review of corrective actions
- Review of regulatory history
- Third-party audit review
- Supplier performance monitoring
- Complaint trend review
- Import alert or warning letter screening
- Periodic reassessment
Supplier approval vs supplier verification
Supplier approval
"Should we use this supplier?"
Supplier verification
"Do we have evidence that this supplier continues to control the relevant risks?"
A supplier is not low risk forever just because it was approved in the past. Supplier risk can change because of new products, new allergens, new manufacturing sites, raw material changes, process changes, ownership changes, recurring deviations, failed COAs, customer complaints, recalls, regulatory actions, import refusals, fraud signals or weak communication.
What does FDA expect from supplier verification?
From the FDA perspective, supplier approval and verification should be connected to hazards, controls and evidence — not just certificates or questionnaires.
Under FDA's FSMA and FSVP logic, companies should identify known or reasonably foreseeable hazards, determine who controls those hazards, and select appropriate supplier verification activities based on risk.
The supplier file should tell a clear story:
- This is the food.
- This is the hazard.
- This is who controls it.
- This is how we verified control.
- This is what happens when control fails.
- This is why the supplier remains acceptable.
Examples:
- Salmonella in spices controlled by a supplier's validated treatment
- Aflatoxin in peanuts controlled by supplier sourcing, sorting and testing
- Pesticide residues in fruit controlled by agricultural practices and monitoring
- Undeclared allergen risk controlled by formulation, segregation and label controls
- Environmental pathogen risk in ready-to-eat ingredients controlled by sanitation and environmental monitoring
- Authenticity risk controlled by traceability, testing and fraud-prevention controls
What is FSVP and how does it affect foreign supplier verification?
FSVP stands for Foreign Supplier Verification Program. It requires U.S. importers, where applicable, to verify that foreign suppliers produce food in a way that meets applicable U.S. food safety standards.
Even when FSVP is legally the importer's responsibility, the foreign supplier must provide much of the evidence the importer needs. A supplier that cannot provide clear, organized and technically meaningful evidence becomes harder to approve, harder to defend and harder to keep.
A supplier with clear hazard analysis, reliable records, meaningful COAs, audit evidence, corrective action history and transparent communication is easier for a serious importer to trust — foreign supplier readiness becomes a competitive advantage.
Is a food safety certificate enough to approve a supplier?
No. A certificate can support supplier approval, but it should not replace a risk-based supplier evaluation.
A GFSI certificate, organic certificate, HACCP certificate or customer audit report may show that the supplier has a management system or passed a specific assessment. But serious food safety teams still need to ask whether the supplier controls the specific hazards relevant to the specific food being purchased.
Certificate review checklist
- Does the certificate cover the actual manufacturing site?
- Does it cover the actual product?
- Does it cover the relevant process?
- Is it current?
- Were there exclusions?
- Were major findings identified?
- Were corrective actions verified?
- Does it address the hazard of concern?
Is a Certificate of Analysis enough for supplier verification?
No. A COA can be useful, but it is not proof of control unless it is lot-specific, technically meaningful, reviewed correctly and connected to the hazard being verified.
A COA is only meaningful when the company understands what it proves, what it does not prove and whether it is reliable.
A strong COA should include
- Product name
- Supplier name
- Lot number
- Production date
- Analyte tested
- Test method
- Numerical result where appropriate
- Specification limit
- Unit of measurement
- Sampling information where available
- Laboratory identity
- Accreditation or qualification status where relevant
- Date of analysis
- Clear connection to the lot received
Practical questions to ask
- Is the COA lot-specific?
- Does it address the hazard identified in the hazard analysis?
- Are the results actual or generic?
- Is the method fit for purpose?
- Is the sampling plan appropriate?
- Is the laboratory qualified?
- Is the result close to the limit?
- Has COA reliability been independently verified?
Why measurement uncertainty matters in supplier testing
Laboratory results are not always as simple as "pass" or "fail." Results close to a legal limit, specification or customer threshold must be interpreted carefully.
Sampling, analytical method performance, matrix effects, recovery, detection limits, laboratory variability and measurement uncertainty can all affect interpretation.
A test result can influence:
- Release or rejection of a lot
- Supplier approval
- Border detention risk
- Customer acceptance
- Recall decisions
- Dispute resolution
- Regulatory response
A serious supplier verification program should not only collect test reports. It should ensure that someone can interpret them scientifically — for pesticide residues, mycotoxins, heavy metals, veterinary drug residues, allergens, food additives, microbiological results and authenticity markers.
Supplier fraud is supplier risk
Food fraud should be part of supplier approval because a supplier may adulterate, substitute, dilute, misrepresent or conceal information for economic gain.
A supplier's fraud can become the importer's fraud crisis. Even when deception begins upstream, the importer or brand owner may face customer complaints, recalls, regulatory questions, lawsuits, loss of trust and damage to market access.
Examples:
- Dilution with undeclared water
- Substitution with cheaper ingredients
- Undeclared sugar addition
- Undeclared preservatives
- Undeclared colors or flavors
- False origin claims
- False organic claims
- Fake or recycled COAs
- Unauthorized pesticide use
- Mixing compliant and noncompliant lots
- Undeclared allergens
- Misrepresented species
- Lower-grade material substitution
- Manipulation of Brix, protein, fat, moisture or purity markers
Example: supplier risk in orange juice, concentrates, pulps and tropical ingredients
A superficial supplier approval process may ask only for specification, COA, certificate, price, shelf life and shipping documents.
A better risk-based process asks:
- Could the product be diluted with undeclared water?
- Could sugar be added without declaration?
- Could unauthorized colors or flavors be used?
- Could preservatives be present but not declared?
- Could pulp wash or by-products affect identity or labeling?
- Does the supplier control pesticide residues for the target market?
- Are Brix, acidity, ratio and authenticity markers consistent?
- Are microbiological hazards controlled according to product type?
- Is the product shelf-stable, refrigerated, frozen, juice, puree, concentrate or ingredient?
- Does Juice HACCP apply?
- Are raw material suppliers verified?
- Are COAs lot-specific and scientifically meaningful?
- Can the supplier provide records quickly in English if the importer, FDA or customer asks?
This is the difference between buying a commodity and approving a supplier.
Do you approve suppliers by commercial convenience or by risk?
Many companies approve suppliers because they are cheaper, available, fast, known, already exporting, certified or commercially convenient. These factors may matter, but they do not answer the food safety question.
A stronger supplier approval process ranks suppliers using:
- Product hazard profile
- Intended use
- Ready-to-eat status
- Vulnerable consumers
- Severity and likelihood of hazards
- Supplier-controlled hazards
- Supplier maturity
- Regulatory history
- Audit history
- Complaint history
- Authenticity risk
- Allergen risk
- Testing reliability
- Country and commodity risk
- Transparency
- Responsiveness to deviations
- Ability to provide records
- Strategic dependence
"A supplier that is commercially convenient but technically opaque may be a dangerous supplier."
When is an onsite food supplier audit needed?
An onsite audit may be needed when the supplier controls a significant hazard, when the product is high risk, or when documents alone are not enough to understand whether the supplier's system works.
An audit should not be a generic checklist. It should evaluate the specific process, product, hazards and controls that matter for the food being supplied.
An onsite audit may be especially important when:
- The supplier controls a pathogen hazard
- The food is ready-to-eat
- There is no later kill step
- The supplier controls allergen cross-contact
- The ingredient has significant chemical hazard risk
- Supplier records are unclear
- COAs are weak or inconsistent
- The supplier has deviations or complaints
- The supplier has regulatory history
- The product is vulnerable to fraud
- The supplier is critical to the business
What should a supplier approval file include?
Nine core components of a defensible supplier file.
Supplier identity
Legal name, manufacturing site, address, ownership, broker or trader relationship, actual producing establishment, contact persons and emergency contacts.
Product identity
Product supplied, specifications, product codes, intended use, packaging, storage, shelf life and lot coding.
Hazard and risk assessment
Biological, chemical, physical, allergen and fraud-related hazards, severity, likelihood and who controls the hazard.
Approval rationale
Why the supplier is acceptable, approval criteria, responsible person, date, limitations and required verification activities.
Verification evidence
Audits, COAs, testing, records, process validation, corrective actions, complaints, performance history and regulatory history.
COA and testing review
Methods, limits, lab identity, sampling plan, acceptance criteria, trend review and independent verification where needed.
Food fraud and authenticity
Vulnerability assessment, authenticity markers, origin verification, mass balance where relevant, supplier transparency and targeted testing.
Change management
Formulation changes, process changes, site changes, allergen changes and raw material source changes.
Corrective actions & reevaluation
Deviations, failed tests, complaints, nonconforming lots, CAPA, reassessment and approval status.
Not sure whether your supplier files would hold up under scrutiny?
Common supplier approval failures
Patterns that recur in inspections, audits and importer reviews.
Approving suppliers based only on price or availability
Treating certification as enough
Treating a COA as proof without reviewing method, sampling and limits
Not identifying who controls each hazard
Using the same questionnaire for every supplier
Not checking warning letters, import alerts or import refusals
Not evaluating food fraud vulnerability
Not verifying allergen cross-contact risk
Not reassessing suppliers after deviations
Not documenting why verification activities are appropriate
Not understanding laboratory results
Not considering measurement uncertainty near limits
Not linking supplier files to the hazard analysis
Not knowing the actual manufacturing site behind a trader or broker
Not having a plan when supplier evidence is missing or weak
FDA-style questions companies should ask
Structured self-assessment across suppliers, COAs, fraud and importer responsibilities.
For any supplier
- Why did we approve this supplier?
- What food safety risks are associated with this product?
- Which hazards are controlled by the supplier?
- What evidence proves those hazards are controlled?
- Is the supplier file current?
- Has supplier performance changed?
- What would make us suspend approval?
For COAs
- Is the COA lot-specific?
- Does it show actual numerical results?
- Does it identify the method?
- Does it identify the laboratory?
- Does it address the actual hazard?
- Is the result close to the limit?
- Do we understand measurement uncertainty?
- Have we verified the supplier's COA reliability?
For food fraud
- How could this supplier adulterate the product?
- What would be the economic incentive?
- What tests or records would detect it?
- Are authenticity markers monitored?
- Could the supplier dilute, substitute, mislabel or conceal origin?
- Are unusual price offers investigated?
For importers
- Can we identify the actual foreign supplier?
- Is the supplier file organized by food and supplier?
- Does the hazard analysis reflect the actual imported food?
- Is supplier verification matched to the hazard?
- Do we have enough evidence to defend supplier approval?
- What happens if the supplier has a warning letter, import alert, recall or repeated deviation?
Why this matters when sourcing food suppliers from Brazil
Brazil is an important source of food products, ingredients, juices, tropical fruits, coffee, animal products, processed foods and agricultural commodities. For foreign importers, the opportunity can be strong, but supplier qualification should not depend only on price, volume and export willingness.
A serious importer should understand:
- Who the actual manufacturer is
- Whether a trader or broker is involved
- What product pathway applies in the destination market
- Whether the supplier controls food safety hazards
- Whether fraud vulnerability exists
- Whether documentation is defensible
- Whether COAs are reliable
- Whether the supplier can respond technically in English
- Whether the supplier can support customer, importer or regulatory questions
The five questions every supplier approval program should answer
What can go wrong with this food or ingredient?
Who controls the risk?
What evidence proves control?
What happens when control fails?
How do we know the supplier remains acceptable?
Supplier approval should not be a one-time administrative step. It should be a living risk-management system. Companies that understand this reduce food safety, fraud, regulatory and commercial risk. Companies that ignore it may discover the problem only when the product is already detained, rejected, recalled or questioned by a customer or regulator.
Need an independent technical view of a food supplier?
InspectIQ helps food companies and importers evaluate supplier risk, supplier documentation, food safety controls, fraud vulnerability, COA reliability, corrective actions and FDA/FSVP readiness — especially for companies working with Brazilian food suppliers.
Official references
- FDA — FSMA Foreign Supplier Verification Programs (FSVP)
- eCFR — 21 CFR Part 1 Subpart L (FSVP)
- eCFR — 21 CFR Part 117 Subpart G (Supply-Chain Program)
- FDA — FSVP Small Entity Compliance Guide
- FDA — Inspections of Food Facilities (Q&A)
- EPA — Pesticide Tolerances
- Codex Alimentarius — Measurement Uncertainty (CXG 54-2004)
InspectIQ provides independent technical and regulatory support. This page is for informational purposes only and does not replace legal advice, certification bodies, accredited laboratories, official regulatory decisions or the company's own regulatory responsibilities.
