Non-conformance: The facility has not identified the risk rating for raw material suppliers, packaging suppliers and contract service providers.
Auditor told me I could just add another column onto our registry for suppliers and contractors and rate the risk they pose (low, medium, high).
Is it really that simple? I feel like this isn't enough, and can't find anything on here when I search.
Thank you so much in advance