Management are probably working along the correct lines. Depending on your systems, either a non-conformance, deviation or CAPA is probably appropriate. Then within the deviation include a risk assessment on why the non-approved supplier was acceptable, root cause of how did it happen and how you will stop it happening again.