Core topic · evidence, certificates, audits
Supplier compliance is the question of whether you can prove it.
The audit question is rarely whether your suppliers work cleanly. It is what proves that you checked – with a date, a basis and a named owner.
Supplier compliance means defining what you require of your suppliers, verifying that they meet it, and documenting both in a provable way. The difference from purchasing is the angle: purchasing asks about price, date and quantity. Compliance asks whether certificates are valid, whether self-disclosures exist and whether deviations were handled.
That is why procurement rarely owns it. Quality management, information security, compliance and the board do – roles that all look at the same suppliers with different questions and, in most companies, from different lists.
Where inspections fail
- The evidence exists, but nobody finds it within the deadline given.
- The certificate is on file and expired four months ago.
- The evaluation was carried out; the criteria behind it are nowhere on record.
- A deviation was discussed, but the action was never documented.
- The responsible person changed roles and took the knowledge with them.
What supplier compliance covers
- Requirement
- Define what a supplier must meet – graded by criticality, not one rule for everyone.
- Collection
- Obtain self-disclosures, certificates and declarations and file them in structure.
- Verification
- Verify rather than receive: issuer, validity, scope.
- Monitoring
- Track expiry dates and repeat cycles automatically.
- Deviation
- Carry findings through to closure with an action, an owner and a deadline.
- Evidence
- A timestamped history showing what was decided when and on what basis.
How SCRM covers it
Evidence file per supplier
Every document with issuer, issue date and expiry, visible to the roles that need it.
Verified status, not just storage
A document is either checked or it is not. That difference decides audits and is recorded.
Deadlines that raise themselves
Expiry and repetition create tasks with a name and a date.
Audit export
A report on the verified portfolio, produced in seconds instead of days.
Frequently asked
Isn’t this purchasing’s job?
Purchasing often collects the documents but rarely owns the verification. Judging whether evidence suffices belongs to the specialist function – quality, information security or compliance. Which is exactly why one shared record beats parallel lists.
How much evidence makes sense?
As much as you can actually verify. A fully verified set of 40 critical suppliers is worth more in an audit than 300 unchecked documents.
What if a supplier does not respond?
That is a result too, and it belongs on record. Chase, set a deadline, define the consequence – the trail of attempts is part of the evidence.