SCRM Supplier Compliance & Risk Management

Home

Core topic · due diligence and evidence

Due diligence does not mean nothing may go wrong. It means you looked.

No law demands a flawless supply chain. What is demanded is a reasonable, documented effort: know the risks, prioritise, act, evidence.

Supply chain due diligence comes from the UN Guiding Principles on Business and Human Rights and is now anchored in several legal systems. The structure is similar everywhere: a policy statement, risk analysis, preventive and remedial measures, a grievance channel, documentation.

For Swiss SMEs the trigger is almost never their own statute but their customer. Large buyers must analyse their chain and can only do so if suppliers answer. The questionnaire will come – the only question is whether you answer it from your records or research it again each time.

Where the duty comes from

  • Swiss law: due diligence on conflict minerals and child labour, with the planned NUFG to come.
  • EU law: the CSDDD, which after Omnibus I binds only very large companies directly.
  • German law: the LkSG, whose reporting duty has gone while the due diligence duties remain.
  • Contracts: codes and self-disclosures through which obligated customers pass their duties on.

The five steps

Policy
Set down in writing which standards apply in your chain.
Risk analysis
By country, sector and commodity group, regularly and on specific triggers.
Prevention
Contractual assurances, training, selection criteria, risk-based controls.
Remediation
On findings, a plan with an action, a deadline and an effectiveness check.
Documentation
Complete and retained – seven years in Germany.

How SCRM covers it

Country and commodity profile

The base data every risk analysis draws on.

Questionnaire dispatch

Request self-disclosures digitally, store answers on the supplier, see what is open.

Action tracking

Remediation with an owner, a deadline and a closure instead of a meeting note.

Provable repetition

Annual assessments versioned – the trail shows what was known when.

Frequently asked

We have 200 suppliers. Must we analyse them all?

The analysis starts with the whole portfolio; depth is then graded. Reasonable means risk-based: a Swiss office supplier and a raw material source in a high-risk region do not need the same scrutiny – but you must be able to justify the grading.

How far into the chain?

Usually to the first tier, deeper where there are substantiated indications. No current regime requires an unbroken chain to raw materials.

Is it worth it if we are not obligated?

The question rarely stays open long. Once a large customer asks for the self-disclosure it becomes a sales question – and response speed helps decide the order.

As of July 2026. Not legal advice.

Contact

Request a consultation

A few details is all we need. We reply within one working day with an honest read on whether SCRM fits your situation.

  • A free seven-day demo account on request
  • Reply within one working day
  • No newsletter, no sharing with third parties
  • An honest read, including when we are not the fit
What drives your supply chain monitoring? *

Select all that apply

How can we reach you? *

Either one of the two is enough.

No leading zero, e.g. 79 123 45 67

* Required