Checklist · Supplier evidence checklist

Supplier compliance checklist

Use this operational checklist to keep supplier requirements, evidence, review decisions, expiry dates, exceptions, and follow-up connected to the affected work.

By LetCM5 minute read

Direct answer

A supplier compliance checklist should confirm the approved requirement and its scope, the supplier and services affected, the evidence requested, the file or response received, issue and expiry dates, the authorised reviewer and outcome, any gap or exception, the affected contract or site, and the next action owner. The checklist supports coordination; the organisation remains responsible for deciding which requirements apply and what an accepted, rejected, expired, or exceptional item means operationally and legally.

1. Define the requirement before requesting documents

Requirement design

  • Identify the approved policy, contract, risk, legal, regulatory, safety, insurance, security, or other source for the requirement.
  • Define which supplier types, services, contracts, sites, values, or activities it applies to.
  • Name the responsible requirement owner and authorised reviewer.
  • Define evidence type, acceptable scope, review criteria, validity period, and exception path.
  • Avoid requesting evidence merely because it appears on a generic list.

2. Collect and review the evidence

Request and receipt

  • Send a request that identifies the evidence, supplier entity, scope, due date, and secure submission route.
  • Record when the request was sent, who owns follow-up, and the supplier contact used.
  • Connect the received file or response to the canonical supplier and requirement record.
  • Use a clear 'received, review required' state rather than treating upload as approval.

Review

  • Confirm the supplier/entity, activity, site, service, value, or period covered where relevant.
  • Check legibility, completeness, issue date, valid-from date, expiry date, and version/reference.
  • Record reviewer, review date, decision, concise rationale, and source context.
  • Route specialist questions to the authorised function instead of inferring an answer from document appearance.

3. Handle gaps, expiry, and exceptions

Missing, rejected, or expiring evidence

  • Create a named follow-up action and due date.
  • Record the affected contract, site, service, or operational dependency.
  • Escalate according to the approved process when the deadline or risk threshold is reached.
  • Start renewal requests early enough for supplier response and internal review before expiry.

Exceptions

  • Record the exception scope, rationale, approver, conditions, start/end or next-review date, and affected work.
  • Keep the underlying requirement and gap visible.
  • Do not convert a temporary exception into a permanent accepted state silently.
  • Review or close the exception at the agreed milestone.

Minimum supplier evidence record

All example values are synthetic and do not represent a real supplier or compliance decision.
FieldExample valueReview note
RequirementApproved insurance evidence typeUse the organisation's actual approved requirement
Supplier and scopeSynthetic Supplier Ltd — Site A maintenanceConfirm legal entity and covered service
Evidence referenceEXAMPLE-CERT-001Synthetic example only; link the real secure source
Issue / expiry1 Jan 2027 / 31 Dec 2027Verify against the evidence
StatusReview requiredPresence is not approval
Reviewer / dateNamed authorised reviewer / review datePreserve accountability
Gap or exceptionMissing scope confirmationState the unresolved point and approved handling
Next actionSupplier to provide corrected evidence by dateName owner and due date
ImpactContract ABC / Sites A–CConnect evidence to affected operations

4. Run the ongoing review queue

Weekly or regular operational review

  • Newly received items waiting for review.
  • Requests and actions past their due date.
  • Evidence expiring within the organisation's lead-time window.
  • Rejected items and open supplier responses.
  • Exceptions approaching end or review date.
  • Unowned requirements, evidence, or impacted contracts/sites.

Periodic control review

  • Requirements remain approved, current, and correctly scoped.
  • Supplier and contract/site relationships are still accurate.
  • Status definitions and exception authority remain understood.
  • Access, retention, and secure document handling follow approved policy.
  • Reports distinguish workflow status from legal or regulatory conclusions.

Related resources