Direct answer
A supplier compliance checklist should confirm the approved requirement and its scope, the supplier and services affected, the evidence requested, the file or response received, issue and expiry dates, the authorised reviewer and outcome, any gap or exception, the affected contract or site, and the next action owner. The checklist supports coordination; the organisation remains responsible for deciding which requirements apply and what an accepted, rejected, expired, or exceptional item means operationally and legally.
1. Define the requirement before requesting documents
Requirement design
- Identify the approved policy, contract, risk, legal, regulatory, safety, insurance, security, or other source for the requirement.
- Define which supplier types, services, contracts, sites, values, or activities it applies to.
- Name the responsible requirement owner and authorised reviewer.
- Define evidence type, acceptable scope, review criteria, validity period, and exception path.
- Avoid requesting evidence merely because it appears on a generic list.
2. Collect and review the evidence
Request and receipt
- Send a request that identifies the evidence, supplier entity, scope, due date, and secure submission route.
- Record when the request was sent, who owns follow-up, and the supplier contact used.
- Connect the received file or response to the canonical supplier and requirement record.
- Use a clear 'received, review required' state rather than treating upload as approval.
Review
- Confirm the supplier/entity, activity, site, service, value, or period covered where relevant.
- Check legibility, completeness, issue date, valid-from date, expiry date, and version/reference.
- Record reviewer, review date, decision, concise rationale, and source context.
- Route specialist questions to the authorised function instead of inferring an answer from document appearance.
3. Handle gaps, expiry, and exceptions
Missing, rejected, or expiring evidence
- Create a named follow-up action and due date.
- Record the affected contract, site, service, or operational dependency.
- Escalate according to the approved process when the deadline or risk threshold is reached.
- Start renewal requests early enough for supplier response and internal review before expiry.
Exceptions
- Record the exception scope, rationale, approver, conditions, start/end or next-review date, and affected work.
- Keep the underlying requirement and gap visible.
- Do not convert a temporary exception into a permanent accepted state silently.
- Review or close the exception at the agreed milestone.
Minimum supplier evidence record
| Field | Example value | Review note |
|---|---|---|
| Requirement | Approved insurance evidence type | Use the organisation's actual approved requirement |
| Supplier and scope | Synthetic Supplier Ltd — Site A maintenance | Confirm legal entity and covered service |
| Evidence reference | EXAMPLE-CERT-001 | Synthetic example only; link the real secure source |
| Issue / expiry | 1 Jan 2027 / 31 Dec 2027 | Verify against the evidence |
| Status | Review required | Presence is not approval |
| Reviewer / date | Named authorised reviewer / review date | Preserve accountability |
| Gap or exception | Missing scope confirmation | State the unresolved point and approved handling |
| Next action | Supplier to provide corrected evidence by date | Name owner and due date |
| Impact | Contract ABC / Sites A–C | Connect evidence to affected operations |
4. Run the ongoing review queue
Weekly or regular operational review
- Newly received items waiting for review.
- Requests and actions past their due date.
- Evidence expiring within the organisation's lead-time window.
- Rejected items and open supplier responses.
- Exceptions approaching end or review date.
- Unowned requirements, evidence, or impacted contracts/sites.
Periodic control review
- Requirements remain approved, current, and correctly scoped.
- Supplier and contract/site relationships are still accurate.
- Status definitions and exception authority remain understood.
- Access, retention, and secure document handling follow approved policy.
- Reports distinguish workflow status from legal or regulatory conclusions.
Related resources
