Direct answer
Supplier compliance is the organisation's process for defining applicable supplier requirements, collecting and reviewing evidence, tracking validity and expiry, recording gaps or approved exceptions, assigning follow-up, and understanding which contracts, sites, or services are affected. Software can support this coordination, but a document being present—or a status being green—does not by itself prove legal, regulatory, safety, or policy compliance. The requirement, evidence, reviewer, and decision authority must be defined by the organisation.
The supplier evidence control model
| Element | Record to keep | Question it answers |
|---|---|---|
| Requirement | Evidence type, scope, source policy/contract, applicability | What is expected and why? |
| Supplier and coverage | Supplier, services, contracts, sites, categories | Where does the requirement apply? |
| Evidence | Document/reference, issue and expiry dates, version | What has been supplied? |
| Review | Reviewer, review date, status, note, source | Has an authorised person checked it? |
| Gap or exception | Missing/expired state, rationale, approver, review date | What remains unresolved or has been accepted temporarily? |
| Follow-up | Request, owner, due date, reminder, supplier response | Who is doing what next? |
| Impact | Affected contract, site, service, operational dependency | What work or decision may be affected? |
A practical supplier compliance workflow
- 01
Define the requirement
Record the approved requirement and where it comes from. Different supplier types, services, sites, and contracts may require different evidence.
- 02
Request and receive evidence
Use a controlled request and keep the received file or reference connected to the supplier and affected service context.
- 03
Review rather than merely collect
An authorised reviewer checks relevance, dates, scope, legibility, and organisational rules. Automation may extract details but should not silently approve them.
- 04
Record status, validity, and source
Use clear states such as requested, received, review required, accepted, rejected, expired, exception, or not applicable according to the organisation's approved model.
- 05
Assign gaps and exceptions
Missing, expiring, rejected, or exceptional evidence becomes owned work with a due date and review path, not an unowned red flag.
- 06
Review impact and renew evidence
Link the gap to affected contracts, sites, or services and start the next evidence cycle before validity ends.
Evidence status should describe workflow, not make a legal conclusion
| Status | Operational meaning | What it does not prove |
|---|---|---|
| Requested | A request has been issued and is awaiting response | That the supplier has or will provide valid evidence |
| Received | A file or response is present | That it is current, applicable, authentic, or sufficient |
| Review required | A person still needs to check the evidence | That the supplier may proceed |
| Accepted | An authorised reviewer accepted it under the organisation's process | Universal legal or regulatory compliance |
| Rejected | The evidence did not satisfy the approved review rule | A final legal conclusion or automatic supplier termination |
| Expired | The recorded validity date has passed | The full legal or operational consequence without further review |
| Exception | An authorised temporary or scoped exception is recorded | That the underlying requirement disappeared |
Questions for each evidence record
Applicability
- Which supplier, service, contract, site, or category does the requirement cover?
- Who approved the requirement and where is the source policy or contract context?
- Is the requirement current and correctly scoped?
Evidence quality
- Is the document or response complete, legible, and attributable to the expected supplier/entity?
- Are issue, valid-from, and expiry dates captured and reviewed where relevant?
- Does the evidence cover the right activity, location, value, or period under the approved rule?
Accountability
- Who reviewed it, when, and with what outcome?
- Who owns any gap, supplier request, or exception review?
- Which contract, site, or service needs to know about the outcome?
Related resources
