play icon for videos

Supply Chain Due Diligence: Supplier Evidence and Follow-Up

Plan supply chain due diligence with supplier and site records, protected worker input, document review, corrective actions and evidence of follow-up.

Updated
September 15, 2026
360 feedback training evaluation
Use Case
Partners & suppliers · Practical guide

Supply Chain Due Diligence: Supplier Evidence and Follow-Up

Plan supply chain due diligence with supplier and site records, protected worker input, document review, corrective actions and evidence of follow-up.

Read the guide ↓

What is supply chain due diligence?

Supply chain due diligence is an ongoing process for identifying and addressing relevant risks and adverse impacts connected with business relationships. In responsible business conduct, it includes understanding impacts on people and the environment, taking appropriate action and examining whether the response works.

It is broader than a supplier questionnaire, an audit or worker feedback alone. The OECD’s due diligence guidance describes a risk-based approach involving policies, assessment, action, tracking, communication and remedy where appropriate. Sector and legal requirements need their own assessment.

This guide focuses on the evidence workflow that supports that process: connecting suppliers, sites, documents, protected stakeholder input, findings and follow-up. It is useful for growing teams whose supplier information is spread across forms, email and reports.

Start with the scope and the relationships

Identify what the review covers: products or services, direct suppliers, relevant upstream relationships, sites and locations. Make gaps in visibility explicit rather than treating a completed direct-supplier questionnaire as a complete view of the chain.

A supplier can operate several sites with different activities and conditions. A certificate may apply to only one facility or product. A subcontractor may sit behind a relationship that looks simple in the purchasing system.

Scroll horizontally to see all columns →

RecordWhat it should distinguish
SupplierThe organization and the commercial relationship
SiteThe location and activities covered by evidence
Product, service or transactionThe work or goods relevant to the question
Assessment or documentIts scope, date, version and validity where relevant
Finding and responseThe issue, review, action owner and follow-up evidence

Not every team needs every level for every question. Use enough structure to avoid applying evidence to the wrong site or relationship. Define who maintains those connections when suppliers or contracts change.

Prioritize the assessment rather than asking everyone everything

Use the appropriate risk method to decide where more attention is needed. Consider the activity, location, available evidence and potentially affected people or environment. A long questionnaire sent indiscriminately can consume time without resolving the important unknowns.

Begin with existing information. Purchasing records may establish the relationship. Technical assessments may address environmental questions. Audits, worker engagement and operational documents may provide different views of conditions.

Then identify the unanswered questions and the most suitable way to investigate them. A missing policy document and a report of an unsafe condition need different responses. Do not let a single completion score obscure that distinction.

Keep the prioritization rationale and responsible reviewer visible. A reporting tool can organize the evidence; qualified people must decide the assessment and response appropriate to the situation.

Combine supplier records, assessments and stakeholder evidence

Scroll horizontally to see all columns →

Evidence sourceWhat it can contributeWhat to check
Supplier questionnaireStructured information and declared practicesDefinitions, scope and support for important answers
Audit or assessmentFindings from a defined reviewMethod, date, coverage and outstanding issues
Policy or certificateA stated commitment or documented statusApplicability, issuer, validity and evidence of implementation
Worker or community inputExperience and concerns not fully reflected in formal recordsSafe participation, confidentiality and appropriate follow-up
Operational or physical dataEvents, deliveries, measurements and changes over timeUnits, completeness and the measurement method

Audits can include worker interviews and other substantive evidence; they are not necessarily a supplier declaration. Feedback platforms can support confidential reporting and alerts. Evaluate how the sources and processes work together rather than dismissing whole categories of tools.

No single source establishes everything. A current policy does not prove every practice follows it. A reported concern is important evidence but is not automatically a confirmed violation. Preserve contradictory information for appropriate review.

Add worker voice without exposing people

Worker input can reveal conditions that routine management reporting misses. Its usefulness depends on whether people can participate safely and whether the organization responds appropriately.

Choose the channel and access model deliberately. Explain who sees responses, what follow-up is possible and how the information will be used. Provide appropriate options for anonymous or confidential reporting. Do not make a name mandatory merely to attach the evidence to a supplier.

A source identifier, date and permitted site context can support traceability without exposing identity. Small groups, detailed quotes and combinations of attributes can still reveal people, so review what appears in dashboards and shared reports.

Separate ordinary feedback from urgent reporting routes. A general survey and automated analysis should not be the only mechanism for serious concerns. Route sensitive matters through the established specialist process and preserve the relevant protections.

A worked example: one supplier, two sites, one misleading status

This fictional example illustrates evidence management, not a customer result or a compliance determination.

A supplier submits an assessment covering Site A. The supplier-level dashboard marks the assessment requirement complete. Later, a reviewer notices that the contract also includes work at Site B, which the submitted document does not cover.

The correction is not to declare the entire supplier compliant or noncompliant. The team records the scope gap, identifies what evidence is required for Site B and assigns a reviewer. Site A’s documented status remains separate.

A protected feedback submission then raises an issue at Site B. It stays connected to the site and the appropriate restricted review. The broad supplier view shows an open assessment and response status without exposing the reporter.

When a corrective action is reported as complete, the team asks for evidence appropriate to that action and reviews whether the underlying condition changed. Uploading a file is a submission event; it is not automatically proof of effective remediation.

Use common definitions without a universal questionnaire

A distributed supply network needs some shared fields: supplier and site identity, assessment period, requirement, evidence status, responsible owner and next review. These fields make it possible to compare coverage and follow-up.

Other questions should vary with the activity and context. A logistics provider, manufacturing site and professional-services partner may need different evidence. Standardize the meaning of shared measures instead of forcing the same full survey on every contributor.

In the data dictionary, distinguish a confirmed zero, not applicable, not reported and awaiting review. If a requirement does not apply, preserve the reason. Do not treat missing evidence as either a positive result or a proven adverse impact.

Version requirements and definitions. When the team changes the scope, identify the affected suppliers and prior assessments. Historical results should not silently change meaning.

Review documents and findings with clear source context

For each important finding, retain the document or submission, the relevant passage or measurement, the period, the scope and the reviewer’s interpretation.

AI-assisted analysis can help locate passages, compare declared answers with available documents and identify unanswered questions. It can also miss evidence or misread a statement. “No supporting evidence found in these files” is different from “the supplier does not follow this practice.”

Keep coverage visible: inaccessible files, unread pages, missing attachments and unreviewed results should not disappear into a completed badge. Human reviewers need a way to correct a proposed finding and retain the reason.

For recurring text analysis, use team-owned definitions and review the affected records when those definitions change. The qualitative and quantitative analysis guide explains how this can reduce repeated coding and joining while preserving review.

Track the response through to evidence of change

A useful response record includes the assessed issue, agreed action, owner, due date, implementation evidence and the basis for the next status. Preserve disagreement and unresolved questions where relevant.

Do not equate a supplier promise, an uploaded plan, a completed action and an effective remedy. These represent different stages. The appropriate review depends on the issue and may require specialist assessment and engagement with affected people.

Escalation and decisions about the relationship need qualified judgment. An automated score should not terminate a supplier or determine legal obligations. Keep the decision rationale and follow-up connected to the source evidence.

The ESG risk management guide covers the broader assessment-to-response view.

Report coverage and findings separately

A portfolio dashboard should show what is known and what remains open. Useful views include suppliers in scope, sites covered, evidence awaiting review, open actions and overdue follow-up.

For example, if 40 of 50 in-scope sites have current reviewed assessments, coverage is 80%. That does not mean 80% are compliant or that the remaining 20% have confirmed violations. It describes assessment coverage under the stated definition.

Likewise, a lower number of worker reports may reflect a change in reporting access or confidence. Do not use report counts alone to rank suppliers as safe or unsafe.

Keep the management summary connected to restricted detail so authorized reviewers can inspect the basis without exposing sensitive sources to every viewer.

Test the complete supplier-evidence workflow

Sopact’s relevant approach connects collection, contextual records, analysis and review across partners and sites. It can support an evidence workflow alongside the organization’s purchasing, assessment and specialist processes.

Test with one supplier that has two sites, a revised document, a scope gap, protected feedback and a follow-up action. Ask ordinary team members to maintain the next reporting cycle.

  • Can evidence stay attached to the correct site and period?
  • Can different contributors supply relevant information without duplicating stable registration details?
  • Can reviewers distinguish a declaration from a supported finding?
  • Can sensitive input remain protected in the shared portfolio view?
  • Can the team follow an action through implementation and effectiveness review?
  • How much manual matching, document searching and report rebuilding remains?

Evaluate total implementation and maintenance effort without assuming that software replaces professional due diligence, legal review or an appropriate grievance process.

Build the recurring partner workflow

Continue with the Partner & Supplier evidence course to plan the collection, records, analysis and review. The partner intelligence guide explains the broader operational context.

Watch: connect evidence from several sources

This portfolio-reporting video explains the value of preserving source context. It is not a supplier certification or a demonstration of every due diligence requirement.

Frequently asked questions

Is a supplier questionnaire the same as due diligence?

No. It is one collection method. Due diligence includes assessing relevant evidence, responding appropriately and tracking the results of the response.

Can worker feedback be anonymous?

Yes. Preserve the anonymity promise and connect the evidence to permitted supplier or site context without requiring personal identification.

Does a certificate cover every site of a supplier?

Not necessarily. Check the document’s scope, validity and applicability to the site, activity or product being reviewed.

Does completing a corrective action close the issue?

Not automatically. Review the evidence needed to determine whether the action addressed the underlying condition and record the basis for closure.

Can AI make a final supplier compliance decision?

AI can assist with organizing evidence and preparing review. Qualified people must make consequential assessments and decisions through the relevant process.

Explore Portfolio Intelligence →