Skip to content

Supplier due diligence ​

Due diligence on a new supplier before the first purchase order: a questionnaire covers the company, its owners and, for software suppliers, security certification; a screening step checks the company; findings go to procurement. Pack: examples/policies/supplier-due-diligence/.

A pattern for expressing a supplier & third-party risk policy, not compliance guidance: the thresholds, lists and fields are placeholders chosen to make the example run; a real policy comes from the business's own rules. The screen step needs mock-sanctions installed (Connect › Apps; no configuration or secrets).

The decision it automates ​

Whether to approve the supplier, send it to compliance, or decline it, when the questionnaire is submitted.

Data expected ​

  • The supplier as a subject (kind merchant, a business); nothing is read from its data.
  • The questionnaire's answers under submission: legalName, country, category, annualValue, ownersDeclared with ownerName and ownershipPct, and the security answers for software suppliers.
  • The screen step's answer under companyScreening.
  • The supplier_high_risk_countries list, which the pack creates with a placeholder row.

Steps and rules ​

StepTypeWhy
collectwait_for_collectionThe supplier-questionnaire flow; software suppliers get the security step.
screencall_appmock-sanctions screen on the company's name and country, standing in for a sanctions vendor.
rulesevaluate_rulesThe supplier-due-diligence rule set under max_severity.
routebranchrules.outcome == manual_review opens a case.
reviewcreate_caseprocurement_review, 5-day SLA.
decideemit_decisionFrom the rules, or the reviewer's decision.

The rule set supplier-due-diligence (useCase: onboarding) uses max_severity: a failed block rule rejects, a failed warn rule sends the run to review, and the weights add up to the score.

RuleTypeSeverity, weightFails when
supplier_sanctions_clearcomparisonblock, 100the screen found a match
supplier_ownership_declaredcomparisonblock, 100ownersDeclared is no
supplier_country_risklist lookupwarn, 30country is on supplier_high_risk_countries
supplier_contract_valuescore thresholdwarn, 20annualValue is above 500 000

What a reviewer sees ​

A procurement_review case with the questionnaire, the screening answer and each rule's result; an export of the audit trail with its digest serves the audit later.

How to adapt it ​

Swap mock-sanctions for OpenSanctions, screen each owner too, add a call_app step that creates the supplier in your ERP (an app you build) once approved, and have your scheduler start a screening run for every active supplier each year.

Run it ​

bash
pnpm policy:import examples/policies/supplier-due-diligence --publish

The fixture registers a goods supplier in Antarctica (the placeholder on the list) with declared owners: the screen finds no match, the country-risk rule fails, a procurement_review case opens, the check approves it and the run completes with a manual approve.

Released under the Apache-2.0 License.