Appearance
Supplier due diligence
Due diligence on a new supplier before the first purchase order: a questionnaire covers the company, its owners and, for software suppliers, security certification; a screening step checks the company; findings go to procurement. Pack: examples/policies/supplier-due-diligence/.
A pattern for expressing a supplier & third-party risk policy, not compliance guidance: the thresholds, lists and fields are placeholders chosen to make the example run; a real policy comes from the business's own rules. The screen step needs mock-sanctions installed (Connect › Apps; no configuration or secrets).
The decision it automates
Whether to approve the supplier, send it to compliance, or decline it, when the questionnaire is submitted.
Data expected
- The supplier as a subject (kind
merchant, a business); nothing is read from its data. - The questionnaire's answers under
submission:legalName,country,category,annualValue,ownersDeclaredwithownerNameandownershipPct, and the security answers for software suppliers. - The
screenstep's answer undercompanyScreening. - The
supplier_high_risk_countrieslist, which the pack creates with a placeholder row.
Steps and rules
| Step | Type | Why |
|---|---|---|
collect | wait_for_collection | The supplier-questionnaire flow; software suppliers get the security step. |
screen | call_app | mock-sanctions screen on the company's name and country, standing in for a sanctions vendor. |
rules | evaluate_rules | The supplier-due-diligence rule set under max_severity. |
route | branch | rules.outcome == manual_review opens a case. |
review | create_case | procurement_review, 5-day SLA. |
decide | emit_decision | From the rules, or the reviewer's decision. |
The rule set supplier-due-diligence (useCase: onboarding) uses max_severity: a failed block rule rejects, a failed warn rule sends the run to review, and the weights add up to the score.
| Rule | Type | Severity, weight | Fails when |
|---|---|---|---|
supplier_sanctions_clear | comparison | block, 100 | the screen found a match |
supplier_ownership_declared | comparison | block, 100 | ownersDeclared is no |
supplier_country_risk | list lookup | warn, 30 | country is on supplier_high_risk_countries |
supplier_contract_value | score threshold | warn, 20 | annualValue is above 500 000 |
What a reviewer sees
A procurement_review case with the questionnaire, the screening answer and each rule's result; an export of the audit trail with its digest serves the audit later.
How to adapt it
Swap mock-sanctions for OpenSanctions, screen each owner too, add a call_app step that creates the supplier in your ERP (an app you build) once approved, and have your scheduler start a screening run for every active supplier each year.
Run it
bash
pnpm policy:import examples/policies/supplier-due-diligence --publishThe fixture registers a goods supplier in Antarctica (the placeholder on the list) with declared owners: the screen finds no match, the country-risk rule fails, a procurement_review case opens, the check approves it and the run completes with a manual approve.