← Insights

Compliance

Onboarding suppliers without inheriting their risk

July 2026 · 6 min read

Approving a supplier is the easy part. You gather the certificates, tick the boxes, add them to the approved list, and move on. The problem is that a supplier's compliance is not a state you confirm once - it is a set of documents with expiry dates, and every one of them is quietly counting down from the day you filed it. The insurance certificate lapses. The ISO 9001 registration falls out of date. The ethical audit comes due. And you find out none of this until a customer asks you to evidence it, which is the worst possible moment to discover a gap.

A supplier's risk becomes your risk the moment you rely on them. The way to onboard without inheriting that risk is not a harder approval gate; it is a register that keeps the evidence current and tells you the moment it stops being current.

Compliance is not the same as performance

It is worth drawing a line most tools blur. A supplier scorecard measures how a supplier performs - on-time delivery, defect rates, responsiveness. That matters, but it answers a different question. A compliance register measures whether a supplier is allowed and evidenced - the right documents on file, still in date, the re-audit not overdue. A supplier can be scoring beautifully on delivery while their liability insurance quietly expired last month. Performance and compliance are separate axes, and the compliance one is the one that leaves you exposed if a customer or auditor comes asking, because it is the one most systems skip.

What to track, per supplier

A working supplier compliance register holds, for each supplier, the small set of facts that decide whether relying on them is safe:

Let the status decide itself

The register earns its place by computing each supplier's compliance status rather than making someone maintain it by hand. From the evidence flags and the review date it can decide: complete when the required documents are on file and the review is not overdue; docs missing when something required is not there; review overdue when the re-audit date has passed; suspended when the supplier is. Because the status is derived, it is never stale and never a matter of someone remembering to update a column. A lapsed certificate or a missed re-audit surfaces on its own, well before anyone outside your business asks about it.

Next-review and days-left figures, worked out from the last audit date and your review frequency, count down live. Scrutiny stops being an annual panic and becomes a queue you work down - the register tells you which suppliers are due, in what order.

Due diligence you can evidence

There is a difference between doing due diligence and being able to prove you did it, and only the second one helps you when it counts. If a customer audits your supply chain, or something goes wrong downstream and the question becomes "what did you check and when?", a register that shows each supplier's evidence, its dates, and a trail of completed reviews is the answer. It converts a vague assurance - "our suppliers are compliant" - into a documented, dated position you can put in front of anyone. That evidence trail is the real product of the whole exercise; the approved list is just the visible tip of it.

The register is doing its job when a supplier's lapsed certificate reaches you before your customer's auditor does - and when "prove it" is a five-minute answer, not a scramble.

What documents a given supplier must hold, and how often to re-audit them, depends on your sector, your customers' requirements and your own risk appetite - a register organises and dates the evidence rather than deciding what evidence you need, so set the requirements with the relevant standard or a qualified adviser in mind. What it guarantees is that once you have set the rules, no certificate lapses and no re-audit slips past unnoticed. You onboard the supplier; you do not quietly inherit the risk they came with.

The register that keeps the evidence current

Per-supplier risk tier and onboarding status, evidence flags for insurance, ISO 9001 and ethical audits, a compliance status that decides itself, next-review countdowns and a live dashboard. With a worked example.

Get the Supplier Compliance Register on Etsy

Never miss a guide

New articles and templates, straight to your inbox. Plus a free tool to start.

By subscribing you consent to receive emails from Axiom. Your address is stored with Kit, our email provider, and never shared. Unsubscribe any time via the link in every email. Privacy policy.