DIRECT ANSWER
Supplier due diligence may include legal identity, facility and process review, quality systems, labour and environmental controls, certifications, financial or sanctions checks where appropriate, references and subcontracting. An audit can identify evidence and gaps at a point in time; it cannot guarantee future performance or eliminate concealment risk.
An audit is a time-bound evidence exercise. Its value depends on scope, competence, transparency, corrective action and what happens between visits.
01
Define the decision the audit supports
A technical capability review, social audit, environmental review, security assessment and quality-system audit answer different questions. Scope should follow the product, market and risk.02
Read documents in context
Check issuer, scope, site, validity, exclusions and corrective action. A certificate for one location or process should not be stretched across an unrelated supply chain.03
Follow findings into behaviour
A closed corrective-action report is useful when the change is implemented and verified. Repeated issues, superficial evidence or late disclosure may indicate a deeper governance problem.04
Keep due diligence current
Ownership, facilities, workforce, subcontracting, certifications and risk can change. Refresh frequency should be based on consequence and credible change signals, not a universal calendar.KEY TAKEAWAYS
What to carry into the next decision
- Match audit scope to the decision and risk.
- Verify site and scope of every certificate.
- Treat corrective action and ongoing behaviour as evidence.
Editorial note: This guide is general operational information, not legal, tax or regulatory advice. Product, marketplace and destination requirements should be confirmed from current authoritative sources and qualified specialists.
Risk & control
Quality & compliance
Quality & compliance