Skip to main content
Category: Third-Party and Supply Chain

Supplier Code of Conduct

Also known as: SCoC, Vendor Code of Conduct, Third-Party Code of Conduct
Simply put

A Supplier Code of Conduct is a document a company issues to set out the standards and expectations it wants its suppliers to meet, covering areas such as safe working conditions, fair labor practices, and ethical behavior. It communicates the company's core values and describes how the company and its suppliers are expected to behave toward each other. It is typically a company-imposed standard rather than a law, and its specific contents vary from one organization to another.

Formal definition

A Supplier Code of Conduct is a formal document through which a buying organization defines the ethical, social, environmental, and operational standards it expects its suppliers and other third parties to observe, often addressing safe working conditions, fair labor, and responsible business practices. It generally functions as a voluntary, company-driven standard that articulates the buyer's values and mutual behavioral expectations, and may be incorporated into contractual arrangements to become binding on suppliers, though this depends on the specific facts, the terms adopted, and applicable jurisdiction. Its scope, enforceability, and content are set by the issuing organization and are not uniform across companies; it should be distinguished from binding statutory or regulatory obligations, which may separately impose supply-chain due diligence or reporting duties depending on jurisdiction, sector, and entity type.

Why it matters

A Supplier Code of Conduct extends an organization's values and behavioral expectations beyond its own workforce to the third parties it depends on, addressing areas such as safe working conditions, fair labor practices, and ethical business behavior. Because much of a company's operational, reputational, and ethical exposure sits within its supply chain rather than inside its own walls, articulating clear expectations for suppliers is a common way for organizations to communicate the standards they expect and to establish a shared understanding of how the parties will behave toward each other.

The practical significance of a Supplier Code depends heavily on how it is used. On its own, it is generally a voluntary, company-imposed standard rather than a legal requirement, and its contents vary from one organization to another. Where its provisions are incorporated into contractual arrangements, they may become binding on suppliers, but whether and how this occurs depends on the specific terms adopted and the applicable jurisdiction. Boards and compliance functions should therefore be careful not to assume that publishing a code, by itself, creates enforceable obligations or discharges any separate legal duties.

It is important to distinguish a Supplier Code of Conduct from binding statutory or regulatory obligations. Some jurisdictions and sectors impose supply-chain due diligence or reporting duties on certain entities, and those obligations exist independently of any voluntary code. A Supplier Code can support an organization's broader compliance and third-party risk management efforts, but it is not a substitute for meeting whatever legal requirements apply to a given entity, and its effectiveness ultimately turns on monitoring, verification, and follow-through rather than on the existence of the document alone.

Who it's relevant to

Chief Compliance and Ethics Officers
Compliance functions typically own the drafting, communication, and administration of a Supplier Code of Conduct as part of a broader third-party and ethics program. They are generally responsible for ensuring the code reflects the organization's values and for coordinating how expectations are communicated to suppliers, while remaining mindful that the code is usually a voluntary standard distinct from any binding legal obligations that may apply.
Procurement and Supplier Management Teams
Those managing supplier relationships are often the front-line function that introduces the code to suppliers, seeks acknowledgment, and monitors adherence in day-to-day dealings. Because the code addresses areas such as safe working conditions, fair labor, and ethical behavior, procurement teams generally play a central operational role in setting mutual expectations and escalating concerns.
General Counsel and Legal
Legal advisors are typically consulted on whether and how to incorporate the code into contracts, since incorporation is what can make its provisions binding on suppliers depending on the terms and jurisdiction. They also help distinguish the voluntary code from any separate statutory or regulatory supply-chain due diligence or reporting duties that may apply to the entity.
Boards and Relevant Committees
Boards and their committees generally exercise oversight of the organization's approach to supply-chain conduct and third-party risk, rather than administering the code directly. Their interest is typically in whether management has established appropriate standards, monitoring, and escalation, and in understanding the limits of what a voluntary code achieves relative to applicable legal obligations.
Internal Audit and Assurance Functions
Assurance functions may assess whether controls related to the Supplier Code, such as supplier acknowledgment, contractual incorporation, and monitoring, are designed appropriately and operating effectively. Their focus is generally on independent evaluation rather than on setting or enforcing the standards themselves.

Inside SCoC

Ethical and Labor Standards
Provisions setting expectations for how suppliers treat workers, typically addressing matters such as prohibitions on forced or child labor, wage and working-hour expectations, non-discrimination, and health and safety. These provisions often reference underlying legal requirements that vary by jurisdiction, and the code generally states the entity's expectations rather than creating law itself.
Anti-Corruption and Business Integrity
Statements addressing bribery, corruption, conflicts of interest, gifts and hospitality, fair dealing, and competition. Where an entity is subject to anti-corruption statutes, these provisions typically extend the entity's compliance expectations into its supply chain, though the code is generally a contractual or relationship standard rather than a source of legal obligation for the supplier.
Environmental Expectations
Provisions covering matters such as regulatory compliance, resource use, waste and emissions, and, in some codes, broader sustainability commitments. These typically reference the supplier's obligation to meet applicable environmental laws, which vary by jurisdiction and sector, plus any voluntary standards the entity chooses to require.
Scope and Applicability
Language defining who is bound, direct suppliers, subcontractors, or lower-tier suppliers, and whether the code applies to a specific contract, a relationship, or an entire supply chain. Reach beyond first-tier suppliers is often aspirational and depends on the terms actually incorporated into contracts.
Compliance, Monitoring, and Assurance Provisions
Mechanisms such as self-assessment, audit or inspection rights, evidence requirements, and reporting or grievance channels. These describe how the entity intends to gain assurance over supplier conduct; the design of such controls and their actual operating effectiveness are distinct matters that require separate evaluation.
Consequences and Remediation
Provisions describing expected responses to non-compliance, which may range from corrective action plans to termination. The enforceability of these consequences generally depends on whether the code is incorporated into a binding contract and on applicable law.

Common questions

Answers to the questions practitioners most commonly ask about SCoC.

Does adopting a supplier code of conduct make an organization legally responsible for its suppliers' conduct?
Not automatically. A supplier code of conduct is generally a contractual and policy instrument that sets out expectations for third parties; it does not by itself transfer legal liability for a supplier's actions to the buying organization. Whether legal responsibility attaches depends on the applicable law, the contractual terms, the degree of control or knowledge involved, and the relevant jurisdiction and sector. Some legal regimes do impose due diligence or supply chain obligations on organizations, but those obligations arise from statute rather than from the existence of a code. This entry is educational and not legal advice; assessing liability exposure requires professional judgment on specific facts.
Is a supplier code of conduct the same as having an effective third-party risk management or compliance monitoring program?
No. A supplier code of conduct is typically a statement of expected standards, whereas third-party risk management and ongoing compliance monitoring are broader activities that include risk assessment, due diligence, contractual controls, and verification of actual behavior over time. The code sets out what is expected; monitoring, auditing, and assurance activities test whether those expectations are met in practice. Treating the publication of a code as equivalent to a functioning program conflates control design with operating effectiveness. A code is generally one component within a larger governance and compliance framework, not a substitute for it.
Who within the organization should own a supplier code of conduct?
Ownership typically sits with management rather than the board, though allocation varies by organization. Procurement, compliance, legal, or a dedicated third-party risk function commonly leads drafting, implementation, and monitoring, often with cross-functional input. The board or a relevant committee generally exercises oversight of the associated risks rather than operational responsibility for the code itself. Clarifying which function is accountable for maintenance, which performs monitoring, and where independent assurance sits helps preserve the distinction between the lines of defense. The appropriate structure depends on the organization's size, sector, and risk profile.
How can an organization encourage or verify that suppliers actually adhere to the code?
Common approaches include incorporating the code by reference into contracts, requiring supplier acknowledgment or attestation, conducting risk-based due diligence, using self-assessment questionnaires, and, for higher-risk relationships, performing audits or requesting independent certifications. Mechanisms for raising concerns, such as reporting channels, may also support adherence. The intensity of verification is generally calibrated to the assessed risk of each supplier rather than applied uniformly. No single technique guarantees compliance; effectiveness depends on how consistently these measures are designed and operated, and organizations typically apply their own judgment to proportionality.
Should the same supplier code apply to every supplier regardless of size or risk?
Organizations often apply a common set of baseline expectations while tailoring the depth of due diligence, contractual controls, and monitoring to the risk each supplier presents. Factors that may inform this risk-based approach include the nature of goods or services, geographic and sector exposure, spend, and access to sensitive data or people. A uniform document can promote consistency, but treating all suppliers identically in terms of verification effort may misallocate resources. The appropriate degree of differentiation depends on the organization's risk appetite and the facts of its supply base.
How often should a supplier code of conduct be reviewed or updated?
Codes are generally reviewed periodically and when circumstances change, such as shifts in applicable law, regulatory expectations, the organization's risk profile, or its supply base. Many organizations align reviews with broader policy governance cycles and assign clear responsibility for keeping the document current. There is no single universally mandated frequency; the appropriate cadence depends on the organization's sector, jurisdiction, and internal governance practices. Updates may also prompt re-communication to suppliers and, where relevant, refreshed acknowledgments. This is a general practice observation, not a legal or audit requirement.

Common misconceptions

A supplier code of conduct is itself legally binding on suppliers.
A code is typically a statement of the entity's expectations. It generally becomes enforceable against a supplier only to the extent it is incorporated into a contract or other binding instrument. Whether and how it binds depends on the facts and applicable law in the relevant jurisdiction.
Publishing a code and obtaining supplier sign-off means the supply chain is compliant.
A signed code addresses control design and stated commitment, not operating effectiveness. Confirming that suppliers actually meet the standards typically requires monitoring, verification, or assurance activity, and even then coverage may be limited to certain tiers or samples.
The supplier code of conduct is owned and managed by the board.
Drafting, deploying, and monitoring a supplier code are generally management responsibilities, often shared among compliance, procurement, and related functions. The board or a committee typically exercises oversight of the program rather than performing the operational activity.

Best practices

Incorporate the code into contracts where enforceability matters, rather than relying on a standalone published document, and confirm with legal counsel how it operates under applicable law and jurisdiction.
Clearly define scope, including whether obligations extend to subcontractors and lower-tier suppliers, so expectations and any assurance activity are not assumed to reach further than the terms actually provide.
Assign clear ownership across procurement, compliance, and related functions for drafting, communication, and monitoring, while positioning the board or relevant committee for oversight rather than execution.
Distinguish between obtaining supplier commitment (control design) and verifying adherence (operating effectiveness), and build proportionate monitoring, audit rights, or assurance activities accordingly.
Align the code's provisions with the applicable legal requirements of the jurisdictions and sectors in which suppliers operate, and update it as those requirements change.
Establish accessible reporting or grievance channels and a defined remediation process, so non-compliance can be identified and addressed rather than only penalized after the fact.