Skip to main content
Category: Third-Party and Supply Chain

Supply Chain Due Diligence

Also known as: SCDD, Supplier Due Diligence, Due Diligence for Responsible Business Conduct
Simply put

Supply chain due diligence is a process a company uses to research and evaluate its suppliers and wider business relationships to identify risks and potential negative impacts before and during those relationships. It generally aims to help the company find, prevent, and address problems connected to its operations and supply chain, including harms it may be linked to directly or indirectly. The specific scope and any legal obligations vary by jurisdiction, sector, and the type of entity involved.

Formal definition

Supply chain due diligence refers to a systematic, ongoing process through which an organization identifies, prevents, mitigates, and accounts for actual and potential adverse impacts across its operations, supply chains, and business relationships, including impacts to which it may be connected directly or indirectly. In practice it typically includes verifying and evaluating suppliers before onboarding and reassessing them throughout the relationship as part of a broader risk management approach. Whether such diligence is a binding legal requirement or a voluntary standard, and the precise obligations it entails, depends on the applicable jurisdiction, regulatory regime, sector, and entity type; this entry is educational and not legal, audit, or compliance advice.

Why it matters

Supply chain due diligence has become a focal point for compliance and risk functions because an organization's exposure to legal, financial, and reputational harm often originates not within its own operations but in the operations of its suppliers and wider business relationships. Adverse impacts to which a company may be connected directly or indirectly, for example through its supply chain, can create obligations, liabilities, or reputational damage even where the company did not itself cause the harm. Structured due diligence helps an organization identify these potential and actual negative impacts before entering a relationship and reassess them as the relationship continues.

The practical significance of the process depends heavily on context. In some jurisdictions and sectors, elements of supply chain due diligence are binding legal requirements, while in others they operate as voluntary standards or expectations of responsible business conduct, such as the framework reflected in the OECD's due diligence guidance. Because obligations vary by jurisdiction, regulatory regime, sector, and entity type, a program that is adequate for one organization may fall short for another. Understanding which requirements are legally mandatory and which are voluntary best practice is essential to scoping the effort appropriately.

Without a systematic and ongoing approach, an organization may onboard suppliers whose risks are only discovered after a problem materializes, at which point remediation is more costly and the company's ability to demonstrate that it took reasonable steps is weaker. This entry is educational and not legal, audit, or compliance advice; whether and how supply chain due diligence applies to a given organization is a fact-specific and jurisdiction-specific question that calls for professional judgment.

Who it's relevant to

Chief Compliance Officers and Compliance Teams
Compliance functions typically design and operate supplier verification and evaluation processes, determine which requirements are binding versus voluntary for the organization, and maintain records demonstrating that due diligence was performed before and during supplier relationships. They generally own the day-to-day execution and monitoring of the program, with scope calibrated to applicable jurisdiction, sector, and entity type.
Chief Risk Officers and Risk Functions
Risk functions generally integrate supply chain due diligence into the organization's broader risk management approach, helping to identify and assess potential and actual adverse impacts arising from suppliers and business relationships. Their focus is typically on ensuring that supplier-related risks, including those to which the organization may be linked indirectly, are captured, evaluated, and addressed alongside other enterprise risks.
General Counsel and Legal Advisers
Legal advisers are typically relied upon to determine whether supply chain due diligence is a binding legal requirement in a given jurisdiction and sector, or a voluntary standard of responsible business conduct, and to define the resulting obligations. Because these questions are fact-specific and jurisdiction-specific, legal input generally shapes how the process is scoped and documented.
Procurement and Supplier Management
Procurement and supplier management teams generally carry out the front-line steps of verifying and evaluating suppliers before onboarding and reassessing them over the course of the relationship. They typically translate due diligence findings into onboarding decisions, contractual arrangements, and ongoing supplier oversight.
Boards and Board Committees
Boards and relevant committees generally exercise oversight of whether management has established a due diligence process appropriate to the organization's risk profile and applicable requirements. Their role is typically one of oversight and challenge rather than operational execution, which usually sits with management and assurance functions.
Internal Auditors and Assurance Functions
Internal audit and other assurance functions may provide independent evaluation of whether the supply chain due diligence process is designed appropriately and operating effectively over time. This assurance role is generally distinct from the ownership and execution of the process, which typically resides with compliance, risk, and procurement.

Inside SCDD

Risk Identification and Mapping
The process of identifying suppliers, sub-suppliers, and business relationships across the value chain and assessing where adverse impacts, such as human rights violations, environmental harm, or corruption, are most likely to arise. Depth of mapping typically depends on the entity's size, sector, and leverage over counterparties.
Legal Requirement Versus Voluntary Standard
In certain jurisdictions, supply chain due diligence obligations are binding law applicable to entities meeting specified thresholds, while in others they remain voluntary expectations drawn from codes or international guidance. Whether a given obligation is mandatory depends on jurisdiction, sector, entity size, and the nature of the goods or services involved.
Ongoing Monitoring and Assessment
Due diligence is generally treated as a continuous process rather than a one-time exercise, involving periodic reassessment of suppliers, verification activities, and updates as relationships and risk profiles change. This is typically an operational responsibility of management and compliance functions.
Contractual and Remediation Mechanisms
Provisions embedded in supplier contracts, such as codes of conduct, audit rights, and expectations for corrective action, together with processes to address, mitigate, or remediate identified harms where the entity has caused or contributed to an impact.
Governance, Accountability, and Reporting
The allocation of responsibility for the due diligence program, including management ownership of operational execution and board or committee oversight of the overall approach. Some regimes require public disclosure or reporting on due diligence measures, though the scope and format vary by jurisdiction and framework.

Common questions

Answers to the questions practitioners most commonly ask about SCDD.

Is supply chain due diligence just a procurement or purchasing function?
No. While procurement often executes supplier onboarding and contracting steps, supply chain due diligence is a cross-functional discipline that typically draws on compliance, legal, risk, and sometimes ESG or human rights functions. Procurement generally owns operational relationships with suppliers, but accountability for the overall program design, risk assessment methodology, and escalation of serious findings usually sits with compliance or risk leadership, with board or committee oversight where the exposure is material. Treating it as a purely procurement task can leave gaps in independent assurance and in the governance reporting lines that many frameworks and, in some jurisdictions, specific statutes expect.
Does completing due diligence once at onboarding satisfy the obligation?
Generally not. Under most frameworks and the mandatory due diligence regimes that exist in certain jurisdictions, due diligence is typically framed as an ongoing, risk-based process rather than a one-time gate. Supplier circumstances, ownership, sanctions status, and conduct can change, and lower-tier suppliers may only surface over time. Many programs therefore combine initial screening with periodic reassessment, event-driven reviews, and monitoring. The appropriate frequency and depth depend on the assessed risk, the jurisdiction, the sector, and the specific legal or contractual requirements that apply to the entity.
How should an organization decide how deep into the supply chain to look?
Depth is typically determined by a risk-based approach rather than an attempt to map every tier equally. Many programs prioritize by factors such as country, sector, commodity, spend, and the nature of the risk in scope (for example, sanctions, bribery, forced labor, or data security). Some legal regimes in certain jurisdictions set expectations that extend beyond direct suppliers where risks are known or reasonably foreseeable, but the precise reach depends on the applicable law and the facts. Organizations generally document their prioritization rationale so that the scope of review is defensible and consistent with their stated risk appetite. This is a matter for professional judgment against the specific obligations that apply.
What is the difference between control design and operating effectiveness in a supply chain due diligence program?
Control design concerns whether the program's controls, such as screening criteria, contractual clauses, escalation thresholds, and reassessment triggers, are capable in principle of addressing the identified risks. Operating effectiveness concerns whether those controls actually function as intended over time, for example whether screenings are performed, findings are escalated, and remediation is tracked to closure. A program can be well designed on paper yet operate ineffectively in practice. Assurance functions typically test both dimensions separately, and conflating them can create a false sense of coverage.
How should due diligence findings be escalated and who is accountable?
Escalation paths generally reflect the separation between management and oversight. Day-to-day identification and remediation of supplier issues typically sit with management, often within procurement supported by compliance. Serious findings, such as potential sanctions exposure, credible allegations of forced labor, or significant integrity concerns, are usually escalated according to predefined thresholds to senior management and, where material, to the relevant board committee. The board or committee generally holds an oversight duty rather than an operational one; it monitors whether the program is functioning rather than performing the due diligence itself. Clear, documented thresholds help avoid ambiguity about when and to whom an issue moves.
How does supply chain due diligence relate to the organization's broader enterprise risk management and three-lines model?
Supply chain due diligence typically operates as one input into enterprise risk management rather than a standalone silo. In a three-lines structure, first-line functions such as procurement and operations own and manage supplier risk within their processes; second-line compliance and risk functions set the methodology, provide oversight, and challenge; and internal audit, as the third line, provides independent assurance over whether the program is designed and operating effectively. Mapping supply chain risks into the enterprise risk register helps ensure they are assessed for likelihood and impact alongside other risks and considered against the organization's stated risk appetite and tolerance. The specific allocation of roles depends on the entity's size, structure, and governance model.

Common misconceptions

Supply chain due diligence is a universal legal mandate that applies to all companies in the same way.
Whether due diligence is a binding legal requirement or a voluntary best practice depends heavily on jurisdiction, sector, entity type, and applicable thresholds. In some jurisdictions it is embedded in statute for qualifying entities; in others it derives only from non-binding codes or international guidance. Practitioners should confirm which obligations actually apply to their entity.
Completing a supplier questionnaire or one-time audit satisfies due diligence obligations.
Due diligence is generally understood as an ongoing, risk-based process rather than a discrete checkbox. It typically requires continuous monitoring, reassessment as circumstances change, and follow-up on identified risks, not simply a single point-in-time assessment.
The board is responsible for carrying out supply chain due diligence.
Operational execution of due diligence, supplier assessment, monitoring, and remediation, typically sits with management and relevant compliance or procurement functions. The board or its committees generally provide oversight of the program and its adequacy, rather than performing the day-to-day activities.

Best practices

Confirm which due diligence obligations are legally binding for your specific entity given its jurisdiction, sector, size, and applicable thresholds, and distinguish those from voluntary standards you choose to adopt.
Adopt a risk-based approach that prioritizes suppliers and relationships where the likelihood and severity of adverse impacts are greatest, rather than applying uniform scrutiny across the entire supply base.
Treat due diligence as a continuous cycle, embedding periodic reassessment, monitoring, and updates as supplier relationships and risk profiles evolve.
Embed clear expectations, audit rights, and remediation pathways into supplier contracts and codes of conduct so that identified issues can be addressed and corrective action tracked.
Clarify the allocation of roles so that management owns operational execution while the board or a designated committee oversees the adequacy of the program, and document this accountability.
Maintain records of due diligence activities and, where reporting is required or adopted voluntarily, ensure disclosures accurately reflect the measures actually taken without overstating their scope.