Reports and quality
Proving compliance without showing the documents
A client wants assurance; your contracts with third parties are not theirs to read.
It happens as soon as you work with someone large: they ask to see your suppliers' documentation. And you cannot show it in full — it carries prices, terms and third-party data that are not yours to share.
The distinction that solves it
What they are asking for is not the document: it is assurance that it exists, is current, and that someone checked it. Those are different things and they can be separated.
| What they ask for | What they actually need | What you hand over |
|---|---|---|
| "Send me the contracts" | To know there is a contract with everyone | How many, how many current, since when |
| "I want to see the insurance" | To know cover exists and has not lapsed | Status and expiry date, not the policy |
| "Show me the certificates" | To know they are up to date | The certificate yes; what surrounds it, no |
| "I need to audit" | To check the control exists | The check history, with dates |
Important
The fourth row is the most valuable and the least used. The record that a check **happened**, with a date and a name, usually satisfies an auditor better than the document itself — because it proves the process, not one isolated case.
How to prepare it
- 1
Produce the status, not the files
How many current, how many pending, how many expired.
- 2
Add the date of the last check
That is what turns a list into evidence.
- 3
Show one complete example, with permission
Just one, from a supplier who agrees, so they see the rigour.
- 4
And state in writing what you do not share and why
"Third-party data" is a reason people understand, and it closes the conversation.
Watch out
Do not do the opposite: set up a shared folder with everything in it "so they see we hide nothing". That turns a trust problem into a data protection one, and that one has consequences.
When they still insist
If the client demands the full documents, ask the affected suppliers one by one. Some will agree. Those who refuse have given you exactly the answer you need to justify it.
Worth knowing
A sealed document allows something more: a third party can verify that the file you are showing is exactly the one that existed on the date you claim, without taking your word for it.
›Does it count as formal evidence?
For most client audits, yes. For a certification, it depends on the standard.
›Can I give limited access instead of files?
Yes, and it is usually better: they see theirs and nothing else.
›What if the client demands we keep their data?
That is a different matter and belongs in the contract, not the report.
A real case
The situation
An industrial client demands to see the contracts with all thirty subcontractors.
What you do
- Hands over the documentary status with check dates
- Shows one complete file with that subcontractor's permission
What you get
The client considers the requirement met and no third-party data leaves the organisation.
The situation
A client wants to verify compliance and is sent forty documents containing third-party data.
What you do
- Shows the control record instead of the documents
- Shares only what answers their question
- Records what was shared
What you get
The client verifies what they need without receiving information that was not theirs.
The situation
The whole file is sent for convenience.
What you do
- Selects what matches each point
What you get
Nothing extra is handed over.
The situation
The client asks to see documents containing personal data.
What you do
- Offers the control evidence instead
What you get
You demonstrate without exposing third parties.
The situation
A screenshot is shown and the client does not accept it as proof.
What you do
- Shares with controlled, verifiable access
What you get
The client verifies rather than believes.
The situation
The access granted stays open after the review.
What you do
- Revokes it on completion
What you get
The information does not stay exposed.
This article answers
- prove compliance without handing over contracts
- a client asks to see confidential documents
- certify without exposing supplier data
- compliance evidence without sharing files