---
id: KB-IC-010
url: https://app.codecontract.io/help/reports-and-quality/proving-compliance-without-showing-the-documents
idioma: en
categoria: informes-y-calidad
subcategoria: calidad
audiencia: usuario
nivel: avanzado
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-IC-003, KB-IC-007]
citadoPor: [KB-LE-008, KB-AD-011, KB-NO-014, KB-IC-015]
---

# Proving compliance without showing the documents

_A client wants assurance; your contracts with third parties are not theirs to read._

**Responde a:** prove compliance without handing over contracts · a client asks to see confidential documents · certify without exposing supplier data · compliance evidence without sharing files

It happens as soon as you work with someone large: they ask to see your suppliers' documentation. And you cannot show it in full — it carries prices, terms and third-party data that are not yours to share.

## The distinction that solves it

What they are asking for is not the document: it is assurance that it exists, is current, and that someone checked it. Those are different things and they can be separated.

| What they ask for | What they actually need | What you hand over |
| --- | --- | --- |
| "Send me the contracts" | To know there is a contract with everyone | How many, how many current, since when |
| "I want to see the insurance" | To know cover exists and has not lapsed | Status and expiry date, not the policy |
| "Show me the certificates" | To know they are up to date | The certificate yes; what surrounds it, no |
| "I need to audit" | To check the control exists | The check history, with dates |

> [!IMPORTANT]
> The fourth row is the most valuable and the least used. The record that a check **happened**, with a date and a name, usually satisfies an auditor better than the document itself — because it proves the process, not one isolated case.

## How to prepare it

1. **Produce the status, not the files** — How many current, how many pending, how many expired.
2. **Add the date of the last check** — That is what turns a list into evidence.
3. **Show one complete example, with permission** — Just one, from a supplier who agrees, so they see the rigour.
4. **And state in writing what you do not share and why** — "Third-party data" is a reason people understand, and it closes the conversation.

> [!WARNING]
> Do not do the opposite: set up a shared folder with everything in it "so they see we hide nothing". That turns a trust problem into a data protection one, and that one has consequences.

## When they still insist

If the client demands the full documents, ask the affected suppliers one by one. Some will agree. Those who refuse have given you exactly the answer you need to justify it.

> [!NOTE]
> A sealed document allows something more: a third party can verify that the file you are showing is exactly the one that existed on the date you claim, without taking your word for it.

**Does it count as formal evidence?**

For most client audits, yes. For a certification, it depends on the standard.

**Can I give limited access instead of files?**

Yes, and it is usually better: they see theirs and nothing else.

**What if the client demands we keep their data?**

That is a different matter and belongs in the contract, not the report.

## Ejemplos

**An industrial client demands to see the contracts with all thirty subcontractors.**

- Hands over the documentary status with check dates
- Shows one complete file with that subcontractor's permission

→ The client considers the requirement met and no third-party data leaves the organisation.

**A client wants to verify compliance and is sent forty documents containing third-party data.**

- Shows the control record instead of the documents
- Shares only what answers their question
- Records what was shared

→ The client verifies what they need without receiving information that was not theirs.

**The whole file is sent for convenience.**

- Selects what matches each point

→ Nothing extra is handed over.

**The client asks to see documents containing personal data.**

- Offers the control evidence instead

→ You demonstrate without exposing third parties.

**A screenshot is shown and the client does not accept it as proof.**

- Shares with controlled, verifiable access

→ The client verifies rather than believes.

**The access granted stays open after the review.**

- Revokes it on completion

→ The information does not stay exposed.
