---
id: KB-IC-015
url: https://app.codecontract.io/help/reports-and-quality/when-your-client-wants-to-audit-your-supplier
idioma: en
categoria: informes-y-calidad
subcategoria: calidad
audiencia: usuario
nivel: avanzado
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-IC-010, KB-NO-008, KB-CR-019]
citadoPor: [KB-IC-019]
---

# When your client wants to audit your supplier

_Three parties, two contracts and an awkward question: how far your duty to disclose reaches._

**Responde a:** my client wants to audit my supplier · second-tier supply chain audit · they ask for data about my subcontractors · how far must i disclose my chain

It happens more and more: a large client is not content auditing you, they want to see who supplies you too. The request is legitimate and the answer is not automatic, because your supplier has no contract with your client — they have one with you.

## The three ways to respond

| Way | What it involves | When it fits |
| --- | --- | --- |
| You answer on their behalf | You show your control over that supplier, not their documents | Most cases |
| The supplier answers directly | With their consent, and knowing what is being asked | When the client demands traceability to origin |
| On-site audit by the client | Requires all three parties to agree | Regulated sectors or large contracts |

> [!IMPORTANT]
> The first usually settles it and is the least attempted. What your client needs to know is not what your supplier's certificate says: it is that **you request it, check it and act when it is missing**. You can evidence that from your own record without showing a single third-party document.

## What to agree before it is asked

1. **What you may share about your suppliers** — Ideally agreed in your contract with them, not improvised under pressure.
2. **What your client requires contractually** — Sometimes the obligation to give chain access is already signed and nobody has read it.
3. **Who talks to whom** — Letting your client contact your supplier directly without you brings commercial problems that are not worth it.
4. **And what happens if the supplier refuses** — It is a real possibility and it helps to have decided whether that forces a change of supplier.

> [!WARNING]
> The risk almost nobody sees coming is commercial, not documentary: if you put your client in direct contact with your supplier, you have introduced them. In sectors where the intermediary supplies the relationship rather than the product, that has cost entire accounts. Not a reason to refuse, but a reason to decide it deliberately rather than in a hurried email.

## What can be shown without exposing anyone

**En corto**

- How many suppliers you have in that category and how many are current.
- What you require from them and how often you renew it.
- When the last check happened and who did it.
- And what you do when one fails, with a real anonymised case.

That last point convinces more than any list: showing that last year you blocked a supplier over expired documentation proves the control genuinely exists. A percentage does not prove that.

> [!NOTE]
> Certification schemes and supply-chain requirements vary widely by sector and by client, and they change. **What you are obliged to provide and what you are not is a conversation for your adviser and your contract**, not something to infer from the client's request — which will always ask for the maximum.

**Can I refuse?**

It depends what you signed. If it is not in the contract, it is negotiable.

**What if my supplier does not want to?**

That is useful information: a supplier who cannot evidence what you require is also your risk.

**Is showing my supplier's certificate enough?**

It helps, but it only proves that document. What defends you is the ongoing control.

## Ejemplos

**A large client demands to audit the subcontractor making a component.**

- Shows its own control over that subcontractor with check dates
- Agrees with the supplier what may be shared before replying

→ The client considers the requirement met with no direct contact between the two companies.

**A client announces they want to audit your transport supplier and nobody knows what can be shown.**

- Checks what you agreed with that supplier about third-party audits
- Warns the supplier before the request reaches them
- Shares only what concerns that client

→ The audit is arranged without damaging the supplier relationship or over-disclosing.

**The client asks to audit and the supplier contract does not provide for it.**

- Negotiates it with the supplier before committing them
- Writes the outcome down for future contracts

→ The commitment to the client is realistic and the supplier is not ambushed.

**Supplier documentation is handed over containing their other clients' data.**

- Reviews the content before sharing

→ Nothing is leaked that was not yours to give.

**Three clients want to audit the same supplier.**

- Gathers what is asked and negotiates a single audit

→ The supplier receives one visit, not three.

**The audit finds something and nobody knows who answers.**

- Writes down beforehand who owns which finding

→ The action plan has an owner from day one.

**The audit happens and there is no record of what was shown.**

- Records the bundle handed over, with its date

→ The handover is demonstrable afterwards.

**The supplier refuses and the client reads it as opacity.**

- Offers the control evidence instead of the document

→ The client verifies without the supplier exposing what they should not.
