---
id: KB-NO-008
url: https://app.codecontract.io/help/regulation/auditing-your-own-suppliers
idioma: en
categoria: normativa
subcategoria: cadena
audiencia: usuario
nivel: avanzado
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-NO-004, KB-NO-005]
citadoPor: [KB-IC-015, KB-NO-021]
---

# Auditing your own suppliers

_When the demand reaching you has to be passed upstream._

**Responde a:** audit my suppliers · supplier sustainability questionnaire · how do i require from my supplier what is required of me · second-party audit

The moment comes when the demand you receive from a customer has to be passed to your suppliers. And there you discover what your customer already knew: asking is easy, getting it delivered is not.

## The three levels of demand, and what each costs

| Level | What you ask | What response you get |
| --- | --- | --- |
| Declaration | That they sign they comply | High. Almost everyone signs |
| Evidence | That they prove it with documents | Medium. The organised ones do |
| Audit | Going to see it | Low, and expensive. Only for critical ones |

> [!IMPORTANT]
> Start at level one with everyone and escalate only with those who matter. Demanding level three from two hundred suppliers is not rigour: it is an expensive way of achieving nothing, because you cannot audit two hundred and they know it.

## How to decide who escalates

**En corto**

- By what is at stake with that supplier, not by their size.
- By whether their failure shows immediately or takes months to surface.
- And by whether you have an alternative, which changes the whole conversation.

> [!WARNING]
> A supplier who signs a declaration and does not comply leaves you worse off than one who honestly says they cannot: with the signed declaration you accepted something you never checked, and that is on record.

## What makes them respond

The same as any request: ask for little and specific, with the full name of what you want, a real deadline, and a reason that matters to them. "Our customer requires it of us" works better than you would think: most understand because the same happens to them.

> [!NOTE]
> Keep the request even if no answer comes. Before your customer, "we asked on X and received nothing" is a very different position from "we did not ask".

**Can I require it contractually?**

On renewals it is standard; check with your adviser.

**What if a critical supplier refuses?**

That is information for a commercial decision, and worth taking expressly.

**Does a third-party audit help?**

It is usually most efficient for critical suppliers, and avoids duplicating effort with their other customers.

## Ejemplos

**A company demands documentary evidence from its 180 suppliers and 40 respond.**

- Keeps the signed declaration for everyone
- Escalates to evidence only with the 20 critical ones

→ Gets 18 of the 20 that matter, instead of 40 scattered among those that do not.

**Suppliers are asked for less than is asked of you.**

- Passes the same list back up the chain

→ The gap stops sitting on your balance sheet.

**Each supplier replies in a different format.**

- Requests specific documents to a single destination

→ What is received can be compared.

**Chasing thirty suppliers occupies a person.**

- Requests and chases automatically

→ That person reviews instead of nagging.

**A client asks about one supplier by name.**

- Checks that supplier's file

→ You answer with a list rather than an enquiry.

**A supplier's documentation expires without warning.**

- Records third-party expiries too

→ The gap closes before the question.
