Guide · Canadian Regulatory Reporting

Bill S-211 Compliance: What the Act Requires Before May 31

Short answer: Bill S-211 compliance is an annual obligation under Canada's Fighting Against Forced Labour and Child Labour in Supply Chains Act. On or before May 31 each year a covered entity reports to the Minister of Public Safety on the steps it took during its previous financial year to prevent and reduce the risk of forced labour or child labour in the goods it produces or imports, has that report approved and signed by a member of its governing body, and publishes it in a prominent place on its own website. The filing itself is a few weeks of work. Being able to say something true in it about suppliers you have never had to describe in writing before takes the year in front of it.

Why does one Canadian filing land on a desk that is already full?

If you are the person who ends up holding this, the report is rarely the biggest thing on your desk in the spring. Finance is closing the consolidated financial statements, and until those numbers are final nobody can even confirm which of the Act's thresholds the company crossed this year. Procurement is onboarding vendors against production dates that were set before anyone mentioned a statute. HR is being asked for training records that were never built to be quoted in a public document. And Marketing wants to know, reasonably, what is about to be posted on the company website with the company's name on it.

Somewhere inside that same spring, the Act expects a description of your supply chains, the risk inside them, and what you did about it — signed by a named human being who is personally on the hook for whether it is accurate.

I have spent thirty years on both sides of a supply-chain audit, and I have yet to meet a compliance lead who was given a clear year to prepare for this one. What arrives instead is a real statutory obligation landing on a desk with no instrument on it. The Act asks what is inside your supply chain. What most companies can produce is a list of who invoices them, and the distance between those two things is the entire job.

Which companies does Bill S-211 actually apply to?

The Act reaches an entity that is listed on a Canadian stock exchange, or that has a place of business in Canada, does business in Canada, or has assets in Canada and meets at least two of three thresholds — based on its consolidated financial statements, for at least one of its two most recent financial years:

at least $20 million in assets
at least $40 million in revenue
an average of at least 250 employees

Government institutions report under their own separate guidance. Sitting under the thresholds is a smaller comfort than it looks, because the obligation travels down the chain in the ordinary course of business. A customer who has to describe its supply chains has to describe the suppliers inside them, which means somebody is going to send you a document request with a date on it. I have watched mid-sized manufacturers discover their S-211 exposure not from their lawyer but from a customer's procurement team, in an email, in March.

And S-211 is not the only Canadian pressure on the same goods. Since July 1, 2020, tariff item No. 9897.00.00 of the Customs Tariff has prohibited goods mined, manufactured or produced wholly or in part by forced labour from entering Canada, and the Canada Border Services Agency detains suspect shipments at the border under it. One of those obligations produces a document and the other one holds a container, and both of them are asking about the same supply chain.

What does the Act actually require the report to contain?

Subsection 11(3) sets out seven things the report has to cover, and Public Safety Canada's guidance for entities restates them in the same order:

the entity's structure, activities and supply chains
its policies and due diligence processes on forced and child labour
the parts of its activities and supply chains that carry a risk, and the steps taken to assess and manage that risk
any measures taken to remediate forced or child labour found
any measures taken to remediate the loss of income to the most vulnerable families caused by eliminating it
the training given to employees on forced and child labour
how the entity assesses its own effectiveness at preventing and reducing the risk

There are mechanics under that which catch people out the first year. The PDF report and the online questionnaire are two separate submissions and Public Safety Canada requires both — the questionnaire is not an alternative to the report. The report is filed in one of Canada's two official languages, in PDF, and there is a file-size ceiling on the upload. It carries an attestation from a member of the governing body confirming they have the legal authority to bind the entity and that the information is true, accurate and complete in all material respects. Once it is filed it goes on your own website in a prominent place, and a federally incorporated entity also provides it to shareholders with its annual financial statements. If you want the clause-level walkthrough of the report itself, we keep that in what a Bill S-211 report must contain.

Read that list again with an operations eye rather than a legal one. Six of the seven items can only be answered out of evidence somebody collected from a supplier during the year. By the time drafting starts in the spring, the report has become a transcription job, and everything it can honestly say was already decided months earlier.

What does due diligence mean when nobody can name the supplier behind the supplier?

The Act names an outcome and leaves the method entirely open, which sounds like relief until you try to write the first item honestly. Describing your structure, activities and supply chains means naming who is genuinely in the chain, and a purchasing system is built to record the party that sends the invoice, not the party that touched the goods.

I sat with a company once that had bought the same component from the same named manufacturer since before anyone in that room had been hired. Mapped properly, the manufacturer turned out to be a trading house with three producers behind it across two countries, one of which had changed ownership twice without a word to anyone downstream. Nothing about that was carelessness. Nobody there had ever been asked to look, and no system the company owned would have shown them if they had. But it is that kind of finding, or its absence, that has to go into a public document under a named person's signature — and the version most companies file instead, a paragraph about supplier codes of conduct with a policy link under it, is sitting on the open web beside every competitor's, where a customer's legal team can read all of them in one afternoon.

Due diligence that holds up under reading is made of specifics: the supplier list mapped past tier one to whoever actually produces and packs the goods; company registration checked against a public registry instead of copied off a form; the supplier's own answers checked rather than filed; a written record of what came back, who owned it and what was done; and a supplier who declines to answer logged as a refusal with the response plan attached, instead of leaving a blank cell that reads as an answer. Where the evidence is genuinely thin, the report says so and names what is being done about it, because an acknowledged gap with an owner and a date is far easier to defend in public than a silence in the same place.

The instrument we run for that is the Master 5-Step Risk Assessment: mapping cargo flow and identifying business partners, conducting a threat assessment, conducting a vulnerability assessment, preparing an action plan, and documenting the risk assessment process. Bill S-211 is Canadian statute and adopts no other country's program by reference, so nothing outside the Act satisfies it automatically. What is true is that those five steps produce exactly the evidence S-211 asks you to describe, and the same evidence supports a supply chain security accreditation. One assessment, kept current, feeds both filings, and running them as two separate exercises tends to produce two files that disagree with each other in ways somebody outside the company eventually notices.

Who gets asked when the attestation was signed and the evidence was not there?

I have sat in the meeting where a signature gets asked for. It is a short meeting. Someone puts the draft in front of a director or an officer, and that person asks one question before they sign: what is this based on?

The Act makes that question personal rather than corporate. Under section 19, failing to comply with the reporting or publication obligations is an offence punishable on summary conviction with a fine of not more than $250,000, and knowingly making a false or misleading statement to the Minister carries the same maximum. Under section 20, a director, officer, agent or mandatary who directed, authorized, assented to, acquiesced in or participated in the offence is a party to it and personally liable to the same punishment — whether or not the entity itself has been prosecuted or convicted. The attestation is how this statute reaches a person instead of a balance sheet.

The compliance lead is rarely the one signing. They are the one who has to answer that question out loud, in front of the people who will carry the liability for the answer, in the week before a date that has never once moved. I have watched that answer come apart in real time — not through anyone's carelessness, but because the file underneath it had been assembled out of what suppliers said about themselves and there had never been a point in the year where somebody went back and checked any of it. When the trail does exist — who was verified, on what date, against which source, and what was done about what came back — the question gets answered in one sentence and the room moves on to the next item.

What fits into the year you are already having?

What this actually asks for is a sequencing change more than a resourcing one. If the supplier evidence accumulates through the year, April turns into a drafting month instead of an excavation. In practice that means the supplier map maintained past tier one as an ordinary part of onboarding; verification attached to the supplier record rather than living in somebody's inbox; refusals and gaps logged somewhere they can be counted; training records kept in a form you would be willing to quote in public; and the May 31 date visible to a named owner in October rather than discovered in March. When I run this with a client, supplier outreach starts a full quarter before the filing, because a supplier with no deadline of their own will use every week you give them.

XFACTOR VERIFIEDis the layer that builds that supplier evidence file: the mapping, the verification, the assessment against the supplier's real exposure, and the documented action plan that comes out of it, per supplier. XFACTOR COMMANDCENTERis the room that file lives in and the place the compliance calendar and posture are held — the May 31 date, the renewal dates on certificates that expire quietly, and one supplier record every program reads from, so the S-211 description and a security profile are drawn from the same evidence instead of two folders that drift apart. If your search today is “what does the Act require of us,” VERIFIED is where the answer gets built. If it is “we have four programs asking about the same suppliers,” that is CommandCenter.

That standard is also the one I hold my own name to. A 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. I was never someone who gave the bare minimum to my clients, and the same instinct applies to a public filing: the version that survives being read by a customer, a regulator and a journalist is the one built on evidence somebody actually checked.

Free guide

Free guide: How to Evaluate Supplier Risk

The evidence this article describes, in plain English — what to check before you approve a supplier, and what a due diligence file has to hold when someone reads it. We'll email you the link.

We’ll email it to you. No spam, no list-selling. Unsubscribe anytime.


The program this maps to: Bill S-211 · The departments this maps to: Procurement · HR · Related reading: What a Bill S-211 report must contain · Forced labour due diligence · UFLPA compliance in Canada · Answering a customer’s supplier disclosure request · Supplier due diligence · Supply chain risk assessment