Guide · For the Supplier Being Asked
Bill S-211 Supplier Due Diligence: Answering a Customer’s Tier 2 and Tier 3 Request
Short answer: Bill S-211does not require you to disclose your tier 2 and tier 3 suppliers. The word “tier” appears nowhere in the Act, the Act never defines “supply chain,” and it prescribes no method for mapping one. What it requires is that your customer describe its supply chains, the parts of them that carry a risk of forced or child labour, and what it did about that risk — publicly, on or before May 31, under a signature. Asking you for the producers behind you is how that customer chose to be able to write something true. Bill S-211 supplier due diligence, from your side of the request, is the work of answering with evidence rather than a paragraph, and the first time you do it, it is not a two-week job.
The request lands in a week that already has no room in it
The email comes through Sales, because Sales owns the relationship and the request came from the customer’s procurement team. It has a two-week date on it and a spreadsheet attached. Meanwhile the moulding line changes over Thursday and Production needs the confirmation you have been chasing since last week. Purchasing is holding two POs until Finance releases the spend, and Finance is closing the month. Quality is working a customer complaint that came in Friday afternoon and has its own clock. And the account that sent the spreadsheet is a large enough share of your revenue that nobody in the building is going to say the word no out loud.
The spreadsheet asks who makes the components you buy, where those components are physically made, and whether anyone in that chain uses recruitment agencies. Your ERP can tell you, in about four seconds, who invoices you. Everything past that is going to come out of phone calls.
I have been on both ends of that letter — I have written them for clients, and I have sat on the receiving side while one was handed around a table. The honest answer to “who actually makes the sub-component” was three people looking at each other. What the room wanted to do was write something reassuring and get back to Thursday’s changeover. That instinct has never once struck me as carelessness. It is what people do when they are asked a question nobody ever built them a way to answer.
Does Bill S-211 actually oblige you to hand over your sub-suppliers?
It does not, and knowing precisely why changes how you answer. The obligation in the Fighting Against Forced Labour and Child Labour in Supply Chains Actruns to the reporting entity. Read the Act end to end and the word “tier” is not in it. Neither is a definition of “supply chain.” Neither is a prescribed method. Subsection 11(3) names what has to be described and leaves entirely open how the entity gets there.
So the tier 2 and tier 3 framing in your customer’s spreadsheet is their methodology, not a clause. That matters twice. It means the form of the request is negotiable — you can propose a better instrument than their template and reporting entities accept better instruments regularly. It also means the substance is not negotiable at all, because their lawyer has told them, correctly, that describing a supply chain they cannot see is how a public report becomes a false statement.
Being under the thresholds yourself changes nothing about this. An entity reports if it is listed on a Canadian stock exchange, or if it has a place of business in Canada, does business in Canada or has assets in Canada and meets at least two of three tests on its consolidated financial statements for at least one of its two most recent financial years:
at least $20 million in assets
at least $40 million in revenue
an average of at least 250 employees
Those tests decide which companies have to file. They have never had anything to do with which companies get asked. If you sit in the chain of a company that files, you are inside its report whether or not you have ever read the statute.
What is your customer obligated to write, and where does your answer land in it?
Subsection 11(3) sets out seven things the report has to cover, and Public Safety Canada’s guidance for entities restates them in the same order:
its structure, activities and supply chains
its policies and due diligence processes on forced and child labour
the parts of its business and supply chains that carry a risk, and the steps taken to assess and manage that risk
any measures taken to remediate forced or child labour
any measures taken to remediate the loss of income to the most vulnerable families
the training provided to employees on forced and child labour
how the entity assesses its own effectiveness
Your answer feeds the first, third and fourth of those directly. The report is filed with the Minister of Public Safety on or before May 31, covering the previous financial year. Public Safety Canada requires a PDF report anda completed online questionnaire as two separate submissions. Subsections 11(4) and 11(5) require the report to be approved by the governing body, and that approval to be evidenced by the signature of one or more of its members; the attestation Public Safety Canada asks for alongside it has the signatory confirm they have the authority to bind the entity and that the information is true, accurate and complete in all material respects. Then it goes up in a prominent place on the customer’s own website, where anyone can read it, including your competitors and theirs. The clause-level walkthrough of the report itself sits in what a Bill S-211 report must contain.
Under section 19, failing to comply with the reporting or publication obligations is an offence punishable on summary conviction with a fine of not more than $250,000, and knowingly making a false or misleading statement to the Minister carries the same maximum. Under section 20, a director, officer, agent or mandatary who directed, authorized, assented to, acquiesced in or participated in the offence is a party to it and personally liable, whether or not the entity itself was prosecuted or convicted.
That is why the tone of the request is what it is. Somebody at your customer is going to sign their own name to a sentence that includes you, and they have been told what that signature costs if the sentence is wrong. The pressure you can feel in that email is a director somewhere upstream asking what the sentence is based on.
What belongs in the answer, and what should never go in it
A response that holds up is made of things a third party could check. What follows is what I put in front of a supplier facing this for the first time:
the legal name and registered address of each producer behind the goods you sell that customer — not the trading name on your invoice
the physical sites where those goods are produced, finished and packed
country of origin at the production site, not the port of shipment
any labour recruitment or staffing agencies used at those sites
your own policy on forced and child labour, with how you verify it rather than how you circulate it
what changed during your last financial year — new source, new site, change of ownership
a named person who can answer the follow-up
What should never go in it is a blank. I have watched suppliers leave cells empty because they thought silence was neutral, and it is the opposite of neutral: a reader with a statutory deadline treats an empty cell as an answer, and the answer it reads as is no. Where you do not know something, write that you do not know it, name who owns finding out and give a date. A compliance lead reading fifty of these can tell the difference between a company that has looked and come up short and a company that has not looked, and the first one reads better than anything else on the page.
Confidentiality is a real objection and worth making properly. Your sub-tier list is frequently the only thing stopping a customer from sourcing around you, and no clause in the Act obliges you to publish it. What your customer needs is assurance about risk in the part of the chain you occupy, which is a different object from your commercial vendor list. An independent assessment of your own suppliers — findings, verification dates, sources checked, a documented action plan — gives them the first without handing over the second, and a customer with a filing deadline will usually take it. Refusing without offering anything in its place leaves them to write the sentence anyway, with whatever they have, about you.
The review where your answer gets read back to you
The response goes out and the week moves on. The part nobody schedules is the quarterly business review nine months later, where your customer’s compliance lead has the filed report open and a list of suppliers whose answers did not stand up to a second look. I have sat in that room on the supplier’s side of the table. The question is never hostile and it is never complicated: you told us there were two producers. Our audit found a third. When did you know?
Your account manager is beside you, and the honest answer is that nobody knew, because nobody was ever asked to look and no system anyone owned would have shown it. That answer is completely true and it does not help, because what the room heard was that you put a number in a public filing that was not correct. Nobody threatens the account in that meeting. What happens is quieter and slower: the next RFQ goes to three names instead of one, and the supplier who answered in full the first time is now the one described internally as low risk.
The version of that meeting that goes well turns on a record rather than an argument. Somebody opens the file and shows that the third producer was found in February, by whom, from which registry, and what the supplier committed to by June. I have watched both versions many times, and what separated them was never the calibre of the people sitting in the chain.
Three customers, three questionnaires, the same suppliers
The weight of this is rarely the Act itself. One customer sends you an S-211 disclosure request in March. Another sends a supply chain security questionnaire in June, because they hold an accreditation and their programme requires business-partner screening. A third sends a social compliance audit protocol in September with its own portal and its own login. Three formats, three deadlines, three different people at your company chasing the same information from the same suppliers, who by the third round have started taking longer to reply.
Running every programme in its own silo, and hitting your own suppliers separately for each one, is what quietly destroys the relationships the programmes depend on. A supplier answers the first questionnaire in good faith. By the third they are answering to get you off the phone, and the quality of what comes back drops exactly where you need it to hold. I have watched good supplier relationships wear out that way, over paperwork, without a single genuine dispute between the two companies.
The material underneath all three requests is the same material, for a structural reason: every supply chain security accreditation programme rests on a full five-step risk assessment, and Bill S-211 needs the same evidence to support the report it requires. The instrument is the Master 5-Step Risk Assessment — mapping cargo flow and identifying business partners, conducting a threat assessment, conducting a vulnerability assessment, preparing an action plan, and documenting the risk assessment process. Be careful about how far you take that: Bill S-211 is a Canadian statute that adopts no foreign programme by reference, so no accreditation you hold discharges anything under it. What one assessment does is produce, in a single pass, the underlying evidence all three requests are reaching for. Your own suppliers get asked once. You answer three customers out of the same file.
Building the file before the next request arrives
None of this asks for headcount, and it does not deserve a standing meeting. It asks for the evidence to accumulate on the supplier record through the year instead of being excavated in the two weeks after an email. In practice that means your own supplier map maintained past tier one as an ordinary part of onboarding; company registration checked against a public registry rather than copied off a form; supplier answers verified rather than filed; refusals and gaps logged somewhere they can be counted; and one person who owns the answer before Sales needs it, rather than after.
XFACTOR VERIFIED is the layer that builds that file. It maps your chain past the invoicing party, checks what each supplier told you against a source that is not the supplier, assesses what that particular operation is exposed to, and issues a written action plan per supplier with owners and dates on it. That is the object you send when a customer asks — findings somebody stands behind, rather than a paragraph about your code of conduct. XFACTOR COMMANDCENTERis the room it lives in: one supplier record every programme reads from, with the dates visible before they arrive, so the S-211 answer you give in March and the security profile you complete in June come out of the same evidence rather than two files nobody has compared. If your question today is “what do we send this customer,” VERIFIED is where that answer gets built. If it is “we have three customers asking about the same suppliers,” that is CommandCenter.
One thing worth checking before you buy anything: if the customer asking you for this already runs XFACTOR VERIFIED, your side of it is funded by them. Their suppliers receive a Compliance Passport — in-depth training, scenario assessment, documentation verification and audits, and a recommendation report with an action plan written to your operation, for four months, at no cost to you. Ask them. It is a short email and it is the cheapest version of this you will ever be offered.
I will tell you plainly what I hold my own clients to, because it is the same bar I am describing here. A 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. I was never someone who gave the bare minimum to my clients, and the same instinct applies to a supplier facing a customer with a filing deadline. The one who can answer the question in full tends to be the one that customer is still buying from three years later.
Free guide
Free guide: How to Evaluate Supplier Risk
What to check before you approve a supplier, and what a due diligence file has to hold when a customer reads it. We'll email you the link.
Answer the next request with evidence instead of a paragraph.
See what XFACTOR VERIFIED does for a supplier being assessed, or read what the Bill S-211 program covers.
The program this maps to: Bill S-211 · The departments this maps to: Suppliers · Procurement · Related reading: Bill S-211 compliance: what the Act requires · What a Bill S-211 report must contain · Forced labour due diligence beyond tier 1 · Supplier due diligence · Supply chain risk assessment