Guide · Due Diligence
What Should Supply Chain Due Diligence Software Actually Do?
Short answer: supply chain due diligence software is the system of record for a continuous process, and the process has a settled international shape. The OECD describes it in six stages — embed responsible business conduct into policies and management systems, identify and assess actual and potential adverse impacts, cease, prevent and mitigate those impacts, track implementation and results, communicate how impacts are addressed, and provide for or cooperate in remediation when appropriate. Software deserves the name when it carries all six, each with a date and an owner attached. Most of what is sold under the name carries the second stage well, because sending a questionnaire is the easiest part to automate, and leaves the third, fourth and sixth to somebody's inbox. The question worth asking in a demo has nothing to do with how many fields a record holds. Pick a supplier, pick a day, and see whether the tool can show what you found, what you did about it, when, and who stands behind it.
Two pieces of our own work answer different halves of that. Doing the checking itself — mapping the chain, verifying the evidence, scoring it against real criteria, writing the action plans and driving them to closure — is XFACTOR VERIFIED. Holding every obligation that draws on that same evidence, against one supplier record and one set of dates, is XFACTOR COMMANDCENTER.
Three requests for the same thing, in one week, in three different shapes
Internal Audit has your due diligence process on the walkthrough schedule for the third week of the month. They are not asking for the published report. They want to pick a supplier themselves and watch the control operate on it, using the records that were made at the time rather than the summary written afterwards.
Treasury is assembling the renewal package for the credit facility, and the bank has added a rider this year: the signed attestation, the supplier code of conduct, and a description of how the second one is actually enforced against the first.
And your customs broker phoned about a shipment moving into the United States for a customer in Ohio. The importer of record has been asked for tracing documents on one component, and the question that came back down the line was whether you can produce the chain behind that part, link by link, back to raw material.
Not one of those three people used the phrase due diligence software. All three were asking the same thing of it: what did you find, what did you do about it, and where was that written down at the time. Thirty years of this work has shown me that companies almost never get caught out here for doing nothing. They get caught because the work they did lived in three people's sent folders, one spreadsheet on a laptop that has since been replaced, and the memory of somebody who left in March.
What does due diligence actually consist of, before any software touches it?
It helps to be precise about the thing you are buying a tool for, because the word gets used for two different activities. There is the one-time check you run before you sign a supplier, which most people mean when they say supplier due diligence. And there is the standing obligation to know, and keep knowing, what is happening inside a chain you do not own. Statutes and customers are asking about the second one.
The OECD Due Diligence Guidance for Responsible Business Conduct sets out that second activity as a six-stage cycle, and it is worth reading in the original wording because regulators, customers and auditors have all built their expectations on top of it:
1. Embed responsible business conduct into policies and management systems
2. Identify and assess actual and potential adverse impacts associated with the enterprise's operations, products or services
3. Cease, prevent and mitigate adverse impacts
4. Track implementation and results
5. Communicate how impacts are addressed
6. Provide for or cooperate in remediation when appropriate
Lay a typical platform demo against that list. Stage two is where the money has gone: supplier onboarding, questionnaire distribution, reminders, a risk score, a dashboard with a map on it. Stage five is usually there in the form of a report export. Stage one is a document upload. Stages three, four and six — the correction, the tracking of whether it worked, and the remediation when something real is found — are the stages that generate the evidence anyone will later ask you for, and they are routinely the stages left to email and goodwill.
A system built only around stage two can prove that you asked, which is a real thing to be able to prove and is nowhere near what anybody will eventually want from you. A returned questionnaire is one input to that stage, and the limits of what it establishes are set out in the companion guide on what a security questionnaire actually proves.
Which obligations does one due diligence record have to feed?
The reason to insist on all six stages is not tidiness. It is that several unrelated demands land on the same evidence, and they land at different times of year, from different directions, in different formats.
Canadian statute. The Fighting Against Forced Labour and Child Labour in Supply Chains Act requires a covered entity to report to the Minister on or before May 31 each year. Section 11(3) lists what that report must describe: structure, activities and supply chains; policies and due diligence processes; the parts of the business and supply chains carrying a risk of forced labour or child labour and the steps taken to assess and manage that risk; measures taken to remediate forced labour or child labour; measures taken to remediate the loss of income to the most vulnerable families; training provided to employees; and how the entity assesses its own effectiveness. The full breakdown sits on what a Bill S-211 report must contain.
Read that list as an operating specification rather than a writing task and something becomes obvious. Two of the seven items can be written in May from documents you already have. Five of them describe things that either happened during the year and were recorded, or did not. You cannot compose a truthful sentence about measures taken to remediate in the last week of May. Either there is a finding with a correction attached to it and a date it closed, or there is a paragraph that sounds like one.
US border enforcement, which is a separate regime and a separate question. The Uyghur Forced Labor Prevention Act works on the shipment in front of the officer, not on your annual report. To obtain an exception to its rebuttable presumption an importer must have fully complied with the applicable guidance, responded completely and substantively to all inquiries for information, and demonstrated by clear and convincing evidence that the goods were not mined, produced or manufactured wholly or in part by forced labor. That is a documentary chain for one specific part, produced on a clock, and Canadian exporters get caught by it more often than they expect. A vendor who lets you believe that a Canadian annual report answers an American detention has sold you a gap you will discover at the worst possible hour.
The security programmes, which rest on the same foundation. No security profile submitted under C-TPAT, PIP or AEO stands up without a full five-step risk assessment underneath it, and the executive summary of a Bill S-211 report draws on the same underlying evidence. One assessment can therefore serve all of them rather than four running in parallel, because they rest on the same five steps — mapping cargo flow and identifying business partners, conducting a threat assessment, conducting a vulnerability assessment, preparing an action plan, and documenting the risk assessment process. The signed output that aggregates every supplier is the Master 5-Step Risk Assessment.
A tool that cannot serve those three demands from one record will make you keep three records. I have watched teams do exactly that, and the second and third copies always drift, because only one of them is anybody's day job.
Where does the software stop and the human work start?
This is the part most category pages avoid, so let me be plain about it. The checking itself is human work. Deciding whether a certificate is genuine, whether it covers the goods you actually buy rather than a different line the supplier also runs, whether the facility named on it is the facility your cargo moves through, and whether the practice written in the policy is performed by the people on the floor — none of that is a field in a database. Each of those judgements is unpacked in the guide on what supplier verification software actually verifies, and what happens to them once they become a number is in supplier risk assessment software.
What software is genuinely for is the structure around that judgement, and it is not a lesser job. It holds the map, including the parts of it you were refused, so a gap has a name and an owner instead of being an absence. It puts the question in front of the person who can answer it, at the point in the process where the answer still changes the decision. It captures what was concluded, by whom, on what document, on what date. It drives a finding into a corrective action and holds that action open until something closes it. It re-opens anything with an expiry date without anyone having to remember. And it reproduces the whole trail afterwards without a single person rebuilding it from their own memory.
Any vendor telling you their platform removes the human checking is selling you the one stage it cannot perform, and quietly leaving you the four it could have carried. That is a general problem with the category, and it is worth reading what to require before compliance software goes on a purchase order before anyone signs anything.
The remediation that happened and could not be produced
I sat with a company whose published report described a supplier code of conduct with a remediation commitment written into it. The commitment was real. They had found something at a supplier the previous year, they had gone back at it hard, and the condition had genuinely been fixed. When I asked to see it, the evidence turned out to be a chain of emails in one manager's sent folder, a set of photographs on a phone, and a corrective action plan that existed as a Word document with a filename ending in v4_FINAL_revised.
Nothing about that was dishonest. They had done the work, which is more than a lot of companies with better-looking systems can say. But they could not produce it as a record — not for their customer, not for their auditor, and not in a form anybody could check. One person left and the proof would have gone with them. The finding, the plan, the follow-up and the closure were four separate objects in four separate places, and nothing in their stack knew that the four belonged to each other or to the supplier.
What I was looking at was stage six and stage four of the OECD cycle, performed properly and recorded nowhere, because nobody had ever given them a tool that treats a correction as a tracked state sitting on a supplier record instead of a conversation that happened.
The sentence in the report that someone eventually has to stand behind
Under the Act the report has to be approved by the entity's governing body and signed by a member of it. That signature is not decorative. Section 19(1) makes failure to comply an offence punishable by a fine of not more than $250,000. Section 20 goes further and reaches individuals: a director, officer, agent or mandatary who directed, authorized, assented to, acquiesced in or participated in the offence is guilty of the same offence and liable to the same punishment as the entity.
The verb worth reading twice is acquiesced, because it reaches past the person who lied all the way to the person who simply let a sentence go by.
Here is how that arrives in practice. Somebody raises a question about a supplier — a journalist, a customer's compliance team, an NGO, a competitor's lawyer. The company's own published report is the first document they read, because you published it yourself and it is the easiest thing to find. Then the question travels inside the building, and by the time it reaches a room it has stopped being a question about the report and become a question about a person: who told the board this was true. The directors signed on the strength of a summary somebody prepared, and your name is on the summary. Whether that hour runs long or short comes down entirely to whether the records behind each sentence can be put on the table while everyone is still sitting there. The people I have seen struggle in that room were not the ones who had done less. They were the ones holding a real year of work that existed only in their own recollection of having done it.
Where do you start when the process exists and the record does not?
Almost nobody reading this needs to build a due diligence process from nothing. In most companies the process exists — it is being performed by people who care about it, in tools that were never designed to hold it. The gap is custody, not effort, and it does not need headcount or a new standing meeting to close.
Start with the map, because every other stage is scoped by it, and include the parts you were refused. A supplier who will not name their sub-suppliers is a logged, dated, flagged entry with a response plan attached, not a blank. Then take the findings that already exist and give each one an owner, an action and a closure state, so that the remediation you are already doing becomes something you can produce. Put the expiry dates somewhere that raises its hand on its own. And insist that one supplier record serves the customer questionnaire, the customs validation and the annual report, so the same evidence is not assembled three times in three formats by three people who do not know the others are doing it. Working past tier one, where the risk actually concentrates, is covered in forced labour due diligence beyond tier one, and the customer-facing version of the same problem is in answering a customer's tier 2 and tier 3 request.
Doing that checking, and holding what it produces, is XFACTOR VERIFIED. Giving every obligation that asks about a supplier the same record and the same dates to read from is XFACTOR COMMANDCENTER. The standard I build to is the one my own clients were held to for thirty years: a 100% success rate on C-TPAT, PIP and AEO — at Tier II, not the minimum. I was never someone who gave the bare minimum to my clients, and a due diligence record that cannot answer what was found, what was done, and when it closed is the bare minimum wearing better software.
Free guide
Free guide: How to Evaluate Supplier Risk
Where real supplier exposure sits, what you can establish before you ever send a questionnaire, and what a record has to contain before an auditor, a customer or a customs officer will credit it. We'll email you the link.
See what a due diligence record looks like when every stage is in it.
Look at how XFACTOR VERIFIED runs the checking and holds the evidence, and at what Procurement sees when a supplier is approved on evidence. Access is by request, and every request is reviewed personally.
The programs this maps to: Bill S-211 · C-TPAT · The departments this maps to: Procurement · Operations · Related reading: Supplier due diligence · Supplier verification software · Supplier risk assessment software · Bill S-211 compliance · What a Bill S-211 report must contain · Forced labour due diligence beyond tier 1 · UFLPA compliance for Canadian exporters · The Master 5-Step Risk Assessment