SUPPLIER CODE OF CONDUCT

How to create a Supplier Code of Conduct that works in practice

Customers and supplier assessments may ask whether your company defines ESG and compliance expectations for suppliers.

A Supplier Code can document expectations on human rights, working conditions, environment, ethics and responsible procurement. It must fit the actual supplier base and procurement process, and it should not promise rights or processes the company does not have.

Quick Answer

In short

A Supplier Code of Conduct describes the expectations a company sets for suppliers. A credible code defines scope, uses realistic requirements, is internally approved, and is connected to communication, acknowledgment where used and practical supplier-management processes.

Core distinctions

A Supplier Code is an expectation, not proof of supplier performance.

  1. 01

    Code

  2. 02

    Implementation

  3. 03

    Supplier compliance

Published ≠ communicated ≠ acknowledged ≠ contractually incorporated

Code ≠ implementation ≠ supplier compliance

Before drafting

Understand procurement first. Then define supplier expectations.

  • Which supplier types exist?
  • Which countries are relevant?
  • Which materials or services are purchased?
  • Are there critical or strategic suppliers?
  • Is there an existing procurement manual?
  • Are there existing contract terms?
  • Are suppliers already evaluated?
  • Are ESG criteria already used?
  • Are quality or audit processes in place?
  • Who owns supplier relationships?
  • How are new suppliers approved?
  • How are deviations handled today?

Purpose

What a Supplier Code of Conduct is for

01

Expectations

It makes basic supplier expectations visible.

02

Consistency

It creates a common starting point for relevant supplier relationships.

03

Communication

It helps procurement and other functions communicate ESG and compliance expectations in a structured way.

04

Foundation for processes

It can support supplier assessments, contract processes or further review, but it does not replace them.

Framework

Seven building blocks of a credible Supplier Code of Conduct

1 · Scope

Make clear which suppliers, entities or business relationships the code is intended to cover.

  • All suppliers?
  • Direct suppliers only?
  • Selected supplier categories?
  • Group companies?
  • Service providers?
  • Subcontractors?

2 · Human rights and working conditions

Content should fit the intended scope and risk profile.

  • Child labour
  • Forced labour
  • Decent working conditions
  • Discrimination
  • Harassment
  • Freedom of association where relevant
  • Working hours
  • Remuneration under applicable requirements
  • Health and safety

3 · Environment

Environmental expectations should be framed by supplier activity, category and actual relevance.

  • Resource use
  • Energy
  • Emissions
  • Waste
  • Water
  • Relevant chemicals or substances
  • Avoiding unnecessary environmental impacts
  • Applicable environmental requirements
  • Improving relevant environmental performance

4 · Business ethics and compliance

The code can describe expectations on integrity and lawful conduct, without replacing legal compliance review.

  • Corruption
  • Bribery
  • Conflicts of interest
  • Fair competition
  • Confidential information
  • Data or information security where relevant
  • Reporting serious misconduct
  • Actually applicable legal requirements

5 · Suppliers’ own supply chains

Depending on procurement context, a code may set expectations for how relevant principles are considered upstream.

  • Pass on relevant expectations
  • Consider material risks
  • Provide information for legitimate follow-up questions
  • Support evidence where needed

6 · Communication, evidence and cooperation

Describe how suppliers provide information, support follow-up questions and engage when issues are identified.

  • Relevant information where required
  • Support for legitimate follow-up questions
  • Relevant evidence
  • Communication of material changes
  • Dialogue on identified issues
  • Corrective actions where appropriate

7 · Approval, version and ownership

Show who issues the code, which version applies and which internal function owns the content.

  • Issuing entity
  • Version
  • Actual approval date
  • Scope
  • Document owner
  • Approving function
  • Status
  • Review information where used

Limits

What not to include in a Supplier Code of Conduct

Unrealistic guarantees

Do not require broad guarantees that cannot be sensibly bounded or practically checked.

Rights that do not exist

Do not claim audit, access or termination rights unless they have actually been agreed or internally confirmed.

Copy-paste obligations

Requirements from external templates should not be copied without review.

Unclear scope

The code should show which supplier relationships it applies to.

Requirements the company cannot operationalise

Expectations should fit the actual supplier structure and procurement process.

Invented history

A newly introduced code should not be presented as a long-standing supplier-management process.

Contract status

Is a Supplier Code automatically part of the contract?

Not automatically.

Whether and how a Supplier Code is contractually incorporated depends on the actual contract and procurement process. This guide does not draw enforceability conclusions.

  1. 01

    Published

  2. 02

    Communicated

  3. 03

    Acknowledged

  4. 04

    Contractually incorporated

Acknowledgment

What does supplier acknowledgment mean?

Acknowledgment may document receipt or confirmation. It does not automatically prove implementation or compliance.

01

Received

02

Acknowledged / read

03

Accepted / confirmed

04

Contractually incorporated

05

Verified

Evidence

What supporting evidence may be relevant?

The document itself is only one part of the evidence picture.

  • Supplier communications
  • Acknowledgment records
  • Onboarding documentation
  • Supplier questionnaires
  • Procurement procedures
  • Supplier evaluations
  • Corrective-action records
  • Procurement training
  • Risk assessments
  • Contract references where they genuinely exist
  • Audit records where audits were actually performed

Status

What status does your Supplier Code have?

Draft

Content is being prepared.

Pending approval

Content is internally aligned but not officially adopted.

Approved

The responsible function has formally confirmed the code.

In rollout

The code is being integrated into relevant supplier processes or communications.

Needs review / superseded

Content or version must be checked or replaced by a current version.

Version

A Supplier Code also needs version control.

Do not invent backdated approval or rollout dates.

Illustrative example metadata

Document
Supplier Code of Conduct
Version
1.0
Issuing entity
Legal entity / group
Scope
Relevant suppliers
Approval date
Actual approval date
Approved by
Responsible function
Document owner
Procurement / Compliance / Management
Status
Approved
Review
According to internal process or after material changes

Approval

Draft is not the same as approved.

Draft ≠ approved Supplier Code

Evipace can prepare a draft, but the code becomes an official company document only through client review, corrections and authorised internal approval.

Outline

Example structure for a Supplier Code of Conduct

This is a structure guide, not a universal contract or compliance template.

  1. 1. Purpose

    Why the code exists.

  2. 2. Scope

    Which supplier relationships it is intended to cover.

  3. 3. Human rights & working conditions

    Relevant social expectations.

  4. 4. Health & safety

    Expectations for safe working conditions.

  5. 5. Environment

    Relevant environmental principles.

  6. 6. Business ethics

    Corruption, conflicts of interest and integrity.

  7. 7. Supplier-management expectations

    Information, cooperation and relevant evidence.

  8. 8. Handling deviations

    Dialogue, clarification and measures where appropriate.

  9. 9. Document status

    Version, approval and document owner.

Deviations

What happens if a supplier does not meet a requirement?

Do not default every deviation to immediate termination. Clarification, risk assessment and corrective action may be appropriate depending on the facts and actual agreements.

  1. 01

    Issue / deviation

  2. 02

    Clarify facts

  3. 03

    Assess risk

  4. 04

    Agree action

  5. 05

    Review progress

  6. 06

    Further decision

Specific legal or contractual response is outside this guide.

Risk-based

Does every supplier need the same treatment?

A local office-supply vendor, a critical production supplier and a sensitive raw-material supplier may need different levels of information or review.

This is practical operating guidance, not a universal legal requirement.

Customer request

What to do when your customer asks for a Supplier Code of Conduct

  1. 01

    Read the exact question

    Check whether the customer asks whether a code exists, is approved, has been communicated, has been acknowledged, is contractual or is actually used.

  2. 02

    Check existing documents

    Look for a current supplier code or comparable approved rule.

  3. 03

    Check scope

    Confirm that it covers the relevant legal entity and supplier relationships.

  4. 04

    Check approval status

    Distinguish draft, approved, in rollout and superseded status.

  5. 05

    Check actual rollout

    Confirm whether the code has actually been communicated to relevant suppliers or integrated into processes.

  6. 06

    Answer only the current status

    Keep existence, approval, communication, acknowledgment and practical use separate.

If it is missing

What if your company does not have a Supplier Code yet?

Do not answer retroactively as if a formal code already existed.

Review existing procurement requirements, identify actual expectations, draft realistically, review internally, approve and integrate the code into actual supplier processes.

A missing policy can be built. A past that did not exist should not be invented.

Distinction

Supplier Code and Supplier Questionnaire have different jobs.

Supplier Code

What expectations do we set?

Supplier Questionnaire

What information do we ask the supplier for?

Supplier Evidence

What documents support the response?

Supplier Assessment

How do we evaluate the information internally?

A Supplier Code does not automatically replace a questionnaire or assessment.

Avoid copy-paste

A customer requirement and your own Supplier Code are not the same thing.

A customer may require your company to address supplier ESG expectations. That does not mean you should copy the customer’s Supplier Code word for word.

Your own code should fit your supplier structure, procurement process and expectations you can genuinely support and manage.

Assessment context

Supplier Code of Conduct in ESG assessments

A Supplier Code can be relevant in assessments, but it should not be equated with full implementation or comprehensive supply-chain verification.

EcoVadis

Context for supplier assessments. No affiliation, automatic acceptance or scoring claim.

IntegrityNext

Context for supplier assessments. No affiliation, automatic acceptance or scoring claim.

Reuse

An approved Supplier Code should be findable for the next ESG request.

Store the current version, scope, owner and communication status in a reusable ESG information foundation.

Build a reusable ESG data foundation

Lifecycle

From actual expectations to an applied Supplier Code

  1. 01

    Understand supplier base

  2. 02

    Define relevant expectations

  3. 03

    Define scope

  4. 04

    Draft code

  5. 05

    Internal review

  6. 06

    Approval

  7. 07

    Communication

  8. 08

    Document use

Common mistakes

Eight common Supplier Code of Conduct mistakes

01

Copying another template unchanged

The code does not fit the actual supplier structure.

02

Unclear scope

It is not clear which suppliers are covered.

03

Claiming rights that do not exist

Audit, information or termination rights are asserted without being properly agreed.

04

Demanding unrealistic guarantees

Suppliers are asked to guarantee facts they cannot fully control.

05

Equating a code with supplier compliance

An acknowledged document does not prove actual supplier performance.

06

No internal owner

No one owns updates, communication or practical use.

07

Backdating rollout

A newly introduced code is described as a long-standing process.

08

Poor version control

Different or outdated versions remain in use.

Pre-approval

Check before internal approval

  • Is the issuing entity clear?
  • Is the supplier scope defined?
  • Do the requirements fit actual procurement?
  • Are human-rights and working-condition expectations realistic?
  • Are environmental expectations relevant and proportionate?
  • Are ethics and compliance expectations clear?
  • Does the code avoid claiming rights that do not exist?
  • Does it avoid unrealistic guarantees?
  • Is deviation handling understandable?
  • Is internal ownership clear?
  • Are version and approval status documented?
  • Is there a realistic plan for communication and use?

Resource bridge

Place this document in the wider ESG system

Implementation

Customer asking for a Supplier Code, but your process is not cleanly documented yet?

Evipace can help understand the actual supplier and procurement context, structure relevant ESG and compliance topics and prepare a Supplier Code draft.

The document becomes official only through your review, corrections and authorised internal approval.

Methodology

Methodological note

This guide describes a practical approach to preparing a Supplier Code of Conduct for ESG customer requests and supplier management. It is not legal, contract, audit or certification advice.

A good Supplier Code starts with the actual supplier base, not with a template.

When supplier structure, expectations, responsibilities and processes are clear, the code can be realistic, traceable and usable.