Supplier compliance fails quietly. Nobody notices the lapsed insurance certificate until there is an incident, the expired ISO certificate until a customer audit, or the missing Modern Slavery statement until a tender questionnaire asks for your supply-chain due diligence process. By the time a gap is visible, it is usually expensive.
This checklist covers what UK businesses should collect from suppliers, what to verify rather than take on trust, and, the part most guides skip, how quickly each item goes stale. It pairs with our supplier onboarding checklist, which covers the wider intake process; this guide goes deep on the compliance evidence itself.
What Supplier Compliance Covers
Supplier compliance is the evidence that each supplier meets your legal, contractual and policy requirements, both at the point you approve them and continuously afterwards. In practice it is a document and data problem: certificates, statements, registrations and declarations, each with an issuer, a scope and, crucially, an expiry.
Not every supplier needs every item. A sensible approach tiers requirements by category and risk: a contract manufacturer carries the full list below, while a low-value service supplier might only need insurance, data protection and basic corporate checks. Define the tiers once, then apply them consistently; our free approved supplier list template gives you the structure to record who is approved for what.
1. Corporate and Financial Checks
- Company identity. Registered name, company number and registered office, verified against Companies House, not the supplier's letterhead. Confirm the entity you are contracting with is the entity that holds the insurance and certifications.
- Financial health. Filed accounts, overdue filings and insolvency notices are public signals. The Gazette publishes winding-up petitions and administration notices; a supplier in distress usually shows up there before they tell you.
- Sanctions screening. For international exposure, screen against the UK Sanctions List. This is a continuous obligation, not a one-off check at onboarding.
- VAT registration where relevant, verifiable through HMRC's online checker.
2. Insurance
- Employers' liability insurance. A legal requirement for almost all UK employers under the Employers' Liability (Compulsory Insurance) Act 1969, with a minimum cover of £5 million (most policies are written at £10 million). If your supplier has employees on your site, this is non-negotiable.
- Public liability insurance. Not compulsory by law but contractually standard; £1 million to £10 million depending on the work. Set your minimum per supplier category.
- Professional indemnity for suppliers giving advice or design services, and product liability for physical goods.
- Check the certificate, not the claim. Verify insurer, policy number, cover level and, above all, the expiry date. Insurance is the fastest-expiring item on this list; our guide to certificate of insurance tracking covers how to keep it current without a spreadsheet.
3. Certifications and Quality
- ISO 9001 (quality management) is the baseline expectation in most manufacturing supply chains; check the certificate scope actually covers the goods or services you buy, and that the certification body is UKAS-accredited.
- Industry-specific standards: BRCGS or SALSA for food, ISO 13485 for medical devices, AS9100 for aerospace, ISO 27001 where the supplier handles your data.
- Construction: SSIP-member schemes such as CHAS, Constructionline or SafeContractor evidence health and safety pre-qualification.
- Audit evidence. For critical suppliers, certificates alone are not enough; run your own audit on a defined cycle. Our free supplier audit checklist (Excel) covers quality systems, traceability and corrective actions.
4. Labour and Modern Slavery
- Modern Slavery statement. Commercial organisations with UK turnover of £36 million or more must publish an annual slavery and human trafficking statement under section 54 of the Modern Slavery Act 2015. Collect it from suppliers above the threshold; ask smaller suppliers to confirm their position and cooperate with your due diligence. Our Modern Slavery compliance guide covers the whole process.
- A signed code of conduct. The cleanest way to set labour, ethics and environmental expectations in one document; use our free supplier code of conduct template (PDF) as a starting point.
- Right-to-work confirmation where supplier personnel work on your sites.
5. Data Protection
- A data processing agreement (DPA) is mandatory under UK GDPR Article 28 whenever a supplier processes personal data on your behalf, from payroll bureaus to SaaS tools. Our DPA guide for procurement teams covers what the contract must contain.
- ICO registration. Most organisations processing personal data must pay the ICO data protection fee; registration is publicly searchable.
- Security evidence proportionate to the data: a security questionnaire for most, ISO 27001 or a SOC 2 report for suppliers holding sensitive data at scale.
- International transfers: if data leaves the UK, confirm the lawful transfer mechanism.
6. Health, Safety and ESG
- Health and safety policy (written policy required for employers with five or more staff), plus RIDDOR history and method statements for on-site work.
- Environmental compliance: relevant permits, waste carrier registration where applicable, and ISO 14001 for higher-impact categories.
- Carbon data. If you report under SECR or face customer Scope 3 requests, you need emissions data from suppliers, product-level where possible. Our Scope 3 reporting guide explains what to ask for and how to collect it without another spreadsheet round-trip.
The Part Everyone Skips: Re-Verification
Every item above has a shelf life, and they are all different. This is why supplier compliance collapses in spreadsheets: the collection happens once, in a burst of onboarding energy, and the expiry dates quietly pass. A workable re-verification rhythm looks like this:
- Continuous: sanctions screening, insolvency and Companies House monitoring. These are event-driven and free to watch; the problem is that nobody watches manually.
- At every expiry: insurance certificates and certifications. Chase renewals before the lapse, not after you discover it; our free supplier email templates include the renewal request and the escalation for when it goes unanswered.
- Annually: Modern Slavery statements, code of conduct re-acknowledgement, carbon disclosures, security questionnaires for data-handling suppliers.
- Risk-based: audits and deeper reviews, yearly for critical suppliers, less often for the long tail.
If you take one thing from this guide: the checklist is the easy half. The system that notices when an item goes stale is what actually keeps you compliant.
How Supplio Helps
Supplio is supplier compliance software built for exactly this workflow, priced for UK SMEs. Suppliers upload their own documents through a free branded supplier portal, every document carries an expiry with automatic renewal chasing, and Supplier Watch monitors Companies House, The Gazette and the UK Sanctions List daily so the continuous checks actually happen. Compliance status rolls up per supplier, so the question "are we covered?" has a live answer instead of a spreadsheet archaeology session. Plans start at £599 per year.
Sources and Further Reading
- Modern Slavery Act 2015, section 54 (legislation.gov.uk)
- Employers' Liability (Compulsory Insurance) Act 1969 (legislation.gov.uk)
- SECR environmental reporting guidance (gov.uk)
- UK GDPR guidance (ICO)
- Companies House and The Gazette