How To Conduct Supplier Due Diligence In Manufacturing: Step-by-Step Checklist
Supplier Due Diligence
Definition
A structured investigation of a supplier before entering a significant commercial relationship.
Overview
Supplier Due Diligence A structured investigation of a supplier before entering a significant commercial relationship. This article provides a step-by-step checklist manufacturers can use to design a repeatable, risk-based due diligence workflow that fits production cadence and regulatory needs.
A practical due diligence program balances speed and thoroughness: use faster desktop checks for low-risk items and invest in on-site audits, third-party verification, and multi-disciplinary review for strategic suppliers.
Step 1 — Define Scope And Risk Criteria
Decide what aspects matter for the supplier type and product. Typical risk dimensions include safety impact, regulatory exposure (export controls, restricted substances), financial dependence, single-sourcing, and proximity to sensitive IP. Assign a risk score that determines the depth of due diligence.
Step 2 — Gather Documentation
- Legal Documents: Business registration, tax ID, articles of incorporation, and beneficial ownership.
- Quality And Certs: Certifications (ISO 9001, IATF 16949 where relevant), test reports, inspection records.
- Compliance Records: Environmental permits, export licenses, anti-corruption policies, and supplier code of conduct acceptance.
- Financials: Recent financial statements or credit checks for high-spend suppliers.
Step 3 — Perform Remote Checks
Use desktop verification to validate documents, search for negative news, check sanctions lists, and confirm corporate relationships. For IT or electronics suppliers include a basic cybersecurity posture check (e.g., public disclosures, software supply-chain practices).
Step 4 — Technical Assessment
Request samples, run acceptance tests, and review process capability (Cp/Cpk) and control plans. Engineering and quality should evaluate fit-for-use and manufacturability; document corrective actions required before qualification.
Step 5 — On-Site Audit Or Third-Party Verification
For high-risk suppliers conduct a targeted on-site audit or hire a qualified third-party auditor. Focus on non-conformities revealed during earlier steps: e.g., material traceability, hazardous substance controls, or subcontractor oversight. Capture photographic evidence and a corrective action plan with deadlines.
Step 6 — Legal And Contractual Protections
- Contract Terms: Include quality requirements, inspection and audit rights, IP protections, confidentiality, and termination clauses tied to compliance failures.
- Warranties And Remedies: Define warranties for parts and remedies for non-conformance, including repair, replacement, or financial penalties.
- Insurance: Verify required liability, product, and cyber insurance where applicable.
Step 7 — Decision And Onboarding
Use a cross-functional panel to approve or reject the supplier. If approved, move the vendor to a qualified list, set probationary performance targets, and schedule rechecks. Update ERP/WMS with supplier codes and approved SKUs to prevent unauthorized purchases.
Step 8 — Ongoing Monitoring And Requalification
Monitor KPIs such as on-time delivery, quality defects per million (DPM), lead-time variance, and corrective action closure rates. Re-run critical parts of due diligence after major events: M&A, new production sites, repeated non-conformances, or regulatory changes.
Checklist Summary
- Risk Score Assigned: Yes/No
- Documents Collected: Legal, financial, quality, compliance
- Remote Checks Completed: Background, sanctions, media
- Technical Tests Passed: Sample testing and engineering sign-off
- Audit/Verification: Completed with CAPA and timelines
- Contractual Protections: Clauses included and insurance verified
- Approval Outcome: Qualified / Conditional / Rejected
- Monitoring Plan: KPIs and requalification cadence
In short, the Supplier Due Diligence checklist is a structured sequence—from risk scoring and document review to testing, audit, contract, and monitoring—that gives manufacturers a repeatable method to onboard suppliers securely and keep supply chains resilient.
Sources And Additional Reading (3)
- Due Diligence Guidance for Responsible Business Conduct
“Due Diligence Guidance for Responsible Business Conduct.” Organisation for Economic Co-operation and Development, https://www.oecd.org/investment/due-diligence-guidance-for-responsible-business-conduct.htm.
- Supply Chain Risk Management Practices for Federal Information Systems and Organizations (SP 800-161)
“Supply Chain Risk Management Practices for Federal Information Systems and Organizations (SP 800-161).” National Institute of Standards and Technology, https://csrc.nist.gov/publications/detail/sp/800-161/final.
- ISO 9001 — Quality management systems
“ISO 9001 — Quality management systems.” International Organization for Standardization, https://www.iso.org/iso-9001-quality-management.html.
More from this term
Looking for a 3PL?
Compare warehouses on Racklify and find the right logistics partner for your business.