
How to Conduct Supplier Due Diligence Well
A supplier can look capable on paper and still introduce serious WHS, quality, environmental or commercial exposure into your operation. A missing licence, uninsured subcontractor, poor chemical controls or unreliable component source can quickly become your problem when work is performed under your direction or goods enter your supply chain. Knowing how to conduct supplier due diligence gives directors and operational leaders a defensible basis for selecting, approving and monitoring suppliers before an incident, product failure or tender audit exposes a gap.
Due diligence is not a one-off request for a certificate of currency. It is a proportionate process for deciding whether a supplier is competent, compliant and dependable for the specific work, product or service they will provide. The depth of review should reflect the risk they bring to your business.
Start with the supplier's risk profile
Do not apply the same questionnaire to every supplier. A stationery provider and a contractor carrying out confined-space work at your site present materially different risks. Over-screening low-risk suppliers creates administration without improving control. Under-screening critical suppliers can leave major legal and operational exposures unmanaged.
Classify suppliers before requesting documents. Consider what they supply, where the work occurs, whether they interact with your workers or customers, the potential consequences of failure, and whether they use subcontractors. Also consider the supplier's influence on your own obligations, including customer specifications, product safety, modern slavery expectations, environmental commitments and tender conditions.
A practical approach is to separate suppliers into low, medium and high-risk categories. Low-risk suppliers may only require business identification, basic insurance and acceptance of your supplier terms. Medium-risk suppliers often need evidence of relevant competence, licences and quality controls. High-risk contractors, labour hire providers, manufacturers of critical components and suppliers handling hazardous substances require a deeper assessment before approval.
How to conduct supplier due diligence before engagement
The assessment should verify claims with evidence rather than rely on assurances in a capability statement. Build the process around the risks identified in the supplier profile and record who reviewed the information, when it was reviewed and the approval decision.
Confirm legal identity and commercial standing
First, establish exactly who you are contracting with. Confirm the legal entity name, ABN, business address and key contacts. Check that the entity holds the registrations, licences or authorisations relevant to the work. For regulated activities, this may include trade licences, security licences, dangerous goods approvals, transport accreditations or industry-specific registrations.
Commercial due diligence matters as well. A supplier that cannot maintain staffing, stock, plant or insurance cover can disrupt delivery at the point your project is most exposed. The level of financial review depends on contract value and criticality. For a long-term, high-value arrangement, consider payment history, trading references, capacity to meet demand and contingency arrangements if a key facility, person or subcontractor becomes unavailable.
Test WHS capability against the actual scope
For contractors and service providers, WHS documentation must relate to the work they will perform. A generic safety policy does not demonstrate that a business can safely complete demolition, electrical work, security operations, port work or plant maintenance in your environment.
Request evidence that is relevant and current: their WHS management system, risk assessments or safe work method statements where high-risk construction work is involved, training and competency records, plant inspection arrangements, incident reporting process and workers compensation and public liability insurance. Where the work warrants it, verify high-risk work licences, equipment maintenance records, inductions and supervision arrangements.
Under Australian WHS laws, duties cannot simply be contracted away. If your business is a PCBU with a duty to consult, coordinate and cooperate with other duty holders, supplier due diligence is part of establishing how that coordination will occur. The arrangement should make clear who controls the work area, who approves changes, how hazards are reported, and when work must stop.
Review quality controls and traceability
Quality failures often originate upstream. If a supplier provides materials, fabricated items, imported goods, calibrated equipment or services that affect the final product, ask how they control specifications, changes, inspections and non-conforming outputs.
For businesses operating under ISO 9001, this supports control of externally provided processes, products and services. Assess whether the supplier can meet your specifications consistently, not merely whether they hold certification. A current ISO certificate can provide useful confidence, but it is not a substitute for reviewing the scope of certification, performance history and controls relevant to your purchase.
For critical items, define acceptance criteria before placing an order. This may include batch traceability, test certificates, inspection records, sample approval, packaging requirements and notification before any material or process change. Without these controls, a defect may only become visible after installation, production or delivery to your customer.
Check environmental and ethical exposure
Environmental due diligence should be proportionate to the supplier's activities and your own commitments. A waste contractor, chemical supplier, manufacturer or transport provider may affect your ability to meet legal obligations and ISO 14001 objectives. Check licences where applicable, waste tracking arrangements, chemical safety data sheets, spill response measures and how environmental incidents are reported.
Where tenders, customer requirements or company policy call for it, also examine labour practices, forced labour risk, conflict minerals exposure, privacy controls and information security. These issues require more than a signed declaration for higher-risk supply chains. Ask where goods are made, who performs the work, whether subcontracting is permitted, and what verification the supplier undertakes.
Make approval conditional, not automatic
Due diligence only creates value when its findings affect the commercial decision. Set clear approval outcomes: approved, approved with conditions, not approved, or pending further evidence. A supplier with an expired insurance certificate may be suitable once evidence is renewed. A contractor unable to demonstrate required competency for high-risk work should not be mobilised until that gap is resolved.
Document conditions in the purchase order, contract or supplier agreement. Conditions may include site induction, provision of task-specific risk documentation, notification of subcontractors, right to audit, minimum insurance levels, reporting timeframes and corrective action requirements. Be careful not to write obligations that your team will not enforce. A simple, site-ready requirement applied consistently is stronger than a lengthy contract clause no one checks.
Monitor performance after onboarding
Supplier approval has an expiry date, even if it is not formally recorded. Insurances lapse, personnel change, subcontractors are introduced and performance can deteriorate. Set review periods based on risk and trigger earlier reassessment following an incident, serious complaint, quality rejection, environmental event, material change or repeated late delivery.
Use performance information already generated by operations. This can include delivery reliability, defects, rework, incidents, corrective action closure, audit findings, customer complaints and responsiveness. For high-risk or strategic suppliers, hold periodic reviews that focus on trends and agreed actions rather than simply collecting documents.
A useful supplier scorecard usually measures quality, delivery, WHS, environmental performance and commercial responsiveness. The measures should be objective enough to support decisions. If a supplier repeatedly misses requirements, escalate through corrective action, restricted approval or replacement planning. Continuing to use a supplier despite known failures can be difficult to defend after an incident or customer dispute.
Keep records that stand up to scrutiny
An auditor, customer or regulator should be able to see how you reached the approval decision. Maintain a supplier register showing risk classification, evidence reviewed, approval status, review dates, conditions and performance issues. Store supporting records in a controlled location, with responsibilities assigned for renewal checks and reassessments.
For ISO 9001, ISO 45001 and ISO 14001 systems, supplier due diligence should connect to procurement, operational planning, risk management, corrective action and internal audit processes. It should not sit as an isolated spreadsheet managed only when a tender asks for it. This integration is what turns supplier management into an operational control rather than a compliance exercise.
Common mistakes that weaken supplier due diligence
The most common failure is treating supplier assessment as document collection. Certificates may be genuine yet irrelevant to the scope, expired or unsupported by site practice. Another is approving a head contractor without checking how subcontractors will be assessed and controlled. The risk often sits several layers down the chain.
Businesses also lose control when procurement pressures override approval requirements. Urgent work and stock shortages are real commercial issues, but an emergency exception should be authorised, time-limited and followed by a complete review. Otherwise, temporary arrangements become permanent suppliers with no verified controls.
The Safety Hand helps Australian businesses build practical contractor and supplier management processes that align with ISO requirements, WHS duties and tender expectations. The objective is not more paperwork. It is clear evidence that the suppliers supporting your operation are capable, monitored and held to requirements that matter.
A well-run due diligence process gives procurement the confidence to move quickly within defined boundaries. More importantly, it gives directors and managers a clearer view of where supply-chain risk sits before it reaches the worksite, production line or customer.




Comments