Responsible Sourcing & Human Rights Due Diligence
Responsible sourcing and human rights due diligence help companies identify, assess and manage adverse impacts connected to suppliers, sourcing regions, materials and business relationships.
The objective is not simply to collect more supplier questionnaires. It is to establish a repeatable process that shows where risk exists, what evidence supports the assessment, what action was taken and whether identified issues were properly addressed.
For procurement, compliance, sustainability, quality and supply-chain teams, this matters because human-rights and environmental risks can sit far beyond the information normally contained in a supplier master file.
Forced labour, child labour, unsafe working conditions, discrimination, excessive working hours, environmental harm, weak traceability and unreliable supplier documentation can all require closer investigation and stronger supplier controls.
An effective responsible-sourcing programme therefore combines risk screening, supplier engagement, evidence review, corrective action and reassessment. The level of due diligence should be proportionate to the nature and severity of the risk and documented clearly enough to support management decisions, customer requests, audits and regulatory enquiries.
Why Responsible Sourcing and Human Rights Due Diligence Matter
International responsible-business guidance expects companies to understand adverse impacts connected to their operations and business relationships and to act on significant risks.
The OECD Due Diligence Guidance for Responsible Business Conduct provides a widely recognised framework that covers embedding responsible business conduct into management systems, identifying and assessing adverse impacts, preventing or mitigating them, tracking results, communicating responses and supporting remediation where appropriate.
Regulatory requirements are also becoming more specific.
The EU Corporate Sustainability Due Diligence Directive, as amended in 2026, establishes human-rights and environmental due-diligence obligations for companies falling within its scope. Under the amended timetable, Member States must transpose the relevant changes by 26 July 2028 and apply them from 26 July 2029, with Article 16 reporting measures applying for financial years beginning on or after 1 January 2030. Whether an individual company is covered must be assessed against the applicable scope, structure, turnover and jurisdiction.
The EU Forced Labour Regulation adds another important supply-chain consideration. From 14 December 2027, products made with forced labour may not be placed or made available on the EU market or exported from it. The prohibition covers products regardless of origin and can apply where forced labour has occurred at any stage of production, manufacture, harvest or extraction.
For businesses, the practical message is clear: supplier due diligence needs to be risk-based, evidence-led and capable of demonstrating what the organisation did when a concern was identified.
What Should a Supplier Human-Rights Risk Assessment Cover?
A responsible-sourcing assessment should look beyond country risk alone.
Geography may be important, but the risk profile can also depend on sector, commodity, labour model, sourcing tier, manufacturing activity, supplier history, workforce characteristics, traceability and the reliability of available evidence.
|
Risk Area |
What to Assess |
Examples of Useful Evidence |
|
Human rights |
Forced labour, child labour, discrimination, freedom of association, grievance access and severe rights impacts |
Supplier policies, declarations, audit records, worker-related evidence and remediation records |
|
Labour conditions |
Wages, working hours, recruitment practices, health and safety, accommodation and labour agencies |
Policies, audits, certifications, workforce information and corrective-action evidence |
|
Environmental risk |
Pollution, waste, water, emissions, hazardous substances, biodiversity or deforestation exposure where relevant |
Permits, environmental data, certificates, test reports and site or product information |
|
Responsible sourcing |
Origin, traceability, chain of custody, high-risk materials or commodities and upstream visibility |
Origin records, chain-of-custody evidence, material declarations and supplier questionnaires |
|
Evidence quality |
Completeness, validity, consistency, scope and reliability of supplier information |
Current documents, issue dates, versions, supporting records and approval status |
|
Supplier behaviour |
Responsiveness, repeated gaps, unresolved findings and willingness to provide supporting evidence |
Response history, open issues, escalation records and previous assessment results |
Practical Guidelines for Responsible Sourcing Due Diligence
1. Define Scope and Ownership
Start by identifying which legal entities, supplier groups, sites, products, materials, sourcing countries and markets are included in the due-diligence programme.
Assign clear responsibilities across procurement, sustainability, compliance, legal, quality and supply-chain functions. A supplier assessment is difficult to manage consistently when responsibility is unclear or different departments apply different rules to the same risk.
Document who assesses suppliers, who approves risk classifications, who manages escalation and who verifies corrective actions.
2. Build a Reliable Supplier and Value-Chain Map
Maintain controlled supplier records that connect each relevant supplier with the products, components, materials or services it provides.
Where the level of risk requires greater visibility, investigate relevant production sites, subcontractors or upstream sources rather than limiting the assessment to the direct contractual supplier.
The important question is not simply who sent the invoice, but where the relevant production, sourcing or labour activity actually takes place.
3. Screen Inherent Risk Before Deep Assessment
Use proportionate screening criteria to decide where deeper due diligence is required.
Relevant factors may include country, sector, commodity, production activity, labour intensity, sourcing complexity, use of migrant or temporary workers, known concerns and the commercial importance of the supplier.
Higher-risk relationships may justify enhanced questionnaires, additional evidence, specialist review or independent verification. Lower-risk relationships can normally remain subject to proportionate monitoring and periodic reassessment.
This prevents organisations from treating every supplier identically while allowing resources to focus on the areas where adverse impacts may be more significant.
4. Collect Structured Supplier Evidence
Use standardised supplier questionnaires and defined evidence requirements instead of relying on disconnected email requests.
Questions should be relevant, understandable and linked to the supplier, manufacturing location, material, product or sourcing relationship being assessed.
For forced-labour risk, assessments can consider areas such as recruitment fees, retention of identity documents, freedom of movement, debt, withholding of wages, threats, excessive overtime and other warning indicators.
The ILO’s revised 2025 Indicators of Forced Labour provide practical indicators intended to help identify potential forced-labour situations and determine when additional investigation may be necessary.
5. Validate Evidence, Not Only Supplier Answers
A completed questionnaire is not automatically evidence that the underlying risk has been controlled.
Review supporting documents for completeness, validity, consistency and relevance. Confirm that the information applies to the correct supplier, site, product, material or activity.
Watch for expired documents, unsupported statements, inconsistent answers, missing scope information and evidence that does not actually address the risk being assessed.
Supplier due diligence becomes stronger when the organisation assesses evidence quality as well as evidence availability.
6. Prioritise Risks by Severity, Likelihood and Exposure
Use a documented methodology to determine which findings require the greatest attention.
Risk ratings should be explainable. Reviewers should be able to understand why a supplier received a particular classification and what information influenced that conclusion.
Separate inherent risk from evidence quality where practical. A supplier operating in a higher-risk environment may provide strong evidence and controls, while a supplier considered inherently lower risk may still provide incomplete or unreliable information.
Avoid risk scores that generate a number without explaining what it means or what action should follow.
7. Turn Findings Into Corrective Actions
Every material finding should lead to a defined next step.
Document the issue, responsible owner, expected action, target date, required closure evidence and current status.
Corrective actions may include obtaining missing documentation, improving traceability, changing a labour practice, revising a supplier policy, conducting a deeper investigation or providing additional independent evidence.
For serious human-rights impacts, remediation should consider the people affected and the nature of the harm rather than treating the issue as an administrative task that can simply be marked “closed.”
Supplier disengagement should not automatically be treated as the correct response to every finding. Decisions should consider severity, leverage, available remediation, legal requirements and whether disengagement itself could create further adverse impacts.
8. Establish Clear Escalation Rules
Define escalation criteria before serious issues arise.
Credible allegations, repeated supplier non-response, missed corrective-action deadlines, conflicting documentation, severe findings or indicators of forced labour should trigger a higher level of review.
Depending on the issue, escalation may involve management, procurement, legal or compliance specialists, enhanced supplier engagement, independent verification or reconsideration of the sourcing relationship.
Clear escalation criteria make supplier treatment more consistent and reduce reliance on individual judgement alone.
9. Verify Closure and Reassess Risk
Do not close a finding simply because a supplier states that the corrective action has been completed.
Review the closure evidence and determine whether the identified risk has genuinely changed.
Supplier risk should also be reassessed when meaningful circumstances change. Triggers can include a new manufacturing location, sourcing changes, significant incidents, new credible information, expired evidence, changes in suppliers or changes in applicable regulatory requirements.
Human-rights due diligence is therefore an ongoing risk-management process rather than a one-time supplier questionnaire.
10. Maintain an Audit-Ready Decision Trail
Retain the information necessary to reconstruct the supplier due-diligence decision.
That should include supplier profiles, initial screening information, questionnaire responses, supporting documents, assessment rationale, risk classifications, approvals, corrective actions, escalation records and reassessment outcomes.
A strong record enables another reviewer to answer three fundamental questions:
What did the company know? Why did it make the decision? What happened afterwards?
What Good Human-Rights Due-Diligence Evidence Looks Like
Good evidence is current, traceable and connected to a decision.
A practical supplier file should make it possible to determine:
- Which supplier, site, product, material or sourcing relationship was assessed.
- Which human-rights, forced-labour, environmental or responsible-sourcing risks were considered.
- Which information and supporting evidence informed the assessment.
- What corrective or preventive action was required, who owned it and when it was due.
- What evidence demonstrated completion, remediation or a change in the supplier’s risk position.
This helps prevent a common supplier-risk problem: collecting large volumes of documents without showing how those documents affected the organisation’s actual due-diligence decisions.
Create a Continuous Responsible-Sourcing Process
Responsible sourcing should not end when the initial supplier assessment is completed.
Supplier locations change. Production processes change. Documents expire. New sourcing tiers become visible. Regulatory requirements evolve. Serious incidents or credible external allegations can also change a previously accepted risk assessment.
Organisations should therefore combine scheduled supplier reviews with event-driven reassessment.
Useful management indicators can include overdue questionnaires, missing documentation, expired evidence, high-risk findings, unresolved corrective actions, repeated supplier non-response and significant changes to manufacturing or sourcing locations.
The goal is a due-diligence programme that directs attention toward meaningful risk instead of creating an administrative exercise around questionnaire completion.
How ComplyMarket Supports Responsible Sourcing and Human Rights Due Diligence
ComplyMarket’s publicly documented supplier-risk and sustainability capabilities provide practical building blocks for a more structured responsible-sourcing process.
ComplyMarket supports customised supplier questionnaires, dedicated supplier accounts, automated supplier communication, supplier risk assessment focused on supplier trustworthiness and AI-supported analysis of supplier declarations. Its wider compliance workflows also include supplier data requests, task assignment, supplier-response tracking, evidence management and alerts for evidence that is missing or approaching expiry.
This enables organisations to move supplier due diligence away from disconnected spreadsheets, inboxes and document folders toward a more controlled information process.
ComplyMarket can also connect supplier records with relevant product, component, material, substance, legislation and evidence information. Its sustainability-compliance approach supports reusable question groups and supplier-facing questionnaire packages, enabling organisations to request comparable information from suppliers through a repeatable process.
For responsible sourcing and human rights due diligence, these capabilities can support several critical parts of the workflow:
- Structure supplier and sustainability information.
- Deploy consistent supplier questionnaires.
- Gather and review supporting evidence.
- Assess supplier trustworthiness and information quality.
- Track supplier requests and responses.
- Identify missing or expiring documentation.
- Focus additional review on areas requiring greater attention.
- Maintain stronger evidence behind supplier-risk decisions.
- Connect supplier information with wider product, material and compliance processes.
ComplyMarket therefore provides an operational compliance and data-management foundation for organisations building more consistent supplier due-diligence processes.
Each organisation should still define its own applicable legal scope, risk methodology, escalation thresholds, remediation strategy and final sourcing decisions. Where regulatory interpretation, suspected forced labour or serious human-rights impacts are involved, appropriate legal and subject-matter expertise should be included.
Build a More Defensible Supplier Due-Diligence Process
Responsible sourcing becomes more effective when supplier risk, evidence, decisions and follow-up are managed as one continuous process.
ComplyMarket helps bring supplier engagement, compliance information and sustainability data into a connected environment, enabling teams to replace fragmented supplier records with a more structured and evidence-based approach to supplier risk assessment.
Whether your organisation is strengthening responsible procurement, preparing for evolving supply-chain due-diligence expectations or improving visibility into supplier human-rights and environmental risk, the starting point is the same: know your suppliers, understand the relevant risks, require meaningful evidence and document what happens next.