Supplier Code of Conduct: What to Include (Template)

Supplier Code of Conduct: What to Include (Template)
Igor Brooks

A supplier code of conduct states the minimum standards an organization expects from vendors and relevant subcontractors. It normally addresses law, ethics, labor and human rights, health and safety, environment, information protection, reporting, and cooperation with due diligence.

The code is most useful when it is connected to supplier qualification, contracts, training, risk assessment, monitoring, corrective action, and renewal. A document posted online without defined scope, evidence, ownership, and consequences may communicate values but will not manage supplier conduct by itself.

What is a supplier code of conduct?

A supplier code of conduct is a written set of behavioral, legal, social, environmental, and governance expectations for suppliers. It tells vendors what standards apply to their own operations and, where relevant, to subcontractors or upstream supply chains involved in delivering the buyer's products and services.

Definition

The code translates enterprise values and risk requirements into supplier-facing rules. It can cover compliance with law, anti-bribery, conflicts, fair competition, labor rights, forced and child labor, discrimination, freedom of association, wages and working time, health and safety, environmental management, product integrity, cybersecurity, privacy, confidential information, records, reporting, and remediation.

Scope must be explicit. The code may apply to the contracting entity, its affiliates, workers, agents, subcontractors, and suppliers supporting the buyer. Flow-down requirements should be proportionate and contractually clear. A Tier 1 supplier cannot guarantee every act in a distant supply chain, but it may be required to conduct risk-based due diligence, communicate standards, preserve traceability, and address identified harm.

Why companies require it

A consistent code reduces fragmented expectations across business units and contracts. It supports supplier onboarding, sourcing, due diligence, training, audits, incident response, and corrective action. It also gives suppliers a common reference before they accept an order or agreement.

The OECD guidance on responsible business conduct due diligence emphasizes identifying and addressing actual and potential adverse impacts in operations, supply chains, and business relationships. A code is one component of that process, not a substitute for risk assessment or remediation.

Technology suppliers may require additional provisions. NIST SP 800-161 Rev. 1 addresses cybersecurity supply chain risk across acquisition and supplier management, including contract requirements, monitoring, vulnerabilities, incident reporting, provenance, and resilience. These topics can appear in a general code at a high level and in detailed security schedules where the supplier's access or product risk warrants it.

What it is not

A supplier code is not automatically a contract. Its legal effect depends on how it is issued, accepted, incorporated, and enforced under applicable law. A web page or PDF may state expectations, but procurement should not assume it modifies an existing agreement.

InstrumentMain purposeTypical legal role
Supplier code of conductState common supplier standardsPolicy or incorporated obligation
ContractCreate enforceable commercial obligationsSigned agreement
Supplier questionnaireCollect representations and evidenceDue diligence input
Audit protocolDefine review method and accessContract-linked control
Corrective-action planResolve a specific gapTime-bound remediation record
Supplier scorecardTrack performance and complianceGovernance and decision support

Legal counsel should determine incorporation language, precedence, change control, audit rights, remedies, termination, and jurisdiction. The code should not contradict the main agreement or create obligations the buyer cannot administer consistently.

What does a supplier code of conduct example or sample look like?

A supplier code of conduct example usually opens with purpose and scope, states core standards by topic, explains reporting and verification, and closes with acknowledgment and consequences. A concise code can be effective if requirements are clear and supported by detailed contracts or standards.

Typical sections

SectionCore contentEvidence or control
Purpose and scopeWho and what the code coversSupplier acknowledgment and contract reference
Legal complianceApplicable laws, licenses, sanctions, tradeRegistration, licenses, screening, records
EthicsBribery, conflicts, gifts, competition, fraudPolicies, training, disclosures, investigations
Labor and human rightsForced labor, child labor, discrimination, association, wages, hoursWorkforce records, grievance process, assessments
Health and safetySafe workplace, hazards, incidents, emergency planningSafety system, training, incident records
EnvironmentPermits, pollution, resources, waste, emissionsPermits, metrics, improvement plans
Information and product integrityPrivacy, security, confidentiality, quality, counterfeit preventionAssessments, controls, traceability, incident reporting
Supply-chain managementFlow-down and risk-based due diligenceSupplier mapping, screening, corrective actions
Monitoring and remediationEvidence, audits, reporting, cooperationReview record and action plan
ConsequencesEscalation, suspension, termination, remedyContract and governance decision

The ILO fundamental principles and rights at work cover freedom of association and collective bargaining, elimination of forced labor, abolition of child labor, elimination of employment discrimination, and a safe and healthy working environment. These principles provide a credible foundation for labor provisions, while applicable law and sector risk determine detailed requirements.

Sample language

The following clauses illustrate structure and need legal and operational adaptation:

Compliance: "Supplier will comply with laws and regulations applicable to its performance and maintain licenses, permits, and records required for that work."

Ethics: "Supplier will not offer, authorize, request, or accept improper payments or benefits and will disclose actual or potential conflicts related to the buyer's business."

Labor: "Supplier will not use forced, trafficked, or prohibited child labor and will maintain working conditions consistent with applicable wage, hour, nondiscrimination, freedom-of-association, and health-and-safety requirements."

Environment: "Supplier will comply with applicable environmental requirements, control material impacts associated with its performance, and provide agreed data using the specified method and reporting period."

Reporting: "Supplier will promptly report suspected material violations affecting the buyer's products, services, workers, information, or reputation through the designated channel and will cooperate with appropriate investigation and remediation."

These examples avoid absolute claims the supplier cannot support. Terms such as "all international standards" or "zero environmental impact" are difficult to interpret and verify.

Common variations by industry

Manufacturing codes may emphasize materials, traceability, quality, counterfeit prevention, worker safety, and environmental permits. Technology codes add secure development, vulnerabilities, access, privacy, incident notification, and subprocessor controls. Logistics codes address safety, labor, emissions, cargo integrity, and subcontracted carriers. Staffing codes address worker classification, recruitment fees, wages, background checks, and data.

Use official PDF resources as references, not unexamined copies. The UN Supplier Code of Conduct resource provides a public example. The OECD and NIST publications provide due diligence and cybersecurity context. An organization's final code must match its operations, jurisdictions, supplier population, risk, and contracts.

Where can you get a supplier or vendor code of conduct template?

A supplier or vendor code of conduct template can be built in Word from a controlled outline, adapted from credible public examples, or prepared with legal and subject-matter support. A free template is a starting structure; it is not evidence that the resulting policy is complete or enforceable.

Template structure

Use a Word document with:

  1. Document owner, version, approval date, and effective date.
  2. Purpose and relationship to enterprise policies.
  3. Defined supplier, worker, affiliate, agent, and subcontractor scope.
  4. Applicable-law and contract-precedence statement.
  5. Topic-specific standards.
  6. Supplier due diligence and flow-down expectations.
  7. Records, information, and reporting requirements.
  8. Monitoring, audit, and cooperation.
  9. Corrective action and remediation.
  10. Escalation, suspension, and termination.
  11. Questions and reporting channels.
  12. Acknowledgment and authorized signature.
Template fieldRequired detailOwner
ScopeEntities, activities, geographies, and supply-chain tiersLegal and procurement
StandardClear expected or prohibited conductSubject-matter owner
ApplicabilityUniversal, risk-based, or category-specificProcurement and risk
EvidenceRecords, data, certification, assessment, or auditControl owner
ReportingEvent, method, timing, and contactCompliance or incident owner
RemediationAction, owner, due date, validationProcurement and control owner
ConsequenceEscalation and contractual responseLegal and business authority
ReviewVersion, change, supplier acknowledgment, renewalDocument owner

Word format

Use real headings, short paragraphs, controlled lists, defined terms, and a separate acknowledgment page or form. Add a contents table for a longer code. Do not place detailed questionnaires inside the policy; keep assessments and evidence requests in separate tools that can change without rewriting the core code.

Version control matters. Identify which code applies to each supplier and contract. When the code changes, follow the contract's notice and change mechanism rather than assuming a website update automatically binds existing suppliers.

Adapting for your industry

Start with risk mapping. Identify jurisdictions, worker populations, materials, environmental impacts, data, systems, intellectual property, product safety, licenses, intermediaries, government interactions, and sub-tier dependencies. Add detailed provisions only where the organization has a clear objective, evidence method, owner, and response.

For technology, align code-level expectations with the more precise security schedule. NIST 800-161 supports a lifecycle view of supplier risk and emphasizes acquisition, monitoring, incident information, and verification. For labor-intensive categories, use ILO principles and risk-based due diligence. For sustainability, connect data to category metrics and contract methods.

Do not promise anonymity, audit coverage, or remediation the organization cannot deliver. Reporting channels need an owner, confidentiality rules, anti-retaliation controls where applicable, triage, investigation, and response.

Hubzone Depot's vendor sourcing strategy can support qualification and market evaluation before a supplier enters the relationship. The code then communicates minimum conduct expectations across the approved base.

Before release, run legal, compliance, labor, environmental, information-security, privacy, procurement, and operational review as applicable. Pilot the acknowledgment process and confirm that vendor records can store version, date, signer, and exceptions.

What should a supplier code of conduct policy cover, including sustainability?

A supplier code of conduct policy should cover the behaviors and controls that protect people, environment, information, product integrity, lawful commerce, and the buyer's legitimate interests. Sustainability provisions belong inside the same governance model: clear requirement, material scope, evidence, monitoring, and remediation.

Labor and ethics standards

Labor provisions commonly address forced labor and trafficking, child labor, recruitment fees, working time, wages and benefits, nondiscrimination, harassment, freedom of association, collective bargaining, grievance mechanisms, and safe working conditions. Requirements should reflect applicable law and recognized principles without implying that one clause resolves every jurisdictional issue.

Ethics provisions may cover bribery, facilitation payments, gifts, conflicts, fraud, money laundering, fair competition, confidential information, insider information, sanctions, export controls, books and records, and reporting. State whether prior disclosure or written approval is required for specific conflicts, gifts, agents, or government interactions.

Environmental standards

Environmental provisions may require applicable permits, pollution prevention, responsible chemicals management, waste control, resource efficiency, energy and emissions data, water stewardship, packaging, recycling, biodiversity, and incident reporting. Match the level of detail to the category.

The code can set a general duty, while contracts define product-specific standards, baselines, targets, calculation methods, and data frequency. A broad requirement to "reduce emissions" is difficult to enforce without a boundary and measure.

Sustainability reporting expectations

Reporting areaMinimum definitionExample evidence
Labor and safetyCovered workers, locations, period, incident definitionsWorkforce and safety records
Energy and emissionsBoundary, units, method, period, allocationMeter data, inventory, calculation
MaterialsProduct scope and composition methodDeclaration, certification, test
Waste and circularityWeight, destination, recovery methodCarrier or facility record
Supplier diversityCertification scope, direct or Tier 2 spend, periodValid certification and spend file
Due diligenceRisk scope, findings, actions, closureAssessment and corrective-action record

Require accurate, complete, and timely data and preservation of supporting records. Define whether estimates are allowed and how they are labeled. Suppliers should correct material errors and notify the buyer when assumptions or boundaries change.

The OECD due diligence framework includes embedding policy, identifying and assessing impacts, ceasing or mitigating harm, tracking results, communicating, and enabling remediation. A code aligned to that sequence moves beyond declarations by connecting expectations to action.

Sustainability terms should also consider the buyer's own practices. Unrealistic lead times, unstable forecasts, last-minute changes, and unsustainable price pressure can undermine supplier compliance. OECD guidance specifically recognizes that purchasing practices and commercial incentives may create barriers to responsible conduct.

For cybersecurity and resilience, include risk-based expectations for secure products, vulnerabilities, incident notification, continuity, access, and subcontractors. Detailed control requirements belong in agreements and technical schedules that can be tested.

Avoid claiming every supplier has identical impact. Apply universal ethical minimums, then use category and risk modules for labor, environmental, security, quality, and regulatory depth.

What best practices make a supplier code of conduct enforceable, not just symbolic?

A supplier code becomes operational when suppliers acknowledge it, contracts establish its role, controls test compliance, findings produce corrective action, and serious or repeated violations lead to proportionate consequences. Enforcement depends on consistent process, not aggressive wording alone.

Acknowledgment and sign-off

Require an authorized supplier representative to acknowledge the current version before onboarding, award, or renewal according to policy. Record supplier legal name, signer, authority, version, date, exceptions, and related contract.

Incorporate the code by reference or attach it where legal counsel determines appropriate. Define precedence if the code conflicts with the contract, and define how future changes apply. A supplier should not be asked to accept obligations that can be changed unilaterally without the agreed process.

Provide a channel for questions and disclosed gaps. Conditional approval with a time-bound plan may create more improvement than forcing an inaccurate representation.

Monitoring and audits

Use risk-based monitoring. Inputs can include self-assessments, certifications, data, screening, incident reports, grievances, worker feedback, site assessments, product testing, document review, and audits. Independent audit may be appropriate for high-risk situations, but an audit is a sample at a point in time and does not transfer accountability.

The OECD recommends prioritizing the most significant impacts rather than expecting perfect coverage everywhere at once. This helps organizations focus audits and remediation on severity and likelihood instead of sending the same extensive questionnaire to every supplier.

NIST's supply chain guidance similarly connects requirements, monitoring, verification, vulnerability information, and incident processes for ICT and operational technology. The lesson is that the contract and monitoring plan must fit the actual product or service.

Escalation for violations

Finding levelExampleTypical response
AdministrativeMissing acknowledgment or expired recordRequest correction and set due date
ModerateRepeated reporting failure or control weaknessCorrective action and increased monitoring
SeriousMaterial safety, labor, ethics, security, or environmental breachExecutive and control-function escalation
CriticalProhibited conduct, severe harm, deliberate concealment, or legal restrictionSuspend activity, investigate, notify, remediate, or terminate as authorized

Corrective actions need root cause, owner, action, due date, interim protection, evidence, validation, and closure authority. Do not treat termination as the only response. Abrupt exit can worsen harm to workers or communities in some situations; legal, compliance, and responsible-business specialists should determine an appropriate remedy.

Measure effectiveness through recurrence, time to close significant findings, verified improvement, incident severity, supplier coverage, data reliability, and remediation outcomes. Counting signed codes shows reach, not impact.

Enforcement must be consistent and documented. Similar violations should follow comparable decision rules, while severity, supplier leverage, legal duties, business continuity, cooperation, and remediation affect the response. Exceptions require authority and expiration.

The code also needs internal accountability. Procurement, business owners, compliance, sustainability, security, quality, legal, and audit functions must know who receives reports, who decides consequences, and who verifies closure.

What should you do first before rolling out a supplier code of conduct?

Before rollout, map the code to supplier risks, existing contracts, onboarding controls, data systems, and decision owners. The first operational action is to identify which suppliers need acknowledgment, when it will be collected, and what happens if a supplier raises an exception.

Establish scope and baseline

Inventory active suppliers, categories, locations, criticality, contract dates, existing clauses, current codes, risk assessments, and known findings. Segment suppliers by risk and renewal timing. Do not begin with a mass signature campaign if the organization cannot store or act on responses.

Compare the draft code with applicable laws, enterprise policies, customer obligations, recognized standards, and existing supplier requirements. Resolve conflicts and duplication. Define universal requirements and category-specific additions.

Design the enforcement workflow

Assign:

  • Policy owner and approver.
  • Supplier communication owner.
  • Legal interpretation and contract owner.
  • Labor, ethics, environmental, security, privacy, quality, and compliance reviewers.
  • Reporting-channel and investigation owner.
  • Corrective-action owner.
  • Exception and consequence authority.
  • Recordkeeping and renewal owner.

Test four scenarios: full acceptance, requested exception, suspected violation, and refusal to acknowledge. The workflow should produce a consistent decision and record in each case.

Plan phased rollout

Start with new suppliers and upcoming renewals, then address active high-risk suppliers. Provide communication explaining purpose, scope, effective date, acknowledgment method, support, and deadlines. Offer training or guidance where requirements are complex.

Rollout elementRequired decisionCompletion evidence
ScopeWhich suppliers and tiers are covered?Approved segmentation
Legal effectHow is the code incorporated?Contract and precedence language
AcknowledgmentWho signs, when, and where is it stored?Controlled record
EvidenceWhich controls apply by risk?Due diligence matrix
MonitoringWhat data, assessments, and audits occur?Monitoring plan
Violation responseWho triages, investigates, and decides?Escalation procedure
RemediationHow are actions validated?Corrective-action method
ReviewWhen do code and acknowledgments renew?Version and renewal calendar

Require signed acknowledgment before the next renewal cycle where policy and contract strategy permit, but do not wait to address critical risk. New supplier onboarding can apply the current code immediately, while active contracts follow their agreed change mechanisms.

The ILO provides labor-rights foundations, the OECD provides a risk-based due diligence process, and NIST provides cybersecurity supply chain practices. Use each source for its relevant domain and have qualified professionals interpret legal or sector-specific obligations.

The rollout is ready when the organization can answer five questions for every covered supplier: which version applies, who accepted it, what evidence is required, who monitors it, and what happens when a material violation occurs. That turns a statement of values into a managed supplier standard.

More articles

    Let's get you to the right place

    We just need a few quick details.

    How can we reach you?

    Please provide your contact information.

    You may receive marketing communications from Stripe including product updates, industry news and events. You can unsubscribe at any time.

    Thank You! You've successfully subscribed to our newsletter. Stay tuned for updates and insights.