Policies
Written by Joanne Hughes, Policy & Compliance SpecialistLast reviewed

Why Customers Ask for Your Supply Chain Policy

If you supply larger organisations or bid for public contracts, you have probably been asked to produce a supply chain policy. The request usually arrives in a tender questionnaire, a supplier onboarding pack or a contract renewal, often with a short deadline attached.

The reason is regulatory cascade. Section 54 of the Modern Slavery Act 2015, the Procurement Act 2023 and the failure to prevent fraud offence under the Economic Crime and Corporate Transparency Act 2023 all place duties on large organisations and public bodies. Those organisations discharge their duties by checking the suppliers beneath them, so the paperwork lands on you.

Few of these laws name smaller suppliers directly, and many businesses receiving the requests sit below every statutory threshold involved. That offers little protection in practice. If your customer is regulated, your contract will carry the requirements whether the legislation does or not.

This article explains what a supply chain policy covers, which laws and frameworks drive the requests, and what buyers are looking for when they assess your supply chain oversight.

The Requests at a Glance

What drives the requestWho it binds directlyWhy it reaches you
Modern Slavery Act 2015, section 54Commercial organisations with annual turnover of £36 million or moreStatements must describe supply chain due diligence, so large customers question their suppliers
Procurement Act 2023Public bodies awarding contracts, in force since 24 February 2025Exclusion and debarment grounds cover supplier conduct, including modern slavery offences
Failure to prevent fraud, ECCTA 2023Large organisations meeting two of three size tests, in force since 1 September 2025Reasonable procedures must cover fraud by agents and other associated persons
Cyber Security and Resilience BillOperators of essential services and managed service providers, still before Parliament as of July 2026Supply chain security duties are expected to flow down through contracts

Who Is Asking

Three groups generate most of the requests. Public sector tender evaluators ask because procurement rules require them to assess supplier conduct before awarding contracts. Large private sector customers ask because their own modern slavery statements and fraud prevention procedures depend on knowing who is in their chain.

Prime contractors are the third group. They carry compliance risk for their whole delivery chain, so they push their obligations down to subcontractors through flow-down clauses and supplier codes.

Regulated customers add a further layer. Banks, insurers, defence contractors, utilities and health providers face sector rules on outsourcing and operational resilience, which makes their supplier onboarding processes among the most demanding you will meet.

What Is a Supply Chain Policy?

A supply chain policy sets out how your organisation selects, manages and monitors the suppliers and subcontractors it depends on. It states the standards suppliers must meet, the checks you run before and during the relationship, and what happens when a supplier falls short.

It is a different document from a modern slavery statement, although the two overlap. The statement is an annual public report required of organisations above a turnover threshold. The policy is the internal rulebook that makes the statement true.

For a customer, your policy is evidence. A buyer cannot audit every supplier at every tier, so it asks each supplier to show that it manages its own tier competently. A written policy, applied in practice, is the simplest form of that assurance.

What a Supply Chain Management Policy Covers

There is no single statutory format, but customer and tender expectations are consistent. A supply chain management policy normally addresses six areas:

  • Supplier due diligence. The checks run before a supplier is approved, such as financial standing, insurance, regulatory compliance and sanctions screening, with deeper checks reserved for higher-risk suppliers.
  • Modern slavery and ethical sourcing. How the risk of forced labour, human trafficking and unethical practices is assessed and managed across the chain, in line with the Modern Slavery Act 2015.
  • Business continuity. How the organisation responds if a key supplier fails, including alternative supplier arrangements, stock buffers and escalation routes.
  • Subcontractor management. Whether and how suppliers may subcontract, and how your standards flow down to the tiers below them.
  • Oversight and monitoring. Performance measures, audit rights, review frequencies and named accountability for supplier relationships.
  • Information and data security. Requirements for suppliers who handle your data or connect to your systems, an area regulators are paying increasing attention to.

The depth should be proportionate. A twenty-person business does not need the supplier governance framework of a listed company, but it does need a document that reflects what the business actually does.

The Laws Driving the Requests

Modern Slavery Act 2015: The Section 54 Cascade

Section 54 requires commercial organisations with an annual turnover of £36 million or more to publish a slavery and human trafficking statement each financial year. The statement must be approved by the board, signed by a director and published on the organisation's website with a prominent homepage link, as set out in the government guidance on publishing a statement.

The statement is expected to describe the organisation's due diligence processes and where slavery risk sits in its supply chains. A large customer cannot describe that due diligence unless it has questioned its suppliers, so questionnaires and policy requests cascade down the chain to businesses far below the threshold.

Public sector buyers ask the same questions of bidders of every size. Our guide to modern slavery statements for public sector tenders explains what a proportionate response looks like for a smaller supplier.

Procurement Act 2023: Public Contracts

The Procurement Act 2023 has governed most public procurement in England, Wales and Northern Ireland since 24 February 2025. It gives contracting authorities sharper tools for scrutinising supplier conduct, including mandatory and discretionary exclusion grounds and a central debarment list that can bar a supplier from public contracts for up to five years.

The mandatory exclusion grounds in Schedule 6 to the Act include convictions for slavery and human trafficking offences under the Modern Slavery Act 2015. Contracting authorities therefore examine how bidders govern their supply chains, and tender questionnaires routinely ask for the policy that proves it.

Our Procurement Act 2023 supplier guide covers the regime in detail, including how supplier registration, exclusion and debarment work.

The Cyber Security and Resilience Bill

The Cyber Security and Resilience (Network and Information Systems) Bill is expected to add a cyber dimension to supply chain requests. The Bill completed its Commons stages in June 2026 and had its second reading in the House of Lords on 14 July 2026, so at the time of writing it remains before Parliament and its final text may still change.

As drafted, it widens the Network and Information Systems regime to cover additional sectors, including managed service providers, and strengthens duties around supply chain security. If it passes in its expected form, regulated customers will need assurance about the security practices of their suppliers, and contracts are the mechanism they will use to get it.

Progress can be tracked on the Parliament page for the Bill. Our small business guide to the Cyber Security and Resilience Bill explains the expected cascade in more detail.

Failure to Prevent Fraud Under ECCTA 2023

The failure to prevent fraud offence, created by the Economic Crime and Corporate Transparency Act 2023, came into force on 1 September 2025. A large organisation commits the offence if a person associated with it commits a specified fraud offence intending to benefit the organisation, unless the organisation can show it had reasonable fraud prevention procedures in place.

An organisation is large for these purposes if it meets at least two of three conditions: more than 250 employees, turnover above £36 million, or a balance sheet total above £18 million. Associated persons include employees, agents and others performing services for the organisation, which is why fraud prevention procedures reach into supplier and subcontractor relationships.

The Home Office guidance sets out the principles those procedures should follow, and conviction carries an unlimited fine. Our failure to prevent fraud employer guide covers the offence and the 2026 Fraud Strategy in full.

What Buyers Mean by Supply Chain Oversight

Supply chain oversight is the ongoing part: the monitoring, reviewing and escalation that happens after a supplier is approved. Evaluators distinguish sharply between a business that vets suppliers once and a business that keeps watching.

Good oversight evidence includes risk-tiering of suppliers, scheduled performance reviews against defined measures, audit or inspection rights that are actually exercised, and a named owner for supplier governance. It also includes flow-down, meaning contract clauses that push your standards to your suppliers' own subcontractors.

Tender scoring reflects this. A policy that describes onboarding checks but says nothing about what happens in year two of the relationship reads as incomplete, and it scores accordingly.

Common Failure Points When a Customer Asks

The same problems appear repeatedly when suppliers respond to these requests:

  • A template policy that still references another organisation's sector, structure or supplier base.
  • A policy that contradicts the organisation's modern slavery statement, website or tender answers.
  • No named owner, so nobody reviews the document and the customer's follow-up questions go unanswered.
  • No subcontractor provisions, leaving the tiers below you invisible to the customer.
  • Business continuity covered in a single sentence, with no alternative supplier arrangements identified.
  • Claims of accreditations or audit programmes the business does not actually hold or run.

Buyers read a lot of these documents. A policy that does not match the business that submitted it is spotted quickly, and the damage to credibility spreads across the rest of the bid.

The Cost of Not Having One

The immediate cost is commercial. Supply chain questions in tenders are often scored, and sometimes operate as a pass or fail gateway. A missing or inadequate policy loses marks at best and disqualifies the bid at worst, and private sector customers apply similar tests during onboarding and renewals.

The regulatory costs sit further back but are real. Section 54 can be enforced by injunction, a conviction for a Schedule 6 offence can put a supplier on the debarment list for up to five years, and a large organisation convicted of failure to prevent fraud faces an unlimited fine.

There is also contract risk. Supplier codes and framework agreements commonly allow termination for compliance failures, so a weak answer to a supply chain question can threaten existing revenue as well as new bids.

Supply Chain Policy and Procedure Writers

Policy Pros writes supply chain policies and procedures for UK businesses of every size, from proportionate documents for small suppliers facing their first tender questionnaire to full supplier governance frameworks. Every document is written around your actual supplier base, risk profile and customer requirements rather than adapted from a generic template.

Our supply chain management policy writing service covers supplier due diligence, ethical sourcing, modern slavery provisions, business continuity, subcontractor management and oversight arrangements. If the request has arrived inside a bid, our tender and RFP support service can help you respond to the wider submission as well.

To discuss a supply chain policy for your business, contact Policy Pros for a quote.

Frequently Asked Questions

What is a supply chain policy?

A supply chain policy is a document setting out how an organisation selects, manages and monitors its suppliers and subcontractors. It typically covers supplier due diligence, ethical sourcing and modern slavery, business continuity, subcontractor management and ongoing oversight. Customers and tender evaluators ask for it as evidence that you manage your own tier of the supply chain competently.

What should a supply chain management policy include?

A supply chain management policy should include supplier selection and due diligence criteria, modern slavery and ethical sourcing commitments, business continuity arrangements for supplier failure, rules on subcontracting and flow-down of standards, and monitoring arrangements such as performance reviews and audit rights. It should also name who is accountable for supplier governance. The depth should be proportionate to the size and risk profile of the business.

What is supply chain oversight?

Supply chain oversight is the ongoing monitoring of suppliers after they have been approved. It includes risk-tiering, scheduled performance reviews, exercising audit or inspection rights, escalation routes when problems arise, and contract clauses that push standards down to subcontractors. Tender evaluators look for evidence of oversight, since it separates businesses that vet suppliers once from businesses that manage them continuously.

Is a supply chain policy a legal requirement in the UK?

There is no general statutory duty for a UK business to hold a supply chain policy. The nearest legal duty is section 54 of the Modern Slavery Act 2015, which requires organisations with turnover of £36 million or more to publish an annual slavery and human trafficking statement. In practice, contracts, supplier codes and tender questionnaires make a written policy a commercial requirement for many far smaller businesses.

Why do customers ask suppliers for a supply chain policy?

Customers ask because laws and frameworks hold them accountable for their own supply chains. Modern slavery statements must describe supplier due diligence, the Procurement Act 2023 requires public buyers to assess supplier conduct, and the failure to prevent fraud offence makes large organisations liable for fraud by their agents. The only way a customer can meet those duties is to question and monitor its suppliers.

Do I need a modern slavery statement if my turnover is below £36 million?

No. The section 54 duty to publish an annual statement only applies at £36 million turnover or above. Buyers may still ask smaller suppliers for a modern slavery policy or a short description of their approach, which is a proportionate due diligence request rather than a demand for a full board-approved statement.

Share:
Trustpilot Reviews - 5 Stars