What it means
A company buys goods from many factories and service providers. It wants clear expectations for safe work, lawful wages and honest business conduct.
A supplier code puts those expectations in one document. The OECD recommends risk-based due diligence across operations and supply chains.
A code can communicate standards, but due diligence also needs assessment, action and follow-up. Define the scope by stating which suppliers, subcontractors and sites are covered, since a first-tier signature may not reach the factory doing the work.
Use clear language and translate where needed, because requirements should be understandable to suppliers and workers in their own languages, and vague values make verification difficult. Cover human rights, addressing forced labour, child labour, discrimination and freedom of association as relevant, while remembering that local legal rules and international expectations may differ.
Cover safety by specifying safe working conditions and incident reporting, cover ethics by prohibiting bribery and conflicts of interest with a channel for reporting concerns, and cover the environment with expectations for waste, emissions or resource use proportionate to the sector and contract. Consider data protection, since suppliers handling personal or confidential data need relevant security and privacy duties that a generic environmental code will not cover, and make sure procurement staff follow the same ethical principles.
Connect the code to contracts with clear obligations, reporting and remedies, because a standalone PDF with no contractual route may have limited effect. Check feasibility and train buyers: small suppliers may need time or support to meet new standards and unrealistic deadlines can encourage false attestations, while purchasing teams should not demand prices or deadlines that make safe working conditions impossible.
Assess risk so that high-risk regions, materials or processes get deeper review than low-risk purchases, and do not audit every supplier identically. Verify claims using self-assessments, worker interviews, site visits and records, since no one method is complete, and consult workers safely because managers may not see or report every issue.
Protect reporting so workers can raise issues without retaliation, since a hotline nobody trusts is ineffective, and handle audit records carefully by limiting access and retention to what is needed, because they can contain sensitive worker information. Respond to problems with investigation and a corrective plan, remembering that immediate termination may sometimes worsen harm to workers, and track remediation by assigning owners and deadlines and verifying changes, since a signed action plan is not the same as a fixed workplace.
Set escalation so that serious or repeated harm may lead to suspension or ending a supplier relationship, with a plan that considers affected people, review subcontractors by requiring visibility and escalation from the direct supplier, and update standards as laws, markets and risks evolve. Measure beyond sign-up, because the proportion of suppliers signed is easy to report but says little about compliance quality, so track risks and resolved findings, align with credible standards to avoid conflicting customer codes, keep requirements proportionate so they are not used to exclude suppliers unfairly, and remember that for owners the real test is whether the company checks important risks and helps correct actual harm.
In practice
Real-world examples.
Example
A manufacturing supplier agrees to safety and labour standards in its contract. The code is attached as a schedule, with reporting duties and remedies spelled out. The supplier's management confirms in writing that the standards also apply to its subcontractors.
Example
A buyer checks a high-risk subcontractor site rather than relying only on a signed form. The visit includes confidential worker interviews and a review of working-hours and payroll records. The findings are shared with the direct supplier with a dated plan for correction.
Example
A supplier corrects a hazardous process under a verified improvement plan. The buyer reviews photographs, training records and a follow-up inspection before it accepts the fix. The case is closed only when the evidence shows the new control working in practice.
Formula
Calculation
Illustrative sign-up rate = active suppliers that accepted the code / active suppliers in scope x 100. At 90 of 100, the rate is 90%; it does not measure actual compliance.
Two companion measures give a fuller picture. Risk coverage = high-risk sites reviewed / high-risk sites in scope x 100, so 15 reviewed of 20 gives 15 / 20 x 100 = 75%. Verified remediation rate = findings verified as fixed / findings raised x 100, so 9 fixed of 12 raised gives 9 / 12 x 100 = 75%.
Read the three together: a 90% sign-up rate with 75% risk coverage and 75% verified remediation tells a more honest story than the sign-up rate alone, and the 25% still open points to the sites and findings needing attention next.Case study
Seen in the real world.
Entirely fictional case: Birch Apparel asks factories to sign its code. A review finds unsafe exits at one subcontractor despite a signed declaration. Birch and its supplier agree on immediate safeguards and a verified repair plan. Birch also reviews its purchasing deadlines, which contributed to pressure on the site.
Birch then changes how it reports progress. Instead of quoting the number of signed codes, its quarterly report lists the high-risk sites reviewed, the findings raised and the findings verified as fixed. It also trains its buyers to check delivery deadlines with the factory before agreeing them, so commercial pressure does not undermine the standards written in the code.
Watch out
Common mistakes.
- Treating a signature as proof of safe practice.
- Setting demands that conflict with the buyer's prices and deadlines.
- Terminating every supplier immediately without considering remediation and worker harm.
Questions
People also ask.
What is a supplier code of conduct?
A document stating standards the buyer expects from suppliers.
Is publishing a code enough?
It communicates expectations but needs risk assessment, monitoring and corrective action.
How should a buyer handle a breach?
The buyer should investigate, address risk and use contractual remedies proportionately.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%