Questions to Ask Vendors About Their Compliance Programs
These are questions to ask vendors about their compliance programs when you are the one signing off on the supplier: in compliance, procurement or risk, at onboarding or when a periodic review comes round. The groups follow the order such a review usually takes: who runs the program, how the code, training and reporting line reach staff, bribery and sanctions controls, data and the supply chain, audits and past problems, and last what the vendor will put in the contract. Match the depth to the vendor's risk, since a low-risk local supplier does not need every group.
Want questions from the whole vault instead? Try the random question generator.
The questions
Each question, and why to ask it
Who runs it
Who is responsible for compliance at your company, and is it their whole job?
Why ask it
A named person with the title and the time is the starting point for everything else you ask. Where compliance is one of several hats worn by the finance lead or the general counsel, find out roughly how much of their week it gets and who covers when they are away.
Who does the head of compliance report to, and do they have a direct line to the board or the owners?
Why ask it
The reporting line shows whether bad news can travel upward past the person it embarrasses. Ask when the compliance lead last presented to the board or owners and what was on the agenda. A date and a topic are more convincing than an org chart.
Can you send us your compliance policies, with the date each one was last reviewed?
Why ask it
Review dates say more than the titles do. A policy untouched for years while the vendor grew or entered new markets has probably stopped describing what staff do. Note who approves revisions, because that is the person to ask about any policy that looks stale.
When did you last carry out a compliance risk assessment, and what came out as your top risks?
Why ask it
A vendor that can name its three biggest risks without looking them up has done the thinking. Set their list beside the reasons you rated them as a risk. If you worry about their use of sales agents and agents never come up, raise it yourself.
Which laws and regulators apply to the work you would do for us, and who tracks changes to them?
Why ask it
Let them give their list before you offer yours, since what they leave out is the finding. The right list depends on the countries, the sector and the service, so have your own counsel check it and do not treat either side's memory as complete.
How many people work on compliance, and what budget or outside help do they have?
Why ask it
The point is whether the program is sized for the business. Two people can be plenty for a small vendor in one country. For one selling through agents in many countries, ask who covers each region.
How does senior leadership take part in compliance, beyond signing the policy?
Why ask it
Look for something leaders do on a schedule, such as reviewing hotline figures or opening a training session. If the answer is the chief executive's foreword to the code, ask who decided the last hard case where a sale and a rule pulled in different directions.
What has changed in your compliance program in the last two years, and what prompted it?
Why ask it
Living programs change: a new policy after an acquisition, extra screening after entering a market, retraining after an incident. 'Nothing' from a company that has grown in that time deserves a second question about how they know the program still fits.
Training and reporting
Do you have a code of conduct, and who does it apply to?
Why ask it
Ask for the current version and read the scope clause first: employees only, or contractors, agents and temporary staff too. Also ask how often people re-confirm it, because a signature collected at hiring says little about someone who joined eight years ago.
What compliance training do staff receive, and who gets more than the basic course?
Why ask it
A general course for everyone is the floor. The staff who matter to you are in sales, purchasing and finance, plus anyone who meets public officials or handles your data. Find out what extra they get and whether it draws on real cases from the business.
What was the completion rate in your last training cycle, and what happens to people who miss it?
Why ask it
A figure produced on the spot suggests someone tracks it. The second half matters more: whether a manager is told, whether system access or a bonus is affected, or whether reminders simply continue until the next cycle starts.
Will the people assigned to our account be briefed on our requirements as well as your own?
Why ask it
Your supplier standards mean nothing to staff who have never seen them. See whether the vendor would run your training module or accept a short session from your side, and who would brief replacements when the account team changes.
Do you run background checks on the staff who would work on our account, and what do they cover?
Why ask it
Find out whether the check happens once at hiring or is repeated, and whether temporary and contract staff go through it too. What an employer may look into differs by country and sometimes by state, so ask what is checked in each place your work would be done. In sectors where a regulator keeps a list of excluded or barred individuals, ask whether staff are screened against it as well.
How can an employee or an outsider report a concern, and can they do it anonymously?
Why ask it
Find out who answers the line, in which languages, and whether subcontractor staff and your own people may use it. Rules on anonymous reporting and whistleblower protection differ from country to country, so ask how the channel works in each place the vendor operates.
Roughly how many reports came in last year, and how many led to some action?
Why ask it
A reporting line that receives nothing in a company of any size deserves a second look, because it can mean staff do not know about it or do not trust it. Case details are not needed. Volume, the main categories and the number substantiated are enough.
When a report comes in, who investigates it, and what happens if it names a senior manager?
Why ask it
The first half should produce a named function and a rough time to close a case. The second half is the harder test: a report about the chief executive or the head of sales needs a route that does not pass through that person, such as the board, the owners or outside counsel.
How do you protect someone who raises a concern from retaliation?
Why ask it
The policy sentence is the easy part. Press on how they would find out that a reporter had been sidelined afterwards, and whether anyone checks in with reporters a few months after a case closes.
Has a senior person or a top performer ever been disciplined for a compliance breach, and what happened?
Why ask it
No names are needed, only the level of the person and the outcome. A program that has only ever disciplined junior staff has shown the sales team where the real line sits.
How do conduct and compliance figure in performance reviews, bonuses and promotions?
Why ask it
Incentives pull harder than policies. Where sales targets carry the whole bonus, ask what stops a manager from looking away near quarter end and whether anyone has lost variable pay over conduct.
Bribery and sanctions
What does your anti-bribery policy cover, and does it bind everyone who acts on your behalf?
Why ask it
Check that agents, distributors, consultants and joint venture partners are inside it, since much of the exposure sits with them. Which anti-corruption laws reach the vendor depends on where it is incorporated and where it trades, so have them name the ones they work to.
What are your rules on gifts, hospitality and travel, and could we see a sample of the register?
Why ask it
Value limits and a pre-approval step show the rule can be applied on an ordinary working day. Entries in the register are evidence it is. An empty register after a year of client entertaining tells you the opposite.
Would any part of this work involve dealing with government officials or state-owned bodies, directly or through someone else?
Why ask it
The answer decides how deep to go on the rest of this group. Permits, customs clearance, inspections and licenses are the usual points of contact. For each one, establish who handles it and whether a local agent is paid on success.
How do you respond to requests for small unofficial payments to speed something up?
Why ask it
You are hoping for a clear rule and a story about a time it was tested. Legal systems treat these payments differently, so ask which standard the vendor applies across every country and what staff are told to do when the request is made face to face.
How do you choose, pay and monitor agents and intermediaries who win or keep business for you?
Why ask it
Commission well above the local norm, payment into an account in a third country and a vague description of services are the classic warning signs. Request the blank due diligence template for intermediaries and the interval at which each one is screened again.
What are your rules on political contributions, charitable donations and sponsorships?
Why ask it
All three can carry a payment that could not be made openly. Who approves them is the first follow-up. The second is whether a request that comes from a customer or an official is handled differently from one the vendor thought of itself.
How do you identify and manage conflicts of interest, including any with our own staff?
Why ask it
Put it plainly: does anyone at the vendor have a family or financial tie to someone in your organization, and how would a new tie be declared? This is one of the few answers you can check against your own conflict disclosures, so do.
Do you screen customers, suppliers and payees against sanctions lists, and how often?
Why ask it
A check run once at onboarding misses anyone listed later, so establish whether screening is continuous or periodic and which lists are loaded. The lists that matter depend on the jurisdictions touching your deal. Have your own team confirm the set.
What happens when a screening check returns a possible match?
Why ask it
The detail worth having is who clears the alert, how fast, and whether the transaction is held in the meantime. A rough count of last year's alerts and of true matches among them shows whether the process is exercised or theoretical.
Do you look at who owns and controls the companies you deal with, or only at the company name?
Why ask it
A clean name can sit in front of an owner who is on a list. See how far up the ownership chain the vendor looks, and what it does when a counterparty refuses to say who is behind it.
Are any goods, software or technical data in this work subject to export or trade controls?
Why ask it
Skip this for purely local services. Where it applies, the follow-up is who classifies the items and who applies for licenses, since the answer turns on the products and countries involved and is not something to assume from a sales deck.
How would your finance controls catch an improper payment?
Why ask it
Improper payments are often recorded under ordinary headings such as consulting fees, commissions or marketing costs. Find out whether a payment to a third party needs a contract and proof of service before release, and whether anyone samples those payments afterwards.
Data and supply chain
What personal or confidential data of ours would you handle, and where would it be stored and processed?
Why ask it
Make them map it for your engagement instead of describing their general setup. Where the data sits is one of the things that decides which privacy rules apply, and those vary by country and sometimes by state, so pass the answer to your privacy lead before going further.
If a data breach affected us, how soon would we be told, and by whom?
Why ask it
Get the answer in hours or days, then see whether they will write that figure into the contract. Legal notification deadlines differ by jurisdiction and sector, so set the contractual period against whatever your own obligations require.
How long do you keep our data, and how is deletion or return confirmed when the work ends?
Why ask it
Backups and copies held by subcontractors are the parts that outlive a contract, so ask about both. Requesting a deletion certificate now keeps it from becoming a negotiation at exit.
Which subcontractors or sub-suppliers would touch our work or our data?
Why ask it
You want names, locations and what each one does. A vendor that needs a week to assemble that list has just told you how closely it watches them.
How do you vet a subcontractor before using it?
Why ask it
The fair test is whether they put to their suppliers what you are putting to them. Get a copy of the questionnaire or checklist and note what it leaves out. Sanctions, labor standards and data handling are the usual gaps.
Do your compliance requirements flow down into subcontractor contracts, and how do you check they are met?
Why ask it
A clause copied into a contract is not monitoring. The telling details are when they last audited or visited a subcontractor, what turned up, and whether they have ever ended a relationship over a compliance failure.
Would you tell us before adding or changing a subcontractor on our account?
Why ask it
Decide beforehand whether you want notice or a right to object, because the two are negotiated differently. Then ask how much warning they could give in practice. A vendor that swaps suppliers at a few days' notice will sign a thirty-day clause it cannot keep.
How do you address forced labor, child labor, wages and working hours in your own operations and your supply chain?
Why ask it
This matters most for manufacturing, logistics, agriculture and outsourced staffing. Ask what they could show you, such as site audit reports, and how many tiers down those reach. Supply chain disclosure duties vary by country, so confirm which ones fall on you.
Audits and history
Which compliance certifications or attestations do you hold, and what exactly does each one cover?
Why ask it
A certificate can be limited to one site, one product line or one legal entity. Get the document itself with the issuing body and expiry date, and confirm that the part of the business serving you falls inside it.
Who audits your compliance program, internally and externally, and how often?
Why ask it
An internal audit team that reports to the board carries more weight than a self-review by the compliance function. Find out when the last audit finished and whether the auditors were free to choose what they examined.
What were the main findings of your last compliance audit, and which are still open?
Why ask it
An audit of any depth usually turns something up, so a clean sheet invites a question about how far it went. What you want is the open items with an owner and a date against each, and a promise to tell you when the ones touching your work are closed.
Which licenses, permits or registrations does this work depend on, and are they all current?
Why ask it
Copies, renewal dates and the name of whoever tracks them are the things to collect. What a vendor must hold depends on the sector and the place, so confirm the requirement with the relevant authority or your counsel for the location where the work is done.
In the last five years, has the company or any director or senior manager been investigated, fined or penalized by a regulator or prosecutor?
Why ask it
Run your own public-record and news search first, then ask. A vendor that volunteers what you already found is easier to trust than one that has to be led to it. Repeat the question in the written questionnaire so the answer is on file.
Is there any current litigation, investigation or whistleblower complaint that relates to compliance?
Why ask it
They may be limited in what they can say about a live matter, and that is reasonable. The subject, the stage it has reached and whether it involves the unit or people who would serve you are fair things to request.
Have you ever been debarred, suspended or removed from a customer's or a government's supplier list?
Why ask it
Many debarment lists are public, so this is partly a test of candor. After a yes, ask about the cause and the conditions the vendor had to meet to return.
What is the most serious compliance failure you have had, and what did you change afterwards?
Why ask it
Here is where a working program and a binder on a shelf part ways. Listen for how the problem came to light. Caught by their own controls and reported upward is a far better story than found by a customer or a journalist.
How do you measure whether the program is working, and who sees the numbers?
Why ask it
Training completion alone measures attendance. Stronger answers add hotline volume and closure times, the due diligence backlog, audit findings closed on schedule, and survey results on whether staff feel safe speaking up.
Contract
Will you sign our supplier code of conduct, or show us where yours is equivalent?
Why ask it
If they offer their own code in its place, have someone compare the two line by line before agreeing. The differences tend to sit in subcontractor coverage and in the duty to report breaches to you.
What compliance representations and warranties are you prepared to give in the contract?
Why ask it
Raise this before the lawyers exchange drafts, so the commercial team hears the answer too. Typical requests are that no bribe has been or will be paid in connection with the work, that no owner or director is on a sanctions list, and that the licenses the work depends on are held. How each is worded, and what follows if one proves untrue, is for your counsel under the law that governs the contract.
Will you agree to audit rights, and what limits would you want on them?
Why ask it
Notice periods, a cap on frequency and who pays are all normal points to negotiate. A flat refusal is different. Ask what they would offer in its place, such as an independent report or sight of their internal audit results.
Will you commit to telling us promptly about a violation, an investigation or a sanctions issue that touches our work?
Why ask it
Define promptly as a number of days and name the person on your side who takes the call. Without the clause, what you learned in this review is a snapshot the vendor has no duty to update.
Would you accept our right to suspend or end the contract if a serious compliance breach comes to light?
Why ask it
The debate will be over what counts as serious and whether they get time to put it right. Bring examples of what you mean, such as a bribery charge or a sanctions designation, and leave the final wording to counsel.
Are you willing to certify compliance each year and update the answers you have given us today?
Why ask it
An annual certificate costs an honest vendor little and gives you a dated statement to rely on. Check who would sign it. A signature from a director or the compliance lead means more than one from the account manager.
Who is our contact for compliance questions after signing, and how do we escalate past them?
Why ask it
The account manager is rarely the right person to hear a concern about their own deal. Get a name in the compliance function and a second one above it, and try the contact details once before you need them.
What do you need from us to keep the relationship compliant on your side?
Why ask it
Careful vendors run due diligence on their customers too, and may send you forms or a code of their own. Hearing what they ask of clients is a quiet check on how seriously they take the subject.
Getting a vendor compliance review to tell you something
Practical guidance for the conversation itself
Before you send anything
Rate the vendor's risk first
Few suppliers need the whole list. Sort each one by what it does for you: where it operates, whether it meets officials on your behalf, whether it holds personal data, how much you spend with it and how hard it would be to replace. A local office supplier may need only the first few questions under Who runs it and two under Contract. An overseas sales agent needs everything under Bribery and sanctions, asked in person.
Run your own checks before hearing theirs
Search public records, news coverage and the sanctions and debarment lists relevant to your deal for the company and its principals before the conversation. The questions under Audits and history then test candor as well as collecting facts, because you already know part of the answer.
Agree who on your side reads which answers
Sanctions answers belong with whoever runs your screening, data answers with your privacy lead, contract answers with counsel. Assign each group of questions to a reader before the replies arrive, or a forty-page response will be skimmed by one person who is expert in a fifth of it.
Tell the vendor why you are asking
A short covering note helps: what the review is for, which parts are standard for every supplier in their risk tier, who will see the answers and when you need them. Vendors tend to answer more fully when they can tell a routine review from a sign of suspicion.
Questionnaire, call or visit
Put the factual questions in writing
Policies, certificates, license numbers, subcontractor names and the history of fines or investigations suit a written questionnaire. The vendor can gather documents, a named person signs the response, and you have a dated record to compare against next year's.
Keep the judgment questions for a conversation
The worst failure they have had, how a senior person was disciplined and what happens when a sale and a rule collide get rehearsed prose on paper. Asked aloud, they get hesitation, detail and follow-ups, which is where the information is.
Speak to the compliance lead, not only to sales
The account team will often answer from a prepared sheet. Ask for half an hour with the person who runs the program. How easily that meeting is arranged, and whether they can talk without the salesperson steering, is an answer in its own right.
Ask for the document behind the answer
For every yes, request one piece of evidence: the policy, the training record, a redacted register page, the audit summary. You will not read all of it. Vendors that can produce it within days differ from vendors that have to create it.
Weighing what comes back
Judge the program against the vendor's size and risk
A twenty-person firm is unlikely to have a hotline provider or an internal audit team, and should not be marked down for that. What it does need is a named owner, a few written rules that fit its real risks and proof they are followed. A multinational with the same thin setup is a different finding.
Separate gaps you can live with from ones you cannot
Missing training records can usually be fixed within a few months. An agent paid on success to deal with officials, with no due diligence file, is a reason to pause. Write down which findings are conditions to close before signing, which go into a remediation plan with dates, and which end the discussion.
Notice how the hard questions were handled
A vendor that discloses an old fine, explains what changed and offers the paperwork is showing you how it will behave when something goes wrong on your account. Evasion on the same question predicts the opposite, whatever the policies say.
Record the decision and its reasons
Keep the answers, the evidence, who reviewed them and why the vendor was approved, approved with conditions or declined. If a problem surfaces later, that file shows what you asked and what you were told. Ask your own counsel what your organization is expected to retain and for how long.
Where these reviews go wrong
Treating a certificate as the whole answer
A certification shows that a defined scope met a standard on the day it was assessed. It does not cover the subsidiary outside that scope, the agent hired last month or the conduct of the team on your account. Use it to shorten the questions, not to replace them.
Asking once and never again
Onboarding answers age. Set a review interval by risk tier, and name the events that trigger an early one: a change of owner, a new country, a new subcontractor, an adverse news story. At a periodic review, start from last time's open items.
Sending every question to every vendor
A long form sent to a low-risk supplier gets boxes ticked by whoever has time, and it teaches your own colleagues that the process is a formality. Shorter and targeted gets truer answers.
Letting the deal deadline set the depth
Reviews are often started the week the business wants to sign. Ask procurement to bring compliance in when the shortlist is made, so that a slow reply from a vendor is a finding and not a reason to skip the question.