Supplier Code of Conduct: What to Include

A supplier signature is not the same thing as supplier implementation.

A code of conduct can clarify what a buyer expects from suppliers and subcontractors. It can make labor, workplace, integrity, environmental, product, recordkeeping, and transparency expectations visible before problems appear. But a PDF with a signature block does not show whether people understand the code, whether a factory has the systems to apply it, or whether workers can safely raise concerns.

A good supplier code sets a clear baseline and connects it to onboarding, sourcing decisions, communication, worker-safe reporting, corrective action, and regular review.

Legal and labor-rights boundary: This article is general responsible-sourcing education, not legal, labor-rights, regulatory, contractual, audit, or employment advice. It does not determine whether a code is enforceable or adequate, whether a supplier complies, what contract remedy applies, or whether a buyer should begin, continue, or end a supplier relationship. Codes and obligations should be reviewed with current qualified local, legal, labor-rights, and contract advisers for the business and market involved.

Define what the code is for

A supplier code should not try to replace every contract, policy, technical specification, or local-law review. State its role clearly.

The U.S. Department of Labor describes a code of conduct as a document setting out standards and policies with which a company and its suppliers and subcontractors are expected to comply. It also cautions that company-led codes can have limited effect when they are voluntary, lack enforcement, or are not backed by rigorous training for workers and managers. 1

Code purpose What to say in plain language
Baseline expectation The behavior, systems, records, and cooperation the buyer expects from suppliers and relevant subcontractors
Scope boundary Which legal entities, factories, facilities, subcontractors, products, markets, and services the code covers or excludes
Relationship to other documents How the code connects to contracts, purchase orders, technical specifications, product-safety controls, quality plans, and grievance processes
Ownership Which buyer role maintains the code, approves revisions, answers questions, and receives escalations
Supplier responsibility What the supplier must communicate, train, document, disclose, maintain, and escalate within the stated relationship
Review method How the buyer will update the code and how suppliers will be notified of changes

The first page should answer: “Who must follow this? What must they do? What happens when an issue is raised? Where do they ask for help?”

Set clear scope and definitions

Vague scope lets critical relationships fall outside the code. Define the terms that matter to your sourcing model.

Definition to include Why it matters
Supplier Clarifies whether the code covers direct seller, factory, service provider, agent, or another business relationship
Facility/site Avoids treating a brand name or trading company as proof that every production location is covered
Subcontractor Makes it clear when a supplier must disclose planned production or process outsourcing before it occurs
Worker Ensures the code’s worker-focused expectations consider direct, temporary, migrant, agency, contract, and other relevant workers in the applicable context
Product/process Links the code to the actual manufacturing, packing, inspection, logistics, and service work performed
Applicable requirement Identifies the need to follow relevant law, contract, customer, and code obligations with qualified support rather than guessing from a generic template
Concern/complaint Defines a reportable issue and the route for making a good-faith report without retaliation
Corrective action Distinguishes a planned response from verified, sustained improvement

A code may need separate annexes for higher-risk product categories, markets, worker populations, or supply-chain tiers. Adding an annex can be more usable than hiding important detail in an all-purpose document.

Cover worker and workplace expectations carefully

Codes often cover worker-treatment and workplace topics. The objective is to make expectations understandable and route specific legal or technical questions to qualified processes.

The Department of Labor says strong codes commonly cover scope, governance/management, labor standards including wages, hours, overtime, benefits, health and safety, freedom of association, humane treatment, freedom from sexual harassment, management systems, contractual controls, risk reduction, and enforcement mechanisms. 2 Treat this as a planning framework, not a universal legal checklist.

Topic area Operational wording question
Respectful treatment Does the code state that abusive, degrading, discriminatory, harassing, or retaliatory treatment is not acceptable and explain where concerns can be raised?
Freedom of association and worker voice Does the code explain the buyer’s expectation for lawful worker representation/voice and safe communication channels, subject to local qualified review?
Forced and child labor risk Does it state a prohibition and require supplier cooperation, transparent recruitment/workforce facts, and immediate escalation of credible concerns?
Wages, hours, benefits, and contracts Does it require accurate records, lawful treatment, clear worker information, and a route for qualified review rather than promising a generic outcome?
Health and safety Does it expect hazard identification, preventive controls, training, incident reporting, emergency readiness, and safety records appropriate to the workplace?
Recruitment and labor agencies Does it require disclosure of agency use, recruitment practices, fees/conditions concerns, and worker-document controls for review?
Discrimination and harassment Does it make respectful, non-discriminatory treatment and non-retaliation explicit, with safe reporting and response ownership?
Accommodation, privacy, and living conditions If relevant to the supplier relationship, does it state expectations and boundaries around sensitive worker circumstances without asking for unnecessary personal data?

Avoid copying clauses that the business cannot explain or implement. If a requirement belongs in a separate legal, labor, safety, or country procedure, link the code to that procedure and name the owner.

Include management and implementation controls

A code needs operational controls, not only principles.

Implementation element What to include
Leadership commitment Supplier leadership is expected to assign an accountable contact with authority to communicate and manage code-related issues
Policy communication Supplier communicates relevant requirements to managers, supervisors, workers, and subcontractors in understandable formats/languages where appropriate
Training Supplier identifies who needs training, what the training covers, how attendance/understanding is recorded, and when refreshers are considered
Documentation Supplier retains relevant records, policies, training logs, production/workforce data, corrective-action evidence, and source documents according to applicable requirements
Risk assessment Supplier identifies material risks in its operation and communicates significant concerns through agreed routes
Change notification Supplier tells the buyer before a material change in facility, subcontracting, product/process, workforce, ownership, or a relevant risk factor where required by the relationship
Monitoring cooperation Supplier provides reasonable access, records, and factual responses under the agreed process while protecting worker privacy and legal rights
Corrective action Supplier participates in fact finding, action planning, evidence review, effectiveness checks, and escalation under a documented process

The Department of Labor says due-diligence systems should prioritize the supply-chain areas where risk of severe labor abuses is greatest, based on operating context, product/service, and other relevant considerations; it also notes the value of worker and worker-organization perspectives. 3 A code should support that risk-based system, not replace it.

Address product, environmental, and business-integrity expectations

Even when a code is focused on labor and workplace concerns, the supplier relationship often involves other conduct risks. Keep these sections specific enough to guide behavior and route technical/legal decisions to the right process.

Topic Useful code expectation
Product quality and safety Supplier provides accurate product/material/process facts, follows approved specifications, reports changes, and cooperates with qualified product-safety and quality reviews
Environmental practices Supplier complies with relevant requirements and reports material environmental, waste, chemical, resource, or permit-related concerns through the agreed route; do not use the code to make technical determinations
Anti-bribery and conflicts Supplier does not offer or accept improper advantages and discloses relevant conflicts under the buyer’s stated integrity process
Accurate records Supplier does not falsify, conceal, or manipulate records, reports, product facts, worker records, certifications, or audit evidence
Data and confidentiality Supplier protects confidential business data and personal information, while retaining and sharing evidence through authorized channels
Trade/product restrictions Supplier accurately discloses product, material, origin/manufacturer, claim, and compliance facts; open restrictions questions are escalated rather than hidden
Community and security impacts When relevant, supplier raises risk signals through the designated responsible-sourcing or legal process

The code should be consistent with product-compliance, restricted-product, chemical/material, and quality procedures. Contradictory supplier documents invite weak controls.

Build a worker-safe concern and non-retaliation route

A code is more credible when people can use it safely.

Channel control What the code should state
Who can raise concerns Workers, managers, suppliers, subcontractors, business partners, and other stakeholders as appropriate to the channel
Access Contact route, languages/formats, alternative options where possible, and who can answer questions
Good-faith reporting A clear expectation that good-faith concerns can be raised without retaliation
Confidentiality Information is shared only with people who need it for a fair, lawful response, within the limits of the process
Urgent issues How immediate safety, coercion, or other serious concerns are escalated to qualified owners without delay
Investigation/fact finding The business will assess reports through an appropriate process; the code should not promise a pre-decided outcome
Feedback Where safe and appropriate, the reporter is told that the concern was received and how the process will move forward
Protection against misuse The code can prohibit knowingly false records or retaliation without discouraging people from reporting uncertainty or concerns in good faith

Do not require workers to use a manager-controlled route as their only option. Do not ask suppliers to identify confidential interview participants in order to disprove a concern.

Connect the code to sourcing and contracts

A code that never appears in supplier onboarding or purchase decisions will become a file-attachment exercise.

Relationship stage Code control
Supplier inquiry Send the current code, record receipt, and gather questions before the supplier is presented as approved
Onboarding Confirm supplier/facility/subcontractor scope, code contact, required disclosures, risk-intake facts, and any training/implementation plan
Contract/purchase order Obtain qualified contract review to align code expectations, notice, record, access, corrective action, confidentiality, and dispute/remedy language where appropriate
Production change Require advance notice of material factory, subcontracting, workforce, product/process, or risk changes that could affect the code’s scope or evidence
Audit/monitoring Use a documented, worker-safe process with scope, findings, limits, corrective-action ownership, and evidence review; see What Social Compliance Audits Can and Cannot Tell You
Corrective action Assign action owner, support/resources, completion evidence, effectiveness check, escalation, and decision governance
Renewal/expansion Review trends, repeated gaps, open concerns, supplier communication, and buyer-side commercial pressures before expanding the relationship

The Department of Labor calls a code a foundation for detailed guidance used by decision-makers implementing a labor due-diligence system. 2 Give sourcing staff a short implementation guide so they know what to do after the code is signed.

Manage corrective action without treating it as a punishment spreadsheet

Corrective-action field What to record
Issue and source What was reported/observed, the location/process/scope, source/date, and what remains unverified
Immediate protection Any urgent worker/safety or business-integrity control identified by qualified owners
Root-cause work The questions, factory/buyer context, worker-safe evidence, and specialist help needed before choosing a response
Action plan Specific action, owner, resource, target date, evidence of completion, and change to prevent recurrence
Buyer contribution Relevant forecast, lead-time, pricing, payment, specification, capacity, or communication pressure that may need review
Effectiveness Later evidence or review showing whether the control works and the issue has not simply moved elsewhere
Escalation Named governance route for stalled actions, serious concerns, conflicting evidence, or decisions beyond the normal supplier manager
Closure Status only changes after the agreed evidence and effectiveness check; preserve residual risk/open questions

A supplier code cannot promise that every concern will be resolved. It can establish a fair, fact-based way to respond and decide when the issue needs qualified escalation.

Keep the code current and usable

Maintenance control Why it matters
Version/date/owner Prevents suppliers and internal teams from working from different code versions
Translation and accessibility Helps people understand expectations in the appropriate language and format; qualified review may be needed for legal-language accuracy
Training and acknowledgment Shows that relevant people received the code, had a chance to ask questions, and know where to find updates
Supplier feedback Reveals unclear requirements, impossible timelines, local context, and training/support needs before an issue becomes hidden
Review triggers New market, product, supplier tier, legal/customer update, significant incident, recurring finding, business-model change, or annual policy review
Internal alignment Keeps supplier code, responsible-sourcing policy, product controls, contracts, audit method, and grievance process from contradicting each other
Public claims Limits public/customer statements to what the business can support with current evidence and approved ownership

For wider policy architecture, see How to Build a Responsible Sourcing Policy. To check whether supplier evidence matches real product and factory facts, see How to Verify Product Certificates Without Relying on a PDF. For an early product-risk stop process, see How to Avoid Restricted or Banned Products.

Roll out the code without creating a paperwork bottleneck

Plan the rollout in stages. Send the code before onboarding rather than after the first order. Give suppliers a named contact, reasonable time to read it, a way to raise translation or scope questions, and a clear description of the acknowledgments and records required. Train internal buyers on the same document; they need to know which supplier facts, changes, and concerns must be routed before they promise delivery dates. Track unanswered questions and incomplete acknowledgments as open onboarding items, not as administrative noise. The rollout should test whether the code can be understood and used by the people responsible for production and purchasing.

Supplier code of conduct checklist

A usable code sets purpose and scope; defines suppliers, facilities, subcontractors, workers, and concerns; states worker/workplace, product, integrity, record, and disclosure expectations; assigns owners; creates safe reporting routes; connects to onboarding, contracts, changes, monitoring, and corrective action; and stays current through controlled versions, training, feedback, and review.

The signature matters. The operating system behind it matters more every day.

References

  1. U.S. Department of Labor, Develop a Code of Conduct
  2. U.S. Department of Labor, Key Topic: What Makes a Good Code of Conduct?
  3. U.S. Department of Labor, Why Develop a Social Compliance System?
Scroll to Top