Skip to content

Use case · Supplier compliance review

Supplier compliance review, with the evidence attached

Run a supplier’s certificates, policies, corrective actions and agreements against the requirements your policy sets. Every finding links to its source. Where nothing supports a requirement, the finding says so.
Built for
Supplier Quality Engineers and Supplier Assurance Coordinators, reporting to the Quality or Technical Manager who signs the approval.
When it runs
A customer or certification body asks for the approval file on a named supplier, or a supplier is up for periodic re-approval.

The template

Four starting requirements, in a reviewer’s words

The Supplier Compliance Review template is where most programmes begin. Keep these, edit them, or add your own.
  1. Req. 1

    Does the supplier hold the certifications we require?

    Evidence it looks for

    certificate · schedule of registration · accreditation record

  2. Req. 2

    Are the supplier’s policies current?

    Evidence it looks for

    policy document · issue or revision record

  3. Req. 3

    Have corrective actions been completed and closed?

    Evidence it looks for

    corrective action record · closure evidence · CAPA log

  4. Req. 4

    Are the required documents on file at all?

    Evidence it looks for

    supply agreement · quality agreement · questionnaire return

What a finding shows

On file, not on file, and only related

For each requirement the reviewer sees what is on file, opens it at its source, and gets a gap they can send to the supplier.

Key to findings

…certificate valid until 2 March 2028…
Evidence located
A passage DataStruct could support against the requirement, shown with its file, page and section, or its sheet and rows.
…annual review completed…
Cited, not confirmed
A source the answer relied on that DataStruct could not confirm as support. Listed first, so the reviewer opens it first.
…the policy requires an annual test…
Related material
Returned by the search and not used as evidence. Kept apart so it never reads as proof.
[ no supporting passage ]
No supporting evidence located
Nothing in the set supports the requirement. The finding says so and names what is missing.
Confirmed · reviewer

Only a named person can confirm, reject or mark a finding for follow-up. The decision is attributed and logged. Green is theirs alone: no system state is ever shown in green.

Designed around

Three tests the review is built to pass

These are the design criteria in the programme definition. They describe what the review is for, not a measured result.
  • The reviewer can see, per requirement, what is on file and what is not.
  • Every located passage can be opened and checked at its source.
  • The gap list is short enough to send to the supplier without editing.

When evidence is missing, the next step is the reviewer’s: request the artefact from the supplier, or record why it is not held.

Questions

Supplier review questions

Does DataStruct approve suppliers?

No. It locates and prepares the evidence and states what it could not find. The approval decision, and every decision about a finding, belongs to your reviewer.

Can we add our own requirements?

Yes. The template is a starting point. Write requirements in your own words; they persist between runs, and editing the wording applies to future runs while earlier findings keep the wording they were judged against.

Does it check whether a certificate is still valid?

It shows the passages it found, including any dates they state, and the reviewer decides. It does not yet pick the current version of a superseded record: where an old and a new version are both on file, both can be returned.

What happens at the next re-approval?

Rerun the programme. Each run has its own identity and date; earlier findings and reviewer decisions stay on record, and decisions never carry over to the new run.

Bring one supplier file

The fastest way to judge DataStruct is to point it at a supplier you are reviewing now.