Internal audit: useful when nobody is defending a number
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
A supplier code of conduct sets what you require of the people you buy from. What to include, how to make it enforceable, and why long codes get signed and ignored.
A supplier code of conduct states the standards you expect from the companies you buy from — on labour, safety, the environment, bribery, and how they treat their own suppliers in turn. It is signed at onboarding, filed, and in most companies never referred to again. That is a shame, because it is the only document that gives you a contractual basis to ask questions later, and the difference between a code that works and one that does not is almost entirely about whether a small supplier could realistically comply with it.
Length is the enemy. A forty-page code sent to a twelve-person machining firm will be signed unread, and you will have bought a signature rather than a standard. Two to four pages that a small supplier can actually implement produces more compliance than a comprehensive document produces paper.
Ettex Records holds the signed acknowledgements against each supplier record — who signed, when, which version — which is the question that arrives during a customer audit and the one that spreadsheets answer badly. The code itself belongs with your other published policies, and where your customers require it, alongside the modern slavery statement that draws on the same supply-chain work. The supplier onboarding file is where the acknowledgement should be collected in the first place. Ettex does not audit suppliers and does not assess compliance.
If your customers ask for evidence of supply-chain standards, you need one to pass it down, and increasingly they do. It can be short. What matters is that it exists, is referenced contractually, and is acknowledged.
Ask why before treating it as a red flag. Refusals often come from a specific clause that is impossible in their jurisdiction or unworkable at their size — which is useful information about your code, not only about them.
Your internal code binds your staff; this binds companies you have no authority over, which is why it works through contract and audit rather than through management. Copying the internal one across is the most common reason supplier codes read as unusable.
Internal audit checks whether controls actually work. How to plan by risk, write findings people act on, and stay independent without becoming the police.
Succession planning is a list of roles you cannot afford to lose and what happens if you do. How to build one small enough to maintain and honest enough to use.
A certificate of analysis states what was tested and what was found. What has to be on it, the checks that take a minute, and why filing it unread is the risk.