A supplier code of conduct template is an editable document setting out the legal, ethical and operational rules every vendor and third party must follow. It protects your reputation and holds your supply chain to recognised international standards on labour, safety, environment and integrity.
A supplier code of conduct is the rulebook your suppliers, and their subcontractors, agree to follow while they work for you. It turns your values into concrete rules on how they treat workers, keep sites safe, look after the environment, deal honestly and protect your data, and it spells out what you can do if they fall short.
Procurement and compliance teams issue it when a new supplier is onboarded and refer to it in contracts and purchase order terms. Customers, investors and auditors increasingly ask buyers how they check standards in their supply chain, and a signed code is usually the first piece of evidence.
A template saves you drafting from a blank page. You keep the structure, set the standards that matter for what you buy and remove sections that do not apply.
Why the code exists, which suppliers and subcontractors it covers, and the baseline duty to obey every law where they operate.
No forced or child labour or trafficking, plus fair pay, reasonable hours and freedom from discrimination.
Clean, safe sites and proper training, run to a recognised management standard such as ISO 45001.
Lawful waste disposal, fewer hazardous substances and careful use of energy, water and materials.
No bribes, kickbacks or corruption, and firm rules on personal data and your confidential information.
Your rights to audit sites, ask for records and end the contract when a supplier breaches the code.
Ready to use in Word, Google Docs and PDF. Fill it in, save it, reuse it.
Adapt the template to what you buy and where your suppliers operate. Keep each rule specific and checkable.
Legal, compliance and procurement sign it off, and a senior leader owns it.
Send it with every new supplier's onboarding pack and reference it in contracts and PO terms.
Ask high-risk suppliers for a self-assessment and evidence, and audit where the risk justifies it.
Agree corrective actions for breaches, and review the code and the supplier list every year.
Start with four sections: Purpose and scope, Labour, Safety and environment, Business ethics, plus a signature line. Add audit, reporting and enforcement rules as your supplier base grows.
Each section in the download has a short prompt and suggested wording. Write in plain language a supplier's site manager could follow without a lawyer, and keep the whole code to four to six pages.
Why the code exists, which suppliers it covers and that it extends to their staff and subcontractors.
Suppliers obey every law where they operate; where this code sets a higher standard, the code applies.
No forced, bonded or child labour or human trafficking; fair pay and working hours; freedom of association; no discrimination or harassment.
Clean, safe workplaces, training, protective equipment, emergency plans and accident reporting, managed to a standard such as ISO 45001.
Permits held, waste disposed of lawfully, hazardous substances minimised and energy, water and materials used efficiently.
No bribes, kickbacks or facilitation payments, limits on gifts and hospitality, conflicts of interest declared and honest records.
Your confidential information, personal data and intellectual property protected and used only for the contract.
Suppliers apply equivalent standards to their own suppliers and tell you before subcontracting your work.
Self-assessments on request, your right to audit sites and request records with notice, and records kept to show compliance.
How workers and suppliers can raise a concern, including anonymously, and a promise of no retaliation.
Corrective action plans for most issues, and suspension or termination of the contract for serious ones.
Signature by an authorised representative confirming the supplier has read and will follow the code.
3. Labour and human rights [Supplier name] will not use forced, bonded, prison or trafficked labour, and will not employ anyone below the legal minimum working age or [16], whichever is higher. Workers will be paid at least the legal minimum wage, receive written terms of employment and be free to leave their employment on reasonable notice. Working hours, including overtime, will not exceed local legal limits. 6. Business ethics and anti-corruption [Supplier name] will not offer, pay, request or accept a bribe, kickback or facilitation payment, directly or through a third party, in any dealings connected with [Company name]. Gifts and hospitality offered to [Company name] employees must be modest, infrequent and below [$100 / £75] in value. Any actual or potential conflict of interest must be declared to [procurement@company.com] before work begins. 10. Reporting concerns Anyone who suspects a breach of this code can report it to [ethics@company.com] or [hotline number], anonymously if they prefer. [Company name] will not tolerate retaliation against anyone who raises a concern in good faith.
Illustrative wording and limits. Replace every bracketed entry with your own.
A code nobody signed is hard to enforce. Ask for the form before the first purchase order, and make it part of the onboarding checklist so it cannot be skipped. The download includes it as the last page of the code.
Supplier Code of Conduct: Acknowledgement Supplier legal name: [Supplier name] Supplier ID: [V-0000] Code version: [v2.0, issued 01 Oct 2026] On behalf of [Supplier name], I confirm that: 1. We have received and read the [Company name] Supplier Code of Conduct. 2. We will follow it, and require equivalent standards from our subcontractors who work on [Company name] business. 3. We will tell [Company name] within [10] working days if we become aware of a breach. 4. We will complete a self-assessment or allow an audit when reasonably asked. Name: [Full name] Job title: [Title] Signature: ____________________ Date: [DD Mon YYYY]
| Field | What to enter | Example |
|---|---|---|
| Supplier legal name and ID | The registered name and your internal vendor number | Northwind Logistics Ltd, V-0214 |
| Code version | The version and issue date the supplier is signing | v2.0, issued 01 Oct 2026 |
| Breach notice period | How fast the supplier must tell you about a breach | 10 working days |
| Signatory | A director or someone authorised to bind the supplier | Head of Operations |
| Date | The date signed; set a reminder to re-sign at the next version | 14 Oct 2026 |
Every "no" is a conversation, not an automatic failure. Ask for a document behind each "yes" on high-risk items, such as a policy, a training record or a permit. The download adds a comments column and an evidence column to each check.
Sort suppliers by what they do, where they operate and how much access they have to your data, people or customers. A cleaning contractor and an office stationery supplier carry very different risks. Recheck the tier at every renewal.
| Tier | Typical suppliers | What you ask for | Review |
|---|---|---|---|
| High | Manufacturing, labour-intensive services, suppliers handling your customer data | Signed code, self-assessment with evidence, right to audit | Every year |
| Medium | Logistics, facilities, professional services | Signed code and self-assessment | Every two years |
| Low | Office supplies, software with no data access, one-off purchases | Code accepted through onboarding or PO terms | At renewal |
Illustrative tiering. Set your own criteria based on what you buy.
The easiest place to collect signatures is supplier onboarding, when the supplier already expects to send documents. For high-risk suppliers, pair the self-assessment with your wider third-party risk management checks.
Ending a relationship straight away can leave workers worse off and your supply at risk. A clear grading lets the supplier know what is expected and lets you act fast when it matters. Record every breach and outcome in the supplier file.
| Level | Example | Response | Timeline |
|---|---|---|---|
| Minor | Gifts register not kept; training records out of date | Written notice and fix confirmed by the supplier | 30 days |
| Serious | Excessive overtime; expired environmental permit | Corrective action plan, follow-up evidence or visit, new orders reviewed | 60-90 days |
| Critical | Forced or child labour; bribery; deliberate data misuse | Escalate to legal and leadership; suspend orders; consider termination | Immediately |
Illustrative timelines. Align them with the termination rights in your contracts.
Supplier: [Supplier name] Code section breached: [3. Labour and human rights] Finding: [Overtime above legal limits for 18 warehouse staff in March] Agreed action: [Hire two additional shift staff and cap overtime in the rota system] Owner at supplier: [Name, title] Due date: [DD Mon YYYY] Evidence required: [Three months of timesheets after the change] Status: [Open / Closed]
Collect the signed code at onboarding. Spendflo runs supplier onboarding and third-party risk checks.
See how it worksA small unofficial payment to speed up a routine action, such as a customs clearance. Most codes ban them outright.
Work done under threat, or to pay off a debt the worker cannot realistically clear, including withheld identity papers.
Your supplier's own suppliers and subcontractors, where many labour and environmental risks sit.
Your contractual right to inspect a supplier's sites and records, usually with reasonable notice.
A channel for workers to raise concerns without fear of losing their job.
A written, dated plan agreed with a supplier to fix a breach, with an owner and evidence.
| Document | Who it binds | What it does |
|---|---|---|
| Supplier code of conduct | Suppliers and their subcontractors | Sets ethical, labour, safety, environmental and data standards |
| Supplier contract or PO terms | The supplier, legally | Makes the code a condition of doing business, with audit and termination rights |
| Internal procurement policy | Your own employees | Sets how staff choose, approve and manage suppliers |
| Employee code of conduct | Your own employees | Sets how staff behave, including gifts received from suppliers |
Link the documents explicitly: a clause in your contract or ethical procurement policy should say that compliance with the supplier code is a condition of the relationship, and name the version in force.
Say "no worker under 16" rather than "respect children's rights", so compliance can be tested.
Reference the code and its version in contracts and PO terms so it is enforceable.
Issue the code in the main language of each supplier's workforce, not only in English.
Publish a reporting channel that supplier staff can use directly and anonymously.
Update for new risks and laws, issue a new version number and ask high-risk suppliers to re-sign.
Standards written for a global manufacturer may be unworkable for a twenty-person services supplier.
A signature without any follow-up on high-risk suppliers is paperwork, not assurance.
Walking away from a supplier at the first issue can leave its workers worse off.
If you cannot say which version a supplier signed, you cannot say what they agreed to.
Remove sections that do not apply, set your gift limit and breach notice period, and fill every bracket.
Have legal and compliance review it, and a senior leader approve it as version 1.0.
Send the code, acknowledgement form and self-assessment with a 30-day deadline.
Make the signed form a required document before any new supplier receives a PO.
Lumen Retail sent its code to 85 active suppliers and tiered 12 as high risk. All 12 returned self-assessments within 30 days; Harbour Facilities answered no on recorded working hours. The two agreed a 60-day corrective action plan with three months of timesheets as evidence, and the contract continued. Illustrative scenario.
Every part on this page, in Word, Google Docs and PDF, with the examples filled in.
A two-page code with integrity, labour, safety and reporting sections, plus the acknowledgement form. Collect signatures at onboarding.
Expand labour, safety and environment sections, require sub-tier disclosure and keep audit rights for overseas sites.
Expand data protection, confidentiality and subcontracting sections, and connect them to your security questionnaire.
Best for the approved master and version control.
Best while legal, compliance and procurement review the draft.
Best for sending to suppliers and publishing.
$3.7B in software spend processed through Spendflo, at 30% average savings.
See your savingsA good supplier code of conduct sets clear, checkable standards and gets every supplier to sign them. What makes it count is the follow-up: tiering, self-assessments and a fair response when something goes wrong.
Quick answers to what people ask most about the supplier code of conduct template.
Include an introduction and purpose, labour and human rights, health and safety, environmental responsibility, business ethics with data privacy, and compliance and enforcement rights, plus a signed acknowledgement. The download covers these in twelve sections with sample wording.
Yes, you can download a free supplier code of conduct template from this page in Word, Google Docs or PDF. It includes the code, an acknowledgement form and a supplier self-assessment.
It is the set of legal, ethical and operational standards a buyer expects every supplier and subcontractor to meet, signed as a condition of doing business. You can download a ready-to-edit version from this page and adapt it to what you buy.
There is no single official list, but most supplier codes rest on five principles: respect for labour and human rights, safe and healthy workplaces, environmental responsibility, ethical business conduct and compliance with the law. The download is organised around those five, with audit and enforcement sections to back them up.
Yes, the Word download is fully editable and includes the code, the acknowledgement form and the self-assessment checklist. Google Docs and PDF versions are also available for review and for sending to suppliers.
Vendor management
Purchase orders
Contracts
Sourcing and RFx
Budgets and business cases
Procurement
Accounts payable
Purchasing
Software buying
Supply chain
Spendflo runs supplier onboarding and third-party risk management, so the signed code and risk checks are in place before a purchase is approved. Reporting is coming soon.
Enter your work email and we'll unlock every format.
Didn't start, or need another format? Pick one below.
Google Docs: upload the file to Google Drive, then open it with Google Docs.