Skip to content

Supplier review workflow

How to Build an ICT Supplier Due Diligence Evidence Pack

Organize approved software-supplier documents into a source-backed evidence pack with provenance, scope, gaps, owners, and review dates.

Qi-Xuan LuUpdated 9 min read
See the supplier evidence workflow

About this guide

01

Workflows

02

Procurement, security, and IT owners reviewing one ICT or software supplier before approval or renewal

03

9 min read

01

Keep every supplier claim attached to an approved document, date, revision, and evidence scope.

02

Record data access, resilience, foundational security evidence, dependencies, and unanswered questions separately.

03

Give the packet an owner and re-review date instead of turning old questionnaire answers into permanent truth.

Worked example

Build an ICT supplier due-diligence evidence pack

A fictional three-file due-diligence exercise: separate supplier assertions from evidence, find the gaps, and leave the open questions with procurement and legal reviewers.

Try this task

Using only the three source files, inventory what is actually evidenced, list every material gap, and state why a human procurement or legal owner must keep the decision open. Cite each conclusion with [[filename]].

Expected reasoning

The supplier provides descriptions and a questionnaire statement, not independent or contract evidence. Deletion evidence, residency, subprocessors, assurance, and signed terms are missing; no certification or acceptable-risk conclusion is warranted.

Why keep this connected

One incomplete supplier pack can be checked by hand. A source-linked due-diligence wiki helps when questionnaire revisions, contracts, evidence attachments, and human review decisions must remain traceable without inventing assurance.

Review boundary

Check each assertion for an attached record, especially deletion evidence, residency, subprocessors, and contract terms; infer no certification, and keep the procurement and legal review visible.

Download this example

Inspect the example in Wenlan

Wenlan v0.18.3 interface displaying data read back from an isolated test run. The sources are fictional and the reference answer was written for this exercise. No automatic AI generation or approval is shown.

Build an ICT supplier due-diligence evidence pack — The reference page still contains the original answer and links to its three sources.

Scroll or swipe to explore the enlarged image.

Open original
The reference page still contains the original answer and links to its three sources.
Build an ICT supplier due-diligence evidence pack — Following the citation opens the changed source. Compare it with the answer that still needs review.

Scroll or swipe to explore the enlarged image.

Open original
Following the citation opens the changed source. Compare it with the answer that still needs review.

After the cited source changed, Wenlan marked the page as out of date and kept its original text. The ‘updating…’ label indicates a pending rebuild here; it does not show a completed correction. Review the changed source before rebuilding and accepting a new answer.

Source files

Open a file to read its complete authored Markdown.

The source files are the same authored English dataset in all three locale views.

  1. 01supplier-profile.mdMicaGrid Systems — fictional supplier profile
    # MicaGrid Systems — fictional supplier profile
    
    MicaGrid Systems is a fictional hosting supplier for this teaching exercise. Its profile says it can host application workloads in an EU region and describes encryption in transit and at rest.
    
    The profile is a supplier-authored description. It includes no signed contract, independent assurance report, certificate, data-flow diagram, or evidence that the described options are enabled for a particular customer.
  2. 02security-questionnaire.mdMicaGrid Systems — questionnaire response
    # MicaGrid Systems — questionnaire response
    
    Status: fictional response, evidence review pending.
    
    The supplier states that customer data can be deleted within 30 calendar days after a written request. It has not attached a deletion test, retention configuration, or service-specific record. Data residency details and the current subprocessor list are unanswered.
    
    These statements are questionnaire answers, not legal or compliance certification.
  3. 03procurement-review.mdProcurement review checklist
    # Procurement review checklist
    
    The reviewer has a supplier profile and a questionnaire but no signed data-processing terms, independent assurance report, deletion evidence, residency confirmation, or subprocessor list.
    
    Keep the supplier decision on hold until the responsible procurement and legal owners review the missing evidence and contract terms. Do not infer certification, regulatory approval, or acceptable risk from the supplier's statements. A human owner must record any final decision.

Reference answer

Reference answer: a supplier statement is not a certification

The packet contains supplier descriptions and a questionnaire statement about deletion within 30 days, but no independent or contract evidence. Residency and subprocessors are unanswered, and procurement and legal owners must review the gaps before deciding; no certification or compliance conclusion is warranted.

MicaGrid Systems — due-diligence reference

Evidence present

The fictional supplier profile describes EU-region hosting and encryption in transit and at rest, but it is a supplier-authored description with no attached contract, assurance report, certificate, data-flow diagram, or customer-specific enablement evidence. supplier-profile.md

The questionnaire states that data can be deleted within 30 calendar days after a written request, but provides no deletion test, retention configuration, or service-specific record. Residency and the current subprocessor list are unanswered. security-questionnaire.md

Decision boundary

This is an evidence gap, not a legal or compliance certification. The missing terms, assurance report, deletion evidence, residency confirmation, and subprocessor list keep the decision on hold. Procurement and legal owners must review the evidence and contract before recording any final decision. procurement-review.md

Changed source: security-questionnaire.md

Expected update after this change

The reference's statement that the supplier says data can be deleted within 30 calendar days becomes stale. Revision 2 removes that fixed period and makes timing dependent on the service and written agreement, so deletion timing is now unknown. The missing evidence, no-certification boundary, hold status, and human procurement/legal review remain unchanged.

# MicaGrid Systems — questionnaire response, revision 2

Status: fictional response, evidence review pending.

The supplier cannot state a fixed deletion period. Deletion timing depends on the service and written agreement, and no deletion test, retention configuration, or service-specific record is attached. Data residency details and the current subprocessor list remain unanswered.

These statements are questionnaire answers, not legal or compliance certification.

01

Quick answer

Build one evidence pack for one ICT or software supplier. Register only approved source documents, then record each claim's provenance, revision, data-access scope, resilience and security evidence, dependencies, gaps, owner, and review date. Mark unsupported or stale claims as unverified and keep the final approval decision with procurement, security, legal, and privacy reviewers.

Wenlan can connect supported Markdown, text, text-extractable PDFs, folders, and read-only Obsidian sources to source-backed Pages, citations, revisions, stale state, lint, and human review. It does not validate certifications, crawl vendor sites, monitor suppliers, scan vulnerabilities, score risk, or approve procurement.

See the supplier evidence workflow

02

When this problem appears

Supplier reviews often mix a current security policy, an old questionnaire, an architecture diagram, a certification claim, and an email clarification into one spreadsheet. Without source dates and scope, a confident summary can hide which statement is current, which applies only to one service, and which still lacks evidence.

03

Build one reviewable supplier evidence pack

Start with one supplier and one procurement or renewal decision. The source register and review fields remain useful even if the team does not use Wenlan.

  • Define the supplier, product or service, decision, business owner, review team, date range, approved source set, and excluded confidential material.
  • Register current policies, architecture and data-flow documents, resilience material, subprocessors or dependencies, completed questionnaires, and dated clarifications only when your organization has approved their use.
  • For every important claim, record the exact source passage, document revision, service scope, data-access profile, evidence owner, and next review date.
  • Separate supplied evidence, reviewer interpretation, residual risk, missing evidence, contradictions, and open questions. Never turn an unanswered questionnaire row into an affirmative control claim.
  • Map dependencies and supplier tiers explicitly. A downstream service, subprocessor, or hosting dependency may need its own evidence and owner.
  • When a document or service scope changes, resync the affected source and mark dependent claims stale until a qualified reviewer checks the new revision.
  • Before approval or renewal, open the cited source and let procurement, security, legal, and privacy owners make the decision under the organization's existing controls.

A bounded supplier-evidence workflow

wenlan status
wenlan sources add ~/Reviews/approved-supplier-docs
# In a Wenlan plugin client:
/distill <supplier and review scope>
/pages <supplier evidence pack>
/lint
/curate

04

What to check next

A questionnaire or evidence pack is not a security guarantee. Wenlan does not validate certifications, perform legal or privacy review, discover vendors, crawl websites, monitor live supplier changes, scan vulnerabilities, score risk, or approve or reject a supplier. Keep sensitive material inside your organization's approved access controls and use qualified human reviewers.

Make one supplier review traceable

Choose one supplier and service scope, connect approved evidence, and leave every unsupported or stale claim visible before the decision meeting.

FAQ

Can Wenlan validate a supplier's certification or approve the vendor?+
No. Wenlan does not validate certifications, score supplier risk, or approve procurement. It helps keep approved documents, claims, gaps, revisions, and review state inspectable for qualified reviewers.
Is a completed vendor questionnaire enough evidence?+
No. Treat each answer as one supplied claim. Record its source, date, scope, owner, supporting document, contradictions, and next review date; leave unsupported answers explicitly unverified.

Share this guide