# Build an ICT supplier due-diligence evidence pack

A fictional three-file due-diligence exercise: separate supplier assertions from evidence, find the gaps, and leave the open questions with procurement and legal reviewers.

## Task

Using only the three source files, inventory what is actually evidenced, list every material gap, and state why a human procurement or legal owner must keep the decision open. Cite each conclusion with [[filename]].

## Expected reasoning

The supplier provides descriptions and a questionnaire statement, not independent or contract evidence. Deletion evidence, residency, subprocessors, assurance, and signed terms are missing; no certification or acceptable-risk conclusion is warranted.

## Complete source packet

### MicaGrid Systems — fictional supplier profile — supplier-profile.md

```markdown
# MicaGrid Systems — fictional supplier profile

MicaGrid Systems is a fictional hosting supplier for this teaching exercise. Its profile says it can host application workloads in an EU region and describes encryption in transit and at rest.

The profile is a supplier-authored description. It includes no signed contract, independent assurance report, certificate, data-flow diagram, or evidence that the described options are enabled for a particular customer.
```

### MicaGrid Systems — questionnaire response — security-questionnaire.md

```markdown
# MicaGrid Systems — questionnaire response

Status: fictional response, evidence review pending.

The supplier states that customer data can be deleted within 30 calendar days after a written request. It has not attached a deletion test, retention configuration, or service-specific record. Data residency details and the current subprocessor list are unanswered.

These statements are questionnaire answers, not legal or compliance certification.
```

### Procurement review checklist — procurement-review.md

```markdown
# Procurement review checklist

The reviewer has a supplier profile and a questionnaire but no signed data-processing terms, independent assurance report, deletion evidence, residency confirmation, or subprocessor list.

Keep the supplier decision on hold until the responsible procurement and legal owners review the missing evidence and contract terms. Do not infer certification, regulatory approval, or acceptable risk from the supplier's statements. A human owner must record any final decision.
```

## Reference answer: a supplier statement is not a certification

The packet contains supplier descriptions and a questionnaire statement about deletion within 30 days, but no independent or contract evidence. Residency and subprocessors are unanswered, and procurement and legal owners must review the gaps before deciding; no certification or compliance conclusion is warranted.

# MicaGrid Systems — due-diligence reference

## Evidence present

The fictional supplier profile describes EU-region hosting and encryption in transit and at rest, but it is a supplier-authored description with no attached contract, assurance report, certificate, data-flow diagram, or customer-specific enablement evidence. [[supplier-profile.md]]

The questionnaire states that data can be deleted within 30 calendar days after a written request, but provides no deletion test, retention configuration, or service-specific record. Residency and the current subprocessor list are unanswered. [[security-questionnaire.md]]

## Decision boundary

This is an evidence gap, not a legal or compliance certification. The missing terms, assurance report, deletion evidence, residency confirmation, and subprocessor list keep the decision on hold. Procurement and legal owners must review the evidence and contract before recording any final decision. [[procurement-review.md]]

## Changed source

### security-questionnaire.md

```markdown
# MicaGrid Systems — questionnaire response, revision 2

Status: fictional response, evidence review pending.

The supplier cannot state a fixed deletion period. Deletion timing depends on the service and written agreement, and no deletion test, retention configuration, or service-specific record is attached. Data residency details and the current subprocessor list remain unanswered.

These statements are questionnaire answers, not legal or compliance certification.
```

## Expected change

The reference's statement that the supplier says data can be deleted within 30 calendar days becomes stale. Revision 2 removes that fixed period and makes timing dependent on the service and written agreement, so deletion timing is now unknown. The missing evidence, no-certification boundary, hold status, and human procurement/legal review remain unchanged.

## Review boundary

Check each assertion for an attached record, especially deletion evidence, residency, subprocessors, and contract terms; infer no certification, and keep the procurement and legal review visible.

## Comparison

One incomplete supplier pack can be checked by hand. A source-linked due-diligence wiki helps when questionnaire revisions, contracts, evidence attachments, and human review decisions must remain traceable without inventing assurance.

## Read the localized page

https://wenlan.app/learn/build-ict-supplier-due-diligence-evidence-pack
