Supplier Code of Conduct template
Sets minimum ethical, environmental, security, and data protection standards for all suppliers and third parties. Covers Modern Slavery Act obligations, GDPR DPA requirements, anti-bribery, and audit rights. Directly supports vendor risk management.
Generate your supplier code of conduct in minutes
Answer a few questions about your business and PolicyKit produces a tailored, professionally structured document — ready to export as PDF or Word.
Generate freeAbout this document
A supplier code of conduct sets out the standards an organisation expects its suppliers and their workers to meet. It covers ethical, labour, and environmental expectations. A clear code helps manage supply-chain risk and reinforces responsible business practices.
Who needs one: Organisations that want to set responsible standards across their supplier base.
What a strong supplier code of conduct covers
- Expected standards on ethics and lawful conduct
- Labour rights and prohibition of forced or child labour
- Health, safety, and fair working conditions
- Environmental responsibility and sustainability expectations
- Anti-bribery, conflicts of interest, and fair dealing
- Monitoring, audits, and consequences of non-compliance
Regulations and frameworks this aligns to
PolicyKit references the standards relevant to your jurisdiction when it generates your supplier code of conduct.
- UK GDPR
- The retained UK version of the General Data Protection Regulation, governing how organisations process the personal data of people in the UK.
- UK Bribery Act 2010
- The UK Act creating offences of bribery and failure to prevent bribery, under which organisations are expected to have adequate procedures in place.
- Modern Slavery Act 2015
- The UK Act addressing slavery, servitude, forced labour, and human trafficking, including a transparency-in-supply-chains reporting requirement for larger organisations.
Frequently asked questions
What should a supplier code of conduct include?
A robust supplier code of conduct sets out scope, roles and responsibilities, the specific controls or procedures involved, and how compliance is monitored and reviewed, mapped to frameworks like uk-gdpr, uk-bribery-act, modern-slavery-act. PolicyKit structures all of this automatically based on your business.
Is this legal advice?
No. PolicyKit generates AI-assisted professional templates and starting points, not legal advice. Every document should be reviewed with qualified legal and compliance counsel before use.
Can I tailor it to my country?
Yes — PolicyKit tailors each document to your jurisdiction, including UK, EU, United States, Australia, Singapore, Hong Kong and more.
You may also need
Cybersecurity & Information Security
Protect your systems, networks, and data from cyber threats. Aligned with NIST Cybersecurity Framework and Cyber Essentials.
Data Protection & Privacy
Manage personal data lawfully and transparently. Covers GDPR, UK GDPR, and US privacy law (CCPA/CPRA) requirements.
Acceptable Use & Access Control
Define how employees and contractors may use company systems, devices, and data — and who can access what.
Incident Response
Prepare for, detect, contain, and recover from security incidents and personal data breaches. Includes breach notification obligations.
Ready to create your supplier code of conduct?
Start freePolicyKit provides AI-assisted templates and starting points, not legal advice.