OECD guidance makes due diligence an operating loop—not a supplier score
The OECD guidance organizes responsible-business due diligence as six connected activities: embed policy, identify and assess impacts, act, track, communicate, and remediate where appropriate. Supplier screening can inform that process, but it cannot stand in for the operating decisions and evidence the full loop requires.
Editorial figure by Supply Chain Signal. Source context: OECD — Due Diligence Guidance for Responsible Business Conduct.
The framework starts before a supplier questionnaire
The OECD places policy and management systems at the beginning of its framework, then connects them to identifying and assessing actual and potential adverse impacts. That sequence matters. A questionnaire can collect assertions, but it cannot decide the company’s scope, risk methodology, ownership, escalation rights, affected stakeholders, or the evidence standard used to distinguish a weak signal from a substantiated impact.
The source also reaches beyond a conventional first-tier supplier list. Its business-relationship language includes multiple commercial and institutional relationships through which a company can be linked to impacts. A supply-chain system should therefore preserve the relationship, product or service, geography, activity, time period, source, confidence, and linkage theory behind a finding rather than attaching one permanent score to a legal entity.
Assessment should lead to a named response
The third step calls for ceasing, preventing, or mitigating adverse impacts. Those are not interchangeable outcomes. The appropriate response depends in part on whether the enterprise caused, contributed to, or is directly linked to an impact and on the circumstances described by the guidance. A workflow that labels every result high risk without showing the response owner and decision basis compresses the framework at its most consequential point.
A usable record would link the assessed impact to the responsible owner, action selected, leverage or dependency considered, target date, approvals, stakeholder engagement where relevant, and unresolved limitations. This is an analytical translation for system evaluation, not a determination that any response is adequate. The OECD guidance remains a reference framework; sector rules, contracts, local law, and facts can require more specific analysis.
Tracking and communication make the process a loop
OECD separates taking action from tracking implementation and results, and it separately addresses communicating how impacts are handled. A closed task proves that someone completed a workflow step. It does not establish that the action reduced an impact, that new evidence was considered, or that the communication was accurate and appropriate for the affected audience.
Buyers should ask a platform to reopen one assessed relationship after contradictory evidence arrives. The system should preserve the prior assessment, new source and date, changed confidence, affected decisions, reassigned actions, outcome indicators, communication history, and next review. Because the guidance describes due diligence as iterative, a product that only produces a point-in-time supplier rating is supporting an input, not the full operating model.
Remediation and applicability remain decision boundaries
The sixth step addresses providing for or cooperating in remediation when appropriate. A case-management feature can preserve allegations, engagement, actions, outcomes, and evidence, but it does not determine causation, contribution, rights, remedy, or whether the process is legitimate for affected people. Those judgments require accountable human and legal or subject-matter review.
Supply Chain Signal uses the guidance as a structured source, not a universal compliance rule or certification test. The document itself points readers toward sector-specific OECD guidance where it may offer more detailed approaches. Companies should record which instrument, jurisdiction, sector, relationship, and time period apply before turning a framework step into a requirement or making a claim about a supplier or product.
Enterprise buyer test
Translate this change into the exact population, record type, workflow stage, decision owner, effective date, and evidence that could be affected. Ask current or prospective providers to demonstrate the named workflow with representative data and an exception—not a polished feature tour. Record what official documentation establishes, what a provider states, what the team observes, and what remains unresolved.
A defensible review also identifies the dependency outside the product. Authority interpretation, policy configuration, data quality, integrations, human judgment, approval rights, release governance, training, and retained evidence may remain customer or service responsibilities. The evaluation should preserve those boundaries instead of treating a technology claim as the complete operating model.
What we will watch next
Supply Chain Signal will watch the named source and affected market records for later evidence that changes status, scope, availability, implementation timing, workflow consequence, or the limits of the initial report. A later announcement does not silently overwrite this dated account; the change ledger preserves the sequence.