Accountability sits with the company’s governance and compliance functions, but the article makes clear that failure has external consequences as well. BAFA can levy fines, and customers may terminate relationships if remediation is not implemented. That means responsibility must span legal, compliance, procurement, and supplier management teams, with documented ownership for risk reviews, corrective actions, and reporting.
Who carries responsibility when due diligence evidence is missing?
When a company cannot show compliance, accountability does not sit with a single person in isolation. The governance owner is responsible for proving that due diligence is operating, while legal, compliance, procurement, and supplier management must each own the controls and records that make that proof possible. If evidence is missing, the process is already weak, even before any regulator or customer responds.
The practical question is not just who signs off, but who can produce the audit trail. That includes documented risk reviews, corrective actions, supplier follow-up, and escalation records that demonstrate the company did more than rely on informal assurances.
What “accountable” means in a supply chain due diligence failure
Accountability in this context is organisational, not merely individual. Boards and senior management remain responsible for oversight, but day-to-day ownership normally sits across functions that control the evidence chain: compliance defines the requirement, procurement gathers supplier information, legal interprets obligations and contracts, and operational supplier owners execute remediation.
That split matters because a compliance failure is often a coordination failure. A company can have policies on paper yet still fail due diligence if no one owns supplier screening, issue tracking, remediation deadlines, or sign-off on exceptions. In practice, accountability means someone must be able to answer who knew what, when they knew it, and what they did next.
Why external consequences follow internal ownership gaps
Missing compliance evidence creates both regulatory and commercial exposure. Regulators can treat an inability to demonstrate due diligence as a control failure, while customers may see it as a trust failure and terminate or freeze the relationship. Even where the underlying supplier risk is manageable, weak documentation can make the company look unable to govern its own supply chain.
The distinction between actual control and provable control is important. A company may believe it has taken reasonable steps, but if those steps are not recorded, reviewed, and retained, the organisation cannot reliably defend its position. In due diligence, evidence is part of the control.
Risk and Threat Considerations
supply chain due diligence failures create regulatory, contractual, and operational risk at the same time. The immediate exposure is usually not just the supplier issue itself, but the inability to demonstrate that the company identified, assessed, escalated, and remediated the issue in a defensible way.
Failure mechanism: ownership is fragmented, supplier records are incomplete, and no function maintains a complete chain of review, escalation, and corrective action. That makes the organisation vulnerable to enforcement, contractual loss, and repeat control failure even when individual teams believe they acted appropriately.
Impact: the company may face fines, customer termination, delayed remediation, and loss of credibility with auditors and counterparties. Over time, poor evidence discipline also increases the chance that unresolved supplier issues are repeated rather than closed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 — Risk Management Strategy | Supply chain due diligence failures are governed through enterprise risk ownership and oversight. |
| GV.RR-01 — Roles, Responsibilities, and Authorities | The question turns on which functions own compliance evidence and escalation. | |
| GV.SC-02 — Supply Chain Risk Management | The subject is supplier due diligence and the ability to demonstrate control over suppliers. | |
| Recommendation — Assign clear owners for supplier risk reviews and track remediation to closure. Define legal, compliance, procurement, and supplier-management responsibilities in writing. Maintain supplier risk records and remediation evidence for material third parties. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier oversight and evidence retention are central to due diligence compliance. |
| A.5.20 — Addressing information security within supplier agreements | Contractual accountability and remediation expectations depend on supplier terms. | |
| Recommendation — Apply supplier controls that require documented assurance and follow-up. Embed evidence, escalation, and remediation duties into supplier agreements. | ||
Practitioner Guidance
What to verify: confirm that one named governance owner can produce the complete due diligence record, not just point to dispersed team activity. The test is whether the organisation can show a current supplier inventory, assigned ownership for each high-risk supplier, and dated evidence of review, escalation, and closure.
Decision rule: if a supplier issue can affect regulatory compliance, customer trust, or business continuity, treat the documentation gap as a control gap, not an admin gap. Escalate unresolved ownership to legal or compliance leadership until someone is accountable for the record and the remediation plan.
Practitioner takeaway: the company is accountable as a whole, but defensibility depends on whether responsibility is translated into named owners, retained evidence, and closed-loop remediation across the functions that control the supplier relationship.
Related resources from NHI Mgmt Group
- How should organisations build a practical compliance programme for the German Supply Chain Due Diligence Act?
- Who is accountable when a company attests to NIST 800-171 compliance for JCP but cannot support the claim?
- Who is accountable when a business fails to meet Dutch customer identification and due diligence requirements?
- Who is accountable when customer identification and due diligence requirements are not met in Germany?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org