If procurement checks price and delivery but leaves security questions until after the contract is signed, put a secure supply chain policy in place. Define which suppliers need closer assessment, who can accept the remaining risk and what evidence the decision requires.
A secure supply chain policy is not a rebadged procurement policy with a risk paragraph added. It is a separate governance document that tells buyers, contract managers and security teams exactly which suppliers need extra scrutiny, what that scrutiny checks for, and who signs off when something doesn't clear.

Why your existing procurement policy won't catch this
Procurement policies are built to answer procurement questions: value-for-money, competitive process, delegation limits, conflict of interest. They are not built to answer security questions: does this supplier have access to sensitive systems, is this supplier or its ultimate owner subject to sanctions, does the goods or technology being procured fall under an export control regime, and does the subcontracting chain introduce a country or entity risk nobody has looked at.
A lengthy procurement policy can still omit security screening. Define responsibility for sanctions, export controls and foreign ownership, control or influence (FOCI) checks, with procurement, security and legal specialists agreeing the hand-offs. These requirements can sit in an integrated procurement policy or in clearly linked supporting procedures.
What a secure supply chain policy template actually needs to decide
Strip away the boilerplate and a workable policy needs to answer five questions before a contract is signed:
- Which suppliers or contracts trigger enhanced screening, and which don't.
- What does enhanced screening check — ownership, sanctions exposure, cyber posture, subcontracting chain, jurisdiction.
- Who has authority to accept a supplier with an unresolved flag, and under what conditions.
- How long are screening records kept, and who can produce them if asked.
- What happens when a cleared supplier's status changes mid-contract.
If your current policy doesn't answer all five, it's a procurement policy wearing a security hat.
Two tiers, not one screening process for everyone
Screening every supplier to the same depth is how security teams end up with a backlog and a procurement team that routes around them. A workable model uses two tiers.
Tier 1 — critical and strategic suppliers. Access to sensitive systems or data, involvement in critical infrastructure, sole-source dependency, or spend above a threshold the organisation sets. These get full screening: ownership and FOCI check, sanctions and export control screening, cyber baseline assessment, subcontracting chain disclosure, and a documented sole-source justification if there's no alternative supplier.
Tier 2 — standard suppliers. Everyone else. A lighter check — sanctions screening and a basic cyber baseline — proportionate to the lower exposure.
The point of tiering isn't to let Tier 2 suppliers skip scrutiny altogether. It's to stop Tier 1 depth being applied to a stationery contract, because that's exactly what causes a policy to be quietly ignored within eighteen months.
The clauses that actually do the work
A secure supply chain policy earns its place by covering, at minimum:
- Export controls. Does the good, service or technology being procured, or the technology the supplier will access to deliver it, fall under an export control regime. This needs to be a checkpoint before contract signature, not a question raised after an incident.
- Sanctions screening. The supplier, its parent, and — where the contract is significant enough — its known subcontractors, screened against applicable sanctions lists at onboarding and on a defined re-screening cycle.
- FOCI. Foreign ownership, control or influence over the supplier that could create a conflict with national interest, data sovereignty requirements, or the organisation's own obligations to its clients or regulator.
- Cyber baseline. A minimum set of expected controls appropriate to the access the supplier will hold — this can reasonably reference a recognised framework such as the ASD Essential Eight or NIST CSF 2.0 without importing the whole standard into the contract.
- Sole-source justification. Where there is genuinely one viable supplier, that decision is documented, dated, and re-tested periodically rather than assumed to still hold two years later.
- Modern slavery and ESG. Increasingly a standalone due-diligence obligation in its own right, not a line item under "other."
- Retention. Screening records, sign-offs and re-screening results kept for a defined period — long enough to survive an audit, a regulator's request, or a dispute that surfaces years after the contract ended.
Worked example: a three-site logistics firm
A fictional mid-size logistics operator — three distribution sites, around 300 staff — reviews its 140 active suppliers against a new secure supply chain policy.
| Category | Count | Tier | Example trigger |
|---|---|---|---|
| Warehouse management software vendor | 1 | Tier 1 | Access to shipment and customer data; single supplier |
| Fuel and fleet maintenance | 6 | Tier 1 | Critical to continuity of operations |
| Site security systems installer | 2 | Tier 1 | Access to physical security infrastructure |
| Office supplies, uniforms, catering | 40+ | Tier 2 | Low access, low criticality |
| Casual labour hire agencies | 8 | Tier 2, escalate on findings | Screen for modern slavery indicators; escalate to Tier 1 depth if flagged |
The exercise reclassifies nine suppliers from "no formal review" to Tier 1, and identifies that the warehouse management vendor — the one everyone assumed had been checked because it's been in place for years — had never had a FOCI or sanctions screen at all.
Common mistakes
- Treating the policy as a one-off gate. Screening happens at onboarding and is never repeated, so a supplier that changes ownership or gets added to a sanctions list two years into a contract is invisible.
- No sole-source discipline. "There's only one supplier" is accepted once and never revisited, even after the market changes.
- Subcontractors excluded from scope. The prime supplier is screened; the three subcontractors actually doing the work are not.
- No documented escalation path. A flag comes up during screening and there's no record of who decided to proceed anyway, or why.
- One-size screening. Applying Tier 1 depth to every supplier burns the team out; applying Tier 2 depth to every supplier misses what matters.
Get the policy and procedure
A policy is only as good as the information handling discipline behind it — Traffic Light Protocol Explained: TLP:RED to TLP:CLEAR covers how to mark and share screening findings so they don't end up in the wrong inbox. For board-level framing of why supplier risk belongs on the agenda, see Five Cybersecurity Questions Every Board Should Be Asking. If this responsibility is new to you, start with the first-week security risk guide.
The SRMBOK Procurement and Secure Supply Chain Policy and Procedure gives you both documents ready to adapt: a procurement and secure supply chain policy, and a supplier risk assessment procedure, covering export controls, sanctions, FOCI, cyber baselines, sole-source justification, modern slavery and ESG, with two-tier risk tiering and seven-year retention built in. Download the free policy and procedure and adapt the tiering thresholds to your own supplier base rather than starting from a blank page.
Adapt the example tiering and retention periods to your organisation. Sanctions, export controls, ownership screening and record-retention obligations depend on the jurisdictions, activities and contracts involved; have the responsible specialists confirm the applicable requirements. A template does not establish compliance.
