Executive summary: 

A supplier can pass onboarding, complete due diligence, and satisfy every requirement placed in front of them.

Then procurement moves on.

The supplier does not.

Ownership changes. Subcontractors change. Financial pressure builds. Operations shift.

A common approach is to review suppliers on a schedule.

Risk doesn't operate on a schedule.

That gap is becoming increasingly important.

In July, the Federal Government announced its intention to introduce a criminal offence for large companies that fail to prevent modern slavery in their supply chains, with a defence available for organisations that can demonstrate they took reasonable steps to prevent it.

Much of the commentary has focused on the offence.

Procurement should be paying more attention to the defence.

Because defence is where evidence matters.

And much of that evidence sits inside procurement.

The challenge is not whether a supplier was assessed.

It is whether procurement would notice when something changed and what should make it look again.

Supplier Risk Doesn't Wait for the Next Review
The Assessment Is a Snapshot. The Supplier Isn't.

Ask a procurement team when they last assessed a strategic supplier.

In my experience, the answer comes quickly.

Now ask what has changed about that supplier since.

That answer takes longer.

Onboarding and due diligence are designed to answer a point-in-time question:

Is this supplier suitable for us to engage?

That answer may have been correct at the time.

Six months later:

๐Ÿ”น Ownership may have changed.

๐Ÿ”น A new subcontractor may have entered the chain.

๐Ÿ”น Operations may have moved to a different geography.

๐Ÿ”น Labour practices may have shifted.

๐Ÿ”น Financial pressure may have increased.

๐Ÿ”น New adverse media or compliance concerns may have emerged.

The original assessment still exists.

The supplier it describes may not.

The question is not what procurement knew then.

The question is what procurement knows now.

Most of the Attention Is on the Offence. Procurement Should Focus on the Defence.

On 16 July, the Federal Government announced its intention to introduce a criminal offence for failing to prevent modern slavery in supply chains.

Under the proposal, organisations with annual consolidated revenue above $100 million could be criminally liable unless they can demonstrate they took reasonable steps to prevent modern slavery occurring within their supply chains.

Public consultation has now closed.

The detail of the offence is still being designed.

The offence attracts attention because offences make headlines.

The defence deserves attention because the defence determines outcomes.

If the reforms proceed as proposed, the practical question for many organisations will not be:

"Did modern slavery exist somewhere in our supply chain?"

The practical question may become:

"What can we demonstrate we did about it?"

That is quite a different conversation.

And it is one procurement is uniquely positioned to influence.

Because demonstrating reasonable steps is an evidence exercise.

Evidence of what was known.

Evidence of what risks were visible.

Evidence of what actions were taken.

Evidence of how decisions were made.

Supplier records.

Contracts.

Risk assessments.

Spend data.

Approval trails.

None of those belong to the legal team.

Much of it sits with procurement.

This Is the Same Weakness, Tested From a Different Direction

Last month I wrote about why supplier masters struggle to answer new questions about AI in the supply chain.

The same supplier often exists under different records.

Contracts sit in one system.

Spend sits in another.

Risk assessments somewhere else again.

Modern slavery reform is testing the same weakness.

With one major difference.

This time, the answer may underpin a legal defence.

In my experience, the information is not missing.

It is disconnected.

Individually, each source tells part of the story.

Together, they provide the evidence needed to understand supplier exposure and demonstrate reasonable steps.

Too often, procurement teams are left to connect those pieces manually.

And demonstrating reasonable steps is rarely about producing a single document.

It is about demonstrating a chain of decisions.

Chains are only visible when the links are connected.

Commercial Decisions Are Risk Signals Too

One of the more interesting aspects of the consultation paper is that its examples do not only look at supplier behaviour.

They also look at buyerโ€™s behaviour.

Purchasing practices.

Cost pressures.

Unrealistic deadlines.

This matters because procurement creates risk signals every day through ordinary commercial decisions.

For example:

๐Ÿ”น Spend with a supplier increases significantly

๐Ÿ”น A contract is extended or expanded

๐Ÿ”น A supplier becomes the dominant source within a category

๐Ÿ”น The supplier base is consolidated and dependency increases

๐Ÿ”น New regions or labor markets are introduced

๐Ÿ”น Sourcing timelines are compressed

Each is a commercial decision.

Each changes organisational exposure.

Yet no one necessarily appears in a risk register as a formal risk event.

Procurement's own records often contain some of the earliest indicators that a supplier deserves another look.

Those signals only become useful when they can be connected to supplier history, spend exposure, contracts, and existing risk information.

The Same Data That Protects You Can Also Expose You

This is the part procurement should think carefully about.

The same information that helps demonstrate reasonable steps can also reveal where risk was created.

The same records that support a defence can also explain the decisions that increased exposure.

That is not an argument against maintaining evidence.

It is an argument for understanding what that evidence says.

The Better Question Is What Makes You Look Again

None of this means reassessing every supplier every week.

That simply creates a different operational problem.

The more useful question is:

What should trigger a second look?

Potential triggers might include:

๐Ÿ”น Material changes in spend

๐Ÿ”น Ownership changes

๐Ÿ”น New subcontracting arrangements

๐Ÿ”น Expansion into higher-risk geographies

๐Ÿ”น Adverse media events

๐Ÿ”น Sanctions or compliance developments

๐Ÿ”น Significant contract changes

๐Ÿ”น Growing dependency on a single supplier

๐Ÿ”น Multiple smaller indicators that become meaningful when viewed together

The answer will differ between organisations.

The principle remains the same.

Calendar-based reviews tell you when you last looked.

They do not necessarily tell you when you should have.

Where Technology Helps and Where It Doesn't

Technology cannot decide whether a supplierโ€™s risk is acceptable.

That remains a human judgement.

What technology can do is help organisations recognise meaningful changes sooner.

The objective is not another dashboard.

The objective is connected intelligence.

Supplier information, spend activity, contract exposure and risk signals viewed together in context.

This is where RobobAI's Risk Agent plays a role, bringing supplier, spend and risk information together so procurement teams can see where something has changed and investigate it in context.

Not to replace judgement.

To direct it.

Because procurement teams cannot investigate everything.

But they do need confidence they are looking in the right places.

The Question Worth Asking

Supplier onboarding asks:

"Is this supplier acceptable?"

Supplier governance asks:

"What do we know now that we didn't know then?"

If the reforms proceed as proposed, it is the second question that matters most.

So here is a practical test.

If one of your top fifty suppliers changed ownership last quarter, how would you find out, and how long would it take

 

 

 

Related posts

The Deadlines Are Moving. What They Ask of Us Isn't.

The Deadlines Are Moving. What They Ask of Us Isn't.

Executive summary: For a long time, organisations have planned regulatory change backwards from a date. A requirement was announced. A commencement...

Read more >