Semantius Logo

Supplier Risk and Compliance

1. Overview

Supplier risk assessment, certifications, sanctions and compliance screening, and ESG. Operational, qualification-gated supplier risk, distinct from deep third-party due diligence (TPRM).

2. Entity summary

Namedata_objectDescription
Supplier Attestationssupplier_attestationsDeclarations the supplier signs, such as code-of-conduct, modern-slavery, and conflict-minerals attestations, tracked through signature and expiry.
Supplier Beneficial Ownerssupplier_beneficial_ownersBeneficial-ownership records for each supplier, capturing owner identity, ownership percentage, and verification source.
Supplier Certificationssupplier_certificationsSupplier-issued certifications such as food safety, organic, kosher, halal, allergen statements, and insurance coverage, with expiry tracking.
Supplier Diversity Classificationssupplier_diversity_classificationsDiversity spend certifications for each supplier, such as MBE, WBE, and VBE, with certifying body and expiry.
Supplier Insurance Certificatessupplier_insurance_certificatesCertificates of insurance for each supplier, with coverage type, limits, carrier, and expiry.
Supplier Risk Assessmentssupplier_risk_assessmentsRisk-scoring records per supplier across operational, financial, and cyber dimensions.
Supplier Screening Recordssupplier_screening_recordsSanctions, denied-party, and PEP screening events per supplier, with results and adjudication trail.
Supplier ESG Assessmentssupplier_esg_assessmentsSupplier ESG performance profiles, with questionnaire responses, audit results, certifications, and Scope 3 estimates, refreshed annually.
Supplier Questionnairessupplier_questionnairesReusable questionnaire templates used across qualification, performance, and risk workflows, such as insurance, security, ESG, and financial forms.
flowchart TD
  classDef master fill:#d4f4dd,stroke:#27ae60,color:#0b3d20;
  classDef consumer fill:#e8def8,stroke:#7b1fa2,color:#3a155d;
  classDef platform_builtin fill:#e0e0e0,stroke:#424242,color:#1a1a1a;
  supplier_risk_assessments["Supplier Risk Assessments"]
  supplier_certifications["Supplier Certifications"]
  supplier_screening_records["Supplier Screening Records"]
  supplier_beneficial_owners["Supplier Beneficial Owners"]
  supplier_diversity_classifications["Supplier Diversity Classifications"]
  supplier_insurance_certificates["Supplier Insurance Certificates"]
  supplier_attestations["Supplier Attestations"]
  supplier_questionnaires["Supplier Questionnaires"]
  supplier_esg_assessments["Supplier ESG Assessments"]
  users["Users"]
  users -->|"authors"| supplier_risk_assessments
  users -->|"approves"| supplier_risk_assessments
  users -->|"uploads"| supplier_certifications
  class supplier_risk_assessments master;
  class supplier_certifications master;
  class supplier_screening_records master;
  class supplier_beneficial_owners master;
  class supplier_diversity_classifications master;
  class supplier_insurance_certificates master;
  class supplier_attestations master;
  class supplier_questionnaires consumer;
  class supplier_esg_assessments consumer;
  class users platform_builtin;
  style supplier_screening_records stroke-dasharray:5 5;
  style supplier_beneficial_owners stroke-dasharray:5 5;
  style supplier_diversity_classifications stroke-dasharray:5 5;
  style supplier_insurance_certificates stroke-dasharray:5 5;
  style supplier_attestations stroke-dasharray:5 5;
  style supplier_questionnaires stroke-dasharray:5 5;
  style supplier_esg_assessments stroke-dasharray:5 5;

3. Entities catalog

#data_objectcanonical codesingularpluralrolemastered inmastered labelnecessitypersonal_contententity_typewrite tiernotes
1supplier_attestationssupplier_attestationsSupplier AttestationSupplier Attestationsmaster--optional-operational_workflow:manage-
2supplier_beneficial_ownerssupplier_beneficial_ownersSupplier Beneficial OwnerSupplier Beneficial Ownersmaster--optionalyesoperational_record:manage-
3supplier_certificationssupplier_certificationsSupplier CertificationSupplier Certificationsmaster--required-operational_workflow:manage-
4supplier_diversity_classificationssupplier_diversity_classificationsSupplier Diversity ClassificationSupplier Diversity Classificationsmaster--optional-operational_workflow:manage-
5supplier_insurance_certificatessupplier_insurance_certificatesSupplier Insurance CertificateSupplier Insurance Certificatesmaster--optional-operational_workflow:manage-
6supplier_risk_assessmentssupplier_risk_assessmentsSupplier Risk AssessmentSupplier Risk Assessmentsmaster--required-operational_workflow:manage-
7supplier_screening_recordssupplier_screening_recordsSupplier Screening RecordSupplier Screening Recordsmaster--optional-operational_workflow:manage-
8supplier_esg_assessmentssupplier_esg_assessmentsSupplier ESG AssessmentSupplier ESG Assessmentsconsumer--optional-operational_workflow:manage-
9supplier_questionnairessupplier_questionnairesSupplier QuestionnaireSupplier Questionnairesconsumersrm-supplier-lifecycleSupplier Lifecycle Managementoptional-catalog:admin-

4. Aliases and industry synonyms

(none: no industry-scoped aliases for this scope)

5. Relationships

5.1 Intra-scope edges

(none: no relationships with both endpoints inside the scope)

5.2 Built-in edges (users and other platform built-ins)

fromverbtocardinalitynecessityowner_sidedelete_modefk_formatnotes
usersauthorssupplier_risk_assessmentsone_to_manyoptionalsourceclearreference-
usersapprovessupplier_risk_assessmentsone_to_manyoptionalsourceclearreference-
usersuploadssupplier_certificationsone_to_manyoptionalsourceclearreference-

5.3 Cross-scope edges

5.3a Outbound from this scope’s masters and contributors

Edges this scope drives: the in-scope endpoint has role of master or contributor.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
audit_engagementssamplessupplier_risk_assessmentsmany_to_manyoptionalnonen/a-
supplier_certificationsauthorizestraceability_lotsmany_to_manyoptionalnonen/a-
suppliersholdssupplier_certificationsone_to_manyoptionalnonen/a-
suppliersassessed_bysupplier_risk_assessmentsone_to_manyoptionalnonen/a-
supplier_qualificationsrequiressupplier_certificationsmany_to_manyoptionalnonen/a-
supplier_risk_assessmentsfeedssupplier_scorecardsone_to_manyoptionalnonen/a-
supplier_risk_assessmentsescalates_toaudit_issuesone_to_manyoptionalnonen/a-
supplier_risk_assessmentssampled_byaudit_engagementsone_to_manyoptionalnonen/a-
supplier_certificationsupdatessupplier_qualificationsone_to_manyrequirednone (required-if-present)n/a-

5.3b Context edges on embedded shells and consumed entities

Edges the canonical owner drives, shown for context: the in-scope endpoint has role of embedded_master, consumer, or derived.

fromverbtocardinalitynecessitydelete_modefk_formatnotes
supplier_esg_assessmentsupdatessupplier_qualificationsone_to_manyoptionalnonen/a-

6. Cross-domain context

6.1 Master consumers (other modules / domains that embed this scope’s masters)

data_objectother module / domainrolenecessitynotes
supplier_certificationsFOOD-TRACE-SUPPLIER-PROVENANCE (Supplier Documents and Provenance) - FOOD-TRACEmasterrequired-
supplier_certificationsFSQM-AUDIT-SUPPLIER (Certification Audit and Supplier Risk) - FSQMcontributorrequired-

6.2 Outbound handoffs (events this scope publishes)

source moduletarget domaintarget moduletrigger_eventtransitionpayloadintegrationfrictiondescription
(domain-level)GRC(domain-level)supplier_risk_assessment.elevated(threshold)supplier_risk_assessmentsevent_streamhighElevated supplier risk opens a GRC issue and may trigger remediation.
(domain-level)AUDIT(domain-level)supplier_risk_assessment.completed(lifecycle)supplier_risk_assessmentsbatch_syncmediumAUDIT samples supplier risk assessments as part of third-party-risk testing.

6.3 Inbound handoffs (events this scope reacts to)

target modulesource domainsource moduletrigger_eventtransitionpayloadintegrationfrictiondescription
(domain-level)ESG(domain-level)supplier_esg_assessment.score_updatedassessedassessed (state_change)supplier_esg_assessmentsapi_callmediumUpdated ESG score → SUP-LIFE supplier_qualifications field; tier reassessment.

6.4 Master providers (modules / domains that own masters this scope embeds)

data_objectrole herenecessitycanonical owner(s)slice notes
supplier_esg_assessmentsconsumeroptional(no canonical owner recorded)-
supplier_questionnairesconsumeroptionalSRM-SUPPLIER-LIFECYCLE (SRM)-

7. Lifecycle states

supplier_attestations (Supplier Attestation)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10requested----
20signed--srm-risk-compliance:sign_attestation-
30expired----

supplier_certifications (Supplier Certification)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
0uploaded---Certification document uploaded and awaiting verification.
1verified--food-trace-supplier-provenance:verified_supplier_certificationCertification verified against the issuing authority and document validity.
2active----Certification active and within its validity window.
3expiring----Certification approaching expiry; renewal requested.
4expired----Certification past expiry with no renewal received.
5renewed----Certification renewed with a current valid document; validity window resets.
6revoked-food-trace-supplier-provenance:revoked_supplier_certificationCertification revoked; supplier blocked from new lot acceptance until restored.

supplier_diversity_classifications (Supplier Diversity Classification)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10valid----
20expiring_soon-----
30expired----
40revoked----

supplier_insurance_certificates (Supplier Insurance Certificate)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10valid----
20expiring_soon-----
30expired----

supplier_screening_records (Supplier Screening Record)

orderstate_nameinitial?terminal?requires_permission?derived gatedescription
10pending----
20screened-----
30hit_review-----
40adjudicated-srm-risk-compliance:adjudicate_screening-
50cleared----

8. Permissions and business rules (derived)

8.1 Permissions

permissiontierdescriptionincluded in :admin?
srm-risk-compliance:readbaseline-readRead access to every entity in the module
srm-risk-compliance:managebaseline-manageEdit operational records
srm-risk-compliance:adminbaseline-adminEdit reference data and inherit every workflow gate below-
srm-risk-compliance:adjudicate_screeningworkflow-gate (lifecycle)Transition supplier_screening_records into state adjudicated
srm-risk-compliance:sign_attestationworkflow-gate (lifecycle)Transition supplier_attestations into state signed
srm-risk-compliance:view_all_supplier_beneficial_ownersoverride (personal_content)View all supplier_beneficial_owners rows beyond row-scope
srm-risk-compliance:manage_all_supplier_beneficial_ownersoverride (personal_content)Manage all supplier_beneficial_owners rows beyond row-scope

8.2 Business rules

rule_namedata_objectsource flagintent
supplier_beneficial_owner_edit_scopesupplier_beneficial_ownershas_personal_contentRow-scope by default; override via srm-risk-compliance:view_all_supplier_beneficial_owners / srm-risk-compliance:manage_all_supplier_beneficial_owners

9. Roles, RACI, and responsibilities (derived)

Baseline roles, the permission hierarchy, and RACI realization are DERIVED from this scope’s entity-type write tiers + process_raci; none of it is stored in the catalog (the deployer provisions it from this blueprint).

9.1 SRM-RISK-COMPLIANCE

Baseline roles:

rolebaseline grant
srm-risk-compliance_viewersrm-risk-compliance:read
srm-risk-compliance_managersrm-risk-compliance:manage

Permission hierarchy:

permissionincludes
srm-risk-compliance:adminsrm-risk-compliance:manage
srm-risk-compliance:managesrm-risk-compliance:read
srm-risk-compliance:adminsrm-risk-compliance:adjudicate_screening
srm-risk-compliance:adminsrm-risk-compliance:sign_attestation
srm-risk-compliance:adminsrm-risk-compliance:view_all_supplier_beneficial_owners
srm-risk-compliance:adminsrm-risk-compliance:manage_all_supplier_beneficial_owners

RACI realization:

(none: no process_raci assignments wired to this module’s gated processes yet)

9.2 Functional ownership and default grants

responsibilitybusiness functiondefault roledefault tier
ownerProcurementadmin:admin
contributorGovernance, Risk and Compliancemanage:manage
contributorLegalmanage:manage