The Due Diligence That Would Have Caught the Supplier That Went Under
Blog + supporting content | Supplier Due Diligence pillar | ~1,180 words | Pro Outsourcing
Here is the pattern I see quite a lot. A supplier goes under. Not one of the small ones. A meaningful supplier for a meaningful category. The FD asks how this happened, and the answer, once everybody has been honest about it, is that the due diligence that was done at onboarding gave no indication of any trouble at all.
Which is generally true. The Companies House filings looked fine. The credit report came back clean. The references were positive. The site visit went well. The supplier had been trading for years and their marketing materials looked professional. There was nothing to flag.
Six months later they were in administration, and the business is now scrambling to find an alternative source under time pressure, at a higher price, for a critical part of the operation.
Nobody covered themselves in glory in that story, but it doesn’t mean anybody did anything wrong. The due diligence that was done was the due diligence that most businesses do. That’s the problem.
Due diligence as a one-off is only half the job
The way most mid-market businesses handle supplier due diligence is at onboarding. A new supplier is proposed, a form gets filled in, some checks get run, a decision gets signed off, and the supplier is in. From that point on, unless something specific triggers a review, the diligence sits in a folder and is not looked at again.
That model was probably fine when suppliers stayed in roughly the same shape year on year. It is less fine now, because the reasons suppliers go wrong tend not to be reasons that were visible when you first onboarded them. A supplier who was healthy in 2023 can be in real trouble by 2026 for entirely different reasons than the ones you checked for at the start.
What is actually needed for a critical supplier is a lighter, ongoing pattern of attention. Not another full onboarding review every year. Just a regular touchpoint on the things that would change in the eighteen months before a supplier gets into trouble.
The things that would actually have caught it
The credit report will tell you the supplier is not currently in default. It will not tell you their working capital position is tightening quarter on quarter, or that late payment days to their own suppliers have doubled, or that they have lost three customers who together made up 40% of last year’s revenue.
That kind of information takes a bit more digging. Some of it shows up if you know where to look. Slow supplier payments to their own base leak out through their accounts payable practices, which you can sometimes see from your own end of the relationship. Cash flow pressure sometimes shows up in willingness to negotiate on payment terms, in questions about milestone payments, in requests to accelerate invoicing. Loss of key customers sometimes shows up in the supplier’s LinkedIn hiring pattern, or in changes to their sales team.
None of this is easy to spot in isolation. If you are paying attention to a supplier that matters, the signs are usually there for months before the failure.
Beyond financial, the other bits that matter more than they used to
Financial health is only one strand of proper supplier due diligence, and probably not even the strand where the biggest risks now sit.
Concentration risk, in either direction, is worth knowing. If you are a major customer of a supplier and they are heavily dependent on your business, they are more exposed to your decisions than they might admit, and the relationship can shift quickly if you need to reduce spend. If they are a small customer of yours and you are 2% of their revenue, they will deprioritise your issues when they need to make choices about resource.
Ownership changes matter, because a supplier that gets acquired often stops being the supplier you signed up with. Product roadmap decisions get made elsewhere, service standards shift, and the person you would normally call is either gone or reporting into somebody who has never heard of you.
Regulatory and reputational exposure is worth a look for suppliers in sectors where those risks are meaningful. Sanctions changes, ownership traceability, anti-slavery declarations, ESG credentials that are accurate rather than aspirational. None of this is exciting but it is the kind of thing that gets nasty fast if you have not looked and it turns out to matter.
Cyber posture is a specific one that has grown into a real issue over the past few years. A supplier’s security is now often your security, particularly if you are integrated to any degree. Basic assurances are not enough for suppliers of any real material scale.
Proportionate is the word
None of this needs to be dramatic. A proportionate approach to due diligence starts by working out which of your suppliers actually justify ongoing attention. For most businesses, that is a small number. The top ten or twenty by spend, plus anybody who is genuinely critical to the operation regardless of spend, plus anybody whose failure would be materially painful. Add up carefully and you are often looking at thirty to fifty suppliers out of hundreds.
For those, a lighter-touch annual review, plus a routine set of monitoring on the financial and operational signals, is usually enough. It is the difference between a due diligence process that catches problems and a process that documents the fact that you were not watching.
For the rest, the onboarding check probably is enough, provided procurement governance means you would notice a change of circumstance if one landed via other routes.
The supplier that went under did not necessarily need a more elaborate onboarding check. They needed somebody in the business paying occasional attention to the signals over the following twelve months. Which is a much smaller ask than businesses often make of themselves when they think about due diligence.
Happy to talk it through if you want to work out which of your suppliers would repay that attention.