# What Is Vendor Compliance Management? A South African Guide

> Vendor compliance management verifies that suppliers and contractors meet your legal and contractual requirements, and keeps checking. What it covers in South Africa, from B-BBEE and COID to POPIA operators.

_Published 2026-09-29 · GRC · XGRC® Software_

Every organisation depends on suppliers, contractors and service providers, and every one of them carries risk. A contractor without valid COID cover working on your site, a supplier whose B-BBEE certificate expired three months ago, or a cloud provider processing personal information without a proper agreement can each become your problem, not theirs. Vendor compliance management is how organisations keep that risk under control.

## What Is Vendor Compliance Management?

Vendor compliance management is the process of verifying that suppliers, contractors and service providers meet your legal, contractual and policy requirements before you engage them, and of monitoring that they keep meeting them for as long as you work with them. It covers the documents a vendor must provide, the checks you run on them, the expiry dates you track and the actions you take when something lapses.

It is sometimes called supplier compliance management or contractor compliance management. The principle is the same: you cannot outsource accountability, so you need evidence that the organisations you rely on are compliant.

## Vendor Compliance, Third-Party Risk and Procurement

These terms overlap, but they are not the same thing:

- Procurement is about buying: sourcing, pricing, contracts and purchase orders
- Vendor compliance is about proof: collecting and verifying the documents and attestations a vendor must hold, and keeping them current
- Third-party risk management is the wider discipline of assessing and managing all the risks a third party brings, including financial, operational, cyber and reputational risk

Vendor compliance is usually the foundation of third-party risk management. Without verified, current compliance records, a risk assessment of a supplier rests on assumptions. For a closer look at the difference between compliance tooling and procurement systems, see [supplier compliance software vs procurement systems](https://xgrcsoftware.com/insights/supplier-compliance-software-vs-procurement-systems/).

## The South African Requirements

In South Africa, a typical vendor compliance programme has to cover several specific obligations. The exact mix depends on your sector and on what each vendor does for you.

B-BBEE verification. Preferential procurement is part of the Broad-Based Black Economic Empowerment scorecard, so organisations need valid evidence of each supplier's B-BBEE status. Larger suppliers provide a certificate from a SANAS-accredited verification agency, normally valid for 12 months. Exempted Micro Enterprises, and Qualifying Small Enterprises that are at least 51% black owned, can provide a sworn affidavit instead. Sector codes can change the thresholds, so check which code applies.

Tax compliance. Suppliers can share a Tax Compliance Status PIN from SARS, which lets you confirm their tax compliance status directly.

Compensation for occupational injuries. Contractors whose employees work on your premises should hold a letter of good standing under the Compensation for Occupational Injuries and Diseases Act 130 of 1993.

Health and safety. Under section 37(2) of the Occupational Health and Safety Act 85 of 1993, an employer can agree in writing with a contractor (a mandatary) that the contractor takes responsibility for health and safety compliance. That agreement, together with the contractor's safety file, risk assessments and competence records, is core evidence. Construction work also falls under the Construction Regulations 2014, and contractors on mines work under the Mine Health and Safety Act 29 of 1996.

Personal information. Under the Protection of Personal Information Act 4 of 2013, a vendor that processes personal information on your behalf is an operator. Section 21 requires a written contract that obliges the operator to establish and maintain appropriate security measures, and the responsible party remains accountable. If personal information will be sent outside South Africa, section 72 sets conditions for the transfer.

Company and banking details. Confirming CIPC registration and verifying bank details before the first payment are simple checks that prevent supplier fraud, one of the most common and expensive vendor failures.

## The Vendor Compliance Lifecycle

Vendor compliance is not a one-off check at onboarding. It runs for the whole relationship:

- Classify the vendor by risk: what it supplies, whether it works on site, whether it handles personal information, and how critical it is to your operations
- Set the requirements for that risk tier, so a high-risk contractor provides more evidence than a low-risk stationery supplier
- Collect and verify the documents and attestations, checking them against the issuing source where possible
- Approve the vendor only when every mandatory requirement is met, with the approval recorded
- Track every expiry date, and request renewals before documents lapse
- Monitor performance, incidents and changes such as a new owner or a new service
- Re-assess periodically, and offboard cleanly when the relationship ends, including the return or destruction of personal information

## Why Vendor Compliance Breaks Down

Most programmes fail for predictable reasons. Documents arrive by email and are saved to shared folders that nobody reviews. Expiry dates live in a spreadsheet that one person maintains. Site managers let a contractor start work because the paperwork is "on its way". Procurement, SHEQ and legal each hold part of the picture, and nobody can say with confidence which vendors are compliant today.

The consequences are real. An expired COID letter or missing section 37(2) agreement leaves the organisation exposed after an injury on site. An operator without a POPIA-compliant contract turns a supplier's data breach into your reportable security compromise. A lapsed B-BBEE certificate can change your own scorecard.

## Where to Start

Organisations that are moving from spreadsheets rarely need to design everything at once. A practical first phase looks like this:

- List every active vendor in one place, and remove duplicates and dormant accounts
- Agree three or four risk tiers, and the mandatory documents for each tier, with procurement, SHEQ, legal and finance in the room
- Start with the highest-risk group, usually contractors who work on site and vendors who process personal information
- Set one rule that everyone follows: no work starts and no purchase order is released until the mandatory documents are verified
- Report compliance status by tier every month, so gaps are visible to management rather than discovered during an audit or after an incident

Once the high-risk group is under control, extend the same process to the rest of the vendor base, and add periodic re-assessment for critical suppliers.

## What Good Vendor Compliance Software Does

Vendor compliance software replaces email and spreadsheets with a structured process. It should give vendors a portal to submit their own documents, validate submissions against your requirements, track every expiry date and chase renewals automatically, stop non-compliant vendors from being approved for work, and give every stakeholder the same live view of each vendor's status. It should also keep a full audit trail, so you can show an auditor, a regulator or a board exactly what was checked, when and by whom.

The most useful systems connect vendor compliance to the rest of governance. When a supplier's compliance status feeds your risk register, your incident records and your audit plan, third-party risk is governed as part of your total exposure. For the bigger picture, see [what extended enterprise risk management involves](https://xgrcsoftware.com/insights/extended-enterprise-risk-management/).

## How XGRC® Compliance Hub Supports Vendor Compliance

[XGRC® Compliance Hub](https://xgrcsoftware.com/compliance-hub/) is a structured external portal for supplier and contractor compliance. Vendors submit documents such as B-BBEE certificates, tax compliance status, COID letters, insurance certificates and safety files through the portal. Each submission is checked against your requirements, expiry dates are tracked, and vendors that are not compliant cannot be approved for site work.

Because Compliance Hub runs on the same platform as [SHEQX®](https://xgrcsoftware.com/sheqx/) and [enterprise risk management](https://xgrcsoftware.com/erm/), a contractor's compliance status, the incidents on its sites and the risks it carries sit in one connected record. See the [vendor management use case](https://xgrcsoftware.com/use-cases/vendor-management/) for how it works in practice, or [compliance management](https://xgrcsoftware.com/use-cases/compliance-management/) for the wider programme.

## Frequently asked questions

### What is vendor compliance management?

Vendor compliance management is the process of verifying that suppliers, contractors and service providers meet your legal, contractual and policy requirements before you engage them, and monitoring that they keep meeting them for the whole relationship, including tracking expiry dates and renewals.

### What documents should a South African supplier provide?

It depends on the risk, but typical requirements are B-BBEE evidence (a certificate from a SANAS-accredited verification agency or a sworn affidavit), a SARS Tax Compliance Status PIN, CIPC registration and bank confirmation. Contractors working on site usually also provide a COID letter of good standing, a section 37(2) OHS Act agreement and a safety file.

### How long is a B-BBEE certificate valid?

A B-BBEE verification certificate is normally valid for 12 months from the date it is issued, so suppliers need to renew it every year. Sworn affidavits for qualifying small and micro enterprises also need to be kept current.

### Does POPIA apply to our vendors?

Yes, when a vendor processes personal information on your behalf. POPIA calls that vendor an operator, and section 21 requires a written contract obliging the operator to maintain appropriate security measures. Your organisation, as the responsible party, stays accountable for the personal information.

---

Source: https://xgrcsoftware.com/insights/vendor-compliance-management
