OECD due diligence
Operationalise OECD due diligence through ownership, cadence, escalation and review
A framework becomes an operating system only when it is translated into named roles, cadence, escalation and management review.
One distinction should be made at the outset. The OECD Due Diligence Guidance for Responsible Business Conduct uses a six-step due diligence process. The OECD Minerals Guidance for conflict-affected and high-risk areas uses a five-step framework. A company may draw on both, but should identify the document it is referencing.
Whichever framework applies, implementation is not achieved by turning every step into a chapter of policy. Each step must be translated into four operating elements: who owns it, how often it happens, what triggers escalation, and when management reviews the result.
“The department is responsible” is not enough
Policies often say that supply-chain management is responsible for supplier due diligence. An assessment will go further: which role performs the work, is it in the job description, who provides cover during absence, and who approves the result?
Responsibility should be assigned to roles, with backup and approval arrangements. A practical tool is a responsibility matrix that names the primary role, backup role and approving role for each action. It usually exposes two risks: empty ownership, or the same person performing and approving an action with no meaningful control separation.
Cadence determines the evidence
“Periodically” contains very little verifiable information. Teams need to define cadence, triggers and whether different risk levels operate on different rhythms.
| Risk level | Illustrative review cadence | Triggered review examples |
|---|---|---|
| Higher risk | More frequent, management-confirmed | Red flags, origin interruption, serious adverse information |
| Medium risk | Semi-annual or on material change | Ownership, location, product or source changes |
| Lower risk | Annual or risk-based | New information indicating a changed risk profile |
This is an operating example, not an OECD-mandated frequency table. Each company should determine and document the rationale for its cadence based on the applicable standard, supply-chain scale, risk profile and resources.
Once policy says “quarterly”, evidence should show a credible quarterly rhythm. Four records produced together at year end can raise a reliability issue, not merely a missed deadline.
Escalation must be decidable, accountable and reviewable
“Report significant risk to management promptly” is difficult to operate. A stronger mechanism defines:
- which red flags or events trigger escalation;
- the accountable role;
- the information that must be captured;
- the internal time allowed for initial assessment and decision;
- decision options, including continued trade with measurable mitigation, temporary suspension, or disengagement after failed mitigation or when mitigation is not feasible or acceptable.
Internal timelines should be designed around risk and governance; examples should not be presented as OECD requirements. What matters is having triggers, ownership, timeframes and decision paths together.
Management review is more than an annual meeting
Management needs risk trends, mitigation progress, overdue actions, resource constraints and decisions—not activity counts alone.
Standing inputs can include:
- risks identified during the period and their distribution;
- progress and effectiveness of mitigation;
- closure status of audit findings;
- supplier additions, suspensions, terminations and material changes;
- system weaknesses, data quality and resource needs.
Outputs should include decisions, accountable roles and deadlines. Public reporting should also reconcile with management review so that external statements do not contradict internal records.
Convert the framework into an operating calendar
| Rhythm | Activity | Main output |
|---|---|---|
| Onboarding / continuous | New supplier or source screening | Screening record and decision |
| Monthly | Red flags, grievances and high-risk actions | Risk register and escalation record |
| Quarterly | Higher-risk reassessment and data-integrity review | Reassessment and exception log |
| Semi-annual | Cross-functional governance meeting | Minutes and decisions |
| Annual | Management review and public reporting | Review, action plan and disclosure |
| Event-driven | Significant-risk escalation | Assessment, decision and mitigation plan |
The calendar is an implementation tool, not wording from the standard. It lets a company demonstrate how the system keeps operating over time.
Important note and sources
This article distinguishes the OECD RBC six-step process from the Minerals Guidance five-step framework. Cadence, timelines and risk segmentation are implementation recommendations, not fixed standard requirements.