Questionnaires frequently ask whether a supplier has a policy. The resulting evidence is often a PDF containing purpose, scope and responsibilities. That may be necessary, but it only answers one question: has the organisation documented an intention?
The operating-evidence ladder
- Statement: the organisation says the control exists.
- Approved document: the control is defined and authorised.
- Ownership: named people understand their responsibilities.
- Use: records show the control operating in normal work.
- Exception: failures or deviations are identified.
- Correction: action addresses the cause and is followed through.
- Review: management examines performance and changes the system.
The appropriate rung depends on risk and procurement stage. A buyer should not demand an excessive evidence pack for a low-risk market conversation. A supplier should not rely on a signed policy where failure could harm users, service continuity or information security.
Example: complaints
A complaints policy can be tested through a sample log, acknowledgement time, investigation notes, outcome, trend classification and evidence that a recurring cause changed the process. A blank template is not the same as an operating complaint system.
Example: business continuity
A continuity plan is stronger when the organisation has tested contact trees, remote access, supplier dependencies, data restoration or alternative capacity. The test should record what failed and what changed.
Evidence should also show limits
Credible records explain coverage, date, sample size and unresolved weakness. “No complaints” may mean excellent service, low volume, poor reporting or a missing route. Evidence without context can create false confidence.
The Standards & Systems Clinic helps organisations build this evidence chain without claiming that implementation equals independent certification.