# Supplier risk questionnaire

To be completed by the supplier; each answer with a document reference where one exists.

## Company

1. Legal entity, registration number, ownership structure
2. Financial statements available: latest year, audited yes/no
3. Sites relevant to our supply, by country

## Continuity

4. Business continuity plan: exists, last tested (date)
5. Single points of failure in your supply to us (sites, sub-suppliers, materials)
6. Insurance: types and limits

## Compliance

7. Certifications (ISO 9001, ISO 14001, ISO 27001, others) with certificate dates
8. Sanctions and export control screening of your own suppliers: process
9. Code of conduct for your suppliers: exists, how enforced

## Information security (if data is exchanged)

10. Where is our data stored and processed
11. Access control and incident notification terms
12. Sub-processors

## Sustainability

13. Emissions reporting: scope, method, last period
14. Audits by third parties: which, when, findings addressed
