Skip to content
SUPPLIER STANDARDS

AuditFile® Supplier Code of Conduct

Last Updated: August 11, 2026

What we expect of the companies and people we buy from, how we check, and what they can expect from us.

1. Purpose

AuditFile, Inc. makes AuditFile®, cloud audit software. We are a small company. Our suppliers are cloud infrastructure, AI model hosting, payment and software providers, and a few professional firms and contractors. This Code sets out what we expect from them. We aim to meet the same standards ourselves.

2. Scope and how this Code applies

This Code sets out what we expect of every AuditFile supplier, contractor and sub-processor. We apply it in proportion to risk. Suppliers that host or process customer data, or that power AI features, receive the closest review. A supplier that publishes its own code of substantially equivalent scope meets this Code by following its own. This Code supplements our contracts and creates no rights for third parties.

3. Standards we draw on

This Code is informed by the UN Global Compact Ten Principles, the ILO Declaration on Fundamental Principles and Rights at Work, the UN Guiding Principles on Business and Human Rights, and the OECD Guidelines for Multinational Enterprises on Responsible Business Conduct. AuditFile is not a participant in the UN Global Compact and claims no certification or endorsement under any of these instruments.

4. Compliance with law

Suppliers and their subcontractors must follow the laws that apply where they operate and where they serve AuditFile. Where this Code asks for more than the law, we expect the higher standard. Where the two conflict, the law governs.

5. Labor and human rights

Suppliers must:

  1. use no forced, bonded, trafficked or child labor, and not knowingly buy goods or services produced with it;
  2. pay at least legally required wages and benefits, respect legal limits on working hours, and provide required leave;
  3. respect workers' lawful right to form or join organizations of their choice and to bargain collectively;
  4. provide equal employment opportunity and not discriminate unlawfully;
  5. treat every worker with dignity, with no physical, sexual, psychological or verbal harassment or abuse;
  6. provide a safe and healthy workplace that meets applicable safety law;
  7. respect internationally recognized human rights, including those in the Universal Declaration of Human Rights.

We prefer suppliers that pay a living wage.

6. Business integrity

Suppliers must not offer, pay or accept bribes, kickbacks or facilitation payments, or give gifts or hospitality to influence a decision. On our behalf, they must give no gifts at all to employees of our government and public sector customers. Suppliers must disclose conflicts of interest, compete fairly, keep accurate records, and follow sanctions and export rules. They must describe their products, certifications and environmental claims accurately.

7. Data protection, privacy and security

Suppliers that handle AuditFile or customer data must protect it with safeguards suited to its sensitivity. They must use it only to deliver the contracted service, never sell it, keep it in agreed regions, and promptly report any security incident that affects it. We expect suppliers that host customer data to hold current independent security assurance, such as a SOC 2 Type II report or an ISO/IEC 27001 certificate.

8. Responsible use of AI

Suppliers that provide or use AI in services for AuditFile must not train models on AuditFile or customer content without our written permission. They must tell us where AI is used, keep human oversight of decisions that affect people, and comply with applicable law.

9. Accessibility

Suppliers whose software or content reaches our users are expected to work toward WCAG 2.1 Level AA conformance and to provide accessibility documentation on request.

10. Environmental responsibility

Suppliers must comply with environmental law. We expect them to measure and work to reduce their energy use, emissions and waste. We expect much of our own environmental impact to sit in cloud hosting and AI services. We prefer providers that publish climate targets, report progress, report energy and water efficiency, and manage hardware end of life responsibly.

11. Subcontractors

Suppliers are responsible for anyone they use to serve AuditFile and must pass on equivalent expectations. Where personal data is involved, equivalent data protection terms must be in a written contract.

12. Raising concerns

Anyone may report a suspected breach of this Code, including suppliers, their workers, our staff and our customers. Write to [email protected] with “Supplier conduct” in the subject line. AuditFile will not retaliate against anyone who raises a concern in good faith. We expect suppliers to give their own workers the same protection.

13. How we check

We consider this Code when we select or renew a supplier. We may ask any supplier reasonable questions or request documents. We do not perform on-site audits of large cloud providers and rely on their independent third-party reports.

14. When something goes wrong

Our first step is to raise the issue with the supplier and ask for a correction plan with dates. If a supplier will not correct a serious problem, or the problem involves forced or child labor, bribery or deliberate misuse of data, we will reduce, suspend or end the relationship where we practically can. Where we cannot, we will weigh alternatives at renewal.

15. What suppliers can expect from us

Clear requirements. Payment on agreed terms. Proportionate requests for information. Protection of supplier confidential information. No pressure to cut corners on the standards in this Code.

16. Ownership and review

AuditFile's management owns this Code. We review it at least once a year, and sooner when laws or major suppliers change. Questions go to [email protected].