Supplier Approval, Procurement & Due Diligence Policy

Version 1.0 · Last Updated:

1. Purpose

This policy sets out Murzo Group's approach to supplier approval, procurement due diligence, onboarding, monitoring, and supplier risk management.

The purpose is to support lawful, ethical, resilient, secure, and commercially sound purchasing decisions across products, services, materials, ingredients, packaging, technology, logistics, professional services, and international partnerships.

2. Scope

This policy applies to suppliers, contractors, consultants, manufacturers, co-packers, agents, distributors, logistics providers, laboratories, technology providers, farms, processors, recruiters, professional advisers, and other third parties providing goods or services to Murzo Group.

It applies before onboarding and during the supplier relationship, with controls scaled according to supplier risk and importance.

3. Supplier Risk Factors

Murzo Group will consider supplier risk before appointment and during the relationship.

  • Product safety, food safety, allergen, quality, traceability, chemical, animal by-product, or biosecurity risk
  • Data protection, cybersecurity, confidential information, intellectual property, or access to systems
  • Modern slavery, labour standards, ethical conduct, equality, harassment, and human rights risk
  • Bribery, corruption, fraud, sanctions, export controls, tax, and financial crime risk
  • Environmental impact, waste, packaging, green claims, transport, and sustainability risk
  • Business continuity, insurance, financial stability, location, subcontracting, and critical dependency

4. Due Diligence

Supplier due diligence should be proportionate to the risk, value, jurisdiction, and sensitivity of the goods or services.

  • Basic identity, company, ownership, contact, and trading information
  • Relevant certifications, licences, registrations, insurance, qualifications, or approvals
  • Policies and controls for quality, safety, data protection, security, modern slavery, anti-bribery, and environment where relevant
  • Product specifications, safety data sheets, allergen information, batch records, testing, labelling, and traceability evidence where relevant
  • Sanctions, adverse media, conflict of interest, financial stability, and legal-risk checks where appropriate
  • Subcontractor, agent, or intermediary checks where the supplier uses third parties

5. Approval & Onboarding

Suppliers should be approved by an authorised Murzo Group representative before use, with higher-risk suppliers subject to additional review.

Onboarding may include purchase terms, confidentiality terms, data processing terms, technical specifications, insurance requirements, product requirements, service levels, incident notification requirements, audit rights, or acceptance of the Supplier Code of Conduct.

6. Procurement Principles

Murzo Group procurement decisions should balance quality, safety, security, legal compliance, reliability, ethical performance, resilience, environmental impact, and commercial value.

People involved in procurement must avoid conflicts of interest, improper gifts, inducements, personal benefit, undisclosed commissions, and supplier favouritism.

7. Monitoring & Review

Supplier performance may be monitored through delivery performance, complaint data, incident reports, audits, document reviews, product checks, test results, account reviews, security reviews, and corrective action follow-up.

Critical or high-risk suppliers should be reviewed periodically and when there is a material change, incident, legal development, ownership change, service failure, or product safety concern.

8. Non-Conformance & Suspension

Murzo Group may require corrective action, suspend orders, block product release, remove system access, terminate a contract, report a concern, or replace a supplier where supplier performance or conduct creates unacceptable risk.

Supplier issues involving safety, legality, fraud, sanctions, modern slavery, data breach, security, recall, or serious misconduct must be escalated promptly.

9. Records & Responsibilities

Murzo Group will keep appropriate supplier records, including approvals, contracts, due diligence, specifications, certificates, insurance evidence, incidents, reviews, corrective actions, and termination decisions.

Procurement leads, managers, product owners, technical leads, compliance leads, and authorised representatives are responsible for applying this policy and escalating supplier risk.

10. Review

This policy will be reviewed periodically and when Murzo Group changes supplier categories, product types, jurisdictions, procurement systems, legal requirements, or risk profile.

Murzo Group signature