A plain-English glossary of third-party document terms.
Definitive, no-jargon definitions for the 36 terms that come up most in supplier readiness, evidence packs, TPRM and compliance. Use it as a shared vocabulary for your team - and as a jumping-off point into the tools and guides.
Core concepts
The foundational ideas behind third-party document management and supplier readiness.
- Chain of custody
- Chain of custody is the documented trail of who uploaded, reviewed, approved and shared a supplier document, from the moment it entered the system to every place it has since been sent. Full definition
- Evidence pack
- An evidence pack is a bundled set of supplier documents assembled for a specific audience - a client audit, a tender response or an insurer review - and shared as a single trustworthy artefact. Full definition
- Readiness
- Readiness is the state in which every document a supplier needs is on file, in date and available to share without last-minute chasing. Full definition
- Single source of truth
- A single source of truth is one authoritative place where the current version of every supplier document lives, so different teams cannot end up sharing different copies. Full definition
- Supplier onboarding
- Supplier onboarding is the structured process of collecting the documents, data and approvals needed before a new supplier can start work. Full definition
- Third-party risk management (TPRM)
- Third-party risk management (TPRM) is the ongoing process of identifying, assessing and monitoring the risks that suppliers, vendors, contractors and other external parties bring to your organisation. Full definition
Document types
The specific certificates, policies and reports that make up a supplier compliance file.
- Certificate of insurance (COI)
- A certificate of insurance (COI) is a one-page summary issued by an insurer that confirms the policy holder, cover type, limits, effective dates and any endorsements - the standard evidence supplied to prove a supplier is insured. Full definition
- DBS check
- A DBS check is a UK criminal-record check issued by the Disclosure and Barring Service, used to screen individuals for roles involving vulnerable people, security or trust. Full definition
- Employers' liability insurance
- Employers' liability insurance is a UK legal requirement for most businesses with employees, covering claims from staff who are injured or become ill because of their work. Full definition
- ISO 27001
- ISO 27001 is the international standard for information security management systems, and its certificate is the most commonly accepted proof that a supplier has independently audited security controls. Full definition
- Method statement
- A method statement is a written description of how a specific task will be carried out safely, in the correct order, with the right equipment and by competent people. Full definition
- Modern slavery statement
- A modern slavery statement is a published statement, required by the UK Modern Slavery Act 2015 of businesses over £36m turnover, describing the steps taken to prevent modern slavery in operations and supply chains. Full definition
- PAT test certificate
- A PAT test certificate confirms that portable electrical appliances used by a supplier have been inspected and tested to be electrically safe. Full definition
- Professional indemnity insurance
- Professional indemnity (PI) insurance covers claims arising from professional advice or services that cause a client financial loss. Full definition
- Public liability insurance
- Public liability insurance covers a business against claims for injury or property damage caused to third parties in the course of its work. Full definition
- RAMS (risk assessment and method statement)
- RAMS is the shorthand for a paired risk assessment and method statement - the standard site-safety document that describes hazards, controls and the sequence of work. Full definition
- Risk assessment
- A risk assessment is a structured evaluation of the hazards a task or activity presents, with each risk rated before and after the controls the supplier will apply. Full definition
- SIA licence
- An SIA licence is the individual authorisation issued by the UK Security Industry Authority that lets someone lawfully carry out licensable security work such as door supervision, guarding or close protection. Full definition
Compliance and data protection
The legal and regulatory concepts that shape how supplier information is collected and shared.
- Anti-bribery policy
- An anti-bribery policy is a written statement of a business's commitment to comply with the UK Bribery Act 2010, setting out what employees and third parties may and may not do around gifts, hospitality, facilitation payments and conflicts of interest. Full definition
- Data controller
- The data controller is the organisation that decides why and how personal data will be processed - the party accountable to regulators and to individuals under GDPR. Full definition
- Data processing agreement (DPA)
- A data processing agreement (DPA) is the contract required under GDPR whenever a data controller uses a data processor, setting out the scope, purpose, security and sub-processing rules for the personal data involved. Full definition
- Data processor
- A data processor is a supplier that handles personal data on behalf of a controller, strictly following the controller's documented instructions. Full definition
- Data protection impact assessment (DPIA)
- A data protection impact assessment (DPIA) is a structured review, required by GDPR before high-risk processing, that identifies and mitigates the risks to individuals from a proposed use of personal data. Full definition
- GDPR
- GDPR is the General Data Protection Regulation, the EU and UK data-protection framework that governs how personal data is collected, processed, shared and protected. Full definition
Roles and parties
Who does what across a third-party relationship.
- Compliance manager
- A compliance manager is the person in a business accountable for making sure suppliers, contractors and internal processes meet the regulatory, contractual and policy obligations that apply. Full definition
- Principal contractor
- The principal contractor is the party legally responsible under CDM 2015 for planning, managing and monitoring the construction phase of a project involving more than one contractor. Full definition
- Subcontractor
- A subcontractor is a party engaged by a supplier or contractor to perform part of the work the supplier has contracted to deliver. Full definition
- Supplier
- A supplier is any external organisation that provides goods or services to your business under a commercial arrangement. Full definition
- Third party
- A third party is any external individual or organisation your business relies on but does not directly employ - suppliers, vendors, subcontractors, agents, partners, resellers and referral sources all count. Full definition
- Vendor
- A vendor is an external party that sells a product or service - often used specifically for technology and SaaS providers, though the term overlaps heavily with supplier. Full definition
Strategy and methodology
How mature teams organise, prioritise and prove supplier readiness.
- Audit trail
- An audit trail is the time-stamped, immutable record of every action taken on a supplier document - upload, review, approval, share and expiry - that lets a third party reconstruct exactly what happened, when and by whom. Full definition
- Evidence-first procurement
- Evidence-first procurement is the approach of collecting and reviewing the actual supplier documents before advancing a commercial conversation, rather than requesting them after selection. Full definition
- Expiry management
- Expiry management is the discipline of tracking every dated supplier document and refreshing it before it lapses, so packs, portals and audits never surface expired evidence. Full definition
- Minimum viable evidence
- Minimum viable evidence is the smallest set of documents that genuinely answers the question a client, auditor or regulator is asking - no more, no less. Full definition
- Risk-based due diligence
- Risk-based due diligence is the practice of scaling the depth of supplier review to the risk that supplier presents, rather than applying the same checklist to every third party. Full definition
- Supplier segmentation
- Supplier segmentation is the classification of suppliers into tiers - typically critical, important and routine - so that onboarding effort, review frequency and evidence requirements match actual risk. Full definition
Glossary questions and answers
Turn the vocabulary into a working evidence pack.
Credbase gives every supplier a live readiness score, tracks expiry dates for you, and produces a shareable evidence pack in seconds. Free to start, no card required.