Learn · Glossary

A plain-English glossary of third-party document terms.

Definitive, no-jargon definitions for the 36 terms that come up most in supplier readiness, evidence packs, TPRM and compliance. Use it as a shared vocabulary for your team - and as a jumping-off point into the tools and guides.

Core concepts

The foundational ideas behind third-party document management and supplier readiness.

Chain of custody
Chain of custody is the documented trail of who uploaded, reviewed, approved and shared a supplier document, from the moment it entered the system to every place it has since been sent.
Full definition
Evidence pack
An evidence pack is a bundled set of supplier documents assembled for a specific audience - a client audit, a tender response or an insurer review - and shared as a single trustworthy artefact.
Full definition
Readiness
Readiness is the state in which every document a supplier needs is on file, in date and available to share without last-minute chasing.
Full definition
Single source of truth
A single source of truth is one authoritative place where the current version of every supplier document lives, so different teams cannot end up sharing different copies.
Full definition
Supplier onboarding
Supplier onboarding is the structured process of collecting the documents, data and approvals needed before a new supplier can start work.
Full definition
Third-party risk management (TPRM)
Third-party risk management (TPRM) is the ongoing process of identifying, assessing and monitoring the risks that suppliers, vendors, contractors and other external parties bring to your organisation.
Full definition

Document types

The specific certificates, policies and reports that make up a supplier compliance file.

Certificate of insurance (COI)
A certificate of insurance (COI) is a one-page summary issued by an insurer that confirms the policy holder, cover type, limits, effective dates and any endorsements - the standard evidence supplied to prove a supplier is insured.
Full definition
DBS check
A DBS check is a UK criminal-record check issued by the Disclosure and Barring Service, used to screen individuals for roles involving vulnerable people, security or trust.
Full definition
Employers' liability insurance
Employers' liability insurance is a UK legal requirement for most businesses with employees, covering claims from staff who are injured or become ill because of their work.
Full definition
ISO 27001
ISO 27001 is the international standard for information security management systems, and its certificate is the most commonly accepted proof that a supplier has independently audited security controls.
Full definition
Method statement
A method statement is a written description of how a specific task will be carried out safely, in the correct order, with the right equipment and by competent people.
Full definition
Modern slavery statement
A modern slavery statement is a published statement, required by the UK Modern Slavery Act 2015 of businesses over £36m turnover, describing the steps taken to prevent modern slavery in operations and supply chains.
Full definition
PAT test certificate
A PAT test certificate confirms that portable electrical appliances used by a supplier have been inspected and tested to be electrically safe.
Full definition
Professional indemnity insurance
Professional indemnity (PI) insurance covers claims arising from professional advice or services that cause a client financial loss.
Full definition
Public liability insurance
Public liability insurance covers a business against claims for injury or property damage caused to third parties in the course of its work.
Full definition
RAMS (risk assessment and method statement)
RAMS is the shorthand for a paired risk assessment and method statement - the standard site-safety document that describes hazards, controls and the sequence of work.
Full definition
Risk assessment
A risk assessment is a structured evaluation of the hazards a task or activity presents, with each risk rated before and after the controls the supplier will apply.
Full definition
SIA licence
An SIA licence is the individual authorisation issued by the UK Security Industry Authority that lets someone lawfully carry out licensable security work such as door supervision, guarding or close protection.
Full definition

Compliance and data protection

The legal and regulatory concepts that shape how supplier information is collected and shared.

Anti-bribery policy
An anti-bribery policy is a written statement of a business's commitment to comply with the UK Bribery Act 2010, setting out what employees and third parties may and may not do around gifts, hospitality, facilitation payments and conflicts of interest.
Full definition
Data controller
The data controller is the organisation that decides why and how personal data will be processed - the party accountable to regulators and to individuals under GDPR.
Full definition
Data processing agreement (DPA)
A data processing agreement (DPA) is the contract required under GDPR whenever a data controller uses a data processor, setting out the scope, purpose, security and sub-processing rules for the personal data involved.
Full definition
Data processor
A data processor is a supplier that handles personal data on behalf of a controller, strictly following the controller's documented instructions.
Full definition
Data protection impact assessment (DPIA)
A data protection impact assessment (DPIA) is a structured review, required by GDPR before high-risk processing, that identifies and mitigates the risks to individuals from a proposed use of personal data.
Full definition
GDPR
GDPR is the General Data Protection Regulation, the EU and UK data-protection framework that governs how personal data is collected, processed, shared and protected.
Full definition

Roles and parties

Who does what across a third-party relationship.

Compliance manager
A compliance manager is the person in a business accountable for making sure suppliers, contractors and internal processes meet the regulatory, contractual and policy obligations that apply.
Full definition
Principal contractor
The principal contractor is the party legally responsible under CDM 2015 for planning, managing and monitoring the construction phase of a project involving more than one contractor.
Full definition
Subcontractor
A subcontractor is a party engaged by a supplier or contractor to perform part of the work the supplier has contracted to deliver.
Full definition
Supplier
A supplier is any external organisation that provides goods or services to your business under a commercial arrangement.
Full definition
Third party
A third party is any external individual or organisation your business relies on but does not directly employ - suppliers, vendors, subcontractors, agents, partners, resellers and referral sources all count.
Full definition
Vendor
A vendor is an external party that sells a product or service - often used specifically for technology and SaaS providers, though the term overlaps heavily with supplier.
Full definition

Strategy and methodology

How mature teams organise, prioritise and prove supplier readiness.

Audit trail
An audit trail is the time-stamped, immutable record of every action taken on a supplier document - upload, review, approval, share and expiry - that lets a third party reconstruct exactly what happened, when and by whom.
Full definition
Evidence-first procurement
Evidence-first procurement is the approach of collecting and reviewing the actual supplier documents before advancing a commercial conversation, rather than requesting them after selection.
Full definition
Expiry management
Expiry management is the discipline of tracking every dated supplier document and refreshing it before it lapses, so packs, portals and audits never surface expired evidence.
Full definition
Minimum viable evidence
Minimum viable evidence is the smallest set of documents that genuinely answers the question a client, auditor or regulator is asking - no more, no less.
Full definition
Risk-based due diligence
Risk-based due diligence is the practice of scaling the depth of supplier review to the risk that supplier presents, rather than applying the same checklist to every third party.
Full definition
Supplier segmentation
Supplier segmentation is the classification of suppliers into tiers - typically critical, important and routine - so that onboarding effort, review frequency and evidence requirements match actual risk.
Full definition

Glossary questions and answers

Put it into practice

Turn the vocabulary into a working evidence pack.

Credbase gives every supplier a live readiness score, tracks expiry dates for you, and produces a shareable evidence pack in seconds. Free to start, no card required.