Vendor governance

Ethical Procurement & Supplier Policy

Raeburn aims to select suppliers on capability, value, risk and responsible business practice rather than logos or commercial incentives. Requirements are applied proportionately: a low-risk commodity supplier does not require the same depth of assessment as a provider handling confidential client data or privileged system access.

Current supplier assurance status

Current supplier review: complete

All current Raeburn Consulting suppliers have been reviewed against the applicable requirements of this Ethical Procurement & Supplier Policy. The depth of assessment is proportionate to each supplier's role, access, data processing, criticality and operational risk.

Security

Suppliers handling Raeburn or client systems, credentials or data should apply security controls proportionate to risk, including least privilege, secure authentication, supported software, vulnerability remediation, appropriate encryption and timely incident notification. Material security weaknesses may require remediation before onboarding or continued use.

Privacy & data protection

Suppliers must process personal data lawfully and only for agreed purposes, minimise collection, protect data appropriately, support applicable data-subject and deletion obligations, and provide sufficient information for Raeburn to assess relevant processing, transfers, retention and risk.

Modern slavery & labour standards

Raeburn does not knowingly support forced labour, human trafficking, child labour or exploitative working practices. Suppliers are expected to comply with applicable labour and modern-slavery law, respect fundamental worker rights and raise credible concerns in their own supply chains.

Sanctions & lawful business

Suppliers are expected to comply with applicable UK sanctions, export controls, anti-bribery, anti-corruption and other relevant trade restrictions. Raeburn may decline, suspend or end a supplier relationship where legal restrictions, ownership concerns or credible misconduct create unacceptable risk.

Environmental responsibility

Where proportionate to the purchase, suppliers should minimise unnecessary resource use, waste and emissions; favour durable, repairable or efficient options where commercially reasonable; and provide credible environmental information rather than unsupported green claims.

Accessibility & inclusion

Digital products and services should support accessible use where relevant, with recognised accessibility practices considered during selection and delivery. Suppliers should not knowingly introduce avoidable barriers for disabled users or personnel.

Confidentiality

Confidential information must be used only for the authorised purpose, shared only with people who need it, protected against unauthorised disclosure and returned, deleted or retained in accordance with agreed obligations. Confidential access never transfers ownership of client or Raeburn information.

Subprocessors & subcontractors

A supplier must be able to identify material subprocessors or subcontractors that handle relevant data or critical service functions when requested. Equivalent contractual, privacy, confidentiality and security obligations should flow down where appropriate. Material changes that alter risk should be communicated in accordance with the applicable agreement.

How supplier governance works

Proportionate due diligence

Supplier review reflects what is being bought, the data and systems involved, criticality, geography, legal obligations and realistic impact of failure.

Conflicts & incentives

Material referral fees, commissions, ownership interests or other incentives that could influence supplier selection should be disclosed and managed consistently with the Technology Independence Charter.

Evidence over badges

Certifications can support assurance but do not replace assessment of the actual service, contract, architecture, data handling and operating evidence.

Ongoing review

Material suppliers may be reassessed following significant service changes, incidents, ownership changes, regulatory developments or evidence that controls no longer meet the required risk level.

Remediation before exclusion

Where lawful and proportionate, Raeburn may seek a time-bound corrective action before ending a relationship. Serious illegality, sanctions exposure, deliberate deception or unacceptable security/privacy risk may justify immediate action.

Scope and accountability

Current suppliers have completed the applicable supplier review. This does not mean every supplier receives identical diligence: assessment depth is risk-based and evidence requirements increase for suppliers with sensitive data, privileged access, critical service dependencies or material subprocessor exposure. Contractual terms, applicable law and client-specific requirements may impose stricter obligations. Material exceptions should be documented and approved according to risk.

Published 27 August 2026. Supplier assurance status confirmed 27 August 2026. Review when material legal, supplier-risk or operating requirements change.