You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: Adoption-Preparation/Model-Provisions/openchain-standards-model-provisions.0.5.md
+40Lines changed: 40 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -242,3 +242,43 @@ None.
242
242
243
243
The Customer requires clarity regarding the type of certification that the Supplier has undergone to contextualize their risk. A Customer may regard third-party certification as preferable due to the inherent audit involved. Alternatively, a Customer may be satisfied that self-certification is sufficient given that OpenChain ISO/IEC 5230:2000 or ISO/IEC DIS 18974 both require the party with a conformant program to maintain documentation on how they accomplished their conformance.
244
244
245
+
### Issue - Risk that the Declaration is just pro-forma, how to verify?
246
+
247
+
#### Commentary
248
+
249
+
None listed.
250
+
251
+
#### Who is best placed to bear risk?
252
+
253
+
Supplier
254
+
255
+
#### Best mechanism to tackle risk
256
+
257
+
Audit rights
258
+
259
+
#### Sample Wording
260
+
261
+
Customer may request that an audit be carried out to verify compliance to ISO/IEC 5230:2000 by a Third party auditor (**"Audit"**) that shall be approved by Supplier and such approval shall not be unreasonably withheld.
262
+
263
+
The Audit is subject to the following conditions:
264
+
265
+
a. it must only concern Supplier's OpenChain-related material, processes, policies and other relevant Artefact as provided for by ISO/IEC 5230:2000 that are used to demonstrate compliance.
266
+
a. the auditor shall undertake a formal non disclosure agreement if it was not bound to professional secrecy by operation of the law;
267
+
a. it must be carried out no more than once a year;
268
+
a. it must come with an adequate advance notice, in no case less than 5 business days, and may be carried out during normal working hours, without interrupting the continuity of Supplier's activities or causing Supplier excessive burden and inconvenience, and in compliance with Supplier's safety policies;
269
+
a. Customer shall bear all expenses arising out of or in connection with Audits at Supplier's premises, unless such Audits reveal that Supplier is not acting in compliance ISO/IEC 5230:2000, in which case all expenses shall be borne by Supplier. Customer may prepare an audit report summarizing the results and observations of the Audits (**"Audit Report"**);
270
+
a. If at all possible, the Audit shall be documental, but the auditor may interview personnel of the Supplier to verify the level of compliance.
271
+
272
+
Audit Reports are confidential information of Supplier and Customer undertakes not to disclose them to third parties, with the exception of its own consultants, including legal consultants and its own employees.
273
+
274
+
Supplier can respond to a request to carry out an audit by handing over a recent Audit Report performed by a reputable third part; such handing over may carry reasonably confidentiality conditions. A recent Audit Report is a report that was formed no more than 10 months prior to the request to carry over the audit. Customer shall not unreasonably refuse to accept such Audit Report *in lieu* of a full audit, but can demand to carry over an audit on areas which have not been accurately described or which have not been covered by the Audit Report.
275
+
276
+
[in case Supplier is self-certified] Supplier may retain the auditor for becoming third-party certified or to renew third-party certification, but any such request may not be made earlier than one calendar month after the Audit Report has been delivered.
277
+
278
+
#### Supplier's Arguments
279
+
280
+
Cost and complication of an audit process, confidentiality.
281
+
282
+
#### Customer's Arguments
283
+
284
+
Costs are borne mainly by Customer, confidentiality is tackled by NDA and the process is run by a third party, frequency is limited and the audit can be done by showing a reliable audit done by a reputable third party.
0 commit comments