Skip to content

Commit 15eb832

Browse files
committed
Update openchain-standards-model-provisions.0.5.md
Aligning this with Carlo's proposal for 0.4 - which I was slow to merge here. See his original pull request here: #51
1 parent 2c1623f commit 15eb832

File tree

1 file changed

+40
-0
lines changed

1 file changed

+40
-0
lines changed

Adoption-Preparation/Model-Provisions/openchain-standards-model-provisions.0.5.md

Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -242,3 +242,43 @@ None.
242242

243243
The Customer requires clarity regarding the type of certification that the Supplier has undergone to contextualize their risk. A Customer may regard third-party certification as preferable due to the inherent audit involved. Alternatively, a Customer may be satisfied that self-certification is sufficient given that OpenChain ISO/IEC 5230:2000 or ISO/IEC DIS 18974 both require the party with a conformant program to maintain documentation on how they accomplished their conformance.
244244

245+
### Issue - Risk that the Declaration is just pro-forma, how to verify?
246+
247+
#### Commentary 
248+
249+
None listed.
250+
251+
#### Who is best placed to bear risk? 
252+
253+
Supplier
254+
255+
#### Best mechanism to tackle risk 
256+
257+
Audit rights
258+
259+
#### Sample Wording 
260+
261+
Customer may request that an audit be carried out to verify compliance to ISO/IEC 5230:2000 by a Third party auditor (**"Audit"**) that shall be approved by Supplier and such approval shall not be unreasonably withheld.
262+
263+
The Audit is subject to the following conditions:
264+
265+
a. it must only concern Supplier's OpenChain-related material, processes, policies and other relevant Artefact as provided for by ISO/IEC 5230:2000 that are used to demonstrate compliance.
266+
a. the auditor shall undertake a formal non disclosure agreement if it was not bound to professional secrecy by operation of the law;
267+
a. it must be carried out no more than once a year;
268+
a. it must come with an adequate advance notice, in no case less than 5 business days, and may be carried out during normal working hours, without interrupting the continuity of Supplier's activities or causing Supplier excessive burden and inconvenience, and in compliance with Supplier's safety policies;
269+
a. Customer shall bear all expenses arising out of or in connection with Audits at Supplier's premises, unless such Audits reveal that Supplier is not acting in compliance ISO/IEC 5230:2000, in which case all expenses shall be borne by Supplier. Customer may prepare an audit report summarizing the results and observations of the Audits (**"Audit Report"**);
270+
a. If at all possible, the Audit shall be documental, but the auditor may interview personnel of the Supplier to verify the level of compliance.
271+
272+
Audit Reports are confidential information of Supplier and Customer undertakes not to disclose them to third parties, with the exception of its own consultants, including legal consultants and its own employees.
273+
274+
Supplier can respond to a request to carry out an audit by handing over a recent Audit Report performed by a reputable third part; such handing over may carry reasonably confidentiality conditions. A recent Audit Report is a report that was formed no more than 10 months prior to the request to carry over the audit. Customer shall not unreasonably refuse to accept such Audit Report *in lieu* of a full audit, but can demand to carry over an audit on areas which have not been accurately described or which have not been covered by the Audit Report.
275+
276+
[in case Supplier is self-certified] Supplier may retain the auditor for becoming third-party certified or to renew third-party certification, but any such request may not be made earlier than one calendar month after the Audit Report has been delivered.
277+
278+
#### Supplier's Arguments 
279+
280+
Cost and complication of an audit process, confidentiality.
281+
282+
#### Customer's Arguments 
283+
284+
Costs are borne mainly by Customer, confidentiality is tackled by NDA and the process is run by a third party, frequency is limited and the audit can be done by showing a reliable audit done by a reputable third party.

0 commit comments

Comments
 (0)