Supplier Compliance

The Compliance Loop That Ran Over Email Now Runs Inside the Platform.

Enterprise SaaSGovernanceAI Workflows
Supplier Compliance

Role

Lead Product Designer — IC

Product

B2B SaaS — Supply Chain Compliance Platform

Duration

Jan 2024 – Present · 18 months

Team

Cross-functional — Product, Engineering, Compliance

Executive Summary

Compliance is a mission-critical process in fashion. Global brands need to prove that every tier of their supply chain meets environmental, labour, and legal standards — across EUDR, UFLPA, and multi-jurisdictional due diligence obligations. Before this system existed, brands ran compliance audits and sent findings via unstructured email. Suppliers received PDFs with dozens of nonconformities, no clear priority order, and no deadline visibility. Brands lost sight of closure status the moment the email left the outbox.

The result was a platform that processes 1,500+ audit requests per month across 500+ global fashion brands — transforming unstructured compliance work into a traceable, escalable, and exportable system directly connected to the legal filings brands submit to customs authorities.

500+Global Fashion Brands
1.5kAudit Requests / Month
3xUsage Growth Post-Launch
5+Usability Improvements Per Release

Workflow

Five actors. Six phases. One loop that ends at customs clearance.
Five actors. Six phases. One loop that ends at customs clearance.

Problem

We have all the regular documents. There is up to 51 different parameters. Sometimes things go wrong — and when they do, we don't even get a clear question. Just a PDF.

Supplier Operations Lead, Southeast Asia

Fashion brands operating under EUDR, UFLPA, and multi-jurisdictional regulatory frameworks must prove every supplier is compliant — with traceable, audit-ready evidence that holds up under customs scrutiny. The Due Diligence Statements filed with EU TRACES before market entry, and the chain-of-custody evidence required under UFLPA to prevent shipment detentions at US customs — all of it depends on this system working precisely.

Before a unified system existed, corrective actions were managed over email — non-conformities flagged manually, remediation tracked in threads with no structured response format, no enforced deadlines, no audit trail. At enterprise scale, this produced compliance records that couldn't be exported, filed, or defended in a regulatory inquiry.

Field Research

Before building the supplier-facing experience, I visited a garment manufacturing facility in Tiruppur supplying Fortune 500 fashion brands. One or two people there were solely responsible for responding to brand compliance requests — going department to department, collecting certificates, safety records, and corrective evidence by hand. By the time everything was compiled, the brand's deadline had passed. The problem wasn't that suppliers were unresponsive. It was that sourcing compliance documentation is a genuine operational task — and no reminder email changes that. That insight shaped every decision that followed.

Constraints

1

Proprietary Data per Core Jurisdiction

Every brand runs compliance under its own regulatory profile — EUDR, UFLPA, German Supply Chain Act. The system had to support brand-level configuration without fracturing the shared data model. A change in one brand's scoring logic could not silently affect another's risk threshold.

2

Non-Party Consolidation Under Legal Process

Suppliers receive audit requests from multiple brands simultaneously — each with different timelines, evidence requirements, and CAP structures. The supplier view had to consolidate cross-brand obligations without exposing one brand's compliance strategy to another.

3

Partial Manufacturer in a Non-Linear Process

Facilities are not always the entity legally accountable for compliance. A tier-2 supplier may produce a component that feeds into a tier-1 manufacturer's finished good. The system had to track compliance at facility level while rolling up risk at the brand's sourcing level.

Decisions

01Architectural Decision

Designing CAP as a Platform-Level Remediation Engine, Not an Audit Feature

When corrective action was first scoped, the plan was to build it as an audit output only — ship for audits first, expand later. The risk I saw: every compliance module that surfaces a risk signal would eventually need its own remediation path if CAP was built around a single trigger. That means rebuilding the same logic three times as the platform grew.

I called a meeting with engineering. I laid out the long-term cost — if we build CAP for audits only, every module that surfaces a risk will eventually need its own remediation path. I explained what generic meant in practice: one lifecycle, one role model, one CAPA structure — regardless of what triggered it. We agreed to ship a constrained MVP first, limited configurability, no advanced customisation. That MVP proved the concept. Assessment-triggered CAP came later, without a rebuild.

The model was later extended to support progressive CAP closure — suppliers submitting remediation evidence item by item — and bulk closure for brand teams. Both extensions required no structural changes because the foundation was generic from day one.

Tradeoff:

Gain → Every future module gets remediation built in — no rebuild needed as the platform grows

Cost → Constrained MVP at launch — limited configurability until the foundation proved itself

CAP built as a platform primitive — any compliance signal triggers one generic remediation lifecycle.
CAP built as a platform primitive — any compliance signal triggers one generic remediation lifecycle.

02System Design Decisions

Enforcing One Role Model Consistently Across All Three Modules

Brand's posture is fixed across the entire system: configure the request, send it, review the response, request revision, read the compliance score. Supplier's posture is equally fixed: receive the request, source the evidence, submit with documentation. Whether the context is a third-party facility audit, a structured regulatory assessment, or a corrective action cycle — the mental model doesn't change.

Maintaining that consistency required resisting module-specific shortcuts at every build phase. Fragmented interaction patterns at this scale would mean users relearning the workflow every time a new compliance trigger was introduced — and a unified per-supplier compliance view becoming significantly harder to build.

Tradeoff:

Gain → Users never relearn the workflow — same mental model across every compliance trigger

Cost → Module-specific shortcuts refused — consistency took priority over speed in some interactions

Brand sends and reviews. Supplier responds and submits. The same posture across every module.
Brand sends and reviews. Supplier responds and submits. The same posture across every module.

03AI Integration Decision

Embedding AI at the Five Points Where Manual Effort Creates Compliance Risk

The factory visit research showed that manual documentation effort was the primary source of delay and error. AI had a specific role — but only at the right decision points. The design challenge wasn't adding AI features. It was deciding where AI reduces genuine compliance risk without creating a different risk: users accepting AI output without exercising the judgment that carries legal accountability.

Design principle across all five: AI assists at each decision point. The brand reviewer approves. The distinction between assistance and accountability is visible in the interface at every step — because the output is a legal document.

Tradeoff:

Gain → Manual effort reduced at every high-risk decision point in the compliance cycle

Cost → Each AI point required explicit UI design to keep the assist/approve distinction visible — not just functional

1

Assessment Response Assistance

AI helps suppliers fill assessment fields correctly against regulatory standards — reducing incomplete submissions before they become nonconformities.

2

Nonconformity Detection

AI analyses supplier responses against brand and regulatory standards, surfacing gaps for auditor review instead of manual field-by-field comparison.

3

CAP Recommendation

When a nonconformity is raised, AI suggests a standard corrective action based on the finding type and regulation — giving the supplier a structured starting point.

4

Evidence Verification

When a supplier submits remediation proof, AI checks it against the CAP requirement and provides a confidence signal. The brand reviewer makes the final approval.

5

Compliance Report Assembly

Once all CAPs are closed and scores finalised, AI assembles the structured compliance data into a report-ready format for regulatory filing and DDS submission to customs authorities.

Key Screens

All evidence assembled, scored, and filed. The compliance loop closes with a customs-ready DDS.
All evidence assembled, scored, and filed. The compliance loop closes with a customs-ready DDS.
Brand configures and assigns a facility audit to a third-party auditing firm in under a minute.
Brand configures and assigns a facility audit to a third-party auditing firm in under a minute.
Three-tier score history — original, overridden, and post-CAP — traceable at every stage.
Three-tier score history — original, overridden, and post-CAP — traceable at every stage.
AI suggests, extracts, and verifies. The supplier decides. Legal accountability stays with the human.
AI suggests, extracts, and verifies. The supplier decides. Legal accountability stays with the human.
One request carries every nonconformity, legal recommendation, and deadline. No email required.
One request carries every nonconformity, legal recommendation, and deadline. No email required.
Supplier remediates item by item, progressively. Score updates as each CAPA closes.
Supplier remediates item by item, progressively. Score updates as each CAPA closes.

Outcome

The compliance loop that previously ran over unstructured email now runs entirely inside the platform — traceable, exportable, and directly connected to the regulatory filings brands submit to customs authorities.

The platform processes 1,500+ audit requests per month across 500+ global fashion brands at launch — with usage growing 3× within months. Fortune 500 sportswear companies, global luxury groups, and multi-brand fashion retailers run supplier compliance covering EUDR, UFLPA, and multi-jurisdictional obligations within a single workflow.

Assessment-triggered CAP is now live. One request carries all nonconformities, all legal guidance, and the complete remediation structure. Suppliers submit progressively as they complete each corrective action. Scores update as closures are confirmed. The record is traceable and directly connected to the legal filings brands submit to customs authorities.

60% of suppliers respond within the expected cycle. The remaining 40% reflects the structural challenge of sourcing regulatory documentation at facility level — a constraint the progressive CAP model was explicitly designed to accommodate, not ignore. Each release has shipped 5+ usability improvements driven directly by field research and user feedback.

Reflection

What Worked

  • Building CAP as a generic engine from day one. When the team needed to extend it to assessments, no rebuild was required. The architecture decision paid off exactly as argued.
  • The consistent role model across all three modules. Brand and supplier users didn't need to relearn the workflow as new compliance triggers were introduced.
  • Field research before designing the supplier experience. The Tiruppur visit completely reframed the problem from "suppliers not responding" to "documentation sourcing is genuinely hard." Every subsequent design decision improved because of that reframing.

What I'd Approach Differently

  • Push AI evidence verification into the audit workflow earlier. The same documentation sourcing problem from the factory visit applies to audit responses too. The field research signal was strong enough to justify both surfaces simultaneously.
  • Establish a unified supplier compliance health indicator earlier. Audit scores and assessment scores are brand-configured independently — right for flexibility, wrong for the compliance officer who needs a single health signal per supplier, not two scores to reconcile manually.

Supplier compliance is still evolving — EUDR delegated acts land in 2027, UFLPA enforcement is tightening, and every new regulation creates a new configuration requirement. The architecture decisions made here were designed to absorb that change. That was the point.


© 2026 Gopalchandru Krishnan. All rights reserved.