BuildWrightFor Builders
ServicesPricingResourcesPartners

BuildWright Consultants

Your virtual compliance team for early-stage businesses across India: incorporation, licenses, documentation, and dispute resolution.

Services

  • Incorporation
  • Licenses & registrations
  • Documentation
  • Dispute resolution
  • Monthly plans

Company

  • Blog
  • Resources
  • Tools
  • Partners
  • For Advisers
  • For Freelancers
  • Privacy Policy
  • Terms of Use

Get in touch

  • Free consultation
  • WhatsApp
  • Client login

BuildWright Consultants is a virtual compliance team. We do not provide advocacy or litigation representation.

Your data is encrypted in transit and at rest on Google Cloud infrastructure. We never sell it. See our privacy policy.

© 2026 BuildWright Consultants. All rights reserved.

HomeDocumentationVendor Onboarding Policy Pack

Documentation

Vendor Onboarding Policy Pack

When a larger customer's vendor onboarding checklist asks for a code of conduct, an anti-bribery policy, or a confidentiality policy, that's a contract requirement from them, not an Indian statutory duty on you. We draft the actual policies your customer's checklist is asking for, matched to what they've requested rather than a generic pack.

When a larger customer's vendor onboarding checklist asks for a code of conduct, an anti-bribery policy, or a confidentiality policy, that's a contract requirement they've set. Indian law doesn't put it on you. We draft the actual policies your customer's checklist is asking for.

Enterprise customers put policy documents on their vendor onboarding checklist before they'll sign you as a supplier. None of it is Indian law reaching down to your company. It's a condition of the contract, set by whoever runs their procurement process.

We read a large manufacturer's supplier code of conduct in full to see what this actually looks like in practice: three pages, sign-and-return, covering a defined set of areas.

Scope

What's included

  • The most commonly recurring item across the vendor checklists we reviewed.

  • Consistently the second most common ask. Some enterprise checklists cite the Prevention of Corruption Act, the FCPA, and the UK Bribery Act specifically.

  • Third on the recurrence list, and one of the areas the supplier code we reviewed covered directly.

  • Fourth on the list.

  • Fifth.

  • Framed as asset protection where the checklist reads like a manufacturing supplier code, or as formal information security where it's an IT or services checklist. Where you already have DPDP documentation in place through BuildWright, this draws on it rather than duplicating it.

Specifics

The details

This is a customer ask

None of the six policies in this pack are Indian statutory requirements on a company your size. They're what a larger customer's procurement or supply-chain team puts on a vendor onboarding checklist. The checklist is theirs. The government isn't running it.

What one real supplier code actually asked for

We read Tata Motors' Supplier Code of Conduct in full. It runs three pages, sign-and-return, and covers product and service quality, regulatory compliance, bribery and corruption, human rights (no child labour, no forced labour), gifts and hospitality, health and safety, environment, conflict of interest, third-party representation and confidentiality, protecting company assets, and a whistleblower channel for reporting violations.

It notably didn't ask for an information-security policy, a business continuity plan, or a diversity policy, three things a lot of teams assume are standard vendor asks. Business continuity plans tend to show up on IT and services vendor checklists specifically. They're rarely a default. Diversity policies had the weakest evidence behind them across what we reviewed, so we don't build one in unless your specific checklist names it.

Confidentiality and data protection: where this meets your DPDP work

The confidentiality item on most checklists doubles as a data protection ask, especially from IT and services customers. If you've already built out DPDP documentation with BuildWright, we draft this policy to sit on top of that work rather than starting a second, disconnected version of the same commitments.

Process

How it works

Step 1 of 4

Send us the checklist

If your customer sent one, we draft against the actual list rather than a generic pack.

Send us the checklist

If your customer sent one, we draft against the actual list rather than a generic pack.

Common mistakes founders make

  • Treating the request as an Indian legal filing instead of a contract requirement your customer set.
  • Building a business continuity plan or a diversity policy nobody asked for, while missing something the checklist actually names.
  • Drafting a confidentiality policy that duplicates DPDP documentation you already have, instead of building on it.
  • Sending back a generic downloaded template instead of one matched to the actual checklist.

Clarifications

Frequently asked questions

No. Indian law doesn't require them at your size. This is a contract condition your customer's onboarding process sets.

Only if you're being onboarded as an IT or services vendor. It shows up on those checklists specifically, and we haven't seen it as a default ask elsewhere.

The weakest and least common item across what we reviewed. We only build one in if your specific checklist names it, rather than adding it by default.

The supplier code we read in full ran three pages, sign-and-return. We match your customer's expected format rather than producing a lengthy standalone manual.

Related

Learn more

Prefer to skip the paperwork?

BuildWright can take this off your plate — done properly, the first time.

Ready to get started?

Tell us about your partners and business and we'll take it from there.

Get a Quote

Skip the hassle — have us do it for you. We do it best.

  • The journey
  • What's included
  • The details
  • How it works
  • FAQ
  • Learn more
  • Pricing

Key terms

Vendor onboarding checklist
The list of policy documents and commitments an enterprise customer's procurement or supply-chain team requires before signing a new supplier.
Sign-and-return document
A short policy or code the vendor signs and returns as part of onboarding, rather than a lengthy standalone manual.