Problems & solutions · Supply Chain

Supply Chain Due Diligence Software Problems: The 7 That Break Your Evidence Trail, and How to Avoid Them

Supply Chain DUE Diligence Software workflow illustration showing common problems and fixes.
The short answer

The most expensive failure in due diligence software is performing assessment against the vendor master, which is a payment construct rather than a risk one. A campaigning organisation names a specific facility on a Wednesday, the board wants an answer by Friday, and the file contains a questionnaire completed nineteen months ago by that supplier's head office, a code of conduct acknowledgement and an audit report the supplier provided themselves. None of it describes the facility named, because the entity has eleven sites in four countries, and nobody can say whether the company buys from that plant at all. The cost is a public position taken without evidence, and every subsequent statement inherits that weakness.

Why does due diligence get scoped as a survey campaign?

Most programmes begin with a distribution problem. We need to reach nine hundred suppliers, collect a questionnaire, chase the non responders, and report a completion percentage. So the project gets scoped as a survey engine with a supplier portal attached, and the measure of success becomes response rate.

Response rate is not the obligation. Statutory human rights and environmental due diligence duties, whether under the German supply chain act, the corporate sustainability due diligence directive as it lands in member state law, or import controls that place the burden of proof on the importer, are not satisfied by having asked a question. They are satisfied by risk based prioritisation, action proportionate to the risk, evidence that the action happened, and documentation you can hand to an authority. A completed questionnaire is a claim, and a programme built to collect claims produces a folder nobody can trace to a specific site.

The fix is to change the acceptance test before any form is designed. From a single site identifier, the system must show whether you buy from it and how much, the risk band it sits in and why, the assessments performed with the evidence attached and its validity dates, the corrective actions open and closed with owners, and the escalation history. If the first release can answer that for one site in under a minute, everything else in the programme has something to attach to. If it cannot, the survey engine has bought you completion statistics and no defence.

What goes wrong when supplier hierarchy and assessment history are migrated?

The vendor master is a list of legal entities with bank details, and risk does not live there. It lives at the factory, the farm, the smelter, the mine, the recruitment agency. One vendor may supply from six sites with completely different profiles, and the site with the problem is rarely the one whose head office signed your code of conduct.

Migration exposes this immediately and painfully. Historical assessments are attached to entities, so re-attaching them to sites requires a judgement about which facility was actually assessed, and the audit report often names a plant that appears nowhere in your records. Group structures change over the period you are migrating: acquisitions, divestments, renamed subsidiaries and joint ventures that were once wholly owned. Assessments performed under a superseded methodology have to remain readable under the model that applied at the time.

The fix is to model supplier group, legal entity, site and commodity as separate objects, then bind them to your own purchase order and receipt history so exposure is calculated rather than asserted. During migration, build a site register with alias and address history before attaching anything, and route unresolvable facilities to a review queue rather than to a default parent. Keep effective dates on every relationship so an ownership change does not silently rewrite history. Sites you cannot place are a finding in themselves, because they represent assessments you paid for that describe somewhere you cannot identify.

Why do subscription platform and purchasing integrations break after launch?

You will keep EcoVadis, Sedex, IntegrityNext, Assent or Prewave as data sources, and those feeds drift for structural reasons rather than technical ones. Their refresh cycles are theirs, so a scorecard that looks current may be eighteen months old, and a system that displays it without an as at date invites a decision based on stale information. Their entity resolution is their own, so a supplier your team knows as one group arrives as three unmatched records. Adverse signal feeds match on names, and names in this domain are ambiguous across languages and transliterations.

The purchasing integration breaks differently. Large groups routinely run several purchasing systems after acquisitions, each with its own vendor numbering, and the spend figure that drives prioritisation is assembled from all of them.

The fixes are specific. Stamp every imported record with a source and an as at date, and show both wherever a score is displayed. Keep entity matching as a reviewable process with a queue rather than an automatic merge, because a wrong merge here attaches one site's findings to another company. Reconcile spend per purchasing system on a schedule. Then treat every adverse media hit as a candidate requiring human review, because an automated status change on a false match damages you in both directions.

What happens when evidence validity, grievance intake and reporting are not covered?

Three gaps turn a competent assessment tool into an indefensible one.

Evidence without validity is the first. A questionnaire answered yes is not evidence. The artefact is the wage register sample, the age verification procedure, the recruitment fee reimbursement policy, the third party audit report with its own scope and date, the closure photograph. Survey tools collect answers and do not manage a document with an expiry, a scope and a source, so certificates age quietly and the questionnaire still shows a ticked box.

Grievance intake is the second. Statutory schemes generally expect an accessible complaints procedure, and one bolted on later cannot feed risk rescoring or open a corrective action against the right site.

Reporting is the third. If evidence is spread across a subscription platform, a survey tool and email, the annual report is written by hand by someone reading everything, which is why it takes months and reads like it.

The fix is to make evidence a first class object attached to a control at a site, with a validity period, a source, an uploader and an immutable copy, so an expiring certificate changes the site status automatically. Design the grievance channel with legal from the start, covering anonymity, language accessibility, restricted access, retention and protection against retaliation. Then generate the report from the operational record, with every figure linking to the underlying records so an auditor clicks rather than asks.

Should you build custom or configure what you already own?

Some companies should subscribe and stop. If you have a few hundred direct suppliers, mostly in lower risk categories and jurisdictions, and your obligation today is a customer questionnaire rather than a statute, EcoVadis or Sedex plus a disciplined process is proportionate, and building would be an expensive way to feel serious. Prewave is genuinely useful for adverse signal detection, Assent is strong at collecting declarations and regulatory data at scale, and Sedex carries site level audit data in a way most tools do not.

Configuration is also underused. Many programmes send an identical assessment to every supplier regardless of category risk, which burns the supplier goodwill you will need when you ask for something difficult. Segmenting templates by commodity and country, and switching on corrective action tracking that your existing subscription already includes, removes a real part of the workload before any software is commissioned.

Build when two or more of these are true. You carry a statutory duty with enforcement exposure rather than a voluntary commitment. Your risk sits at site level and your vendor master cannot tell you which site fulfils an order. You operate in commodities with known forced labour exposure where the burden of proof falls on you. You need evidence and corrective action tracking with a defensible audit trail rather than scorecards. Or you already pay for two or three platforms and still assemble the annual report by hand, which is the clearest signal of all.

How do hidden costs get into the quote?

Digital Heroes delivery bands here are $85,000 to $170,000 over 12 to 18 weeks for a first release covering the supplier and site hierarchy bound to purchasing data, your own versioned risk model, assessment with evidence management and corrective action workflow, then $200,000 to $450,000 phased across 7 to 12 months for the full platform. Overruns come from work treated as an assumption.

  • Languages. A supplier portal that Chinese, Turkish, Vietnamese and Portuguese speaking factory staff can actually use is a localisation programme, not a translation file.
  • Grievance channel design. Confidentiality, access control, retention and hosting decisions need legal input and carry genuine ethical weight.
  • Fragmented purchasing systems. Each additional system is its own connector and its own vendor numbering reconciliation.
  • Risk methodology workshops. Agreeing factors, weights and thresholds needs sustainability, legal, procurement and often the audit committee in one room, repeatedly.
  • Subscription data synchronisation. Their refresh cycles, their entity model, your as at dates.
  • Assurance readiness. If an external assurer will review the report, the traceability they expect should be designed in rather than demonstrated afterwards.

Cost falls sharply if you start with the commodity categories and countries your own risk analysis already flags. Covering every supplier in year one is an expensive way to prove that most of your suppliers are boring.

What separates a build that works from one that fails here?

The programmes that hold up version their risk model. Factors, weights and thresholds carry effective dates, so a decision made two years ago renders under the model in force then while today's decisions use the current one. Every score displays as a derivation showing which factors contributed what. That is the difference between a number and a defence, and it is the first question worth asking any prospective developer, because a system that silently recalculates history has destroyed the evidence you built it to produce.

They are also honest about upstream visibility. No software solves beyond tier one outright, and cascading questionnaires fail predictably as response rates collapse at each level and responses remain unverifiable. What works is reasoning over partial signals together: declared chains where suppliers will disclose, chain of custody documents where a scheme exists, trade and shipment data where you have access, and enforcement or media signals mapped to named facilities, presented with a confidence level rather than false certainty. The gaps then drive commercial action, meaning contract clauses, disclosure requirements at renewal, and targeted verification where exposure is highest.

There is one place machine assistance clearly earns its keep, and it should be scoped explicitly: extracting issue dates, expiry dates, scope and issuing body from supplier documents in many languages and layouts, then flagging mismatches against what the supplier claimed. That processes documents nobody currently reads. Every extracted field still needs a human above the confidence threshold, and no model should change a supplier's status by itself.

Settle ownership before kickoff. You should own the repository, the infrastructure accounts and the right to hire anyone else, and at Digital Heroes the client owns the code from the first commit. Your due diligence record is legal evidence with a multi year retention expectation, and it must never sit somewhere you cannot take it.

Research & sources

The evidence behind this guide

Independent findings on why this investment pays off. Every link goes to the primary source.

  1. 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
  2. The federal government spends about 80% of its IT budget on operations and maintenance of existing systems rather than on development or modernization, with many critical systems being decades old. Source: U.S. Government Accountability Office (GAO) (2025) →
  3. McKinsey found that currently demonstrated technologies can fully automate about 42% of finance activities and mostly automate a further 19%, indicating roughly 60% of finance work is technically automatable. Source: McKinsey & Company (2018) →
  4. This World Bank report argues that digital technology adoption raises SME competitiveness, productivity and resilience, while documenting that smaller firms consistently lag larger ones in digital adoption - a gap that constrains their growth and market reach. Source: World Bank (2022) →
Kabir B. · Director of Mobile Engineering · Delhi

Kabir directs mobile engineering at Digital Heroes across iOS, Android and cross platform builds. Day to day that means release trains, store review cycles, device coverage and deciding when native work is worth the extra cost. Useful reading before committing to an app roadmap.

View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.

FAQ

Frequently asked questions

An allegation names one of our supplier's factories. Why can we not answer?
Because the assessment was performed against a legal entity and the entity operates several sites. Your questionnaire describes a head office, your purchase orders reference a vendor number, and the vendor number does not know which plant fulfils. Model supplier group, legal entity, site and commodity separately, bind sites to your purchase order and receipt history, and the two questions that matter in a crisis, do we buy from this facility and how much, become calculated rather than researched.
Why is a vendor supplied risk score not enough?
It is a reasonable input and a weak decision. A generic blend of country and sector indices plus supplier self reporting does not know your commercial influence, your contract terms, your purchasing volatility or your board's risk appetite. When an authority asks why a supplier was categorised low risk and therefore not assessed, pointing at a third party proprietary blend is a poor answer. Implement risk as an explicit model with named factors, weights, thresholds and version history that renders as a derivation.
What happens to past assessments if we change the risk methodology?
Nothing should be overwritten. The model needs effective dates so a decision made two years ago still renders under the model in force at the time, while current decisions use today's version. Regulators, auditors and litigation all look backwards, and a system that silently recalculates history destroys the evidence you built it to produce. Ask any prospective developer how they version scoring logic before you discuss screens or dashboards.
Can software give us real visibility beyond tier one?
Not outright, and any vendor claiming full multi tier visibility from cascading questionnaires is selling comfort. Response rates collapse at each level and responses are largely unverifiable. What works is combining partial signals, declared chains where suppliers disclose, chain of custody documents where a scheme exists, trade and shipment data where available, and enforcement or media signals mapped to named facilities, then presenting a confidence level and using the gaps to drive contract clauses and targeted verification.
How should supplier evidence be handled so it stays defensible?
As a first class object attached to a control at a site, carrying a validity period, a scope, a source, an uploader and an immutable copy. Assessments reference evidence rather than restating it, so an expiring certificate changes the site status automatically instead of aging quietly behind a ticked box. Ask specifically what happens when a document is superseded, because that behaviour tells you whether the system was designed for regulated evidence or for a questionnaire.
Where does machine learning actually help in due diligence?
One place clearly earns its keep: extracting issue dates, expiry dates, scope and issuing body from supplier documents arriving as photographs and files in many languages, then flagging documents that do not match what the supplier claimed. That processes thousands of documents nobody currently reads. Entity matching for adverse media also benefits, though every hit needs human review before it changes a supplier's status, since a false match damages you in both directions.
Do we need our own grievance channel, and can it sit in the same system?
Statutory schemes generally expect an accessible complaints procedure, and building it into the same platform lets a grievance trigger risk rescoring and a corrective action against the correct site. It also brings real obligations: anonymity, language accessibility, restricted access, retention limits and protection against retaliation. Treat it as its own design conversation with legal, and ideally with someone who has run a channel in practice, rather than as another form on the supplier portal.
We already pay for two platforms. Why would we build anything?
You probably should not, unless you are still assembling the annual report by hand, which is the clearest signal in this category. Subscriptions are strong data sources and weak systems of record: they cannot hold your thresholds, your escalation policy, your evidence with validity periods or your exposure by site. Most mature programmes end up hybrid, keeping the subscriptions as inputs and building the record layer that holds hierarchy, risk model, evidence, actions and reporting.
What should I prepare before contacting a software development agency?
A one-page brief beats a 40-page requirements document: the business problem in plain words, who will use the system, the 5 to 10 workflows it must handle, the tools it must connect to, and your budget range and deadline driver. You do not need wireframes, a specification, or technical vocabulary; producing those is the agency's job during discovery. Stating a budget range up front is the single best move, because it gets you honest scoping instead of a quote engineered to win the meeting.
What does it cost to maintain custom supply chain software each year?
Budget 15 to 20 percent of the original build cost per year, so roughly $9,000 to $12,000 annually on a $60,000 system, covering hosting management, dependency updates, bug fixes, and small enhancements. Across its maintenance contracts, Digital Heroes sees supply chain systems need more upkeep than typical web apps because carrier APIs, EDI specs, and ERP versions keep changing underneath them. Hosting itself is usually minor, often $100 to $500 per month for a mid-size operation.
How many people should be working on my software project?
Three to five for a typical focused build: a project lead, one or two engineers, a designer, and part-time QA, which is the standard shape across 2,000+ Digital Heroes projects. Larger platforms justify 6 to 10, but a ten-person team on a small first version usually signals bill padding rather than horsepower. What predicts success is whether a senior engineer is writing your code daily, not the headcount on the proposal.
Is custom software more secure than off-the-shelf SaaS?
Neither is secure by default; security tracks the practices of whoever builds and operates the system, not the model. SaaS gives you the vendor's certifications and patching but puts your data in a shared multi-tenant platform on their terms, while custom gives you full control over data residency, access rules, and compliance requirements like HIPAA, with the responsibility sitting with you and your agency. Before hiring anyone for a system holding sensitive data, ask for their security checklist: encryption at rest and in transit, an OWASP Top 10 review, role-based access, and a penetration test before launch.
Will custom software scale as we add warehouses, SKUs, and order volume?
Yes, if multi-location support and your target volumes are stated requirements at design time, because a schema built for one warehouse is expensive to retrofit for ten. A well-built system on PostgreSQL comfortably handles millions of SKUs and tens of thousands of orders per day on modest cloud hardware, so scaling cost shows up in hosting bills rather than rewrites. Give your agency the 3-year growth picture upfront even if phase one covers a single site.
How much should a small business budget for its first custom app or website?
For a focused first build, most small businesses land between $8,000 and $60,000: roughly $8,000 to $45,000 for a custom website and $25,000 to $60,000 for an internal tool or simple web app, based on Digital Heroes delivery across 2,000+ projects. Customer-facing products with payments, logins, or a mobile app start around $40,000. Quotes far below these bands usually mean a template with your logo on it, not software shaped around your workflow.
What security and compliance requirements should supply chain software meet?
At minimum: role-based access control, encryption in transit and at rest, audit logs on inventory and order changes, and tested backups, because the system holds supplier pricing and customer purchase history your competitors would love to see. If enterprise customers connect to it, expect security questionnaires and possibly SOC 2 expectations; food, pharma, and aerospace add traceability rules like FDA lot tracking or ITAR data handling. Raise these in the first scoping call, since retrofitting audit trails onto a live system costs far more than designing them in.
Will an app built for 10 users survive growing to 500?
Yes, if it is built on standard cloud infrastructure with a sound data model, because moving from 10 to 500 users is a hosting configuration change, not a rebuild. The scaling decisions that actually hurt are made early and invisibly: how the database is structured, how accounts and permissions are modeled, and whether background work is queued properly. Ask your agency how the system would handle ten times the load; the right answer is boring and specific, and a promise to cross that bridge later means you will pay for the bridge twice.
Who can build a custom supply chain software system?

Digital Heroes builds custom supply chain software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.

Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.

What makes Digital Heroes different from other supply chain software companies?

Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.

Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.

How can I check Digital Heroes is legitimate before getting in touch?

Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.

Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.

Keep reading
let's build

Build something worth launching.

A plan, a team, a timeline, within 24 hours. No decks, no discovery calls. Tell us what you're building and we'll come back with a real scope and a real number.

message us directly · we reply within one business day

mission briefing

Monthly dispatch

Playbooks, real build costs, and what we're shipping. One email a month. No fluff.

visit us

New York HQ

1140 Broadway, Suite 704 · New York, NY 10001

Get directions
Online now

Hey there 👋 How can we help you today?