Criterion: KYC and Supplier Due Diligence

Version 1.0.0 | Status: Active
UN conformity topic code:

KYC processes for suppliers and high-risk sources, including identity, relationship, legality, ownership / beneficial...

Full Description

KYC and Supplier Due Diligence

Criterion ID: AM10-KYC-and-Supplier-Due-Diligence Category: Risk Management

Description

KYC processes for suppliers and high-risk sources, including identity, relationship, legality, ownership / beneficial ownership, sanctions screening, upstream actor information, and consistent implementation.

Assessment Coverage

Assessors evaluate the facility's Know Your Counterparty (KYC) processes for immediate suppliers, covering identity verification, business type, legality of operations, ownership and beneficial ownership disclosure, and sanctions screening. Questions also examine collection and retention of upstream actor information, consistent KYC implementation, and — where high-risk sourcing is identified — the scope of actors included in enhanced KYC and evidence of consistent application across high-risk supply chains.

Conformance Claim

Conformance with this criterion indicates that the facility has implemented a Know Your Counterparty process for immediate suppliers and, where applicable, has extended KYC processes to additional upstream actors.

Profiles using this criterion
Conformity Alignment

Conform

Pass: Yes
Definition: "The facility is conformant with a requirement if no non-conformances are identified - i.e., significant deviations from the Standard requirements or the Assessment Criteria. "

Conform Continual Improvement

Pass: Yes
Definition: "The facility has developed the required policy, procedure, or process but has only partially completed its implementation. The facility must formally acknowledge that not all due diligence has been completed and provide a plan or road map for full implementation. Outstanding items must be resolved within the following assessment period. "

Conform Observation

Pass: Yes
Definition: "The assessor notes information that does not constitute a non-conformance, including limitations encountered during the assessment, unique aspects of facility operations, or other relevant feedback. Non-conformances addressed during the on-site assessment are reclassified to this level in the final report. "

Non Conform

Pass: No
Definition: "The facility's systems, processes, and practices deviate from the Standard requirements or the Assessment Criteria. Deviations are substantive gaps in policy, process, or implementation that constitute a non-conformance as supported by sufficient and appropriate assessment evidence. "

Zero Tolerance

Pass: No
Definition: "A zero-tolerance situation exists where access to the facility, documentation, or key personnel is denied; any bribe or gift is offered to the assessor; documentation has been falsified; the facility deliberately misrepresents facts through deception, coercion, or interference; or any other action or absence thereof risks the credibility or integrity of the RMAP system. The assessor stops the assessment immediately and notifies RMI. "

Not Applicable

Pass: No
Definition: "The criterion or assessment activity does not apply to the facility based on its operations, sourcing profile, or assessor determination of applicability conditions. "

Change Log

1.0.0 (2026-07-03)

Initial release.