← All posts Buyer insights

Supplier Diversity Reporting: What Auditors Actually Want to See

Most supplier diversity reports answer the question 'how much did we spend with diverse suppliers?' That's necessary but it's not what auditors are looking for. An auditor wants to know whether the number is real — and whether you can prove it.

The difference between a report that passes and one that doesn't usually comes down to three things: the source of the certification data, the currency of that data, and whether the spend classification is consistent.

Source: where did the certification come from?

A supplier saying they are minority-owned is not the same as a supplier being certified as minority-owned by NMSDC. Both can appear in your diversity numbers, but an auditor will want to know which is which.

There are three levels of assurance, and your report needs to distinguish between them clearly:

  • Certified — the supplier holds a current certification from a recognised certifying body (NMSDC, WBENC, SBA 8(a), NVBDC, NGLCC, etc.). You should be able to trace the certification to the body that issued it and confirm it hasn't expired.
  • Verified — a third party has confirmed the supplier's status through an independent check, but they don't hold a traditional certification. SupplierGateway's Enhanced Digital Certification (EDC) falls in this category — it's a verified credential that costs $25 a year and takes 15 minutes, which makes it accessible to small suppliers who can't afford or don't need a full NMSDC certification.
  • Self-declared — the supplier has stated their status but no external body has confirmed it. This is valid to include in your reporting, but it must be labelled clearly as self-declared. An auditor who finds self-declared classifications mixed in with certified spend without distinction will flag the entire report.

The fix is straightforward: every line in your report should carry its source. Not 'diverse supplier' but 'MBE — NMSDC certified, exp. 03/2027' or 'WBE — self-declared'. That level of traceability is what turns a diversity report from a summary into evidence.

Currency: is the data current?

A certification that expired six months ago is not a current certification. This sounds obvious, but it's the most common finding in diversity reporting audits — because most organisations check certifications at onboarding and never check them again.

Certifications expire. NMSDC certifications last one year. WBENC certifications last one year. SBA 8(a) programme participation is reviewed annually. A supplier who was certified when you onboarded them in 2023 may not be certified today, and any spend attributed to their diverse status after expiry is misreported.

The practical implication is that your diversity reporting system needs to know when every certification expires and either re-verify automatically or flag the gap. Running a year-end diversity report against a static database of certifications that were loaded at various points over the past five years will produce a number, but it won't produce a defensible one.

Continuous monitoring — checking certification status on an ongoing basis rather than at a point in time — is what separates a report that stands up from one that doesn't. It's also what lets you catch lapses before they affect your numbers, rather than discovering them at year-end when it's too late to fix.

Consistency: is the same supplier classified the same way everywhere?

A supplier can be minority-owned (MBE), woman-owned (WBE), and small business (SB) simultaneously. How you count them matters — and it needs to be consistent.

If you count the same supplier's spend in all three categories, your total diverse spend will be higher than if you use a primary-classification approach. Neither is wrong, but the method needs to be documented and applied consistently. An auditor who finds one division counting a supplier as MBE and another counting the same supplier as WBE will question the entire methodology.

The standard practice is to report at the classification level (how much spend with MBE suppliers, how much with WBE, etc.) and at the unique-supplier level (how much total spend with any diverse supplier, de-duplicated). Both numbers are useful; the second is the one that matters for programme targets.

Whatever method you choose, it needs to be documented in the report methodology section, applied uniformly across all business units, and consistent from year to year. Changing the counting method between reporting periods without disclosing the change is the fastest way to trigger a full review.

What a defensible report looks like

A report that passes an audit without findings has five characteristics:

  • Every diverse supplier in the report has a named certification source — certified body, EDC, or self-declared — and the source is visible on every line.
  • Every certification has a current expiry date, and the report excludes or flags any spend attributed to expired certifications.
  • The classification methodology is documented — how overlapping categories are handled, whether spend is counted once or multiple times, and whether the method changed from the prior period.
  • Tier-1 and tier-2 spend are separated, with tier-2 clearly labelled as reported by the prime contractor rather than verified independently.
  • The report can be reproduced — meaning someone other than the person who created it can run it again and get the same numbers, because the data, filters, and methodology are recorded rather than ad hoc.

Most organisations that fail an audit fail on reproducibility. The report was built in a spreadsheet by one person who knew which tabs to pull, which columns to filter, and which suppliers to exclude. When that person moves on, the methodology moves with them.

Getting there

If your current reporting doesn't meet these standards, the gap is usually in the data layer rather than the reporting tool. You can't report what you don't track, and you can't audit what isn't sourced.

Data enrichment — matching your supplier records against certified databases and flagging the source and expiry of every classification — is the first step. It doesn't change your spend; it changes what you can prove about your spend. That's the difference between a diversity programme and a diversity report.

See Supplier Impact reporting