Record on site Works offline Finding becomes part of the file

Custom app development for supplier visits and supply chain signals

Due diligence is judged on what you did after you knew something. That knowledge rarely starts with a questionnaire; it usually starts during a visit: someone sees something on a factory floor, in a conversation or on site. What is recorded there, and whether it reaches the file, determines whether you can later show that you acted.

Why the visit is the weak link

Since Omnibus I, the due diligence obligation focuses on a company's own operations, subsidiaries and direct business partners, with investigation further along the chain only when there is plausible information about adverse impacts. Member States must transpose it by 26 July 2027, and the first group of companies must comply from 26 July 2028.

That wording puts the weight on signals. A questionnaire produces answers the supplier writes down himself; a visit produces observations he did not choose. Those observations are precisely what matters later, because they form the plausible information the directive refers to.

In practice they disappear. Someone drives to a factory, sees something that doesn't add up, makes a note in a notebook or takes a photo on their phone, and never gets it into the file when they get home. When accounting for it, that observation does not exist, even though the organisation did in fact make it. That is not ill will, but a lack of a place to put it.

How we build this

The visit is the unit here. If what was observed reaches the file at the moment itself, the rest of your due diligence process has something to build on.

1
Joining a visit

We look at how a visit currently runs, what gets written down and what is lost along the way. That shapes the design more than the legal framework does.

2
Keeping the visit structure light

A hundred-point questionnaire gets skipped on the way. We build a short structure with room for what doesn't fit the list, because that is usually where the finding lies.

3
Offline as the baseline

Factories outside the EU, sites without guest networks, roaming charges you'd rather not pay. The app works offline and syncs later.

4
Linking findings to follow-up

Every observation that needs attention automatically becomes a case with an owner and a deadline when you return. Without that link, it remains a note.

What the app does in practice

The app records what someone sees and makes sure it reaches the right place. Which components you need depends on how often and where you visit.

Visits with a short, fixed structure

A limited number of topics per visit, always with room for free observations. A checklist that is too long gets rushed through, and so delivers less than a short one.

Photo with time and place

A blocked emergency exit, unshielded storage, a shift schedule pinned to the wall. A timestamped image is more convincing as evidence than a description written afterwards.

A finding becomes a case straight away

What needs attention gets an owner and a deadline on the spot and lands in the same file as the enquiry. The guideline looks at what you did after you knew, and that starts here.

Fully offline operation

Visits continue without a connection and are synchronised later, with a clear indication per visit of whether that succeeded. Outside the EU, that is more the rule than the exception.

Sensitive signals handled separately

A report about working conditions can be traceable to a person. It goes into a separate stream with its own rights, kept apart from the regular visit report.

History per business partner

All visits to the same partner side by side, so you can see whether a finding recurs. One observation is an incident; the same observation three times is a pattern.

Who we build for

Who carries out the visit differs greatly between organisations. Four situations.

Purchasing at production sites

Your buyer is already visiting for price and lead time. That same visit can serve the due diligence side, provided recording it takes no more than a few minutes.

Brand owners with shifting supply chains

With seasonal sourcing, locations change from collection to collection. A visit history per partner is then more valuable than an annual snapshot, because the partner may be gone next season.

Trade and distribution

You buy from parties that source themselves. Your observations at the direct supplier are what you have; what lies behind them only comes into view when a signal emerges from there.

External auditors and inspection bodies

If a third party carries out the visits, you want the findings in your own file and not only in their report. This resembles the approach in an inspection app, with a different assessment framework.

Not yet sure about a large project?

Test your idea first: a working prototype in 1 day

With OneDayBuild, we turn your idea into something tangible in one day for €1,150, so you can see whether further development is worth the investment. Decide to go ahead with the full build? Then we credit the full cost.

Explore OneDayBuild →

Technology and integrations

The app is the field side of your due diligence file, not a separate administration. What it records goes into the same register as the enquiry and the risk assessment.

React Native or native iOS and Android Offline storage with synchronisation Visit structure configurable per partner type Photo with time and location Finding with owner and deadline Separate flow for sensitive signals History per business partner Roles and permissions per user Integration with the due diligence register Integration with procurement or ERP Multilingual input for local staff Remote device management Audit logging per action Hosting in the EU

Why Appfront

Accountability is about what you did after knowing

That is why we link an observation directly to follow-up. A finding without an owner counts against you with supervisors rather than reassuring them.

The places that matter have no signal

We build offline as the starting point. An app that stalls on a factory site delivers nothing exactly where the observation is worth the most.

A signal about people is not an ordinary finding

Reports traceable to a person or a whistleblower receive stricter rights and separate follow-up.

One file, not a second version of reality

The app writes to the same register as the office side, via integrations. That side is on CSDDD software.

Security and privacy

On a device that travels abroad, the risks are different. A phone can be inspected at a border crossing, lost or left behind. That is why we limit what is stored offline on the device to the visits of the moment, and make sure a device can be disconnected remotely without bringing colleagues' work to a standstill.

The content also calls for discretion. Findings on working conditions can be traced back to individual employees of your supplier, and those people have no interest in their names appearing in your system. We therefore separate the observation from the source, give sensitive signals their own access model, and record who has viewed them. On the evidentiary side, the reverse applies: photo, timestamp and observer should be tamper-proof, because a report that has been updated afterwards proves nothing. How we handle security ourselves is set out in our information security policy; reports from outside come through our CVD policy.

Frequently asked questions about the supplier visit app

Since Omnibus I, the directive applies only to very large undertakings, so you are probably indeed not covered. Your customer may well be, and it will then ask you what you know about your own chain. Anyone who records their visits answers that question with observations rather than a statement.

The actions look similar, but the purpose is different. An audit tests against a standard and delivers a judgement; this records what someone observed, even where that falls outside any standard. It is precisely these free-form observations that constitute the plausible information the directive looks at.

That is the most important design requirement rather than an objection. If recording takes more than a few minutes, it won't happen, and you end up with a system with no content. We therefore keep the structure short and let the app fill in most of the details itself: partner, location, time and who was present.

Yes, that is the principle. Visits, photos and findings are stored locally and synchronised as soon as there is a connection, with each visit showing whether that succeeded. Without that, you miss exactly the visits that deliver the most value.

They can, and it often delivers more than visits from the Netherlands, because someone on the ground comes more frequently and speaks the language. Input can be multilingual, with fixed choices rather than free text wherever possible. You will, however, need to settle in advance who may see which findings.

It becomes a case with an owner and a deadline, in the same register as your questionnaires, so that follow-up is visible. That is exactly what counts when reporting: not that you found something, but what you did afterwards. The register side is covered under CSDDD software.

That is the other side of the same chain. If you receive a questionnaire from a large customer, you answer it from a register; see VSME software. This app concerns what you observe yourself at your own suppliers.

That depends on the number of visit types, whether multilingual input is needed and how demanding the offline functionality is. A visit with photos and a finding is usually quick to get working; the separate stream for sensitive signals and the integrations cost more. We give a reasoned estimate after the discovery phase.

Want to record visits that currently disappear?

Ask the buyer who was most recently at a supplier what caught their eye, and check where that was written down. That gap is what you miss when reporting. We build this as a standalone app and as part of a broader custom app development or custom software development project.

Edit content