The King V Supplier Practice Map
The 14 King V recommended practices your board now discloses against - and whether you could evidence them today.
King V has no supplier principle. What it has instead is fourteen recommended practices whose evidence sits substantially in your supply base - and a Disclosure Framework that asks your governing body to state, publicly, whether it is satisfied. Answer for the reporting period, not for today.
The period matters more than the practice. King V disclosure applies to financial years commencing on or after 1 January 2026, and covers a full reporting period. A control you introduced last month does not evidence the ten months before it - so "we do this now" is a Point-in-time only answer, not a Yes.
Ethics and corporate citizenship
Practice RP12
Can you evidence active screening of your supply base for fraud, corruption and money-laundering risk across the whole reporting period?
Obliges the governing body to approve programmes for the prevention and detection of corruption, fraud and money laundering.
Practice RP13
Do your suppliers have documented access to your ethics code - and is your ethics standard applied and recorded at the point of sourcing?
Obliges application of the organisation's ethics standards to “the sourcing of suppliers”, and supplier access to ethics codes, embedded through induction and awareness.
Practice RP18
Do you hold measures and targets covering your supply base across Workplace, Economy, Society and Environment?
Obliges oversight of the direct and indirect consequences of activities and outputs, “including ensuring measures and targets in all of the following areas” - all four.
Strategy, impact and reporting
Practice RP20
Does your strategy process appraise the availability, quality and affordability of your supply base as a strategic risk?
Obliges appraisal of the resources and relationships the organisation uses and affects, and how these pose risks and opportunities for strategy formulation.
Practice RP22
Do you continually assess and respond to the negative impacts of your activities across the value chain?
Obliges the organisation to continually assess, and responsibly respond to, negative impacts on the resources and relationships it uses and affects.
Practice RP26
Does your sustainability reporting cover impact materiality - your effects on stakeholders and context - and not only financial materiality?
King V explicitly endorses double materiality: matters affecting the organisation financially, and its significant actual or expected impacts on stakeholders and on its economic, social and environmental context.
Risk and compliance
Practice RP93
Does your enterprise risk assessment include supplier concentration, single-source dependency and continuity exposure?
Obliges risk assessment covering risks arising from the economic, social and environmental context, and business continuity arrangements allowing organisational resilience.
Practice RP97
Have you specified which non-binding rules, codes and standards you adopt - and do you know which of them bind your suppliers?
Obliges the governing body to approve compliance policies “including specifying which non-binding rules, codes and standards the organisation adopts”.
Practice RP98
Is supplier regulatory status monitored continuously and integrated into your compliance system?
Obliges oversight of compliance execution, integration of compliance into the organisation-wide risk management system, and monitoring of the regulatory environment.
Data, technology and cyber
Practice RP103
Do you know which suppliers process personal information on your behalf, and in which jurisdictions?
Obliges effective management of data and information risk “when using outsourced services, suppliers and third parties, including across jurisdictions”.
Practice RP108
Have you set minimum assurance requirements for your service providers' controls over significant risks - before onboarding them?
Obliges management of outsourced-technology risk “including having minimum requirements for assurance to be provided by the service provider with respect to the effectiveness of the controls over significant risks”.
Assurance, stakeholders and group
Practice RP121-123
Does your combined assurance model cover third-party risk as a named line, rather than by implication?
Obliges a combined assurance model incorporating line management, specialist functions, internal and external audit, regulatory inspectors and specialist service providers, covering the organisation's significant risks.
Practice RP135
Are suppliers identified and managed as stakeholders, with dispute-resolution mechanisms in place?
Obliges methodologies to identify stakeholders who significantly affect or are significantly affected by the organisation, analysis of the resulting risks, and dispute resolution mechanisms to preserve relationships.
Practice RP149
Does one supplier governance standard apply across your group, adopted by each subsidiary's governing body?
Obliges a group governance framework, considered and approved by the governing bodies of the subsidiaries too, since each is a separate juristic entity to which its own members owe duties.
B1SA - B1LINKv2.1
