When nobody noticed. Designing for the gaps in compliance.

Supplier compliance

When nobody noticed. Designing for the gaps in compliance.

Supplier compliance

(Services)

(Services)

Product design

Product design

,

,

UX Research

UX Research

,

,

Design Systems

Design Systems

(Industry)

(Industry)

B2B SaaS

B2B SaaS

(Year)

(Year)

2025

2025

(Information)

(Information)

Organisations managing large supplier bases were running compliance and document workflows across spreadsheets, email chains, and third-party tools. No single source of truth. No proactive alerts. The risk mostly surfaced when something had already gone wrong.

The client needed a way to bring that entire workflow - supplier onboarding, document management, compliance tracking, information requests - into a single, coherent place. I joined the project post-discovery, inherited the OST, and led design from concept through to dev handoff across a three-month engagement working in a product trio with a PM and tech lead.

Organisations managing large supplier bases were running compliance and document workflows across spreadsheets, email chains, and third-party tools. No single source of truth. No proactive alerts. The risk mostly surfaced when something had already gone wrong.

The client needed a way to bring that entire workflow - supplier onboarding, document management, compliance tracking, information requests - into a single, coherent place. I joined the project post-discovery, inherited the OST, and led design from concept through to dev handoff across a three-month engagement working in a product trio with a PM and tech lead.

(Information)

(Information)

The as-is wasn't a product problem yet - it was a fragmentation problem. Suppliers came in through different touchpoints, got logged inconsistently, and the compliance work happened wherever someone had decided to keep track of it that quarter. Years of workarounds had produced a system that technically functioned but required constant human intervention to hold together.

The OST that came before me had already mapped the core opportunity: procurement managers needed oversight across their entire supplier base without having to chase information. The system had to surface what mattered, when it mattered, without adding cognitive load to an already complex role.

What I added was the detail layer - tracing how each job story actually played out in practice, and where the existing workarounds would resist a new system.

The as-is wasn't a product problem yet - it was a fragmentation problem. Suppliers came in through different touchpoints, got logged inconsistently, and the compliance work happened wherever someone had decided to keep track of it that quarter. Years of workarounds had produced a system that technically functioned but required constant human intervention to hold together.

The OST that came before me had already mapped the core opportunity: procurement managers needed oversight across their entire supplier base without having to chase information. The system had to surface what mattered, when it mattered, without adding cognitive load to an already complex role.

What I added was the detail layer - tracing how each job story actually played out in practice, and where the existing workarounds would resist a new system.

(Information)

(Information)

Pain points that shaped the design:

  • Documents uploaded without the right metadata were invisible to the compliance system - the problem wasn't uploading, it was categorisation

  • Expiring documents had no proactive surfacing - procurement managers only found out when something had already lapsed

  • Supplier-facing requests happened over email, with no tracking, no context, and no record in the system

  • Information about a single supplier lived in multiple places - profile, assessments, documents, compliance status all separated - forcing context switching and causing things to fall through

Pain points that shaped the design:

  • Documents uploaded without the right metadata were invisible to the compliance system - the problem wasn't uploading, it was categorisation

  • Expiring documents had no proactive surfacing - procurement managers only found out when something had already lapsed

  • Supplier-facing requests happened over email, with no tracking, no context, and no record in the system

  • Information about a single supplier lived in multiple places - profile, assessments, documents, compliance status all separated - forcing context switching and causing things to fall through

(Information)

(Information)

The key structural decision

Early in the project, there was a pull toward separate modules - documents here, assessments there, compliance status somewhere else. Pushing back on that was the decision I felt most strongly about. The reason procurement teams were missing things was exactly that the information lived in too many places. If you're reviewing a compliance gap, you need the document history in the same view. The supplier profile became the single source of truth: everything about a supplier - their tier, their documents, their assessment status, their activity log - in one place, without switching context.

Design decision #1 - Information request flow

The first instinct was a form. But when we traced how these requests played out in practice, the problem wasn't the form suppliers often had no idea what was being asked of them or why. We redesigned the request loop with context built in: what's being asked, why it matters, and what happens next. The supplier-facing side of this flow was the handoff most likely to break and the one I spent the most time testing.

Design decision #2 - Expiring documents

There was simply nothing surfacing expiring documents before they lapsed. We designed a tiered alerting system: quiet indicators within the supplier profile for low-urgency items, more visible flags in the inbox view, and a dedicated compliance overview for managers who needed the full picture across their supplier base. The logic was that different users needed different levels of signal not everyone needed to see everything all the time.

Design decision #3 - Document lifecycle

It sounds straightforward upload a file, tag it, update it when it expires. But tracing the full document lifecycle properly reveals the complexity: a document uploaded without the right metadata is invisible to the compliance system. One that gets replaced without preserving the old version loses its audit trail. One that expires silently creates a gap nobody catches. The design had to hold all of that together without making it feel like a burden to the person uploading.

Supplier segmentation

We landed on a three-tier model - H1 for suppliers requiring full compliance tracking down to H3 needing minimal oversight - after testing confirmed that users think in tasks, not categories. The information architecture shifted away from category-based navigation toward something more task-oriented: what do I need to do with this supplier today, and what do I need to see to do it.

The key structural decision

Early in the project, there was a pull toward separate modules - documents here, assessments there, compliance status somewhere else. Pushing back on that was the decision I felt most strongly about. The reason procurement teams were missing things was exactly that the information lived in too many places. If you're reviewing a compliance gap, you need the document history in the same view. The supplier profile became the single source of truth: everything about a supplier - their tier, their documents, their assessment status, their activity log - in one place, without switching context.

Design decision #1 - Information request flow

The first instinct was a form. But when we traced how these requests played out in practice, the problem wasn't the form — suppliers often had no idea what was being asked of them or why. We redesigned the request loop with context built in: what's being asked, why it matters, and what happens next. The supplier-facing side of this flow was the handoff most likely to break — and the one I spent the most time testing.

Design decision #2 - Expiring documents

There was simply nothing surfacing expiring documents before they lapsed. We designed a tiered alerting system: quiet indicators within the supplier profile for low-urgency items, more visible flags in the inbox view, and a dedicated compliance overview for managers who needed the full picture across their supplier base. The logic was that different users needed different levels of signal — not everyone needed to see everything all the time.

Design decision #3 - Document lifecycle

It sounds straightforward — upload a file, tag it, update it when it expires. But tracing the full document lifecycle properly reveals the complexity: a document uploaded without the right metadata is invisible to the compliance system. One that gets replaced without preserving the old version loses its audit trail. One that expires silently creates a gap nobody catches. The design had to hold all of that together without making it feel like a burden to the person uploading.

Supplier segmentation

We landed on a three-tier model - H1 for suppliers requiring full compliance tracking down to H3 needing minimal oversight - after testing confirmed that users think in tasks, not categories. The information architecture shifted away from category-based navigation toward something more task-oriented: what do I need to do with this supplier today, and what do I need to see to do it.

(Information)

(Information)

Outcome

I wasn't there for the full release, so I can't give long-term numbers. Early user feedback indicated a meaningful reduction in manual work for compliance tracking - the work that had previously lived in someone's inbox and memory. The information request flow was on track to replace most of the email back-and-forth. The supplier profile consolidation meant procurement managers had a single place to review status without switching between tools.

What I'd do differently

I joined after initial research was done, which meant I'd never spoken directly to suppliers - the users the supplier-facing view was designed for. I compensated with prototype testing and second-hand insights, but I'd have pushed harder for even a few supplier interviews early on.

We underinvested in supplier-facing notifications. Giving suppliers earlier signals that something was expiring would have reduced the reactive work on the procurement side significantly. I'd revisit that.

More broadly, I'd have mapped the full user journey more rigorously from the start - across both sides. Some of the friction we discovered late would have been visible earlier if we'd traced the end-to-end flow before touching Figma.

Outcome

I wasn't there for the full release, so I can't give long-term numbers. Early user feedback indicated a meaningful reduction in manual work for compliance tracking - the work that had previously lived in someone's inbox and memory. The information request flow was on track to replace most of the email back-and-forth. The supplier profile consolidation meant procurement managers had a single place to review status without switching between tools.

What I'd do differently

I joined after initial research was done, which meant I'd never spoken directly to suppliers - the users the supplier-facing view was designed for. I compensated with prototype testing and second-hand insights, but I'd have pushed harder for even a few supplier interviews early on.

We underinvested in supplier-facing notifications. Giving suppliers earlier signals that something was expiring would have reduced the reactive work on the procurement side significantly. I'd revisit that.

More broadly, I'd have mapped the full user journey more rigorously from the start - across both sides. Some of the friction we discovered late would have been visible earlier if we'd traced the end-to-end flow before touching Figma.

More Projects

Let’s create Something Together

Let’s create Something Together

Let’s create Something Together