Third-party lifecycle management for France operations
Last updated: August 19, 2026
Verdana is a third-party lifecycle management platform that helps companies operating in France manage supplier and contractor due diligence, documentation, and monitoring, in one system built around the obligations that follow from using third parties to do business.
The Loi de Vigilance (Article L. 225-102-4 of the Code de commerce) requires large companies to establish, publish, and implement a vigilance plan identifying and preventing serious human rights, safety, and environmental risks across their sphere of influence — explicitly including subcontractors and suppliers with an established commercial relationship. Sapin II, Article 17, separately requires companies above defined size and revenue thresholds to run a risk map and to evaluate the situation of clients, first-rank suppliers, and intermediaries against it, under guidance from the Agence Française Anticorruption. Verdana runs the supplier side of both: risk-based classification, structured evidence collection, and monitoring that can requalify a supplier's risk level as new information comes in.
Articles L.8222-1 to L.8222-7 of the Code du travail require a company contracting for a service above a set annual value to verify, at signing and every six months after, that the subcontractor is current with its declaration obligations — the vigilance certificate check. Skipping that verification exposes the contracting company to joint and several liability for the subcontractor's unpaid taxes, contributions, and wages if undeclared work is later found. Verdana tracks that verification and its renewal date per contractor, the way it tracks any other document with an expiration.
France sits alongside the rest of Europe, Latin America, and the United States in the same platform: document requirements are configured per jurisdiction, and headquarters gets one consolidated view of every supplier and contractor regardless of where they operate.
Frequently asked questions
What does the Loi de Vigilance require regarding suppliers and subcontractors?
Covered companies must establish, publish, and implement a vigilance plan that identifies and works to prevent serious human rights, health and safety, and environmental risks across their sphere of influence — a scope that explicitly reaches subcontractors and suppliers with an established commercial relationship, not only the company's own operations.
What does Sapin II expect regarding third-party evaluation specifically?
Article 17 requires an up-to-date risk map and procedures to evaluate clients, first-rank suppliers, and intermediaries against that map. Guidance from the Agence Française Anticorruption describes third parties as re-evaluated individually — a supplier that scores low-risk on the general map can still be requalified as high-risk after specific review.
What is the vigilance certificate obligation under Article L.8222-1?
A company contracting for a service above a set annual threshold must verify, at signing and every six months while the contract runs, that the subcontractor is current on its declaration obligations. Missing that check exposes the contracting company to joint liability for the subcontractor's unpaid taxes and social contributions if undeclared work is later found.