Supplier Code of Conduct and Sustainable Procurement Policy
Last updated: June 2026
Introduction
Corporate integrity, responsible sourcing, and the wellbeing of workers across our supply chain are central to Broadhead’s mission and values. These principles guide all aspects of our business operations and extend to all our vendors, partners, service providers, and other third parties (each a “Supplier” and collectively “Suppliers”) who conduct business with Broadhead.
This Supplier Code of Conduct (“Code of Conduct”) outlines the minimum standards expected of all Suppliers regarding:
- Treatment of workers;
- Workplace health and safety;
- Environmental stewardship;
- Ethical and lawful business practices.
Applicability
This Code of Conduct applies to all Suppliers providing goods or services to Broadhead. Suppliers are responsible for compliance with these standards across their operations and throughout their entire supply chains. Suppliers must comply with this Code in:
- All facilities they own, lease, or operate;
- All operations, including production, distribution, sales, marketing, intellectual property, labor management, environmental impact, and worker welfare.
Suppliers must also ensure that their own suppliers, agents, vendors, and subcontractors (“Partners”) meet these standards.
Sustainable Procurement
Broadhead is committed to sustainable procurement and responsible sourcing. We seek to select and retain suppliers that operate in an ethical, environmentally responsible, socially responsible, and legally compliant manner. These expectations are integrated into supplier onboarding, evaluation, contracting, monitoring, and renewal processes.
Onboarding and Due Diligence
Broadhead may conduct supplier due diligence before onboarding and periodically thereafter based on risk. Due diligence may include review of legal entity information, ownership, sanctions/watchlists, adverse media, regulatory history, information security posture, anti-corruption controls, labor and human rights practices, and environmental compliance.
Supplier Risk Tiering
Broadhead recognizes that not all supplier relationships carry the same level of risk. To ensure that due diligence efforts are proportionate and practical, Broadhead classifies suppliers into three tiers based on the nature and risk profile of the engagement.
Low Risk: Standard domestic suppliers providing goods or services with no government interaction, no sensitive data access, and low transaction value (examples: office supplies, standard software subscriptions, commodity vendors). For low-risk suppliers, Broadhead’s process is an internal vetting step: the requestor confirms the vendor falls within a standard category and accounting confirms no sanctions or watchlist flags through Broadhead’s existing purchase order approval workflow. No supplier-facing documentation is required at this tier.
Medium Risk: Suppliers with broader or ongoing service relationships, access to Broadhead or client data, international components, or higher transaction values. For medium-risk suppliers, Broadhead’s Supplier Code of Conduct is incorporated by reference into its standard purchase order terms and vendor agreement templates. By accepting a Purchase Order or executing a vendor agreement with Broadhead, the supplier agrees to conduct business in a manner consistent with the principles of this Code. No separate signature is required — acceptance of the commercial relationship constitutes acknowledgment.
High Risk: A limited universe of suppliers presenting elevated compliance exposure, including commission-based agents, suppliers interacting with government officials on Broadhead’s behalf, international relationships in higher-risk jurisdictions, or relationships involving significant contingent compensation. High-risk suppliers are required to sign a formal acknowledgment of this Code of Conduct prior to engagement and are subject to enhanced due diligence including sanctions screening, adverse media review, beneficial ownership verification, and where appropriate, a Politically Exposed Person (PEP) screening.
Risk tier assessments are made at onboarding and reviewed as circumstances change. Suppliers who move into a higher-risk category due to changes in their operations, ownership, or scope of work with Broadhead will be subject to the requirements of the applicable tier from that point forward.
Business Ethics and Anti-Corruption
Suppliers must:
- Comply with all applicable anti-bribery and anti-corruption laws.
- Not offer, give, request, or accept bribes, kickbacks, facilitation payments, or anything of value intended to improperly influence a business decision.
- Maintain accurate books, records, and invoices.
- Disclose actual or potential conflicts of interest involving Broadhead business.
- Not provide gifts, travel, meals, entertainment, or hospitality to Broadhead personnel unless modest, lawful, infrequent, and approved under applicable policy.
- Promptly report suspected misconduct or violations.
Gifts, Hospitality and Sensitive Transactions
Suppliers must not provide gifts, travel, meals, entertainment, hospitality, or anything of value to Broadhead personnel unless it is modest in value, lawful, infrequent, transparent, and would not create the appearance of an obligation or conflict of interest (“Sensitive Transaction”). Broadhead defines the following standards:
- Facilitation payments of any kind — payments made to expedite an administrative or governmental process — are strictly prohibited.
- Suppliers must maintain records of all Sensitive Transactions provided to Broadhead personnel and must make those records available to Broadhead upon request.
- Suppliers must promptly disclose to Broadhead any Sensitive Transaction where the cumulative value or frequency with a single Broadhead employee may, in the supplier’s reasonable judgment, warrant transparency.
- Broadhead employees who receive hospitality or gifts from suppliers are independently required to report such items in accordance with Broadhead’s internal Anti-Corruption and Bribery Policy (Employee Handbook, January 2026).
Broadhead reserves the right to require a supplier to return or donate any gift that does not comply with this section, and repeated violations may result in termination of the supplier relationship.
Environmental Laws
Suppliers must comply with applicable environmental laws and work to reduce environmental impacts associated with their operations, including responsible management of waste, emissions, energy use, water use, and hazardous substances where relevant.
Environmental Sourcing Preferences
Broadhead is committed to integrating environmental responsibility into its procurement decisions. In addition to complying with applicable environmental laws, suppliers are encouraged to:
- Demonstrate improving environmental performance over time, including reductions in greenhouse gas emissions, energy consumption, waste generation, and use of hazardous substances.
- Disclose relevant environmental performance data to Broadhead upon request, including energy and GHG reporting, waste management practices, and any environmental certifications held.
- Give preference to eco-friendly, recycled, bio-based, or sustainably sourced materials and inputs where operationally feasible.
- Engage constructively with Broadhead’s sustainable procurement objectives and respond to reasonable supplier sustainability questionnaires.
Broadhead gives preference, all else being equal, to suppliers who can demonstrate a commitment to reducing their environmental footprint. Environmental performance may be considered in supplier selection, evaluation, and renewal decisions.
Labor Practices
Slavery, Human Trafficking, and Child Labor
All labor must be voluntary. Suppliers and their Partners shall not engage in or support slavery, human trafficking, child labor, or any form of forced or involuntary labor.
Suppliers must:
- Prohibit compelled, coerced, or forced labor;
- Prohibit the use of child labor. Workers must meet the minimum age for employment as defined by applicable law, or in no case be younger than 15 years old;
- Prohibit any penalties, threats, or retaliation associated with labor;
- Respect workers’ freedom of movement and allow them to leave the workplace at the end of shifts, for health and safety needs, or personal emergencies without reprisal.
Freedom to Terminate Employment
Suppliers must permit workers to terminate their employment without undue restrictions, penalties, or threats of retaliation.
Compensation and Benefits
Suppliers must compensate workers fairly, providing wages, overtime premiums, and benefits that meet or exceed the higher of applicable legal requirements or collective bargaining agreements. Benefits must be provided in a timely and transparent manner.
Suppliers must:
- Provide wage documentation in workers’ native languages;
- Ensure transparency in calculations of wages and deductions;
- Retain accurate wage payment records.
Only lawful deductions, such as required tax withholdings, are permitted.
Work Hours
Suppliers must not require workers to exceed maximum work hours allowed by applicable law.
Health and Safety
Suppliers must:
- Ensure facilities meet building codes and industry standards;
- Obtain and maintain all required construction, zoning, and use permits;
- Provide adequate emergency evacuation plans, lighting, clear exits, and evacuation signage;
- Maintain proper ventilation, lighting, sanitation, and fire prevention systems;
- Provide potable water and private toilet facilities;
- Display necessary safety rules, inspection reports, and permits visibly.
Dining facilities, if provided, must be safe, clean, and compliant with all health and safety standards.
Freedom of Association and Collective Bargaining
Suppliers must respect workers’ rights to freely associate, form, and join unions, and engage in collective bargaining. Suppliers must not interfere with or retaliate against workers who exercise these rights.
Third-Party Supplier Security Requirements
Broadhead engages with third-party vendors, consultants, contractors, and service providers (“Vendors”) who may process, transmit, or store Company or client data. To protect Broadhead’s assets and maintain compliance with contractual and legal obligations, all Vendors must meet the security and data protection standards outlined in this section.
Vendor Risk Assessment
Prior to engagement, all Vendors with access to Broadhead’s information systems or data may need to undergo a security and privacy risk assessment, coordinated by the IT and Legal teams.
Risk factors include:
- Type and sensitivity of data accessed or processed;
- Access to internal systems or networks;
- Cloud services, hosting, or data storage roles;
- Regulatory implications (e.g., HIPAA, GDPR, CCPA, PCI-DSS).
Contractual Security Requirements
All Vendors must provide for:
- Implementation and maintenance of reasonable and appropriate technical, administrative, and physical safeguards to protect data.
- Compliance with applicable data protection laws and client contractual obligations.
- Prompt breach notification (typically within 24–72 hours) of any security incident affecting Broadhead or client data.
- Prohibition against subcontracting or offshoring data without prior written consent from Broadhead.
- Confidentiality obligations that survive termination of the agreement.
- Right for Broadhead to audit or request security certifications (e.g., SOC 2, ISO 27001) on an annual basis or upon reasonable request.
Ongoing Monitoring
Vendors may be subject to periodic reassessment based on risk classification. IT may review third-party compliance through security questionnaires, certifications or penetration test reports, and on-site assessments (where high-risk). Contracts with Vendors that handle sensitive or client data must be re-reviewed every 12–24 months, or upon renewal or scope change.
Vendor Breach Response
In the event of a Vendor-related security incident:
- The Vendor must immediately inform Broadhead’s IT and Legal Departments.
- Vendor cooperation is required for containment, investigation, and client or regulatory notifications.
- Vendors may be liable for damages, remediation costs, and legal exposure if breach results from negligence or contract violations.
Data Return or Destruction
Upon termination of services, Vendors must:
- Return all Broadhead or client data in a usable format, if requested.
- Permanently destroy all copies of such data (including backups) within 30 days, unless otherwise required by law.
- Provide written certification of data deletion or destruction.
Ethical Business Conduct Expectations
Broadhead selects and retains suppliers who share its commitment to ethical business conduct. We expect all suppliers, regardless of size or engagement type, to operate with integrity, honesty, and respect for applicable laws and the people they employ.
Suppliers are expected to be familiar with the standards set out in this Code of Conduct and to conduct their business in a manner consistent with its principles. This does not require suppliers to adopt Broadhead’s internal training programs or administrative processes, but simply to reflect these values in how they operate day to day.
Suppliers who become aware of conduct within their own organization that materially conflicts with the principles of this Code — including corruption, labor violations, or significant environmental non-compliance — are expected to take appropriate steps to address it and to notify Broadhead where the matter affects or could affect their relationship with Broadhead.
Non-conformance
Where non-conformance is identified, Broadhead may require a corrective action plan with defined timelines. Suppliers are expected to cooperate with remediation efforts and provide evidence of corrective actions. Repeated, material, or unresolved non-conformance may result in suspension or termination of the relationship.
Termination of Relationship
Broadhead reserves the right to immediately terminate its business relationship, including any purchase orders or contracts, with any Supplier that fails to meet these standards.
Ongoing Compliance Expectation
Broadhead’s Supplier Code of Conduct and Sustainable Procurement Policy is maintained online and updated periodically. Suppliers are expected to familiarize themselves with the current version, which is available at broadheadco.com/code-of-conduct/.
By continuing to do business with Broadhead — including through acceptance of a Purchase Order or execution of a vendor agreement — suppliers affirm their ongoing commitment to conduct business in a manner consistent with the principles of this Code. Broadhead will notify suppliers of material updates to the Code through its standard vendor communications.
Suppliers who have undergone significant changes in ownership, operations, or legal status are encouraged to notify Broadhead’s accounting team at [email protected] so that the relationship can be reviewed appropriately.
Acknowledgment
By engaging with Broadhead — including by accepting a Purchase Order, executing a vendor agreement, providing goods or services, or receiving payment from Broadhead — each Supplier acknowledges receipt of this Supplier Code of Conduct and agrees to conduct its business in a manner consistent with its principles. No signed acknowledgment is required; the act of engagement constitutes acceptance.
Suppliers who have questions about this Code or wish to raise a concern may contact Broadhead’s CFO at [email protected].