At 7:45 a.m. an auditor signs in. At 7:48 somebody discovers that a key supplier’s fire safety certificate expired eleven days ago. The current file is in an inbox, the spreadsheet still shows the old date and the procurement system says only “approved”. This is not a lack of digital tools. It is three digital truths with no agreed order of authority

A document has a life story

Supplier documents are often treated as attachments. In business terms, they are time limited evidence. They are requested, submitted, reviewed, accepted, rejected, replaced and eventually archived. Every stage has a time, an accountable person and a reason

For each file, the portal needs to record the document type, scope, issuer, supplier, affected sites and validity date. An insurance policy may also require a coverage value; a quality certificate may require the certification body. A generic “upload document” field discards precisely the information people will search for later

A deadline is not a calendar event

A reminder seven days before expiry sounds sufficient, but rarely is. Some evidence needs a technical review, a question or reissue. Good deadlines are planned backwards from expiry, allowing for review time, expected supplier response and escalation

The rule after expiry matters just as much. Is the supplier suspended automatically, blocked only from new orders or merely flagged? Software must not invent that business decision. It should enforce the chosen rule consistently and record exceptions

OCR is an assistant, not an examiner

Text recognition can extract certificate numbers and dates. Modern models can handle inconsistent layouts surprisingly well. Poor scans, handwritten amendments and language variants remain error prone. Critical fields need confidence indicators and visible human review

Provenance is essential: which value came from the document, which was entered by the supplier and which was corrected internally? If only the latest value is kept, the evidence trail disappears. A useful record separates the original, extracted suggestion, confirmed value and reviewer

The smallest useful review desk

  • a work queue ordered by risk and due date, not merely supplier name
  • the document and extracted fields side by side
  • approval, rejection and questions with a required reason
  • versions so that a new document does not erase the old one
  • delegation for holidays and absence
  • an audit export containing timestamps and decisions

A status such as “complete” should be computed. It depends on the evidence required for that supplier category, its validity and its review state. A manually coloured spreadsheet cell is not a dependable status

Security begins at file intake

Uploads need an allowlist of file types, size limits and technical content inspection. Neither the filename nor the media type reported by the browser can be trusted. Files should receive new internal names, sit outside publicly accessible web directories and be checked before release. Access should use short lived authorised links rather than permanent public addresses

A legitimate file can still contain confidential data. Retention and deletion should therefore follow document type and purpose. Keeping everything forever creates future risk, not additional security

Implementation starts with a document map

Before development, examine twenty or thirty real cases: valid evidence, rejected scans, exceptional approvals, suppliers with several sites and historical versions. Those cases create the map of document types and decisions. Only then is it worth importing existing lists

The import is not a side task. Duplicate supplier names, inconsistent date formats and missing owners need treatment first. Uncertain matches belong in a review queue, not an automatic migration

If secure file transfer is the main problem, a well designed upload form may be enough initially. Once deadlines, reviews and supplier roles meet, the full domain model of a B2B portal is required. Its value does not come from having fewer files. It comes from one traceable answer to the question of which evidence is currently valid