Document collection

Document collection.

Still chasing suppliers manually for documents and never sure what's current? The module centralises and automates all your document requirements — from request to archiving, with AI pre-analysis of every document.

AI analysis of collected documentsSupplier portalEnforceable audit trail11 regulatory frameworks
The challenge

A legal obligation, handled manually

From €5,000 excl. VAT per contract, the law requires you to collect — and renew every six months — the supporting documents from your subcontractors. The scope keeps expanding; the tools haven't moved.

The duty of care (art. L8222-1 of the Labour Code) requires a social contributions certificate, a Kbis extract, and a list of foreign workers for any significant contract. The corporate duty of vigilance (Law 2017-399) and the European CS3D directive add governance, human rights, environment, and whistleblowing mechanisms. On top of that come Sapin II, GDPR, AML-CTF, CSRD, and the deforestation regulation. In most organisations, this collection still relies on Excel spreadsheets, email follow-ups, and manual checks.

Fragmentation

Up to six departments involved — procurement, compliance, legal, cyber, DPO, finance — with no shared reference or consolidated view.

Silent expiry

A social contributions certificate lasts six months, a Kbis three. Without automatic tracking, the gap between 'submitted' and 'valid' widens without anyone noticing.

Unenforceable proof

A file reconstructed after the fact does not demonstrate diligence. You need dated, timestamped, verifiable traceability.

The process

Five steps, from requirements to proof

The module follows the real lifecycle of a supporting document: define what's expected, invite the supplier, they submit, the platform analyses, you monitor. Every step is supported; none depends on a spreadsheet.

1

Configure

Choose a regulatory baseline, build your supplier profiles, adjust document lifespans and thresholds.

2

Invite

The supplier receives an access code by email, sets a password, and accesses their workspace. No account creation required.

3

Submit

Guided portal, contextual help for each document, motivated 'Not applicable' declaration when a document doesn't apply.

4

Analyse

AI pre-analysis in under a minute: verdict, score, extracted data, and an educational message to the submitter.

5

Monitor

Statuses, expiries, reminders, and compliance rates — by supplier, by document, by campaign.

The reference library

A library of documents, ready to use

Built from a duty-of-vigilance reference framework, the library describes each document you can require from a supplier: what it's for, how to check it, how long it stays valid, and which law requires it.

FamilyDocsExamples
Legal identification5Kbis extract (< 3 months), articles of association, beneficial owner, tax compliance certificate, bank details
Social and labour law documents6Social contributions certificate (URSSAF), foreign workers list, disability employment certificate, collective agreement, DUERP, RC / decennial insurance
Governance and internal policies8Code of conduct, CSR policy, human rights, anti-corruption, responsible procurement, vigilance plan, climate transition plan, risk mapping
Environmental documents5Carbon footprint / BEGES, ISO 14001, waste and water management, impact assessments, material traceability (EUDR)
Alert and reporting mechanisms3Whistleblowing system, complaints procedure, remediation procedure
Certifications and labels6ISO 9001, 45001, 26000, 37001, Ecovadis rating, sector labels (SA 8000, FSC, RSPO, OEKO-TEX)
Contractual commitments and audit rights5ESG clauses, code of conduct acceptance, audit rights, N+1 / N+2 cascade commitment, corrective plan
Questionnaires and audits4ESG questionnaire, social and environmental audit reports, CSRD report
Data protection3Processing register / DPO, DPA clauses, IT security policy
Construction / public contracts requirements6PRO BTP, CIBTP certificate, decennial insurance valid at construction opening, site RC, economic dependence form

Eleven regulatory frameworks cross-referenced

Each document indicates whether it is mandatory, recommended, or not applicable for:

Duty of careFrench Corporate Vigilance LawCSDDDCSRDSapin IIWhistleblowingEUDR deforestationConflict mineralsForced labourGDPRAML-CTF

Calibrated document lifespans

  • 3 months — Kbis extract
  • 6 months — social contributions certificate, tax compliance, foreign workers list
  • 1 year — internal policies, insurance certificates, questionnaires, Ecovadis
  • 2 years — social audit reports
  • 3 years — articles of association, ISO certifications, environmental audit reports
Exemple — KbisExample — Kbis compliance checklist: Issue date under 3 months (art. D8222-5 Labour Code) · consistency of name / SIREN / registered office with contract · NAF code compatible with the service · no insolvency proceedings · signatory powers verified (AML-CTF).
Trois documents verrouillésThe Kbis extract, social contributions certificate, and foreign workers list are required by article D8222-5 of the Labour Code. They cannot be removed from any supplier profile.
The requirements policy

Three regulatory baselines, tailored profiles

You don't ask the same things of an IT provider, a site worker, and a personal data sub-processor. The module starts from a legal baseline, then lets you compose each profile.

Labour Code · art. L8222-1

Duty of care

Any contract ≥ €5,000 excl. VAT

7documents
Law 2017-399

Corporate Vigilance Law

≥ 5,000 employees in France or 10,000 worldwide

26documents
EU Directive 2024/1760

CS3D / CSDDD

≥ 5,000 employees and turnover ≥ €1.5bn

29documents

Supplier profiles

Six standard profiles, all editable: Default Supplier, IT Supplier, Logistics Supplier, HR Contractors, On-site Workers, Personal Data Sub-processors.

  • Required documents, chosen from the library
  • Document-level lifespan overrides
  • Associated questionnaires, information forms
  • Custom documents specific to your organisation

Cascading insurance thresholds

Minimum coverage amounts are set at profile, category, or organisation level — the most precise applies.

  • Professional Liability: €150,000 by default
  • Cyber Insurance: €150,000 by default
  • Public Liability: €1,000,000 by default
  • Early expiry alert: 90 days
Marchés & exigences clientThe 'Construction / public contracts' family and the ability to attach suppliers to specific contracts (phase, project owner, lots) let you capture requirements specific to a client or building site — PRO BTP certificate, decennial insurance valid at site opening, economic dependence form.
The supplier experience

A portal your suppliers actually use

The quality of a collection depends first on how easy it is for the supplier to submit. The Document Collection portal guides each document and works in three languages.

Access in three steps

The supplier receives an access code by email, sets a password, and arrives at their workspace. The company is identified by its registration number via the public API: name, address, NAF code, headcount, and legal form are pre-filled.

Three languages

Interface available in French, English, and Spanish. Foreign-language documents are accepted and translated during analysis — language can never justify a rejection.

One space, multiple clients

The supplier finds all their Conitiv clients in one space. They can choose to share documents across all their clients: one upload, multiple files updated.

Contributors

Each document can be assigned to a colleague (accountant, internal insurer, HR). The manager keeps the overview; the right people submit.

'Not applicable', but justified

When a document doesn't apply, the supplier declares it not applicable with a mandatory reason. The declaration is sent to the client for approval; once accepted, it counts as compliant.

Compliance certificate

At 100% validated file, the supplier downloads their compliance certificate in the client's name. Before that, they see exactly what remains to be provided and what's under review.

The differentiator

Every certificate read, checked and scored before your teams

Receiving a PDF is not the same as checking a guarantee. The module passes each insurance certificate to our AI agents who read the document natively, apply your thresholds, and return an argued verdict — in under a minute.

The file is sent as-is to the model, with no intermediate OCR. The analysis uses the supplier's context — company name, registration number, NAF code — and your coverage thresholds. It runs as soon as a document is submitted; the supplier sees 'Analysis in progress…' then the result.

Four verdicts, one score

Compliant

All blocking checks passed, no alerts.

100 / 100
Compliant with reservations

Checks passed, at least one alert to review.

75 / 100
To verify

One point cannot be determined automatically (Cover Note, approximate identity).

50 / 100
Non-compliant

At least one blocking check failed.

20 / 100

The decision remains yours

  • Auto-rejection of non-compliant documents (enabled by default)
  • Auto-validation of compliant documents (option)
  • 'Under review' status for human check
  • Manual override by an administrator, with comment and history
  • Analysis re-run on demand
Périmètre & méthodeThe analysis currently covers Professional Liability, decennial, and Cyber certificates — the documents where errors cost the most. Other families follow the same framework: a versioned prompt, a reference PDF set with expected verdicts, and decision rules recalculated server-side.
Lifecycle monitoring

A document is never 'done', it's valid until a date

Every document follows an explicit lifecycle, from request to expiry. At any moment, you know what's missing, what's expiring, and who's been contacted.

Requested→Submitted→AI Analysis→Under review→Validated→Rejected→Not applicable→Expired

Calculated expiry, not guessed

The expiry date follows the document lifespan in the supplier's profile. It's shown next to every document, on both the supplier and client sides.

ValidExpires in 23 daysExpired

Scheduled reminders

Suppliers who haven't responded are automatically reminded at D+7, D+14, and D+30, with a capped number of reminders. Frequency is set per campaign.

Supplier dashboard

The supplier sees actions sorted by urgency: 'Action required immediately' for expired or rejected documents, 'Due within 14 days' for those approaching expiry.

Supplier compliance status

Each supplier carries a compliance status — Compliant, Partial, Non-compliant, In progress, Not started — and a rate calculated from required, validated, expired, and missing documents.

Monitoring

A consolidated view for the compliance manager

On the client side, the module replaces the spreadsheet with a control centre: where each supplier stands, which documents are blocking, who to chase, what to export.

Document collection

  • Global and per-document-type compliance rate
  • List of non-compliant suppliers: missing documents, expired, last reminder, criticality
  • Individual or bulk reminders for non-compliant suppliers
  • Filters by document type, status, and criticality

Collection campaigns

  • Supplier targeting by criticality and relationship type (supplier, subcontractor, subsidiary, partner)
  • Document selection
  • Automatic reminders, configurable frequency and cap
  • Tracking: invited suppliers, compliant suppliers, response rate

Supplier record

  • Documents tab with the status of each document
  • Company registry record (INPI) accessible in one click from the registration number
  • Portal invitation and last login tracking
  • AI analysis report and manual decision

Enforceable traceability

  • Timestamping of requests, submissions, validations, and reminders
  • SHA-256 fingerprint of each analysed file
  • History of verdicts and manual decisions, with author and comment
  • Dated exportable report, source document in appendix
Connecté au reste de la plateformeDocument status feeds the risk matrix (missing or expired documents = aggravating factor, certifications present = mitigating factor), the vigilance plan, and the general dashboard. Collection is not a silo: it's the declarative component of the 360° score.
What you gain

Less processing, more proof

Continuous compliance, without spreadsheets

Requirements are defined once per supplier profile. Expiries, reminders, and statuses update without intervention.

Your teams only see what needs attention

AI rejects membership forms, flags insufficient coverage, and translates foreign documents before anyone opens the file.

Suppliers who submit, and submit correctly

No account to create, help for every document, a clear message when rejected. Response rates go up, back-and-forths go down.

Demonstrable diligence

In the event of a tax audit, vigilance audit, or legal dispute, you produce a timestamped, verified, exportable file.

A reference that tracks regulation

Eleven cross-referenced frameworks, three legal baselines, adjustable lifespans and thresholds: the library evolves with your obligations.

A brick in the 360° score

Collection completes automated scoring (solvency, cyber, CSR, GDPR, sovereignty) and evidence-based audits in a single platform.

Take action

See the module on your own supplier portfolio

A 30-minute demonstration, with your supplier profiles and one of your insurance certificates to test the analysis live.

Request a demo →
Parlez à un
expert Conitiv