Cadelis Rivergate Steady ground for your financial decisions
The method

Evidence first,
opinion last

Every engagement runs the same audited path so the findings hold up long after we leave. Here is how the five phases fit together, what each one produces, and how the scoring model quantifies risk you can otherwise only feel.

01 — Phases

The five phases
in full

Documented, repeatable, and built on the ISO 19011:2018 guidelines for auditing management systems.

Standard applied: ISO 19011:2018
No. Phase What happens & what you get
01 Scope & criteria Audit criteria, materiality thresholds and access agreed in writing. Deliverable: a signed scoping note. Typical duration: five working days.
02 Evidence collection Ledgers, supplier masters, contracts and payment runs consolidated into one verified dataset. Deliverable: a reconciled data foundation with anomalies flagged.
03 Verification Material suppliers checked against CIPC, VAT and beneficial-ownership records on a graded confidence scale. Deliverable: a verification log per supplier.
04 Scoring & analysis Verified exposure run through the weighted model. Deliverable: a comparable 0–100 score per supplier and category.
05 Report & handover Board-ready report, working papers and the live model, plus a training session. Deliverable: everything you need to act and to keep the model running.
Supply chain logistics operation on the Highveld, illustrating the evidence collection phase
02 — Measurement

What we measure,
and why it matters

Concentration risk — 30%

How much category or total spend rests on one vendor, and how that has moved over time.

Why it matters: concentration is the single most common cause of a supply shock a board never saw coming.

Solvency & financial health — 30%

Registration status, filing currency, judgments and credit signals.

Why it matters: a supplier that folds mid-contract costs far more than the price you negotiated.

Compliance — 25%

CIPC registration, VAT validity, ownership clarity and sector obligations.

Why it matters: an unregistered or non-compliant vendor is a finding waiting to happen at your next audit.

Continuity — 15%

Single-source dependency and lead-time fragility.

Why it matters: some suppliers are cheap to lose and some would stop a plant within a fortnight — the score tells them apart.

Bands: 0–39 low risk · 40–69 watch · 70–100 material

Advisory team discussing supplier scoring results around a table
03 — On the method

What people ask
about the approach

ISO 19011 governs how auditing is done — sampling, evidence, independence and reporting. Applying it is what makes our findings defensible. A management-system certification wouldn't tell you anything about the quality of a supplier review.
Yes. The four criteria are fixed but their weightings shift by sector and, where justified, by client. Any change is documented in the model version so it stays defensible.
Each check is graded from documentary-confirmed down to unverifiable. A supplier can't reach a low-risk band on unverified evidence, which stops the score flattering anyone.
The base engagement is a point-in-time view. Many clients then take an ongoing monitoring retainer that re-scores the register quarterly against fresh data.
You do. We hand over the live model and train your team to run it. There's no lock-in and no dependency on us to keep it working.
Most of it. Data flows electronically under our POPIA framework. We prefer to run the scoping and handover sessions in person, at your site or ours in Witbank.

Want the method
run over your book?

Send us a rough supplier count and the deadline you're working to. We'll tell you honestly whether it's worth doing and what it would take.