
Contents
Quick answer
ESG supply chain assessment is the systematic process of identifying, measuring, and monitoring environmental, social, and governance risks across all tiers of a supply network, from direct Tier 1 vendors down to raw material sources.
It evaluates whether suppliers meet carbon reduction commitments, respect labour rights, operate with governance integrity, and comply with mandatory due diligence laws including the EU Corporate Sustainability Due Diligence Directive, the German LkSG, the UK Modern Slavery Act, and the Uyghur Forced Labor Prevention Act. A complete ESG supply chain assessment goes beyond questionnaire self-disclosure and combines open-source intelligence, verified data, and continuous monitoring to surface risks that structured databases have not yet indexed.
Key takeaways
ESG in supply chain management refers to the integration of environmental, social, and governance standards into how organisations source, evaluate, and monitor the third parties that deliver goods, raw materials, components, and services. The three pillars map to concrete obligations, not abstract values.
Environmental covers a supplier’s carbon emissions, water usage, waste disposal, resource extraction practices, and alignment with the GHG Protocol Scope 3 framework. Social covers labour rights, fair pay, health and safety standards, modern slavery risk, and community impact. Governance covers anti-bribery and corruption policies, beneficial ownership transparency, regulatory compliance, and business ethics.
A decade ago, supply chain ESG was a voluntary corporate responsibility initiative. It is now a mandatory compliance obligation in the EU, Germany, the UK, France, and the Netherlands, with the US applying UFLPA enforcement to goods with forced-labour exposure at any tier of the supply chain. Organisations that treat ESG as optional are building compliance exposure, not avoiding it.
The Neotas supply chain risk management guide covers how ESG assessment integrates with the full SCRM framework across 9 risk categories. The TPRM guide sets out the 7-stage vendor lifecycle within which ESG assessment sits.
ESG is relevant to supply chain management because the supply chain is where most ESG risk actually sits. A company’s own operations may be clean, well-governed, and compliant. Its Tier 2 and Tier 3 suppliers may not be. Under CSDDD, LkSG, and the UK Modern Slavery Act, “I did not know” is not a defence. These laws impose a duty to know.
The specific reasons ESG is now operationally central to supply chain management:
Regulatory obligation, not preference
Five major jurisdictions now require mandatory supply chain due diligence. Fines and import bans apply to non-compliant organisations.
Scope 3 emissions disclosure
Supply chain emissions are the largest part of most companies’ carbon footprint. Investors and regulators now require Scope 3 measurement and reduction plans.
Investor and lender pressure
Major institutional investors require supply chain ESG evidence as a condition of capital allocation. Weak supply chain ESG scores reduce access to sustainable finance.
Customer and contract requirements
Large customers in Europe and North America now include ESG minimum standards as contract terms. Suppliers who cannot evidence compliance lose commercial relationships.
A supply chain ESG audit is a formal verification of a supplier’s ESG claims, policies, and practices. It goes beyond questionnaire review to examine actual operations, records, and conditions. Audits are required under LkSG when risk analysis identifies a violation or substantiated indication of a violation, and under CSDDD as part of a systematic Due Diligence process.
There are three audit types relevant to supply chain ESG programmes, and choosing the right one for the right supplier determines whether the audit adds real intelligence or just cost.
| Audit type | What it covers | When to use | Regulatory relevance |
|---|---|---|---|
| First-party (self-assessment) | Supplier’s internal ESG policies, certifications, and self-reported data | Standard-tier suppliers; initial screening for all tiers | Necessary but not sufficient under CSDDD and LkSG |
| Second-party (buyer-conducted) | On-site audit by buyer’s team of supplier facilities, records, and worker conditions | High-risk Tier 1 and critical Tier 2 suppliers in high-risk jurisdictions | Recommended under OECD Guidance; satisfies LkSG audit obligation |
| Third-party (independent verification) | Independent accredited audit body verifies ESG claims, certification status, and practices | Critical suppliers; suppliers with known or suspected ESG violations; CSRD-related assurance | Required for CSRD sustainability reporting assurance; highest evidentiary value for regulatory inspection |
Pre-engagement audit checklist:
During-engagement audit checklist:
Post-engagement and ongoing:
ESG supply chain risk ratings provide a standardised, comparable assessment of a supplier’s ESG risk profile across the three pillars. They turn multi-source assessment data into a score that can be applied consistently across your supplier portfolio, embedded in procurement decisions, and used as a monitoring trigger.
Most ratings use a tiered or numeric scale: Negligible / Low / Medium / High / Critical, or a 0-100 score with defined risk band thresholds. What matters is not which scale you use, but that the methodology behind it is documented, consistently applied, and updated when new information emerges.
| Risk rating | Typical profile | Due diligence requirement | Monitoring cadence |
|---|---|---|---|
| Critical | Active ESG violations confirmed; sanctions list match; documented forced labour; critical Tier 1 operational dependency | Immediate enhanced due diligence; senior escalation; remediation or disengagement decision required | Continuous automated monitoring plus monthly manual review |
| High | High-risk sourcing jurisdiction; unverifiable beneficial ownership; adverse media signals; weak ESG policy evidence | Full intelligence-led assessment covering all three ESG pillars; corrective action plan before contract execution | Quarterly review plus automated alerts |
| Medium | Some ESG gaps but no confirmed violations; moderate-risk jurisdiction; incomplete certification coverage | Standard DDQ with independent adverse media verification; corrective action plan within 90 days for identified gaps | Bi-annual review plus automated alerts for key ESG risk categories |
| Low | Strong ESG certifications verified; clean adverse media; transparent ownership; low-risk jurisdiction; strong GHG data | Lightweight annual questionnaire with exception-based review | Annual review |
Supply chain ESG reporting has three distinct obligations that require different data, different methodologies, and different publication timelines. Most compliance teams conflate them, which produces reports that satisfy none of them fully.
Scope 3 GHG emissions disclosure
Required under CSRD (ESRS E1) and investor disclosure expectations globally. Follows GHG Protocol Scope 3 Standard.[5] Requires supplier-level emissions data for Category 1 (purchased goods and services) and Category 4 (upstream transportation). Most organisations cannot report credible Scope 3 data without supplier data collection programmes. A target without data is a press release, not a disclosure.
CSRD sustainability reporting (ESRS)
EU CSRD[6] requires in-scope companies to report against ESRS standards including supply chain due diligence practices (ESRS G1), supply chain working conditions (ESRS S2), and upstream environmental impacts (ESRS E1-E5). This requires documented supplier assessment processes, not just self-reported sustainability statements. Third-party assurance of the supply chain data will become mandatory as the CSRD assurance framework matures.
Modern Slavery Act transparency statement (UK)
Required annually for UK organisations above £36M turnover.[3] Must be signed by a board director. Published on the UK Modern Slavery Statement Registry.[8] A statement that only lists ESG policies and does not describe the due diligence steps actually taken and the risks identified is considered inadequate by the Home Office and NGO monitors who use the Registry to hold companies to account.
Covers all three ESG pillars, the CSDDD/LkSG/Modern Slavery Act compliance checklist, the 5-step supplier ESG assessment process, the ESG metrics table, and a Scope 3 data collection framework. Used by procurement and compliance teams across the UK, EU, and US.
Download the checklistImmediate access. No credit card required.
These patterns appear in programmes that have passed internal audits but still fail regulatory inspections, produce ESG incidents, or generate investor concerns. Each represents a structural gap, not a one-off oversight.
Mistake 1: Treating the Modern Slavery Act statement as the complete modern slavery programme
The annual transparency statement is the publication requirement. The underlying programme, which must cover supplier screening, risk tiering, due diligence, corrective action, and monitoring, is the obligation. Organisations that publish a statement without a documented programme that produced it are non-compliant regardless of how well-written the statement is. The Home Office’s modern slavery guidance and the Business and Human Rights Resource Centre both monitor statement quality against exactly this distinction.
Mistake 2: Using the same questionnaire for all suppliers regardless of risk profile
A questionnaire designed for a low-risk stationery supplier is not an appropriate ESG assessment for a Tier 2 garment manufacturer in a high-risk sourcing country. One-size questionnaires produce data that looks complete but lacks depth where depth matters. They also create false assurance: a supplier completing a generic questionnaire in good faith may still have significant ESG exposures that the questionnaire was not designed to surface.
Mistake 3: Collecting Scope 3 emissions data without a methodology disclosure
A Scope 3 emissions figure without a stated methodology is not reportable data. CSRD and the GHG Protocol both require disclosure of whether the figure is calculated using spend-based, activity-based, or hybrid methods, and whether it is estimated, self-reported, or third-party assured. Collecting supplier-reported GHG numbers and aggregating them without methodology verification produces a Scope 3 number that will not survive assurance review or regulatory scrutiny.
Mistake 4: Screening only against English-language adverse media
A labour rights violation at a Tier 2 factory in Vietnam will be reported in Vietnamese regional press before it reaches international English-language media, if it reaches international media at all. A sanctions enforcement action in Turkey will appear in Turkish regulatory announcements first. ESG adverse media screening that covers only English-language sources misses the majority of supply chain risk signals that appear before an incident escalates to global visibility. This is not a niche problem. It is the most common gap in standard ESG screening programmes.
Mistake 5: No corrective action process for red-flag findings
Identifying an ESG risk without a structured corrective action process is not due diligence. OECD Guidance and CSDDD both define due diligence as including prevention and mitigation steps, not just identification. If your programme identifies a modern slavery risk and there is no documented remediation process, escalation path, timeline, or resolution record, the finding is a liability without the corresponding evidence of action. Regulators and investors look for closed-loop processes, not open-ended observations.
Chief Procurement Officer
Your operational risk is a Tier 2 or Tier 3 supplier ESG violation that surfaces publicly and implicates your sourcing decisions. Your regulatory risk is LkSG or CSDDD enforcement when your due diligence records cannot evidence the process behind your supplier approvals. The specific artefact regulators request under LkSG Section 10 is a documented risk analysis and preventive action plan for your supplier base. Most organisations cannot produce it on request.
Chief Compliance Officer / ESG Director
Your exposure is multi-jurisdictional: satisfying CSDDD’s due diligence standard does not automatically satisfy LkSG’s more specific process requirements, and neither satisfies the Modern Slavery Act’s transparency statement requirements. You need a programme that maps to each framework’s specific evidence standard, not a single universal ESG policy applied to all three. The Omnibus simplification package proposed changes to CSDDD scope and civil liability; verify the current transposition status in your member states before you finalise your 2026 programme design.
CFO and Board Members
Supply chain ESG non-compliance is a quantified financial risk. CSDDD non-compliance carries penalties of up to 5% of global net turnover.[1] LkSG non-compliance carries up to 2% of global annual turnover plus procurement exclusion.[2] ESG supply chain incidents produce reputational damage that markets price within days of media disclosure. Investor ESG disclosure requirements are expanding, not contracting. An ESG supply chain programme is a financial risk management investment with a calculable return relative to the downside it prevents.
General Counsel and Legal Teams
CSDDD creates civil liability exposure, including the ability for claimants to bring actions in EU courts for supply chain harms. LkSG Section 3 creates legal obligations that are enforceable by the Federal Office of Economics and Export Control (BAFA). Both require audit-trail documentation of due diligence decisions. The contract clauses you need include: ESG minimum standards, audit rights, Scope 3 data provision obligations, modern slavery flow-down requirements, and corrective action obligations with defined timelines. These need to be written into supplier contracts, not just referenced in a supplier code of conduct.
Neotas provides intelligence-led ESG supply chain assessment for procurement, compliance, and legal teams. Rated in the Chartis FCC50 as a leading financial crime compliance technology provider, Neotas specialises in the intelligence layer that questionnaire-only and database-only programmes cannot reach.
| Capability | ESG pillar addressed | What it delivers |
|---|---|---|
| Adverse media screening (200+ languages) | E, S and G | Surfaces ESG incidents in regional press, emerging media, and non-English language sources before they reach global visibility or structured databases |
| Beneficial ownership and sanctions investigation | G | Multi-layer corporate structure investigation, OFAC/UN/EU sanctions screening, PEP identification, UFLPA entity list verification |
| Sub-tier OSINT sourcing investigation | E and S | Open-source investigation of Tier 2 and Tier 3 suppliers, raw material origins, and sub-contractor labour conditions in high-risk commodity categories |
| Continuous monitoring and automated alerts | E, S and G | Automated adverse media, sanctions, enforcement, and financial distress alerts for Critical and High-tier suppliers. Closes the annual-review gap. |
| Modern Slavery Act and UFLPA compliance support | S | Supplier screening against ILO standards, UFLPA entity list, DHS enforcement database; Modern Slavery Act statement evidence gathering and gap analysis |
Build an ESG supply chain programme that satisfies regulators and protects the business
Our intelligence-led ESG supply chain assessments cover all three ESG pillars, all five major regulatory frameworks, and go beyond Tier 1 questionnaires to surface the sub-tier risks that produce the most costly supply chain incidents. Chartis FCC50 recognised.
Rated Chartis FCC50 · Assessment findings within 5 working days · No commitment required
Understanding which specific risks sit in each ESG pillar is the first step in building an assessment framework that a regulator, investor, or customer would accept. The following breaks each category into its supply chain risk types, assessment criteria, and the regulatory frameworks that govern it.
Carbon emissions, resource use, waste, deforestation, water
Key supply chain risks
Assessment criteria
Labour rights, modern slavery, health and safety, community impact
Key supply chain risks
Assessment criteria
Corruption, bribery, sanctions exposure, beneficial ownership, ethics
Key supply chain risks
Assessment criteria
Governing frameworks
The intelligence gap that questionnaires cannot close
Standard supplier questionnaires capture what a supplier chooses to disclose. They cannot surface emerging adverse media in regional press, beneficial ownership arrangements that create sanctions exposure, ESG violations at Tier 2 and Tier 3 manufacturers, or financial distress signals before they become public. These are the risk categories that produce the most costly supply chain incidents. Intelligence-led assessment closes this gap by going beyond self-disclosure to verified, multi-source investigation.
The regulatory landscape for ESG supply chain due diligence has shifted from voluntary to mandatory across major trading jurisdictions. Each framework imposes its own scope, obligations, and penalty structure. The table below gives a compliance-ready overview of the five frameworks your programme must account for.
| Regulation | Jurisdiction | In-scope companies | Supply chain obligation | Penalty |
|---|---|---|---|---|
| EU CSDDD [1] | EU (27 member states) | Large EU companies + non-EU companies with substantial EU revenue. Thresholds subject to Omnibus amendment: verify at official EU source. | Identify, prevent, mitigate, and account for adverse human rights and environmental impacts across the full supply chain and business relationships | Up to 5% of global net turnover |
| German LkSG [2] | Germany | Companies with 1,000+ employees in Germany (since 1 Jan 2024) | Risk analysis, preventive and remedial action, grievance procedure, reporting for direct and indirect suppliers | Up to 2% of global annual turnover (or up to €800,000 for smaller companies). Procurement ban for 3 years possible. |
| UK Modern Slavery Act [3] | UK | Organisations with £36M+ annual turnover supplying goods or services in the UK | Annual transparency statement disclosing steps to identify and address modern slavery across supply chains and operations | Court injunctions; Home Office naming and shaming; reputational damage. Director liability possible. |
| US UFLPA [7] | United States | All US importers; applies to goods with any Xinjiang-origin component | Rebuttable presumption of forced labour for Xinjiang-origin goods. Must rebut presumption with documented evidence to import. | Shipment detention and import ban. Entity list exposure. |
| EU CSRD [6] | EU (27 member states) | Large EU companies and listed SMEs (phased in from 2024 to 2028) | Mandatory sustainability reporting including Scope 3 supply chain emissions, social impacts, and governance disclosures using ESRS standards | Member state penalties; financial market and investor consequences. |
Multi-jurisdiction exposure is cumulative, not sequential
A company exporting goods to the EU from the US with German corporate customers and UK suppliers may face simultaneous obligations under CSDDD, LkSG, UFLPA, and the UK Modern Slavery Act. These frameworks have different scope definitions, different evidence requirements, and different enforcement timelines. A programme designed to satisfy only one does not satisfy the others. If your supply chain compliance programme was built before CSDDD was enacted in 2024 or before LkSG expanded to 1,000+ employees in January 2024, it was designed for a regulatory landscape that no longer exists. A programme gap review takes 30 minutes. Contact Neotas to schedule one.
Related: ESG supply chain assessment guide | Enhanced due diligence services | Vendor due diligence services
Neotas — Rated Chartis FCC50
Most ESG programmes satisfy one jurisdiction and miss the others. Neotas runs intelligence-led supply chain assessments that cross-reference all five major regulatory frameworks, go beyond Tier 1 vendor questionnaires, and deliver findings within 5 working days.
A supplier ESG risk assessment is not a questionnaire. A questionnaire is a data collection tool; the assessment is the analytical process that turns data into a risk-rated, auditable conclusion. These five steps describe what a complete supplier ESG risk assessment looks like when it is built to satisfy OECD Due Diligence Guidance standards [11] and stand up to regulatory scrutiny.
Classify the supplier by risk tier before applying any assessment
Tiering logic must be specific to your supply chain, not copied from a generic framework. Risk tier criteria for ESG include: sourcing country (is it on a high-risk jurisdiction list for labour violations, environmental enforcement gaps, or sanctions?), commodity type (does it carry known ESG risk patterns, such as cotton from Central Asia, electronics with rare-earth minerals, or agricultural products from deforestation-risk regions?), contract value and clinical criticality, and Tier level in your supply chain. A Tier 1 distributor in Germany is a different ESG risk profile from a Tier 3 raw material supplier in a jurisdiction with no environmental enforcement. They need different assessment methodologies.
Run a pre-screening before the questionnaire
Sanctions and PEP screening, adverse media in 200+ languages, beneficial ownership check against OFAC, UN and EU consolidated lists, UFLPA entity list verification, and public regulatory enforcement database searches. This pre-screening serves two purposes: it surfaces risks the supplier would not disclose in a questionnaire, and it prevents you from onboarding a supplier whose ESG profile is already documented as problematic. The Neotas EDD checklist covers the specific data sources required for each pre-screening category.
Issue a risk-tiered ESG due diligence questionnaire (DDQ)
One questionnaire for all suppliers is a programme design failure. High-risk suppliers need a DDQ that covers all three ESG pillars in depth, requests certified documentation, and asks specific questions about sub-tier sourcing. Standard-risk suppliers need a lighter DDQ focused on the highest-materiality risk for their category. The questionnaire should not only collect policy documents but request evidence: audit certificates, ISO certification numbers, signed modern slavery statements, GHG emissions data with methodology disclosure, and sub-tier supplier names for high-risk commodity categories. Require a response to every question. Treat non-responses as a risk signal, not a gap to carry forward.
Conduct enhanced ESG due diligence for high-risk and critical-tier suppliers
Enhanced due diligence goes beyond the questionnaire to verify claims, surface undisclosed information, and map sub-tier risk. For high-risk suppliers this includes: OSINT investigation of corporate structure, beneficial ownership, and regulatory enforcement history; adverse media analysis covering emerging sources and regional press in the supplier’s primary operating country; financial health screening for distress signals; and where feasible, on-site audits or third-party site verification. The Neotas OSINT platform conducts this intelligence layer across 200+ data sources and languages. Findings that differ materially from questionnaire disclosures go to remediation planning before contract execution.
Assign an ESG risk rating, document the rationale, and set the monitoring cadence
A supply chain ESG risk rating is only defensible if the underlying methodology is documented. Rate suppliers on a consistent scale (three or four tiers: Critical, High, Medium, Low) and record the specific findings that drove each rating. Embed the rating in the contract. Set corrective action plans with timelines for any finding above your acceptable threshold. Establish the monitoring cadence based on rating: Critical-tier suppliers monthly or continuously; Standard-tier suppliers annually. The rating and methodology must be reproducible for a regulator or auditor who asks to inspect your supply chain due diligence records.
ESG supply chain due diligence is a continuous process across the full vendor lifecycle, not a one-time pre-contract exercise. The OECD Due Diligence Guidance for Responsible Business Conduct [11] and the UN Guiding Principles on Business and Human Rights [10] both define it this way. Regulators enforcing CSDDD and LkSG are using the same framework. These are the practices that separate a programme built for compliance from one built to survive a regulatory examination.
Embed ESG criteria at the RFP stage
Include ESG performance scoring in all tender evaluations. Set minimum ESG thresholds as a pass/fail criterion, not a weighted preference. A supplier that fails the ESG threshold should not be awarded a contract regardless of price competitiveness.
Embed ESG contractual obligations from day one
Supply contracts must include: ESG minimum standards with specific measurable thresholds, right to audit ESG compliance, reporting obligations including Scope 3 data provision, corrective action timelines, and contract termination rights for material ESG violations.
Go to the sub-tier, not just Tier 1
The most significant ESG risks in most supply chains sit at Tier 2 and Tier 3. A programme that only assesses direct suppliers misses the raw material sourcing, the component manufacturing conditions, and the logistics sub-contractors where forced labour, environmental violations, and governance failures are most likely to sit.
Replace annual reviews with continuous monitoring for high-risk suppliers
ESG risks emerge and escalate between annual review cycles. Automated monitoring for adverse media alerts, sanctions list changes, regulatory enforcement actions, and financial distress signals gives procurement teams the lead time to act before a supplier failure becomes an operational crisis.
Document everything with audit trail logic
CSDDD and LkSG both require companies to be able to demonstrate their due diligence process to national supervisory authorities. Every assessment decision, every corrective action, every reassessment must be timestamped and retained. A programme that exists but cannot be evidenced is legally equivalent to no programme.
Establish a grievance mechanism
LkSG (Section 8) and CSDDD both require companies to have an accessible grievance or complaints mechanism through which workers in the supply chain and other affected parties can report ESG violations. This is a legal requirement, not a best-practice option.
The metrics you collect from suppliers determine whether your ESG programme produces actionable intelligence or just documentation. These are the ESG metrics that carry real risk signal value, the regulatory frameworks that require them, and the data quality standard you need from suppliers to use them meaningfully.
| ESG pillar | Metric | What it signals | Regulatory relevance | Data quality standard |
|---|---|---|---|---|
| Environmental | GHG emissions (Scope 1, 2, and 3 by category) | Carbon footprint of your supply chain; Scope 3 Category 1 and 4 most material for most buyers | CSRD (ESRS E1); CSDDD; SBTi supply chain requirements | GHG Protocol methodology disclosure required. Accept ISO 14064 or third-party verified data. |
| Environmental | Environmental enforcement and violation history | Pattern of regulatory non-compliance; facility shutdown risk; reputational exposure | CSDDD; LkSG | Independent OSINT verification required. Questionnaire self-disclosure alone insufficient. |
| Social | Modern Slavery Act transparency statement | Whether supplier has mapped and addressed modern slavery risk in its own supply chain | UK Modern Slavery Act 2015 (for suppliers above £36M turnover) | Verify on the UK Modern Slavery Statement Registry. Do not accept unsigned or undated statements. |
| Social | Labour practice certification (SA8000, ILO compliance) | Formal evidence of fair labour, health and safety, and worker rights standards | CSDDD human rights chapter; LkSG; UN Guiding Principles | Require current certificate with issuing body name and expiry date. Verify independently. |
| Social | UFLPA entity list status and Xinjiang sourcing disclosure | Forced labour exposure and US customs import compliance risk | UFLPA (US); DHS UFLPA Entity List [9] | Check against current DHS entity list. Require supply chain mapping to origin for Chinese commodity categories. |
| Governance | Beneficial ownership disclosure (UBO level) | Sanctions exposure, PEP connections, conflict-of-interest arrangements in ownership structure | LkSG; UK Bribery Act; US FCPA; CSDDD governance chapter | OSINT multi-layer corporate structure investigation required. Self-disclosure is insufficient for high-risk suppliers. |
| Governance | ABAC policy and enforcement evidence | Risk of bribery in procurement, permit acquisition, and contract management | UK Bribery Act; US FCPA; OECD Anti-Bribery Convention | Require signed ABAC policy with training records. Adverse media investigation for bribery incidents supplements. |
Data quality matters as much as data collection. An ESG metric that is self-reported, unverified, and three years old does not satisfy the evidentiary standard that CSDDD and LkSG require. For each high-risk supplier, require a methodology disclosure alongside the metric, a verification status (third-party assured, self-reported, or estimated), and a measurement date. Without these three fields, the data cannot drive a defensible risk decision.
Ready to future-proof your supply chain with ESG risk assessments?
Start today with our free ESG Supply Chain Risk Template – your first step towards sustainable, compliant, and resilient operations.
ESG Risk in the Supply Chain & the Rising Trend of ESG Compliance
The full supply chain risk management guide covering 9 risk categories, 5-stage assessment process, fourth-party risk, and how ESG integrates into the broader SCRM framework.
A complete vendor risk assessment template covering risk tiering logic, DDQ structure, ESG assessment criteria, financial screening, cybersecurity, and ongoing monitoring protocols.
How ESG supply chain risk management applies to pharmaceutical supply chains, medical device procurement, and health system vendor assessment. Covers UFLPA pharma exposure, Modern Slavery Act for NHS, and FDA DSCSA traceability.
How intelligence-led EDD surfaces ESG risks that questionnaire-only programmes structurally cannot detect, including adverse media in 200+ languages, sub-tier sourcing investigation, and beneficial ownership opacity.
How Neotas delivers vendor Due Diligence assessments combining OSINT, financial health screening, adverse media in 200+ languages, sanctions and PEP screening, and beneficial ownership investigation.
The foundational TPRM guide: the 7-stage lifecycle, regulatory requirements across DORA, FCA, OCC, and CMS, risk categories, maturity model, and best practices. The framework within which ESG supply chain assessment sits.
How open-source intelligence is applied to ESG supply chain screening: adverse media in 200+ languages, regulatory enforcement research, sub-tier supplier investigation, and beneficial ownership analysis.
How AML, KYC, and sanctions screening intersects with ESG supply chain governance risk: bribery exposure, beneficial ownership opacity, sanctions evasion through supply chain structures, and ABAC compliance.
Through our advanced ESG Due Diligence and Supply Chain Risk Assessment platform, organisations can systematically uncover hidden risks across vendors, suppliers, and third parties — well beyond surface-level checks. We join the dots between Corporate Records, Adverse Media, and Open Source Intelligence (OSINT), helping you make informed, defensible decisions while safeguarding your operations against ESG breaches.
✅ Strengthen vendor onboarding and monitoring processes with precision
✅ Ensure ESG compliance and ethical sourcing across your global supply chain
✅ Reduce reputational, operational, and regulatory risks through early risk detection
The Neotas platform also automates supplier assessments, enabling businesses to onboard new vendors with confidence, speed, and full ESG alignment.
Our customisable dashboards offer real-time visibility into supplier ESG risks, seamlessly integrating into your existing CRM, ERP, or Supply Chain Management (SCM) systems. This ensures that ESG risk management becomes an embedded, proactive part of your procurement and supply chain strategy — not an afterthought.
Let’s Talk!
If you are exploring how to strengthen ESG compliance across your supply chain and reduce third-party risks, we are here to support you.
🗓️ Schedule a Call with our experts today — let’s help you build a more transparent, resilient, and future-ready supply chain.
Strengthen Your ESG Compliance and Safeguard Your Supply Chain with Neotas
Neotas offers an advanced ESG Due Diligence and Supply Chain Risk Assessment solution, powered by AI-driven insights. Our platform intelligently connects Corporate Records, Adverse Media, and Open Source Intelligence (OSINT) to uncover hidden risks that traditional checks often miss.
✅ Conduct deeper ESG assessments across your supply chain
✅ Identify third-party risks early and act proactively
✅ Ensure compliance with emerging global ESG regulations
✅ Build a more resilient, transparent, and sustainable supply chain🗓️ Schedule a Call to discover how Neotas can help you embed ESG best practices and strengthen your supply chain risk management strategy.
Neotas Enhanced Due Diligence covers 600Bn+ Archived web pages, 1.8Bn+ court records, 198M+ Corporate records, Global Social Media platforms, and more than 40,000 Media sources from over 100 countries to help you screen & manage risks.
We leverage Open source intelligence (OSINT) to use publicly available data to provide organisations with hyper-accurate and fully auditable insights with no false positives.
Improve analyst efficiencies, including cost and time reduction of minimum 25% with zero false positives.
The FCA recommends open source Internet checks as best practice (FG 18/5). Manage and reduce risk by incorporating 100% of online sources into your processes.
Manage risk with hyper accurate ongoing monitoring. We will monitor 100% of publicly available online data to help identify relevant risks.
| Cookie | Duration | Description |
|---|---|---|
| AWSALBTG | 7 days | AWS Application Load Balancer Cookie. Load Balancing Cookie: Used to encode information about the selected target group. |
| AWSALBTGCORS | 7 days | AWS Classic Load Balancer Cookie: Used to map the session to the instance. This cookie is identical to the original ELB cookie except for the attribute &SameSite=None; |
| cookielawinfo-checkbox-advertisement | 1 year | Set by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category . |
| cookielawinfo-checkbox-analytics | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics". |
| cookielawinfo-checkbox-functional | 11 months | The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional". |
| cookielawinfo-checkbox-necessary | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary". |
| cookielawinfo-checkbox-others | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other. |
| cookielawinfo-checkbox-performance | 11 months | This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance". |
| CookieLawInfoConsent | 1 year | Records the default button state of the corresponding category & the status of CCPA. It works only in coordination with the primary cookie. |
| debug | never | Cookie used to debug code and website issues |
| shown | session | Session cookie to control number of times a pop up is shown. |
| viewed_cookie_policy | 11 months | The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data. |
| Cookie | Duration | Description |
|---|---|---|
| __cf_bm | 30 minutes | This cookie, set by Cloudflare, is used to support Cloudflare Bot Management. |
| AnalyticsSyncHistory | 1 month | Used to store information about the time a sync took place with the lms_analytics cookie |
| bcookie | 2 years | LinkedIn sets this cookie from LinkedIn share buttons and ad tags to recognize browser ID. |
| bscookie | 2 years | LinkedIn sets this cookie to store performed actions on the website. |
| lang | session | LinkedIn sets this cookie to remember a user's language setting. |
| lidc | 1 day | LinkedIn sets the lidc cookie to facilitate data center selection. |
| UserMatchHistory | 1 month | LinkedIn sets this cookie for LinkedIn Ads ID syncing. |
| Cookie | Duration | Description |
|---|---|---|
| li_gc | 2 years | Used to store consent of guests regarding the use of cookies for non-essential purposes |
| rl_anonymous_id | 1 year | Generates an unique anonymous Id to identify a user and attach to a subsequent event. |
| rl_user_id | 1 year | to store a unique user ID for the purpose of Marketing/Tracking |
| Cookie | Duration | Description |
|---|---|---|
| _ga | 2 years | The _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors. |
| _gat_gtag_UA_107495977_1 | 1 minute | Set by Google to distinguish users. |
| _gat_UA-107495977-1 | 1 minute | A variation of the _gat cookie set by Google Analytics and Google Tag Manager to allow website owners to track visitor behaviour and measure site performance. The pattern element in the name contains the unique identity number of the account or website it relates to. |
| _gcl_au | 3 months | Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services. |
| _gid | 1 day | Installed by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously. |
| attribution_user_id | 1 year | This cookie is set by Typeform for usage statistics and is used in context with the website's pop-up questionnaires and messengering. |
| CONSENT | 2 years | YouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data. |
| Cookie | Duration | Description |
|---|---|---|
| _fbp | 3 months | This cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website. |
| fr | 3 months | Facebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin. |
| IDE | 1 year 24 days | Google DoubleClick IDE cookies are used to store information about how the user uses the website to present them with relevant ads and according to the user profile. |
| test_cookie | 15 minutes | The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies. |
| VISITOR_INFO1_LIVE | 5 months 27 days | A cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface. |
| YSC | session | YSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages. |
| yt-remote-connected-devices | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt-remote-device-id | never | YouTube sets this cookie to store the video preferences of the user using embedded YouTube video. |
| yt.innertube::nextId | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |
| yt.innertube::requests | never | This cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen. |