How to Manage ESG Supply Chain Risks

For many organisations, the most significant ESG risks they face are not in their own operations. They are in their supply chains. Emissions generated by suppliers producing goods and services account for the majority of most organisations' total carbon footprint. Labour standards violations and human rights abuses in supplier facilities create both direct ethical responsibility and considerable regulatory and reputational exposure. And mandatory human rights and environmental due diligence legislation is extending legal accountability explicitly to the value chain.
5 min read time

This is not a new problem, but the pressure to actually address it has intensified considerably. The EU's Corporate Sustainability Due Diligence Directive creates binding human rights and environmental due diligence obligations. CSRD requires detailed supply chain impact disclosure. And large buyers are increasingly flowing sustainability requirements down to their own suppliers, meaning that ESG supply chain performance is both something organisations need to manage for their own reporting and something they will increasingly be asked to demonstrate to their own customers.

Where the Risk Actually Sits

The Upstream Concentration Problem

The starting point for managing ESG supply chain risk is understanding where material exposures actually sit, because the intuitive answer, that risk is greatest with direct first-tier suppliers, is frequently wrong.

Environmental risk, particularly greenhouse gas emissions, often concentrates in upstream raw material extraction and processing, which may sit several tiers below direct suppliers. The GHG Protocol's Scope 3 category covering purchased goods and services is the single largest source of emissions for many organisations, and the emissions intensity of specific purchased inputs varies enormously depending on how and where they are produced.

Social risk, covering labour standards, health and safety, and human rights, tends to concentrate in lower-tier suppliers in higher-risk geographies rather than in the more sophisticated direct suppliers closer to the organisation. Supply chain audit programmes that only assess first-tier suppliers miss the majority of this exposure.

Governance Risk in the Supply Chain

Governance risk in supply chains involves the ethics and anti-corruption practices of suppliers, the quality of their own governance structures, and whether their compliance practices would create regulatory problems for an organisation associated with them. As supply chain due diligence obligations extend, the governance practices of suppliers become a compliance matter as well as a reputational one.

The Regulatory Context

CSDDD: The Binding Due Diligence Obligation

The EU's Corporate Sustainability Due Diligence Directive requires large companies to conduct due diligence to identify, prevent, and mitigate adverse human rights and environmental impacts across their own operations and value chains. After a series of amendments, the Directive applies to EU companies with more than 1,000 employees and net turnover above 450 million euros, as well as non-EU companies with significant EU turnover, with phased implementation beginning from 2027.

The CSDDD creates a legal obligation to act, not merely to report. Where adverse impacts are identified, companies must take preventive or corrective action, or if impacts cannot be mitigated, provide remediation. Companies must also have a transition plan aligned with the Paris Agreement's 1.5 degree pathway.

CSRD Supply Chain Disclosure

CSRD requires disclosure of the organisation's approach to supply chain due diligence, including policies, processes, and outcomes related to human rights and environmental impacts across the value chain. This disclosure requirement means even organisations not directly subject to CSDDD may face supply chain reporting expectations through their own CSRD obligations.

The UN Guiding Principles

The UN Guiding Principles on Business and Human Rights remain the internationally recognised framework for human rights due diligence, describing the corporate responsibility to respect human rights as a due diligence process covering impact identification, prevention, mitigation, and remediation. CSDDD was explicitly designed to operationalise the UNGPs through binding legislation.

Building a Supplier ESG Assessment Programme

Risk-Tiered Assessment

Most organisations need to approach supplier ESG assessment in a risk-tiered way. Assessing every supplier with equal depth is impractical and, given resource constraints, tends to mean either everything gets superficial attention or the programme stalls entirely.

A tiered approach starts by identifying which suppliers carry the most material ESG risk, based on the nature of what they supply, the geography and jurisdiction they operate in, the labour intensity of their business, and their position in the supply chain relative to higher-risk processes and inputs. Even a rough categorisation of suppliers into higher, medium, and lower risk tiers allows due diligence effort to be directed where it matters most.

What Assessment Should Cover

For higher-risk suppliers, assessment should cover:

Environmental practices, including emissions management, energy sourcing, water use, waste management, and any environmental incidents or violations.

Labour standards, covering working hours, wages relative to local living wage benchmarks, freedom of association, health and safety performance, and absence of forced or child labour.

Human rights policies and implementation, covering the supplier's own due diligence processes, grievance mechanisms, and track record on human rights.

Governance and ethics, covering anti-corruption practices, regulatory compliance history, and the supplier's own approach to managing risks in its supply chain.

Self-assessment questionnaires provide a starting point. The GRI Standards on supplier social assessment and supplier environmental assessment provide a widely used reference for what questions to ask. For the highest-risk relationships, independent verification through audit or third-party assessment adds credibility that self-reporting alone cannot provide.

Turning Assessment Into Action

Using Findings to Drive Commercial Decisions

Assessment data is only valuable if it informs decisions and drives improvement. A supplier with material, unaddressed ESG failures should face consequences: a remediation requirement with a defined timeline, a decision to reduce dependency on that supplier, or in serious cases, exit from the relationship.

If assessment results consistently have no practical implications for the commercial relationship, the programme loses credibility with both suppliers and internal stakeholders. The test of a functioning ESG supply chain programme is whether findings change what happens, not whether findings are documented.

Engagement vs Enforcement

Supplier engagement, providing guidance and support for improvement rather than pure compliance enforcement, tends to produce better outcomes for most supplier relationships. Smaller suppliers in particular may lack the knowledge or resources to address ESG issues without guidance. Treating due diligence as purely extractive, demanding data without reciprocal engagement, produces low-quality responses and does not improve actual ESG performance in the supply chain.

This does not mean abandoning enforcement. Where serious issues are identified, especially evidence of forced labour, child labour, or significant environmental harm, there must be a clear process for what happens next, including defined escalation paths, decision-making authorities, and thresholds for supplier exit.

Embedding ESG Into Procurement

Sustainability as a Procurement Criterion

The most durable ESG supply chain programmes are those where sustainability considerations are embedded into how procurement works day to day, rather than existing as a separate assessment exercise with limited connection to commercial decisions.

Practically this means ESG factors appearing in tender evaluation criteria alongside cost, quality, and delivery. It means contract terms including minimum ESG standards and audit rights. It means procurement teams having enough ESG literacy to understand what supplier responses mean and to ask appropriate follow-up questions.

Connecting to the Risk Framework

Supply chain ESG risk belongs in the organisation's enterprise risk register, not only in a sustainability programme. Risks that are significant enough to affect the supply chain's ability to deliver, to create regulatory exposure, or to produce reputational damage are material organisational risks. The risk function and the sustainability function need to work together to ensure supply chain ESG findings reach the governance level where they can influence decisions.

References and Further Reading

Next Steps

Confident about the ESG risks sitting in your supply chain?

GreenFeet powered by calQrisk helps you map, assess and evidence supplier ESG risk across the value chain.
Book a Demo