GreenScore
Supply Chain

How to Conduct an ESG Vendor Due Diligence Process

A practical guide to building an ESG vendor due diligence process that helps mid-market companies assess supplier risk, document findings, and act on issues.

GreenScore TeamSeptember 12, 20269 min read
Procurement and ESG leaders reviewing supplier due diligence risk data on a dashboard
A risk-based ESG vendor due diligence process helps teams assess suppliers consistently.

For many mid-market companies, ESG risk does not start inside the four walls of the business. It starts across the vendor base: contract manufacturers, logistics partners, facilities providers, staffing firms, packaging suppliers, IT vendors, and other third parties that influence emissions, labor practices, business continuity, and brand exposure.

That is why an ESG vendor due diligence process is becoming a core operating requirement, not a nice-to-have procurement exercise. Customers increasingly ask how companies evaluate supplier practices. Investors want to understand third-party exposure. Regulators are raising expectations around transparency, governance, and value chain impacts. And internal teams need a more consistent way to separate low-risk vendors from those that require deeper scrutiny.

The challenge is that many companies still handle vendor ESG review through ad hoc questionnaires, scattered spreadsheets, and one-off escalations. That approach creates inconsistent decisions, weak documentation, and avoidable surprises during reporting season.

This guide explains how to build a practical ESG vendor due diligence process for a mid-market organization. It focuses on a workflow that procurement, legal, compliance, finance, and sustainability teams can actually run at scale. If you are building a broader program, start with this complete guide to ESG reporting for additional context on frameworks, governance, and disclosure expectations.

What ESG vendor due diligence means

ESG vendor due diligence is the structured process of evaluating a current or prospective vendor for environmental, social, and governance risks before and during the business relationship.

In practice, that means gathering relevant information, rating risk, identifying red flags, documenting decisions, and defining follow-up actions. The goal is not to make every supplier perfect. The goal is to apply a proportionate, defensible review process that helps your company:

  • Identify third-party risks before they become operational or reputational issues
  • Prioritize higher-risk vendors for deeper review
  • Support customer, investor, and board questions with documented evidence
  • Improve the quality of upstream ESG and emissions data
  • Show a credible process for ongoing oversight and remediation

An effective process should align with recognized concepts from sources such as the GHG Protocol, the Global Reporting Initiative, and the EU CSRD, especially where value chain impacts and governance are concerned.

Why mid-market companies need a formal process

Large enterprises have been building third-party risk programs for years. Mid-market companies are now feeling similar pressure, but usually with leaner teams and less mature systems. A formal process matters because supplier ESG review now affects multiple business priorities at once.

Customer and investor expectations are rising

B2B customers increasingly ask suppliers to explain labor standards, emissions practices, human rights policies, data security governance, and incident history. Investor diligence has also broadened beyond direct operations to include supply chain exposure. If your company cannot explain how it vets key vendors, that gap can weaken trust.

Regulatory pressure is moving into the value chain

Even when a company is not directly in scope for every disclosure regime, market expectations travel downstream. Companies subject to formal reporting rules ask their suppliers for better data and stronger controls. Vendors that cannot respond may lose business or face increased scrutiny.

Procurement decisions create reporting consequences

Vendor selection affects Scope 3 emissions, supply continuity, social risk, and governance quality. Without due diligence, procurement may optimize for price and lead time while unintentionally increasing ESG exposure. A documented process helps teams make trade-offs more consciously.

Which vendors should go through ESG due diligence

Not every vendor needs the same level of review. A small software subscription and a high-spend overseas manufacturer should not receive identical scrutiny. The most efficient approach is risk-based segmentation.

Start by grouping vendors using factors such as:

  • Spend: annual contract value or total business volume
  • Criticality: how important the vendor is to operations, revenue, or customer delivery
  • Geography: countries or regions with elevated labor, environmental, or corruption risk
  • Category risk: sectors with known issues such as manufacturing, apparel, agriculture, mining, logistics, staffing, or waste management
  • Data relevance: whether the vendor provides emissions or ESG data used in reporting
  • Customer sensitivity: whether the vendor supports a product, service, or account with heightened ESG expectations

If your team is still mapping supplier exposure, a structured supply chain ESG risk assessment can help identify where deeper diligence will matter most.

Vendor tierTypical profileRecommended ESG review
Tier 1High spend, operationally critical, elevated geography or category riskFull questionnaire, policy review, evidence request, risk scoring, remediation plan, annual refresh
Tier 2Moderate spend or moderate category riskStandard questionnaire, targeted evidence for flagged areas, review every 1-2 years
Tier 3Low spend, low criticality, low inherent riskBasic screening, code of conduct acknowledgment, review on exception

This tiering model helps companies avoid overengineering low-risk relationships while still showing a disciplined approach.

The core steps in an ESG vendor due diligence process

A strong process is repeatable, documented, and easy for cross-functional teams to follow. The steps below work well for most mid-market companies.

Step 1: Define your risk criteria

Before sending questionnaires, decide what your company actually cares about. Your criteria should reflect your industry, operating model, stakeholder expectations, and reporting obligations.

Common ESG risk areas include:

  • Energy use and greenhouse gas emissions
  • Waste, water, hazardous materials, and pollution controls
  • Workforce health and safety
  • Forced labor, child labor, and working conditions
  • Diversity, equity, and inclusion practices
  • Ethics, anti-bribery, and whistleblower mechanisms
  • Data privacy and cybersecurity governance
  • Board oversight, policy management, and incident response

Keep the criteria practical. If a factor will never influence a decision or escalation, it may not belong in your first version.

Step 2: Build a tiered questionnaire

Create a base questionnaire for all in-scope vendors and a deeper set of questions for higher-risk vendors. This keeps response burden proportionate.

Your questionnaire should ask for a mix of:

  • Binary disclosures, such as whether a policy exists
  • Quantitative data, such as emissions or injury rates where relevant
  • Narrative explanations of governance and controls
  • Supporting documents, such as policies, certifications, or audit summaries

Avoid writing a survey that tries to replicate every framework at once. The best questionnaires are concise enough to complete and specific enough to support decisions.

Step 3: Screen for red flags

Once responses are submitted, review them for immediate concerns. Examples include missing policies in a high-risk category, unresolved labor allegations, environmental violations, refusal to provide data, or repeated answers that are clearly generic and unsupported.

At this stage, the objective is fast triage. Determine whether the vendor can proceed, needs clarification, or should move into an escalated review path.

Step 4: Score the risk

Use a simple scoring model that combines inherent risk and control strength. For example, a manufacturer in a high-risk geography may have high inherent risk, but strong policies, audit evidence, and certifications could reduce residual risk.

Good scoring models are:

  • Transparent enough that non-specialists can understand them
  • Consistent across vendors
  • Flexible enough to account for business context
  • Documented so decisions can be defended later

If the vendor also contributes to your emissions inventory, align this work with your carbon data approach. Teams often pair diligence with tools such as a carbon footprint calculator to improve supplier data capture and screening.

Step 5: Decide: approve, escalate, or remediate

Not every issue should block onboarding. The better model is to set clear decision paths:

  • Approve: low residual risk or acceptable controls
  • Approve with conditions: minor gaps with a defined remediation timeline
  • Escalate: significant concerns needing legal, compliance, or executive review
  • Decline: unacceptable risk, repeated non-cooperation, or severe unresolved issues

Document both the rationale and the owner for next steps. That record matters later when customers, auditors, or leadership ask why a vendor was accepted.

Step 6: Monitor on an ongoing basis

Due diligence is not a one-time event. Vendors change ownership, expand into new regions, experience incidents, or fall behind on corrective actions. Build refresh cycles based on vendor tier and trigger event reviews when something material changes.

Many teams miss this step and end up with stale vendor files that provide little real protection.

What good ESG vendor questionnaires include

A practical questionnaire should focus on decision-useful information. It does not need to be long, but it must cover the highest-value signals.

Environmental topics

  • Does the vendor measure greenhouse gas emissions?
  • Does it have emissions reduction targets or energy management practices?
  • Are there known environmental fines, spills, or permit violations?
  • What waste, water, or hazardous materials controls exist where relevant?

Social topics

  • Are there policies on labor standards, modern slavery, and human rights?
  • How does the vendor manage worker health and safety?
  • Are there grievance or whistleblower channels?
  • Has the vendor experienced recent labor controversies or legal findings?

Governance topics

  • Is there a code of conduct or ethics policy?
  • What anti-bribery and corruption controls are in place?
  • Who oversees ESG or compliance matters internally?
  • How are incidents investigated and reported?

Where possible, ask for evidence rather than accepting policy claims at face value. A certificate, summary report, or management attestation is often more useful than a simple yes or no.

Common mistakes that undermine vendor ESG review

Many due diligence programs fail not because the intent is wrong, but because the design is too theoretical or too burdensome.

Mistake 1: Treating all vendors the same

A one-size-fits-all review wastes time on low-risk vendors and still misses nuance in high-risk categories. Risk tiering is essential.

Mistake 2: Collecting data without a decision model

If no one knows what counts as a red flag or what triggers escalation, questionnaires become administrative paperwork. Define thresholds and outcomes before rollout.

Sustainability teams rarely control supplier onboarding on their own. Procurement and legal must be part of the process so ESG review influences contracts, approvals, and remediation commitments.

Mistake 4: Failing to store evidence systematically

Scattered documents make it hard to respond to customer requests or prove that a review happened. Centralized documentation improves both efficiency and defensibility. Many mid-market teams move this work into dedicated ESG reporting software so vendor data, evidence, and follow-up actions are not trapped in inboxes and spreadsheets.

Mistake 5: Never refreshing the review

An onboarding questionnaire from two years ago does not reflect current risk. Establish refresh periods and trigger-based reassessments.

How to govern the process across teams

The most effective ESG vendor due diligence processes are cross-functional by design. Each function should have a clear role.

FunctionPrimary role
ProcurementInitiates review, collects vendor information, tracks onboarding requirements
Sustainability/ESGDefines criteria, reviews ESG responses, advises on risk significance
Legal/ComplianceAssesses regulatory exposure, contract clauses, escalations, and remediation terms
FinanceEvaluates spend significance, investor sensitivity, and control implications
Operations/Business ownerAssesses criticality, feasibility of alternatives, and operational impact

Governance does not need to be bureaucratic. In many mid-market companies, a monthly review meeting for high-risk vendors is enough, provided the escalation path is clear and decisions are documented.

If your broader ESG operating model is still maturing, using a central system like the GreenScore ESG platform can help connect vendor review, evidence management, and reporting outputs in one place.

How to measure whether the process is working

If you want the process to last, show that it improves outcomes. Track a small set of performance indicators from the start.

Useful metrics include:

  • Percentage of in-scope vendors reviewed before onboarding
  • Percentage of high-risk vendors with completed remediation plans
  • Average cycle time from questionnaire sent to decision
  • Percentage of vendors providing required evidence
  • Number of escalations by risk theme
  • Percentage of vendor emissions data received on time where relevant

These measures help leadership see whether the process is merely collecting information or actually reducing risk and improving reporting readiness.

Practical tip: In year one, prioritize consistency over complexity. A simple, repeatable process with documented decisions is far more valuable than an ambitious framework that teams cannot maintain.

Conclusion

An ESG vendor due diligence process helps mid-market companies bring discipline to one of the most important and least controlled parts of ESG risk: the third-party ecosystem. Done well, it improves supplier transparency, supports compliance, strengthens reporting, and gives procurement teams a clearer basis for decision-making.

The key is to keep it risk-based and operational. Segment vendors, ask focused questions, score the results consistently, document decisions, and refresh reviews over time. You do not need a massive enterprise program to get started. You need a process that the business can run reliably and defend when stakeholders ask hard questions.

If you want to assess how prepared your company is for supplier ESG review, reporting, and compliance workflows, start with our free ESG readiness assessment.

#esg due diligence#vendor risk#supplier esg#supply chain compliance#third-party risk#procurement

Frequently Asked Questions

Ready to simplify your ESG reporting?

Take our free ESG readiness assessment and see where your company stands.

No credit card required. Takes less than 2 minutes.