Person
Person

Jul 27, 2026

Supplier Sustainability Assessment Checklist

ESG Strategy

In This Article

Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.

Supplier Sustainability Assessment Checklist

If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.

This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.

A few points stand out fast:

  • Supply chain emissions can be far above a company’s own direct emissions.

  • U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.

  • The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.

  • A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.

  • A supplier review only matters if it leads to clear actions, due dates, and proof of closure.

Here’s the article in one view:

  • Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.

  • Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.

  • Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.

  • Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.

The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process

Supplier Sustainability Assessment: 4-Step Repeatable Process

How to Use Claude in Excel for Supplier ESG Analysis

1. Assessment planning checklist

Start by locking scope and ownership so outreach goes only to the suppliers that matter most.

Set objectives, scope, and supplier tiers

Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.

Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:

  • Annual spend

  • Business criticality such as sole-source or critical-material suppliers

  • Geographic and sector risk

  • Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act

This helps you focus on the suppliers driving the most spend, risk, and emissions.

Assign each supplier to one of three tiers based on that review:

Tier

Supplier Type

Assessment Depth

Frequency

Tier 1

Strategic, high-spend, high-risk

Full ESG assessment + potential on-site audit

Annual

Tier 2

Operational, moderate risk

Standardized questionnaire + targeted document review

Every 2 years

Tier 3

Low-impact, low-risk

Basic compliance check + short questionnaire

Every 3 years

Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.

Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.

Choose assessment criteria, owners, and deadlines

Set your main assessment dimensions at the start:

  • Environmental: GHG emissions, energy use, water, waste

  • Social: labor practices, health and safety, freedom of association

  • Governance: anti-corruption policies, board oversight, reporting channels

  • Ethics: codes of conduct, OECD alignment

  • Supply-chain management: whether suppliers carry out their own supplier due diligence

Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.

Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.

Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.

With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.

2. Supplier outreach and data collection checklist

Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.

Send a clear outreach package

Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.

State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.

Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.

Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.

Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.

Request evidence and manage follow-up

Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.

Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:

Topic

Mandatory for All Tiers

Tier 1 Additional Requirements

Evidence to Request

Emissions & Energy

Do you measure Scope 1 and 2 emissions? (Yes/No)

Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals

GHG inventory, emissions methodology, utility records, SBTi validation

Waste & Circularity

Do you track total waste generated? (Yes/No)

Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products

Waste management records, recycling/recovery rates, circular design documentation

Water

Do you measure water withdrawal? (Yes/No)

Annual withdrawal and discharge volumes; water risk assessment

Water use records, discharge permits

Labor & Human Rights

Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment?

Workforce size; unionization status; sub-supplier labor oversight

HR policies, modern slavery statement, signed code of conduct

Health & Safety

Do you track workplace incidents? (Yes/No)

OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents

ISO 45001 certificate, OSHA logs, safety training records

Ethics & Governance

Written code of conduct and anti-corruption policy?

Board or executive ESG oversight; whistleblower mechanism

Anti-bribery policy, ethics hotline documentation, governance charter

Sub-Supplier Oversight

Do you assess your own suppliers' sustainability practices? (Yes/No)

Sub-tier supplier list; due diligence process description

Supplier code of conduct, sub-tier assessment records

Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.

When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.

Use complete submissions as the input for document review, scoring, and audit triggers.

3. Document review, scoring, and audit triggers checklist

Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.

Review policies, performance data, and supporting documents

For each document, start with three checks: recency, traceability, and alignment.

Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.

Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.

The table below shows what to collect and what to verify by topic area:

Review Area

Evidence to Verify

What to Verify

Environmental

Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data

Reporting period, source data, calculation method, audit trail

Water & Waste

Water and waste records, permits, corrective action plans from prior assessments

Current totals, disposal or discharge records, unresolved findings

Labor & Human Rights

Human rights and labor policy, code of conduct, corrective action plans

Policy currency, signed commitments, supplier oversight

Health & Safety

Health and safety metrics, audit reports, corrective action plans

Incident trends, lost-time events, open corrective actions

Ethics & Governance

Anti-corruption policy, governance documentation, third-party certifications

Policy currency, coverage, consistency with reported practices

Circularity

Recycled content data, take-back or reuse records, product design documents

Recycled content percentage, repairability, reuse programs

Build a weighted scorecard and define audit triggers

Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.

The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].

Scorecard Criterion

Weight

Scoring Basis

Automatic Trigger

Climate & Energy

30%

GHG inventory, target validation, renewable share

>10% year-over-year emissions increase with no reduction plan

Labor & Human Rights

25%

Policy currency, supplier oversight, workforce data

Any confirmed human rights violation

Ethics & Governance

20%

Anti-corruption policy, governance documentation, whistleblower mechanism

Missing anti-corruption policy

Circularity

15%

Recycled content, take-back participation, repairability

<5% recycled content where mandated

Risk Exposure

10%

Geographic risk, Tier 2/3 visibility, financial stability

No Tier 2 visibility

Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.

Trigger

Risk Level

Owner

Timeframe

Action

Score 80–100, no material issues

Low

Procurement

Annual review

Standard approval; schedule next assessment

Score 60–79 or incomplete documentation

Medium

Sustainability / Procurement

10 business days

Desktop review or virtual audit; request missing items

Score below 60 or repeated data gaps

High

Procurement + Sustainability

30 days

Mandatory corrective action plan; reassess after remediation

High-risk geography or spend above a defined threshold

Medium–High

Supply Chain Director

Annual

On-site audit for in-scope Tier 1 suppliers

Credible allegation of forced labor, child labor, or imminent safety risk

Critical

Legal + Compliance + Sourcing Leadership

Within 24 hours

Immediate escalation; sourcing halt pending investigation

Use these outcomes to set corrective actions and follow-up deadlines.

4. Improvement tracking and supplier development checklist

Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.

Set baselines, targets, and corrective actions

Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.

Set targets across four categories:

  • Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.

  • Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.

  • Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.

  • Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.

Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.

For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.

Monitor progress and link results to sourcing decisions

Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.

Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.

Supplier Name

Risk Tier

Key Findings (Latest Assessment)

Agreed Actions

Deadlines

Status

Score Trend






















Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.

Provide training, diagnostics, or co-investment only when they close a documented CAP item.

Conclusion: A repeatable supplier assessment process at a glance

This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.

The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.

Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.

FAQs

How do I choose supplier tiers?

Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.

Tier suppliers based on a few plain factors:

  • geographic risk

  • commodity type

  • spend volume

Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.

For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.

What proof should I ask suppliers for?

Ask for independently verifiable evidence based on risk, not just self-reported claims.

That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.

You might request:

  • Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade

  • Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs

  • Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures

Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.

For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.

When should a low score trigger an audit?

A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.

Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Jul 27, 2026

Supplier Sustainability Assessment Checklist

ESG Strategy

In This Article

Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.

Supplier Sustainability Assessment Checklist

If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.

This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.

A few points stand out fast:

  • Supply chain emissions can be far above a company’s own direct emissions.

  • U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.

  • The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.

  • A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.

  • A supplier review only matters if it leads to clear actions, due dates, and proof of closure.

Here’s the article in one view:

  • Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.

  • Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.

  • Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.

  • Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.

The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process

Supplier Sustainability Assessment: 4-Step Repeatable Process

How to Use Claude in Excel for Supplier ESG Analysis

1. Assessment planning checklist

Start by locking scope and ownership so outreach goes only to the suppliers that matter most.

Set objectives, scope, and supplier tiers

Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.

Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:

  • Annual spend

  • Business criticality such as sole-source or critical-material suppliers

  • Geographic and sector risk

  • Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act

This helps you focus on the suppliers driving the most spend, risk, and emissions.

Assign each supplier to one of three tiers based on that review:

Tier

Supplier Type

Assessment Depth

Frequency

Tier 1

Strategic, high-spend, high-risk

Full ESG assessment + potential on-site audit

Annual

Tier 2

Operational, moderate risk

Standardized questionnaire + targeted document review

Every 2 years

Tier 3

Low-impact, low-risk

Basic compliance check + short questionnaire

Every 3 years

Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.

Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.

Choose assessment criteria, owners, and deadlines

Set your main assessment dimensions at the start:

  • Environmental: GHG emissions, energy use, water, waste

  • Social: labor practices, health and safety, freedom of association

  • Governance: anti-corruption policies, board oversight, reporting channels

  • Ethics: codes of conduct, OECD alignment

  • Supply-chain management: whether suppliers carry out their own supplier due diligence

Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.

Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.

Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.

With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.

2. Supplier outreach and data collection checklist

Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.

Send a clear outreach package

Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.

State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.

Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.

Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.

Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.

Request evidence and manage follow-up

Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.

Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:

Topic

Mandatory for All Tiers

Tier 1 Additional Requirements

Evidence to Request

Emissions & Energy

Do you measure Scope 1 and 2 emissions? (Yes/No)

Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals

GHG inventory, emissions methodology, utility records, SBTi validation

Waste & Circularity

Do you track total waste generated? (Yes/No)

Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products

Waste management records, recycling/recovery rates, circular design documentation

Water

Do you measure water withdrawal? (Yes/No)

Annual withdrawal and discharge volumes; water risk assessment

Water use records, discharge permits

Labor & Human Rights

Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment?

Workforce size; unionization status; sub-supplier labor oversight

HR policies, modern slavery statement, signed code of conduct

Health & Safety

Do you track workplace incidents? (Yes/No)

OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents

ISO 45001 certificate, OSHA logs, safety training records

Ethics & Governance

Written code of conduct and anti-corruption policy?

Board or executive ESG oversight; whistleblower mechanism

Anti-bribery policy, ethics hotline documentation, governance charter

Sub-Supplier Oversight

Do you assess your own suppliers' sustainability practices? (Yes/No)

Sub-tier supplier list; due diligence process description

Supplier code of conduct, sub-tier assessment records

Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.

When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.

Use complete submissions as the input for document review, scoring, and audit triggers.

3. Document review, scoring, and audit triggers checklist

Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.

Review policies, performance data, and supporting documents

For each document, start with three checks: recency, traceability, and alignment.

Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.

Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.

The table below shows what to collect and what to verify by topic area:

Review Area

Evidence to Verify

What to Verify

Environmental

Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data

Reporting period, source data, calculation method, audit trail

Water & Waste

Water and waste records, permits, corrective action plans from prior assessments

Current totals, disposal or discharge records, unresolved findings

Labor & Human Rights

Human rights and labor policy, code of conduct, corrective action plans

Policy currency, signed commitments, supplier oversight

Health & Safety

Health and safety metrics, audit reports, corrective action plans

Incident trends, lost-time events, open corrective actions

Ethics & Governance

Anti-corruption policy, governance documentation, third-party certifications

Policy currency, coverage, consistency with reported practices

Circularity

Recycled content data, take-back or reuse records, product design documents

Recycled content percentage, repairability, reuse programs

Build a weighted scorecard and define audit triggers

Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.

The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].

Scorecard Criterion

Weight

Scoring Basis

Automatic Trigger

Climate & Energy

30%

GHG inventory, target validation, renewable share

>10% year-over-year emissions increase with no reduction plan

Labor & Human Rights

25%

Policy currency, supplier oversight, workforce data

Any confirmed human rights violation

Ethics & Governance

20%

Anti-corruption policy, governance documentation, whistleblower mechanism

Missing anti-corruption policy

Circularity

15%

Recycled content, take-back participation, repairability

<5% recycled content where mandated

Risk Exposure

10%

Geographic risk, Tier 2/3 visibility, financial stability

No Tier 2 visibility

Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.

Trigger

Risk Level

Owner

Timeframe

Action

Score 80–100, no material issues

Low

Procurement

Annual review

Standard approval; schedule next assessment

Score 60–79 or incomplete documentation

Medium

Sustainability / Procurement

10 business days

Desktop review or virtual audit; request missing items

Score below 60 or repeated data gaps

High

Procurement + Sustainability

30 days

Mandatory corrective action plan; reassess after remediation

High-risk geography or spend above a defined threshold

Medium–High

Supply Chain Director

Annual

On-site audit for in-scope Tier 1 suppliers

Credible allegation of forced labor, child labor, or imminent safety risk

Critical

Legal + Compliance + Sourcing Leadership

Within 24 hours

Immediate escalation; sourcing halt pending investigation

Use these outcomes to set corrective actions and follow-up deadlines.

4. Improvement tracking and supplier development checklist

Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.

Set baselines, targets, and corrective actions

Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.

Set targets across four categories:

  • Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.

  • Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.

  • Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.

  • Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.

Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.

For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.

Monitor progress and link results to sourcing decisions

Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.

Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.

Supplier Name

Risk Tier

Key Findings (Latest Assessment)

Agreed Actions

Deadlines

Status

Score Trend






















Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.

Provide training, diagnostics, or co-investment only when they close a documented CAP item.

Conclusion: A repeatable supplier assessment process at a glance

This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.

The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.

Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.

FAQs

How do I choose supplier tiers?

Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.

Tier suppliers based on a few plain factors:

  • geographic risk

  • commodity type

  • spend volume

Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.

For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.

What proof should I ask suppliers for?

Ask for independently verifiable evidence based on risk, not just self-reported claims.

That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.

You might request:

  • Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade

  • Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs

  • Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures

Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.

For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.

When should a low score trigger an audit?

A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.

Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.

Related Blog Posts

FAQ

01

What does it really mean to “redefine profit”?

02

What makes Council Fire different?

03

Who does Council Fire work with?

04

What does working with Council Fire actually look like?

05

How does Council Fire help organizations turn big goals into action?

06

How does Council Fire define and measure success?

Person
Person

Jul 27, 2026

Supplier Sustainability Assessment Checklist

ESG Strategy

In This Article

Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.

Supplier Sustainability Assessment Checklist

If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.

This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.

A few points stand out fast:

  • Supply chain emissions can be far above a company’s own direct emissions.

  • U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.

  • The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.

  • A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.

  • A supplier review only matters if it leads to clear actions, due dates, and proof of closure.

Here’s the article in one view:

  • Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.

  • Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.

  • Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.

  • Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.

The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process

Supplier Sustainability Assessment: 4-Step Repeatable Process

How to Use Claude in Excel for Supplier ESG Analysis

1. Assessment planning checklist

Start by locking scope and ownership so outreach goes only to the suppliers that matter most.

Set objectives, scope, and supplier tiers

Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.

Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:

  • Annual spend

  • Business criticality such as sole-source or critical-material suppliers

  • Geographic and sector risk

  • Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act

This helps you focus on the suppliers driving the most spend, risk, and emissions.

Assign each supplier to one of three tiers based on that review:

Tier

Supplier Type

Assessment Depth

Frequency

Tier 1

Strategic, high-spend, high-risk

Full ESG assessment + potential on-site audit

Annual

Tier 2

Operational, moderate risk

Standardized questionnaire + targeted document review

Every 2 years

Tier 3

Low-impact, low-risk

Basic compliance check + short questionnaire

Every 3 years

Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.

Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.

Choose assessment criteria, owners, and deadlines

Set your main assessment dimensions at the start:

  • Environmental: GHG emissions, energy use, water, waste

  • Social: labor practices, health and safety, freedom of association

  • Governance: anti-corruption policies, board oversight, reporting channels

  • Ethics: codes of conduct, OECD alignment

  • Supply-chain management: whether suppliers carry out their own supplier due diligence

Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.

Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.

Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.

With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.

2. Supplier outreach and data collection checklist

Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.

Send a clear outreach package

Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.

State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.

Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.

Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.

Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.

Request evidence and manage follow-up

Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.

Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:

Topic

Mandatory for All Tiers

Tier 1 Additional Requirements

Evidence to Request

Emissions & Energy

Do you measure Scope 1 and 2 emissions? (Yes/No)

Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals

GHG inventory, emissions methodology, utility records, SBTi validation

Waste & Circularity

Do you track total waste generated? (Yes/No)

Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products

Waste management records, recycling/recovery rates, circular design documentation

Water

Do you measure water withdrawal? (Yes/No)

Annual withdrawal and discharge volumes; water risk assessment

Water use records, discharge permits

Labor & Human Rights

Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment?

Workforce size; unionization status; sub-supplier labor oversight

HR policies, modern slavery statement, signed code of conduct

Health & Safety

Do you track workplace incidents? (Yes/No)

OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents

ISO 45001 certificate, OSHA logs, safety training records

Ethics & Governance

Written code of conduct and anti-corruption policy?

Board or executive ESG oversight; whistleblower mechanism

Anti-bribery policy, ethics hotline documentation, governance charter

Sub-Supplier Oversight

Do you assess your own suppliers' sustainability practices? (Yes/No)

Sub-tier supplier list; due diligence process description

Supplier code of conduct, sub-tier assessment records

Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.

When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.

Use complete submissions as the input for document review, scoring, and audit triggers.

3. Document review, scoring, and audit triggers checklist

Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.

Review policies, performance data, and supporting documents

For each document, start with three checks: recency, traceability, and alignment.

Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.

Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.

The table below shows what to collect and what to verify by topic area:

Review Area

Evidence to Verify

What to Verify

Environmental

Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data

Reporting period, source data, calculation method, audit trail

Water & Waste

Water and waste records, permits, corrective action plans from prior assessments

Current totals, disposal or discharge records, unresolved findings

Labor & Human Rights

Human rights and labor policy, code of conduct, corrective action plans

Policy currency, signed commitments, supplier oversight

Health & Safety

Health and safety metrics, audit reports, corrective action plans

Incident trends, lost-time events, open corrective actions

Ethics & Governance

Anti-corruption policy, governance documentation, third-party certifications

Policy currency, coverage, consistency with reported practices

Circularity

Recycled content data, take-back or reuse records, product design documents

Recycled content percentage, repairability, reuse programs

Build a weighted scorecard and define audit triggers

Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.

The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].

Scorecard Criterion

Weight

Scoring Basis

Automatic Trigger

Climate & Energy

30%

GHG inventory, target validation, renewable share

>10% year-over-year emissions increase with no reduction plan

Labor & Human Rights

25%

Policy currency, supplier oversight, workforce data

Any confirmed human rights violation

Ethics & Governance

20%

Anti-corruption policy, governance documentation, whistleblower mechanism

Missing anti-corruption policy

Circularity

15%

Recycled content, take-back participation, repairability

<5% recycled content where mandated

Risk Exposure

10%

Geographic risk, Tier 2/3 visibility, financial stability

No Tier 2 visibility

Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.

Trigger

Risk Level

Owner

Timeframe

Action

Score 80–100, no material issues

Low

Procurement

Annual review

Standard approval; schedule next assessment

Score 60–79 or incomplete documentation

Medium

Sustainability / Procurement

10 business days

Desktop review or virtual audit; request missing items

Score below 60 or repeated data gaps

High

Procurement + Sustainability

30 days

Mandatory corrective action plan; reassess after remediation

High-risk geography or spend above a defined threshold

Medium–High

Supply Chain Director

Annual

On-site audit for in-scope Tier 1 suppliers

Credible allegation of forced labor, child labor, or imminent safety risk

Critical

Legal + Compliance + Sourcing Leadership

Within 24 hours

Immediate escalation; sourcing halt pending investigation

Use these outcomes to set corrective actions and follow-up deadlines.

4. Improvement tracking and supplier development checklist

Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.

Set baselines, targets, and corrective actions

Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.

Set targets across four categories:

  • Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.

  • Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.

  • Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.

  • Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.

Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.

For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.

Monitor progress and link results to sourcing decisions

Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.

Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.

Supplier Name

Risk Tier

Key Findings (Latest Assessment)

Agreed Actions

Deadlines

Status

Score Trend






















Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.

Provide training, diagnostics, or co-investment only when they close a documented CAP item.

Conclusion: A repeatable supplier assessment process at a glance

This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.

The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.

Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.

FAQs

How do I choose supplier tiers?

Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.

Tier suppliers based on a few plain factors:

  • geographic risk

  • commodity type

  • spend volume

Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.

For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.

What proof should I ask suppliers for?

Ask for independently verifiable evidence based on risk, not just self-reported claims.

That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.

You might request:

  • Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade

  • Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs

  • Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures

Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.

For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.

When should a low score trigger an audit?

A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.

Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.

Related Blog Posts

FAQ

What does it really mean to “redefine profit”?

What makes Council Fire different?

Who does Council Fire work with?

What does working with Council Fire actually look like?

How does Council Fire help organizations turn big goals into action?

How does Council Fire define and measure success?