

Jul 27, 2026
Supplier Sustainability Assessment Checklist
ESG Strategy
In This Article
Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.
Supplier Sustainability Assessment Checklist
If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.
This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.
A few points stand out fast:
Supply chain emissions can be far above a company’s own direct emissions.
U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.
The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.
A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.
A supplier review only matters if it leads to clear actions, due dates, and proof of closure.
Here’s the article in one view:
Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.
Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.
Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.
Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.
The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process
How to Use Claude in Excel for Supplier ESG Analysis
1. Assessment planning checklist
Start by locking scope and ownership so outreach goes only to the suppliers that matter most.
Set objectives, scope, and supplier tiers
Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.
Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:
Annual spend
Business criticality such as sole-source or critical-material suppliers
Geographic and sector risk
Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act
This helps you focus on the suppliers driving the most spend, risk, and emissions.
Assign each supplier to one of three tiers based on that review:
Tier | Supplier Type | Assessment Depth | Frequency |
|---|---|---|---|
Tier 1 | Strategic, high-spend, high-risk | Full ESG assessment + potential on-site audit | Annual |
Tier 2 | Operational, moderate risk | Standardized questionnaire + targeted document review | Every 2 years |
Tier 3 | Low-impact, low-risk | Basic compliance check + short questionnaire | Every 3 years |
Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.
Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.
Choose assessment criteria, owners, and deadlines
Set your main assessment dimensions at the start:
Environmental: GHG emissions, energy use, water, waste
Social: labor practices, health and safety, freedom of association
Governance: anti-corruption policies, board oversight, reporting channels
Ethics: codes of conduct, OECD alignment
Supply-chain management: whether suppliers carry out their own supplier due diligence
Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.
Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.
Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.
With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.
2. Supplier outreach and data collection checklist
Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.
Send a clear outreach package
Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.
State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.
Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.
Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.
Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.
Request evidence and manage follow-up
Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.
Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:
Topic | Mandatory for All Tiers | Tier 1 Additional Requirements | Evidence to Request |
|---|---|---|---|
Emissions & Energy | Do you measure Scope 1 and 2 emissions? (Yes/No) | Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals | GHG inventory, emissions methodology, utility records, SBTi validation |
Waste & Circularity | Do you track total waste generated? (Yes/No) | Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products | Waste management records, recycling/recovery rates, circular design documentation |
Water | Do you measure water withdrawal? (Yes/No) | Annual withdrawal and discharge volumes; water risk assessment | Water use records, discharge permits |
Labor & Human Rights | Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment? | Workforce size; unionization status; sub-supplier labor oversight | HR policies, modern slavery statement, signed code of conduct |
Health & Safety | Do you track workplace incidents? (Yes/No) | OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents | ISO 45001 certificate, OSHA logs, safety training records |
Ethics & Governance | Written code of conduct and anti-corruption policy? | Board or executive ESG oversight; whistleblower mechanism | Anti-bribery policy, ethics hotline documentation, governance charter |
Sub-Supplier Oversight | Do you assess your own suppliers' sustainability practices? (Yes/No) | Sub-tier supplier list; due diligence process description | Supplier code of conduct, sub-tier assessment records |
Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.
When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.
Use complete submissions as the input for document review, scoring, and audit triggers.
3. Document review, scoring, and audit triggers checklist
Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.
Review policies, performance data, and supporting documents
For each document, start with three checks: recency, traceability, and alignment.
Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.
Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.
The table below shows what to collect and what to verify by topic area:
Review Area | Evidence to Verify | What to Verify |
|---|---|---|
Environmental | Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data | Reporting period, source data, calculation method, audit trail |
Water & Waste | Water and waste records, permits, corrective action plans from prior assessments | Current totals, disposal or discharge records, unresolved findings |
Labor & Human Rights | Human rights and labor policy, code of conduct, corrective action plans | Policy currency, signed commitments, supplier oversight |
Health & Safety | Health and safety metrics, audit reports, corrective action plans | Incident trends, lost-time events, open corrective actions |
Ethics & Governance | Anti-corruption policy, governance documentation, third-party certifications | Policy currency, coverage, consistency with reported practices |
Circularity | Recycled content data, take-back or reuse records, product design documents | Recycled content percentage, repairability, reuse programs |
Build a weighted scorecard and define audit triggers
Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.
The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].
Scorecard Criterion | Weight | Scoring Basis | Automatic Trigger |
|---|---|---|---|
Climate & Energy | 30% | GHG inventory, target validation, renewable share | >10% year-over-year emissions increase with no reduction plan |
Labor & Human Rights | 25% | Policy currency, supplier oversight, workforce data | Any confirmed human rights violation |
Ethics & Governance | 20% | Anti-corruption policy, governance documentation, whistleblower mechanism | Missing anti-corruption policy |
Circularity | 15% | Recycled content, take-back participation, repairability | <5% recycled content where mandated |
Risk Exposure | 10% | Geographic risk, Tier 2/3 visibility, financial stability | No Tier 2 visibility |
Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.
Trigger | Risk Level | Owner | Timeframe | Action |
|---|---|---|---|---|
Score 80–100, no material issues | Low | Procurement | Annual review | Standard approval; schedule next assessment |
Score 60–79 or incomplete documentation | Medium | Sustainability / Procurement | 10 business days | Desktop review or virtual audit; request missing items |
Score below 60 or repeated data gaps | High | Procurement + Sustainability | 30 days | Mandatory corrective action plan; reassess after remediation |
High-risk geography or spend above a defined threshold | Medium–High | Supply Chain Director | Annual | On-site audit for in-scope Tier 1 suppliers |
Credible allegation of forced labor, child labor, or imminent safety risk | Critical | Legal + Compliance + Sourcing Leadership | Within 24 hours | Immediate escalation; sourcing halt pending investigation |
Use these outcomes to set corrective actions and follow-up deadlines.
4. Improvement tracking and supplier development checklist
Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.
Set baselines, targets, and corrective actions
Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.
Set targets across four categories:
Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.
Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.
Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.
Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.
Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.
For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.
Monitor progress and link results to sourcing decisions
Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.
Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.
Supplier Name | Risk Tier | Key Findings (Latest Assessment) | Agreed Actions | Deadlines | Status | Score Trend |
|---|---|---|---|---|---|---|
Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.
Provide training, diagnostics, or co-investment only when they close a documented CAP item.
Conclusion: A repeatable supplier assessment process at a glance
This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.
The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.
Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.
FAQs
How do I choose supplier tiers?
Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.
Tier suppliers based on a few plain factors:
geographic risk
commodity type
spend volume
Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.
For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.
What proof should I ask suppliers for?
Ask for independently verifiable evidence based on risk, not just self-reported claims.
That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.
You might request:
Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade
Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs
Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures
Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.
For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.
When should a low score trigger an audit?
A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.
Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.
Related Blog Posts

Latest Articles
©2025
FAQ
01
What does it really mean to “redefine profit”?
02
What makes Council Fire different?
03
Who does Council Fire work with?
04
What does working with Council Fire actually look like?
05
How does Council Fire help organizations turn big goals into action?
06
How does Council Fire define and measure success?


Jul 27, 2026
Supplier Sustainability Assessment Checklist
ESG Strategy
In This Article
Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.
Supplier Sustainability Assessment Checklist
If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.
This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.
A few points stand out fast:
Supply chain emissions can be far above a company’s own direct emissions.
U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.
The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.
A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.
A supplier review only matters if it leads to clear actions, due dates, and proof of closure.
Here’s the article in one view:
Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.
Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.
Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.
Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.
The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process
How to Use Claude in Excel for Supplier ESG Analysis
1. Assessment planning checklist
Start by locking scope and ownership so outreach goes only to the suppliers that matter most.
Set objectives, scope, and supplier tiers
Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.
Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:
Annual spend
Business criticality such as sole-source or critical-material suppliers
Geographic and sector risk
Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act
This helps you focus on the suppliers driving the most spend, risk, and emissions.
Assign each supplier to one of three tiers based on that review:
Tier | Supplier Type | Assessment Depth | Frequency |
|---|---|---|---|
Tier 1 | Strategic, high-spend, high-risk | Full ESG assessment + potential on-site audit | Annual |
Tier 2 | Operational, moderate risk | Standardized questionnaire + targeted document review | Every 2 years |
Tier 3 | Low-impact, low-risk | Basic compliance check + short questionnaire | Every 3 years |
Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.
Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.
Choose assessment criteria, owners, and deadlines
Set your main assessment dimensions at the start:
Environmental: GHG emissions, energy use, water, waste
Social: labor practices, health and safety, freedom of association
Governance: anti-corruption policies, board oversight, reporting channels
Ethics: codes of conduct, OECD alignment
Supply-chain management: whether suppliers carry out their own supplier due diligence
Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.
Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.
Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.
With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.
2. Supplier outreach and data collection checklist
Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.
Send a clear outreach package
Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.
State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.
Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.
Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.
Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.
Request evidence and manage follow-up
Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.
Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:
Topic | Mandatory for All Tiers | Tier 1 Additional Requirements | Evidence to Request |
|---|---|---|---|
Emissions & Energy | Do you measure Scope 1 and 2 emissions? (Yes/No) | Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals | GHG inventory, emissions methodology, utility records, SBTi validation |
Waste & Circularity | Do you track total waste generated? (Yes/No) | Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products | Waste management records, recycling/recovery rates, circular design documentation |
Water | Do you measure water withdrawal? (Yes/No) | Annual withdrawal and discharge volumes; water risk assessment | Water use records, discharge permits |
Labor & Human Rights | Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment? | Workforce size; unionization status; sub-supplier labor oversight | HR policies, modern slavery statement, signed code of conduct |
Health & Safety | Do you track workplace incidents? (Yes/No) | OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents | ISO 45001 certificate, OSHA logs, safety training records |
Ethics & Governance | Written code of conduct and anti-corruption policy? | Board or executive ESG oversight; whistleblower mechanism | Anti-bribery policy, ethics hotline documentation, governance charter |
Sub-Supplier Oversight | Do you assess your own suppliers' sustainability practices? (Yes/No) | Sub-tier supplier list; due diligence process description | Supplier code of conduct, sub-tier assessment records |
Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.
When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.
Use complete submissions as the input for document review, scoring, and audit triggers.
3. Document review, scoring, and audit triggers checklist
Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.
Review policies, performance data, and supporting documents
For each document, start with three checks: recency, traceability, and alignment.
Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.
Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.
The table below shows what to collect and what to verify by topic area:
Review Area | Evidence to Verify | What to Verify |
|---|---|---|
Environmental | Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data | Reporting period, source data, calculation method, audit trail |
Water & Waste | Water and waste records, permits, corrective action plans from prior assessments | Current totals, disposal or discharge records, unresolved findings |
Labor & Human Rights | Human rights and labor policy, code of conduct, corrective action plans | Policy currency, signed commitments, supplier oversight |
Health & Safety | Health and safety metrics, audit reports, corrective action plans | Incident trends, lost-time events, open corrective actions |
Ethics & Governance | Anti-corruption policy, governance documentation, third-party certifications | Policy currency, coverage, consistency with reported practices |
Circularity | Recycled content data, take-back or reuse records, product design documents | Recycled content percentage, repairability, reuse programs |
Build a weighted scorecard and define audit triggers
Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.
The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].
Scorecard Criterion | Weight | Scoring Basis | Automatic Trigger |
|---|---|---|---|
Climate & Energy | 30% | GHG inventory, target validation, renewable share | >10% year-over-year emissions increase with no reduction plan |
Labor & Human Rights | 25% | Policy currency, supplier oversight, workforce data | Any confirmed human rights violation |
Ethics & Governance | 20% | Anti-corruption policy, governance documentation, whistleblower mechanism | Missing anti-corruption policy |
Circularity | 15% | Recycled content, take-back participation, repairability | <5% recycled content where mandated |
Risk Exposure | 10% | Geographic risk, Tier 2/3 visibility, financial stability | No Tier 2 visibility |
Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.
Trigger | Risk Level | Owner | Timeframe | Action |
|---|---|---|---|---|
Score 80–100, no material issues | Low | Procurement | Annual review | Standard approval; schedule next assessment |
Score 60–79 or incomplete documentation | Medium | Sustainability / Procurement | 10 business days | Desktop review or virtual audit; request missing items |
Score below 60 or repeated data gaps | High | Procurement + Sustainability | 30 days | Mandatory corrective action plan; reassess after remediation |
High-risk geography or spend above a defined threshold | Medium–High | Supply Chain Director | Annual | On-site audit for in-scope Tier 1 suppliers |
Credible allegation of forced labor, child labor, or imminent safety risk | Critical | Legal + Compliance + Sourcing Leadership | Within 24 hours | Immediate escalation; sourcing halt pending investigation |
Use these outcomes to set corrective actions and follow-up deadlines.
4. Improvement tracking and supplier development checklist
Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.
Set baselines, targets, and corrective actions
Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.
Set targets across four categories:
Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.
Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.
Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.
Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.
Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.
For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.
Monitor progress and link results to sourcing decisions
Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.
Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.
Supplier Name | Risk Tier | Key Findings (Latest Assessment) | Agreed Actions | Deadlines | Status | Score Trend |
|---|---|---|---|---|---|---|
Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.
Provide training, diagnostics, or co-investment only when they close a documented CAP item.
Conclusion: A repeatable supplier assessment process at a glance
This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.
The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.
Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.
FAQs
How do I choose supplier tiers?
Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.
Tier suppliers based on a few plain factors:
geographic risk
commodity type
spend volume
Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.
For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.
What proof should I ask suppliers for?
Ask for independently verifiable evidence based on risk, not just self-reported claims.
That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.
You might request:
Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade
Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs
Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures
Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.
For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.
When should a low score trigger an audit?
A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.
Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.
Related Blog Posts

FAQ
01
What does it really mean to “redefine profit”?
02
What makes Council Fire different?
03
Who does Council Fire work with?
04
What does working with Council Fire actually look like?
05
How does Council Fire help organizations turn big goals into action?
06
How does Council Fire define and measure success?


Jul 27, 2026
Supplier Sustainability Assessment Checklist
ESG Strategy
In This Article
Four-step checklist to plan, collect, score, and track supplier ESG performance with tiering, evidence, audits, and corrective action plans.
Supplier Sustainability Assessment Checklist
If I want supplier due diligence to change sourcing decisions, I need a simple loop: pick the right suppliers, ask for the right proof, score results the same way, and track fixes until they close.
This article lays out that process in four steps. I start by setting scope, goals, tiers, owners, and deadlines. Then I send a short supplier package with tier-based questions and proof requests. After that, I review documents for date, source trail, and match across claims, data, and records. Last, I turn scores and findings into corrective action plans, review them on a set cadence, and link results to renewals, approvals, and supplier phase-out.
A few points stand out fast:
Supply chain emissions can be far above a company’s own direct emissions.
U.S. rules such as the Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act can create legal risk when supplier checks are weak or missing.
The checklist uses three supplier tiers so high-risk and high-spend suppliers get deeper review.
A 0–100 scorecard helps decide whether to approve, monitor, correct, audit, or halt sourcing.
A supplier review only matters if it leads to clear actions, due dates, and proof of closure.
Here’s the article in one view:
Plan the assessment: define goals, choose in-scope suppliers, sort by tier, assign owners, and set deadlines.
Collect supplier data: send a clear questionnaire, ask for proof tied to claims, and follow up on gaps within set business days.
Review and score: check records for recency, traceability, and alignment; then apply weighted scoring and audit triggers.
Track fixes: open corrective action plans, set baselines and targets, monitor status, and tie results to sourcing decisions.
The core message is simple: a supplier assessment should be a repeatable management process, not a one-time form exercise.

Supplier Sustainability Assessment: 4-Step Repeatable Process
How to Use Claude in Excel for Supplier ESG Analysis
1. Assessment planning checklist
Start by locking scope and ownership so outreach goes only to the suppliers that matter most.
Set objectives, scope, and supplier tiers
Tie the assessment directly to your organization’s sustainability commitments. If your company has a net-zero target, turn that into a clear supply-chain goal. For example, aim to measure and cut Scope 3 Category 1 emissions by X% by 2030. If human rights sit high on the agenda, connect that priority to supplier expectations around due diligence, grievance mechanisms, and labor practices. Keep each assessment cycle tight. A small set of measurable outcomes works better than a long wish list, especially when those outcomes match the data you plan to gather.
Once the objectives are clear, decide which suppliers are in scope. Pull a 12–24 month spend report and segment the supplier base using four criteria:
Annual spend
Business criticality such as sole-source or critical-material suppliers
Geographic and sector risk
Legal exposure, including the U.S. Uyghur Forced Labor Prevention Act and the California Transparency in Supply Chains Act
This helps you focus on the suppliers driving the most spend, risk, and emissions.
Assign each supplier to one of three tiers based on that review:
Tier | Supplier Type | Assessment Depth | Frequency |
|---|---|---|---|
Tier 1 | Strategic, high-spend, high-risk | Full ESG assessment + potential on-site audit | Annual |
Tier 2 | Operational, moderate risk | Standardized questionnaire + targeted document review | Every 2 years |
Tier 3 | Low-impact, low-risk | Basic compliance check + short questionnaire | Every 3 years |
Tiering shapes the rest of the process. It tells you how much evidence to ask for, how deep the review should go, and when an issue needs escalation. Use these tiers to set questionnaire depth, evidence requests, and audit frequency in the next step.
Also document which tiers are in scope for the current cycle, any exclusions such as one-time or very low-spend vendors, and the reassessment cadence for each tier.
Choose assessment criteria, owners, and deadlines
Set your main assessment dimensions at the start:
Environmental: GHG emissions, energy use, water, waste
Social: labor practices, health and safety, freedom of association
Governance: anti-corruption policies, board oversight, reporting channels
Ethics: codes of conduct, OECD alignment
Supply-chain management: whether suppliers carry out their own supplier due diligence
Then layer in category-specific criteria. An agricultural supplier needs closer review on deforestation and labor rights. A tech supplier, by contrast, may need more focus on conflict minerals and data center energy use. Same framework, different pressure points.
Every step needs a named owner. That usually means an assessment sponsor, an ESG lead for criteria and scoring, category managers for supplier relationships and follow-up, a data specialist for validation, and compliance or legal for regulatory review. Set one deadline for each phase, and hold document review until at least 80% of priority suppliers have submitted complete responses.
Before outreach begins, lock the evidence standard by tier. Tier 1 should provide verified data and third-party evidence. Tier 2 should submit targeted documents. Tier 3 should provide a signed code of conduct and self-assessment.
With objectives, owners, deadlines, and evidence standards in place, supplier outreach can begin.
2. Supplier outreach and data collection checklist
Start by collecting data from in-scope suppliers with an outreach package that is clear and easy to complete. Once responses come in, move any incomplete submissions into review.
Send a clear outreach package
Lead with a one-page cover letter that explains the purpose of the assessment, the scope, and how the results will be used for risk ranking, sourcing, improvement, and reporting. This data helps organizations build climate resilience across their supply chains. Keep the package in line with supplier tier, so higher-risk suppliers provide deeper evidence. Frame the process as a shared effort, not just a compliance task. That simple shift often helps response rates and improves the quality of what comes back.
State plainly that responses will be stored securely, shared only with authorized teams, and handled under current NDAs or data protection policies.
Include a firm deadline in U.S. date format - for example, Responses due by September 30, 2026 - and give suppliers a realistic estimate of the time required. Tier 1 suppliers should expect 45–60 minutes. Lower-risk tiers should expect 20–30 minutes. Include the name of a specific contact person, along with an email address and phone number, and list office hours in the local time zone, such as 9:00 a.m.–5:00 p.m. Eastern Time.
Build the questionnaire in three layers. Start with baseline questions for every supplier: legal name, location, sector, primary contact, current sustainability policies or commitments, and whether they already track emissions, energy, waste, water, labor practices, health and safety, ethics, governance, and sub-supplier oversight.
Then add topic-based sections with 3–6 focused questions each so you can gather comparable quantitative or categorical data. Keep the total questionnaire to 20–40 questions across environmental, social, and governance topics, and clearly mark mandatory questions. Last, connect evidence prompts directly to key claims so suppliers know exactly what to upload with each answer.
Request evidence and manage follow-up
Evidence requests should match the answers suppliers provide. If a supplier says they are ISO 14001 certified, ask for the certificate. If they claim a net-zero target by 2040, ask for the Science Based Targets initiative validation letter or similar documentation. This keeps the request in proportion to the claim and makes review much easier.
Use this minimum evidence set by tier. The table below lists the mandatory questions and required evidence by tier:
Topic | Mandatory for All Tiers | Tier 1 Additional Requirements | Evidence to Request |
|---|---|---|---|
Emissions & Energy | Do you measure Scope 1 and 2 emissions? (Yes/No) | Annual Scope 1 and 2 totals (metric tons CO₂e); electricity use (kWh); share of renewable electricity; science-based targets or other validated goals | GHG inventory, emissions methodology, utility records, SBTi validation |
Waste & Circularity | Do you track total waste generated? (Yes/No) | Total waste generated (short tons); percentage recycled or reused; take-back or circular design programs; use of recycled materials in products | Waste management records, recycling/recovery rates, circular design documentation |
Water | Do you measure water withdrawal? (Yes/No) | Annual withdrawal and discharge volumes; water risk assessment | Water use records, discharge permits |
Labor & Human Rights | Written policies on minimum age, non-discrimination, freedom of association, and anti-harassment? | Workforce size; unionization status; sub-supplier labor oversight | HR policies, modern slavery statement, signed code of conduct |
Health & Safety | Do you track workplace incidents? (Yes/No) | OSHA recordable rate (TRIR per 200,000 hours); lost-time incidents | ISO 45001 certificate, OSHA logs, safety training records |
Ethics & Governance | Written code of conduct and anti-corruption policy? | Board or executive ESG oversight; whistleblower mechanism | Anti-bribery policy, ethics hotline documentation, governance charter |
Sub-Supplier Oversight | Do you assess your own suppliers' sustainability practices? (Yes/No) | Sub-tier supplier list; due diligence process description | Supplier code of conduct, sub-tier assessment records |
Before outreach starts, define exactly what counts as complete. A complete submission should have every mandatory field answered, all required numeric data filled in, and all listed documents attached.
When a submission is incomplete, send a targeted reminder within 5 business days that points out the missing item. Then allow another 7–10 business days for the supplier to respond. For Tier 1 suppliers, a second missed deadline should lead to a phone call or virtual meeting. For lower-risk tiers, two email reminders with documented follow-up are usually enough. If a supplier keeps missing deadlines or sends repeated gaps, flag that in the system and carry it into scoring and sourcing decisions.
Use complete submissions as the input for document review, scoring, and audit triggers.
3. Document review, scoring, and audit triggers checklist
Use the submitted package to check whether claims, data, and attachments line up. The goal is simple: confirm that the story the supplier tells is backed by dated records, source data, and documents that do not conflict with each other.
Review policies, performance data, and supporting documents
For each document, start with three checks: recency, traceability, and alignment.
Recency means the evidence covers the expected reporting period and shows a clear date.
Traceability means the supplier can point to the source data, calculation method, or audit trail behind each claim.
Alignment means policies, performance data, and certifications support the same picture. If they don’t, flag contradictions between policies, data, and certifications.
Watch for missing dates, metrics that don’t match, claims with no backup, and unexplained year-over-year swings in emissions or health and safety data. Not every gap needs a full escalation. Small issues - like an out-of-date attachment, a missing signature, or a minor empty field - should lead to a short correction request with a clear turnaround time. Escalation should be saved for signs of concealment, systemic noncompliance, or legal exposure.
The table below shows what to collect and what to verify by topic area:
Review Area | Evidence to Verify | What to Verify |
|---|---|---|
Environmental | Sustainability or ESG policy, environmental management system documents, greenhouse gas inventory or energy data | Reporting period, source data, calculation method, audit trail |
Water & Waste | Water and waste records, permits, corrective action plans from prior assessments | Current totals, disposal or discharge records, unresolved findings |
Labor & Human Rights | Human rights and labor policy, code of conduct, corrective action plans | Policy currency, signed commitments, supplier oversight |
Health & Safety | Health and safety metrics, audit reports, corrective action plans | Incident trends, lost-time events, open corrective actions |
Ethics & Governance | Anti-corruption policy, governance documentation, third-party certifications | Policy currency, coverage, consistency with reported practices |
Circularity | Recycled content data, take-back or reuse records, product design documents | Recycled content percentage, repairability, reuse programs |
Build a weighted scorecard and define audit triggers
Use a 0–100 weighted scorecard to compare suppliers and report results. Score each criterion from 0–5, apply the category weight, and total the result into a 0–100 composite score. In this model, 0 means no evidence, 3 means partial or unverified evidence, and 5 means a strong, independently verified system is in place.
The weighting should match your actual exposure rather than split every category evenly. A manufacturing supplier with high emissions intensity should carry more environmental weight. A labor-heavy services supplier should carry more social weight. Research on weighted supplier sustainability models shows that strategic suppliers often use weights such as Environmental 30%, Labor & Human Rights 30%, and Governance & Ethics 25%, while suppliers in high-risk geographies may shift Labor & Human Rights to 40% because the exposure is higher [1].
Scorecard Criterion | Weight | Scoring Basis | Automatic Trigger |
|---|---|---|---|
Climate & Energy | 30% | GHG inventory, target validation, renewable share | >10% year-over-year emissions increase with no reduction plan |
Labor & Human Rights | 25% | Policy currency, supplier oversight, workforce data | Any confirmed human rights violation |
Ethics & Governance | 20% | Anti-corruption policy, governance documentation, whistleblower mechanism | Missing anti-corruption policy |
Circularity | 15% | Recycled content, take-back participation, repairability | <5% recycled content where mandated |
Risk Exposure | 10% | Geographic risk, Tier 2/3 visibility, financial stability | No Tier 2 visibility |
Once the score is set, use it to decide the next move: approve, monitor, request correction, or escalate. A high score should not cancel out business criticality. Use both the sustainability score and supply risk when deciding whether to approve, monitor, or escalate.
Trigger | Risk Level | Owner | Timeframe | Action |
|---|---|---|---|---|
Score 80–100, no material issues | Low | Procurement | Annual review | Standard approval; schedule next assessment |
Score 60–79 or incomplete documentation | Medium | Sustainability / Procurement | 10 business days | Desktop review or virtual audit; request missing items |
Score below 60 or repeated data gaps | High | Procurement + Sustainability | 30 days | Mandatory corrective action plan; reassess after remediation |
High-risk geography or spend above a defined threshold | Medium–High | Supply Chain Director | Annual | On-site audit for in-scope Tier 1 suppliers |
Credible allegation of forced labor, child labor, or imminent safety risk | Critical | Legal + Compliance + Sourcing Leadership | Within 24 hours | Immediate escalation; sourcing halt pending investigation |
Use these outcomes to set corrective actions and follow-up deadlines.
4. Improvement tracking and supplier development checklist
Use the scorecard and audit triggers to open a corrective action plan (CAP) for each supplier. Then carry each supplier’s score, findings, and audit trigger into a live CAP. If nobody reviews it, it’s just paperwork. It’s not progress.
Set baselines, targets, and corrective actions
Start with the initial assessment score and the key metrics you’ve already collected. Treat those as the baseline, normalize them by spend or output, and store them in a central register so the data stays in one place.
Set targets across four categories:
Governance: Adopt a supplier code of conduct, put human rights and anti-corruption policies in place, and set board-level sustainability oversight.
Certifications: Reach ISO 14001, ISO 45001, or SA8000 within a timeframe that fits the supplier’s capacity.
Incident reduction: Reduce recordable safety incidents, stop repeated nonconformities, and close all critical findings within 90 days.
Emissions and resource performance: Meet absolute or intensity-based goals, such as a 15% reduction in Scope 2 emissions or a 10% reduction in water use per unit of output. Strategic suppliers should also set science-based targets aligned with 1.5°C pathways.
Set these targets with the supplier, not for them. That matters. The timeline has to match what the supplier can actually deliver.
For each corrective action, assign a responsible role at the supplier, a due date, interim milestones, and the exact evidence needed for closure. Use a standard CAP template so every item is marked open, in progress, verified, or closed. Each CAP should have a clear owner on your side, usually a procurement category manager or supplier relationship manager. Review progress quarterly for higher-risk suppliers and at least once a year for lower-risk ones. Use site verification only when high-risk findings stay unresolved.
Monitor progress and link results to sourcing decisions
Reassess suppliers on the same tiered cadence already in place. Also reassess right after a major incident, a major operational change, or a pattern of overdue actions.
Keep every supplier in one register so progress, deadlines, and score trends stay visible at a glance.
Supplier Name | Risk Tier | Key Findings (Latest Assessment) | Agreed Actions | Deadlines | Status | Score Trend |
|---|---|---|---|---|---|---|
Results should feed straight into sourcing decisions. Suppliers that keep improving scores, close findings on time, and meet emissions milestones can earn preferred status, longer contract terms, or a larger share of spend. Suppliers with flat scores or unresolved critical findings should move into remediation, get less business, or be phased out after repeated noncompliance. Review those outcomes in quarterly business reviews alongside cost, quality, and delivery.
Provide training, diagnostics, or co-investment only when they close a documented CAP item.
Conclusion: A repeatable supplier assessment process at a glance
This checklist works best as a simple loop: plan, collect, review, score, act, and then do it again. Tiering sets the level of scrutiny for each supplier, so your team can spend more time where spend, criticality, and risk are highest.
The next test is simple: does the score change supplier behavior? A score has weight only if it leads to corrective actions, sourcing decisions, and contract terms.
Used this way, the assessment shifts from a one-off review to a recurring management process. That makes the checklist repeatable, comparable, and ready for action.
FAQs
How do I choose supplier tiers?
Use a risk-based approach rather than putting every supplier through the same process. Not all suppliers carry the same level of exposure, so your review process shouldn’t look identical across the board.
Tier suppliers based on a few plain factors:
geographic risk
commodity type
spend volume
Then match the depth of due diligence to the level of risk. High-risk suppliers often make up just 10–20% of your supplier base, yet they account for most of your risk exposure. That’s where deeper checks make sense. Lower-risk suppliers can go through lighter reviews, which saves time and keeps teams from getting buried in paperwork.
For high-risk commodities like cobalt or palm oil, stop at Tier 1 and you’ll miss too much of the picture. In those cases, map the supply chain past Tier 1 into Tier 2+ so you can see where the biggest issues may be hiding.
What proof should I ask suppliers for?
Ask for independently verifiable evidence based on risk, not just self-reported claims.
That means looking beyond what a supplier says about itself and asking for proof you can check. The right level of proof will depend on the risk involved, but the goal stays the same: don’t rely on claims alone.
You might request:
Policies and certifications, such as environmental and social policies, code of conduct, ISO 14001, SA8000, FSC, or Fair Trade
Performance data, including Scope 1 and 2 emissions, energy use, safety records, and, where relevant, LCA data or EPDs
Operational evidence, such as audit reports, human rights due diligence, and regulatory disclosures
Then cross-check self-reported information against independent disclosures. If a supplier says one thing in a questionnaire but public filings, audit findings, or certification records tell a different story, that gap matters.
For smaller suppliers, keep requests simpler while still keeping enough oversight in place. You don’t want to bury a small business in paperwork, but you also shouldn’t waive basic checks when the risk is there.
When should a low score trigger an audit?
A low sustainability score should trigger an on-site audit when it marks a supplier as high-risk.
Focus audit resources on suppliers flagged through risk mapping - especially when geography, commodity type, and spend volume point to added exposure. The same applies when risk indicators call for a closer look than a desk-based review or self-assessment can offer.
Related Blog Posts

FAQ
What does it really mean to “redefine profit”?
What makes Council Fire different?
Who does Council Fire work with?
What does working with Council Fire actually look like?
How does Council Fire help organizations turn big goals into action?
How does Council Fire define and measure success?


