Platform, applications
ESGreen Monitoring: intelligence and automation in third-party risk management
Suppliers, clients and partners.
Continuous tracking of CNPJs and CPFs in auditable sources, with alerts organized by type and by company and the ESGreen Score recalculated with every relevant new event.
- Portfolio
- Example monitored portfolio
- Scope
- Suppliers, clients and business partners
-
Lawsuits
New lawsuit
EV-2026-09-30-1188 -
Certificates
Expired certificate
EV-2026-09-30-1191 -
Restricted lists
Added to a restrictive list
EV-2026-09-30-1197 -
News
Adverse news
EV-2026-09-30-1202 -
Registration
Change in ownership structure
EV-2026-09-30-1212
Context and landscape
The regulatory environment has evolved. Monitoring needs to evolve with it.
- Stricter regulation. CMN and Central Bank resolutions, SUSEP rules and IFRS S2 require financial institutions to take a view of risk that goes beyond their own balance sheet and reaches the entire counterparty chain.
- A practice that is still manual. One-off lookups, scattered spreadsheets and case-by-case checks, with no ongoing routine.
- Consequence. More reactive analysis and difficulty seeing the portfolio as a whole.
That is exactly the gap ESGreen Monitoring was built to close.
Problem and impact
Between one lookup and the next, blind spots appear
Management loses agility and visibility into portfolio risks.
- Reactive analysis. Relevant changes reach the assessment of suppliers, clients and partners late, weighing on Risk, Compliance and Credit.
- More effort from the team. Scattered information requires manual work to consolidate data and prioritize findings, overloading Onboarding, Qualification and Procurement.
- Gaps in identification. Legal, tax, socio-environmental and reputational risks can stay off the radar, exposing the institution to regulatory risk.
Every company outsources part of its own risk.
- of monitored companies have at least one active alert
- ~48%
- alerts on national restrictive lists
- 240+
- alerts on international sanctions lists
- 95+
- alerts from news and media
- 1.600+
Source: ESGreen consolidated monitoring base, 2025. Published Sep 2026.
33% of organizations suffered financial loss or reputational damage in the last three years due to vulnerabilities tied to suppliers, partners or service providers.
Solution and how it works
From identified change to documented decision
-
Continuous tracking
Replaces reactive analysis with frequent checks of CNPJs and CPFs against auditable sources.
Solves Reactive analysis
-
Change alert
Removes the manual effort of consolidating data: every relevant change arrives already organized and flagged.
Solves Team effort
-
Recalculated ESGreen Score
Helps identify changes and prioritize analysis, consolidating risk into a single score whenever a new event arises.
Solves Gaps and prioritization
-
Documented follow-up
The alert goes to the right area in the Alert Center, with an owner, follow-up deadline, supplier response through the portal and final sign-off.
Solves Unrecorded decisions
Monthly recalculation and with every relevant new event, the entire base at once
It is the difference between taking a snapshot of risk and watching a video as it unfolds.
Portfolio dashboard
The whole portfolio in one dashboard, from group to company
The contracting organization sees the consolidated risk of all monitored entities and quickly reaches the company that needs attention.
- The portfolio in numbers
- Total monitored entities, average ESGreen Score, average climate risk, average maturity rating and completed questionnaires, always in view.
- From group to company
- The view drills down by level: your monitored entities, central cooperatives, cooperatives and each company. It fits cooperative systems, economic groups and multi-unit networks.
- Comparison and trends
- Average by pillar, company ranking and the portfolio's monthly trend show where risk is improving and where it is getting worse.
- Scales that become filters
- The portfolio is spread across three scales: ESGreen Score (high, medium and low risk), climate risk (from very low to very high) and maturity level. One click on a band shows its companies.
- Portfolio map
- Company locations show where risk is concentrated.
- Exportable list
- Any slice becomes a list ready for the committee, audit or procurement.
Portfolio dashboard
- My monitored entities
- Central
- Cooperative
- Company
- Monitored entities
- 1.248
- Average ESGreen Score
- 712
- the higher, the lower the risk
- Average climate risk
- Medium
- Average maturity
- Root
- maturity level
- Completed questionnaires
- 386
ESGreen Score
- High risk 14%
- Medium risk 41%
- Low risk 45%
Climate risk
- Very low 18%
- Low 31%
- Medium 29%
- High 15%
- Very high 7%
Maturity level
- Soil 12%
- Seed 24%
- Root 33%
- Tree 21%
- Fruit 10%
Recommended actions
The dashboard already points to the next step
Automatic rules read the portfolio and turn each situation into a recommendation. For each rule, the team sees how many companies match, what to do and a list ready for action.
Rule
Expired certificate
23 companies match
Recommendation Request an updated certificate from the supplier.
Sample rules
- High score Consider adding to the preferred supplier list.
- Low score Propose an ESG action plan.
- Critical lawsuits Escalate the case to legal review.
- Expired certificate Request an updated certificate from the supplier.
- Company on the slave-like labor list Immediate review of the relationship.
- Very high climate risk Assess the operation's exposure and adaptation plan.
- Environmental violations Ask for clarification and evidence of remediation.
- Workplace accidents Check health and safety management.
- KYC and compliance findings Deepen integrity due diligence.
- No diversity policy Guide the creation of the policy.
- High turnover Understand the causes with the supplier.
- No whistleblower channel Recommend setting up a channel.
- No water or energy data Request consumption records.
- No emissions inventory Guide the Scope 1, 2 and 3 inventory.
The rules suggest and organize. The decision belongs to your team.
360° View
Everything that matters about the counterparty, gathered around it
An interactive graph gathers around the company everything the platform knows about it. Each branch opens the detail, with the evidence.
Exemplo Serviços Ltda.
Fictitious company and CNPJ
- ESGreen Score From 0 to 1,000, with the Confidence Index and breakdown by dimension
- Registration
- Partners and economic group Active and inactive companies, branches
- Lawsuits
- Certificates
- News
- Alerts
- Environmental
- Social
- Governance
- ODS
- Climate risks For the municipality, under scenarios
- Self-assessment
- Score history The past year, month by month
From a partner, the team opens that partner's panel or requests their Pre-assessment, without leaving the investigation.
Explore the interactive 360° View Explore individual monitoring
Personal data processed for integrity checks, KYC and AML, as described on the Trust page and in the Privacy Policy.
Deliverables and uses
More visibility to act. More context to decide.
- 360° visibilityConstant monitoring
- Alerts organized by type and by company, covering news, lawsuits, certificates, sanctions and climate risk, among other monitored sources.
- PrioritizationUpdated ESGreen Score
- ESGreen Score from 0 to 1,000, recalculated with every new event, to compare and prioritize the monitored portfolio. The higher the score, the lower the risk.
- TraceabilityRecords and resolution of open items
- Case history, records and resolution of open items with the counterparty, all centralized inside the platform.
Alert types
Features
- CNPJs and CPFs
- Tracking of related companies and individuals.
- Integrated ESGreen Score
- An indicator to support prioritization.
- Case management
- History, notes and interactions in the platform.
CPFs, partners and directors join the monitoring from the ownership structure, for integrity checks, KYC and AML. Explore individual monitoring
Case management: each follow-up with conversation, record and reference number
-
Conversation with the monitored entity
Messages and files exchanged with the counterparty inside the platform, with no stray emails.
-
Internal notes
The team's analysis is recorded, with attachments, without being visible to the monitored entity.
-
Reminders
Dates and recipients set by the team, so no open item stalls.
-
Manual case
The team opens a case on its own, and the monitored entity sees it so it can respond.
-
Closure with a reference number
Each case closes with the reason and a reference number, both recorded in the audit trail.
From alert to decision
Monitoring connects with the rest of the platform
-
Lookup centers
Lawsuits, certificates, news and self-assessments across the portfolio, each topic in its own dashboard, to dig into what the alert showed.
Explore the Lookup centers -
Alert Center
Each alert with its area, owner, follow-up deadline, supplier response and final sign-off.
Explore the Alert Center -
Supplier qualification
What monitoring shows supports the decision to onboard and renew a supplier, which always rests with the client.
Explore Supplier qualification -
Individuals (CPF)
Partners, directors and other CPFs tracked for integrity checks, KYC and AML.
Explore individual monitoring
For the teams responsible for third-party risk
-
Risk
Relevant changes reach the assessment too late.
Alerts by type and by counterparty, with a recalculated Score.
-
Compliance, AML and integrity
Identification gaps expose the institution to regulatory risk.
Restrictive lists and sanctions cross-checked continuously, with a handling trail.
-
Credit
The client portfolio changes after credit is granted.
A sign of change in the counterparty during the life of the operation.
-
Onboarding and qualification
Scattered information requires manual consolidation.
The entire monitored base at once, with open items centralized.
-
Procurement and sourcing
A supplier approved today may have a problem tomorrow.
Records of exchanges with the supplier and decision history.
-
Sustainability and reporting
Reports require evidence on the value chain.
Record of supplier management for GRI and IFRS S2 reports.
Regulation
The counterparty chain within the policy
- CMN 4.945 (PRSAC) The policy applied to clients, suppliers and partners, as an ongoing routine.
- BCB 151 (DRSAC) Social, environmental and climate risk signals by counterparty, ready for reporting.
- BCB Circular 3,978 Know your client, partner and supplier with continuous monitoring.
- Decree 11,129/2022, art. 57, XIII Risk-based due diligence for hiring and supervising third parties.
- Law 14,133/2021 Supplier integrity programs in large public procurement contracts.
The platform supports the institution's compliance with regulations, with data, evidence and an audit trail. Informational content; it does not constitute a legal opinion.
Documented recognition, technology present in real decisions
- companies assessed and monitored
- 100K+
- institutions using ESGreen's infrastructure
- 60+
- public, regulatory and global sources integrated
- 70+
Data as of Sep 2026. Source: ESGreen database.
In the Responsible Solutions chapter of the Sicredi 2025 Sustainability Report, prepared under the GRI standard, ESGreen is cited as the platform used to monitor and assess the ESG performance of Sicredi's suppliers.
“Today we have a customizable, agile platform that centralizes all the analysis of our supply chain, records every interaction with suppliers and generates a comparable ESG Score in minutes.”
Sicredi 2025 Sustainability Report, ch. 6 “Soluções Responsáveis” (Responsible Solutions), p. 127 (GRI 2-6 | 3-3)
Read the Sicredi case studyScope and success criteria
The value shows up in daily use
Indicators and targets defined jointly with the client.
-
Base coverage
Track the share of the planned base that is being monitored.
-
Alert handling
Track the analysis and recording of relevant cases.
-
Use in decision-making
Verify how the Score and history support the team's prioritization.
Implementation and onboarding
The base goes in at once, and monitored entities receive communications under the contracting organization's brand.
-
Base uploaded by spreadsheet
The whole base goes in at once, and invalid CNPJs are flagged before monitoring starts.
-
Emails with your brand
Welcome messages, notifications, invitations and self-assessment reminders reach monitored entities under the client's brand.
-
Email summaries
Periodic digests of portfolio alerts, certificates and news, plus an ESG market news bulletin.
-
Users and profiles by area
Access by area or unit: each team sees its part of the portfolio and receives its own digests.
-
In-dashboard announcements
Platform updates and notices appear right in the dashboard.
Responsibilities
- ESGreen
- Provide the contracted features and guide use of the solution.
- Client
- Keep the base aligned with the scope, analyze alerts and record decisions.
Targets, frequency and owners are set during implementation.
Monitoring aligned with your operation
What shapes the quote
Investment aligned with the contracted scope. There is no public pricing.
Delivery formats
Where alerts land
- Dashboard With the monitored portfolio, filters and history.
- Alerts By type and by company.
- ESGreen Score Overall, by dimension and by layer, with the Confidence Index.
- API and bulk upload Of the monitored base.
Each alert with its source and collection date
The monitored sources, the Score recalculation rules and model governance are published in the Methodology.
Frequently asked questions
Short answers to the most common questions.
Still have questions? Talk to an expert
What is third-party monitoring?
It is the continuous tracking of compliance, legal, tax, social-environmental and reputational risk of suppliers, clients and partners, cross-checking data from multiple public sources instead of relying only on a one-off assessment.
What is the difference between supplier qualification and continuous monitoring?
Supplier qualification assesses a supplier at a specific point in time, usually when the contract starts. Continuous monitoring repeats that assessment over time, with monthly recalculation and with every relevant new event, and captures changes that arise after approval.
Which sources are monitored?
70+ public, regulatory and global sources, with alerts on news, lawsuits, certificates, sanctions, restrictive lists, environmental embargoes and violations, registration and ownership changes, and climate risk.
What happens when an alert comes up?
The change arrives organized by type and by company, the counterparty's ESGreen Score is recalculated, and the team records its analysis, notes and exchanges with the counterparty right in the platform.
Can individuals be monitored?
Yes. Monitoring tracks CNPJs and CPFs, including partners and directors added from the ownership structure, for integrity checks, KYC and AML. The legal bases for processing personal data, the data protection officer and the data subject channel are described on the Trust page.
How does Monitoring relate to Pre-assessment?
Pre-assessment shows the risk of a CNPJ or CPF on the lookup date. Monitoring tracks the same reading over time, for the whole base, and alerts you when something changes.
What are recommended actions?
They are automatic rules that read the portfolio and point to the next step. Each rule shows how many companies match, the recommendation and a list ready for action: for example, considering high-scoring companies for the preferred supplier list, or an immediate review of the relationship when a company appears on the slave-like labor list. The rules suggest and organize; the decision belongs to your team.
How does the 360° View work?
It is an interactive graph centered on the company. It brings together the ESGreen Score with its breakdown by dimension, registration data, partners and economic group, environmental, social and governance topics, lawsuits, certificates, news, SDGs, alerts, the municipality's climate risks under scenarios, self-assessment and Score history. From a partner, the team opens that partner's panel or requests their Pre-assessment.
Can I import my whole base at once?
Yes. The base is uploaded by spreadsheet, and the platform flags invalid CNPJs before monitoring starts. Monitored entities then receive welcome messages and invitations by email, under the contracting organization's brand.
How is the quote defined?
By the size of the monitored base (number of CNPJs and CPFs), the included features, the number of users and access profiles, the contract term and the required integrations.
Shall we talk about the risks of your suppliers, clients and partners?
Book 30 minutes to see ESGreen Monitoring.
- Demo with cases from your segment
- Pre-assessment of CNPJs in your base
- Climate exposure readout for operations and assets
Or write to contato@esgreen.com.br