Platform, applications
Supplier qualification in a single flow, from invitation to each area's sign-off
Corporate suppliers, before contracting.
Classify each supplier's risk, invite them to answer questionnaires and submit documents through a portal with your brand, and record each area's sign-off, with public data and an audit trail in the same process.
- Legal name
- Exemplo Agroindustrial Ltda.
- CNPJ
- EX.EMP.LO1/0001-07
-
Registration and tax
Approved
PAR-2026-09-30-0412 -
Compliance
Approved with reservations
PAR-2026-09-30-0415 -
LGPD
Additional document requested
PAR-2026-09-30-0418 -
IT and security
Approved
PAR-2026-09-30-0421 -
Environment
Approved
PAR-2026-09-30-0426
Context
Spreadsheet-based qualification does not stand up to audit
- Each area asks all over again. Procurement, compliance, legal and IT request documents from the same supplier, each through its own channel, and no one sees the whole picture.
- The same screening for everyone. Without a risk scale, an office supplies vendor faces the same requirements as one that will process personal data or access systems.
- The decision leaves no trace. The sign-off sits in an email thread. At audit time, the outcome shows up, but not who decided, when or why.
ESGreen Supplier qualification brings the process into one place, from invitation to sign-off.
How it works
Classify, collect, decide
What your team does and what the supplier sees, at each step.
-
Classify
Risk before the invitation.
Your team
Enters the CNPJ and describes the supply. The platform indicates the risk level, explains why and suggests the areas that should review. The team adjusts the areas and writes the invitation.
Supplier
Receives the invitation by email, with the contracting company's brand and an individual, secure link, with no login to create.
-
Collect
Everything in one place.
Your team
Tracks each area's progress and checks, within the same process, the supplier's ESGreen Score, certificates, lawsuits and other public signals.
Supplier
Accepts the contracting company's terms, answers the questionnaires and submits each area's documents in any order, and reviews everything before submitting.
-
Decide
Each area with its own sign-off.
Your team
Each area reviews answers and documents, asks for more when something is missing and records its sign-off: approve, approve with reservations or reject, with a rationale.
Supplier
Resolves the flagged open items and receives the outcome by email. Internal comments and the dossier stay with the contracting company only.
Once the supplier is approved, tracking continues in ESGreen Monitoring. Explore Monitoring
You set the bar
Rigor follows the risk of what is supplied
An office supplies vendor does not go through the same screening as one that processes personal data. You set the scale, and the platform applies it to every new supplier.
- Low Simple supply, with no access to data or systems.
- Medium Recurring service, with operational impact.
- High Processing of personal data or access to systems.
- Critical Privileged access, critical operational continuity or handling of financial resources.
What you configure
- Areas and owners
- Use the default areas or create your own, each with its owner.
- Questions and documents
- Mandatory or conditional, waived depending on the supplier's answer.
- Templates by risk level
- The areas involved at each level, applied to every new supplier.
- Classification criteria
- How much each type of supply and each sensitive activity weighs in the risk level.
- Terms and invitation
- The terms the supplier accepts and the invitation message, with your brand.
- Versioned methodology
- Each qualification keeps the scale it was classified under, so auditors can understand the decision at the time.
What is assessed
Each area reviews what is theirs. The public data is already there.
Review areas
- Registration and tax
- Articles of association and clearance certificates.
- Compliance and integrity
- Code of conduct, whistleblower channel and anti-corruption policy.
- LGPD and privacy
- Privacy Policy, data protection officer and record of processing activities.
- IT and information security
- Security policy, security standards adopted and continuity plan.
- Legal
- Court records certificates, financial statements and powers of attorney.
- Environment
- Environmental license and waste management plan.
- Occupational health and safety
- Occupational health and risk management programs, and accident history.
- Business continuity
- Continuity plan, disaster recovery and insurance policies.
Plus any areas your company creates.
Public data in the process
The review starts with the supplier's public risk in view, even before the first answer.
Deliverables
From invitation to sign-off, everything becomes evidence
- DossierQualification report
- PDF with summary, risk level, areas and sign-offs, documents, open items and history.
- DecisionEach area's sign-off
- Decision, rationale, owner and date, area by area.
- TraceabilityAudit trail
- Every event in the process with author and date, from invitation to outcome.
- CollaborationComments with attachments
- Internal, between areas, and external, with the supplier. Internal comments never reach the supplier.
- ManagementQualification dashboard
- Progress, distribution by risk level and each area's open items, with spreadsheet export.
- RelationshipEmails with your brand
- Invitation, open items and outcome sent under the contracting company's brand.
For the areas that assess suppliers before the contract
-
Procurement and supply
The contract waits on qualification, and qualification waits on email replies.
A single process per supplier, with a deadline set by the client, progress by area and a recorded outcome.
-
Compliance and integrity
Risk-based due diligence calls for criteria and proof.
Risk level explained, integrity policies assessed and the sign-off in the audit trail.
-
Risk
Critical suppliers get lost among low-impact ones.
Classification by risk level and a dashboard showing the distribution of suppliers under qualification.
-
Legal
Certificates and powers of attorney checked outside the process.
Legal documents assessed within the qualification, with open items recorded.
-
IT, security and privacy
Suppliers that access systems or process personal data require more.
Information security, continuity and LGPD assessed by those responsible for them.
-
Sustainability, environment and OHS
The report calls for evidence on the supply chain.
Licenses, waste management and occupational health and safety assessed with documentation.
Before, during and after
From supplier onboarding to a resolved alert
Qualification tells you whether the supplier gets in. Monitoring tells you what changed. The Alert Center shows what your team did about it.
| Pre-assessment | Supplier qualification | Monitoring and Alert Center | |
|---|---|---|---|
| Question | What is the public risk of this CNPJ? | Can I engage this supplier, and with what precautions? | What changed, and what did the team do about it? |
| Who it is for | Clients, suppliers and partners, by CNPJ or CPF | Corporate suppliers | Suppliers, clients and partners in the base |
| When | On the lookup date | Before the contract | During the relationship |
| Who takes part | Your team | Your team, the reviewing areas and the supplier | Your team and, when needed, the supplier |
| Outcome | Report with ESGreen Score and critical risks | Each area's sign-off and the qualification report | Alerts handled, with a follow-up deadline and recorded decision |
In the Alert Center, the latest qualification result appears next to each supplier alert, and the follow-up ends with a recorded decision, including the decision to keep the supplier qualified.
Regulation
Third-party due diligence, with criteria and records
- Decree 11,129/2022, art. 57, XIII Appropriate, risk-based due diligence to engage and oversee third parties.
- Law 14,133/2021 Integrity of suppliers to the public sector in large-scale contracts.
- CMN 4.945 (PRSAC) For financial institutions, the policy also applied to suppliers and service providers.
- BCB Circular 3,978 For financial institutions, knowing suppliers and outsourced service providers.
- LGPD Suppliers that will process personal data, assessed before the contract.
The platform supports the company's compliance with regulations, with data, evidence and a trail. Informational content; it does not constitute a legal opinion.
Technology already at work in supplier management
- companies assessed and monitored
- 100K+
- institutions using ESGreen's infrastructure
- 60+
- public, regulatory and global sources integrated
- 70+
Data as of Sep 2026. Source: ESGreen database.
In the Responsible Solutions chapter of the Sicredi 2025 Sustainability Report, prepared under the GRI standard, ESGreen is cited as the platform used to monitor and assess the ESG performance of Sicredi's suppliers.
“Today we have a customizable, agile platform that centralizes all the analysis of our supply chain, records every interaction with suppliers and generates a comparable ESG Score in minutes.”
Sicredi 2025 Sustainability Report, ch. 6 “Soluções Responsáveis” (Responsible Solutions), p. 127 (GRI 2-6 | 3-3)
Read the Sicredi case studyDelivery formats
Where qualification happens
- Dashboard Qualifications by progress and risk level, with each area's open items.
- Supplier portal Individual, secure link, with the contracting company's brand.
- PDF report Summary, risk, sign-offs, documents and history.
- Emails Invitation, open items and outcome, with your brand.
- Spreadsheet Export of the qualification list.
- ESGreen Score With the supplier's public signals, inside the process.
The decision is yours. The evidence is on record.
ESGreen organizes the process and the evidence; approving or rejecting a supplier is always the client's decision. The public data in the process follows the ESGreen Score Methodology, and personal data processing is described on the Trust page.
Frequently asked questions
Short answers to the most common questions.
Still have questions? Talk to an expert
Does ESGreen approve the supplier?
No. The decision always rests with the client: each area records its own sign-off. ESGreen organizes the process, gathers the public data and keeps the evidence of each step.
Does Supplier qualification work for clients and partners?
No. Supplier qualification is designed for corporate suppliers, before contracting. For clients and partners, ESGreen offers the Pre-assessment, with the risk of a CNPJ or CPF on the lookup date, and continuous Monitoring.
Does the supplier need to create a login?
No. The supplier accesses the portal through an individual, secure, time-limited link, sent in the invitation under the contracting company's brand.
Can I use my own questions, documents and risk scale?
Yes. Areas, owners, questions, mandatory or conditional documents, templates by risk level and classification criteria are configured by your company. Each qualification keeps the version of the scale used.
What is the difference between Supplier qualification, Pre-assessment and Monitoring?
Pre-assessment shows the public risk of a CNPJ or CPF on the lookup date. Supplier qualification runs a supplier's assessment before the contract, with questionnaires, documents and each area's sign-off. Monitoring tracks the base after that and alerts you when something changes.
What happens after approval?
The supplier can move on to continuous Monitoring. When an alert comes up, the Alert Center shows the latest qualification result alongside it and records the follow-up through to the decision, including the decision to keep the supplier qualified.
Can the supplier see internal comments?
No. The supplier sees only what is theirs: invitation, terms, questionnaires, documents, open items and outcome. Internal comments and the dossier are restricted to your team.
Shall we organize your supplier qualification?
In 30 minutes, we show Supplier qualification applied to your procurement process: risk scale, reviewing areas and supplier portal.
- Qualification demo with procurement and compliance cases
- A conversation about your company's risk scale and reviewing areas
- Pre-assessment of supplier CNPJs in your base
Or write to contato@esgreen.com.br