Supply chainResearch
Supplier monitoring: why 48% have an active risk
In the ESGreen database, about 48% of monitored companies have at least one active alert. See why supplier risk stays invisible and how to monitor it.
Data
Intelligence
Third parties and counterparties
Reporting and maturity
Solutions for companies
Structured supplier qualification, continuous monitoring of the base and documented follow-up of every alert, by CNPJ and CPF, for Procurement, Compliance and Sustainability.
An ESGreen specialist replies within one business day to schedule a time.
Source: ESGreen consolidated monitoring base, 2025. Published Sep 2026.
The lookup is not automatic. An ESGreen expert reviews the request and replies by email.
A certificate can expire, a lawsuit can arise, a company can land on a restrictive list months after it was approved.
Qualification shows the supplier on the day it comes in. Without continuous monitoring and a recorded follow-up, what changes after the contract can take months to be discovered, and even longer to be resolved.
33% of companies suffered financial loss or reputational damage in the last three years due to vulnerabilities linked to suppliers, partners or service providers. 28% had direct production disruptions.
Source: KPMG, 2026 Global Third-Party Risk Management Survey, 851 organizations.
Banks and cooperatives assess the social and environmental risk of those they finance. European buyers send supply chain due diligence questionnaires. The answer needs evidence, not declarations.
Between one lookup and the next, blind spots appear.
For those who hire
For those being assessed
Every new supplier comes in with a risk level, questionnaires and documents by area and the sign-off of whoever is responsible for each, before the contract.
After approval, the base remains tracked by CNPJ and CPF in auditable sources, with alerts organized by type and by company and the ESGreen Score recalculated with every relevant new event.
In the Alert Center, each alert reaches the right area with the result of the latest qualification alongside. The team works it through with the supplier and records the decision, with a follow-up deadline and an audit trail.
Explained risk level, questionnaires and documents by area, a supplier portal with your brand and each area's sign-off recorded.
Module: Supplier qualification
Suppliers, clients and partners tracked by CNPJ and CPF, instead of being revisited only at contract renewal.
Module: ESGreen Monitoring
Alerts routed to the responsible area, a conversation with the supplier, a follow-up deadline and a final decision recorded in the audit trail.
Module: Alert Center
Consolidated Score, registration data and CNAE, clearance certificates, ownership structure with politically exposed persons, lawsuits and critical risks, in one report.
Module: ESGreen Pre-assessment
Each topic on its own dashboard, with each company's history, to anticipate what needs attention.
Module: Lookup centers
Questionnaires by company size and CNAE, with AI-assisted document validation and an annual history.
Module: ESGreen Evidence Assessment
Risk-based due diligence when hiring and supervising third parties, with dated evidence.
Module: Supplier qualification and ESGreen Monitoring
Lookup via API and alerts in the onboarding flow, with the integration scope defined in the proposal.
Module: Data & API
A platform in three layers: data, intelligence and applications. Every result can be traced back to its source.
Risk level, questionnaires and documents by area, a supplier portal and each area's sign-off, before the contract.
Intelligence and automation in third-party risk management: suppliers, clients and partners.
Every alert with a responsible area, a follow-up deadline, a conversation with the supplier and a recorded decision.
Lawsuits, certificates, news and self-assessments across the portfolio, each topic on its own dashboard.
Individual report by CNPJ or CPF for qualification, onboarding, credit and compliance.
ESG maturity with 400+ criteria by company size and CNAE and AI-assisted document validation.
ESG risk from 0 to 1,000 (the higher, the lower the risk), across 12 layers, recalculated with every new event.
70+ sources and delivery via API, dashboard, report, alerts and batch.
The company is the one that complies with the regulation. ESGreen provides data, evidence and an audit trail.
| Regulation | Status | What it requires | How ESGreen helps |
|---|---|---|---|
| Law 12,846/2013 (Anti-Corruption) + Decree 11,129/2022, art. 57, XIII | In force | Integrity program with appropriate, risk-based due diligence to contract and oversee third parties, including politically exposed persons. |
Supplier qualification at contracting, continuous monitoring and the Alert Center during supervision, with restrictive lists, sanctions and ownership structure. |
| Law 14,133/2021 (public procurement), art. 25, §4º | In force | Integrity program within 6 months of signing large-scale contracts (R$261,968,421.04 in 2026, under Decree 12,807/2025). |
Dated evidence of due diligence on the supply chain for those that contract with the public sector. |
| CMN Res. 4,945/2021 (lenders' PRSAC) | In force | Banks and cooperatives apply their social and environmental policy to the clients they finance. |
Organized evidence of ESG risk and maturity for the conversation with the lender. |
| CVM Res. 193/2023 + CVM Res. 244/2026 | VoluntaryFor listed companies; "comply or explain" model on the way | Voluntary IFRS S1/S2 reporting, with a commitment of at least 3 fiscal years and assurance for those that adopt it. |
Value chain risk data with source, date and version to support reporting. |
| EUDR (EU Regulation 2023/1115) | PublishedApplied in phases: large and medium operators first, micro and small later. Deforestation cutoff date of December 31, 2020 | Zero-deforestation due diligence for soy, cattle, coffee, cocoa, palm oil, rubber and wood exported to the European Union. |
Checks for embargoes, deforestation and territorial overlaps by suppliers' CNPJ, CPF and property. |
| CSDDD (EU Directive, Omnibus I) | PublishedApplying further ahead, through large European companies that pass the requirement on to suppliers | Supply chain due diligence by companies with more than 5,000 employees and €1.5 billion in revenue, which pass questionnaires on to suppliers. |
Supplier monitoring and Evidence Assessment to answer European clients' questionnaires. |
| CBAM (European Union) | In forceDefinitive regime already applied; certificate sales on the way | Carbon cost on imports of steel, iron, aluminum, cement and fertilizers, among others. |
A topic we follow in Research for exporters in these sectors. |
| LGPD (Law 13,709/2018) | In force | Legal basis, data protection officer and data subject rights in the processing of personal data. |
Processing of CPFs with an appointed data protection officer (DPO) and a channel for data subjects; details on the Trust page. |
Deadlines are set by regulators and may change. Official dates and estimates, with the review date, are on the regulatory map.
Deadlines may change. The direction does not: every requirement moves from drafting to consultation, from publication to effectiveness. And the evidence it will call for needs a history.
Foreseen in an official document, with no date set in a rule yet.
Under consultation or with a proposed timeline. The direction is already set.
Rule published. The requirement takes effect in stages.
Already applies. Evidence must be kept up to date.
Informational content; not legal advice. Deadlines are set by regulators and subject to change; official dates are on the regulatory map. Status reviewed on .
In chapter 6, “Responsible Solutions”, of the Sicredi 2025 Sustainability Report, ESGreen is cited as the platform used to monitor and assess supplier ESG.
“Today we have a customizable, agile platform that centralizes all the analysis of our supply chain, records every interaction with suppliers and generates a comparable ESG Score in minutes.”
Sicredi 2025 Sustainability Report, ch. 6, p. 127 (GRI 2-6 | 3-3)
Read the Sicredi case study“This move was key to getting us qualified by a multinational and to facing RFPs with confidence.”
“Meetings became more objective, team engagement increased and we started making strategic decisions based on concrete data.”
85K+ companies monitored continuously, 70+ integrated sources. Data as of Sep 2026.
Via API, dashboard, report or alert.
Security, privacy and LGPD: See the Trust page
Short answers to the most common questions.
Still have questions? Talk to an expert
It is the process of continuously tracking the compliance, financial, legal and reputational risk of the companies in the supply chain, cross-referencing data from multiple public sources instead of relying only on a one-time qualification.
Qualification assesses the supplier at entry, before the contract. In ESGreen Supplier qualification, this includes risk level, questionnaires and documents by area and each area's sign-off. Continuous monitoring tracks the supplier after approval and captures the changes that arise while the contract is in force. In the Alert Center, the team handles each alert and records the decision.
More than 70 public, regulatory and global sources: national and international restrictive lists, sanctions lists, lawsuits, federal, state, municipal, labor and environmental certificates, registration and corporate data, and news.
ESGreen Pre-assessment is an individual report by CNPJ or CPF, on demand, used in qualification, onboarding or credit analysis. ESGreen Monitoring tracks the entire base continuously, with alerts and incident management.
Yes. ESGreen Evidence Assessment applies an ESG maturity questionnaire with 400+ criteria by company size and CNAE, validates the submitted documents with AI assistance and keeps an annual history. The result is a maturity rating that the company can present to clients, lenders and buyers.
No. ESGreen does not issue certifications. It provides data, evidence and an audit trail so that the contracting company makes and records its own decisions: in Supplier qualification, each of the client's areas records its own sign-off. The ESGreen Score and the maturity rating do not constitute a credit rating or legal opinion.
In a 30-minute conversation, we show the infrastructure applied to your base of suppliers, clients and partners.
Or write to contato@esgreen.com.br
An ESGreen specialist replies within one business day to schedule a time.