Articles / Risk
Supplier risk and ESG: from yearly questionnaires to continuous monitoring
A supplier can be healthy in January and insolvent by June. Continuous monitoring turns risk management from a yearly paperwork exercise into an early-warning system.
For many years, supplier risk meant a questionnaire sent once a year. The supplier ticked boxes, someone filed the answers, and the information was out of date within weeks. Recent supply shocks showed how little that approach protects a business.
What has changed
Two things make continuous monitoring practical now.
- More data is available. Company registers, financial filings, sanctions lists, court notices, news, certifications and shipping information are accessible through data providers and APIs.
- Software can watch it for you. Rather than a person checking each supplier, a system monitors thousands and raises an alert when something changes.
What to monitor
- Financial health. Late payments, deteriorating accounts, changes in ownership or credit ratings.
- Compliance. Sanctions and exclusion lists, which matter greatly in public procurement, where grounds for exclusion are defined by law.
- Operational risk. Single sites, dependence on one region, long lead times, or a single raw-material source.
- Cyber and data risk. Particularly for suppliers who handle your systems or data.
- ESG. Emissions, labour practices, certifications and supply-chain due diligence.
The regulatory push
Rules on sustainability reporting, forced labour and supply-chain due diligence differ by market, but they are tightening in the EU, the US and elsewhere, and large buyers in the Gulf and Asia increasingly ask for the same evidence. Larger companies increasingly need data from their suppliers, and that data flows down to smaller firms. Even where a law does not yet apply to you, your customers may ask the questions on its behalf. Public buyers can also include environmental and social criteria in tenders, so being able to document your position is a competitive advantage for bidders.
A practical model
Step 1: Segment. Sort suppliers by spend and by how critical they are. A small supplier of a part you cannot replace deserves more attention than a large supplier of office paper.
Step 2: Match monitoring to the segment.
- Critical: continuous monitoring, regular reviews, a plan B.
- Important: automated alerts and an annual review.
- Routine: basic checks at onboarding.
Step 3: Define what happens on an alert. Who is notified, what is the first action, and when do you escalate? An alert without a response plan is just noise.
Step 4: Test the plan. Run an exercise: "our sole supplier of X stops tomorrow." What do you do in the first week?
Handling the data responsibly
- Prefer objective, verifiable data over opinion scores.
- Give suppliers a chance to respond to a flagged issue before taking action.
- Document decisions, especially in public procurement, where unequal treatment can be challenged.
Resilience beyond monitoring
Monitoring tells you a problem is coming. Resilience is what you do about it: dual sourcing for critical items, buffer stock where it is affordable, contracts that include continuity obligations, and good relationships that help you get priority in a shortage.
The bottom line
Risk management works best when it is quiet and constant. Start with your most critical suppliers, automate the watching, and define the response before you need it.