ESG Insights

Supplier ESG Due Diligence: A Proportionate Process for SMEs

A risk-based cycle for identifying supplier impacts, setting expectations, improving performance, tracking outcomes and escalating serious issues.

In brief: Treat supplier due diligence as a cycle: identify and assess risks, prevent or mitigate harm, track results, communicate and enable remediation. Prioritise higher-risk categories and critical suppliers instead of applying the same burden to everyone.

Responsible business due diligence looks beyond collecting policy documents. The objective is to understand where adverse impacts may occur and use the organisation’s influence to prevent, reduce or remedy them. An SME can implement a proportionate process by focusing on its most significant risks and integrating requirements into procurement decisions.

Map risk before issuing questionnaires

Segment categories and suppliers by country, sector, workforce model, environmental exposure, criticality and spend. Use incident history and stakeholder information. A low-spend supplier may still present severe risk, so financial size should not be the only filter.

Set clear and workable expectations

Translate policies into a supplier code, tender questions, contract clauses and evidence requirements. Explain which standards apply, what must be reported and how concerns can be raised. Requirements should match the relationship and risk.

Assess evidence and agree improvement

Review documents, data, worker feedback, site information or independent assessments as appropriate. Classify findings by severity and likelihood. For remediable gaps, agree actions, owners, deadlines and support rather than relying only on pass-or-fail scoring.

Track outcomes and enable remediation

Follow whether corrective action addresses the underlying impact. Escalate persistent or severe issues under defined criteria. Ending a relationship may sometimes be necessary, but an abrupt exit can worsen harm, so consequences and leverage should be considered.

A practical implementation sequence

Pilot the cycle with one risk-relevant category. Align procurement, legal, operations and sustainability roles, then integrate the process into onboarding, tendering, supplier review and contract renewal. Keep a route for confidential concerns.

  1. Create a category and supplier risk map.
  2. Issue a proportionate supplier code and evidence request.
  3. Assess priority suppliers using multiple evidence sources.
  4. Agree corrective actions, support, owners and deadlines.
  5. Track outcomes, grievances, escalation and remediation.

For every step, retain the owner, source, reporting period, method, version, reviewer and known limitations. Estimates can be useful during transition, but they should never be presented as measured data.

Decision risks to control

  • Using one questionnaire score as the entire assessment.
  • Demanding evidence without definitions or supplier support.
  • Terminating relationships automatically without considering harm.

Retain the risk map, supplier code, tender and contract records, assessments, corrective-action plans, worker or stakeholder evidence where appropriate, escalation decisions and closure verification. Protect confidentiality and personal data.

Frequently asked questions

Must every supplier be audited?

No. Use risk-based prioritisation and choose evidence methods proportionate to severity, relationship and available leverage.

Is a signed code of conduct sufficient?

No. It sets expectations but does not prove implementation. Higher-risk relationships need evidence, engagement and follow-up.

What should an SME do with limited influence?

Collaborate with customers, industry groups or peers, simplify requirements, provide support and focus leverage on the most material risks.

When should a supplier relationship end?

Use defined severity and escalation criteria, consider whether disengagement may worsen harm, and document the decision and transition.

Authoritative sources

This article is for general information and education only. It is not legal, investment, financial, assurance, certification, compliance or other professional advice.