Supplier risk mapping

 

‍

Knowing where the risks lie
‍

You cannot take responsibility for what you do not know. Supplier risk mapping systematically identifies the social, environmental and compliance risks within your supply base ensuring you know where the greatest exposure lies, where to prioritise, and how to defend your approach to clients, auditors and regulators.

Talk
to an expert

Why a sound risk assessment is crucial

Many businesses have a supplier list but no view of the risks. They know who supplies them, but not where the real vulnerabilities lie – in which countries, sectors or product categories the likelihood of forced labour, deforestation or climate impact is greatest.

‍

Many companies have a supplier list but lack visibility regarding the associated risks. They know who their suppliers are, but not where the true vulnerabilities lie—in which countries, sectors or product categories the risk of forced labour, deforestation or climate impact is highest.

‍

The result is a due diligence approach that spreads attention thinly across the board, without delivering sufficient impact anywhere. Meanwhile, pressure is mounting: the CSDDD, EUDR and the Forced Labour Regulation all demand a demonstrably risk-based approach. Furthermore, clients and procurement officials are increasingly asking specific questions about how you identify risks within your supply chain.

Which businesses is this relevant for?

Businesses that need to set up or strengthen a risk-based due diligence approach in the context of the CSDDD, EUDR or FLR

‍

Organisations with a broad or international supplier base that do not know where their priorities lie

‍

Businesses that cannot adequately answer customer or audit questions about supply chain transparency

‍

Procurement teams that want to strengthen their supplier management with a systematic and documented risk framework

Our approach

A robust risk assessment is more than just a list of scores. It is an analytical tool that guides your due diligence efforts – ensuring they are proportionate, defensible and actionable in practice.

‍

‍We work in four steps:‍

‍

Mapping the supplier base – Who are your direct suppliers? Which products, raw materials and services do you source, from which sectors and countries? We structure your supplier base so that it can serve as the starting point for a layered risk assessment.

‍

Risk profile by supplier and segment – Based on sector, country and product risk indicators, we assign a risk profile to each supplier segment. For this we draw on recognised international sources – the ILO, the OECD and sector-specific risk databases – and combine these with your specific procurement context.

‍

Prioritisation and risk matrix – Which suppliers require immediate attention? Which can be followed up through standard processes? We translate the risk assessment into a clear set of priorities that serves as the basis for your due diligence planning.

‍

Reporting and governance – The risk assessment is documented in a format that is both practical for internal use and robust enough to withstand external verification or client enquiries. Together we assess which software can support risk management and the updating of the risk register.

‍

What does it deliver?

  • More targeted due diligence: your efforts go to the suppliers and segments where the real risks lie
  • A compliance foundation: a documented risk assessment serves as a basis for CSDDD, EUDR and FLR requirements
  • An answer to customer questions: a clear risk register gives you a defensible answer to due diligence questions of buyers and contracting authorities
  • Procurement intelligence: insight into risks by supplier and region also strengthens your procurement strategy and sourcing decisions
  • A basis for supplier engagement: the risk assessment determines whom you survey, when and how

Related services

  • Supplier engagement – Surveying and following up with the right suppliers based on a risk assessment.
  • Due diligence policy and governance – Embedding the risk assessment in internal policy and processes.
  • CSDDD – Risk assessment as a core element of the CSDDD approach.
  • EUDR – Origin and country risks as the basis for EUDR due diligence.
  • FLR – Labour risks by sector and country as the starting point for FLR compliance.

Take

 

the next step

Want to know where the risks in your supply chain lie?

A systematic risk assessment is the starting point of any credible due diligence approach. We help you lay that foundation – documented, defensible and usable as an instrument for strategy and compliance.

Leave your email address and we will get in touch to schedule a no-obligation consultation with an expert.