SUPPLY CHAIN SUSTAINABILITY
The EU Corporate Sustainability Due Diligence Directive (CSDDD/CS3D) is expanding corporate legal liability for adverse environmental and human rights impacts across supply chains — moving supply chain ESG risk from a reputational concern to a legal compliance obligation. CSRD's ESRS S2 (Workers in the Value Chain) and ESRS E1 (Climate, Scope 3) require documented assessment of supply chain ESG risks and impacts. Together, these frameworks are asking organizations to demonstrate that they know what ESG risks exist in their supply chains, that they have assessed them systematically, and that they have taken action to address the most material ones.
Semtrio conducts structured supplier ESG due diligence assessments — covering environmental, social, and governance criteria across in-scope supplier tiers — producing findings that are documented to the audit-ready standard that regulatory compliance, investor disclosure, and legal defensibility require. For organizations that need supply chain ESG risk visibility continuously rather than periodically, Carbondeck Supplier Analytics deploys as the live digital infrastructure layer — connecting to ERP and accounting systems to provide real-time supplier emission exposure data 7/24.
The EU Corporate Sustainability Due Diligence Directive requires in-scope organizations to identify actual and potential adverse environmental and human rights impacts across their supply chains, take action to prevent, mitigate, or remediate identified impacts, and establish grievance mechanisms for affected stakeholders. Non-compliance exposes organizations to regulatory enforcement and civil liability — including in some circumstances for harms caused by Tier 2 and beyond suppliers. This is a materially different standard from voluntary supply chain auditing.
CSRD's double materiality assessment must cover supply chain impacts — and where supply chain topics are identified as material, ESRS requires documented evidence of how those impacts have been assessed and addressed. An ESRS sustainability statement that identifies supply chain labour rights or emissions as material but provides no evidence of structured assessment is a disclosure gap that limited assurance providers will flag.
Institutional investors operating under SFDR and stewardship obligations are increasingly requiring evidence of supply chain due diligence processes from portfolio companies. Enterprise buyers with their own CSDDD obligations are requiring Tier 1 suppliers to conduct and document due diligence on their own supply chains. The due diligence requirement is cascading through supply chains.
The distinction between a supplier sustainability questionnaire and a supplier ESG due diligence assessment is the difference between asking suppliers how they perform and independently assessing whether their self-reported performance is accurate, whether material ESG risks exist that the supplier has not identified, and whether the organization's procurement relationship creates legal exposure. Due diligence under CSDDD is not a questionnaire campaign. It is a structured risk assessment process that must be documented, repeatable, proportionate to risk, and capable of producing specific findings that inform both procurement decisions and remediation plans.
Semtrio's supplier ESG due diligence assessments are structured to satisfy the legal and regulatory standard — covering environmental impact assessment, social risk assessment (including labour rights, health and safety, and human rights), and governance assessment across the ESG dimensions that CSDDD, ESRS, and investor frameworks require. Our findings are produced in audit-ready format — with evidence documentation, risk ratings, and remediation recommendations structured for ESRS sustainability statement disclosure and, where applicable, regulatory reporting. And for organizations that need continuous supplier ESG visibility rather than periodic assessment cycles, Carbondeck Supplier Analytics provides the live data infrastructure layer — extracting purchasing data from ERP systems and processing invoices with agentic AI to produce real-time supplier emission exposure data that makes the next assessment cycle faster, more precise, and grounded in actual purchasing reality rather than historical estimates.
OUR PROCESS
A structured supplier ESG due diligence assessment — audit-ready findings, risk-rated, and structured for CSDDD and ESRS compliance.
From periodic supplier assessments to continuous supply chain ESG visibility.
Supplier ESG due diligence conducted once a year, based on self-reported questionnaire data, and rebuilt at the start of each assessment cycle has a structural limitation: it produces a point-in-time picture of supply chain ESG risk based on data that may already be twelve months old by the time the findings are used. For CSDDD compliance, which requires ongoing due diligence — not periodic audit — this periodic model is increasingly insufficient. And for ESRS E1 Scope 3 disclosures, the precision of supply chain emission data depends on having current purchasing reality, not historical estimates.
Carbondeck Supplier Analytics changes the data foundation that due diligence is built on. Connected directly to the organization's accounting, billing, and finance ERP systems, Carbondeck extracts purchased goods and services data at the supplier level continuously. Supplier invoices processed by the agentic AI system are automatically categorized by supplier, mapped to Scope 3 emission calculations, and updated in real time — producing a live picture of supplier emission exposure that reflects actual purchasing patterns as they happen, not as they were estimated twelve months ago. The result is a due diligence process that is grounded in current data, more precise in its risk identification, and faster to execute in subsequent cycles because the data infrastructure is already in place.
As an accredited Climateware consulting partner, Semtrio configures and deploys Carbondeck Supplier Analytics alongside the due diligence assessment — connecting the ERP integration, configuring the AI invoice processing, and establishing the Scope 3 calculation methodology. The due diligence assessment identifies where ESG risks sit. Carbondeck provides the continuous data visibility that makes monitoring those risks ongoing rather than annual.
Explore Carbondeck Supplier AnalyticsCSDDD due diligence findings feed directly into ESRS S2 (Workers in the Value Chain) and ESRS E1 (Climate, Scope 3) disclosures — Semtrio designs due diligence assessments and ESRS reporting as a coordinated engagement, ensuring findings are structured for disclosure from the assessment outset.
Learn moreSupplier environmental due diligence identifies Scope 3 emission exposure across the supply chain — findings on supplier energy use, process emissions, and climate risk feed directly into Scope 3 risk quantification and SBTi supply chain target setting.
Learn moreEcoVadis assessments cover supply chain due diligence as a scored theme — organizations with structured, documented due diligence processes score higher on EcoVadis supply chain scoring. Semtrio designs due diligence processes and EcoVadis preparation in coordination.
Learn moreSupply chain ESG due diligence findings are among the most important inputs to a sustainability strategy — they identify where the organization's most material adverse impacts occur, inform which supply chain topics should be strategic priorities, and provide the evidence base for value chain remediation commitments.
Learn moreAudit-ready supplier ESG due diligence — structured for the legal and regulatory standard CSDDD and ESRS require, with continuous data visibility from live digital infrastructure.
The gap between a supplier questionnaire campaign and a legally defensible ESG due diligence assessment is significant — and it is the gap that CSDDD and CSRD auditors are specifically trained to identify. A questionnaire asks suppliers to self-report. A due diligence assessment independently evaluates whether those self-reports are credible, whether material ESG risks exist that the supplier has not identified, and whether the buying organization's procurement relationship creates exposure to adverse impacts under CSDDD's liability framework.
Semtrio designs supplier ESG due diligence assessments to satisfy the legal and regulatory standard — not the questionnaire standard. Our assessments are structured around the CSDDD obligation framework, the ESRS S2 and E1 topical requirements, and the severity and likelihood risk rating methodology that makes findings actionable for procurement decisions. Our findings documentation is produced in the format that limited assurance providers accept for ESRS sustainability statement evidence.
For organizations ready to move beyond point-in-time assessments, Carbondeck Supplier Analytics provides the continuous data layer — connected to ERP and accounting systems, processing invoices with agentic AI, producing real-time Scope 3 supplier emission data 7/24. The assessment identifies the risks. The infrastructure monitors them continuously.
Talk to our team about supplier ESG due diligenceDue diligence structured to satisfy legal obligation standards — not questionnaire campaign standards
Findings, risk ratings, and remediation recommendations in the format ESRS assurance providers and regulatory frameworks require
Carbondeck Supplier Analytics — ERP-connected, agentic AI invoice processing, real-time 7/24 — due diligence grounded in current purchasing reality
Whether you're scoping a single service engagement, evaluating end-to-end advisory across multiple clusters, or looking for one accountable partner across strategy and disclosure — start here.

Yaren Ünal
Senior Specialist,Client Solutions

Hamza Söylemez
Specialist,Client Solutions
Frequently asked questions about supplier ESG due diligence
Whether you are establishing your first supplier due diligence process or strengthening an existing one for CSDDD compliance and ESRS disclosure — we will design the scope, conduct the assessments, deploy the digital infrastructure, and produce findings that are auditable, risk-rated, and continuously monitored.