Skip to main content
DoneThat

AI Adoption GuideProcurementSource

ESG supplier screening

NLP and external data sources classify shortlisted suppliers on sustainability, labor practices, and regulatory compliance.

Procurement processRequestApproveSourceEvaluateSelectOrderReceiveReview

By Don, DoneThat’s AI coach · updated

Screening produces an evidence file, not a pass

Screening runs on the shortlist before award. It does not find suppliers, and it does not sign a compliance opinion.

The file a category manager can use has three dimensions per name: labor, environment, and sanctions. Each is a hit, a clear, or unknown. Every hit includes a source the buyer can open: a filing page, a news article, a questionnaire PDF, a certificate, or a restricted-party match. If the source cannot be opened, the row is unknown.

A missing third-party score is unknown. It is not a pass, and it is not a number you generate to close the spreadsheet.

A model reads the texts you hold and the public sources you add, then proposes those classifications. A person accepts, parks, or discards. AI supplier discovery produces the longlist. This screen runs after someone kept a handful of names. If sustainability or labor is a scored award criterion, feed the evidence into proposal scoring against RFP criteria instead of judging ESG in a side meeting.

EcoVadis, IntegrityNext, SAP Ariba, and Coupa are examples of tools that already hold scorecards, due-diligence questionnaires, and supplier-risk records. Read those records where they exist. Add filings and news the questionnaire never covered. Do not invent a substitute rating when the record is empty.

Where law imposes a duty to check (sanctions, forced labor, modern slavery, deforestation), the model prepares the pack. A person still does the check.

Screen the mill and the parent, not only the bidder

If you screen only the quoting entity, you miss the mill and the parent.

The name on the bid is often a sales company, a converting subsidiary, or a regional LLC. The exposure may sit at the pulp mill, the farm, the dye house, or the parent that files. Resolve, at minimum:

  • The quoting legal entity: name, jurisdiction, identifiers already in your master
  • The producing site for this award: mill, plant, farm, or warehouse
  • The ultimate parent, plus any intermediate company that actually files
  • Trade names news will use instead of the letterhead

If you cannot name the producing site, mark site-level labor and environment unknown. Do not copy the parent's sustainability report onto the mill, and do not treat the mill's silence as the parent's clearance.

Dropping the only dual-source plant on an unresolved parent hit can recreate the single-source risk you were trying to close. Park the row and ask which site will produce.

Pull filings, news, and the questionnaires you already collect

Build the pack from questionnaires you already hold, then public filings, then news and list checks.

  • Questionnaires and scorecards. Self-assessment forms from the last cycle, code-of-conduct attestations, EcoVadis scorecards if present, due-diligence questionnaires in IntegrityNext, and exhibits already sitting in SAP Ariba or Coupa. A completed form is what the supplier declared, not a site audit.
  • Public filings and certificates. For listed parents: the annual report or 10-K risk factors, the sustainability or modern-slavery statement, and any consent-order language in those documents. For private firms: what the home jurisdiction publishes, plus certificates already in the file (FSC, SFI, ISO 14001, SA8000). Quote the section. Point at the stored PDF or the public filing page.
  • News. Search the resolved names, not only the bid letterhead. Keep the article, the date, and the entity it actually names. A labor story about a similarly named consumer brand is not a hit on your converter.
  • Restricted-party lists. Run the quoting entity, the parent, and any named producing site against the lists your policy already names, including OFAC and the matching EU and UK lists where those apply. Attach the match record, not generated prose.

Keep the screen to labor, environment, and sanctions unless policy actually blocks award on another theme.

Every row needs a source the category manager can open. No openable source means unknown.

Worked example: recycled-content corrugated before award

Take the food manufacturer that kept a handful of corrugated converters after discovery. This walkthrough is illustrative, not a measured result.

The award is a recycled-content grade for a retailer program. The shortlist is two incumbents plus two new converting plants. ESG is a check before invite, not a tie-break after price.

The pack for each name used the last questionnaire in the master, public filings and certificates, and news plus restricted-party checks on the quoting entity, the converting plant, and the parent.

Labor

One new plant's parent appeared in a regional article about a union vote at a different mill in another state. The source was that article, opened against the mill it named, not the converting site on the bid. Status: hit at a sibling site. The buyer kept the plant in the event and asked which sites would produce the grade.

Environment

The mill-owned converter quoted through a converting LLC. The LLC questionnaire was complete and raised nothing on water.

The parent's annual report discussed a wastewater consent order at the pulp mill that supplies the recycled furnish. The source was that filing section and the mill named in it. Screening only the LLC would have shown clear.

The file showed an environment hit at the mill, unknown at the converting site for water, and an FSC or SFI claim only if the certificate named that mill.

Sanctions

All four quoting entities and their parents returned no match on the lists in the policy. That is a sanctions clear, with the search record attached. It is not a labor or environment clear.

Unknowns the model must not fill

The family-owned Midwest incumbent had no EcoVadis scorecard and a thin website. Treating the blank as a pass would have put them on the same footing as the mill-owned parent that files. The file marked the commercial score unknown, attached the empty slot, and kept the questionnaire and certificates that did exist. The buyer requested a scorecard, accepted unknown for a small regional plant, or parked the name. They did not invent a rating.

A fifth name from an older panel had a quality escape on file. The ESG screen does not know that. Historical performance retrieval from nonconformance logs is a separate pack before anyone invites them.

After markup, one plant was invited with an environment question on the mill, one was parked pending a site confirmation, the family incumbent stayed in as unknown-on-scorecard, and nobody was dropped on the union headline alone.

A missing score is unknown; a headline is not a ban

A blank score is unknown, a bidder-only screen is incomplete, and a headline is not a disqualification.

Listed firms with investor pages fill commercial scorecards more easily than family converters and many plants outside the US and Western Europe. Auto-passing a blank EcoVadis field selects for firms that never bought a scorecard. Auto-failing it drops the plants discovery was meant to find. Leave it unknown. Policy then says what unknown may do: request a scorecard, cap spend, require a visit, or park.

If the producing site is missing from the row, labor and environment stay unknown even when the bidder's questionnaire is complete.

Adverse-media matching trips on common names, closed cases, contractors, and stories that name a parent site you will never buy from. Open the source. If the article does not name the entity or site on the award, it is not a hit. Give the supplier a route to correct stale certificates and mismatched media. Most disputes are identity and date, not a fight about the facts.

After award, the same sources belong in supplier risk continuous monitoring. The pre-award file is a snapshot. A consent order, a list add, or a labor story can arrive between signature and the first PO.

Screening is finished when the category manager can open every hit, see unknown where the record is empty, and choose invite, park, or discard without the model filling the blanks.

Is this worth automating for you?

Whether this pays back depends on how much time it takes your team today. Most teams estimate that from memory, and the estimate is usually wrong in one direction or the other.

DoneThat reconstructs where the time actually went, with no timers to forget, so you can measure the baseline before committing to a project and check the gain afterward.

Measure the baseline first