See the full list of cookies
Look up a CNPJ Talk to an expert Menu

Platform, applications

Supplier qualification in a single flow, from invitation to each area's sign-off

Corporate suppliers, before contracting.

Classify each supplier's risk, invite them to answer questionnaires and submit documents through a portal with your brand, and record each area's sign-off, with public data and an audit trail in the same process.

Supplier qualificationIllustrative data
Legal name
Exemplo Agroindustrial Ltda.
CNPJ
EX.EMP.LO1/0001-07
  1. Registration and tax Approved PAR-2026-09-30-0412
  2. Compliance Approved with reservations PAR-2026-09-30-0415
  3. LGPD Additional document requested PAR-2026-09-30-0418
  4. IT and security Approved PAR-2026-09-30-0421
  5. Environment Approved PAR-2026-09-30-0426
Sample qualification of a fictitious supplier: each area's sign-off, with time and ID in the audit trail.

Context

Spreadsheet-based qualification does not stand up to audit

  • Each area asks all over again. Procurement, compliance, legal and IT request documents from the same supplier, each through its own channel, and no one sees the whole picture.
  • The same screening for everyone. Without a risk scale, an office supplies vendor faces the same requirements as one that will process personal data or access systems.
  • The decision leaves no trace. The sign-off sits in an email thread. At audit time, the outcome shows up, but not who decided, when or why.

ESGreen Supplier qualification brings the process into one place, from invitation to sign-off.

How it works

Classify, collect, decide

What your team does and what the supplier sees, at each step.

  1. Classify

    Risk before the invitation.

    Your team

    Enters the CNPJ and describes the supply. The platform indicates the risk level, explains why and suggests the areas that should review. The team adjusts the areas and writes the invitation.

    Supplier

    Receives the invitation by email, with the contracting company's brand and an individual, secure link, with no login to create.

  2. Collect

    Everything in one place.

    Your team

    Tracks each area's progress and checks, within the same process, the supplier's ESGreen Score, certificates, lawsuits and other public signals.

    Supplier

    Accepts the contracting company's terms, answers the questionnaires and submits each area's documents in any order, and reviews everything before submitting.

  3. Decide

    Each area with its own sign-off.

    Your team

    Each area reviews answers and documents, asks for more when something is missing and records its sign-off: approve, approve with reservations or reject, with a rationale.

    Supplier

    Resolves the flagged open items and receives the outcome by email. Internal comments and the dossier stay with the contracting company only.

Once the supplier is approved, tracking continues in ESGreen Monitoring. Explore Monitoring

You set the bar

Rigor follows the risk of what is supplied

An office supplies vendor does not go through the same screening as one that processes personal data. You set the scale, and the platform applies it to every new supplier.

  1. Low Simple supply, with no access to data or systems.
  2. Medium Recurring service, with operational impact.
  3. High Processing of personal data or access to systems.
  4. Critical Privileged access, critical operational continuity or handling of financial resources.
Illustrative examples Each company sets its own scale: the higher the level, the more areas review and the more evidence is requested, to the extent you define.

What you configure

Areas and owners
Use the default areas or create your own, each with its owner.
Questions and documents
Mandatory or conditional, waived depending on the supplier's answer.
Templates by risk level
The areas involved at each level, applied to every new supplier.
Classification criteria
How much each type of supply and each sensitive activity weighs in the risk level.
Terms and invitation
The terms the supplier accepts and the invitation message, with your brand.
Versioned methodology
Each qualification keeps the scale it was classified under, so auditors can understand the decision at the time.

What is assessed

Each area reviews what is theirs. The public data is already there.

Review areas

Registration and tax
Articles of association and clearance certificates.
Compliance and integrity
Code of conduct, whistleblower channel and anti-corruption policy.
LGPD and privacy
Privacy Policy, data protection officer and record of processing activities.
IT and information security
Security policy, security standards adopted and continuity plan.
Legal
Court records certificates, financial statements and powers of attorney.
Environment
Environmental license and waste management plan.
Occupational health and safety
Occupational health and risk management programs, and accident history.
Business continuity
Continuity plan, disaster recovery and insurance policies.

Plus any areas your company creates.

Public data in the process

  • ESGreen Score
  • Certificates
  • Lawsuits
  • Active alerts
  • High-risk news
  • Environmental violations
  • Workplace accidents
  • Slave-like labor list
  • Credit information, for authorized profiles

The review starts with the supplier's public risk in view, even before the first answer.

Deliverables

From invitation to sign-off, everything becomes evidence

DossierQualification report
PDF with summary, risk level, areas and sign-offs, documents, open items and history.
DecisionEach area's sign-off
Decision, rationale, owner and date, area by area.
TraceabilityAudit trail
Every event in the process with author and date, from invitation to outcome.
CollaborationComments with attachments
Internal, between areas, and external, with the supplier. Internal comments never reach the supplier.
ManagementQualification dashboard
Progress, distribution by risk level and each area's open items, with spreadsheet export.
RelationshipEmails with your brand
Invitation, open items and outcome sent under the contracting company's brand.

For the areas that assess suppliers before the contract

  • Procurement and supply

    The contract waits on qualification, and qualification waits on email replies.

    A single process per supplier, with a deadline set by the client, progress by area and a recorded outcome.

  • Compliance and integrity

    Risk-based due diligence calls for criteria and proof.

    Risk level explained, integrity policies assessed and the sign-off in the audit trail.

  • Risk

    Critical suppliers get lost among low-impact ones.

    Classification by risk level and a dashboard showing the distribution of suppliers under qualification.

  • Legal

    Certificates and powers of attorney checked outside the process.

    Legal documents assessed within the qualification, with open items recorded.

  • IT, security and privacy

    Suppliers that access systems or process personal data require more.

    Information security, continuity and LGPD assessed by those responsible for them.

  • Sustainability, environment and OHS

    The report calls for evidence on the supply chain.

    Licenses, waste management and occupational health and safety assessed with documentation.

Before, during and after

From supplier onboarding to a resolved alert

Qualification tells you whether the supplier gets in. Monitoring tells you what changed. The Alert Center shows what your team did about it.

Explore the Alert Center

Comparison of Pre-assessment, Supplier qualification and Monitoring with the Alert Center
Pre-assessmentSupplier qualificationMonitoring and Alert Center
Question What is the public risk of this CNPJ? Can I engage this supplier, and with what precautions? What changed, and what did the team do about it?
Who it is for Clients, suppliers and partners, by CNPJ or CPF Corporate suppliers Suppliers, clients and partners in the base
When On the lookup date Before the contract During the relationship
Who takes part Your team Your team, the reviewing areas and the supplier Your team and, when needed, the supplier
Outcome Report with ESGreen Score and critical risks Each area's sign-off and the qualification report Alerts handled, with a follow-up deadline and recorded decision

In the Alert Center, the latest qualification result appears next to each supplier alert, and the follow-up ends with a recorded decision, including the decision to keep the supplier qualified.

Regulation

Third-party due diligence, with criteria and records

See the regulatory map

  • Decree 11,129/2022, art. 57, XIII Appropriate, risk-based due diligence to engage and oversee third parties.
  • Law 14,133/2021 Integrity of suppliers to the public sector in large-scale contracts.
  • CMN 4.945 (PRSAC) For financial institutions, the policy also applied to suppliers and service providers.
  • BCB Circular 3,978 For financial institutions, knowing suppliers and outsourced service providers.
  • LGPD Suppliers that will process personal data, assessed before the contract.

The platform supports the company's compliance with regulations, with data, evidence and a trail. Informational content; it does not constitute a legal opinion.

Technology already at work in supplier management

companies assessed and monitored
100K+
institutions using ESGreen's infrastructure
60+
public, regulatory and global sources integrated
70+

Data as of Sep 2026. Source: ESGreen database.

In the Responsible Solutions chapter of the Sicredi 2025 Sustainability Report, prepared under the GRI standard, ESGreen is cited as the platform used to monitor and assess the ESG performance of Sicredi's suppliers.

“Today we have a customizable, agile platform that centralizes all the analysis of our supply chain, records every interaction with suppliers and generates a comparable ESG Score in minutes.”

Bruno Virtuoso, Procurement and Sourcing Manager, Sicredi

Sicredi 2025 Sustainability Report, ch. 6 “Soluções Responsáveis” (Responsible Solutions), p. 127 (GRI 2-6 | 3-3)

Read the Sicredi case study

Delivery formats

Where qualification happens

Security, privacy and LGPD

  • Dashboard Qualifications by progress and risk level, with each area's open items.
  • Supplier portal Individual, secure link, with the contracting company's brand.
  • PDF report Summary, risk, sign-offs, documents and history.
  • Emails Invitation, open items and outcome, with your brand.
  • Spreadsheet Export of the qualification list.
  • ESGreen Score With the supplier's public signals, inside the process.

The decision is yours. The evidence is on record.

ESGreen organizes the process and the evidence; approving or rejecting a supplier is always the client's decision. The public data in the process follows the ESGreen Score Methodology, and personal data processing is described on the Trust page.

Frequently asked questions

Short answers to the most common questions.

Still have questions? Talk to an expert

Does ESGreen approve the supplier?

No. The decision always rests with the client: each area records its own sign-off. ESGreen organizes the process, gathers the public data and keeps the evidence of each step.

Does Supplier qualification work for clients and partners?

No. Supplier qualification is designed for corporate suppliers, before contracting. For clients and partners, ESGreen offers the Pre-assessment, with the risk of a CNPJ or CPF on the lookup date, and continuous Monitoring.

Does the supplier need to create a login?

No. The supplier accesses the portal through an individual, secure, time-limited link, sent in the invitation under the contracting company's brand.

Can I use my own questions, documents and risk scale?

Yes. Areas, owners, questions, mandatory or conditional documents, templates by risk level and classification criteria are configured by your company. Each qualification keeps the version of the scale used.

What is the difference between Supplier qualification, Pre-assessment and Monitoring?

Pre-assessment shows the public risk of a CNPJ or CPF on the lookup date. Supplier qualification runs a supplier's assessment before the contract, with questionnaires, documents and each area's sign-off. Monitoring tracks the base after that and alerts you when something changes.

What happens after approval?

The supplier can move on to continuous Monitoring. When an alert comes up, the Alert Center shows the latest qualification result alongside it and records the follow-up through to the decision, including the decision to keep the supplier qualified.

Can the supplier see internal comments?

No. The supplier sees only what is theirs: invitation, terms, questionnaires, documents, open items and outcome. Internal comments and the dossier are restricted to your team.

Shall we organize your supplier qualification?

In 30 minutes, we show Supplier qualification applied to your procurement process: risk scale, reviewing areas and supplier portal.

  • Qualification demo with procurement and compliance cases
  • A conversation about your company's risk scale and reviewing areas
  • Pre-assessment of supplier CNPJs in your base

Or write to contato@esgreen.com.br

Tell us what you need

Fields marked with * are required.

We use this email to reply.

Client, supplier or partner. An expert gets back to you with the pre-assessment.

0 of 2,000