See the full list of cookies
Look up a CNPJ Talk to an expert Menu

Solutions for companies

Every company outsources part of its own risk.

Structured supplier qualification, continuous monitoring of the base and documented follow-up of every alert, by CNPJ and CPF, for Procurement, Compliance and Sustainability.

An ESGreen specialist replies within one business day to schedule a time.

What already applies and what is coming

  • Decree 11,129 In force Risk-based due diligence on third parties, in force
  • Law 14,133 In force Integrity program within 6 months for large-scale contracts
  • EUDR Published Proof of zero deforestation to export to the European Union; large and medium operators first
  • CSDDD Published Due diligence by large European companies, passed on to suppliers

See the full regulatory map

of monitored companies have at least 1 active alert
~48%
alerts on national restrictive lists
240+
alerts on international sanctions lists
95+
alerts from news and media
1.600+

Source: ESGreen consolidated monitoring base, 2025. Published Sep 2026.

Check the ESG risk of a CNPJ

Enter the CNPJ of a supplier, client or partner. An expert gets back to you with the pre-assessment.

Accepts the new alphanumeric CNPJ.

The lookup is not automatic. An ESGreen expert reviews the request and replies by email.

A supplier's risk is not static.

A certificate can expire, a lawsuit can arise, a company can land on a restrictive list months after it was approved.

  • Qualification is only the beginning.

    Qualification shows the supplier on the day it comes in. Without continuous monitoring and a recorded follow-up, what changes after the contract can take months to be discovered, and even longer to be resolved.

  • The risk has already materialized.

    33% of companies suffered financial loss or reputational damage in the last three years due to vulnerabilities linked to suppliers, partners or service providers. 28% had direct production disruptions.

    Source: KPMG, 2026 Global Third-Party Risk Management Survey, 851 organizations.

  • Clients and lenders ask.

    Banks and cooperatives assess the social and environmental risk of those they finance. European buyers send supply chain due diligence questionnaires. The answer needs evidence, not declarations.

Between one lookup and the next, blind spots appear.

Where third-party risk shows up in the company

Procurement and sourcing
Scattered information requires manual work to consolidate data and prioritize incidents.
The team spends time gathering data instead of deciding.
Onboarding and qualification
Every new supplier requires documents, certificates and sign-off from several areas.
Without a single process, requests are repeated by email and the decision leaves no trace.
Compliance and integrity
Decree 11,129 calls for appropriate, risk-based due diligence when hiring and supervising third parties.
Legal, tax, socio-environmental and reputational risks can slip off the radar.
Sustainability and reporting
Sustainability reports and client questionnaires ask for data on the value chain.
Data needs a source and a date to withstand the next question.
Legal
A supplier's lawsuits, embargoes and sanctions reach the contracting company.
Late discovery becomes a problem in an audit, a credit renewal or an investigation.
Executive board
Reputation and business continuity.
In practice, the supplier's risk becomes the company's own risk.

On both sides of the chain

For those who hire

Know, track and address the risk of every third party.

  • Structured qualification, with risk level and each area's sign-off
  • Continuous monitoring of the base
  • Alerts handled with a follow-up deadline and a recorded decision
  • Case logs and resolution of pending items with the counterparty
Explore Supplier qualification

For those being assessed

Show your ESG maturity with evidence.

  • Questionnaire with 400+ ESG criteria by company size and CNAE
  • AI-assisted document validation
  • Alignment with the UN SDGs
  • Annual progress history
Explore Evidence Assessment

From qualification to follow-up, in the same process

  1. Structured qualification.

    Every new supplier comes in with a risk level, questionnaires and documents by area and the sign-off of whoever is responsible for each, before the contract.

  2. Continuous monitoring.

    After approval, the base remains tracked by CNPJ and CPF in auditable sources, with alerts organized by type and by company and the ESGreen Score recalculated with every relevant new event.

  3. Documented follow-up.

    In the Alert Center, each alert reaches the right area with the result of the latest qualification alongside. The team works it through with the supplier and records the decision, with a follow-up deadline and an audit trail.

Value shows up in day-to-day use: indicators defined with the client

Base coverage
share of suppliers qualified and under monitoring.
Alert handling
analysis and recording of relevant incidents.
Use in decision-making
how Score and history support the team's prioritization.

From qualification to the committee, on the same database.

  • Qualify suppliers with risk criteria.

    Explained risk level, questionnaires and documents by area, a supplier portal with your brand and each area's sign-off recorded.

    Module: Supplier qualification

  • Monitor the entire base at once.

    Suppliers, clients and partners tracked by CNPJ and CPF, instead of being revisited only at contract renewal.

    Module: ESGreen Monitoring

  • Handle every alert through to a decision.

    Alerts routed to the responsible area, a conversation with the supplier, a follow-up deadline and a final decision recorded in the audit trail.

    Module: Alert Center

  • Look up a CNPJ before the conversation.

    Consolidated Score, registration data and CNAE, clearance certificates, ownership structure with politically exposed persons, lawsuits and critical risks, in one report.

    Module: ESGreen Pre-assessment

  • Track certificates, lawsuits and news across the portfolio.

    Each topic on its own dashboard, with each company's history, to anticipate what needs attention.

    Module: Lookup centers

  • Measure the ESG maturity of the supply chain.

    Questionnaires by company size and CNAE, with AI-assisted document validation and an annual history.

    Module: ESGreen Evidence Assessment

  • Support the integrity program.

    Risk-based due diligence when hiring and supervising third parties, with dated evidence.

    Module: Supplier qualification and ESGreen Monitoring

  • Integrate risk into the procurement ERP.

    Lookup via API and alerts in the onboarding flow, with the integration scope defined in the proposal.

    Module: Data & API

Platform modules for companies

A platform in three layers: data, intelligence and applications. Every result can be traced back to its source.

  • Supplier qualification

    Risk level, questionnaires and documents by area, a supplier portal and each area's sign-off, before the contract.

  • ESGreen Monitoring

    Intelligence and automation in third-party risk management: suppliers, clients and partners.

  • Alert Center

    Every alert with a responsible area, a follow-up deadline, a conversation with the supplier and a recorded decision.

  • Lookup centers

    Lawsuits, certificates, news and self-assessments across the portfolio, each topic on its own dashboard.

  • ESGreen Pre-assessment

    Individual report by CNPJ or CPF for qualification, onboarding, credit and compliance.

  • ESGreen Evidence Assessment

    ESG maturity with 400+ criteria by company size and CNAE and AI-assisted document validation.

  • ESGreen Score

    ESG risk from 0 to 1,000 (the higher, the lower the risk), across 12 layers, recalculated with every new event.

  • Data & API

    70+ sources and delivery via API, dashboard, report, alerts and batch.

Every requirement mapped to a data point, a piece of evidence and a report.

The company is the one that complies with the regulation. ESGreen provides data, evidence and an audit trail.

See the full regulatory map

Regulations for companies: status, requirements and how ESGreen helps
RegulationStatusWhat it requiresHow ESGreen helps
Law 12,846/2013 (Anti-Corruption) + Decree 11,129/2022, art. 57, XIII In force

Integrity program with appropriate, risk-based due diligence to contract and oversee third parties, including politically exposed persons.

Supplier qualification at contracting, continuous monitoring and the Alert Center during supervision, with restrictive lists, sanctions and ownership structure.
Law 14,133/2021 (public procurement), art. 25, §4º In force

Integrity program within 6 months of signing large-scale contracts (R$261,968,421.04 in 2026, under Decree 12,807/2025).

Dated evidence of due diligence on the supply chain for those that contract with the public sector.
CMN Res. 4,945/2021 (lenders' PRSAC) In force

Banks and cooperatives apply their social and environmental policy to the clients they finance.

Organized evidence of ESG risk and maturity for the conversation with the lender.
CVM Res. 193/2023 + CVM Res. 244/2026 VoluntaryFor listed companies; "comply or explain" model on the way

Voluntary IFRS S1/S2 reporting, with a commitment of at least 3 fiscal years and assurance for those that adopt it.

Value chain risk data with source, date and version to support reporting.
EUDR (EU Regulation 2023/1115) PublishedApplied in phases: large and medium operators first, micro and small later. Deforestation cutoff date of December 31, 2020

Zero-deforestation due diligence for soy, cattle, coffee, cocoa, palm oil, rubber and wood exported to the European Union.

Checks for embargoes, deforestation and territorial overlaps by suppliers' CNPJ, CPF and property.
CSDDD (EU Directive, Omnibus I) PublishedApplying further ahead, through large European companies that pass the requirement on to suppliers

Supply chain due diligence by companies with more than 5,000 employees and €1.5 billion in revenue, which pass questionnaires on to suppliers.

Supplier monitoring and Evidence Assessment to answer European clients' questionnaires.
CBAM (European Union) In forceDefinitive regime already applied; certificate sales on the way

Carbon cost on imports of steel, iron, aluminum, cement and fertilizers, among others.

A topic we follow in Research for exporters in these sectors.
LGPD (Law 13,709/2018) In force

Legal basis, data protection officer and data subject rights in the processing of personal data.

Processing of CPFs with an appointed data protection officer (DPO) and a channel for data subjects; details on the Trust page.

Deadlines are set by regulators and may change. Official dates and estimates, with the review date, are on the regulatory map.

Where each requirement stands today

Deadlines may change. The direction does not: every requirement moves from drafting to consultation, from publication to effectiveness. And the evidence it will call for needs a history.

Status of regulations for companies
  1. Under development

    Foreseen in an official document, with no date set in a rule yet.

    • TSB: MRV Portal and first wave (S1 and S2 banks, asset managers, funds and listed companies) TSB
    • TSB: second wave, with credit cooperatives, insurers and pension funds TSB
    • TSB: mandatory verification by accredited verifiers TSB
  2. Proposed

    Under consultation or with a proposed timeline. The direction is already set.

    • SBCE: monitoring plan for regulated facilities SBCE
  3. Published

    Rule published. The requirement takes effect in stages.

    • EUDR: zero-deforestation due diligence for large and medium-sized operators EUDR
    • CVM 244: “comply or explain” model CVM 193/244
    • CBAM: sale of certificates CBAM
    • EUDR for micro and small operators EUDR
    • CSDDD: supply chain due diligence by large European companies, passed on to suppliers CSDDD
  4. In force

    Already applies. Evidence must be kept up to date.

    • CVM 244: voluntary IFRS S1/S2 reporting for listed companies CVM 193/244
    • CBAM: definitive regime for European imports CBAM

Documented recognition, technology present in real decisions

In chapter 6, “Responsible Solutions”, of the Sicredi 2025 Sustainability Report, ESGreen is cited as the platform used to monitor and assess supplier ESG.

“Today we have a customizable, agile platform that centralizes all the analysis of our supply chain, records every interaction with suppliers and generates a comparable ESG Score in minutes.”

Bruno Virtuoso, Procurement and Sourcing Manager, Sicredi

Sicredi 2025 Sustainability Report, ch. 6, p. 127 (GRI 2-6 | 3-3)

Read the Sicredi case study

“This move was key to getting us qualified by a multinational and to facing RFPs with confidence.”

Osmar Pedrozo, CEO, SoftDesign
Read the SoftDesign case study

“Meetings became more objective, team engagement increased and we started making strategic decisions based on concrete data.”

Jeder Dubczak, Process Analyst, Guarida

Clients who trust ESGreen

  • Sicredi
  • Ailos
  • Guarida
  • Cotabox
  • Data Rudder
  • Timenow

85K+ companies monitored continuously, 70+ integrated sources. Data as of Sep 2026.

In the procurement ERP, in onboarding and at the committee.

Via API, dashboard, report or alert.

  • Report by CNPJpre-assessment ready for integration with procurement, credit or compliance systems.
  • Dashboardmonitored base with ranking, filters, Score and incident history.
  • Alertsby type and by company, with the change identified.
  • APIlookup in the onboarding and qualification flow. Documentation on request.
  • Batchload of the supplier base at once, to start monitoring.

Security, privacy and LGPD: See the Trust page

Frequently asked questions

Short answers to the most common questions.

Still have questions? Talk to an expert

What is supplier monitoring?

It is the process of continuously tracking the compliance, financial, legal and reputational risk of the companies in the supply chain, cross-referencing data from multiple public sources instead of relying only on a one-time qualification.

What is the difference between supplier qualification and continuous monitoring?

Qualification assesses the supplier at entry, before the contract. In ESGreen Supplier qualification, this includes risk level, questionnaires and documents by area and each area's sign-off. Continuous monitoring tracks the supplier after approval and captures the changes that arise while the contract is in force. In the Alert Center, the team handles each alert and records the decision.

Which lists and sources are checked?

More than 70 public, regulatory and global sources: national and international restrictive lists, sanctions lists, lawsuits, federal, state, municipal, labor and environmental certificates, registration and corporate data, and news.

What is the difference between Pre-assessment and Monitoring?

ESGreen Pre-assessment is an individual report by CNPJ or CPF, on demand, used in qualification, onboarding or credit analysis. ESGreen Monitoring tracks the entire base continuously, with alerts and incident management.

My company is assessed by clients. Can ESGreen help?

Yes. ESGreen Evidence Assessment applies an ESG maturity questionnaire with 400+ criteria by company size and CNAE, validates the submitted documents with AI assistance and keeps an annual history. The result is a maturity rating that the company can present to clients, lenders and buyers.

Does ESGreen certify suppliers?

No. ESGreen does not issue certifications. It provides data, evidence and an audit trail so that the contracting company makes and records its own decisions: in Supplier qualification, each of the client's areas records its own sign-off. The ESGreen Score and the maturity rating do not constitute a credit rating or legal opinion.

How we assess

How many of your suppliers have an active alert right now that you have not seen yet?

In a 30-minute conversation, we show the infrastructure applied to your base of suppliers, clients and partners.

  • Demo of qualification and the Alert Center with procurement and compliance cases
  • CNPJ pre-assessment of your supplier base
  • Reading of active alerts in a sample of your supply chain

Or write to contato@esgreen.com.br

An ESGreen specialist replies within one business day to schedule a time.

Tell us what you need

Fields marked with * are required.

We use this email to reply.

Client, supplier or partner. An expert gets back to you with the pre-assessment.

0 of 2,000