C
The Procurement Codex
The lifecycle, as a system · Free & open
⚙️

Fully autonomous project. The Procurement Codex is built, verified, and published end-to-end without manual authoring. Its core logic — the spine, the layer model, and the platform comparison rubric — is rebuilt and improved on every iteration for continuous method validation. Content is generated programmatically and refined each cycle: treat it as a directional learning aid, verify against primary sources, and send corrections — accuracy and fairness compound with each pass.

Episode 14 · Where the supply chain becomes a liability

Risk, Compliance & ESG

For most of this spine, a supplier is a source of goods. Here they become a source of exposure — financial, operational, regulatory and reputational. And since roughly 2023, in a growing number of jurisdictions, what your suppliers and their suppliers do has become something you are legally required to know.

Below: the plain concept → how every major platform handles it → best practice → process mining, AI, orchestration and ownership, stacked until standalone is never enough.

L0 · The Concept

What it is

Third-party risk and ESG management is the identification, assessment, mitigation and continuous monitoring of what could go wrong through a supplier: financial failure, operational disruption, sanctions and corruption exposure, cyber and data risk, labour and human rights conditions, and environmental impact — including at tiers you do not contract with.

Why it exists

Because the consequences do not stay with the supplier. A tier-two failure stops your line, a sanctioned counterparty is your regulatory breach, and a labour violation deep in your chain is your headline. Regulation has followed: due diligence obligations now attach the buyer to conduct several tiers away, which converts risk management from prudence into compliance.

What good looks like

Risk is assessed proportionately at onboarding and then monitored continuously, not re-surveyed annually. Screening runs automatically against the supplier master and re-runs when anything changes. ESG data is collected once, in a shared standard, rather than through bespoke questionnaires from every customer. Critical categories have mapped sub-tiers. Findings trigger workflow, not a filing.

L1 · Platform-Native — A vs B vs C

Same rubric for every vendor, 1–5. We state explicitly what each is best and worst at. Toggle platforms to compare.

Platform Best at Watch-out

Scores are directional teaching aids based on typical deployments, not vendor benchmarks. Your mileage varies by configuration, module licensing, scope, and integration maturity.

L2 · Best Practice

Design principles
  • Segment risk before assessing it — a stationery supplier and a sole-source component maker in a sanctioned region do not warrant the same diligence. Proportionality is what makes the programme survivable.
  • Monitor continuously, do not re-survey — risk changes between annual questionnaires. Automated monitoring of financial, sanctions, enforcement and news signals detects change in days rather than at the next renewal.
  • Screen against the entity, not the name — sanctions and ownership screening only works against verified legal entities and beneficial ownership from Ep07. Name matching alone produces false positives and misses real ones.
  • Collect ESG data once, in a shared standard — bespoke questionnaires from every customer create enormous supplier burden and poor data. Shared assessment platforms and recognised standards are the difference between response rates of 20% and 80%.
  • Go beyond tier one where the law and the risk require it — modern due diligence obligations and most real disruptions live below your direct contract. Map sub-tiers for critical categories rather than all of them.
  • Make findings trigger workflow, not filing — a risk finding with no owner, no date and no gate into sourcing or onboarding is documentation of a problem you decided not to fix.
KPIs & failure modes
  • KPIs — percentage of spend under continuous monitoring, time to detect a material change, screening coverage of the active supplier base, ESG assessment coverage by spend, sub-tier mapping depth for critical categories, finding remediation rate and ageing.
  • Point-in-time diligence — screened once at onboarding, never again, so a supplier sanctioned two years later remains an approved vendor in the master data.
  • Questionnaire fatigue — hundreds of bespoke ESG questionnaires with low response rates and unverified self-reported answers that nobody has the capacity to challenge.
  • Tier-one blindness — a well-managed direct supplier concealing a single sub-tier dependency that stops your line or carries the labour risk.
  • Findings without gates — risk is assessed and reported but never blocks an award or an onboarding, so the assessment has no consequence and eventually no credibility.
  • Screening false-positive overload — untuned name matching generating thousands of alerts, which trains the team to clear alerts rather than investigate them.
  • ESG as a reporting exercise — data collected purely to populate a disclosure, disconnected from sourcing decisions in Ep03 and performance reviews in Ep13.

The Layer Peeler — watch standalone become a system

Stack layers onto a one-off onboarding questionnaire and watch the architecture — and the outcome metrics — change. This is the whole thesis of the Codex in one control.

Outcome at this stack level
Spend monitored
Time to detect
Sub-tier mapped
Findings remediated

L7 · The Synergy Composite

A real best-of-breed risk and ESG architecture is never one product. Here is the composite, and where the value actually lives — in the seams.

flowchart LR
SUPP[Ep07 golden supplier record
legal entity and ownership] --> SCREEN[L1 Automated screening
sanctions, PEP, adverse media] SEG[L2 Risk segmentation
by category, geography and criticality] --> DEPTH{How deep to look} SCREEN --> MON[L5 Continuous monitoring
financial, cyber, news, enforcement] RATE[L1 ESG assessment
EcoVadis / IntegrityNext / self-assessment] --> MON DB[Dun and Bradstreet
financial and ownership data] -.entity truth.-> MON SUB[L4 Sub-tier discovery
n-tier mapping and trade data] -.tier two and beyond.-> MON MON --> FIND{L5 Finding
severity and jurisdiction} LAW[L2 Due diligence obligations
CSDDD, LkSG, UFLPA, Modern Slavery] -.what must be evidenced.-> FIND FIND --> ACT[L6 Owned remediation
plan, dates and escalation] PM[L3 Process mining and analytics] -.exposure concentration.-> DEPTH ACT --> GATE[Back to Ep03 sourcing and Ep07 onboarding
as an approval gate] ACT --> SI[Ep15 · Spend Intelligence]

Standalone, a risk module produces a questionnaire archive. Wired to Ep07 for verified legal entities, to ratings and monitoring providers for evidence you did not generate yourself, to sub-tier discovery for the exposure you did not contract for, and to Ep03 and Ep07 as an actual approval gate, it becomes a defensible due diligence system rather than a filing cabinet. No single vendor supplies entity truth, sanctions data, ESG assessment and n-tier visibility at once — the seams are the compliance evidence.

The Stack Builder — compose your own

Pick one from each column. The Codex assembles the composite and calls out where the seams need engineering. Shown here for third-party risk, compliance and ESG; the same engine powers every episode.

Cheat Sheet — Risk, Compliance & ESG

The 5-second definition

Work out what could go wrong through your suppliers and their suppliers, in proportion to how much it would hurt, keep watching, and make what you find actually block something.

KPIs that matter

Spend under continuous monitoring · time to detect · screening coverage · ESG coverage by spend · sub-tier mapping depth · finding remediation ageing.

Scorecard in one line

If a risk finding has never stopped an award, you have a reporting function, not a control.

Platforms in one line

Suites win on workflow and integration into sourcing and onboarding; ratings and data providers win on evidence and coverage; nobody has a complete n-tier picture.

The layers

L0 onboarding questionnaire → L1 screening and assessment → L2 proportionate segmentation → L3 exposure analytics → L4 sub-tier discovery → L5 continuous monitoring orchestration → L6 owned remediation → L7 composite.

The thesis

Standalone is never enough. Diligence becomes defensible only when entity data, external evidence, sub-tier visibility and enforcement gates are wired together.

Scenario Check

Question /