Scope 3 emissions: the numbers you have to ask other people for
Scope 3 covers emissions from your value chain, and it is usually most of the total. The fifteen categories, where to start, and how to get supplier data.
A vendor due diligence checklist that procurement can actually run — the evidence to demand, proportionate tiers, and how to keep the answers current after onboarding.
A vendor due diligence checklist is the evidence you require from a supplier before signing, and the reason you can defend the decision afterwards. It is not the same document as a deal checklist: you are not buying the company, you are letting it near your customers, your data or your production line. What matters is whether the supplier can do the work, survive the contract term, and not create a liability that lands on you.
Running the full vendor due diligence checklist on every supplier is how procurement earns a reputation for obstruction. Decide the tier from exposure, not from spend alone.
Ask for bank details through a separate verified channel and confirm them by telephone against a number you looked up yourself. Supplier payment fraud almost always arrives inside an otherwise legitimate onboarding thread.
Email threads are where vendor due diligence goes to die: attachments land in three inboxes, nobody can say which version is current, and the expiry dates live in people’s memories. Send the checklist as a form instead. Ettex Forms turns each line into a field with a required attachment, so a partial response is visibly partial and the answers arrive in one place, timestamped. The completed responses then belong on the supplier record with their review dates, next to the contract — which is where supplier onboarding and the wider procurement process pick the work up.
Certificates expire, owners change, and a supplier that was solvent at tender can be in difficulty by the second renewal. Give every Tier 1 and Tier 2 answer a review date and let the register surface what has gone stale. This ongoing half of the job is what third party risk management describes, and it is the half that most organisations skip; a supplier audit then becomes the only mechanism for finding out, long after the exposure started.
A vendor due diligence checklist that produces a written decision — approved, approved with conditions, or declined, with the evidence attached — is worth more than a longer list that produces a feeling. The decision is what you will be asked to justify.
Direction and purpose. Client due diligence is an anti-money-laundering obligation about who you take money from; vendor due diligence is a risk and capability assessment of who you pay. The evidence overlaps on identity and ownership, nothing else.
Yes for lower tiers. For Tier 1, ask for the certification scope or an independent report; a self-assessment tells you what a supplier believes about itself.
Annually for Tier 1, at renewal for Tier 2, and immediately on a trigger — a change of ownership, a breach notification, a missed delivery that revealed a subcontractor you did not know about.
Scope 3 covers emissions from your value chain, and it is usually most of the total. The fifteen categories, where to start, and how to get supplier data.
A change control process assesses, approves and records changes before they happen. The stages, who decides what, and the shortcuts that cause the outages.
A supplier audit is a sampling exercise, not an inspection. How to choose what to test, what a finding is worth, and why the closure is the real deliverable.