The problem this solves: which suppliers first

A due-diligence programme with a thousand suppliers and the capacity to assess forty a quarter does not have an information problem, it has an ordering problem. UFLPA and CSDDD both expect a risk-based approach, which means the order has to be defensible: not the biggest suppliers, not the ones someone remembered, but a ranking you can show the reasoning behind. That is what this produces from three columns — a supplier list ranked by impact × risk, with every number decomposable into factor, weight and source.

The eight factors, and what each is worth

Risk is what could go wrong at that supplier. Impact is what it costs you if it does. A supplier who is high on one and low on the other is not an emergency; the ones high on both are the wave you send first.

RISK — WHAT COULD GO WRONG THERE
Country risk0.15corruption, labour rights, environment and rule of law, from published indices
Sector risk0.15what the work itself carries, before location
Conflict minerals0.103TG exposure implied by what they make
Incident history0.10sanctions, forced-labour and debarment findings against them
Information opacity0.10how little they have disclosed — not knowing is a risk, not a neutral
IMPACT — WHAT IT COSTS YOU
Annual spend0.15what you buy from them, from your own ledger
Substitution difficulty0.15how replaceable they are — sole source is the hard case
Continuity criticality0.10what stops if they stop

Two of the risk factors are knowable before you upload anything, and they are published openly: see country × sector baselines for the country and sector halves. The other three need a specific company, which is what the upload supplies.

Not knowing is not the same as low risk

The factor most tools quietly drop is the one for missing information. A supplier who has disclosed nothing scores worse than one who has disclosed something unflattering, and a supplier you sent a questionnaire to who did not answer scores worse still than one you never asked — because you paid to find out and they declined. Otherwise the ranking rewards opacity, and the least visible part of the supply base sinks quietly to the bottom of the list.

Questions people ask before uploading a list

What do I have to upload?
Three columns: supplier name, the country the work happens in, and annual spend. Anything else you have is used if it is there and inferred if it is not, with the inference labelled as one.
Does my spend data leave my account?
No. Spend is private tenant data: it is never rendered on any public page and never leaves your own account. The public pages on this site are built from published reference data and public filings only.
Can I see why a supplier ranked where it did?
Every score decomposes into factor × weight × source. A ranking you cannot take apart is one you cannot defend to an auditor, which is the situation this is meant to replace.
Is the score a model output?
No, and deliberately. Scoring is deterministic arithmetic over published indices and your own figures — the same inputs always produce the same number. No model decides who you assess.
What if I do not know a supplier's country or spend?
The rank still computes and says what it assumed. A supplier you know nothing about is not treated as low risk: not knowing is itself a factor, weighted as information opacity.
No list to hand yet? Screening needs only names, takes no account, and is the fastest way to see whether anything in your supply base is already listed.Free sanctions check →