Responsible procurement is the practice of identifying, preventing, mitigating and accounting for adverse environmental, human-rights, labour and integrity impacts connected to buying decisions and supply chains. It is not a supplier questionnaire or an ESG score: it is a risk-based operating process.
TL;DR
Translate enterprise commitments and legal duties into category-specific risks, requirements, evidence and ownership.
Prioritise the severity and likelihood of harm, not only supplier spend or a generic rating.
Use supplier evidence to inform decisions, but do not mistake certificates, policies or self-attestation for proof of outcomes.
Put remediation, escalation, monitoring and exit rules into the operating model before onboarding suppliers.
Apply stronger due diligence where the product, country, workforce, recruitment model or supply-chain tier creates greater risk.
What responsible procurement covers
ESG is commonly used as a broad label for environmental, social and governance factors. In procurement, the more useful question is: which adverse impacts can this buying decision cause, contribute to or be directly linked to through a business relationship—and what can the organisation do about them?
The OECD Due Diligence Guidance for Responsible Business Conduct describes risk-based due diligence across operations, supply chains and business relationships. The UN Guiding Principles on Business and Human Rights provide the widely used “protect, respect and remedy” framework.
Environmental impacts
greenhouse-gas emissions and credible transition plans;
energy, water and resource use;
pollution, waste and hazardous materials;
biodiversity, land use and deforestation; and
product durability, repairability and end-of-life treatment.
People and human rights
forced labour, child labour and human trafficking;
worker health, safety, pay and freedom of association;
recruitment fees, migrant-worker vulnerability and labour agencies;
discrimination, harassment and community impacts; and
access to grievance and remedy.
The International Labour Organization’s 2022 global estimates report 27.6 million people in forced labour. That figure is a reason to design meaningful due diligence, not a substitute for understanding risk in a specific category or supply chain.
Governance and integrity
bribery, corruption, conflicts of interest and sanctions exposure;
ownership, control and beneficial-owner transparency;
data protection, cybersecurity and responsible technology use;
tax, competition and whistleblowing controls; and
the supplier’s ability to govern its own subcontractors and upstream tiers.
A practical due-diligence process
1. Embed responsibility and policy
Name an accountable executive, operational owner and specialist reviewers. Define which impacts the organisation prioritises, which standards apply and how purchasing decisions will change when evidence is weak or harm is found.
2. Map category and supply-chain risk
Assess the inherent risk of the product or service, geography, workforce, raw materials, recruitment route, subcontracting model and depth of the supply chain. Do not apply the same questionnaire and approval path to every supplier.
3. Define proportionate evidence
Specify what evidence is needed for each material risk. This may include workforce and recruitment information, licences, policies, audit reports, incident history, emissions methodology, traceability records, grievance data and corrective-action plans. Record the source, date, scope and limitations of each item.
4. Evaluate and decide
Separate three things: supplier claims, verified facts and procurement judgement. A certificate can support a decision, but it rarely proves the absence of harm. Score the evidence and residual risk, document exceptions and route high-consequence decisions to the right authority.
5. Contract for action and access
Contract terms should reflect the actual risk and operating model. Consider information and notification duties, subcontractor controls, audit or access rights, corrective-action plans, cooperation with investigations, record retention, remedy and termination rights. Legal advice is required for jurisdiction-specific drafting.
6. Monitor, engage and remediate
Monitoring should combine scheduled evidence refreshes with event-driven signals such as ownership changes, incidents, allegations, regulatory action or material subcontracting changes. When harm is found, the response should consider leverage, engagement and remedy—not default automatically to termination, which can worsen outcomes for affected people.
7. Communicate and improve
Report what was assessed, what was found, which actions were taken and what remains uncertain. Test whether controls change outcomes. Update category strategies, supplier requirements and escalation rules using that evidence.
Supplier questions that reveal more than a generic ESG score
Which parts of this contract will be subcontracted, and where?
How are workers recruited, and can any worker-paid recruitment fees occur?
Which upstream materials or locations create the greatest human-rights or environmental risk?
What incidents or substantiated allegations occurred during the assessment period?
How can workers or communities raise concerns without retaliation?
Which metrics are measured directly, estimated or supplied by third parties?
What corrective actions are open, who owns them and how is closure verified?
What change would trigger immediate notification to the buyer?
Common failure modes
Questionnaire theatre: collecting answers without testing evidence or changing decisions.
One score for every risk: collapsing distinct impacts into an unexplained composite number.
Tier-one blindness: assessing the direct supplier while ignoring the workforce, material or geography where the risk sits.
Policy as proof: treating a published policy as evidence that practice follows it.
No route to remedy: identifying harm without ownership, leverage, escalation or a plan for affected people.
Automatic exit: terminating relationships without considering whether disengagement increases harm.
Modern-slavery statements and legal scope
Legal obligations differ by jurisdiction and change over time. In the UK, official Home Office transparency-in-supply-chains guidance explains Section 54 of the Modern Slavery Act 2015 and the annual statement requirement for organisations in scope. Use current official guidance and legal advice to determine whether an organisation is covered and what its statement must contain.
Where technology helps—and where it does not
Technology can help collect evidence, map relationships, monitor defined signals, manage reviews and retain an audit trail. It cannot decide the organisation’s risk appetite, verify every upstream fact or replace engagement with affected stakeholders.
For a broader market view, see the Supplier Risk AI Platforms vendor landscape. Evaluate any platform using the procurement software buyer framework, then test coverage, data provenance, refresh frequency, explainability, workflow fit and escalation handling against representative suppliers.
How this connects to supplier risk management
Responsible procurement is one part of a wider supplier-risk operating model. Use Supplier Risk Management Explained to design segmentation, ownership, assessment, monitoring and response. Use Third-Party Risk Management Explained where cybersecurity, privacy, compliance, operational resilience and other cross-functional risks must be coordinated.
FAQ
Is responsible procurement the same as ESG procurement?
The terms overlap, but responsible procurement is more operational. It focuses on due diligence, decisions, leverage, remediation and accountability rather than relying on a broad ESG label or score.
Should every supplier receive the same questionnaire?
No. Start with inherent category and supply-chain risk, then request evidence proportionate to the potential impacts and the supplier’s role.
Does a low risk score prove that a supplier is safe?
No. A score reflects a method, inputs and point in time. Review its source coverage, assumptions, date, blind spots and the decision it is being used to support.
Is this legal advice?
No. This is a procurement operating framework. Confirm jurisdiction-specific duties, contractual language and reporting requirements with qualified legal advisers and current official guidance.
