esg due diligence, supply chain screening, esg transactions, sustainability reporting, esg risk scoring
ESG Due Diligence for UK Transactions and Supply Chains
By ESG Consulting Team · · 20 min read
The most popular advice on ESG due diligence is to check whether a target has the right policies, statements and board approvals. That's a useful starting point, but it's a weak finishing line. A modern slavery statement can satisfy a disclosure process while revealing very little about whether supplier risks are identified, remediated and monitored in practice.
For UK deal teams, the more useful question is different: can the target prove what happens beyond its immediate suppliers, and can it support each material sustainability claim with controlled evidence? Buyers, lenders and investors increasingly need diligence that works as an operational control, not a polished compliance file. The difference affects transaction risk, post-deal integration, reporting obligations and the defensibility of public claims.
Table of Contents
- Moving Beyond Compliance Readiness to Operational Traceability
- Scoping Materiality for Transactions and Supply Chains
- Collecting Auditable Data Across the Value Chain
- Scoring Risks and Defending Sustainability Claims
- Building Evidence Trails That Survive External Assurance
- Reporting Findings and Integrating the ESG Action Plan
Moving Beyond Compliance Readiness to Operational Traceability
A compliant file can still conceal operational risk. Operational traceability shows what the organisation did, who approved it, which supplier or site was affected, what evidence supported the decision, and whether the issue was resolved. That record is what a buyer, lender, auditor or regulator can test. A policy describes intent, but it does not establish performance.
Section 54 of the Modern Slavery Act 2015 requires commercial organisations supplying goods or services with total turnover of £36 million or more to publish a slavery and human trafficking statement each financial year. The statement must be approved by the board, signed by a director and made available prominently on the organisation's website. Those requirements create a clear disclosure duty, but they do not prove that the underlying programme operates effectively.
The UK responsible sourcing analysis found that only 14% of companies could show clear improvements from their responsible sourcing programmes, while 25% did not measure impact at all. It also reported board-level oversight at 46% of companies and stakeholder feedback from only 9%. The latter finding has a direct implication for evidence design: supplier questionnaires alone will rarely demonstrate how workers experience the controls or whether remediation has reached them.
Practical rule: A signed statement is an output. A defensible diligence process is the evidence chain behind it.
What traceability changes
A compliance-readiness review asks whether the target has:
- A modern slavery statement: Is it published, approved and accessible?
- A supplier code: Does it describe expected standards?
- A screening process: Does the organisation assess suppliers before onboarding?
- A reporting framework: Does it disclose relevant climate and sustainability information?
An operational review tests the record behind each answer. Which suppliers were screened, on what date and against which criteria? What happened when a supplier failed? Can the business connect a responsible-sourcing claim to contracts, worker feedback, corrective actions and follow-up verification? Does the evidence cover subsidiaries, sites, subcontractors and relevant upstream relationships, or only the entities easiest to contact?
The distinction matters because public wording can exceed operational proof. A target might describe thorough supplier oversight while holding only self-assessments from immediate vendors. It might refer to remediation without records showing who owned the action, what deadline applied, whether workers were consulted or how closure was verified.
Frame diligence around consequences
Start with the potential post-deal consequence, then work backwards to the evidence required. A supply-chain blind spot might create human rights exposure, interrupt delivery, undermine a customer qualification or make a sustainability label difficult to defend. A weak emissions boundary might distort a transition plan or prevent the buyer from integrating the target into group reporting.
This approach changes how gaps are classified. Missing Tier-N evidence is not merely a documentation issue. It may mean the buyer cannot validate a claim, quantify an exposure or assign a credible remediation cost. The diligence report should distinguish policy existence, process operation, outcome evidence and claim support, then identify the owner and next action for each material gap.
The UK's direction of travel reinforces that need. Final UK Sustainability Reporting Standards were expected in 2026, with phased Scope 1 and Scope 2, followed by Scope 3, disclosures in later reporting cycles, according to UK and EU ESG commentary from Simmons & Simmons. For transactions, the sensible response is to establish a traceable chain for information likely to affect value, risk and future reporting. Collecting more documents is not a substitute for knowing which evidence supports each conclusion.
Scoping Materiality for Transactions and Supply Chains
Materiality should determine the diligence budget before fieldwork starts. Treating every issue equally wastes management time, generates unfocused document requests and can still leave the facilities, suppliers or claims with the greatest deal impact untested. Starting late creates the opposite risk: material gaps emerge after valuation, deal protections or integration assumptions have already hardened.
Use a staged scope that moves from screening to evidence collection to targeted verification. The ESG materiality assessment guidance offers a useful structure for prioritisation, but the transaction team must connect those priorities to the target's operating model, value drivers and proposed ownership model.

Start with a focused desk review
The first review should map the target's operating footprint, value-chain profile, regulatory exposure and public claims. Examine the corporate structure, sites, products, procurement categories, major customers, supplier geographies, environmental permits, incident records, workforce arrangements and published sustainability information.
Prioritise signals that change the depth of testing:
- Operational concentration: A small number of facilities or suppliers may account for a disproportionate share of production or revenue.
- Sector exposure: Labour-intensive, resource-intensive or heavily regulated activities require closer examination.
- Geographic complexity: Multiple jurisdictions can create different expectations for labour, environmental performance, data and reporting.
- Transaction-specific value drivers: A low-carbon product, public-sector contract or sustainability-linked financing arrangement needs evidence that supports the relevant commercial proposition.
- Public claims: Labels, ratings, transition statements and stewardship narratives need their own support check.
The desk review is a filter, not a substitute for verification. It should show where an impact may be significant, likely or difficult to remediate, and where a claim may not survive scrutiny without stronger records.
Use management discussions to test ownership
Management interviews should test what the documents show. Ask who owns each material metric, which systems produce the source data, how exceptions are escalated and what happens when a supplier refuses or fails to provide information. A confident answer without a record is a lead for further testing, not evidence of control.
Record the responsible owner, decision rights and escalation route for each priority issue. This makes later requests more precise and exposes whether a control operates in practice or exists only in policy.
The BII Toolkit methodology supports a sequence of desk review, management discussions and site visits to at least a representative sample of existing facilities and any new project sites. Screening findings should set the diligence scope, so material ESG aspects are understood and managed through an action plan that ranks gaps by significance and resource need.
Select sites and suppliers deliberately
A representative sample should reflect risk, not convenience. Select locations according to operational importance, workforce profile, environmental sensitivity, recent incidents and the reliability of existing records. Include new project sites where construction, permitting or community impacts could affect the transaction.
For the supply chain, map beyond the immediate vendor where the product, material or risk requires it. The review depth can differ by supplier, but the file should explain why certain categories, countries, subcontractors or raw materials received more attention. That rationale is part of the assurance trail.
A useful scope decision records four points:
- The material issue, such as labour conditions, emissions, water, waste, governance or claims.
- The affected boundary, including operations, subsidiaries, direct suppliers and relevant upstream relationships.
- The evidence needed, such as contracts, bills, system extracts, grievance records, permits or verification reports.
- The transaction decision, whether the finding affects price, conditions precedent, warranties, integration resources or ongoing monitoring.
This record links the diligence conclusion to its evidence and commercial consequence. It also shows why the team examined particular parts of the business, helping the final report remain a defensible account of the deal's material ESG exposure rather than a disconnected list of observations.
Collecting Auditable Data Across the Value Chain
A completed supplier questionnaire is not an audit trail. It is a starting point. Buyers often collect responses, upload spreadsheets and treat the response rate as visibility, yet those answers rarely prove the underlying position without supporting records.
Supplier self-reporting should therefore be tested against purchase records, contracts, invoices, production information, site documentation, incident logs and other source-level evidence. Where information remains incomplete, record the limitation and its effect on the conclusion. Do not turn an unresolved gap into a precise-looking estimate.
For climate work, the Scope 3 emissions guidance provides useful context, but the transaction team must still define the target's actual boundary, activity data and calculation method.
Establish the data boundary before requesting numbers
Write a boundary statement for every material metric. Identify the entities, facilities, activities, reporting period, exclusions, estimation methods and responsible owner. For emissions, specify whether the boundary follows operational control, financial control or another stated basis. Explain how acquisitions, disposals, leased assets and outsourced activities are treated.
The same discipline applies to social and governance information. A modern slavery metric should state which suppliers, workers, geographies and remediation cases it covers. A health and safety figure should identify the workforce population, treatment of contractors, incident definitions and source systems. Without these definitions, two apparently comparable numbers may describe different realities.
Build a source hierarchy
Evidence should be ranked by its proximity to the underlying activity. A practical hierarchy may start with primary system records and signed operational documents, followed by independently verified information, supplier declarations and management representations. The ranking is not universal. A source's reliability depends on the metric and the control over its creation, so the file should explain why the selected evidence is fit for purpose.
For each data point, retain:
- The source owner: Who created or approved the record?
- The system or document: Where is the original information held?
- The extraction date: When was it retrieved?
- The transformation: What calculations, conversions or adjustments were applied?
- The reviewer: Who checked the result and challenged anomalies?
- The limitation: What remains uncertain or unsupported?
A controlled data register is more useful than a large folder of attachments. It allows the buyer to trace a reported claim to its origin, identify where judgement entered the process and reproduce the calculation for review.
Treat supplier engagement as investigation
Questionnaires are effective when they trigger targeted follow-up. A supplier reporting no modern slavery risk should still be assessed against its workforce, labour model, recruitment practices and subcontracting arrangements. A supplier reporting low emissions should explain its boundary, activity data and calculation method.
Set an escalation path before requests are issued. A non-response, inconsistent evidence or severe issue may require a management call, site visit, corrective action plan, worker or stakeholder feedback, independent verification or a commercial decision. Record the request, response, challenge and resolution. The final status alone does not show how the team exercised judgement.
A missing document isn't always the main risk. The bigger risk is losing the record of how the team responded when the document was missing.
Deep-tier traceability needs a separate workplan where upstream inputs drive the exposure. For example, tracing a raw material two tiers upstream may require purchase orders linking the supplier to a mill, mill certificates identifying the material, and chain-of-custody records connecting it to the relevant production batch. Check whether those documents cover the entity, period and volume in scope. If the chain stops at an intermediary and no reliable record connects the material to the mill, record that boundary as unverified rather than presenting the Tier 1 response as proof.
When a requested document cannot be produced, log the request date, supplier response, escalation step taken and residual risk rating in the diligence register. This record is what allows a buyer to defend its conclusion when evidence remains incomplete.
Scoring Risks and Defending Sustainability Claims
A risk score that ranks environmental or social impact without testing the supporting evidence is inadequate for a transaction. Deal teams must assess whether the target can substantiate its public position, maintain an audit trail and correct wording that exceeds what the records support. A moderate operational issue with clear evidence may have a defined remediation route. A less visible issue paired with an unsupported “responsible” or “low-carbon” claim can create regulatory, customer and transaction risk.

Score impact and proof separately
Use two dimensions rather than forcing every finding into one composite number:
- Impact exposure: How severe could the environmental, social or governance consequence be, and how likely is it to occur?
- Evidence strength: Can the organisation support the assertion with source-level records, defined boundaries, review controls and evidence of the stated outcome?
This approach distinguishes a serious issue that is well documented from a modest issue supported by unreliable records. The first may have an agreed remediation route and a clear owner. The second may require immediate action on the claim, even if the underlying risk has not been fully quantified.
Evidence strength matters under the FCA's anti-greenwashing regime and the wider UK focus on sustainability claims. Apply the test to product labels, ratings, stewardship narratives, transition statements and customer-facing environmental descriptions. The appropriate response is not always more data collection. The defensible decision may be to narrow, defer or remove a claim until the available evidence supports the wording.
Translate the score into deal mechanics
A score must lead to a decision. For each material finding, identify the commercial consequence, the responsible owner and the protection available to the buyer:
- Price adjustment: Use where remediation has a credible cost or the exposure could affect expected performance.
- Specific warranty or indemnity: Use where the buyer needs contractual protection against a defined historical issue.
- Condition before completion: Use where the risk must be addressed before control transfers.
- Post-completion action plan: Use where the issue is manageable but needs resources, ownership and milestones.
- Claim restriction: Use where marketing or reporting language currently exceeds the evidence.
- Walk-away decision: Consider where impact is severe, records are unreliable and remediation has no credible route.
Document why the proposed action follows from the evidence. A generic red rating does not tell an investment committee whether to request a warranty, reserve integration capacity, restrict communications or challenge the transaction thesis. The decision record should identify the evidence reviewed, the gaps that remain and the point at which the residual risk becomes unacceptable.
Make claims defence part of the workplan
Test every material claim against three questions. What exactly is being asserted? What boundary does it cover? What evidence demonstrates that the wording is accurate and current?
A responsible-sourcing claim may require supplier screening records, contract clauses, grievance information, corrective-action outcomes and evidence of upstream coverage. An emissions-reduction claim may require a baseline, calculation files, activity data, approval records and proof that the reduction does not result solely from a boundary change. Record the source, owner, reporting period and review status for each item, so the conclusion can be reconstructed without relying on interview recollection.
The FCA's anti-greenwashing approach and UK ESG litigation developments make the distinction commercially relevant. Diligence protects the buyer by identifying poor outcomes and stopping the business from repeating wording that its evidence cannot sustain.
The practical test is direct. If a regulator, lender, customer or journalist requested the file supporting a claim, could the team retrieve the source data, explain the methodology and show how it handled incomplete evidence? If not, the score should record that weakness and the claim should be restricted until the evidence improves.
Building Evidence Trails That Survive External Assurance
A signed diligence report cannot make weak data reliable. If source files lack ownership, boundaries, approvals and documentary support, the report may need rebuilding when the target enters group reporting or receives an assurance request. Evidence quality is therefore an operational issue, not a formatting exercise.
Treat diligence outputs as assurance workpapers from the first day. Design the file for a reviewer who was absent from management interviews and will not accept an unexplained spreadsheet as proof. A clear trail should connect each conclusion to its source, calculation, review and approval.
Test the controls behind each metric
For every material datapoint, identify the control that supports its reliability. Who enters the data? Who reviews it? What prevents duplicate records? How are late adjustments handled? Which system is authoritative when reports conflict?
Test system boundaries as well. A target may report operational emissions from facilities under direct control while excluding leased sites, outsourced activity or newly acquired operations. A supplier metric may cover approved vendors but omit subcontractors. The exclusion may be legitimate, but the file must state it, explain its relevance and show who approved the boundary.
A practical assurance file includes:
- A metric definition: Calculation method, boundary, units and reporting period.
- A source register: Original records, system locations and data owners.
- A reconciliation: Checks against financial, procurement or operational data.
- An assumptions log: Estimates, proxies, exclusions and judgement calls.
- A review trail: Questions raised, responses received and approvals completed.
- An exceptions record: Missing evidence, unresolved discrepancies and planned actions.
This structure helps post-deal integration because the buyer can distinguish a verified baseline from an inherited estimate. A sustainability reporting consultant can help define the file structure where internal ownership or technical capacity is limited, but management must retain accountability for the evidence.
Understand the assurance limitation
UK assurance engagements do not all test ESG information to the same depth. The FRC found that 75% of FTSE 350 assurance engagements used limited assurance, with 64 providers serving the market in 2022, while 44 providers completed only one or two engagements, according to the FRC-related ESG assurance maturity analysis. A signed report therefore does not prove that every underlying process is established or that every relevant metric was tested.
The same analysis identifies ISAE 3000 as the most common standard. The applicable scope, procedures and assurance level determine what the conclusion means. Deal teams should ask what was tested, what was excluded and whether the engagement covered the metric or claim that matters to the transaction.
Make ownership visible
A control without an owner will weaken during integration. Assign each material metric to a named function, identify the data custodian and record who approves external wording. The buyer should know whether each gap sits with procurement, finance, operations, human resources, legal or sustainability.
In KPMG's most recent maturity survey, only 23% of respondents reported a clear audit trail for non-financial information, and only 31% reported strong policies and procedures supporting ESG disclosures, according to the UK ESG assurance maturity findings. The figures reinforce the practical point: assurance readiness depends on connecting ownership, systems and evidence before sign-off, not on producing a polished report at the end.
Reporting Findings and Integrating the ESG Action Plan
A diligence report earns its place in a transaction by making decisions easier, not by documenting every observation at equal length. A material supplier blind spot should stand out from minor policy gaps, with a clear explanation of its consequence and the action required.
Open with an executive view linking each finding to risk, value, timing and action. Follow it with enough evidence for legal, finance, operations and sustainability teams to test the conclusion. The report should support an investment committee decision while giving an assurance reviewer a traceable route from the finding to the underlying record.
Prioritise by significance and capacity
Rank actions by the seriousness of the impact and the capability required to close the gap. Cost should inform prioritisation, but it should not decide it alone. Some findings require management attention, specialist support, supplier influence or capital expenditure before they can be treated as closed.
Use a consistent action record:
- Finding: What the diligence identified.
- Boundary: Which operations, sites, suppliers or claims are affected.
- Evidence: Which documents, systems and interviews support the conclusion.
- Consequence: What could happen commercially, operationally or reputationally.
- Owner: Which function is accountable for the response.
- Timing: What must happen before completion, during integration or through business-as-usual monitoring.
- Verification: What evidence will demonstrate closure.
Modern slavery reporting shows why publication alone is an inadequate completion test. Section 54 applies to qualifying organisations with turnover of £36 million or more and requires board approval, director signature and prominent access from the homepage, according to the Modern Slavery Act reporting requirements. The action plan should therefore test supplier coverage, remediation records, worker feedback, escalation routes and impact measurement. A signed statement with no supporting operating records leaves a buyer exposed to the same underlying risk.
Climate findings require equivalent treatment. The UK required over 1,300 of its largest companies and financial institutions to disclose climate-related risks and opportunities in line with the TCFD Recommendations from 6 April 2022. UK guidance also requires annual-report disclosure of Scope 1 and Scope 2 emissions, at least one intensity ratio and narrative on energy-efficiency actions, with Scope 3 included where material, as described in the UK climate disclosure analysis. The transaction report should record whether the target has a defensible inventory, a defined boundary and evidence for the stated reductions. It should also separate work required before signing from work that can sit within the integration plan.
Use a decision matrix
| Risk Category | Evidence Strength | Commercial Action |
|---|---|---|
| Severe impact with verified records | Strong, with clear ownership and documented response | Require a defined remediation plan, contractual protection and post-completion monitoring |
| Material impact with incomplete upstream evidence | Moderate or weak, particularly beyond direct suppliers | Expand targeted diligence, restrict unsupported claims and price the traceability work |
| Climate metric with unclear boundary | Insufficient to validate the reported result | Rebuild the inventory, define the boundary and make reporting a completion or integration condition |
| Public sustainability claim without source support | Weak claim-level evidence | Narrow, defer or remove the wording until the evidence is controlled |
| Policy gap with no identified operational consequence | Limited evidence of implementation need | Assign an owner and include the issue in the proportionate integration backlog |
| Repeated finding with no closure record | Weak control and poor outcome evidence | Escalate to senior governance and consider specific warranties, indemnity or transaction restructuring |
Make the action plan usable after completion
Treat the action plan as an integration control, with the same governance cadence as procurement, finance, legal and operational workstreams. Track evidence received, overdue actions, supplier responses, changes to public claims and unresolved assumptions. Each status update should link to a record, not rely on a general statement that work is progressing.
The team also needs to state what remains unknown. UK companies continue to face difficulty obtaining the data required for ESG assurance. 46% of companies surveyed in 2025 said inadequate access to data was a growing challenge, up from 33% in 2024, and 54% of UK companies still struggled with inadequate ESG data access, according to UK ESG assurance findings. The practical response is to cost the gap, assign an owner and define the evidence needed to close it. Unsupported confidence is not a control.
Transaction timing affects bargaining power. A 2024 ESG due diligence study found that 71% of respondents said ESG had become more important in transactions over the previous 12 to 18 months. Buyers that complete this work before signing can use the findings to shape protections, conditions and the integration budget. Buyers that postpone it often inherit remediation without the same ability to secure evidence or allocate responsibility.
ESG Consulting helps UK organisations build transaction-ready evidence across carbon reporting, Scope 3 value-chain mapping, climate-related disclosures, UK SRS and CSRD readiness. If your deal team needs a materiality-led diligence scope, controlled data lineage or an ESG action plan that can move into post-deal reporting, visit ESG Consulting to discuss the evidence gaps before signing.
More from the blog

· 12 min read · Regulation
What is PPN 026? The new Social Value Model
PPN 026 replaces PPN 002 as the Social Value Model for central government contracts from 1 January 2027. Scope, the 10% and 20% weightings and the six criteria.
Read article
· 14 min read · Regulation
UK ESG reporting deadlines for 2026 and 2027
Every UK ESG reporting date to December 2027 - UK SRS, ESOS, SECR, UK CBAM, CSRD, SBTi, PPN 026 and the NHS - each marked mandatory, proposed or voluntary.
Read article