Overview
Due diligence teams — in investment, M&A, and procurement alike — spend real time and money trying to answer a deceptively simple question: is this counterparty's ESG conduct actually what it claims to be? A verified certificate doesn't eliminate that work, but it changes its starting point substantially. This guide explains how to use Standard ESG certification as a practical screening and ongoing-monitoring tool.
What Due Diligence Teams Are Actually Trying to Solve
ESG due diligence exists to answer questions that matter financially and legally: does this target have undisclosed environmental or labour liabilities? Is its governance robust enough to trust its other representations? Could its ESG conduct create reputational or regulatory exposure after the deal closes? Traditionally, answering these questions meant commissioning bespoke environmental and labour audits, reviewing self-reported disclosures with appropriate skepticism, and hoping nothing material had been concealed. A verified certificate doesn't replace this work entirely, but it changes what a diligence team is starting from — evidence-backed data rather than purely self-reported claims.
Reading a Certificate as a Screening Signal
The first, and most important, discipline in using certification for due diligence is reading the level and score together, never the score alone. The level tells you how much independent verification sits behind the score; the score tells you how the company performed within that verification depth. A 9/10 at Level 1 and a 9/10 at Level 3 are not equivalent signals, even though the number is identical — see How the Standard ESG 1–10 Score Works for exactly why the protocol is built this way.
Level 1: A Baseline, Not a Clearance
A Level 1 certificate tells you a company has completed a structured questionnaire and passed an internal plausibility and gates review — useful as an initial screen (it confirms a baseline level of ESG formalization, and confirms the hard gates around child/forced labour and undisclosed corruption sanctions weren't triggered), but it should not, on its own, substitute for deeper diligence on a transaction of any real size or risk. Treat it the way you'd treat a self-reported compliance questionnaire in any other domain: a useful starting filter, not a clearance.
Level 2: Meaningful Document-Backed Confidence
A Level 2 certificate is meaningfully stronger evidence: the company's answers have been substantiated by individually verified documents — permits, policy documents, payroll samples, audit reports — with unsubstantiated claims discounted automatically in the underlying score (see The ESG Evidence Checklist). For most standard commercial due diligence — supplier onboarding, portfolio-company monitoring, mid-sized transactions — a Level 2 certificate provides a genuinely useful degree of assurance that can reduce, though not eliminate, the scope of bespoke ESG diligence work needed.
Level 3: The Strongest Available Signal
A Level 3 certificate reflects on-site physical verification, confidential worker interviews conducted away from management, and declared data traced back to source records — see What to Expect from an On-Site ESG Assessment. For higher-stakes transactions — significant investments, acquisitions, or supply-chain relationships in higher-risk sectors (manufacturing, extractives, agriculture, any labour-intensive operation) — a Level 3 certificate is the strongest single piece of third-party ESG evidence a diligence team can currently obtain without commissioning a fully bespoke audit, and the accompanying Findings & Recommendations Report gives diligence teams specific, itemized detail beyond just the headline score.
Reading Score and Level Together
A practical way to combine the two signals in a due diligence memo:
- Level 1 — Low score (1–4): material concern; deeper diligence required regardless of any other factor. Mid score (5–7): plausible but unverified; treat as a starting hypothesis to test. High score (8–10): positive but self-reported; still confirm independently for significant transactions.
- Level 2 — Low score (1–4): material concern, now document-backed; investigate the specific weak indicators. Mid score (5–7): reasonably credible baseline; scope further diligence to specific gaps. High score (8–10): strong, evidence-backed signal; may reduce (not eliminate) bespoke diligence scope.
- Level 3 — Low score (1–4): serious concern — even on-site verification found issues; treat as a significant red flag. Mid score (5–7): credible, independently observed performance with room for improvement. High score (8–10): strongest available third-party signal short of a bespoke, transaction-specific audit.
The QR Verification Workflow in a Due Diligence Process
Before relying on any certificate presented during diligence, confirm it independently: scan the QR code or look up the certificate ID on the public verification page, and confirm the status shown as active, the level and score match what was represented to you, and the company name matches the legal entity actually under diligence — not a parent, subsidiary, or affiliate with a similar name. See Verify a Certificate for the complete verification workflow. This step takes minutes and should be a standing item in any diligence checklist that references third-party ESG certification, precisely because it costs nothing and closes an easy gap (a lapsed or revoked certificate presented as though still valid).
Revocation and Expiry: What They Tell You
Two status signals carry specific diligence meaning beyond simply "not currently active":
- Expired certificates should prompt a direct question to the counterparty about why renewal hasn't occurred — it may be entirely benign (timing, administrative delay), but it removes the assurance the certificate previously provided and warrants asking rather than assuming.
- Revoked certificates are a materially different and more serious signal: revocation occurs for cause — fraud, a gate violation discovered after issuance, or misuse of the certificate or badge — and should be treated as a significant red flag warranting direct investigation, not a routine administrative lapse. See The Standard ESG Certification Protocol: A Public Overview for exactly what triggers revocation.
Certification as Ongoing Monitoring, Not Just a Point-in-Time Check
Because certificates carry a 12-month validity window and a public, live verification page, they support ongoing portfolio monitoring in a way a one-time bespoke audit doesn't: an investor holding a position, or a buyer maintaining a supplier relationship, can periodically re-check a counterparty's verification page as a low-cost, standing monitoring practice, rather than only investigating ESG conduct at the point of initial investment or onboarding. A certificate that quietly lapses or gets revoked between your last review and now is a signal worth catching promptly, not discovering months later during an unrelated review.
Supply-Chain Due Diligence at Portfolio Scale
For investors and buyers managing due diligence across many counterparties or suppliers simultaneously — a common challenge given ISO 20400's emphasis on sustainable procurement at scale — certification levels provide a practical basis for risk-based segmentation: requiring higher-risk suppliers or larger positions to hold at least a Level 2 certificate, reserving bespoke, resource-intensive diligence for situations where certification isn't available or where the certified level doesn't match the risk profile of the relationship. This mirrors exactly the "risk-based supplier segmentation" approach ISO 20400 itself recommends — see the ISO 20400 primer — applied specifically using certification level as the segmentation signal.
One structural point matters here: Standard ESG does not certify a company's suppliers through that company's own certificate, so a buyer relying on supply-chain certification for diligence purposes needs each individual supplier to hold its own certificate — a parent company's strong certification doesn't transitively certify its supply chain.
A Practical Due Diligence Checklist
- Independently verify the certificate via QR code or certificate ID, not just the PDF presented.
- Confirm the certificate covers the exact legal entity under diligence.
- Read level and score together — never rely on the score alone.
- For Level 1 certificates on significant transactions, scope additional bespoke diligence rather than treating the certificate as sufficient on its own.
- Request the Findings & Recommendations Report where a Level 3 certificate exists — it contains far more specific, actionable detail than the certificate alone.
- Set a calendar reminder to re-check the verification page periodically for any ongoing relationship, not just at initial onboarding.
- For supply-chain diligence, confirm certification status supplier-by-supplier — don't assume it flows down from a parent entity.
Standard ESG (standardesg.org) certificates are designed to be independently, continuously verifiable — built specifically to support exactly this kind of diligence and monitoring use. See The Three Certification Levels Explained for the full detail behind each level referenced here.
Cette page vous a-t-elle été utile ?