Key takeaways
- A controlled supply chain: consistent risk analysis across more than 1,200 suppliers.
- Automated assessment: calculation of the vigilance score and triggering of document-based or on-site audits.
- Smooth oversight: post-audit action plans managed with full traceability.
- Secured compliance: legal obligations under the duty of vigilance and future European requirements (CS3D/CSRD).
A demanding regulatory context, a need for reliability and traceability
Since 2017, large French companies subject to the duty of vigilance have been required to publish an annual Vigilance Plan describing the measures intended to prevent serious harm to human rights, health and safety, and the environment.
To meet these requirements, the organization in this case study must:
- carry out rigorous mapping of internal and external risks,
- regularly assess its tier-one suppliers,
- implement corrective action plans,
- ensure solid governance capable of managing risks across an international scope.
Present in more than 100 countries and active in several sectors (cosmetics, textiles, packaging), the company operates in a complex environment marked by highly variable social, environmental, and geopolitical issues.
The real difficulty: volume, complexity, and inconsistency
Before digitalisation, the Procurement, CSR, and Compliance teams faced major challenges. The first lay in managing a large mass of data that had to be qualified and kept up to date. More than 14,000 suppliers were analyzed, of which roughly 1,200 were considered eligible for an annual assessment.
Risk levels varied according to the purchasing category, the country of operation, the volume of business, and the certifications and labels held. This context called for a multi-criteria analysis that was difficult to manage manually.
The vigilance score depended on the combination of three components: activity-related risk; country risk, calculated from the indicators supplied by EcoVadis (used as an independent reference source to incorporate environmental, social, human rights, governance, and country-stability factors); and risk related to revenue or purchasing volume. This analysis, carried out entirely by hand, proved especially time-consuming and error-prone.
The audit workflows were also highly inconsistent. Between document-based audits, SMETA-type on-site audits, and reference certifications (such as ISO 14001, ISO 45001, SA8000, and others), practices differed considerably from one area to the next, leading to oversights and a lack of uniformity. Added to this was the scattering of action plans. Manual tracking, carried out across different time zones, allowed for neither clear traceability, nor smooth coordination, nor a consolidated view of remediation actions.
How BlueKanGo transformed the management of the duty of vigilance
Faced with these challenges, digitalising the processes emerged as an essential response to optimize the management of the duty of vigilance and strengthen operational efficiency.
- Full centralization of the supplier database
All key information was brought together in a single space: supplier sheets, sites, purchasing volumes, certifications, audit histories, and compliance levels. Now, everyone involved (whether in procurement, auditing, or compliance) draws on the same single source of truth.
- Automated risk analysis
BlueKanGo's quality software automatically applies the company's internal methodology, ensuring a qualitative assessment, a CSR/DV (duty of vigilance) rating, calculation of the vigilance coefficient, and automatic risk classification (low, medium, or high). This process, previously fragmented, has become fast, consistent, and standardized.
- Automatic triggering of the assessment type
Based on the risk level determined, the platform automatically adjusts the type of audit required. No audit is conducted for a low risk; a document-based audit is triggered for a medium risk (BlueKanGo retrieves the EcoVadisscore directly, sparing teams from carrying out a manual assessment); and an on-site audit (SMETA-type or based on an equivalent standard) applies for a high risk. The appropriate audit grid opens automatically according to the supplier's profile, whether a manufacturer or a distributor.
- Integrated management of document-based and on-site audits
BlueKanGo handles planning, campaign management, the centralization of supporting materials, the analysis of results, and the assignment of a score ranging from A to D.
- Action plan tracking
At the end of each audit, an action plan is generated automatically, owners are designated, evidence is centralized, and automatic reminders are scheduled to ensure deadlines are met.
Suppliers have restricted access that allows them to record their own actions, which considerably lightens the load on internal teams.
- Consolidated governance and KPIs
The platform provides a global dashboard, offers visibility into risk areas, enables tracking of the three-year audit plan, and displays the status of action plans. All this data feeds directly into the internal steering committees.
Results: a robust, lasting system
The company is seeing a drop in the number of non-compliant suppliers, along with the complete harmonization of practices across every country where it operates. Management is now handled more strategically, without the need to consolidate data manually.
Legal obligations such as the duty of vigilance, the CS3D, and the CSRD are better managed, while automation delivers significant time savings.
Conclusion
BlueKanGo enabled the company to industrialize its duty-of-vigilance system and make it more reliable on a global scale. The platform is now the digital foundation of responsible oversight, ensuring advanced risk management, transparent governance, and the continuous improvement of environmental and social practices. It now stands as a model of maturity for supplier risk control and sustainable compliance.