Supplier Risk Intelligence

Supplier Risk Intelligence Report

Prepared for
Beispiel Industriegruppe AG
Assessment Scope
LkSG §5 / CSDDD Art. 7-11 — Tier 1 Suppliers (with CBAM, REACH, UFLPA Screening)
Assessment Date
2026-04-15
Report ID
ATESTA-RPT-2026-0418-SCH
Data Freshness
Signals current as of 18 Apr 2026
Classification
Confidential — Client Use Only

Executive Summary

Portfolio risk overview for 25 assessed Tier-1 suppliers across sanctions, LkSG compliance, facility verification, trade flow, media monitoring, country labour risk, and REACH/SVHC dimensions.

6
Clear

No adverse signals detected

1
Flagged

Requires immediate review

18
Insufficient Data

Additional signals needed

Critical Findings

Risk Distribution by Dimension

Sanctions
25 / 25
LkSG Filing
7 / 25
Facility
3 / 25
Trade Flow
0 / 25
Media
0 / 25
Labour Risk
22 / 25
CBAM
14 / 25
REACH/SVHC
25 / 25
11 suppliers trade in CBAM-covered products — steel (11). EU importers must report embedded carbon from 2026.
Estimated default carbon intensity: steel: 1.84 tCO\u2082e/t. These are regulatory defaults, not verified supplier figures.

Key Recommendation

Initiate enhanced due diligence on Beispiel Automation GmbH before the next quarterly LkSG review. For the 18 supplier(s) with insufficient data, consider requesting direct LkSG self-declarations to supplement signal-derived assessments. All 6 clear suppliers can proceed through standard procurement without additional action.

Supplier Risk Matrix

Assessment across four risk dimensions. Confidence reflects signal coverage and entity resolution quality.

Supplier Country Sanctions LkSG Filing Facility Trade Flow Media Labour Risk CBAM REACH Confidence
Beispiel Stahlwerke GmbH & Co. KG DE Clear Compliant No Data N/A N/A Low In Scope (1) Low
0.60
Example Green Steel AB SE Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.50
Example Electronics Co., Ltd. JP Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Example Semiconductors B.V. NL Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Example Schleifwerke AG & Co. KG AT Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Example Chemical Co., Ltd. JP Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Beispiel Automation GmbH DE Clear Compliant Anomaly N/A N/A Low Clear Low
0.70
Beispiel Holding GmbH & Co. KG DE Clear Compliant No Data N/A N/A Low Clear Low
0.60
Beispiel Metall GmbH DE Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.60
Example Circuit Co., Ltd. TW Clear Insuff. No Data N/A N/A Medium Clear Low
0.50
Beispiel Elektronik AG DE Clear Compliant Active N/A N/A Low Clear Low
0.70
Example Metallurgy Holdings Limited GB Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.50
Example Engineers International Limited IN Clear Insuff. No Data N/A N/A Medium In Scope (1) Low
0.50
Example Tools Ltd. IL Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.50
Example Shipping A/S DK Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Beispiel Chemie GmbH & Co. KG DE Clear Compliant Active N/A N/A Low In Scope (1) Low
0.70
Beispiel EWS GmbH AT Clear Insuff. Active N/A N/A Low Clear Low
0.60
Beispiel Präzisionstechnik KG DE Clear Insuff. No Data N/A N/A Low Clear Low
0.60
Beispiel Verpackung GmbH DE Clear Compliant No Data N/A N/A Low Clear Low
0.60
Example Precision Co., Ltd. JP Clear Insuff. No Data N/A N/A Low Clear Low
0.50
Example Stål AB SE Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.50
Example Forge Limited IN Clear Insuff. No Data N/A N/A Medium In Scope (1) Low
0.50
Beispiel Logistik GmbH DE Clear Compliant No Data N/A N/A Low Clear Low
0.60
Beispiel Brücken GmbH DE Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.60
Example Steel Holdings Inc. KR Clear Insuff. No Data N/A N/A Low In Scope (1) Low
0.50

Supplier Profiles — Detailed Assessment

In-depth analysis for flagged suppliers and selected high-importance clear suppliers.

Beispiel Automation GmbH

DE · Germany
LEI: Not available
VAT: Not available
Product:Capital equipment / automation systems

Sanctions Screening

Clear

OFAC SDN: No match found.

EU Consolidated List: No match found.

Checked 18 Apr 2026

LkSG Filing Status

Compliant

Bundesanzeiger filing confirmed. LkSG §10 report identified and verified.

Last checked 18 Apr 2026

Satellite Verification

Anomaly Activity score: 0.15

Sentinel-2 imagery shows significantly reduced facility activity. Further investigation recommended.

Last image: 18 Apr 2026

Trade Flow

N/A

No US Customs trade data available for this supplier.

Data as of 18 Apr 2026

UFLPA Exposure

Clear

No direct or indirect UFLPA Entity List exposure detected. Screened against DHS entity list and cross-referenced with US Customs trade partners.

Cross-referenced 18 Apr 2026

Media & Public Reporting

N/A

GDELT news monitoring data not available for this supplier.

Scan as of 18 Apr 2026

CBAM Exposure

Clear

No CBAM-covered products identified in available trade data. Supplier's HS codes do not match Annex I of CBAM Regulation.

Classification: static (Annex I)

REACH / SVHC Exposure

Low 0 relevant SVHC(s)

Sector classification indicates low SVHC exposure likelihood. Standard REACH obligations apply.

This is sector-based screening, not material composition verification. Full REACH compliance requires supplier-side substance declaration data.

Source: ECHA SVHC Candidate List (2026-01) + NACE sector mapping

Country Labour Risk (DE)

Low 10 / 10 core ILO conventions

Germany has ratified all or nearly all fundamental ILO conventions. Labour indicators are within low-risk thresholds.

Source: ILO NORMLEX / ILOSTAT (2026-Q1)

Example Green Steel AB

SE · Sweden
LEI: Not available
VAT: Not available
Product:Green steel (hydrogen-reduced)

Sanctions Screening

Clear

OFAC SDN: No match found.

EU Consolidated List: No match found.

Checked 18 Apr 2026

LkSG Filing Status

Insuff.

No qualifying Bundesanzeiger filing found. May be a non-German entity or filing not yet published.

Last checked 18 Apr 2026

Satellite Verification

No Data Activity score: 0.50

No satellite imagery available for this facility.

Last image: 18 Apr 2026

Trade Flow

N/A

No US Customs trade data available for this supplier.

Data as of 18 Apr 2026

UFLPA Exposure

Clear

No direct or indirect UFLPA Entity List exposure detected. Screened against DHS entity list and cross-referenced with US Customs trade partners.

Cross-referenced 18 Apr 2026

Media & Public Reporting

N/A

GDELT news monitoring data not available for this supplier.

Scan as of 18 Apr 2026

CBAM Exposure

In Scope (1)

Supplier trades in CBAM-covered products: steel. EU importers must report embedded carbon under Regulation (EU) 2023/956.

HS codes: 7210.30.00

Estimated Embedded Carbon (Default Values)

Product tCO₂e / t Source
steel 1.63 Country-adjusted (SE)

⚠ Regulatory default values. Not verified supplier data. See Methodology for sources.

Classification: static (Annex I) + default carbon factors

REACH / SVHC Exposure

Low 0 relevant SVHC(s)

Sector classification indicates low SVHC exposure likelihood. Standard REACH obligations apply.

This is sector-based screening, not material composition verification. Full REACH compliance requires supplier-side substance declaration data.

Source: ECHA SVHC Candidate List (2026-01) + NACE sector mapping

Country Labour Risk (SE)

Low 10 / 10 core ILO conventions

Sweden has ratified all or nearly all fundamental ILO conventions. Labour indicators are within low-risk thresholds.

Source: ILO NORMLEX / ILOSTAT (2026-Q1)

Beispiel Elektronik AG

DE · Germany
LEI: Not available
VAT: Not available
Product:Automation / drives / factory digitalization

Sanctions Screening

Clear

OFAC SDN: No match found.

EU Consolidated List: No match found.

Checked 18 Apr 2026

LkSG Filing Status

Compliant

Bundesanzeiger filing confirmed. LkSG §10 report identified and verified.

Last checked 18 Apr 2026

Satellite Verification

Active Activity score: 0.90

Sentinel-2 imagery shows active facility operations. No significant anomalies detected.

Last image: 18 Apr 2026

Trade Flow

N/A

No US Customs trade data available for this supplier.

Data as of 18 Apr 2026

UFLPA Exposure

Clear

No direct or indirect UFLPA Entity List exposure detected. Screened against DHS entity list and cross-referenced with US Customs trade partners.

Cross-referenced 18 Apr 2026

Media & Public Reporting

N/A

GDELT news monitoring data not available for this supplier.

Scan as of 18 Apr 2026

CBAM Exposure

Clear

No CBAM-covered products identified in available trade data. Supplier's HS codes do not match Annex I of CBAM Regulation.

Classification: static (Annex I)

REACH / SVHC Exposure

Low 0 relevant SVHC(s)

Sector classification indicates low SVHC exposure likelihood. Standard REACH obligations apply.

This is sector-based screening, not material composition verification. Full REACH compliance requires supplier-side substance declaration data.

Source: ECHA SVHC Candidate List (2026-01) + NACE sector mapping

Country Labour Risk (DE)

Low 10 / 10 core ILO conventions

Germany has ratified all or nearly all fundamental ILO conventions. Labour indicators are within low-risk thresholds.

Source: ILO NORMLEX / ILOSTAT (2026-Q1)

Methodology & Audit Trail

Data Sources

Source Provider Refresh Cadence Last Pull Coverage
OFAC SDN List US Treasury / OFAC Daily 18 Apr 2026 25 / 25 suppliers screened
EU Consolidated Sanctions European Commission Daily 18 Apr 2026 25 / 25 suppliers screened
Bundesanzeiger Filings Bundesanzeiger Verlag Weekly 18 Apr 2026 10 / 25 (German entities)
US Customs / AES US Customs & Border Protection Daily 18 Apr 2026 0 / 25 (US trade routes)
Sentinel-2 Satellite ESA Copernicus Open Access Hub Per pass (~5 days) 18 Apr 2026 4 / 25 (imagery available)
GDELT 2.0 GDELT Project (300,000+ news sources, 120+ languages) Daily 18 Apr 2026 0 / 25 (news monitoring)
ILO NORMLEX ILO — Ratification of Fundamental Conventions Annual 2026-Q1 25 / 25 (country mapped)
ILO ILOSTAT ILO — Child Labour, Working Poverty, Informal Employment Annual 2026-Q1 25 / 25 (indicators available)
CBAM Product Scope EU Regulation 2023/956, Annex I (EUR-Lex) Static N/A (regulatory list) 11 / 25 (in scope)
CBAM Carbon Factors EU Implementing Reg. 2023/1773 + ECOINVENT v3.10 Annual (regulatory update) 2026-Q1 6 product categories (default + country-adjusted)
ECHA SVHC Candidate List European Chemicals Agency (ECHA) Biannual (Jan & Jul) 2026-01-23 25 / 25 (sector classified)

Entity Matching Methodology

Suppliers are resolved to a canonical identity using a priority-ordered matching strategy:

Priority Method Confidence Description
1 (Highest) LEI Match 0.95–1.0 Legal Entity Identifier via GLEIF API. Unique, globally standardized.
2 VAT / Tax ID 0.85–0.95 EU VAT number or national tax identifier. Cross-referenced with VIES.
3 Handelsregister 0.80–0.90 German commercial register number (HRB/HRA). German entities only.
4 (Lowest) Name Fuzzy Match 0.40–0.75 Jaro-Winkler similarity on normalized company name. Flagged when < 0.70.

Confidence Scoring Formula

aggregateConfidence = wsanctions × sanctionsScore + wlksg × lksgScore + wsatellite × satelliteScore + wcustoms × customsScore where weights: sanctions = 0.30, lksg = 0.25, satellite = 0.25, customs = 0.20 Missing signals receive score = 0.0 (penalizes incomplete coverage)

CBAM Screening & Carbon Estimation Methodology

The Carbon Border Adjustment Mechanism (CBAM, Regulation (EU) 2023/956) requires EU importers to report embedded carbon for covered products starting 2026. Atesta classifies suppliers by cross-referencing HS/CN codes from available trade records against the CBAM Annex I product scope covering six categories: iron & steel (CN 7201-7229, 7301-7326), aluminium (7601-7616), cement (2507, 2523, 6810), fertilisers (2808, 2814, 2834, 3102-3105), electricity (2716), and hydrogen (2804). Classification is static and based on the current regulation text.

Default carbon intensity factors: When actual production-specific emission data is unavailable, embedded carbon is estimated using EU CBAM Implementing Regulation (EU) 2023/1773 default values, cross-referenced with ECOINVENT v3.10. For electricity-intensive products (aluminium, hydrogen, steel), country-of-origin grid intensity adjustments are applied using IEA Emission Factors 2024. Values represent tCO₂e per tonne of product (direct + indirect emissions).

Product Category EU Default (tCO₂e/t) ECOINVENT Global Avg Emission Scope
Steel1.852.10Direct (BF-BOF) + electricity
Aluminium6.708.40Direct (smelting) + electricity (65%)
Cement0.660.73Direct (calcination + fuel) + electricity
Fertilisers2.562.90Direct (Haber-Bosch) + electricity + N₂O
Electricity0.420.48Generation mix (highly variable by origin)
Hydrogen9.3010.80Grey H₂ (SMR) baseline

These are regulatory default values for initial CBAM reporting. Verified supplier-specific data (via ZK proofs or direct measurement) will replace defaults when available.

REACH / SVHC Screening Methodology

REACH (Regulation (EC) No 1907/2006) requires disclosure when products contain Substances of Very High Concern (SVHCs) above 0.1% w/w. Atesta screens suppliers against the ECHA SVHC Candidate List (~240 substances) using sector-level classification based on NACE Rev.2 industry codes.

Sector Relevance NACE Divisions Rationale
High C20 (Chemicals), C22 (Plastics/Rubber), C26-C27 (Electronics/Electrical), C13-C15 (Textiles/Leather) Direct manufacturing, processing, or use of chemical substances in products
Medium C24-C25 (Metals), C29-C30 (Vehicles/Transport), C23 (Minerals), C31-C32 (Furniture/Other), F41-F43 (Construction) Processed materials where SVHCs may be present as contaminants or additives
Low All other sectors Minimal chemical substance handling

Important limitation: This is a sector-based screening indicator, not a material composition audit. High sector relevance does not confirm the presence of SVHCs in specific products. Full REACH compliance verification requires supplier-side substance declaration data, which Atesta plans to support via zero-knowledge proofs in a future release.

UFLPA Cross-Reference Methodology

Indirect UFLPA exposure is detected by cross-referencing US Customs trade flow data with the DHS UFLPA Entity List (~27 entities). For each supplier that passes the direct entity list screen, their customs import records are analysed to identify trading partners (shippers) whose names match UFLPA-listed entities using bigram similarity and Levenshtein distance (threshold: 0.85). Indirect exposure indicates the supplier sources from a UFLPA-listed entity at Tier-2, which may subject downstream US imports to withhold/release orders under UFLPA §3.

Country Labour Risk Methodology

Country-level labour risk is assessed using ILO data mapped to LkSG §5(1) requirements. Two data sources are combined into a composite score:

Component Weight Source LkSG Relevance
Core Convention Ratification 40% ILO NORMLEX — 10 fundamental conventions (C029, C087, C098, C100, C105, C111, C138, C182, C155, C187) §5(1) nos. 1–4, 7
Child Labour Rate 25% ILO ILOSTAT SDG 8.7.1 — % of children aged 5–17 §5(1) no. 4
Working Poverty Rate 15% ILO ILOSTAT SDG 1.1.1 — employed living below poverty line §5(1) no. 8 (living wages)
Informal Employment 20% ILO ILOSTAT — % of total employment §5(1) nos. 3, 7 (discrimination, freedom of association proxy)
Risk levels: Low (≥ 75 pts) · Medium (50–74) · High (30–49) · Critical (< 30)

Limitations and Caveats

Verifiable Credentials Issued. Each supplier in this report has been issued a W3C Verifiable Credential on the European Blockchain Services Infrastructure (EBSI). 25 credentials are embedded in this report. See the Cryptographic Proof section for downloads and verification instructions.

Cryptographic Proof — EBSI Verifiable Credentials

Each supplier assessment is backed by a W3C Verifiable Credential signed on the European Blockchain Services Infrastructure (EBSI). These credentials are tamper-proof, machine-readable, and independently verifiable without access to Atesta's systems.

Issuer DID did:ebsi:zXXXXXXXXXXXXXXXXXX
Algorithm ES256 (ECDSA on P-256)
Credential Type VerifiableAttestation / AtestaSupplyChainAttestation
Schema EBSI Trusted Schema Registry — atesta-supply-chain-v1
Credentials Issued 25
Download All Credentials (JSON)
Supplier Credential ID LkSG Status Confidence Issued Expires Download
Beispiel Stahlwerke GmbH & Co. KG 56f5f7fc… Compliant 0.60 2026-04-15 2026-04-15 JWT
Example Green Steel AB 5c484093… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Electronics Co., Ltd. e92e9bfa… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Semiconductors B.V. d78c164a… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Schleifwerke AG & Co. KG a44ae4cb… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Chemical Co., Ltd. 73074b34… Unknown 0.50 2026-04-15 2026-04-15 JWT
Beispiel Automation GmbH 4cf0bb79… Compliant 0.70 2026-04-15 2026-04-15 JWT
Beispiel Holding GmbH & Co. KG 49bbccf5… Compliant 0.60 2026-04-15 2026-04-15 JWT
Beispiel Metall GmbH fedd2900… Unknown 0.60 2026-04-15 2026-04-15 JWT
Example Circuit Co., Ltd. ede10623… Unknown 0.50 2026-04-15 2026-04-15 JWT
Beispiel Elektronik AG 1ea91eea… Compliant 0.70 2026-04-15 2026-04-15 JWT
Example Metallurgy Holdings Limited b9269c7e… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Engineers International Limited 2ec1d236… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Tools Ltd. 9cef824e… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Shipping A/S 663a4205… Unknown 0.50 2026-04-15 2026-04-15 JWT
Beispiel Chemie GmbH & Co. KG 1c97f8d7… Compliant 0.70 2026-04-15 2026-04-15 JWT
Beispiel EWS GmbH 015c29f2… Unknown 0.60 2026-04-15 2026-04-15 JWT
Beispiel Präzisionstechnik KG d4398a5a… Unknown 0.60 2026-04-15 2026-04-15 JWT
Beispiel Verpackung GmbH 8dc53e3d… Compliant 0.60 2026-04-15 2026-04-15 JWT
Example Precision Co., Ltd. e92a25a5… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Stål AB eb8b7638… Unknown 0.50 2026-04-15 2026-04-15 JWT
Example Forge Limited aa9ff54e… Unknown 0.50 2026-04-15 2026-04-15 JWT
Beispiel Logistik GmbH 6c7dcad7… Compliant 0.60 2026-04-15 2026-04-15 JWT
Beispiel Brücken GmbH 049271a3… Unknown 0.60 2026-04-15 2026-04-15 JWT
Example Steel Holdings Inc. 5e5fadd5… Unknown 0.50 2026-04-15 2026-04-15 JWT
How to verify: Each JWT credential can be independently verified by decoding the JWT header and payload, then checking the ES256 signature against the issuer's public key registered in the EBSI DID Registry.