Skip to main content
14 speakers. 7 enterprise risk teams. One day in Charlotte, Oct. 22.Save My Seat
BlackKite: Home
Menu
Back to Glossary

ESG Risk

ESG risk refers to Environmental, Social, and Governance factors that can affect a vendor's operational continuity, including climate-related disruptions, geopolitical instability, labor disputes, and governance failures. ESG risk is increasingly incorporated into third-party risk assessments alongside cybersecurity posture. Black Kite incorporates ESG risk data into its Business Interruption Factor Analysis of Information Risk (FAIR) scenario to model non-cyber disruption factors alongside technical cyber risk.

Why Do Regulators Now Treat Vendor ESG Risk as a Legal Duty?

ESG breaks into three categories that matter differently for vendor oversight:

  • Environmental risk: a vendor's climate impact and resource use.
  • Social risk: labor practices and human rights across its operations.
  • Governance risk: how well a vendor runs itself, including the security oversight that determines whether it can be trusted with data or system access.

The EU's Corporate Sustainability Due Diligence Directive turned vendor ESG due diligence from a voluntary reporting exercise into a legal duty for large companies, though a 2026 simplification package narrowed who that duty actually applies to.

The Corporate Sustainability Due Diligence Directive (CSDDD) requires large EU-scoped companies to identify, prevent, and address human rights and environmental harm across their vendor base, beyond their own operations. The directive entered into force in July 2024, and for two years it looked like the due diligence bar would keep rising. That changed on March 18, 2026, when the EU's Omnibus I simplification package narrowed the directive's direct scope, softened its liability and penalty regime, and dropped the mandatory climate transition plan requirement entirely.

The Omnibus package left the underlying duty itself in place. In-scope companies still need a documented, risk-based due diligence program. The amended directive replaces entity-by-entity mapping with a scoping exercise that identifies the general areas where adverse impacts are most likely or most severe, and it limits information requests to what’s actually necessary. That’s the same prioritization logic that already drives cyber vendor risk tiering.

What Does Governance Risk Have to Do With Cybersecurity?

Governance is the ESG category where cyber risk and ESG risk overlap directly, since a vendor's security oversight is itself a governance control. A vendor that skips basic security hygiene, unpatched systems, unmanaged credentials, absent incident response planning, is exhibiting the same kind of governance failure an ESG due diligence program is supposed to catch elsewhere in the business.

Letter grades and framework checklists don't always catch it early. Black Kite's Third-Party Breach Report 2026 found that among the 50 vendors most frequently shared by the Forbes Global 2000, 52% had suffered at least one verified data breach, even though this group carried a respectable average cyber rating of B. A governance rating built on documentation can miss the same gaps continuous, live monitoring catches immediately.

Where Does a Standard ESG Vendor Assessment Fall Short?

A vendor ESG questionnaire captures what a vendor says its governance program does. What its systems actually show on a given day is a separate question a questionnaire alone can't answer. A vendor security assessment questionnaire like this is a snapshot, filled out once and rarely revisited between review cycles.

That's true of any point-in-time vendor evaluation, ESG or otherwise, and it's the same limitation that shows up across compliance-driven vendor programs generally. A vendor can hold a clean due diligence file and still be running unpatched software or exposing credentials that a scanner would catch in minutes. Paper compliance and technical reality are two different things, and only one of them stops an attacker.

This gap matters more as due diligence shifts toward risk-based prioritization. A company that prioritizes vendors from paperwork returned months ago has no way to know which of those vendors developed a governance problem the week after.

How Is ESG Risk Different From Reputational or Regulatory Risk?

ESG risk, reputational risk, and regulatory risk overlap in practice but describe different exposures, and a vendor incident can trigger all three at once without them being the same thing:

  • ESG risk is about the underlying vendor conduct, environmental, social, or governance.
  • Regulatory risk is about whether a specific law, like CSDDD or a sector rule, applies to that conduct and what it requires.
  • Reputational risk is about what happens to a company's standing once the conduct becomes public, regardless of whether a regulator ever gets involved.

A vendor's data breach illustrates the overlap well. It's a governance failure, it can trigger disclosure obligations under a named law, and it can damage the hiring company's reputation the moment customers find out their data moved through that vendor, all from one incident.

How Does Black Kite Fit Into a Vendor ESG Risk Program?

Black Kite doesn’t audit a vendor’s environmental impact or labor practices, but it covers two parts of vendor ESG risk that are hard to verify from paperwork alone: governance, through the vendor’s actual security posture, and ESG-driven disruption risk, through the Business Interruption scenario in its FAIR financial impact model. Vendor risk monitoring shows whether a vendor's actual security posture backs up its governance claims, and vendor risk tiering helps a company prioritize deeper ESG due diligence toward vendors whose risk profile actually warrants it, tailored vendor by vendor. Black Kite’s Business Interruption scenario also factors in ESG risk derived from natural disaster and armed conflict data for both the company and its suppliers, estimating the likelihood that an environmental or social event disrupts operations.

That's a complement to a broader ESG program, one piece of a larger due diligence picture. A company still needs dedicated environmental and labor due diligence for the parts of ESG risk that fall outside what a security assessment can see.

See also: Why Reputational Risk Matters Regardless of Company Size