> For the complete documentation index, see [llms.txt](https://docs.live-eo.com/tradeaware/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/assess-risk-in-your-supply-chain.md).

# Assess risk in your supply chain

### What is risk assessment in TradeAware?

Risk assessment in TradeAware happens in two steps.

First, TradeAware scores your suppliers for you. The Automated Supplier Risk Score reads the data already in your account — the deforestation analysis on your suppliers' plots, and the due diligence questionnaires they have submitted (excluding the CMS questionnaires) — and turns it into a single number from 0 to 100 for each supplier. Its job is to tell you which suppliers to look at first

Then, you review risks the score has identified and record what you decide, by setting the supplier's status, adding a note, and attaching any supporting documents. That record is what your audit trail is built from, not the score.\
The score is simply to support your decisionsIt never sets a supplier's status for you, and it does not make the compliance decision.<br>

**Note:** risk statuses and their notes are visible only to your business (TradeAware account), for both suppliers and plots. So are flagged questionnaire answers — your suppliers cannot see which of their answers TradeAware flagged, or what you recorded about them. If you want to follow up on a flagged answer, raise the underlying question with them rather than referring to the flag.

### What the Automated Supplier Risk Score is not

Three boundaries worth stating up front, because they are the ones that matter in an audit.

**It is not a compliance verdict.** The score is a prioritisation signal built from the data in your account. The due diligence decision on each supplier and each shipment remains yours.

**It does not classify countries.** Country risk classification under the EUDR is a European Commission determination under Article 29. Nothing in TradeAware, and nothing a supplier answers, changes a country's benchmarked risk level.

**It does not replace Article 9.** Per-shipment information — product description, quantity, plot geolocations, production dates, and evidence of legal and deforestation-free production — is required whatever the risk level. TradeAware collects it through the plot and transaction workflows, not through the score.

### ⚠️ Prerequisites

The Automated Supplier Risk Score is part of TradeAware's paid plans. Free accounts can see where it sits and what it covers — see [What you see on a free account](https://docs.google.com/document/d/1c2ESdnNx--JJY6eWUlVt-zBTMRve8Wi5_lyK5wmRmkM/edit#heading=h.orfg18wsj5hl) below.

The score also needs something to work from. A supplier is scored once TradeAware has analysed plots for them, or they have submitted an EUDR Due Diligence Questionnaire, or both. Suppliers with neither show no score at all.

If you have not yet invited your suppliers or sent them the questionnaire, start with [Connect with your supply chain](https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/connect-with-your-supply-chain) and [Provide and Review Documents](https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/provide-and-review-documents). Every supplier you onboard now is a supplier who gets scored automatically.

#### What you see on a free account

The questionnaire and the evidence are free. Our read on that evidence is the paid part.

On a free account you can send the EUDR Due Diligence Questionnaire to as many suppliers as you like, open any submitted response and read every question and every answer, download it, see how many plots each supplier has and how they came out of open-source screening, and set each supplier's status yourself.

What is locked, shown blurred behind a lock icon: the risk score value, the risk badge, the Risk score column in the Suppliers table, the flagged marker on individual questionnaire answers, the flagged count, and the needs-attention badges and banner.

Nothing is broken when you see a lock, that is the paid layer. Use Upgrade on any supplier panel, or Speak to a Specialist from the panel beneath the plot breakdown.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2FbaphmxjFNkIMFTKdpfvF%2FScreenshot%202026-09-02%20at%2016.08.17.png?alt=media&amp;token=37bd0419-c1e3-4d2c-a986-f956deabeaab" alt=""><figcaption></figcaption></figure>

### Working the list

The score exists to give you an order to work in. In practice:

1. Open the Suppliers table and sort by the **Risk score** column.
2. Open the supplier at the top.
3. Use the **Plots** tab, or **Documents** → **Questionnaires**, to see what is driving the score.
4. Decide, then set the supplier's status and add a note.

That is the loop. Everything below is what you consult while working on it.<br>

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2F7ZQNvAfWHYKghtUix2i0%2FScreenshot%202026-09-02%20at%2016.10.08.png?alt=media&amp;token=ea9c4158-cc44-4510-89b3-186e0c372cbd" alt=""><figcaption></figcaption></figure>

### Two ways a supplier gets assessed

TradeAware supports two assessment routes. Which you have depends on your package — some accounts have one, some have both.

**Automated scoring on the EUDR Due Diligence Questionnaire**. You send the questionnaire, the supplier submits it, and TradeAware scores the response and combines it with the deforestation analysis of their plots into a single supplier score. It covers your whole supplier base at once, updates as data arrives, and every input behind it is inspectable. This is what the rest of this page describes.

**CMS legal review, available as an add-on.** CMS is a specialist legal review carried out by people rather than by the platform. It runs on its own questionnaires, which the supplier completes separately from the EUDR Due Diligence Questionnaire. What comes back is a legal assessment you record against the supplier and file with them.

If your account has both, the EUDR Due Diligence Questionnaire drives the automated score across every supplier, and CMS is the route for the individual cases that need a legal opinion. They are not alternatives. One is triage across the whole base; the other is depth on a single supplier.

**CMS responses do not feed the automated score.** They are a separate instrument with their own questions, asked for a different purpose. If your account is CMS-only you will see CMS outcomes and statuses on your suppliers, but no automated score.

### The Automated Supplier Risk Score

Each supplier in your Suppliers table carries a score from 0 to 100, where 0 is the lowest risk and 100 the highest. The Risk score column is sortable, which is the fastest way to put your supplier base in priority order.

TradeAware recalculates the score when the data underneath it changes: an analysis completing, a supplier submitting a questionnaire, a plot being deleted, or a new supplier connection being made. Marking a plot as EUDR compliant also moves the score, because compliant plots are taken out of the detection count.

You cannot edit a score directly. The only way to move one is to change the data it is built from.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2Fnqk54KvoM3tqfZXRedXm%2FScreenshot%202026-09-02%20at%2016.12.45.png?alt=media&amp;token=8a02771a-08c4-44c4-bdaf-a47b79a2e8e4" alt=""><figcaption></figcaption></figure>

#### What goes into the score

The score has two halves, weighted equally: deforestation risk and legal risk.

**Deforestation risk** is the share of the supplier's plots that carry a positive detection. Where a plot has a Precision analysis, that result is used; where it does not, the open-source screening result is used instead. A plot you have reviewed and marked as EUDR compliant no longer counts as a positive detection, so clearing a detection you have investigated lowers the supplier's score. See [Open Source Deforestation Methodology](https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/open-source-deforestation-methodology) for how detections are produced.

**Legal risk** comes from the supplier's submitted EUDR Due Diligence Questionnaire responses. Each submitted response is scored from 0 to 100, where 0 means none of its scoreable questions were answered in a way that indicates risk and 100 means all of them were. Not every question is scoreable — free-text answers and document uploads cannot indicate risk on their own. The supplier's legal risk is the average of their submitted response scores, so a supplier sourcing from five countries with five submitted questionnaires is assessed on all five.

Only completed questionnaires count. Drafts and archived responses are ignored. A response's score is fixed at the moment it is submitted and does not drift afterwards — it changes only if that response is archived and a new one is submitted in its place.

Responses submitted before the questionnaire was renamed may still appear under its earlier title, EUDR Compliance Questionnaire – Non-EU Suppliers. They are scored the same way.

CMS questionnaire responses are not part of the automated score. See [Two ways a supplier gets assessed](https://app.gitbook.com/o/LVp69MjrJJ3k89rpETv6/s/benSEfMyYbRWLaKU6iTs/~/edit/~/changes/268/using-the-tradeaware-web-app/assess-risk-in-your-supply-chain#two-ways-a-supplier-gets-assessed).

#### What is not in the score yet

This release applies no country weighting. A plot in a country the European Commission has benchmarked as low risk counts exactly the same as a plot in a high-risk country, so read the score as geography-blind for now.

Automated recommended actions and export of the risk report are also not part of this release.

### Reading the risk badge

Alongside the number, TradeAware shows a badge.

* **Low** — the score is 0. Nothing in the deforestation analysis or the questionnaire responses indicates risk. No follow-up is prompted by the automated screening, though you can still set the supplier's status yourself.
* **Medium** — the score is above 0. Something in the underlying data needs your attention. Open the supplier to see whether it is coming from deforestation detections, from flagged questionnaire answers, or from both.

Selecting the info icon next to the score opens an explanation of how it was calculated, without leaving the supplier view.

#### A common misreading

Two suppliers can both be Medium for completely different reasons. One might have strong deforestation signals across many plots; another might have a clean plot record but real gaps in its legal evidence. A Medium at 12 and a Medium at 68 are not the same situation either. The badge tells you to look; the number and the breakdown tell you at what, and how urgently.

### When the evidence does not cover everywhere a supplier operates

TradeAware tells you when a supplier's evidence has gaps, and it does this through banners rather than by changing the score.

Two banners carry it, and they are independent of each other — either or both can appear:

* On the Plots tab: missing uploads for one or more named countries. The supplier has completed a questionnaire for a country where they have registered no plots, so the geographic evidence for that country is absent.
* On the Questionnaires tab: missing submissions for one or more named countries, plus a Needs attention badge on the affected card. The supplier has plots in a country they have not completed a questionnaire for, so the legal declaration for that country is absent.

Countries are named, not counted, so you can see exactly what to chase.

**The score itself is never held back or reduced because of a gap.** It is always calculated from everything available at that moment — every analysed plot across every country, and every submitted questionnaire — and recalculated as more arrives. Nor is the calculation scoped by country: a questionnaire for one country and plots in another both feed the same single supplier score.

So the banner and the number answer different questions. The number is a real reading of the evidence you currently hold. The banner tells you how much of the supplier that evidence covers. A supplier scoring low with three countries covered when you source from five has told you something about three countries and nothing about the other two.<br>

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2FhJegnpOWCe2qpVW12IJt%2FScreenshot%202026-09-02%20at%2016.16.52.png?alt=media&amp;token=5c151001-2124-4232-9b21-378d0ee517d9" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2FTcE4Ev6qU8qYY1lIrgaq%2FScreenshot%202026-09-02%20at%2016.17.09.png?alt=media&amp;token=5293d809-3791-4c84-a6ca-2ef6a1f31963" alt=""><figcaption></figcaption></figure>

#### When there is nothing to score

A supplier with no analysed plots and no submitted questionnaire has nothing to score. TradeAware shows an empty state on the Plots and Questionnaires tabs explaining what is missing, rather than showing a score.

Worth being clear about internally: an absent score is not a low score.

### Staying up to date when scores change

You do not have to keep checking the table. When scores move, TradeAware notifies you once for the whole set rather than once per supplier: how many of your suppliers changed, how many improved, how many declined, and the before-and-after for each. The notification links straight into your supplier list filtered to the ones that moved.<br>

These appear in the Notifications Center in web application.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2FXLJjp2JQW94IqeIpdFmf%2FScreenshot%202026-09-02%20at%2016.19.59.png?alt=media&amp;token=98565efb-ed8c-41a0-a377-044cb79b53c0" alt=""><figcaption></figcaption></figure>

### Reviewing the evidence behind a score

Select a supplier in the Suppliers table to open the Supplier Details Panel. Everything driving the score is one or two clicks away from there.

**Plots tab** — the supplier's plots with the breakdown behind their deforestation risk: the total, the open-source screening results, and the Precision analysis results.

**Documents tab** — opens on Questionnaires, with Files alongside it. The Questionnaires tab lists the questionnaires linked to the supplier with their country and date, plus a summary of the flagged responses driving the legal side of the score. Selecting the preview icon on a questionnaire card opens the full response, with flagged answers highlighted and any evidence the supplier attached shown alongside them. Flagged answers are visible only to you — the supplier cannot see them.

**Files** is where documents live that did not come in through a questionnaire. You can upload anything you have received externally — certificates, CMS reports, supplier declarations — and attach it to the supplier record. Each file is saved with the uploader's name, upload date and file size, can be previewed in the browser or downloaded, and is linked to the supplier's audit trail.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2F9D4hnnuApFm1CSapOJVv%2FScreenshot%202026-09-02%20at%2016.28.27.png?alt=media&amp;token=14cb7e8a-9c00-4c33-8e45-ad2249e8b051" alt=""><figcaption></figcaption></figure>

### Setting a supplier status

The score tells you where to look. The status records what you concluded. Only your business can see it.

Open the Supplier Details Panel and use the status dropdown.

The statuses are:

* New — the default status when you connect with a supplier for the first time.
* Under review — you have started looking at the data the supplier provided.
* Ready for assessment — the supplier has provided their data and is ready to assess.
* CMS assessment requested — a request to CMS to assess the provided data. Available where your package includes CMS support.
* CMS assessment completed — CMS have completed their assessment. Available where your package includes CMS support.
* In risk mitigation — a risk assessment has been completed and mitigation actions are ongoing.
* EUDR compliant — the supplier has been assessed as compliant with EUDR.
* EUDR non-compliant — the supplier has been assessed as non-compliant with EUDR.

When you select a status you can add a note explaining the reason, and upload a relevant document — a legal opinion, a CMS report, a supplier certificate.

The status you set is also visible when you create a transaction with that supplier. See [Manage your transactions](https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/manage-your-transactions).

The dropdown also includes an action to clear the status. A supplier with no status set shows Review evidence and set status in place of a status. Use it if you set one in error.

Setting a supplier status does not change the score. The two are independent by design: the score reflects the data, the status reflects your judgement. The one exception runs the other way — marking a plot as EUDR compliant removes it from the detection count, and that does move the supplier's score.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2F1dUVGk6kZP9qGH1WIueJ%2FScreenshot%202026-09-02%20at%2016.29.53.png?alt=media&amp;token=cdf7cfe0-42e0-45cc-abb3-ea6eeaf54af1" alt=""><figcaption></figcaption></figure>

#### When to escalate a supplier to CMS

The two routes answer different questions. The score tells you which suppliers to look at, across your whole base. CMS tells you what the law says about one of them.

The most useful thing to know when deciding is what the score cannot see. Only questions with a defined answer that indicates risk are scored — free-text answers and uploaded documents are not. So a supplier can answer a yes/no question in the clear and describe something inadequate in the free-text follow-up underneath it, and the score will not move. The questionnaire is also a self-declaration: it records what the supplier says about themselves, and TradeAware does not verify it.

**Escalate when one of these is true:**

* The free text or the attached documents need reading. This is the most common case, because it is exactly the material the score is blind to. If a supplier's written explanations or uploaded evidence look thin, contradictory, or simply hard to judge, that is a legal reading, not a scoring problem.
* You need the self-declaration verified rather than recorded. The questionnaire captures what the supplier asserts. Where the assertion carries real weight, CMS is how you get it examined.
* The commercial exposure justifies an opinion on file. Sole-source, high-volume or long-contract suppliers, where an internal judgement is not what you want sitting in the audit record.
* You are about to act on a finding — marking a supplier EUDR non-compliant, or taking a commercial decision off the back of one, and you want defensible grounds first.
* A substantiated concern has been raised under Article 31, or you have received information that takes you out of simplified due diligence and back into full Articles 10 and 11.

**Do not escalate when:**

* The only signal is a Medium badge. Open the breakdown first. If it is a handful of detections on plots you can review yourself, or a gap you can close by asking for a document, that is faster and cheaper than a legal review.
* A banner tells you evidence is missing. That is a collection gap, not a legal question. Chase the missing questionnaire or geolocation instead.
* You want a second opinion on the number. CMS asks a different set of questions for a different purpose. It will not tell you whether the automated score was right.

#### How an escalation runs

1. Set the supplier's status to CMS assessment requested. This status is available where your package includes CMS support.
2. The supplier completes the CMS questionnaire. This is separate from the EUDR Due Diligence Questionnaire — they are not interchangeable, and a CMS assessment is never run on a response to the default questionnaire.
3. When the review comes back, set CMS assessment completed and attach the report in the Documents tab.
4. Record your own conclusion using the supplier status — EUDR compliant, EUDR non-compliant, or in risk mitigation.

The automated score does not change at any point in this. CMS responses are not part of the calculation, so a completed CMS review leaves the number where it was. What changes is your status and your evidence file, which is what the audit trail is built from.

Contact your Customer Success Manager for CMS availability on your package.

### Risk assessment for plots

Plot-level risk assessment is separate from the supplier score and works the way it always has: review the analysis, then record your decision.

From the Plots tab you can see the statuses assigned by you and your team members to your own plots and those of your suppliers:

* New — the default status when a plot is first added.
* Under review — you have started looking at the data associated with the plot.
* In risk mitigation — a risk assessment has been completed and mitigation actions are ongoing for the plot.
* EUDR compliant — the plot has been assessed as compliant with EUDR.
* EUDR non-compliant — the plot has been assessed as non-compliant with EUDR.

You can also reach these for an individual supplier: select the supplier in the Suppliers table, then select the plot in the Supplier Details Panel.

Marking a plot as EUDR compliant is the one plot-level action that feeds back into the supplier's score — that plot stops counting as a positive detection in the supplier's deforestation risk.

#### Changing status and adding notes

Select a plot in the Plot Table or the Supplier Details Panel, open the Status dropdown, and choose a status. You can add a note to the change. Selecting Change status applies it.

<figure><img src="https://1342046618-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FbenSEfMyYbRWLaKU6iTs%2Fuploads%2FPHeGMA2X4gBcRA8aSrOX%2FScreenshot%202026-09-02%20at%2016.31.31.png?alt=media&amp;token=09aa50d4-ae56-4d92-aef1-45fb771a2bed" alt=""><figcaption></figcaption></figure>

### Frequently asked questions

**Why does my supplier have no score?**

They have no analysed plots and no submitted questionnaire, so there is nothing to calculate from. TradeAware shows an empty state rather than a score. An absent score is not a low score.<br>

**Why did a supplier's score change when nobody touched it?**

Scores recalculate when the data underneath them changes: an analysis completing, a supplier submitting a questionnaire, a plot being deleted, or a new supplier connection being made. You will also get a notification when scores move, so you do not have to watch the table.

\
**Can I change a score, or override it?**

Not directly. Scores only move when the data behind them moves. What you can do is change the outcome: mark a plot as EUDR compliant to take it out of the detection count, or set the supplier's status to record your own conclusion.

**Two of my suppliers are both Medium. Which is worse?**

The number tells you. The badge is a coarse triage filter; use the score and the breakdown to rank within it.

**A banner says evidence is missing. Is the score still valid?**

Yes. The score is always calculated from everything available at that moment — the banner does not hold it back or reduce it. The number is a real reading of the evidence you hold; the banner tells you how much of the supplier that evidence covers.

**Does a CMS assessment change the score?**

No. CMS questionnaire responses are excluded from the automated calculation. Record the CMS outcome using the supplier status, and attach the CMS report in the Documents tab.

**My account has both. Which questionnaire should my supplier fill out?**

The EUDR Due Diligence Questionnaire, to everyone. It is what produces the automated score, so every supplier who completes it becomes one you can triage. The CMS questionnaire goes only to the suppliers you have decided to escalate.

**Why does my account show no scores at all?**

If your package is CMS-only, there is no automated score — you will see CMS outcomes and the statuses you set, but not a number. If your account is on a free plan, the score is present but locked; If you expected scoring and see neither, contact your Customer Success Manager.

**My supplier has submitted a questionnaire but has no plots. Are they low risk?**

They are low risk on the evidence available, which is what the missing-uploads banner is telling you. Nothing has been established about their plots. Ask them to upload their geolocations.

**Can my suppliers see their score, or which answers were flagged?**

No. Scores, flagged answers, statuses and notes are visible only to your business.

For more, see [Frequently Asked Questions](http://frequently-asked-questions).

\ <br>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.live-eo.com/tradeaware/using-the-tradeaware-web-app/assess-risk-in-your-supply-chain.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
