Skip to the answer

Disclosure GuidesPillar guides, articles, FAQ and expert notes

Level 2 · Decision guide·EU Voluntary Standard 2026 · Disclosure guides

Using the EU Voluntary Standard in Tenders, Supplier Onboarding and Customer Due Diligence

How to build a controlled response pack with current evidence, versioning, certifications, above-cap voluntary data and release approvals

Who this is for A 8-minute read for reporting teams working through Approved answers for questionnaires, tenders and lender packs, and for reviewers testing whether the evidence behind it holds.

Published passport

Current as at 10 August 2026
RK Reviewed by Dr Ross KurinkoLinkedIn Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert 15+ years on FTSE 100 & Fortune Global 500 disclosures Canary Wharf, London LRA educational guidance · Not issued or endorsed by European Commission

Edition written against

EU Voluntary Standard (August 2026)

current primary sources checked on 1 August 2026

Published

10 Aug 2026

Knowledge Hub guide

Last reviewed

10 Aug 2026

Short answer

The answer, before the reasoning

The safest way to use the EU Voluntary Standard in a tender or onboarding process is to treat it as a controlled response pack, not as a document that is uploaded unchanged to every portal. Start with an approved Option A or Option B core, then add request-specific evidence, certifications and any voluntary above-cap information through a release-controlled annex.

Every response should identify the recipient, purpose, period, boundary, source version, confidentiality level and approval. The Standard can reduce duplicate questionnaires, but it does not replace product-compliance evidence, contractual declarations, customer due diligence or sector-specific documentation. Nor does the value chain cap automatically apply to every tender or onboarding question.

Rule

KNOWLEDGE CARD PACKAGE

<p>Public practitioner article followed by a publisher and technical pack with SEO fields, indicator mapping, claim ledger, source register, update triggers, review controls and an original branded explanation visual.</p>

Rule

EU-PRO-001

<p>Using the EU Voluntary Standard in Tenders, Supplier Onboarding and Customer Due Diligence How to build a controlled response pack with current evidence, versioning, certifications, above-cap voluntary data and release approvals</p>

In practice

Type

Type Tier Audience — Current context
Procurement and due-diligence implementation guide Tier 3 — Deep guide SME commercial teams, procurement respondents, compliance, finance and sustainability owners — Counterparty-focused use of the EU Voluntary Standard and purpose-specific value chain cap

Why a report alone is rarely enough for a tender

Tenders and onboarding portals combine different information purposes. A customer may request sustainability-reporting data for its own mandatory report, evidence of a policy, proof of a certification, product-level environmental information, sanctions or modern-slavery declarations, incident history and commercial commitments. The EU Voluntary Standard can organise much of the sustainability layer, but a controlled response process must classify what sits inside the report, what needs separate evidence and what should not be released without further approval.

LRA tender response workflow: classify the request, reuse the approved core, add scoped evidence, approve release and archive the exact version sent.

In practice

The four-part controlled response pack

Component Contents Typical access
1. Approved core report B1 basis, Option A or B statement, reporting period, boundary, B-disclosures, full C Module when Option B is claimed, omissions and cross-references. Public or controlled counterparty access.
2. Request-specific response schedule Line-by-line answer, request purpose, cap classification where relevant, report cross-reference, supplementary explanation and owner. Recipient-specific.
3. Evidence library Policies, certificates, permits, calculation extracts, audit/assurance statements, training or incident records, governance approvals. Restricted; release only what is necessary.
4. Release and version record Pack ID, recipient, tender/project, date, expiry, report version, evidence versions, confidentiality, onward-sharing terms and approvers. Internal control record; selected notice may accompany the response.

In practice

Classify each request before answering

Request purpose Examples How the EU Voluntary Standard helps — What remains separate
Customer mandatory sustainability reporting Supplier energy, GHG, workforce, incidents or business-relationship information needed for the customer’s ESRS report. Provides a common reporting core and, where conditions are met, the Annex II cap classification. — Necessity, protected-undertaking test, exact Annex II line and statutory notices.
Tender evaluation or supplier scorecard Policy, target, emissions, diversity, certification or improvement-plan scoring. Provides controlled definitions and evidence-backed responses. — Commercial scoring rules, contract commitments and above-cap voluntary choices.
Supplier onboarding / customer due diligence Legal entity, sanctions, human rights, complaints, safety, corruption, permits and incidents. B1, B2, B9–B11 and C6–C8 can support the sustainability layer. — KYC, sanctions, product law, human-rights due diligence and other legal requirements.
Product or service compliance Product footprint, recycled content, chemicals, deforestation, CBAM or technical specifications. Some source data may be reusable. — Product boundary, prescribed methods, declarations and legal evidence are outside the general report.
Financing or insurance Borrower climate, workforce, incident and governance information. Provides a proportionate counterparty report. — Facility, collateral, underwriting and prudential information.

Using certifications without overstating them

B1 requires a brief description of sustainability-related certifications or labels obtained by the undertaking, including the issuer and, where relevant, date and rating score. This makes certifications easy to reuse in a tender, but their scope must remain visible. An ISO 14001 certificate for one site does not certify the sustainability report, the full group, a product footprint or every environmental disclosure.

In practice

Weak certification answer Controlled answer
“The company is sustainability certified.” “Site A holds ISO 14001 certification issued by [issuer], valid to [date]. The certificate covers the environmental management system at that site; it does not provide assurance over this sustainability report.”
“Our emissions are independently verified.” “The assurance statement dated [date] covers the listed Scope 1 and Scope 2 metrics for the stated period and boundary at limited assurance. Other tender responses are outside that scope.”
Uploading an expired certificate with no explanation. Record issuer, certificate number, site/entity scope, issue date, expiry date, current status and evidence owner.

Above-cap voluntary information

Where the value chain cap applies, information outside Annex II for the protected undertaking’s employee band can be declined for the customer’s mandatory-reporting purpose. The cap does not prohibit voluntary sharing. An SME may choose to provide an above-cap target, Scope 3 estimate, product initiative or policy because it strengthens a tender or reflects common sector practice. The decision should be explicit and should not convert a voluntary answer into a permanent, unrestricted commitment.

In practice

Control question Record to retain
Why are we providing the above-cap field? Tender advantage, contract negotiation, sector practice, investor request or other stated purpose.
Is the information approved and supportable? Current calculation, evidence, limitations and data-owner confirmation.
Who may use it? Named recipient, tender/project, permitted decision and onward-sharing restriction.
How long is it valid? Reporting period, snapshot date, expiry or review trigger.
Does it create a commitment? Legal/commercial review of tender wording, representation and contract incorporation.

In practice

Versioning: the detail that prevents most disputes

Version field Example
Response pack ID TND-2026-017-v1.2
Recipient and purpose Customer X — supplier onboarding and 2027 tender
Source report EU-VS-2026-Option-A-v1.0
Reporting period / snapshot Year ended 31 December 2026; incidents updated to 15 February 2027
Evidence versions ISO14001-SiteA-2025; GHG-CALC-2026-v3; HR-ACC-2026-final
Change from prior version Updated energy total after late invoice; added limitation note; no change to Option statement
Approval Data owners, compliance, commercial lead and final release approver
Expiry / trigger New reporting year, material incident, certificate expiry or contract award

Step-by-step response workflow

1. Register the request. Capture customer, portal, deadline, purpose, contract/tender reference, intended users and required declarations.

2. Split the questionnaire into lines. Do not classify a mixed questionnaire as a single legal purpose.

3. Map each line. Link to the approved EU disclosure, evidence record, other legal source or “new information required”.

4. Test the value chain cap where relevant. Confirm ultimate requester, mandatory-reporting purpose, protected status and exact Annex II coverage.

5. Verify evidence and date. Check entity/site scope, reporting period, method, expiry, assurance scope and unresolved gaps.

6. Choose response type. Report cross-reference, concise answer, document upload, voluntary above-cap answer, clarification request or decline.

7. Apply legal, privacy and confidentiality review. Particular care is needed for incidents, personal data, trade secrets, contracts and product claims.

8. Approve the release. Data owner approves facts; reporting owner approves consistency; commercial/legal owner approves the representation; final approver authorises release.

9. Archive the exact submission. Save portal exports, attachments, screenshots, confirmations and change log — not only the working spreadsheet.

10. Monitor triggers. Correct or update the customer if a material error, incident or certificate change affects the response.

Hypothetical scenario

ILLUSTRATIVE SCENARIO

<p>A 75-employee component supplier responds to a customer tender. The portal asks for Scope 1–3 emissions, renewable-energy share, safety data, human-rights policy, product recycled content, ISO certificates and confirmation that the information is “audited”. The supplier maps B3, B9, C6 and B1 certification data to its approved report. Scope 3 is above the Annex II cap for the customer’s mandatory-reporting purpose but is supplied voluntarily because the estimate is robust and relevant to the tender. Product recycled content is answered under the product specification, not the general report. The company rejects the word “audited” and uploads a limited-assurance statement that covers only Scope 1 and 2. The final pack records each purpose, evidence version and approval.</p>

Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.

Readiness

Practical tender checklist

  • The ultimate customer and each request purpose are documented.
  • The latest approved report version is used.
  • Option A/Option B wording matches the completed modules.
  • Every cross-reference points to a precise page, section or controlled web location.
  • Certifications state issuer, entity/site scope, validity and limitation.
  • Assurance language reproduces the actual subject matter, criteria, period and level.
  • Above-cap or otherwise voluntary data is clearly labelled and purpose-limited.
  • Product, legal, KYC and due-diligence answers are not misrepresented as Voluntary Standard compliance.
  • Confidential, personal and incident information has the correct access level.
  • Data owners confirmed material metrics and narrative claims.
  • Commercial and legal teams reviewed commitments that may enter the contract.
  • The submitted portal response and attachments are archived.
  • Expiry and update triggers are assigned.

Common mistakes

Uploading the same pack everywhere. Different recipients and purposes require different access, wording and evidence.

Letting the portal define the reporting claim. A checkbox such as “ESG report audited” must be reconciled to the actual basis and assurance scope.

Using homepage links. Cross-references should lead directly to the current disclosure or document version.

Treating commercial sensitivity as automatic confidentiality. Apply the Standard’s omission conditions and separate tender-release judgement.

Turning a voluntary answer into a standing warranty. Review tender declarations and contract incorporation.

No record of what was sent. Portal entries can change; archive the exact submission and confirmation.

Marketing edits after approval. Any change to a quantitative or technical claim should return to the owner and reviewer.

Self-check

  1. Why should a tender questionnaire be classified line by line rather than as one purpose?
  2. How can a supplier provide above-cap information without implying a legal duty or permanent commitment?
  3. What information must accompany a certification or assurance statement to avoid overclaim?

Take it with you

The checklists as a working spreadsheet

Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.

Download .xlsx

✓ LRA AI Assistant · Human-in-the-loop

Ask about this guide

It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.

Try
2 free answers Automated · the LRA team is one click away

Go deeper · EU Voluntary Standard 2026

ESG Reporting Full Stack

There is no standalone LRA course for this framework yet. The Full Stack programme covers the reporting system it sits in — materiality, data, drafting and assurance — with exercises on your own data.

Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.

See the Full Stack programme
/en/knowledge-hub/disclosure-guides/eu-voluntary/eu-voluntary-approved-answer-library/using-the-eu-voluntary-standard-in-tenders-supplier-onboarding-and-cus/