What the source record establishes
Exiger presents supply-chain and third-party risk products using due-diligence data, entity intelligence, and monitoring.
The maintained taxonomy connects that documented market position to Human-Rights Environmental And Responsible-Sourcing Due Diligence. This page keeps the claim at the level supported by the source: Exiger presents an offering relevant to this work. It does not silently convert a product description into an observed result, a conformity finding, or a universal recommendation.
Current fit signal: Regulated enterprises and public-sector buyers assessing supplier ownership, sanctions, cyber, geopolitical, and operational exposure.
What human-rights environmental and responsible-sourcing due diligence means in this market
Human-Rights Environmental And Responsible-Sourcing Due Diligence should be evaluated as an operating chain rather than a feature label. The chain begins with a named business condition and governed input, passes through configured logic and accountable review, produces an output or action, handles exceptions, and preserves enough evidence for another person to reconstruct the decision later.
Multi-tier dependency and supplier exposure
The evidence system for relating companies, facilities, products, materials, ownership, tiers, geographies, and critical dependencies without overstating inferred relationships.
Boundary: A network graph can identify research candidates but does not establish every relationship, tier, exposure, or consequence.
Responsible sourcing and regulatory due diligence
The governed process for identifying supply-chain entities and impacts, prioritizing risk, engaging partners, preventing and mitigating harm, tracking action, communicating, and supporting remediation under defined standards and laws.
Boundary: A screening result, supplier statement, map, certificate, or document does not establish the absence of harm, legal compliance, or effective remediation.
Activities that may sit inside the review
- supplier and facility identity
- tier and product relationships
- criticality
- ownership and location
- evidence and change history
- entity product and commodity scope
Who owns the decision
A capability can be technically available while operating ownership remains fragmented. The evaluation should name the person accountable for policy or business interpretation, the person responsible for configuration and data, the reviewer with authority to resolve exceptions, the approver of release or action, and the owner of monitoring and retirement.
Related domain records commonly place responsibility with procurement, supplier risk, continuity, data governance, human rights, sustainability. The local operating model may assign those roles differently, but it should not leave them implicit.
Exiger should be asked to distinguish what the product decides, what it recommends, what it merely displays, and what remains an organizational judgment. A generic “human in the loop” statement is inadequate unless the human has time, context, evidence, and authority.
Evidence package to request from Exiger
- The exact product and package proposed, with a dated list of native, integrated, partner, service, and customer-owned components.
- A representative input set, its authoritative source, permitted use, quality checks, and version history.
- The configured workflow from intake through review, exception, approval, action, retention, and export.
- A normal result and at least two difficult exceptions, including one caused by missing or contradictory evidence.
- Role and access definitions for configuration, review, approval, override, monitoring, and administration.
- An implementation map naming integrations, migrations, customer work, provider work, services, test environments, and release gates.
- A retained decision record showing source, logic or model version, user action, timestamps, disposition, and downstream effect.
- A measurement plan with baseline, observation period, population, error threshold, exclusions, and stop condition.
Demonstration script
- Which exact Exiger product, edition, module, service, and geography support human-rights environmental and responsible-sourcing due diligence?
- What source data, content, rules, and integrations does Exiger require before the workflow can begin?
- Where does human judgment enter, and which person can approve, reject, override, or stop the human-rights environmental and responsible-sourcing due diligence workflow?
- How does the proposed configuration handle missing data, conflicting evidence, changed rules, and an expired or revoked approval?
- What record preserves inputs, transformations, user actions, exceptions, outputs, timestamps, and downstream consequences?
- Which parts are native, partner-delivered, service-delivered, or left to the customer?
- What can be exported at implementation, audit, renewal, migration, and exit?
- Which observation would falsify the current fit hypothesis for Exiger?
- Which relationships are supplier-provided, transactional, public, licensed, or inferred?
- What portion of spend, products, and tiers is mapped?
- How are entities and facilities resolved?
- How is criticality determined and challenged?
Use the same scenario with every finalist. Let the provider explain differences in architecture, but keep the business condition, required evidence, exception, and expected decision record constant. That makes the evaluation comparable without pretending that unlike products should receive one synthetic score.
Failure modes and boundary conditions
- assumption that all tiers are known
- automatic materiality
- legal ownership conclusions
- automatic legal compliance
- risk score as impact finding
- screening as remediation
No independent test established data coverage, entity matching, alert precision, scoring validity, business-specific legal conclusions, or outcomes.
A buyer should also distinguish absence of public evidence from evidence of absence. If Exiger has not publicly documented a required detail, the correct status is “not established in this review” until a current, attributable source or direct observation resolves it.
Authority and standards context
CISA ICT SCRM Resources
The resources help technology and supply-chain buyers structure supplier, product, acquisition, assurance, and response questions without validating a provider score.
Interpretation boundary: The resource library is guidance and does not establish the risk or conformity of a particular supplier or product.
This mapping identifies a workflow that may help organize evidence. It does not state that Exiger conforms to, complies with, or is certified against the authority.
UFLPA Strategy
Supplier and product mapping can help organize evidence and exposure review but cannot establish admissibility, rebut a presumption, or replace customs and legal processes.
Interpretation boundary: The publication does not determine entity identity, product exposure, admissibility, or the sufficiency of importer evidence.
This mapping identifies a workflow that may help organize evidence. It does not state that Exiger conforms to, complies with, or is certified against the authority.
NIST SP 800-161 Rev. 1
It requires buyers to separate product and service assurance, supplier dependencies, risk assessment, monitoring, and response from generic vendor-risk scoring.
Interpretation boundary: The publication is cybersecurity guidance; it does not determine the adequacy of any platform or the risk of a particular supplier.
This mapping identifies a workflow that may help organize evidence. It does not state that Exiger conforms to, complies with, or is certified against the authority.
Comparable records to inspect
The following organizations also have current official positioning mapped to human-rights environmental and responsible-sourcing due diligence. Inclusion is a research pathway, not a shortlist or claim of equivalence.
- Interos — Supplier And Geopolitical Risk Intelligence Platform with documented positioning relevant to Human-Rights Environmental And Responsible-Sourcing Due Diligence
- Prewave — Supplier And Geopolitical Risk Intelligence Platform with documented positioning relevant to Human-Rights Environmental And Responsible-Sourcing Due Diligence
- Altana — Supply-Chain Mapping And Due-Diligence Platform with documented positioning relevant to Human-Rights Environmental And Responsible-Sourcing Due Diligence
- Sourcemap — Supply-Chain Mapping And Due-Diligence Platform with documented positioning relevant to Human-Rights Environmental And Responsible-Sourcing Due Diligence
Official authority sources
The following primary authority pages support the standards context used in this record. They define an evaluation boundary; they do not endorse Exiger or establish product conformity.
CISA ICT SCRM Resources
Open the official authority source and confirm the current text, effective date, scope, and organization-specific applicability before relying on this mapping.
UFLPA Strategy
Open the official authority source and confirm the current text, effective date, scope, and organization-specific applicability before relying on this mapping.
NIST SP 800-161 Rev. 1
Open the official authority source and confirm the current text, effective date, scope, and organization-specific applicability before relying on this mapping.
Conditional conclusion
Exiger belongs in deeper evaluation for human-rights environmental and responsible-sourcing due diligence when its documented supplier and geopolitical risk intelligence platform operating model matches the buyer's real workflow, the proposed package contains the required components, and a representative test produces reviewable evidence through normal and exception paths. The conclusion should be reversed or narrowed when the product boundary, source data, authority mapping, integration burden, human decision rights, exportability, or measured result does not meet the stated approval conditions.