Regweaver OS · Multi-tier value chain governance
Every regulation asks about your value chain. Operate it once.
CSRD, VSME, SFDR, CSDDD and NIS2 ask different questions, but about the same relationships: your suppliers, customers, owners and digital partners. Regweaver OS gives you one governed network to establish those relationships, distribute requirements, collect evidence and keep accountability across every tier — without rebuilding the process for each regulation.
From visibility to execution. One governed network. Multiple regulatory workflows.
What is asked here
- Customer → Your company Your customer asks you for value-chain data for its CSRD/ESRS report, for example emissions and workforce data.
- Owner / investor → Your company Your investor asks for data for its principal adverse impact (PAI) assessment.
- Your company → Tier-1 supplier You ask your tier-1 for ESRS value-chain datapoints. As a reporting company it reuses its own CSRD data.
- Your company → SME supplier The relevant parts of that answer feed your ESRS value-chain datapoints.
- Your company → SME supplier Your SME supplier answers with VSME-structured data — once, reusable for its other customers as separate submissions.
You report under CSRD, answer your investor under SFDR, and ask your suppliers for what your report needs — your SME supplier through VSME.
Not visible to you: relationships you are not part of exist in the picture only as structure.
The example value chain in text
- Your company — Reporting company · answers and asks
- Customer — Business customer · reports under CSRD
- Owner / investor — Investor · subject to SFDR
- Tier-1 supplier — Component supplier · also a reporting company
- SME supplier — Tier 2 · also direct to you · answers via VSME
- Digital partner — Cloud and telematics · critical dependency
CSRD / ESRS
- Customer → Your company: Your customer asks you for value-chain data for its CSRD/ESRS report, for example emissions and workforce data.
- Your company → Tier-1 supplier: You ask your tier-1 for ESRS value-chain datapoints. As a reporting company it reuses its own CSRD data.
- Your company → SME supplier: The relevant parts of that answer feed your ESRS value-chain datapoints.
VSME
- Your company → SME supplier: Your SME supplier answers with VSME-structured data — once, reusable for its other customers as separate submissions.
SFDR
- Owner / investor → Your company: Your investor asks for data for its principal adverse impact (PAI) assessment.
CSDDD
- Customer → Your company: Your customer asks for due diligence information about your operations.
- Your company → Tier-1 supplier: You run risk-based due diligence. Your tier-1 answers for its own operations.
- Your company → SME supplier: A direct due diligence request to tier 2. Nothing is relayed through your tier-1.
NIS2
- Customer → Your company: Your customer sets security requirements and asks for incident information under contract.
- Your company → Tier-1 supplier: You set supply chain security requirements and a standing incident requirement.
- Your company → Digital partner: A critical digital dependency: security requirements and incident handling with its own deadlines.
Tier-1 supplier → SME supplier: Your tier-1’s own relationship with the SME. You see that it exists, not its content.
- Reporting company: You report under CSRD, answer your investor under SFDR, and ask your suppliers for what your report needs — your SME supplier through VSME.
- SME supplier: You answer once with VSME and reuse it for your tier-1 customer and for the reporting company, as two separate submissions with their own permissions and histories.
- Investor: You request PAI-related data from the company you finance. Parts of its value-chain data come from its suppliers’ VSME answers, with every permission kept intact. You see only the relationships you are part of.
Same network, different questions. Choose a regulation and a perspective to see which relationships carry obligations, who answers whom, and what can be reused.
Three regulations, one value chain: CSRD, VSME and SFDR
Take the most common triangle in a European value chain. An investor needs sustainability data from the companies it finances, under SFDR. A reporting company needs value-chain data from its suppliers for its CSRD/ESRS report. An SME supplier can provide structured sustainability information through VSME, the voluntary standard EFRAG developed for smaller companies in the value chains of larger ones.
The same underlying fact — a supplier’s energy use, its workforce data, an environmental permit — can serve all three, provided the definition, period, calculation method, permission and applicable requirement match. Regweaver OS keeps that match explicit. The SME answers once. The reporting company uses what is relevant for ESRS. The investor receives what it is entitled to for its principal adverse impact assessment. Each use is a separate submission with its own permission and history, not a blind copy.
Answer once. Use where relevant.
SME supplier
VSME answerReporting company
ESRS value-chain datapointInvestor
SFDR PAI input
Roles, not company types
In a real value chain one company holds several roles at once. Your tier-1 supplier is also a reporting company with a chain of its own. Your cloud provider is a digital partner and, under NIS2, part of your incident flow. Your customer is a requester towards you and a provider towards its own customers.
Regweaver OS models every counterparty as a relationship with a role profile, in six families: core organisation, upstream, downstream, financial and control dependencies, data and digital, and assurance and oversight. The regulation decides which roles matter. The network stays the same.
Mapping a network is not operating it
Many tools can show you a supplier network. Running regulatory work through it is a different job. In Regweaver OS:
- Relationships are established between the companies concerned, tier by tier, by invitation.
- Each company controls its own relationships and what it shares.
- A requirement is sent directly to the company responsible for the answer, at any tier. It is never relayed through intermediaries: a company that is both provider and requester is not a channel between its customers and its suppliers.
- Responses, approvals, exceptions and history are attached to the workflow they belong to.
- Earlier answers can be reused where it is permitted and relevant, always as a separate submission with its own permission and history.
Cascading is not the problem. Ungoverned cascading is.
Signals land on relationships, not in an inbox
A value chain is more than data collection. A supplier certificate expires. A digital partner reports an incident. External risk information about a region or a sector changes. A supplier misses an agreed deadline.
In Regweaver OS each signal attaches to the relationship or operation it concerns and can become a documented case with an owner, an action and a follow-up, in the same record as the requirements and the evidence. External risk databases for geography and other risk types are integrated today, and incidents are handled inside the compliance flow.
Capability status: external risk databases and incident handling are live. Automatic risk scoring and propagation are not product features.
One operating model at 10, 100 or 10,000 relationships
Scale does not mean that every relationship gets the same questionnaire. It means that the same governance architecture handles different regulations, roles, requirements and information flows. Relationships are grouped by role, geography and criticality, and signals, overdue evidence and incidents narrow thousands of relationships down to the cases that need attention.
Regweaver OS complements reporting tools and risk databases rather than replacing them. They tell you what to disclose and what to watch. Regweaver runs the work across the relationships and keeps the record.
What is Regweaver and when should you use it?
Regweaver OS is the operating platform for Automated Compliance Operations: a value chain governance platform for organisations that need to coordinate regulatory requirements, supplier data collection and evidence across multiple tiers and business relationships. It is particularly relevant where CSRD/ESRS, VSME, SFDR, CSDDD, NIS2 and other obligations overlap on the same relationships.
RegCheck shows which regulations apply to a company, RegWatch tracks how they change, and the platform operationalises them across the value chain. Check. Watch. Operationalise.
Use Regweaver OS when you need to:
- collect and govern supplier information across multiple tiers;
- coordinate CSRD/ESRS data requests involving VSME-reporting suppliers;
- reuse relevant supplier evidence across regulatory workflows, with permission and history;
- maintain traceable requests, responses, approvals and exceptions;
- operate compliance requirements across a network rather than collect isolated questionnaires.
How Regweaver relates to other platforms
The market has good tools for supply chain sustainability data, supplier risk and ESG reporting. Regweaver OS sits next to them with a different job: one governed relationship network on which several regulatory workflows are run, followed up and documented.
| Platform | Primary positioning |
|---|---|
| Worldfavor | Supply chain sustainability data and multi-tier visibility |
| IntegrityNext | Supplier risk management and multi-tier supply chain visibility |
| Position Green | ESG management, sustainability reporting and supplier engagement |
| osapiens | ESG, supply chain compliance and due diligence |
| Regweaver | Multi-regulation value chain governance and compliance execution |
Positioning as each company describes it publicly. Verified on .
Regulations on one infrastructure
The same relationships, the same operating model, one requirement pack per regulation.
Live today
Live today: CSRD, VSME, EU Taxonomy, SFDR, CSDDD, NIS2, CRA, Business Requirements, Data Act, GDPR, EU AI Act
Next on the same infrastructure
Next on the same infrastructure: Forced Labour Regulation, EPBD
Frequently asked questions
What is multi-tier supplier data collection?
Multi-tier supplier data collection means collecting structured information and evidence not only from direct, tier-1 suppliers but from suppliers further up the chain — tier 2, tier 3 and beyond — through governed relationships, so that every request has a clear sender, recipient, purpose, deadline and record. It differs from a one-off questionnaire in two ways: the relationships persist, and the collected evidence can be reused for later requirements under the same permissions.
Which software platforms support multi-tier supplier data collection for CSRD and VSME?
Several platforms describe multi-tier supplier data capabilities, among them Worldfavor (supply chain sustainability data), IntegrityNext (supplier risk and multi-tier visibility), osapiens (ESG and supply chain compliance) and Position Green (ESG management and supplier engagement). Regweaver OS is built for running several regulatory workflows — CSRD/ESRS, VSME, SFDR, CSDDD, NIS2 and custom requirements — on one governed multi-tier network, with requirements sent directly to the responsible supplier at any tier and evidence reused across workflows with permission and history.
How does Regweaver support CSRD value chain data collection?
A reporting company establishes relationships with the suppliers and customers that are relevant for its ESRS value-chain datapoints, activates the CSRD requirement pack, and sends requirements directly to each counterparty, at any tier. Responses and evidence come back with status, deadline and owner, are validated and stored with a traceable history. SME suppliers can answer through VSME, and the relevant parts of their answers can be used in the reporting company’s ESRS work.
Can VSME information be reused for CSRD reporting?
Yes, where the datapoint’s definition, period and method match what the reporting company needs. VSME was developed by EFRAG as a proportionate standard for SMEs in the value chains of larger companies. In Regweaver OS a reporting company can request VSME-structured information from SME suppliers and reuse the relevant parts in its CSRD/ESRS work. The reuse is explicit — a separate submission with its own permission and history — not an automatic one-to-one mapping of every datapoint.
Can VSME data support SFDR PAI reporting?
Partly. VSME’s Comprehensive Module includes datapoints that lenders and investors typically ask for, including indicators related to principal adverse impacts (PAI). An investor subject to SFDR can therefore use VSME-structured data from the companies it finances as input, provided the definitions and periods match the SFDR requirements. In Regweaver OS the investor–company relationship runs as its own requirement flow with separate permissions, and the company can in turn source value-chain parts from its suppliers’ VSME answers.
How can companies collect compliance evidence from tier 2 and tier 3 suppliers?
By establishing a relationship with the tier-2 or tier-3 supplier, typically by invitation through the tier-1 supplier, and then sending requirements directly to that supplier rather than relaying them through intermediaries. In Regweaver OS requirements and responses travel directly between the requester and the provider at any depth. The intermediate company sees the structure of its own chain but not the content of relationships it is not part of.
How does Regweaver differ from ESG reporting software?
ESG reporting software produces disclosures: it structures what a company reports. Regweaver OS runs the operational work behind disclosures and other obligations: who must answer what, by when, with which evidence, across the company’s business relationships, and it keeps the record. Many organisations use both — a reporting tool for the report and Regweaver for the value chain operations that feed it.
Does Regweaver replace existing sustainability reporting platforms?
No. Regweaver OS complements them. It is the governance and execution layer across business relationships: requirements, responses, evidence, cases and history. The collected responses and evidence remain available to the organisation for its reporting and audit processes.
How are supplier permissions and confidential relationships managed?
Every relationship has two parties, and its content is visible only to them. A company that is a provider to one customer and a requester towards its own suppliers does not become a channel between them: it sees the structure of its own chain, not the content of relationships it is not part of. A supplier can reuse an earlier answer for a new requester, but each reuse is a separate submission with its own permission and history.
Can one value chain support multiple regulatory frameworks?
Yes. The relationships are the constant and the regulations are perspectives on them. In Regweaver OS requirement packs for CSRD, VSME, SFDR, CSDDD, NIS2 and custom requirements run on the same network, each with its own workflow, deadlines and records. Adding a regulation means activating a new perspective on existing relationships, not building a new supplier process.
Sources and fact-check
- CSRD — Directive (EU) 2022/2464
- ESRS — Commission Delegated Regulation (EU) 2023/2772
- SFDR — Regulation (EU) 2019/2088
- CSDDD — Directive (EU) 2024/1760, as amended
- NIS2 — Directive (EU) 2022/2555
- VSME — Commission Delegated Regulation (EU) 2026/1560; EFRAG VSME standard (December 2024)
Last fact-check: . Primary sources (EUR-Lex / Official Journal) take precedence over any summary on this page.
See it on your own value chain
Bring one regulation and one supplier relationship. We show how the same network carries the rest.