Methodology
[S/1] is an open-data intelligence platform that matches company-level data with geopolitical signals, ownership networks, public-list records, and authoritative country indicators to produce risk scoring. Data sources include World Bank WGI, Transparency International CPI, EU JRC INFORM, US DOL TVPRA, GDELT, FATF, FSI, RSF, Yale EPI, ND-GAIN, ILO NORMLEX, ILO ILOSTAT Child Labour, and 18 configured public restriction and debarment sources. It is designed as a rapid intelligence and risk-scoring layer — not a substitute for human investigation or final risk decisions. For the source-led path from a country signal to an entity decision, use Salient One's Ukraine counterparty evidence hub.
Materially reviewed 17 August 2026
How should a country-risk score be used?
A country-risk score should route diligence, not deliver the supplier verdict. It identifies the jurisdiction-level questions that need stronger evidence. Approval still requires current facts about the sector, entity, ownership, transaction and applicable controls.
- Read the country context. Use the indicator bands, source dates and missing-data notes to identify the risks that require follow-up.
- Adjust for the sector. The same country conditions do not create identical exposure for construction, logistics, mining and professional services.
- Establish entity and transaction evidence. Verify identity, ownership and control, public-list signals, operating capacity and the facts of the proposed relationship before disposition.
The lightweight S1 Counterparty Evidence Planner converts that sequence into a country-, sector- and decision-stage plan without asking for a company name or making an entity-level determination.
What is a country-risk score for?
A country-risk score is a routing signal. It identifies which jurisdiction-level risks deserve deeper evidence; it does not approve or reject a supplier or counterparty.
Can a country-risk score determine whether a supplier is acceptable?
No. A defensible decision combines country context with sector exposure, current entity and ownership evidence, transaction facts and the organisation's applicable controls.
How does S/1 handle missing country indicators?
A missing indicator does not create a low-risk value. A group without any data is excluded from the composite denominator. S1 requires data from at least two indicator groups before computing a composite rating and shows source vintages on country pages.
Method family · sourcing-risk-2.0
Country × sector × commodity evidence
The sourcing dataset separates upstream facts from Salient One derivations. Each row can identify the source directory URL, a record-level URL, source effective date, retrieval time, derivation owner, method version, assessment basis and enforcement status. Retrieval time is operational freshness; it is never treated as the date the source fact became effective.
World Bank forest-area trend. S1 reads indicator AG.LND.FRST.ZS, compares the oldest and newest available values in the retrieval window and calculates the relative annual change against the oldest forest-area percentage. Positive loss of at least 0.2%, 0.7% and 1.5% per year routes to moderate, high and severe review bands. This is an S1 calculation from World Bank forest-area data, not a Global Forest Watch tree-cover-loss measure.
EUDR evidence-review scope. Existing country × covered-commodity combinations are published as S1 screening flags with no public severity band. They help route evidence collection; they are not the European Union country benchmark. The official country classification remains a distinct legal source and must be checked at decision time.
Conflict-area mineral screening. The current country × mineral assessment is a fixed S1 review-priority snapshot based on a 2021–2024 evidence review. Its published bands are S1 screening bands, not OECD designations. The European Commission describes the official CAHRA list as indicative, non-exhaustive and periodically updated, so current primary material remains mandatory.
CBP enforcement actions. Only actions whose current source status is Active or partially modified/active contribute to current evidence. Inactive actions are excluded. A WRO routes to moderate because CBP describes its evidence as reasonable but inconclusive; a Finding routes to high because it is a determination. The source status and effective date remain visible.
Product safety and labour. Source observations are mapped to the common S1 sector taxonomy. The labour-goods adapter accepts only an official publication with a verified stated effective date, at least 80 resolved countries and at least 150 unique goods. Goods without a high-confidence sector rule remain in the source table but are not assigned to a sector. Any qualitative routing band calculated by S1 is identified through derived_by and method_version. Absence of a subject match is a coverage statement, not evidence of low risk.
How It Works
Download the machine-readable method (JSON)
Each country is evaluated across seven risk groups containing the available country indicators. Every indicator is assigned a risk level — low, moderate, high, or severe — based on fixed, transparent thresholds derived from the source's own scale or established risk-assessment practice.
Within each group, the most elevated available indicator determines the group band. The composite then averages the seven group scores, excluding groups without data from the denominator. This prevents a cluster of correlated indicators from receiving disproportionate weight.
The composite score is reproducible from the group results. Low, moderate, high and severe groups score 0, 1, 2 and 3. S1 sums the available group scores, divides by the number of groups with data, computes a base score as (average ÷ 3) × 100, then publishes min(100, round(base score × (100 ÷ 65))). The calibration preserves the engine's established 0–100 display scale; the qualitative band is determined from the uncalibrated average: low at ≤0.4, moderate at ≤0.9, high at ≤1.6 and severe above 1.6. A severe group prevents the overall result from being classified as low, but it does not automatically make the entire country severe.
A minimum of two indicator groups with data is required to compute a composite rating. Where data is missing for a specific indicator, that group is excluded from the denominator rather than treated as evidence of low risk.
Data Sources
Governance
World Bank — Worldwide Governance Indicators (WGI)
Aggregate governance score combining Voice & Accountability, Political Stability, Government Effectiveness, Regulatory Quality, Rule of Law, and Control of Corruption. Updated annually by the World Bank.
Source ↗Corruption
Transparency International — Corruption Perceptions Index (CPI)
Composite index ranking countries by perceived levels of public-sector corruption, based on expert assessments and business surveys. Scored 0 (highly corrupt) to 100 (very clean).
Source ↗INFORM Risk
European Commission JRC — INFORM Risk Index
Composite humanitarian crisis-risk index covering hazard & exposure, vulnerability, and lack of coping capacity. Developed by the Joint Research Centre for the EU and UN partners.
Source ↗Child / Forced Labour
U.S. Department of Labor — TVPRA List of Goods
Count of goods flagged by the U.S. DOL as produced with forced or child labour in each country, pursuant to the Trafficking Victims Protection Reauthorization Act.
Source ↗Public-List Signals
18 restriction and debarment sources
Total records currently available within an 18-source configured restriction and debarment coverage model: EU Consolidated List, U.S. OFAC SDN, UN Security Council, UK FCDO, Swiss SECO, DFAT Australia, Global Affairs Canada, World Bank Debarment, EBRD Ineligible, EIB Exclusion, SAM.gov Exclusions, U.S. State Department, U.S. Treasury non-SDN lists, U.S. BIS Export Controls (Entity List, Denied Persons, Unverified), UFLPA Entity List, ADB Debarment, IDB Group Debarment, and AfDB Debarment. Source availability varies and is published in the source directory. Normalised by population where data permits.
Source ↗Violent Events
GDELT Project — CAMEO-coded event data via Google BigQuery
180-day intensity of physical conflict events (assault, armed clash, terrorism, mass violence) as a share of total monitored events per country, sourced from the GDELT v2 event database.
Source ↗FATF Status
Financial Action Task Force — Black & Grey Lists
Jurisdictions under increased monitoring (grey list) or subject to a call for action (black list) by the global AML/CFT standard-setter. Updated three times per year.
Source ↗State Fragility
Fund for Peace — Fragile States Index (FSI)
Composite index measuring state vulnerability across cohesion, economic, political, and social dimensions. Scored 0 (sustainable) to 120 (high alert). Updated annually.
Source ↗Press Freedom
Reporters Without Borders — World Press Freedom Index
Annual press-freedom score based on political, legal, economic, social and safety indicators. The current published scale is 0–100, with higher scores indicating greater press freedom.
Source ↗Environmental Performance
Yale & Columbia — Environmental Performance Index (EPI)
Composite index ranking countries on environmental health and ecosystem vitality across 40+ indicators. Scored 0–100 (higher = better). Updated biennially.
Source ↗Climate Risk
Notre Dame Global Adaptation Initiative — ND-GAIN Country Index
Composite index measuring a country's vulnerability to climate disruption and readiness to adapt. Scored 0–100 (higher = better adapted). Covers 181 countries annually. Relevant to physical climate supply-chain risk under CSDDD.
Source ↗Labour Rights
International Labour Organization — NORMLEX Ratification Database
Count of the eight ILO Fundamental Conventions ratified by each country (C029 Forced Labour, C087 Freedom of Association, C098 Collective Bargaining, C100 Equal Remuneration, C105 Abolition of Forced Labour, C111 Discrimination, C138 Minimum Age, C182 Worst Forms of Child Labour). Fewer ratifications indicate weaker statutory labour protections — a direct CSDDD signal.
Source ↗Child Labour
ILO International Labour Statistics (ILOSTAT)
Proportion of children aged 5–17 engaged in child labour, from ILO national surveys. Covers ~100 countries. Directly relevant to supply-chain risk obligations on forced and child labour.
Source ↗Political Freedom
Freedom House — Freedom in the World
Annual assessment of political rights and civil liberties for 195 countries and territories. Scored 0–100 (higher = more free). Corroborates the WGI governance indicator with a rights-based lens.
Source ↗CSDDD Alignment
The EU Corporate Sustainability Due Diligence Directive (CSDDD, Directive 2024/1760) requires large companies to assess human rights and environmental risks across their own operations, subsidiaries, and value chains. S/1 is designed as a country-level intelligence and monitoring tool for procurement risk analysis — providing rapid intelligence on which jurisdictions carry elevated risk of adverse impacts.
Below is the mapping of S/1's fifteen indicator groups to specific CSDDD obligations. Each indicator serves one or more articles; the coverage level indicates whether S/1 provides full country-level signals, partial signals requiring entity-level follow-up, or no coverage (gap).
| CSDDD Obligation | S/1 Indicators | Coverage |
|---|---|---|
| Art 5 — Due Diligence Policy | Governance (WGI), Corruption (CPI), FATF | partial |
| Art 6 — Identifying Adverse Impacts | Governance (WGI), Corruption (CPI), INFORM, Child / Forced Labour (TVPRA), Conflict (GDELT), Environmental (EPI), Fragile States (FSI), Press Freedom (RSF) | full |
| Art 7 — Preventing Potential Adverse Impacts | Sanctions, Child / Forced Labour (TVPRA), Corruption (CPI), Conflict (GDELT), Environmental (EPI) | partial |
| Art 8 — Bringing Adverse Impacts to an End | Child / Forced Labour (TVPRA), Environmental (EPI), Conflict (GDELT) | partial |
| Art 9 — Monitoring | Governance (WGI), Corruption (CPI), Conflict (GDELT), Sanctions | full |
| Art 10 — Communicating on Due Diligence | Governance (WGI), Sanctions, Child / Forced Labour (TVPRA), Environmental (EPI) | full |
| Annex I — Human Rights Harms | Child / Forced Labour (TVPRA), Press Freedom (RSF), Conflict (GDELT) | partial |
| Annex I — Environmental Harms | Environmental (EPI), Fragile States (FSI), Governance (WGI) | partial |
Important limitations
- S/1 provides country-level risk intelligence and company signal matching — not a final legal determination. Articles 7 and 8 require on-site assessment, supply-chain mapping, contractual measures, and stakeholder engagement beyond S/1's scope.
- The CSDDD requires companies to consult affected stakeholders, workers, and trade unions (Art 13). S/1 does not facilitate stakeholder engagement.
- Climate transition plans (Art 15) and director oversight duties (Art 11) are outside S/1's scope.
- S/1's public-list signal matching checks names against restriction and debarment lists. A negative result does not constitute a determination that a business partner is free of all legal or operational risk.
Public-List Signal Matching
The signal engine compares a user-supplied name against tens of thousands of public-list records across 18 configured restriction and debarment sources: OFAC SDN, EU Consolidated, UK FCDO, UN Security Council, Swiss SECO, DFAT Australia, Global Affairs Canada, World Bank Debarment, EBRD Ineligible, EIB Exclusion, SAM.gov Exclusions, US State Department, Treasury non-SDN, US BIS Export Controls (Entity List + Denied Persons + Unverified), UFLPA Entity List, ADB Debarment, IDB Group Debarment, and AfDB Debarment. It also matches against listed aliases and known spelling variants to catch alternative renderings of sanctioned names.
Matching uses a weighted ensemble of four complementary techniques, each contributing to a combined confidence score (0–1):
- Jaccard token overlap — measures how many words (tokens) the query and the target name share, normalised by the total number of unique tokens. Robust to word reordering and partial name matches.
- Dice coefficient on character bigrams — compares overlapping two-character sequences between the query and target. Effective at catching typographical errors and minor spelling variations.
- Levenshtein edit distance — counts the minimum number of single-character insertions, deletions, or substitutions needed to transform one string into the other. Normalised by string length to produce a 0–1 score.
- Double Metaphone phonetic hashing — encodes names into pronunciation-based keys, so names that sound similar (e.g. Muhammad / Mohamed) hash to the same or nearby values regardless of spelling differences.
The four scores are combined into a weighted ensemble, with higher weight given to token-level matching for multi-word names and phonetic matching for single-word names. A configurable minimum confidence threshold (default 35%) filters results before they are returned.
Transliteration support covers Cyrillic (Russian, Ukrainian, Serbian), Arabic, and Chinese (Simplified) scripts. Names in these scripts are automatically Romanised before comparison, enabling cross-script matching without requiring the user to know the original script.
When optional fields are provided — date of birth, passport or ID number, IMO number, address, or place of birth — the engine applies exact and near-exact matching on those fields as a secondary signal. A field-level match boosts the overall confidence score but is not required for a result to be returned.
Limitations
- Indicators update on different cycles — some annually, some daily. The scorecard reflects the most recent data available at generation time.
- All source data is subject to the methodological limitations of its publisher. Governance and corruption indices rely on perception surveys; sanctions counts capture volume but not enforcement intensity; event data depends on media coverage density.
- The composite band is an intelligence signal, not a policy determination. It does not account for sector-specific risks, sub-national variation, or entity-level controls.
- Countries with populations below approximately 300,000 may have limited data coverage across several indicators.
- The public-list signal tool uses fuzzy matching — it is designed to surface candidates for human review, not to make automated match/no-match determinations. False positives and false negatives are possible, particularly with common names or incomplete registry data.
Updates & Freshness
Data is ingested daily via automated pipelines. Each scorecard shows the precise ingestion date for every source. The composite score is recomputed whenever any underlying indicator updates.
For questions about methodology, updates, or access to the raw data, contact [email protected].