CSDDDAdverse impactsEU

CSDDD adverse impact prioritisation workflow

Identify actual and potential adverse human rights and environmental impacts, then rank them by severity and likelihood when not all impacts can be addressed at once.

Use the workflow to connect chain-of-activities evidence, stakeholder input, prevention or corrective measures, remediation, and monitoring records.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the CSDDD as amended by Directive (EU) 2026/470, prioritisation follows a based solely on reasonably available information and an in-depth assessment in areas where impacts are most likely and most severe. When several areas are equally likely or equally severe, the company may assess areas involving direct business partners first. The legal boundary still includes relevant indirect partners. The ranked register should explain the impact, affected right or environmental obligation, severity and likelihood, selected Article 10 or 11 response, relevant stakeholder input, and monitoring evidence.

Section 1

1. Build the adverse-impact register before ranking

Start with the CSDDD definitions. Record whether each item is an adverse human rights impact, an adverse environmental impact, or both. For human rights, identify the abused right or reasonably foreseeable risk to a protected legal interest. For environmental impacts, link the issue to the prohibitions or obligations covered by the Directive's Annex.

Map the chain of activities in enough detail to locate where the impact is most likely and most severe. The register should separate own operations, subsidiaries, direct business partners, and indirect business partners, and should distinguish upstream activities such as design, extraction, sourcing, manufacture, transport, storage, and supply from covered downstream distribution, transport, and storage.

For the in-depth assessment, request business-partner information only when it is necessary. If the business partner has fewer than 5,000 employees, request it only when the information cannot reasonably be obtained by other means. Where several partners could provide the information, ask the partner where the impact is most likely to occur when that is reasonable.

  • Impact statement: describe the harm to people, communities, workers, consumers, or the environment in plain language.
  • CSDDD category: adverse human rights impact, adverse environmental impact, or combined impact.
  • Location in the chain of activities: own operation, subsidiary, direct business partner, indirect business partner, upstream activity, or covered downstream activity.
  • Evidence inputs: independent reports, complaint or notification data, supplier information, audit or verification findings, stakeholder consultation notes, and public risk indicators.
  • Assessment status: general mapping only, in-depth assessment opened, in-depth assessment completed, or response measure active.
Section 2

2. Score severity and likelihood

Article 9 requires prioritisation by severity and likelihood where it is not feasible to address all identified impacts at the same time and to their full extent. Do not rank by commercial exposure alone. The register should show why a lower-revenue site, supplier, product line, or geography was escalated if the harm to people or the environment is more severe.

For severity, use the Directive's definition: nature, scale, scope, irremediable character, gravity, number of affected individuals, extent of environmental damage, irreversibility, and limits on restoration within a reasonable period. For likelihood, use evidence of occurrence, credible complaints, sector and geography risk, business-partner history, and whether the activity is moving into a higher-risk product, process, or location.

The 1-to-5 labels below are Sorena's internal calibration example, not a scale or formula prescribed by the CSDDD. Define each level for the affected right or environmental harm, keep the written rationale, and do not let a numerical average conceal an impact with extreme severity. For example, a credible risk of fatal exposure affecting a small workforce can outrank a more frequent but readily reversible administrative harm; the case facts still control the score.

  • Severity 5: harm to life, health, liberty, irreversible environmental damage, widespread affected population, or no realistic restoration within a reasonable period.
  • Severity 4: serious but partly remediable harm, significant worker or community impact, substantial environmental degradation, or high vulnerability of affected groups.
  • Severity 3: material impact requiring a prevention or corrective plan but with plausible containment, restoration, or compensation options.
  • Likelihood 5: actual impact confirmed, well-founded complaint, repeated supplier evidence, or credible independent reports for the same operation or business partner.
  • Likelihood 4: strong sector, geography, product, or business-model indicators, especially where company purchasing, design, or distribution practices increase risk.
  • Escalation rule: use severity and likelihood to set the order, then record when and how less significant impacts will be addressed. Where prioritisation complies with Article 9, the mere fact that a less significant impact has not yet been addressed does not expose the company to Article 27 penalties.
Section 3

3. Choose the response based on potential versus actual impact

After ranking, route each priority item to the right response. Potential adverse impacts go through Article 10 prevention or mitigation measures. Actual adverse impacts go through Article 11 measures to bring the impact to an end or minimise its extent, plus Article 12 remediation where the company caused or jointly caused the impact.

The response record should explain the company's involvement and ability to influence the partner: whether the impact may be caused by the company alone, jointly with a subsidiary or business partner, or only by a business partner in the chain of activities; whether the impact sits in a subsidiary, direct partner, or indirect partner; and what influence the company can reasonably exercise.

  • Potential impact response: prevention action plan with clear timelines and qualitative or quantitative improvement indicators where needed.
  • Actual impact response: corrective action plan where the impact cannot immediately be brought to an end, with indicators for improvement.
  • Operational measures: investments, process upgrades, changes to purchasing, design, distribution, business plans, strategies, or operations.
  • Business-partner measures: engagement, contractual assurances, proportionate SME support, capacity-building, training, management-system upgrades, and verification where appropriate.
  • Last-resort measures: refrain from a new or extended relationship, adopt an enhanced action plan without undue delay where success can reasonably be expected, and suspend affected activities when the governing law permits unless suspension can reasonably be expected to cause manifestly more severe adverse impacts.
  • Suspension branch: give reasonable notice, address the impacts of suspension, and keep the decision under review. If the company does not suspend, record the reasons, monitor the impact, and periodically reassess the decision and available measures.
  • Remediation record: restoration, compensation, or other remedy proportionate to the company's implication when it caused or jointly caused an actual adverse impact.
Section 4

4. Add stakeholder engagement and complaint evidence

Include relevant stakeholders in prioritisation. Amended Article 13 requires consultation when gathering information to identify, assess, and prioritise adverse impacts; when developing prevention, corrective, and enhanced action plans; and when adopting remediation measures. The 2026 amendment deleted suspension decisions and monitoring-indicator development from the mandatory-stage list.

Use the complaint and notification mechanism as an evidence input, not a separate archive. If a complaint is well-founded, the adverse impact is treated as identified under Article 8 and should move into the register for Article 10, 11, or 12 action.

  • Stakeholder map: directly affected persons or communities, workers, trade unions or workers' representatives, and legitimate representatives. Include consumers only where directly affected and organisations only where they legitimately represent directly affected individuals or communities; keep Article 14 complainant eligibility separate.
  • Engagement safeguards: provide relevant information in a comprehensible format, document any justified refusal to provide additional information, address barriers to participation, and protect against retaliation or retribution.
  • Complaint evidence: complaint date, affected right or environmental concern, whether the complaint is founded, follow-up requested, meeting notes, reasons provided, and actions taken or planned.
  • Expert fallback: where effective stakeholder engagement is not reasonably possible, record the experts consulted and why their insights were credible for the actual or potential impact.
  • Monitoring trigger: update the impact score when stakeholder input, complaints, notifications, public information, business changes, or verification results show a new or changed risk.
Recommended next step

Turn CSDDD prioritisation into an evidence register

This workflow helps structure adverse-impact scoring, stakeholder evidence, Article 10 or Article 11 response measures, remediation records, and monitoring updates.

Section 5

5. Keep evidence that explains the priority order

The evidence file should let a reviewer understand why one impact was handled before another. Keep the raw evidence, the scoring rationale, the stakeholder input considered, the selected measure, the owner, the timeline, the monitoring indicator, and the reason any lower-ranked impact was deferred.

CSDDD monitoring is recurring. Current Article 15 requires assessment without undue delay after a significant change, at least every five years, and whenever there are reasonable grounds to believe measures are no longer adequate or effective or new impact risks have arisen or may arise. Five years is a maximum regular interval, not a waiting period for a serious complaint, failed control, new country, new product, acquisition, or major supplier change. Update the due diligence policy, identified impacts, and measures when the assessment warrants it, taking relevant stakeholder information into account.

  • Priority decision record: ranked impact ID, severity score, likelihood score, rationale, source evidence, and affected stakeholder group.
  • Action record: Article 10 prevention or mitigation, Article 11 corrective action, Article 12 remediation, or monitoring-only rationale for a lower-ranked item.
  • Business-partner record: engagement log, contractual assurance, verification result, SME support offered, and assessment of the company's ability to influence the partner.
  • Stakeholder record: consultation invitations, information shared, additional information requests, barriers addressed, confidentiality or anti-retaliation safeguards, and feedback used.
  • Review record: monitoring indicator, most recent assessment result, significant-change trigger, next review owner, and whether a lower-priority impact has moved up the queue.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.
commission.europa.eu
Referenced sections
  • The Commission describes the CSDDD objective as identifying and addressing adverse human rights and environmental impacts inside and outside Europe.
"identify and address adverse human rights and environmental impacts"
Related guides

Explore more topics

CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.