CSDDD chain of activities and supplier due diligence
This page helps separate the CSDDD legal boundary from the practical supplier map used for human-rights and environmental due diligence.
It focuses on upstream and downstream coverage, subsidiaries, business partners, risk-based prioritisation, supplier engagement, and evidence that should survive review.
Under the Corporate Sustainability Due Diligence Directive (CSDDD), the defines the business-partner boundary for due diligence. It covers partner activities related to the company's production or services and a narrower set of downstream product activities; the duties also cover the company's own operations and subsidiaries.
1
Section 1
What does chain of activities mean under the CSDDD?
Article 3 defines the in two parts. Upstream coverage includes business-partner activities related to producing goods or providing services for the company, including design, extraction, sourcing, manufacture, transport, storage, supply of raw materials, products or product parts, and product or service development.
Downstream coverage is narrower. It covers business partners that distribute, transport, or store the company's product for the company or on its behalf. It does not turn every customer use, product disposal route, or downstream service relationship into CSDDD chain-of-activities scope.
Treat raw materials, components, contract manufacturing, logistics into production, and service-development inputs as upstream mapping candidates.
Example: a mine supplying metal through several processors can be an indirect upstream business partner because extraction and raw-material supply relate to the company's product, even without a contract with the company.
Treat distribution, transport, and storage of the company's product as downstream candidates only when the partner performs those activities for or on behalf of the company.
Example: a warehouse holding the company's finished product under its logistics arrangement can be covered downstream; an independent customer's later storage for its own use is not covered on that fact alone.
Exclude product disposal from the CSDDD chain-of-activities definition rather than forcing waste-stage actors into this page's supplier map.
For regulated financial undertakings, keep the chain-of-activities boundary to upstream activities; downstream recipients of financial services and products are not included in that definition.
Keep export-controlled product scenarios separate because the Directive excludes certain distribution, transport, and storage activities after export authorisation.
Use Sorena to connect CSDDD chain-of-activities boundaries, supplier segmentation, impact evidence, and review records before teams update policies or questionnaires.
How should subsidiaries and business partners be classified?
The CSDDD separates subsidiaries from business partners. A subsidiary is part of the corporate group definition, while a business partner is an entity connected to the company's operations, products, or services. Direct business partners have a commercial agreement with the company or receive services from it; indirect business partners are not direct partners but still perform related business operations.
This classification matters because group-level due diligence support is possible, but subsidiaries remain subject to supervisory powers and civil liability. Supplier maps should therefore record whether a risk sits in the company's own operation, a subsidiary, a , or an .
Create one record per legal entity or site, not one vague supplier-family label.
Tag each record as own operation, subsidiary, , or .
Record the commercial link: contract, purchase order, logistics arrangement, service-development role, distribution appointment, or other relationship.
For subsidiaries covered through parent-company due diligence, retain the subsidiary's adapted policy, cooperation record, and any local measures it still performs.
Do not assume an indirect partner is out of view; Articles 8, 10, and 11 still refer to direct and indirect partners where their activities are part of the .
How should supplier segmentation work in practice?
The Directive does not require every supplier to receive the same questionnaire or contractual package. Amended Article 8 requires a scoping exercise based solely on reasonably available information, followed by in-depth assessment in areas where impacts are most likely and most severe. Article 9 then allows prioritisation when all impacts cannot be addressed at the same time and to their full extent.
A useful segmentation model starts with legal relationship and activity boundary, then adds the amended risk factors: business-partner status under comparable mandatory due diligence law, geography and law enforcement, sector, business operation, and product or service. Stakeholder information, complaints, notifications, and known impact history can then sharpen the assessment. The output should tell teams where an in-depth assessment is needed, not merely rank suppliers by spend.
Boundary segment: upstream production input, upstream service input, downstream product distribution, downstream product transport, downstream product storage, or out of CSDDD chain-of-activities scope.
Relationship segment: own operation, subsidiary, , , SME business partner, or regulated financial undertaking upstream-only case.
Risk segment: severe or likely adverse impact indicators, sector and geography risk, product or service risk, business-model and purchasing-practice risk, and complaint or notification signals.
Assessment segment: no current in-depth assessment needed, targeted information request, site or partner assessment, prevention action plan, corrective action plan, or escalation for an enhanced plan and possible suspension review.
Evidence segment: source of the risk signal, data owner, date of last review, information gaps, supplier response status, stakeholder input, and next review trigger.
Supplier controls should follow the impact finding. Potential adverse impacts point to prevention or mitigation measures; actual adverse impacts point to bringing the impact to an end, minimising its extent, and remediation where the company caused or jointly caused the impact.
The CSDDD examples include prevention and corrective action plans, contractual assurances from direct partners with cascading to relevant partners, verification of those assurances, investments or operational changes, purchasing-practice changes, collaboration, and targeted support for SME business partners where necessary.
Use contractual assurances as one control, not as the whole programme; pair them with verification and impact-specific measures.
When an SME business partner is involved, check whether terms are fair, reasonable, and non-discriminatory and whether targeted capacity, management-system, or financial support is needed.
Separate potential-impact prevention plans from actual-impact corrective action plans so timelines, indicators, and remediation duties are clear.
Directive (EU) 2026/470 removed termination but retained last-resort restrictions on new or extended relationships, an enhanced action plan, and suspension where legally available. Before suspension, assess whether it could cause manifestly more severe impacts; after suspension, provide reasonable notice, address resulting impacts, and keep the decision under review.
Keep stakeholder engagement, complaints, and notification mechanisms connected to the supplier map because they can surface new or better evidence of chain-of-activities impacts.
What evidence should prove the chain-of-activities assessment?
Evidence should show why a partner is inside or outside the , why a risk was prioritised or deferred, and which measure was selected. A reviewer should be able to trace the decision from the CSDDD definition to supplier facts, impact evidence, owner approval, and monitoring results.
Do not keep only supplier self-attestations. Use quantitative and qualitative information, independent reports, digital tools, industry or multi-stakeholder initiatives, complaints, notifications, and relevant stakeholder input. Directive (EU) 2026/470 moved the regular assessment cycle to at least every five years while retaining event-driven reassessment for significant changes, credible new risk information, or evidence that measures are ineffective.
Protect trade secrets and classified or state-security information when collecting partner data. The Directive does not require a partner to disclose a trade secret, but it preserves disclosure of partner identity or essential impact-identification information where necessary and duly justified. Record the necessity, requested field, confidentiality control, and any lawful refusal.
Chain-of-activities boundary memo for each material supplier or partner category, including upstream/downstream classification and any exclusion rationale.
Supplier and subsidiary register showing legal entity, site, activity, direct or indirect status, SME status where relevant, and connected product or service.
Risk segmentation worksheet with sector, geography, product or service, business-operation, complaint, notification, and stakeholder inputs.
In-depth assessment file for higher-risk areas, including source data, information gaps, supplier responses, independent reports, and baseline environmental or human-rights context where relevant.
Prevention or corrective action plan with owner, timeline, qualitative and quantitative indicators, contractual-assurance status, SME support decision, verification method, and monitoring result.
Complaints, notification, stakeholder-engagement, remediation, enhanced-plan, suspension, and no-suspension rationale records linked back to the affected chain-of-activities record.
How does the adopted 2026 amendment change partner assessment?
Directive (EU) 2026/470 requires a scoping exercise across own operations, subsidiaries and relevant business partners using reasonably available information, followed by in-depth assessment in areas where impacts are most likely and most severe. It does not make direct partners the legal boundary.
Request partner information only where necessary. For a business partner with fewer than 5,000 employees, request it only when the information cannot reasonably be obtained by other means; where equally likely or severe areas remain, the company may prioritise assessment involving direct partners.
Do not treat a direct-partner focus as the legal boundary: scope relevant business partners, assess the most likely and severe areas in depth, and use the amended information-request safeguards.
Keep indirect-business-partner data where it supports current CSDDD mapping, product safety, reporting, contractual cascading, complaint handling, or known adverse-impact management.
Record why each information request is necessary. For a business partner with fewer than 5,000 employees, request information only when it cannot reasonably be obtained by other means.
Where several partners can supply the same necessary information, request it, where reasonable, from the partner where the impact is most likely to occur. If areas are equally likely or severe, the company may assess areas involving direct partners first.
Current source for Article 5 information safeguards, Article 8 evidence resources, and the amended Article 15 monitoring triggers and five-year interval.