- Historical Article 15 source; Directive (EU) 2026/470 now sets the regular cycle at least every five years plus event-driven reassessment.
"periodic assessment"
Draw the CSDDD boundary between own operations, subsidiaries, upstream business partners, and limited downstream product activities.
Use the boundary record to decide which entities, activities, partners, and evidence records belong in the due diligence file.
Structured answer sets in this page tree.
Cited legal and guidance references.
Under the Corporate Sustainability Due Diligence Directive, the is narrower than the whole value chain. The due diligence duties cover a company's own operations and subsidiaries, while the definition sets the upstream business-partner boundary and limits downstream coverage to specified product activities carried out for or on behalf of the company.
Build the boundary map in three layers. First list the company's own operations. Second list subsidiaries, because CSDDD due diligence covers actual and potential adverse impacts arising from the company's own operations or those of its subsidiaries. Third list business partners only where their activities relate to the company's .
The directive defines a as an entity with a commercial agreement related to the company's operations, products, or services, or an entity to which the company provides services under the chain-of-activities definition. An is not direct, but performs business operations related to the company's operations, products, or services.
For borderline cases, classify the activity rather than the partner's label. Upstream activities qualify when they relate to producing goods or providing services for the company. Downstream distribution, transport, and storage qualify only for the company's product and only when performed for or on behalf of the company.
Use Sorena to keep CSDDD chain-of-activities classifications tied to the source rule, partner record, contract evidence, and monitoring review.
Upstream coverage is broad. It includes activities of upstream business partners related to production of goods or provision of services by the company, including design, extraction, sourcing, manufacture, transport, storage, supply of raw materials, products or product parts, and development of the product or service.
Downstream coverage is narrower. It covers activities of downstream business partners related to distribution, transport, and storage of the company's product only where those partners carry out those activities for the company or on behalf of the company. The directive does not make ordinary customer use, product disposal, or unrelated downstream services part of this definition.
A parent company may fulfil certain CSDDD obligations on behalf of in-scope subsidiaries where the conditions in Article 6 are met, but that does not erase the subsidiary from the boundary map. The subsidiary and parent must provide each other necessary information, the subsidiary must integrate due diligence into its policies and risk management systems, and the subsidiary remains subject to supervisory powers and civil liability.
For boundary evidence, keep one record for the group-level allocation and another record for each subsidiary's operational perimeter. This avoids the common mistake of treating a group policy as proof that subsidiary-specific operations, partners, and impacts have been mapped.
The direct or indirect label matters because CSDDD uses it in the control design. Prevention and corrective measures can include contractual assurances from direct business partners, cascading assurances to partners where their activities are part of the , and, where impacts cannot otherwise be addressed, assurances from indirect business partners.
Do not classify every lower-tier supplier as out of reach. Amended Article 8 scopes all relevant partner levels using reasonably available information. Necessary information may be requested from a partner with fewer than 5,000 employees only when it cannot reasonably be obtained by other means.
A defensible boundary file should let a reviewer reproduce the classification. It should show the product or service, the entity, the partner relationship, the activity performed, the upstream or downstream side, the inclusion or exclusion rule, the source citation, and the owner who approved the decision.
The record should also connect to due diligence monitoring. Article 15 requires periodic assessments of the company's own operations and measures, those of subsidiaries, and, where related to the , those of business partners. Review the boundary without undue delay after a significant change, whenever new risks or ineffective measures give reasonable grounds for reassessment, and at least every five years.
"periodic assessment"
"keeping all documentation"