This page helps translate Directive (EU) 2024/1760 into operating controls, evidence records, and supervisory-ready documentation.
The focus is the core due diligence cycle: policy integration, impact identification and prioritisation, prevention, corrective action, remediation, complaints, stakeholder engagement, monitoring, communication, and accurate treatment of the removed climate-plan duty.
CSDDD compliance requires a risk-based due diligence system, not only a supplier questionnaire. After Directive (EU) 2026/470, EU companies generally need more than 5,000 employees and EUR 1.5 billion worldwide turnover, while third-country companies use a EUR 1.5 billion Union-turnover route. National measures apply from 26 July 2029. In-scope companies need policies, assessment and prioritisation, appropriate action, stakeholder engagement, complaints, remediation, monitoring, and public communication. The former standalone Article 22 climate-plan duty is no longer current CSDDD law.
1
Section 1
Build the compliance baseline around the amended Articles 7 to 16
A defensible CSDDD programme starts by mapping each obligation to an internal control owner and an evidence record. Article 7 is the anchor: due diligence must be integrated into relevant policies and risk management systems, and the company must have a due diligence policy that supports risk-based due diligence.
The policy record should include the company's long-term due diligence approach, a code of conduct for the company, subsidiaries, and relevant business partners, and the processes used to implement due diligence and verify code-of-conduct compliance. Keep phase-in dates and national transposition status in a separate legal tracker, because timing can change through EU amendments and Member State implementation.
Board or executive governance record: confirms who owns CSDDD implementation, escalation, and resourcing.
Due diligence policy: states the long-term approach, code of conduct, and procedures for integrating due diligence into business processes.
Risk management link: shows how CSDDD impact work connects to enterprise risk, procurement, legal, sustainability, HR, and site-level controls.
Employee consultation record: documents consultation with employees and their representatives before adopting or updating the due diligence policy.
Policy update trigger: captures significant changes and the scheduled review of the policy at least every 24 months.
Amended Article 8 starts with a scoping exercise based solely on reasonably available information across own operations, subsidiaries, and relevant business partners. The company then performs an in-depth assessment in the areas where impacts are most likely and most severe. A generic supplier score does not meet that sequence.
Article 9 allows prioritisation when all identified impacts cannot be handled at the same time and to their full extent. Prioritisation must be based on severity and likelihood, and the record should show why the most severe and most likely impacts were handled first.
Map operations, subsidiaries, and chain-of-activities business partners where adverse impacts are most likely and most severe.
Use quantitative and qualitative inputs, including independent reports, site data, complaints, and notification-channel evidence. Request partner information only where necessary; for partners with fewer than 5,000 employees, request it only when the information cannot reasonably be obtained elsewhere.
Record each identified impact as actual or potential, human rights or environmental, affected stakeholder group, location, business relationship, severity, likelihood, and information source.
Prioritise only when simultaneous full treatment is not feasible, and document the severity and likelihood criteria used.
After the most severe and likely impacts are addressed, keep a backlog for less severe or less likely impacts with owners and next review triggers.
Examples of human-rights impacts include child labour, forced labour, unsafe working conditions, interference with freedom of association, and unlawful displacement where the Annex conditions are met. Environmental impacts are tied to the specific prohibitions and obligations in the Annex, including listed duties on pollution, waste, biodiversity, and hazardous substances; do not substitute a generic ESG issue list.
Prevent potential impacts and correct actual impacts
CSDDD separates potential and actual impacts. For potential impacts, Article 10 requires to prevent them or, where prevention is not possible or not immediately possible, adequately mitigate them. For actual impacts, Article 11 requires appropriate measures to bring the impact to an end or, where that is not immediately possible, minimise its extent.
A useful compliance file should show whether the impact is caused by the company, jointly caused, or linked through a business partner. That analysis drives prevention, corrective action, contractual assurance, verification, operational change, SME support, collaboration, suspension, or remediation. Directive (EU) 2026/470 removed termination but retained last-resort restrictions on new or extended relationships, enhanced action plans, and suspension where legally available and not expected to cause manifestly more severe impacts.
Prevention action plan: use for potential impacts that require structured measures, timelines, and qualitative or quantitative improvement indicators.
Corrective action plan: use for actual impacts that cannot immediately be brought to an end and need staged action.
Business partner controls: document contractual assurances, code-of-conduct flow-down, verification method, and any independent third-party verification.
Operational changes: record changes to purchasing practices, design, distribution, facilities, production, infrastructure, business plans, or overall strategies.
SME support: where relevant, show targeted and proportionate support such as capacity-building, training, management-system upgrades, financing support, or continued sourcing guarantees.
Relationship action: document the legal basis, proportionality, ability to influence the partner, and expected consequences of suspension, disengagement, or continued engagement; termination is no longer a mandatory CSDDD last resort.
Handle remediation, complaints, and stakeholder engagement as operating controls
Article 12 remediation remains tied to the company's involvement in an actual . For Article 13 engagement, use the stakeholder definition and consultation stages as amended by Directive (EU) 2026/470 rather than the broader original list.
Article 14 requires a notification mechanism and complaints procedure. The procedure should be fair, publicly available, accessible, predictable, and transparent. It should allow affected or potentially affected persons and their legitimate representatives, trade unions and worker representatives for workers in the chain concerned, and civil society organisations active and experienced in the relevant area for environmental complaints to raise concerns. Complaints require confidentiality and anti-retaliation safeguards; the notification mechanism must permit anonymous or confidential submissions under national law.
Remediation record: impact, affected person or community, company implication, chosen remedy, proportionality rationale, owner, status, and close-out evidence.
Stakeholder engagement file: consulted stakeholder group, information shared, additional information requests, barriers to engagement, confidentiality measures, and how input changed the decision.
Complaints procedure: public channel, eligibility categories, acknowledgement, assessment, founded or unfounded decision, reasons, follow-up, meeting option, and remediation discussion record.
Notification mechanism: anonymous or confidential intake route for information about actual or potential adverse impacts.
Retaliation control: records measures taken to protect complainant or notifier identity and safety where information must be shared.
Reopen due diligence for acquisitions, restructuring, and new markets
Run a change-event review before an acquisition, merger, restructuring, new country entry, major product or service launch, material input change, or new form of business relationship. The review should identify impacts that the current policy, partner map, complaint channel, and action plans do not cover.
After closing an acquisition or restructuring, integrate the acquired entity or changed operation into the CSDDD system without waiting for the five-year cycle. Current Article 15 requires assessment without undue delay after a significant change and when there are reasonable grounds to believe new risks have arisen or existing measures are no longer adequate or effective.
Pre-transaction file: target or project entities, operations, products and services, countries, workforce, subsidiaries, business partners, known complaints, investigations, environmental liabilities, action plans, remedy commitments, and evidence gaps.
Decision record: salient actual and potential impacts, affected rightsholders, chain-of-activities boundary, proposed prevention or corrective measures, deal or launch condition, owner, budget, timeline, and unresolved risk accepted by the approving body.
Integration plan: policy and training rollout, partner and impact-register migration, complaint-channel access, worker and community communication, contract and purchasing-practice review, supplier support, remediation continuity, monitoring indicators, and Article 16 reporting boundary.
Change triggers after integration: facility closure, workforce transfer, supplier replacement, production relocation, new raw material, changed logistics route, product redesign, new customer or market, serious complaint, failed corrective action, or loss of access to affected stakeholders.
Evidence control: preserve the pre-change baseline and the reasons for each boundary, priority, action, and remedy decision so later reviewers can distinguish inherited impacts from impacts caused or jointly caused after the change.
Monitor, communicate, and separate any retained climate-plan evidence
Article 15 requires assessment of implementation, adequacy, and effectiveness. Directive (EU) 2026/470 moved the regular cycle from at least every 12 months to at least every five years, while retaining event-driven reassessment after significant change or when reasonable grounds indicate new risks or ineffective measures.
Article 16 requires public communication through an annual website statement unless the company is subject to the listed sustainability-reporting requirements, including the relevant exemptions. Publish in the required Union language and, where different, a language customary in international business, no later than 12 months after the balance-sheet date; a third-country company's statement also identifies its authorised representative. The delegated acts specifying content and criteria are due by 31 March 2029, and the reporting measures apply for financial years starting on or after 1 January 2030. Directive (EU) 2026/470 removed the separate CSDDD Article 22 climate-transition-plan duty.
Monitoring pack: assessment date, significant-change trigger, indicators used, findings, stakeholder information considered, and updates to policy, impact register, or measures.
Annual due diligence statement: exemption analysis, publication language, website location, reporting boundary, covered matters, approval record, and ESAP submission readiness from 1 January 2031 where applicable.
If a climate transition plan remains required elsewhere: record the target, milestones, emissions coverage, decarbonisation levers, and product or service portfolio changes required by that separate source.
Climate status evidence: record removal of the standalone CSDDD duty and map any retained plan to its separate current legal, contractual, risk-management, or voluntary basis.
Document retention: keep identified impacts, assessments, action plans, contracts, verifications, remediation measures, monitoring records, notifications, and complaints together for at least five years.
This CSDDD guide helps connect due diligence duties, impact records, complaint channels, climate-plan evidence, and supervisory response files before teams publish or report compliance claims.
CSDDD compliance evidence should be built for supervisory review, not only internal assurance. Member States must designate supervisory authorities to supervise compliance with national provisions adopted under the amended Directive. Track the final transposition law for information powers, investigations, orders, remediation, penalties, interim measures, and appeal procedures.
Directive (EU) 2026/470 requires Member States to set the maximum limit for pecuniary penalties at 3% of the company's net worldwide turnover in the preceding financial year, or 3% of consolidated worldwide turnover for the specified ultimate-parent routes. National law still determines the penalty process and the amount imposed in a case. Track administrative supervision, substantiated concerns, investigation records, remedial-action periods, effective, proportionate, and dissuasive penalties, and possible public statements for unpaid pecuniary penalties.
Authority-response file: designated supervisory authority, contact point, information requests, submissions, response dates, and legal review notes.
Substantiated-concern register: concerns received from authorities or stakeholders, objective basis, competence routing, assessment outcome, and protective measures for identity information.
Investigation record: nature and result of investigation, remedial-action period, enforcement action, and evidence supplied to the authority.
Penalty factors file: gravity, duration, severity of impacts, prevention or corrective investments, collaboration, prioritisation rationale, previous infringements, remedial action, and financial benefit or loss avoided.
Non-EU company file: authorised representative designation, accepted appointment, contact details, powers and resources, and supervisory authority notification.