CSDDD vs OECD Guidelines Binding duty or RBC guidance
This comparison helps separate the EU directive's legal obligations from OECD responsible-business-conduct recommendations.
The useful overlap is operational: both point teams toward risk-based due diligence, adverse-impact management, stakeholder engagement, remediation, and evidence.
The CSDDD and the use related due diligence ideas but have different legal force. The CSDDD is an EU directive that Member States must transpose and supervise for covered companies. The 2023 OECD Guidelines are non-binding government recommendations to multinational enterprises, supported by and the OECD due diligence model. OECD alignment can shape a credible operating process, but it does not establish CSDDD scope or compliance.
Comparison matrix
CSDDD vs OECD Guidelines: compliance and responsible-business-conduct comparison
Use these rows to decide when a company needs a CSDDD legal workstream, when alignment is still relevant, and which evidence can support both without confusing the authority of each framework.
Directive (EU) 2024/1760 as amended creates binding due diligence, stakeholder-engagement, complaint, monitoring, communication, supervisory, penalty, and civil-liability rules once a company is in scope under national transposition. Directive (EU) 2026/470 removed the standalone climate-plan duty.
Second framework
OECD Guidelines
The are non-binding recommendations addressed by adhering governments to multinational enterprises. promote the Guidelines and handle specific instances, but they do not impose CSDDD penalties or determine civil liability.
CSDDD vs OECD Guidelines: compliance and responsible-business-conduct comparison
CSDDD applies only after a company meets the directive's covered-company conditions and after the relevant national rules apply. Its due diligence covers the company's own operations, subsidiaries, and business partners where related to the company's chain of activities.
The apply to multinational enterprises operating in or from adhering countries without defining a turnover, employee, ownership, or sector threshold. They cover human rights, employment and industrial relations, environment, bribery, consumer interests, disclosure, science and technology, competition, and taxation.
Do not use OECD alignment as a proxy for CSDDD scope. First decide whether the company is legally covered by CSDDD; then use OECD expectations to widen the responsible-business-conduct map for entities, products, services, and relationships outside the directive's legal perimeter.
For CSDDD, the accountable actor is the covered company, including any parent-company support arrangement allowed by the directive. Subsidiaries remain exposed to supervisory powers and civil liability where the directive says their obligations or liability remain.
For the , the expectation is addressed to multinational enterprises and all entities within the multinational enterprise according to their actual distribution of responsibilities. Governments commit to promote the Guidelines through , but observance by enterprises is voluntary.
Name the CSDDD legal entity, parent-company support model, supervisory authority, and local transposition owner separately from the enterprise-wide OECD program owner. The same procurement, sustainability, or human-rights team can operate both, but the accountability record should not merge them.
CSDDD starts with legal scope and staged application under the directive and national transposition. Operationally, due diligence is then triggered by identified actual or potential adverse human-rights or environmental impacts in own operations, subsidiaries, or relevant business partners.
OECD due diligence is not triggered by a turnover or employee threshold. It is a risk-based expectation: enterprises should identify, prevent, mitigate, and account for actual and potential adverse impacts connected to their operations, products, services, supply chains, and other business relationships.
Use two trigger checks: one legal check for CSDDD coverage and applicable national timing, and one OECD risk check for whether an activity, product, service, or relationship creates actual or potential adverse impacts even outside CSDDD coverage.
After Directive (EU) 2026/470, CSDDD requires covered companies to run amended risk-based due diligence, including reasonably-available-information scoping across relevant business partners, in-depth assessment where impacts are most likely and most severe, prioritisation, proportionate action, remediation, relevant stakeholder engagement, complaints, monitoring, and communication. The standalone climate-plan duty was removed.
The OECD due diligence model asks enterprises to embed responsible business conduct into policies and management systems, identify and assess impacts, cease, prevent and mitigate impacts, track implementation and results, communicate how impacts are addressed, and provide for or cooperate in remediation when appropriate. The expected response depends on whether the enterprise caused an impact, contributed to it, or is directly linked to it through a business relationship.
Map the OECD six-step model to amended CSDDD Articles 7 to 16, then add the legal controls that the OECD model cannot supply: covered-entity scope, chain-of-activities limits, complaint rights, monitoring intervals, Article 16 rules, national supervision, and penalties. Record former CSDDD Article 22 only as superseded history.
CSDDD evidence should prove the current legal obligations were performed: mapped risk factors, in-depth assessments, prioritisation by severity and likelihood, prevention or corrective action plans, contractual assurances and verification, SME support where relevant, stakeholder consultations at the amended stages, complaint outcomes, monitoring results, public communication, and records for supervisory investigations.
OECD evidence should show a credible responsible-business-conduct process: policies and management systems, impact assessment records, mitigation decisions, ability to influence business relationships, stakeholder input, tracking results, communication to affected stakeholders, and remediation or cooperation with legitimate mechanisms.
A single evidence repository can serve both frameworks, but tag each record by legal function. Record the OECD cause, contribution, or direct-link analysis because it changes the expected response: cease and remediate impacts the enterprise caused or contributed to, and use its influence to prevent or mitigate impacts directly linked through a business relationship. Then map the same facts to the applicable CSDDD article and national law.
After Directive (EU) 2026/470, CSDDD monitoring assessments follow a regular cycle of at least every five years plus event-driven review after significant change or when reasonable grounds suggest new risks or ineffective measures. Article 16 has separate annual-statement timing.
OECD due diligence is ongoing and responsive. The Guidance frames due diligence as multiple processes that adapt to circumstances, business relationships, and stakeholder information rather than a fixed statutory review calendar.
Use the binding CSDDD clock for covered legal records, and use OECD's ongoing-risk lens to trigger extra reviews when new products, sourcing regions, complaints, stakeholder information, or relationship changes create new impact risks.
CSDDD is enforced through Member State supervisory authorities with powers to request information, investigate, order cessation or non-repetition, require proportionate remediation where appropriate, impose penalties, and adopt interim measures. Member States must provide pecuniary penalties subject to the amended 3% maximum-limit rule. Civil-liability conditions are supplied by national law, with full compensation protected where national-law liability is established for damage caused by a covered due diligence failure.
The are not legally enforceable as enterprise obligations. Their implementation mechanism is , which promote the Guidelines and can handle specific instances through non-judicial procedures such as dialogue, mediation, final statements, and recommendations.
Escalate CSDDD failures through the legal, board, and supervisory-response process. Escalate OECD issues through the responsible-business-conduct grievance, stakeholder, and NCP-readiness process. A public NCP statement can create reputation and relationship risk, but it is not the same as a CSDDD fine or damages claim.
CSDDD deliberately borrows the international due diligence architecture: identify and assess impacts, prioritise by severity and likelihood, prevent or mitigate potential impacts, end or minimise actual impacts, engage stakeholders, provide remediation, monitor, and communicate. It converts selected parts into EU legal duties for covered companies.
The and Due Diligence Guidance provide the broader responsible-business-conduct architecture behind that process, including caused, contributed-to, and directly linked impacts, ability to influence business relationships, meaningful stakeholder engagement, tracking, communication, and remediation.
Use OECD materials to make the CSDDD operating model practical, especially for prioritisation, influence over business relationships, stakeholder engagement, and remediation design. Do not use OECD language to soften CSDDD duties where national law creates mandatory requirements.
Use CSDDD when the question is legal coverage, national implementation, mandatory due diligence controls, complaint rights, annual communication, supervisory response, penalties, or civil liability. Directive (EU) 2026/470 deleted the standalone CSDDD climate-transition-plan duty.
Use the when the question is responsible-business-conduct alignment, enterprise-wide due diligence maturity, ability to influence business relationships, stakeholder expectations, NCP readiness, or impacts that matter even when CSDDD legal scope is not triggered.
Build one operating model with two labels on every record: the CSDDD legal duty where applicable and the OECD responsible-business-conduct expectation. If the mappings call for different actions, preserve both analyses; the binding national CSDDD rule controls legal compliance, while the OECD record explains the broader stakeholder and business-relationship response.
CSDDD applies only after a company meets the directive's covered-company conditions and after the relevant national rules apply. Its due diligence covers the company's own operations, subsidiaries, and business partners where related to the company's chain of activities.
The apply to multinational enterprises operating in or from adhering countries without defining a turnover, employee, ownership, or sector threshold. They cover human rights, employment and industrial relations, environment, bribery, consumer interests, disclosure, science and technology, competition, and taxation.
Do not use OECD alignment as a proxy for CSDDD scope. First decide whether the company is legally covered by CSDDD; then use OECD expectations to widen the responsible-business-conduct map for entities, products, services, and relationships outside the directive's legal perimeter.
For CSDDD, the accountable actor is the covered company, including any parent-company support arrangement allowed by the directive. Subsidiaries remain exposed to supervisory powers and civil liability where the directive says their obligations or liability remain.
For the , the expectation is addressed to multinational enterprises and all entities within the multinational enterprise according to their actual distribution of responsibilities. Governments commit to promote the Guidelines through , but observance by enterprises is voluntary.
Name the CSDDD legal entity, parent-company support model, supervisory authority, and local transposition owner separately from the enterprise-wide OECD program owner. The same procurement, sustainability, or human-rights team can operate both, but the accountability record should not merge them.
CSDDD starts with legal scope and staged application under the directive and national transposition. Operationally, due diligence is then triggered by identified actual or potential adverse human-rights or environmental impacts in own operations, subsidiaries, or relevant business partners.
OECD due diligence is not triggered by a turnover or employee threshold. It is a risk-based expectation: enterprises should identify, prevent, mitigate, and account for actual and potential adverse impacts connected to their operations, products, services, supply chains, and other business relationships.
Use two trigger checks: one legal check for CSDDD coverage and applicable national timing, and one OECD risk check for whether an activity, product, service, or relationship creates actual or potential adverse impacts even outside CSDDD coverage.
After Directive (EU) 2026/470, CSDDD requires covered companies to run amended risk-based due diligence, including reasonably-available-information scoping across relevant business partners, in-depth assessment where impacts are most likely and most severe, prioritisation, proportionate action, remediation, relevant stakeholder engagement, complaints, monitoring, and communication. The standalone climate-plan duty was removed.
The OECD due diligence model asks enterprises to embed responsible business conduct into policies and management systems, identify and assess impacts, cease, prevent and mitigate impacts, track implementation and results, communicate how impacts are addressed, and provide for or cooperate in remediation when appropriate. The expected response depends on whether the enterprise caused an impact, contributed to it, or is directly linked to it through a business relationship.
Map the OECD six-step model to amended CSDDD Articles 7 to 16, then add the legal controls that the OECD model cannot supply: covered-entity scope, chain-of-activities limits, complaint rights, monitoring intervals, Article 16 rules, national supervision, and penalties. Record former CSDDD Article 22 only as superseded history.
CSDDD evidence should prove the current legal obligations were performed: mapped risk factors, in-depth assessments, prioritisation by severity and likelihood, prevention or corrective action plans, contractual assurances and verification, SME support where relevant, stakeholder consultations at the amended stages, complaint outcomes, monitoring results, public communication, and records for supervisory investigations.
OECD evidence should show a credible responsible-business-conduct process: policies and management systems, impact assessment records, mitigation decisions, ability to influence business relationships, stakeholder input, tracking results, communication to affected stakeholders, and remediation or cooperation with legitimate mechanisms.
A single evidence repository can serve both frameworks, but tag each record by legal function. Record the OECD cause, contribution, or direct-link analysis because it changes the expected response: cease and remediate impacts the enterprise caused or contributed to, and use its influence to prevent or mitigate impacts directly linked through a business relationship. Then map the same facts to the applicable CSDDD article and national law.
After Directive (EU) 2026/470, CSDDD monitoring assessments follow a regular cycle of at least every five years plus event-driven review after significant change or when reasonable grounds suggest new risks or ineffective measures. Article 16 has separate annual-statement timing.
OECD due diligence is ongoing and responsive. The Guidance frames due diligence as multiple processes that adapt to circumstances, business relationships, and stakeholder information rather than a fixed statutory review calendar.
Use the binding CSDDD clock for covered legal records, and use OECD's ongoing-risk lens to trigger extra reviews when new products, sourcing regions, complaints, stakeholder information, or relationship changes create new impact risks.
CSDDD is enforced through Member State supervisory authorities with powers to request information, investigate, order cessation or non-repetition, require proportionate remediation where appropriate, impose penalties, and adopt interim measures. Member States must provide pecuniary penalties subject to the amended 3% maximum-limit rule. Civil-liability conditions are supplied by national law, with full compensation protected where national-law liability is established for damage caused by a covered due diligence failure.
The are not legally enforceable as enterprise obligations. Their implementation mechanism is , which promote the Guidelines and can handle specific instances through non-judicial procedures such as dialogue, mediation, final statements, and recommendations.
Escalate CSDDD failures through the legal, board, and supervisory-response process. Escalate OECD issues through the responsible-business-conduct grievance, stakeholder, and NCP-readiness process. A public NCP statement can create reputation and relationship risk, but it is not the same as a CSDDD fine or damages claim.
CSDDD deliberately borrows the international due diligence architecture: identify and assess impacts, prioritise by severity and likelihood, prevent or mitigate potential impacts, end or minimise actual impacts, engage stakeholders, provide remediation, monitor, and communicate. It converts selected parts into EU legal duties for covered companies.
The and Due Diligence Guidance provide the broader responsible-business-conduct architecture behind that process, including caused, contributed-to, and directly linked impacts, ability to influence business relationships, meaningful stakeholder engagement, tracking, communication, and remediation.
Use OECD materials to make the CSDDD operating model practical, especially for prioritisation, influence over business relationships, stakeholder engagement, and remediation design. Do not use OECD language to soften CSDDD duties where national law creates mandatory requirements.
Use CSDDD when the question is legal coverage, national implementation, mandatory due diligence controls, complaint rights, annual communication, supervisory response, penalties, or civil liability. Directive (EU) 2026/470 deleted the standalone CSDDD climate-transition-plan duty.
Use the when the question is responsible-business-conduct alignment, enterprise-wide due diligence maturity, ability to influence business relationships, stakeholder expectations, NCP readiness, or impacts that matter even when CSDDD legal scope is not triggered.
Build one operating model with two labels on every record: the CSDDD legal duty where applicable and the OECD responsible-business-conduct expectation. If the mappings call for different actions, preserve both analyses; the binding national CSDDD rule controls legal compliance, while the OECD record explains the broader stakeholder and business-relationship response.
Start with CSDDD only when the company, subsidiary, or third-country entity may be legally covered by national rules transposing Directive (EU) 2024/1760.
Use OECD due diligence to shape the operating process, especially for risk-based prioritisation, influence over business relationships, stakeholder engagement, tracking, communication, and remediation.
Keep separate evidence tags for legal duty, OECD expectation, affected stakeholder, business relationship, decision owner, review trigger, and remediation status.
Do not cite OECD observance as proof that CSDDD is satisfied unless the record also maps to the relevant CSDDD article and national implementation requirement.
What evidence should a combined CSDDD and OECD program keep?
The shared evidence set should show what the company knew about actual and potential adverse impacts, how it prioritised severe and likely impacts, what it asked business partners to do, how it used its influence, what stakeholders said, what remediation was offered or supported, and how the company checked whether the response worked.
The CSDDD record needs legal traceability: article or national-law obligation, covered entity, chain-of-activities link, action-plan status, complaint or notification status, monitoring date, communication status, supervisory request, and civil-liability sensitivity. The OECD record needs responsible-business-conduct traceability: due diligence step, caused, contributed, or directly linked analysis, business relationship, stakeholder group, influence decision, remediation responsibility, and NCP-specific-instance status.
Keep one impact register with fields for severity, likelihood, affected right or environmental matter, location, product or service, business relationship, and source of the signal.
Keep one action register with prevention, mitigation, corrective, remediation, stakeholder-engagement, monitoring, and communication actions mapped separately to CSDDD and OECD.
Keep complaint and notification records accessible enough for CSDDD obligations while also useful as early-warning and remediation inputs under OECD due diligence.
Keep a decision log for suspension or continued engagement with business partners, including the expected adverse impacts of the decision itself. If the company voluntarily terminates a relationship, record the separate legal and contractual basis rather than presenting termination as a current mandatory CSDDD step.
Keep public communication and stakeholder communication records distinct; a CSDDD annual statement does not supersede timely communication to affected stakeholders where OECD due diligence calls for it.
Turn CSDDD and OECD due diligence into one evidence model
This comparison helps label legal CSDDD duties, OECD responsible-business-conduct expectations, owners, business relationships, stakeholder inputs, and remediation evidence without merging their authority.