CSDDDPlaybookEU

CSDDD Due Diligence Steps Playbook

A step-by-step operating sequence for the CSDDD duties in Article 5 and Articles 7-16.

Use it to structure policy integration, impact assessment, prioritisation, prevention, corrective action, remediation, engagement, complaints, monitoring, communication, and evidence.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Article 5 of Directive (EU) 2024/1760, in its version applicable from 18 March 2026, defines CSDDD as a risk-based human rights and environmental process carried out through Articles 7 to 16. Start with company policy and risk systems, then move through impact scoping and assessment, prioritisation, prevention or correction, remediation, stakeholder engagement, complaints, monitoring, and public communication. These EU duties will apply through national transposition measures from 26 July 2029; Article 16 reporting measures apply for financial years starting on or after 1 January 2030.

Section 1

Step 1: integrate due diligence into policy and risk systems

Start with Article 7. Embed the policy in the policies and risk management systems used by procurement, operations, product, legal, and sustainability teams.

The policy should describe the company's approach, include a code of conduct for the company, subsidiaries, and direct or indirect business partners where relevant, and explain the processes used to implement and verify the code. Article 7 also requires prior consultation with employees and their representatives when developing the policy.

  • Owner: board or executive sponsor for the policy; legal, sustainability, procurement, operations, and HR for implementation.
  • Evidence: approved policy, employee consultation record, code of conduct, risk-system mapping, business-partner flow-down approach, and verification process.
  • Review trigger: significant change; Article 7 also requires review and, where necessary, update at least every 24 months.
  • Do not treat Article 7 as only document control. It is the control layer for the later Article 8-16 steps.
Section 2

Step 2: identify, assess, and prioritise adverse impacts

Article 8 turns the policy into a two-stage risk scan. Use only reasonably available information to scope the company's own operations, subsidiaries, and chain-of-activities business partners for areas where adverse human rights or environmental impacts are most likely and most severe. Then perform an in-depth assessment in those higher-risk areas.

Article 9 applies when the company cannot address every actual or potential impact at once. Severity and likelihood set the priority; cost, convenience, and the existing audit cycle do not.

  • Inputs: internal site and activity data, subsidiary data, business-partner and chain-of-activities mapping, independent reports, complaints and notification data, and stakeholder information.
  • Assessment fields: impact type, affected people or environment, severity, likelihood, source of information, business relationship, and whether the impact may be caused by the company, jointly by the company and a subsidiary or business partner, or only by a business partner in the chain of activities.
  • Prioritisation record: ranked impacts, rationale based on severity and likelihood, information gaps, and the next Article 10 or Article 11 action.
  • Information-request control: request only necessary information during in-depth assessment. For business partners with fewer than 5,000 employees, request it only if it cannot reasonably be obtained by other means; where reasonable, ask the partner where the impact is most likely to occur.
  • Evidence: scoping map, in-depth assessment files, necessary information requests, alternative-source checks for smaller partners, complaint inputs, and prioritisation minutes.
  • Article 9 outcome: record the less significant impacts scheduled for later action. If prioritisation complies with Article 9, the mere fact that such an impact has not yet been addressed does not expose the company to Article 27 penalties.
Section 3

Step 3: prevent potential impacts and correct actual impacts

Split potential and actual impacts. Article 10 is for potential adverse impacts: prevent them where possible or adequately mitigate them where prevention is not possible or not immediately possible. Article 11 is for actual adverse impacts: bring them to an end, or minimise their extent if they cannot immediately be ended.

Both articles require the company to consider whether the impact is caused only by the company, jointly with a subsidiary or business partner, or only by a business partner in the chain of activities; where the impact occurs; and the company's ability to influence the relevant business partner.

  • Potential-impact controls: prevention action plan, contractual assurances, verification, operational or infrastructure changes, purchasing-practice changes, SME support, collaboration, and last-resort suspension under amended Article 10; mandatory termination was removed in 2026.
  • Actual-impact controls: neutralisation or minimisation, corrective action plan, contractual assurances, verification, operational change, SME support, collaboration, remediation, and last-resort suspension under amended Article 11.
  • Action-plan fields: impact, root cause, responsible function, business partner, timeline, qualitative and quantitative indicators, support offered to SMEs, verification method, escalation route, and review status.
  • Suspension branch: refrain from a new or extended relationship, adopt an enhanced plan without undue delay where success can reasonably be expected, and suspend affected activities where the governing law permits unless suspension can reasonably be expected to cause manifestly more severe impacts. Record notice, mitigation of suspension impacts, and ongoing review.
  • Non-suspension branch: record why suspension is not required, monitor the impact, and periodically reassess the decision and whether further measures are available.
  • Evidence: prevention and corrective plans, contract clauses, verification, purchasing-practice changes, SME support, suspension assessments, notice, impact-mitigation steps, review dates, and the rationale for the selected influence measure.
Section 4

Step 4: provide remediation and engage stakeholders

Article 12 requires remediation where the company caused or jointly caused an actual adverse impact. If the impact was caused only by a business partner, the company may provide voluntary remediation and may use its influence over the business partner to support remediation.

Article 13 keeps stakeholder engagement inside , but Directive (EU) 2026/470 narrowed the stakeholder definition and mandatory stages. Consult the relevant affected stakeholders or legitimate representatives at the amended decision points and document why the engagement is adequate.

  • Remediation fields: affected rightsholders or environmental harm, company involvement, remedy type, responsible owner, timeline, stakeholder input, completion evidence, and follow-up.
  • Engagement fields: stakeholder group, consultation stage, information shared, additional information requested, response or written refusal rationale, barriers to participation, confidentiality or anonymity measures, and anti-retaliation safeguards.
  • Escalation: if effective stakeholder engagement is not reasonably possible, Article 13 points to additional consultation with experts who can provide credible insights.
  • Evidence: remediation approvals, remedy delivery records, stakeholder consultation notes, information packets, written refusal justifications, expert consultation records, and confidentiality safeguards.
Section 5

Step 5: run complaints, monitoring, communication, and evidence controls

Article 14 requires a notification mechanism and complaints procedure for legitimate concerns about actual or potential adverse impacts in the company's own operations, subsidiaries, or business partners in the chain of activities. The procedure must be fair, publicly available, accessible, predictable, and transparent, with confidentiality and anti-retaliation measures.

Articles 15 and 16 close the loop. Monitoring assesses implementation, adequacy, and effectiveness using qualitative and quantitative indicators where appropriate. Run it without undue delay after a significant change, at least every five years, and whenever there are reasonable grounds to think measures are no longer adequate or effective or new impact risks have arisen or may arise. Communication requires an annual website statement unless the Article 16 reporting exemption applies; the statement is due no later than 12 months after the balance-sheet date and must meet the language and third-country representative rules.

  • Complaints intake: affected persons, legitimate representatives, trade unions, workers' representatives, and experienced civil society organisations for environmental complaints can be eligible complainants under Article 14.
  • Complaint workflow: receive the complaint, protect confidentiality, assess whether it is founded, record reasons, meet at an appropriate level where requested, identify Article 10, 11, or 12 follow-up, and communicate steps taken or planned. A well-founded complaint deems the impact identified under Article 8.
  • Notification workflow: accept information or concerns through an anonymous or confidential route under national law, prevent retaliation, link the notification to impact scoping, and tell the notifier about action where relevant.
  • Monitoring record: assessment date, five-year deadline, significant-change or reasonable-grounds trigger, indicators used, operations and business partners covered, measures tested, stakeholder information considered, findings, and updates to policy, impacts, or measures.
  • Communication record: annual statement owner, language check, publication date, balance-sheet-date deadline check, Article 16 exemption analysis if relying on sustainability reporting under the cited Accounting Directive provisions, and evidence linking public claims to monitored measures.
Recommended next step

Turn CSDDD duties into a usable evidence register

This playbook helps align each Article 7-16 step with accountable owners, impact records, stakeholder inputs, complaints, monitoring, and public communication evidence.

Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.
commission.europa.eu
Referenced sections
  • The Commission overview supports the page context that Directive (EU) 2024/1760 addresses adverse human rights and environmental impacts in companies' operations and global value chains.
"identify and address adverse human rights and environmental impacts"
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.