FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
55of55items
Across 13 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
CSDDD contractual assurances FAQ for Articles 10 and 11

Are the Commission's model clauses mandatory?

No. Amended Article 18 requires the Commission to adopt guidance on voluntary model contractual clauses by 26 July 2027. Until that guidance exists, a company should not present its own wording as an official EU model. After publication, using a model clause will still not replace the impact-specific action, verification, SME treatment, monitoring, or escalation required by Articles 10 and 11.

The clause should match the actual adverse impact and the partner's role. It should identify the code-of-conduct or action-plan obligation, evidence and access needed for verification, support the company will provide where required, milestones, review rights, and the response to non-performance. Contract language does not create an automatic defence to civil liability under amended Article 29.

  • Label internal clauses as company-drafted until official voluntary guidance is published.
  • Do not state that a signed model clause certifies CSDDD compliance.
  • Record which prevention or corrective action the clause supports and how compliance will be verified.
  • Review the clause when Commission guidance, national transposition, the impact assessment, or the partner relationship changes.
Citations
CSDDD contractual assurances FAQ for Articles 10 and 11

What must sit alongside CSDDD contractual assurances?

A signed clause is not enough. Articles 10(5) and 11(6) say contractual assurances must be accompanied by appropriate measures to verify compliance. The directive allows independent third-party verification, including through industry or multi-stakeholder initiatives, where that is appropriate.

The contract file should therefore show both the promise and the control loop: what obligation is covered, how compliance will be checked, who reviews verification results, what evidence is accepted, and what happens when the partner misses the agreed action-plan milestones.

  • Assurance text mapped to the code of conduct, prevention action plan, or corrective action plan.
  • Verification method, such as documentary review, site assessment, third-party verification, or initiative-based verification where appropriate.
  • Improvement indicators and timelines from the prevention or corrective action plan.
  • Escalation trigger for missed milestones, unreliable evidence, refusal to cooperate, or persistent adverse impact.
  • Evidence showing the company kept monitoring instead of relying on paper-only assurances.
Citations
CSDDD contractual assurances FAQ for Articles 10 and 11

How should companies handle SMEs in CSDDD contractual-assurance requests?

SMEs are not brought into the CSDDD scope merely because a large in-scope company asks for assurances, but Articles 10 and 11 protect SMEs in the assurance process. When assurances are obtained from, or a contract is entered into with, an SME, the terms must be fair, reasonable, and non-discriminatory.

The company must also assess whether SME assurances should be accompanied by SME support measures. The directive names capacity-building, training, management-system upgrades, and, where the code of conduct or action plan would jeopardise the SME's viability, targeted and proportionate financial support.

  • Check whether the business partner is an SME before issuing standard assurance language.
  • Remove one-sided terms that push all verification cost, timing pressure, or implementation burden onto the SME.
  • Document whether capacity-building, training, management-system support, or financial support is needed.
  • Where independent third-party verification is carried out for an SME, the in-scope company bears the cost. Record any SME request or agreement to pay part of the cost and whether the SME may share the results with other companies.
Citations
CSDDD contractual assurances FAQ for Articles 10 and 11

How should weak assurances escalate after the 2026 amendment?

Weak assurances should trigger verification, stronger prevention or corrective action, support, operational change, collaboration, and proportionate relationship measures. Directive (EU) 2026/470 removed mandatory termination as the final CSDDD step.

Before suspension, disengagement, or continued engagement, assess expected impacts on affected people and the environment, the company's ability to influence the partner, alternative measures, notice where relevant, and the monitoring needed to test the decision.

  • Keep the original due-diligence finding and severity assessment.
  • Keep the prevention or corrective action plan, including timelines and improvement indicators.
  • Keep the contractual assurance text and any cascading assurances requested from partners.
  • Keep verification results, failed evidence requests, site or initiative findings, and partner responses.
  • Keep the enhanced action plan and the rationale for the selected relationship measure.
  • Keep the assessment of adverse impacts caused by suspension, disengagement, or continued engagement, plus notice and review records where relevant.
Citations
Directive (EU) 2026/470

Article 4(8) and 4(9) replace the last-resort relationship measures in Articles 10 and 11, including suspension, notice, impact assessment, monitoring, and the removal of mandatory termination.

CSDDD prevention vs mitigation: potential and actual adverse impacts

What is the CSDDD difference between prevention and mitigation?

Under the CSDDD, prevention is the first Article 10 objective for a potential adverse impact: stop the impact from occurring where possible. Mitigation is the Article 10 fallback where prevention is not possible or not immediately possible: reduce the likelihood, severity, or conditions that could allow the potential impact to occur.

For actual adverse impacts, the vocabulary changes. Article 11 requires companies to bring each impact to an end. If an impact cannot immediately be brought to an end, the company must minimise its extent and use corrective measures proportionate to the severity of the impact and the company's implication in it.

  • Use Article 10 for potential adverse impacts identified under Article 8 and prioritised under Article 9.
  • Use prevention measures where the impact can still be avoided.
  • Use mitigation measures where avoidance is not possible or not immediately possible.
  • Use Article 11 corrective measures when the adverse impact already exists.
  • Record why the issue is treated as potential or actual before assigning controls.
Citations
Directive (EU) 2026/470

Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.

CSDDD prevention vs mitigation: potential and actual adverse impacts

How should a team classify a finding before choosing a response?

Start with the amended Article 8 process. Use reasonably available information to scope the general areas across the company's own operations, subsidiaries, and relevant chains of activities where impacts are most likely and most severe. Then conduct an in-depth assessment in those areas and decide whether each identified impact is potential or actual. If the company cannot address all identified impacts at the same time and to their full extent, Article 9 requires prioritisation based on severity and likelihood.

The classification should also record involvement and influence. Articles 10 and 11 ask whether the company caused the impact, caused it jointly through acts or omissions with a subsidiary or business partner, or whether only a business partner caused it. They also distinguish where the impact occurs in the chain of activities and whether the company can influence the relevant business partner.

  • Impact status: potential adverse impact or actual adverse impact.
  • Location: own operations, subsidiary, direct business partner, or indirect business partner in the chain of activities.
  • Involvement: caused by the company, caused jointly, or caused only by a business partner.
  • Priority: severity and likelihood when impacts cannot all be addressed fully at once.
  • Influence: what influence the company has and what additional influence can realistically be built.
Citations
Directive (EU) 2026/470

Article 3(6) replaces Article 8(2) with reasonably-available-information scoping followed by in-depth assessment in the areas where impacts are most likely and most severe.

CSDDD prevention vs mitigation: potential and actual adverse impacts

What measures belong in a prevention or mitigation plan?

For potential adverse impacts, Article 10 lists appropriate measures that may be relevant depending on the circumstances. A prevention action plan is needed where the nature or complexity of the measures requires one, and it should include reasonable and clearly defined timelines plus qualitative and quantitative indicators for improvement.

Article 10 covers more than supplier clauses. It also points to investments, operational adjustments, purchasing-practice changes, design and distribution changes, targeted SME support, and collaboration where that increases the company's ability to prevent or mitigate the potential adverse impact.

  • Prevention action plan with timelines and indicators where needed.
  • Contractual assurances from direct business partners, supported by verification measures.
  • Operational investments, adjustments, upgrades, or infrastructure changes.
  • Changes to business plans, strategies, operations, purchasing practices, design, or distribution.
  • Targeted and proportionate SME support where needed in light of resources, knowledge, and constraints.
  • Collaboration with other entities where no other measure is suitable or effective.
Citations
CSDDD prevention vs mitigation: potential and actual adverse impacts

What changes when the adverse impact is already actual?

Once the impact is actual, the response should be managed as Article 11 work. The first objective is to bring the impact to an end. If that cannot happen immediately, the company must minimise the extent of the impact, and Article 11 measures include neutralising the impact or minimising its extent, corrective action plans, contractual assurances, investments, operational changes, SME support, collaboration, and remediation where Article 12 applies.

A corrective action plan addresses a specific actual impact, while a prevention action plan addresses a potential impact. The corrective plan should use reasonable and clearly defined timelines and include qualitative and quantitative indicators for measuring improvement.

  • State the factual evidence showing that the adverse impact has occurred or is occurring.
  • Define what would count as bringing the impact to an end.
  • If immediate ending is not possible, define what minimising the extent means in measurable terms.
  • Use a corrective action plan where needed, not a generic risk-control plan.
  • Assess remediation separately where the company caused or jointly caused the actual adverse impact.
Citations
CSDDD prevention vs mitigation: potential and actual adverse impacts

When does suspension become a last-resort measure?

Directive (EU) 2026/470 removed mandatory termination and retained a mandatory last-resort response. If the preceding Article 10 or 11 measures fail, the company must refrain from new or extended relationships connected to the impact, adopt an enhanced action plan without undue delay where success can reasonably be expected, and suspend the affected activities where the governing law entitles it to do so.

Before suspension, the company must assess whether suspension could reasonably be expected to cause impacts that are manifestly more severe than the unresolved impact. If so, suspension is not required, and the company must be able to give the supervisory authority its duly justified reasons. A company that suspends must address the suspension's impacts, give reasonable notice, and keep the decision under review; a company that does not suspend must monitor the unresolved impact and periodically reassess the decision.

  • Record why ordinary Article 10 or Article 11 measures were insufficient.
  • Record the enhanced prevention or corrective action plan and its timeline.
  • Assess whether suspension could cause impacts that are manifestly more severe than the unresolved impact.
  • Give the business partner reasonable notice if the relationship is suspended.
  • Keep a suspension or non-suspension decision under review and monitor the unresolved impact.
Citations
Directive (EU) 2026/470

Article 3(8) and (9) replace Articles 10(6) and 11(7): they remove termination, require specified last-resort measures, condition suspension on governing law and a comparison of adverse impacts, and require notice, mitigation, monitoring, and review.

CSDDD prevention vs mitigation: potential and actual adverse impacts

What evidence records should be kept?

Use an impact file that lets a reviewer see the identified impact, the Article 10 or Article 11 classification, the prioritisation basis, stakeholder input, measures selected, implementation status, and monitoring result.

Article 15 requires effectiveness assessment. Directive (EU) 2026/470 uses a regular cycle of at least every five years plus event-driven reassessment after significant change or when reasonable grounds indicate new risks or ineffective measures.

  • Impact register entry with potential or actual status, Article 8 scoping evidence, and the in-depth assessment where required.
  • Severity, likelihood, and prioritisation rationale under Article 9.
  • Prevention action plan or corrective action plan, including timelines and indicators.
  • Contractual assurances, verification records, SME support records, and operational-change evidence.
  • Stakeholder engagement notes for information gathering, prevention, corrective and enhanced plan development, and remediation. Record any additional voluntary engagement for suspension decisions or monitoring separately from Article 13's mandatory-stage list.
  • Complaint and notification records, including founded or unfounded outcomes and actions taken or planned.
  • Periodic assessment record showing effectiveness, updates after significant changes, and open residual issues.
Citations
Directive (EU) 2026/470

Article 3(11) replaces Article 15 with monitoring after a significant change, at least every five years, and whenever reasonable grounds indicate new risks or ineffective measures.

CSDDD remediation FAQ: when companies must remedy adverse impacts

When does the CSDDD require remediation?

The mandatory remediation trigger is narrow: the company must provide remediation when it has caused or jointly caused an actual adverse impact. The Directive defines remediation as restoring affected persons, communities, or the environment to a situation equivalent or as close as possible to the one that would have existed without the impact. The response must be proportionate to the company's implication.

Do not treat every supplier incident as an automatic company-funded remedy. If the actual adverse impact was caused only by a business partner, the company may provide voluntary remediation and may use its influence over that business partner to enable remediation.

  • Mandatory: the company caused or jointly caused the actual adverse impact.
  • Voluntary or influence-based: only the business partner caused the actual adverse impact.
  • Not enough by itself: a potential impact, a weak allegation, or a general supply-chain risk without an identified actual adverse impact.
  • Remediation can include financial or non-financial compensation and, where applicable, reimbursement of public-authority costs for necessary remedial measures.
  • Article 12 remediation is separate from Article 11 measures to end an actual impact or minimise its extent; the same incident may require both.
Citations
Directive (EU) 2026/470

Binding amendment that entered into force on 18 March 2026; its CSDDD changes must be transposed by 26 July 2028 and applied from 26 July 2029.

CSDDD remediation FAQ: when companies must remedy adverse impacts

How should a company design and verify remediation?

Define the intended outcome with affected stakeholders before choosing the measure. The outcome should address the people, community, or environmental resource harmed, while reflecting what restoration is possible and the company's implication in the impact. Financial payment may be part of the response, but the Directive also permits non-financial compensation and restoration-oriented measures.

Set completion criteria that test the outcome rather than the activity. A payment record, supplier instruction, or corrective action may prove that a step occurred, but it does not by itself show that affected people or the environment were restored as far as possible. Record any part of the harm that cannot be reversed, any measure controlled by a business partner or public authority, and the follow-up needed.

Examples of non-financial remedy can include restitution, rehabilitation, an apology, or a guarantee of non-repetition, depending on the impact and the affected stakeholder's needs. Those examples come from the UN Guiding Principles' remedy framework; Article 12 controls whether the CSDDD requires the company to provide remediation in the specific case.

  • Confirm that the impact is actual and identify the people, community, or environmental resource affected.
  • Record why the company caused, jointly caused, or did not cause the impact.
  • Consult relevant affected stakeholders on the proposed remediation measure and barriers to participation.
  • Specify the measure, responsible owner, timetable, intended outcome, and evidence of delivery.
  • Check whether the outcome was achieved and record unresolved or irreversible harm.
  • Keep Article 11 corrective action, Article 12 remediation, civil liability, and any voluntary business-partner support as separate conclusions.
Citations
CSDDD remediation FAQ: when companies must remedy adverse impacts

How should teams decide whether the company caused or jointly caused the impact?

Start with the factual link between the company's own operations, its subsidiaries, and business partners in the chain of activities. The remediation file should explain what happened, who was affected, which activity or omission created the harm, and whether the company was one of the causes.

For a jointly caused impact, the remedy should be proportionate to the company's implication. For a business-partner-only impact, the record should explain what influence is available, what the company asked the partner to do, and whether voluntary support is appropriate.

  • Record the actual impact, location, affected persons, communities, workers, or environmental resource.
  • Map the company activity, subsidiary activity, or business-partner activity linked to the impact.
  • State the causation view: caused by the company, jointly caused, caused only by a business partner, or still unresolved.
  • Define the remediation measure, the affected-stakeholder engagement step, the owner, and the follow-up date.
  • Keep the analysis separate from civil-liability conclusions, which depend on national law and Article 29 conditions.
Citations
CSDDD remediation FAQ: when companies must remedy adverse impacts

How do complaints and affected stakeholders change the remediation response?

Complaints can supply evidence for the remediation analysis. Article 14 requires companies to enable complaints from affected persons, people with reasonable grounds to believe they may be affected, their legitimate representatives, relevant trade unions or workers' representatives, and experienced civil-society organisations for environmental impacts.

If a complaint is well founded, the adverse impact is treated as identified and the company must take the relevant measures under the directive, including remediation where Article 12 applies. Complainants can request follow-up, meet company representatives about severe impacts and potential remediation, and receive reasons for a founded or unfounded decision.

  • Make the complaints procedure fair, public, accessible, predictable, and transparent.
  • Protect confidentiality and take reasonably available steps to prevent retaliation against complainants or notifying persons.
  • Do not require a complaint or notification before affected persons can use supervisory-authority procedures, civil-liability procedures, or other non-judicial mechanisms.
  • When adopting remediation measures, consult relevant stakeholders under Article 13 and address barriers to engagement.
Citations
CSDDD remediation FAQ: when companies must remedy adverse impacts

What evidence should teams keep for CSDDD remediation?

The evidence should let a later reviewer see why remediation was required, what outcome was selected, what was done, whether it worked, and what remained unresolved. Recital 61 says compliance documentation should include remediation measures, periodic assessments, notifications, and complaints where relevant.

Keep enough detail to support the causation view and the remedy design without turning the file into unsupported legal conclusions. The most useful record is a compact remediation log tied to the underlying impact assessment, complaint file, stakeholder consultation, and implementation proof.

  • Impact record: actual impact, affected stakeholders, date discovered, source of discovery, and chain-of-activities link.
  • Causation record: caused, jointly caused, business-partner-only, or unresolved, with reasons and evidence.
  • Complaint record: complainant category, confidentiality handling, follow-up, meeting notes where applicable, outcome, and reasons.
  • Stakeholder record: who was consulted, information shared, barriers addressed, refusal reasons for additional information if any, and retaliation safeguards.
  • Remediation record: remedy selected, proportionality rationale, owner, implementation evidence, completion status, and monitoring results.
  • Limit record: why any requested measure was outside Article 12, impossible, disproportionate, voluntary, or dependent on a business partner.
Citations
Page 2 of 4