FAQ item index

Search every question across sub-FAQs

Find the exact question, open the source answer card, and copy a direct link to the anchored sub-FAQ response.

Indexed coverage
55of55items
Across 13 modules • Updated Jul 25, 2026
Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
CSDDD remediation FAQ: when companies must remedy adverse impacts

What are the limits of remediation under the CSDDD?

Remediation under Article 12 does not supersede every other route to remedy. Affected stakeholders do not have to seek company remediation before bringing claims in court, and a company complaint procedure does not block access to supervisory-authority, judicial, or other non-judicial mechanisms.

Civil liability is a separate question. Directive (EU) 2026/470 changed the original harmonised Article 29 formula, so any damages conclusion now requires the applicable Member State transposition and private-law analysis.

  • Do not promise that the company complaint procedure is the exclusive remedy route.
  • Do not present voluntary remediation for a business-partner-only impact as an admission that Article 12 required company remediation.
  • Do not use remediation language to hide unresolved prevention, mitigation, or corrective-action duties.
  • Do not publish penalty amounts or damages thresholds unless they are supported by the applicable national transposition and the source record.
Citations
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence

When can CSDDD teams prioritise adverse impacts instead of addressing everything at once?

Article 9 applies after Article 8 identification and assessment. If it is not feasible to prevent, mitigate, bring to an end, or minimise all identified adverse impacts at the same time and to their full extent, the company must prioritise the impacts so it can fulfil the prevention and mitigation duties in Articles 10 and 11.

The priority order must be based on the severity and likelihood of the adverse impacts. After the most severe and most likely impacts have been addressed within a reasonable time, the company must move on to less severe and less likely impacts. New Article 9(4) also says that the mere fact that a less significant impact has not yet been addressed does not expose the company to Article 27 penalties when the prioritisation decision complied with Article 9. That protection does not excuse a defective ranking or remove the duty to progress to lower priorities.

  • Start from identified actual and potential adverse human rights and environmental impacts. Supplier spend, contract value, media exposure, and convenience are not Article 9 ranking criteria.
  • Use prioritisation to sequence action when capacity, access, or timing prevents simultaneous full response.
  • Record when each lower-priority impact will be revisited so prioritisation does not become permanent deferral.
Citations
Directive (EU) 2026/470

Article 3(6) introduces the current scoping and in-depth assessment process; Article 3(7) adds the penalty rule for compliant prioritisation decisions; Article 5 sets transposition and application dates.

CSDDD risk prioritisation FAQ: severity, likelihood, and evidence

How should teams score severity and likelihood for CSDDD prioritisation?

Severity should focus on the impact on people or the environment. The CSDDD definition of severity of an adverse impact points to scale, scope, and irremediable character, including gravity, the number of people affected, environmental extent, irreversibility, and limits on restoring affected people or the environment within a reasonable period.

Likelihood should capture credible indicators that the impact has occurred or may occur, such as prior assessments, notifications, complaints, geography and context, sector, business operation, product or service, and changed operating conditions. The Directive does not prescribe a numeric scale, weighting formula, tier count, or automatic cutoff. If a team uses scores, it should retain the underlying evidence and explain how the scores express severity and likelihood.

These risk factors should be specific enough to test. For example, a weak rule-of-law context, a history of worker complaints, a hazardous production process, or a product linked to an Annex-listed environmental harm can change the evidence for likelihood or severity. The example identifies inputs, not an automatic classification or score.

The OECD Due Diligence Guidance is non-binding but useful for method design. It treats severity as the predominant factor when prioritising potential human-rights impacts, especially where delay could make an impact irremediable. That method does not replace the CSDDD requirement to consider both severity and likelihood.

  • Severity fields: affected right or environmental interest, scale, scope, irremediability, affected groups, affected sites, and restoration limits.
  • Likelihood fields: known incidents, complaints, credible external reports, supplier or site assessment results, operating context, sector risk, product or service risk, and change triggers.
  • Outcome field: ranked priority tier, immediate action, action owner, planned follow-up for lower-ranked impacts, and the reason the ranking changed or stayed the same.
Citations
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence

What stakeholder evidence belongs in a CSDDD prioritisation file?

Stakeholder evidence should help test the company's view of severity and likelihood. Amended Article 13 requires consultation of relevant stakeholders when gathering information to identify, assess, and prioritise adverse impacts; when developing prevention, corrective, and enhanced action plans; and when adopting remediation measures. Suspension decisions and monitoring-indicator development are no longer listed as mandatory consultation stages.

The record should distinguish direct stakeholder evidence from expert input. If effective stakeholder engagement is not reasonably possible, the company should consult experts who can provide credible insight into actual or potential impacts.

  • Record who was consulted: employees, workers' representatives, directly affected individuals or communities, and legitimate representatives. Include consumers only where directly affected and organisations only where they legitimately represent directly affected individuals or communities; keep Article 14 complainant eligibility separate.
  • Record how barriers were handled: language, access, retaliation risk, confidentiality, anonymity, vulnerable groups, and overlapping vulnerabilities.
  • Record what changed: priority score, action plan, indicator, escalation, or explanation for why stakeholder evidence did not change the ranking.
Citations
Directive (EU) 2026/470

Article 3(10) narrows the mandatory consultation stages by deleting the former suspension-decision and monitoring-indicator stages.

CSDDD risk prioritisation FAQ: severity, likelihood, and evidence

What makes a CSDDD prioritisation rationale audit-ready?

An audit-ready rationale should let a reviewer trace the decision from identified impact to priority ranking to action. It should explain why the selected impacts were treated first, which evidence was used, which stakeholders or experts informed the assessment, and when lower-ranked impacts will be addressed.

The rationale should also separate prioritisation from response design. Articles 10 and 11 ask different questions after prioritisation, including whether the company caused the impact, caused it jointly, or whether only a business partner caused it; where the impact occurs in the chain of activities; and what influence the company can exercise.

  • Impact record: description, actual or potential status, affected people or environmental area, activity, subsidiary, direct or indirect business partner, and chain-of-activities location.
  • Priority record: severity analysis, likelihood analysis, stakeholder or expert evidence, missing information, assumptions, and the reason for the final rank.
  • Action record: prevention, mitigation, ending, minimisation, remediation, business partner engagement, contractual assurance, verification, support to SMEs, or escalation path.
  • Review record: monitoring indicator, responsible owner, next review event, and evidence showing less severe or less likely impacts are not forgotten.
Citations
Does CSDDD Still Have Scope Waves?

Current answer and planning record

The current schedule has one company application date, but it still has distinct legal and reporting milestones. Transposition is due first, the due diligence measures apply next, and Article 16 follows by reference to the start of a financial year. Do not collapse those events into one deadline.

A company can prepare before 2029 without describing the amended CSDDD as already directly applicable to every control. Existing national due diligence laws, sector rules, contracts, and voluntary commitments may impose earlier or different duties and need their own source and date.

  • 26 July 2028: transposition and supervisory-authority notification deadline.
  • 26 July 2029: application to all companies remaining within amended Article 2 scope.
  • 1 January 2030: Article 16 measures apply for financial years starting on or after this date.
  • The single date does not put every former wave company back in scope. Recheck the amended Article 2 thresholds before assigning the 2029 application date.
  • Do not retain 'first wave' and 'broader wave' labels in a current-law calendar.
  • Keep old schedules only in a clearly marked legislative-history record, and track Commission guidance, national transposition, Article 16 reporting, and ESAP as separate milestones.
Citations
Does CSDDD Still Have Scope Waves?

What should replace a wave-based implementation plan?

Use an entity-by-entity scope record. An EU company passes the general route only when it has more than 5,000 employees on average and more than EUR 1.5 billion net worldwide turnover, or it is the ultimate parent of a group meeting both thresholds on a consolidated basis. A third-country company uses more than EUR 1.5 billion net turnover generated in the Union, with a corresponding consolidated ultimate-parent route and no employee threshold.

The separate franchise and licensing route requires more than EUR 75 million in qualifying Union royalties and more than EUR 275 million turnover. EU companies use net worldwide turnover from the last financial year; third-country companies use Union turnover from the financial year preceding the last financial year. Every applicable Article 2 route must be met in two consecutive financial years, and scope ends only after two consecutive relevant years below the conditions.

Once scope is established, record 26 July 2029 as the application date and work backward from national transposition, Commission guidance, voluntary model contractual-clause guidance due by 26 July 2027, and Article 16 reporting dependencies. A legacy wave label does not establish current scope or a current deadline.

  • Inputs: entity formation law, group and ultimate-parent structure, employee count where applicable, net-turnover basis, Union allocation, qualifying royalties, and the two relevant financial years.
  • Branches: EU general route, third-country general route, EU franchise or licensing route, third-country franchise or licensing route, or outside Article 2 on current evidence.
  • Evidence: adopted or consolidated financial statements, employee calculation, agreement and royalty schedule, control analysis, currency method, consolidation eliminations, reviewer approval, and unresolved assumptions.
  • Reassessment: repeat after a threshold-crossing year, acquisition, disposal, restructuring, restatement, change in ultimate parent, new qualifying agreement, or amended national measure.
Citations
Does Franchising Trigger CSDDD Scope?

Apply the franchise and licensing test

The route covers franchising or licensing agreements in the Union with independent third-party companies, in return for royalties, where the agreements ensure a common identity, a common business concept, and uniform business methods. A contract called a franchise, licence, distribution, or brand agreement does not qualify or fail by label alone. Test the parties' independence, the three operating features, the Union connection, and the royalty arrangement.

For an EU company, both amounts are tested in the last financial year for which annual financial statements have been or should have been adopted: qualifying royalties must exceed EUR 75 million and the company or group must have more than EUR 275 million net worldwide turnover. For a third-country company, both amounts are Union amounts tested in the financial year preceding the last financial year. Equality is not enough: EUR 75 million or EUR 275 million exactly does not pass a threshold stated as 'more than'.

The company may qualify directly or as the ultimate parent company of a group that entered into the agreements and met the turnover threshold. Article 2 also requires the complete route to be met in two consecutive financial years. Scope ends only after the conditions cease to be met in each of the last two relevant financial years.

Example: an EU franchisor with EUR 80 million of qualifying Union royalties and EUR 300 million of net worldwide turnover passes the amount tests for that year. It enters this route only if the agreement conditions are also met and the complete test is satisfied in the next consecutive year. A company with EUR 80 million in royalties but EUR 275 million in turnover does not pass because the turnover must be more than EUR 275 million.

A below-threshold franchisee does not become directly subject to CSDDD merely because an in-scope franchisor requests information, contractual assurances, or corrective action. Keep direct Article 2 scope separate from obligations a franchisee may accept by contract and from requests made through a franchisor's due diligence process.

  • Entity and group input: identify the contracting company, every relevant subsidiary, and the ultimate parent company; preserve the control analysis and consolidated financial statements.
  • Agreement input: list the Union agreements, independent counterparties, royalty clauses, common identity, common business concept, and uniform business methods; exclude agreements that fail any element.
  • Amount input: reconcile qualifying royalties and net turnover to the applicable financial statements for each of the two consecutive test years, including the chosen currency-conversion method and consolidation eliminations.
  • EU-company branch: use qualifying Union royalties and net worldwide turnover from the last financial year for which annual financial statements have been or should have been adopted.
  • Third-country branch: use qualifying Union royalties and Union net turnover from the financial year preceding the last financial year.
  • General-route branch: separately test the EU-company employee and worldwide-turnover thresholds or the third-country Union-turnover threshold; failing the franchise route does not settle general scope.
  • Outcome record: state pass, fail, or unresolved for every element, the first of the two consecutive qualifying years, the expected 26 July 2029 application date if scope is maintained, and the reviewer who approved the conclusion.
  • Reassessment triggers: new or terminated agreements, a change in counterparty independence or group control, revised royalty accounting, acquisitions or disposals, restated financial statements, or a threshold result changing in either relevant year.
  • After scope: map which franchise or licensing activities fall within the CSDDD chain of activities; scope under Article 2 does not make every downstream activity part of that chain.
Citations
How CSDDD overlaps with OECD, UNGP, and ILO standards

Are the OECD Guidelines, UNGP, and ILO standards legally equivalent to CSDDD?

No. CSDDD is an EU directive that Member States must transpose and enforce through national law. The OECD Guidelines, UN Guiding Principles on Business and Human Rights, OECD due diligence guidance, and ILO Tripartite Declaration are reference frameworks that influenced the directive's due diligence model.

For legal applicability, thresholds, supervisory authority powers, civil liability, penalties, and application dates, use CSDDD and the implementing national law. For operational design, use the international frameworks to test whether the company's process covers the expected due diligence lifecycle and the relevant rights-holder and worker perspectives.

  • Use CSDDD for binding EU obligations, scope, supervision, documentation retention, and public communication requirements.
  • Use OECD guidance to structure risk-based responsible business conduct due diligence across policies, impact identification, prevention, tracking, communication, and remediation.
  • Use the UNGPs to keep human rights due diligence focused on risks to people, stakeholder consultation, influence over business relationships, communication, and remedy.
  • Use ILO materials to ground labour topics such as forced labour, child labour, discrimination, freedom of association, collective bargaining, occupational safety and health, and worker grievance handling.
Citations
Directive (EU) 2026/470

Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.

How CSDDD overlaps with OECD, UNGP, and ILO standards

How should companies use OECD guidance when building CSDDD due diligence?

OECD guidance is most useful as the operating model for risk-based due diligence. It describes the sequence a CSDDD program should be able to evidence: embed responsible business conduct into policies and management systems, identify and assess actual and potential adverse impacts, cease, prevent and mitigate impacts, track implementation and results, communicate how impacts are addressed, and provide for or cooperate in remediation when appropriate.

That OECD sequence aligns closely with CSDDD's due diligence requirements, but the company still needs a CSDDD-specific control map. Each OECD-inspired process step should point to the relevant CSDDD obligation, the affected operation, subsidiary or chain-of-activities relationship, the risk severity and likelihood assessment, and the evidence retained.

  • Start with CSDDD scope: covered company, subsidiaries, own operations, and chain-of-activities boundaries.
  • Use OECD's risk-based method to prioritize impacts by severity and likelihood when everything cannot be addressed at once.
  • Use the OECD caused, contributed to, or directly linked categories for OECD process design, but map CSDDD decisions to the Directive's own wording, including whether the impact is caused only by the company, caused jointly with a subsidiary or business partner, or caused only by a business partner.
  • Supplier codes, contracts, purchasing-practice changes, training, audits, remediation, and disengagement do not by themselves establish CSDDD compliance.
Citations
OECD responsible business conduct guidance

Supports using OECD responsible business conduct materials as practical due diligence guidance for embedding, identifying, preventing, tracking, communicating, and remediation.

How CSDDD overlaps with OECD, UNGP, and ILO standards

What does the UN Guiding Principles overlap add to CSDDD implementation?

The UNGPs help prevent a CSDDD program from becoming a supplier-audit exercise that misses affected people. They frame human rights due diligence around actual and potential adverse impacts on rights-holders alongside enterprise risk. They also distinguish policy commitment, human rights due diligence, remediation, stakeholder consultation, tracking, and communication.

For CSDDD work, that means the evidence file should show which people or communities may be affected, which human rights standards were considered, what internal or external expertise was used, how potentially affected stakeholders were consulted or why an alternative was used, and how findings were integrated into business decisions.

  • Use the UNGPs to test whether assessments identify specific impacts on specific people in a specific operating context.
  • Use the UNGPs to assess the company's influence and response when an impact is linked to a business relationship rather than caused directly by the company.
  • Use the UNGPs to design communication that is sufficient for stakeholders to evaluate the response without creating safety, confidentiality, or retaliation risks.
  • Do not use the UNGPs to replace CSDDD article mapping, supervisory reporting, or national-law analysis.
Citations
How CSDDD overlaps with OECD, UNGP, and ILO standards

Where do ILO conventions and the ILO Tripartite Declaration fit into CSDDD?

ILO standards help translate CSDDD's human rights due diligence into labour-rights checks. The Directive's Annex identifies specific rights and prohibitions and cites particular international instruments, including ILO conventions. That Annex, read with Article 3, determines which listed labour-rights abuse can be an adverse human rights impact under CSDDD; the wider body of ILO material does not automatically enter CSDDD as binding text. The ILO Tripartite Declaration adds labour and industrial-relations context for multinational enterprises, governments, employers, and workers' organizations.

An official source CSDDD labour-risk file should therefore connect the detected labour issue to the relevant CSDDD annex item, the workforce or worker-representative evidence, the supplier or workplace context, the prevention or mitigation measure, and any remediation or grievance route. It should avoid vague claims that a supplier is ILO-aligned unless the underlying labour rights and evidence are identified.

  • Forced labour and child labour checks should include indicators, worker interview or grievance evidence where appropriate, and remediation escalation for affected people.
  • Freedom of association and collective bargaining checks should involve worker-representative context rather than only management attestations.
  • Safety and health checks should connect hazards, controls, worker information, incidents, corrective actions, and compensation or remediation where relevant.
  • Use the exact CSDDD Annex item and cited instrument for the legal impact analysis; use wider ILO materials for implementation context unless another law gives them separate legal force.
Citations
How CSDDD overlaps with OECD, UNGP, and ILO standards

What evidence shows the overlap has been handled correctly?

Good evidence does not say only that the company follows OECD, UNGP, or ILO standards. It shows how those standards informed a CSDDD control and where the binding CSDDD requirement is satisfied. The record should be readable by legal, sustainability, procurement, internal audit, and business owners without relying on a separate narrative.

Use a crosswalk that records the CSDDD obligation, related international standard, affected operation or business relationship, adverse impact, severity and likelihood, stakeholder input, action taken, owner, result-tracking method, remediation route, and source citation. This prevents both overstatement and under-implementation.

  • CSDDD article or annex item mapped to the relevant OECD, UNGP, or ILO principle.
  • Impact assessment showing the affected rights-holders, workers, communities, or environmental interest.
  • Prioritization rationale based on severity and likelihood, with unresolved high-risk items visible.
  • Prevention, mitigation, remediation, influence, or responsible-disengagement decision with an accountable owner.
  • Stakeholder engagement record, including worker or representative input where labour rights are involved.
  • Tracking and communication evidence showing whether the response worked and what remains open.
Citations
How Does CSDDD Civil Liability Work Now?

What changed from the original Article 29?

Directive (EU) 2024/1760 originally set a harmonised liability test in Article 29(1). Directive (EU) 2026/470 deleted that paragraph, so the Directive no longer supplies one uniform EU test for fault, causation, protected interests, or the former business-partner-only exclusion.

The amendment did not delete the rest of Article 29. Where national law holds a company liable for damage caused by failure to comply with CSDDD due diligence requirements, Article 29(2) requires full compensation and bars punitive, multiple, or other overcompensation. Participation in an industry initiative, third-party verification, or contractual clauses does not create an automatic defence.

Member States must transpose the amended CSDDD by 26 July 2028 and apply those national measures from 26 July 2029. A claim still requires a country-specific check of the law in force when the alleged conduct and damage occurred; this page does not determine liability in an individual case.

  • Identify the national transposition provision and effective date.
  • Identify the ordinary or special civil-liability regime that supplies the cause of action.
  • Where national-law liability is established for a covered due diligence failure, apply the Article 29 right to full compensation without punitive, multiple, or other overcompensation.
  • Test jurisdiction, applicable law, claimant standing, fault, causation, damage, and the available procedural route.
  • Separate a damages claim from supervisory enforcement and administrative penalties.
Citations
Directive (EU) 2026/470 amending the CSDDD

Article 4(20) deletes Article 29(1), replaces the compensation rule, preserves possible liability despite verification or contractual clauses, and removes the representative-action facilitation rule.

How Does CSDDD Civil Liability Work Now?

Which Article 29 procedural safeguards still apply?

Member States must provide a limitation period of at least five years, no shorter than the period under their general civil-liability regime. The period cannot begin before the infringement has ceased and the claimant knows, or can reasonably be expected to know, the relevant conduct and infringement, the resulting harm, and the infringer's identity.

Proceedings must not be prohibitively expensive, and claimants must be able to seek definitive or provisional injunctions to stop an infringement of national CSDDD measures. A court may order a company to disclose evidence when the claimant provides a reasoned justification with reasonably available facts and evidence supporting a plausible damages claim and identifies additional evidence under the company's control. Disclosure remains subject to necessity, proportionality, confidentiality, and national procedural law.

The 2026 amendment deleted Article 29(3)(d), which had required conditions for trade unions, human rights institutions, and certain civil society organisations to bring actions on an injured person's behalf. Whether representative or collective action remains available must therefore be checked under applicable EU and national law.

  • Calculate limitation using both Article 29(3)(a) and the applicable national rules.
  • Distinguish a damages action from an injunction intended to stop ongoing non-compliance.
  • For disclosure, identify the claim, the evidence already available, the evidence believed to be under company control, and why the request is necessary and proportionate.
  • Check national rules for representative and collective actions instead of relying on the deleted Article 29(3)(d).
Citations
Page 3 of 4