FAQCSDDDEU

CSDDD risk prioritisation how to rank adverse impacts by severity, likelihood, and evidence

CSDDD prioritisation is allowed when a company cannot prevent, mitigate, end, or minimise all identified adverse impacts at the same time and to their full extent.

Use severity, likelihood, stakeholder evidence, and a documented rationale to show why one impact was addressed before another.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the as amended by Directive (EU) 2026/470, sequences lower-ranked issues instead of discarding them. It applies to actual and potential impacts identified through reasonably-available-information scoping and in-depth assessment of the areas where impacts are most likely and most severe. The company then ranks identified impacts by severity and likelihood and moves to less severe and less likely impacts after addressing the highest priorities within a reasonable time. Member States must apply the amended due diligence rules from 26 July 2029; until then, current duties depend on the applicable national law.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

When can CSDDD teams prioritise adverse impacts instead of addressing everything at once?

Article 9 applies after Article 8 identification and assessment. If it is not feasible to prevent, mitigate, bring to an end, or minimise all identified adverse impacts at the same time and to their full extent, the company must prioritise the impacts so it can fulfil the prevention and mitigation duties in Articles 10 and 11.

The priority order must be based on the severity and likelihood of the adverse impacts. After the most severe and most likely impacts have been addressed within a reasonable time, the company must move on to less severe and less likely impacts. New Article 9(4) also says that the mere fact that a less significant impact has not yet been addressed does not expose the company to Article 27 penalties when the decision complied with Article 9. That protection does not excuse a defective ranking or remove the duty to progress to lower priorities.

  • Start from identified actual and potential adverse human rights and environmental impacts. Supplier spend, contract value, media exposure, and convenience are not Article 9 ranking criteria.
  • Use to sequence action when capacity, access, or timing prevents simultaneous full response.
  • Record when each lower-priority impact will be revisited so does not become permanent deferral.
Citations
Directive (EU) 2026/470

Article 3(6) introduces the current scoping and in-depth assessment process; Article 3(7) adds the penalty rule for compliant prioritisation decisions; Article 5 sets transposition and application dates.

Question 2

How should teams score severity and likelihood for CSDDD prioritisation?

Severity should focus on the impact on people or the environment. The definition of points to scale, scope, and irremediable character, including gravity, the number of people affected, environmental extent, irreversibility, and limits on restoring affected people or the environment within a reasonable period.

Likelihood should capture credible indicators that the impact has occurred or may occur, such as prior assessments, notifications, complaints, geography and context, sector, business operation, product or service, and changed operating conditions. The Directive does not prescribe a numeric scale, weighting formula, tier count, or automatic cutoff. If a team uses scores, it should retain the underlying evidence and explain how the scores express severity and likelihood.

These should be specific enough to test. For example, a weak rule-of-law context, a history of worker complaints, a hazardous production process, or a product linked to an Annex-listed environmental harm can change the evidence for likelihood or severity. The example identifies inputs, not an automatic classification or score.

The OECD Due Diligence Guidance is non-binding but useful for method design. It treats severity as the predominant factor when prioritising potential human-rights impacts, especially where delay could make an impact irremediable. That method does not replace the requirement to consider both severity and likelihood.

  • Severity fields: affected right or environmental interest, scale, scope, irremediability, affected groups, affected sites, and restoration limits.
  • Likelihood fields: known incidents, complaints, credible external reports, supplier or site assessment results, operating context, sector risk, product or service risk, and change triggers.
  • Outcome field: ranked priority tier, immediate action, action owner, planned follow-up for lower-ranked impacts, and the reason the ranking changed or stayed the same.
Citations
Recommended next step

Turn CSDDD prioritisation into a reviewable evidence file

Use Sorena to connect CSDDD impact records, stakeholder evidence, severity and likelihood rationale, and follow-up actions before decisions are challenged.

Question 3

What stakeholder evidence belongs in a CSDDD prioritisation file?

Stakeholder evidence should help test the company's view of severity and likelihood. Amended Article 13 requires consultation of relevant stakeholders when gathering information to identify, assess, and prioritise adverse impacts; when developing prevention, corrective, and enhanced action plans; and when adopting remediation measures. Suspension decisions and monitoring-indicator development are no longer listed as mandatory consultation stages.

The record should distinguish direct stakeholder evidence from expert input. If effective stakeholder engagement is not reasonably possible, the company should consult experts who can provide credible insight into actual or potential impacts.

  • Record who was consulted: employees, workers' representatives, directly affected individuals or communities, and legitimate representatives. Include consumers only where directly affected and organisations only where they legitimately represent directly affected individuals or communities; keep Article 14 complainant eligibility separate.
  • Record how barriers were handled: language, access, retaliation risk, confidentiality, anonymity, vulnerable groups, and overlapping vulnerabilities.
  • Record what changed: priority score, action plan, indicator, escalation, or explanation for why stakeholder evidence did not change the ranking.
Citations
Directive (EU) 2026/470

Article 3(10) narrows the mandatory consultation stages by deleting the former suspension-decision and monitoring-indicator stages.

Question 4

What makes a CSDDD prioritisation rationale audit-ready?

An audit-ready rationale should let a reviewer trace the decision from identified impact to priority ranking to action. It should explain why the selected impacts were treated first, which evidence was used, which stakeholders or experts informed the assessment, and when lower-ranked impacts will be addressed.

The rationale should also separate from response design. Articles 10 and 11 ask different questions after prioritisation, including whether the company caused the impact, caused it jointly, or whether only a business partner caused it; where the impact occurs in the chain of activities; and what influence the company can exercise.

  • Impact record: description, actual or potential status, affected people or environmental area, activity, subsidiary, direct or indirect business partner, and chain-of-activities location.
  • Priority record: severity analysis, likelihood analysis, stakeholder or expert evidence, missing information, assumptions, and the reason for the final rank.
  • Action record: prevention, mitigation, ending, minimisation, remediation, business partner engagement, contractual assurance, verification, support to SMEs, or escalation path.
  • Review record: monitoring indicator, responsible owner, next review event, and evidence showing less severe or less likely impacts are not forgotten.
Citations
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Article 3(10) narrows the mandatory consultation stages by deleting the former suspension-decision and monitoring-indicator stages.
"Consultation of relevant stakeholders"
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.