CSDDDWorkflowEU

CSDDD grievance, notification, and remediation workflow guide

A source-grounded workflow for turning CSDDD Articles 12, 13, and 14 into complaint intake, stakeholder engagement, remediation, and evidence records.

Use it to design a complaints procedure that feeds due diligence, not a detached inbox that only records issues.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 31, 2026
Sections
7

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 31, 2026
Overview

Article 14 requires both a and a notification mechanism. A well-founded complaint is deemed to identify the adverse impact for Article 8 and must feed the appropriate Article 10, 11, and 12 measures. Article 13 governs consultation at specified due-diligence stages, while Article 12 requires remediation when the company caused or jointly caused an actual adverse impact. The workflow below connects intake, assessment, action, remedy, follow-up, confidentiality, and monitoring.

Section 1

1. Separate complaints, notifications, and whistleblowing intake

Start by defining two CSDDD intake routes. A complaint route is for legitimate concerns raised by the eligible Article 14(2) persons and entities about actual or potential adverse human rights or environmental impacts in the company's own operations, subsidiaries, or business partners in the chain of activities. Its procedure must be fair, publicly available, accessible, predictable, and transparent, including when the company considers a complaint unfounded. A notification route is open to persons or entities with information or concerns about actual or potential adverse impacts, and it must support anonymous or confidential submissions in accordance with national law.

Do not treat the CSDDD mechanism as a renamed whistleblowing channel. The directive describes the Article 14 as separate from the internal reporting procedure under the EU Whistleblowing Directive, although a directly affected employee may sometimes be able to use both.

  • Publish the channel, eligibility rules, confidentiality terms, non-retaliation statement, follow-up path, and escalation contact in language that affected workers and external stakeholders can understand.
  • Allow complaints from affected persons, persons with reasonable grounds to believe they might be affected, their legitimate representatives, relevant trade unions or workers' representatives, and experienced civil society organisations for environmental impacts.
  • Record whether each submission is a complaint, notification, whistleblowing report, supplier audit issue, stakeholder engagement input, or external mechanism reference.
  • If one webform receives several issue types, route CSDDD complaints and notifications to a due-diligence owner who can connect them to adverse-impact assessment, corrective action, and remediation records.
Section 2

2. Triage the submission into the due-diligence workflow

Triage should answer whether the issue concerns an actual or potential adverse impact, where it sits in the company's own operations, subsidiaries, or chain of activities, and which due-diligence step owns the next action. Article 8 allows companies to use information from the Article 14 notification mechanism and when identifying and assessing adverse impacts.

A well-founded complaint belongs in the due-diligence process, not only in customer service. Article 14 deems the adverse impact identified for Article 8 and requires the company to take appropriate measures under Articles 10, 11, and 12.

  • Capture the affected person, community, worker group, environmental area, business partner, site, product, service, or procurement relationship at issue.
  • Classify the concern as potential impact, actual impact, severe actual or potential impact, retaliation risk, confidentiality risk, or insufficient information.
  • Assign one accountable due-diligence owner and one channel owner; the channel owner protects intake integrity, while the due-diligence owner drives assessment and measures.
  • When the facts are incomplete, document the additional information requested, why it is needed, how confidentiality will be protected, and whether expert input is needed.
Recommended next step

Turn CSDDD grievance handling into an evidence workflow

Map complaint intake, stakeholder engagement, remediation decisions, and monitoring evidence against CSDDD Articles 12, 13, 14, and 15.

Section 3

3. Build stakeholder engagement into the case plan

After Directive (EU) 2026/470, Article 13 requires consultation of relevant stakeholders when gathering information to identify, assess, and prioritise impacts; when developing prevention, corrective, and enhanced action plans; and when adopting Article 12 remediation measures. The amendment removed consultation when deciding on suspension and when developing monitoring indicators from Article 13's mandatory-stage list.

The workflow should identify who must be consulted, what information they need, whether additional information requests can be answered, what barriers or retaliation risks exist, and when experts should be consulted because direct engagement is not reasonably possible.

  • Before assessment: consult relevant affected stakeholders or representatives to understand the actual or potential impact and its severity.
  • Before action planning: test whether proposed prevention, corrective, or enhanced corrective action plans respond to the impact rather than only to contract risk.
  • Before suspension or continued engagement: as a workflow safeguard, record stakeholder consequences and compare likely harms. This is not a retained Article 13 consultation stage, but Articles 10 and 11 require the company to assess whether suspension could cause manifestly more severe impacts.
  • Before remediation: consult on the remedy outcome, implementation constraints, confidentiality needs, and whether the remedy is proportionate to the company's implication.
  • For monitoring: define qualitative or quantitative indicators that can show whether the measure is working and whether the complaint pattern is recurring.
Section 4

Design access for the people most likely to be excluded

Test the mechanism with the people who may need it, including workers, community members, and users outside corporate teams. A web form in one language may be unusable for migrant workers without private phone access, people with disabilities, communities with low connectivity, children, or people who reasonably fear retaliation from an employer, recruiter, security provider, or local authority.

The intake route should let a person raise the concern safely and understand what happens next. Where direct access is impractical, accept submissions through legitimate representatives, trade unions, human rights defenders, civil society organisations, or another trusted channel without forcing the affected person to repeat sensitive facts unnecessarily.

  • Access test: language, literacy, disability access, device and connectivity limits, working hours, location, cost, age, immigration status, confidentiality, and safe follow-up method.
  • Gender-sensitive design: check whether women can submit and meet separately where needed, whether case handlers understand gender-based violence and harassment, and whether compensation or other remedy will reach the affected person.
  • Community and indigenous peoples: record legitimate representatives, collective-rights concerns, cultural and land impacts, safe meeting formats, and any separate consultation or consent standard that may apply.
  • Child-related cases: use age-appropriate information, safeguarding, lawful representative involvement, privacy controls, and a remedy plan centered on the child's interests and safety.
  • Migrant and contracted workers: prevent employer, labour recruiter, dormitory manager, or immigration-status dependence from blocking intake, evidence preservation, translation, meetings, or remedy.
Section 5

4. Decide whether Article 12 remediation is required

Article 12 draws an important boundary. Where the company caused or jointly caused an actual adverse impact, it must provide remediation. Where the impact was caused only by a business partner, the company may provide voluntary remediation and may use its influence to enable the business partner to provide remediation.

This means the case file needs a causation and contribution analysis before the remedy decision. A remedy promise should not be broader than the company's role supports, and a refusal to provide remediation should not ignore the company's ability to influence the partner, corrective action, or stakeholder engagement duties elsewhere in the directive.

  • Record whether the impact was caused by the company, jointly caused with a subsidiary or business partner, or caused only by a business partner.
  • If the company caused or jointly caused the impact, define the remedy outcome, affected persons or environment, implementation owner, evidence of delivery, and monitoring indicator.
  • If only a business partner caused the impact, record whether the company will provide voluntary remediation, use its ability to influence the partner, support corrective action, or escalate through contract and sourcing controls.
  • Keep remediation separate from penalties, civil liability, or supervisory authority orders; those are possible consequences in the directive but are not substitutes for the internal remedy workflow.
Section 6

5. Keep evidence that proves the mechanism works

The evidence record should show that the channel is accessible, that confidentiality and retaliation controls were applied, that well-founded complaints entered the due-diligence process, and that remediation decisions match the company's role in the impact. Amended Article 15 requires assessment without undue delay after a significant change, whenever there are reasonable grounds to doubt that measures remain adequate or effective or to identify new risks, and at least every five years.

Evidence should be case-based enough for an authority, auditor, board committee, or affected stakeholder to understand what happened without exposing identities or sensitive information unnecessarily. Separate the access log from the working case file, restrict identities to staff who need them, and record every disclosure decision so follow-up does not endanger the complainant or notifying person.

  • Channel evidence: public access page, intake form fields, anonymous or confidential reporting options, worker and trade-union communication, language coverage, and accessibility checks.
  • Case evidence: submission date, eligible submitter category, impact classification, scope boundary, triage reasoning, confidentiality restrictions, anti-retaliation steps, and owner assignment.
  • Engagement evidence: consulted stakeholder groups, information shared, additional information requests, written refusals where applicable, barriers identified, expert consultation, and meeting records.
  • Remediation evidence: causation or contribution analysis, remedy decision, affected stakeholder input, delivery records, follow-up response, and monitoring indicator.
  • Closure evidence: reasons for founded or unfounded outcome, steps taken or planned, whether complainants requested follow-up or meetings, and whether the matter was also referred to judicial, supervisory, OECD National Contact Point, or other non-judicial mechanisms.
Section 7

Limits and review gates

A published complaints channel does not prove meaningful stakeholder engagement. A collaborative procedure or mechanism may cover specified Article 14 duties only if it meets Article 14's requirements. An industry or multi-stakeholder initiative may support Article 13 consultation, but it cannot replace consultation with the company's own employees and their representatives.

Stop the case before closure if the file cannot explain the scope boundary, why a complaint was founded or unfounded, how confidentiality was protected, which due-diligence measure was triggered, or why remediation was required, voluntary, enabled through influence over a partner, or not provided.

  • Do not promise every complainant a particular remedy. Article 14 gives complainants rights to request follow-up, meet appropriate company representatives about severe impacts and potential remediation, receive reasons for the outcome, and, for a founded complaint, receive information on steps taken or planned.
  • Do not force affected stakeholders to use the company mechanism before accessing supervisory, judicial, OECD National Contact Point, or other non-judicial routes.
  • Do not use public reporting or supplier attestations as substitutes for case-level assessment, stakeholder consultation, and remediation analysis.
  • Do not publish details that undermine confidentiality, anonymity, worker protection, trade secrets, or the safety of affected persons.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Original legal source for Article 12 remediation, Article 13 stakeholder engagement, Article 14 complaints and notifications, and the former Article 15 monitoring cycle; read with Directive (EU) 2026/470.
"Corporate sustainability due diligence"
eur-lex.europa.eu
Referenced sections
  • Supports the remediation boundary between company-caused or jointly caused impacts and impacts caused only by a business partner.
"Remediation of actual adverse impacts"
eur-lex.europa.eu
Referenced sections
  • Lists the due-diligence stages where consultation must take place and the requirements for information, barriers, confidentiality, and expert consultation.
"Meaningful engagement with stakeholders"
eur-lex.europa.eu
Referenced sections
  • Supports the distinction between complaints, notifications, eligible submitters, confidentiality, non-retaliation, and access to other mechanisms.
"Notification mechanism and complaints procedure"
eur-lex.europa.eu
Referenced sections
  • Supports the limits on collaborative mechanisms, stakeholder consultation, access to other mechanisms, confidentiality, and non-retaliation.
"shall not be a prerequisite"
eur-lex.europa.eu
Referenced sections
  • Supports complaint follow-up rights and reasons for founded or unfounded outcomes; its original annual Article 15 cadence has been replaced by Directive (EU) 2026/470.
"notifications and complaints"
eur-lex.europa.eu
Referenced sections
  • Supports using complaint and notification information for impact identification and treating founded complaints as identified adverse impacts.
"information gathered through the notification mechanism"
eur-lex.europa.eu
Referenced sections
  • Current Article 15 monitoring cadence: significant-change and reasonable-grounds triggers plus an assessment at least every five years.
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD supplier human rights impact scoring template
A CSDDD supplier impact scoring template for Article 8 identification, Article 9 prioritisation, severity, likelihood, stakeholder input, chain-of-activities boundaries, and evidence records.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.