CSDDDTemplateEU

CSDDD supplier human rights impact scoring template

A template for identifying and prioritising supplier-related adverse human rights and environmental impacts under CSDDD Articles 8 and 9.

Use it to separate commercial supplier risk from impacts on people and the environment, then record the evidence and stakeholder input behind each score.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 31, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 31, 2026
Overview

This CSDDD supplier scoring template ranks . Supplier convenience, spend, and contract value do not determine the impact score. Under the amended text in force from 18 March 2026, use only to scope areas across relevant business partners, then apply the template where impacts are most likely and most severe. For in-depth assessment, a company may assess areas involving direct partners first only when several areas are equally likely or equally severe. The legal boundary still includes relevant indirect partners. Each record should describe the activity, affected people or environment, and , evidence, and next due diligence measure.

Section 1

Template scope: supplier activity and chain-of-activities boundary

Start each scoring row by fixing the CSDDD boundary. Article 8 covers the company's own operations, subsidiaries, and business partners where their activities are related to the company's . The directive defines that chain to include upstream activities such as design, extraction, sourcing, manufacture, transport, storage and supply, and downstream distribution, transport and storage when carried out for or on behalf of the company.

Do not score a supplier as high risk merely because it is strategic, expensive, or hard to replace. Score the actual or potential adverse impact linked to a defined activity, site, product, service, sector, geography, or operating context.

  • Supplier record fields: supplier name, or indirect business partner status, site or operating location, product or service, and the specific upstream or downstream activity in scope.
  • Boundary fields: whether the impact arises in own operations, a subsidiary, a direct supplier, an indirect supplier, or another business partner in the .
  • Impact fields: affected right or environmental interest, affected workers or communities, actual or potential impact, and whether the impact may be caused by the company, jointly by the company and a subsidiary or business partner, or only by a business partner in the .
  • Risk-factor fields: sector, product or service, geography, business operation, known complaints, audit findings, independent reports, and notification or complaint mechanism inputs.
Recommended next step

Turn supplier impact scoring into CSDDD evidence

This template helps connect supplier impact records with Article 8 identification, Article 9 prioritisation, stakeholder input, and evidence for follow-up measures.

Section 2

Apply sector and operating-context risk before scoring

Sector examples help identify plausible impacts; they do not create a fixed risk score. Combine sector, geography, product, workforce, business-model, and enterprise evidence, then confirm the specific activity and affected through the Article 8 scoping and in-depth-assessment sequence.

Do not narrow the register to first-tier suppliers. The relevant risk may sit with a mine, farm, labour recruiter, contract factory, data-labeling workforce, warehouse, or other indirect partner whose activity is inside the .

  • Apparel and electronics: screen recruitment fees, forced labour, child labour, excessive hours, wage discrimination, unsafe buildings, freedom of association, gender-based violence or harassment, and purchasing practices that can drive these conditions.
  • Extractives and raw materials: screen worker safety, security-force conduct, land and water impacts, displacement, cultural rights, indigenous peoples, community consultation, tailings or pollution, and the ability to restore environmental harm.
  • Agriculture and food: screen child or forced labour, migrant and seasonal worker conditions, pesticide exposure, water use, land tenure, smallholder dependency, purchasing terms, and barriers to worker or community complaints.
  • Logistics, warehousing, and transport: screen working time, subcontracting, road and workplace safety, migrant labour, freedom of association, and whether the activity is upstream or covered downstream work performed for or on behalf of the company.
  • Technology and services: screen outsourced or platform labour, surveillance and privacy impacts, discrimination, content or data-labelling working conditions, energy and water use, and whether a service-development activity sits inside the upstream boundary.
  • Retail, franchise, and licensing networks: separate the Article 2 scope route from due diligence mapping; assess branded product sourcing, franchisee or licensee operations, logistics, purchasing incentives, complaints, and the actual ability to influence each partner.
  • Regulated financial undertakings: test the entity's own CSDDD scope and upstream operations, but do not place downstream recipients of financial services and products inside the chain-of-activities definition.
Section 3

Record how the impact differs across rightsholders

A generic vulnerable-group flag is not enough. Record which people may be affected, how the impact differs for them, what blocks participation or remedy, and whether the available evidence hides those differences.

The assessment can name indigenous peoples, women, children, persons with disabilities, migrant workers and their families, minorities, human rights defenders, and other context-specific groups where the facts support it. Do not assume that every person in a named group faces the same risk.

  • Disaggregate evidence where lawful and useful, for example by sex, age, worker type, recruitment route, disability, location, shift, contract type, or community, while applying privacy and safety controls.
  • Record barriers such as language, literacy, disability access, distance, digital access, employer or recruiter control, immigration status, retaliation risk, gender norms, childcare, and distrust of company-run channels.
  • For indigenous peoples or other communities with collective rights, record representative legitimacy, land or resource interests, cultural and spiritual impacts, and any separate legal standard that applies to consultation or consent.
  • Test whether a proposed prevention measure or remedy reaches the people most affected. A payment to a household, supplier, or community authority may not reach women, migrant workers, children, or another affected group equitably.
  • Where direct engagement is not reasonably possible, record the legitimate representatives, trade unions, human rights defenders, civil society organisations, independent experts, or credible studies used and the limits of that substitute evidence.
Section 4

Article 8 identification fields

Use Article 8 as the intake structure. First scope broad areas, using only , where are most likely and most severe. Then run an in-depth assessment for the supplier activities, locations, products, or services identified by that scoping exercise.

The evidence column should combine quantitative and qualitative information where available. Request business-partner information only when necessary. For a partner with fewer than 5,000 employees, request it only when the information cannot reasonably be obtained by other means. Supplier questionnaires should not displace credible complaints, worker or trade-union input, independent reports, or other relevant sources.

Article 5 does not require a business partner to disclose trade secrets merely because the company is conducting due diligence. That protection does not prevent disclosure of direct or indirect partner identities or essential information needed to identify impacts when the request is necessary and duly justified. Classified information and information whose disclosure would risk essential state-security interests are never required.

  • General mapping fields: sector risk, country or region context, product or raw-material risk, worker group, community group, known vulnerable group, and whether the risk is systemic or site-specific.
  • In-depth assessment fields: specific allegation or impact scenario, source of the information, affected people or environment, available supplier evidence, whether the information was necessary, alternative sources checked for a smaller partner, gaps in evidence, and confidence level.
  • Information-request fields: purpose, necessity, alternative sources checked, essential information needed to identify the impact, trade-secret safeguard, state-security restriction, response, and unresolved gap.
  • Stakeholder input fields: consulted workers, worker representatives, trade unions, community representatives, civil society sources, human rights or environmental institutions, and any barriers to direct consultation.
  • Supplier evidence fields: policies, code-of-conduct acceptance, payroll or working-time evidence, recruitment fee controls, grievance logs, corrective action status, audit or verification results, and evidence freshness.
Section 5

Article 9 scoring rubric: severity before convenience

Article 9 prioritisation applies when it is not feasible to address every identified impact at the same time and to the full extent. The score should therefore rank impacts by and , then show which impacts will move first into prevention, mitigation, corrective action, remediation, or monitoring.

The CSDDD does not prescribe a numeric scoring scale or a formula that combines and . If the company uses numbers, define each level and require a written reason. Each row should explain who may be harmed, the nature, scale, scope, and irremediable character of the harm, how likely the impact is, and which evidence would change the assessment. For example, credible forced-labour indicators or a risk of fatal exposure can require high-severity escalation even where the supplier is low-spend or the affected group is small. The case evidence controls the final score.

  • score: assess scale, scope, and irremediable character, including gravity, number of people affected or potentially affected, environmental extent, irreversibility, and limits on restoration within a reasonable period.
  • score: assess supplier activity, geography, sector, product, workforce model, complaints, independent reports, prior incidents, and strength or weakness of supplier controls.
  • Priority result: use and together and state how uncertainty affects the decision. A limited ability to influence the supplier is not a reason to reduce the assessed impact.
  • Review trigger: rescore after a credible complaint, worker or community input, audit finding, material supplier change, new sourcing geography, or evidence that mitigation is not working.
Section 6

Output columns for action, evidence, and stakeholder follow-up

The completed template should produce an impact register. Each high-priority row needs a linked due diligence action: prevention or mitigation for potential impacts, corrective action for actual impacts, remediation where the company caused or jointly caused an actual impact, and stakeholder engagement at the Article 13 stages relevant to the row.

Before using suspension as an output, record why the specified measures are insufficient, whether governing law permits suspension, whether an enhanced plan can reasonably be expected to succeed, and whether suspension could cause manifestly more severe impacts. Mandatory termination was removed in 2026. Keep notice, impact-mitigation, monitoring, and review evidence attached to the impact row. Rescore without undue delay after a significant change and whenever a complaint, verification result, or other evidence gives reasonable grounds to believe a control is ineffective or a new impact may arise; the five-year Article 15 cycle is only the maximum regular interval.

  • Action fields: prevention plan, mitigation measure, corrective action plan, supplier support, contractual assurance, verification measure, remediation route, enhanced plan, or suspension review.
  • Owner fields: procurement owner, human rights or sustainability owner, legal reviewer, supplier contact, stakeholder-engagement owner, and approval route for high- impacts.
  • Stakeholder follow-up fields: consultation date, groups consulted, information shared, additional information requested, response given, unresolved concerns, and protection against retaliation or access barriers.
  • Evidence fields: source, date, document owner, evidence type, affected stakeholder signal, supplier response, verification status, next review trigger, and the reason for any unresolved evidence gap.
Primary sources

References and citations

eur-lex.europa.eu
Referenced sections
  • Binding current amendment for CSDDD scope, due diligence, monitoring, enforcement, and status changes discussed on this page.
Related guides

Explore more topics

CSDDD adverse impact prioritisation workflow
A CSDDD workflow for identifying actual and potential adverse human rights and environmental impacts, ranking severity and likelihood, and documenting prevention, mitigation, remediation, and stakeholder evidence.
CSDDD Applicability Test After 2026 Changes
Test CSDDD scope after Directive (EU) 2026/470 using the current EU and third-country thresholds, parent-company rules, exclusions, dates, and evidence.
CSDDD chain of activities and supplier due diligence
Explain CSDDD chain-of-activities scope, upstream and downstream boundaries, subsidiaries, direct and indirect business partners, supplier risk segmentation, and evidence.
CSDDD Chain of Activities Boundaries
Define CSDDD upstream and downstream chain of activities boundaries for subsidiaries, direct and indirect business partners, distribution, transport, storage, and records.
CSDDD chain of activities boundaries: upstream and downstream FAQ
FAQ on how the CSDDD defines chain of activities boundaries for subsidiaries, direct and indirect business partners, upstream activities, downstream logistics, and evidence.
CSDDD complaints and notifications FAQ
FAQ on Article 14 CSDDD complaint and notification mechanisms, who may complain, follow-up rights, confidentiality, retaliation, and evidence.
CSDDD compliance duties and evidence guide
A source-backed CSDDD compliance guide covering due diligence policy, impact scoping, prevention, corrective action, complaints, monitoring, reporting, climate-plan status, and supervisory evidence.
CSDDD contractual assurances FAQ for Articles 10 and 11
How CSDDD Articles 10 and 11 use contractual assurances with business partners, verification, SME support, action plans, and possible suspension escalation.
CSDDD Deadlines After Directive 2026/470
Current CSDDD calendar: 2027-2028 guidance, 2028 transposition, 2029 application, 2030 reporting, 2031 ESAP submission and review.
CSDDD due diligence checklist
A source-backed CSDDD checklist for scope, risk scoping, impact prioritisation, action plans, complaints, monitoring, communication, evidence, and the removed climate-plan duty.
CSDDD Due Diligence Steps Playbook for Articles 5 and 7-16
A playbook using current CSDDD provisions for policy integration, impact assessment, prioritisation, prevention, correction, remediation, stakeholder engagement, complaints, monitoring, communication, and evidence.
CSDDD FAQ: scope, dates, duties, liability, and evidence
Practical answers on CSDDD scope, current application dates, chain of activities, due diligence duties, complaints, remediation, civil liability, climate plans, and evidence.
CSDDD grievance and remediation workflow guide
Build a CSDDD grievance, notification, stakeholder engagement, and remediation workflow under Directive (EU) 2024/1760 as amended by Directive (EU) 2026/470.
CSDDD Liability and Enforcement After 2026
Understand CSDDD supervision, national penalties, substantiated concerns, remedial orders, and civil-liability analysis after Directive (EU) 2026/470.
CSDDD Non-EU Scope and 2029 Start
Test third-country CSDDD scope using the amended EUR 1.5 billion EU-turnover route and one 26 July 2029 application date.
CSDDD Penalties After Directive 2026/470
Current CSDDD penalty guidance after the EU 5% rule was replaced by a uniform 3% maximum limit: national sanctions, authority decisions, evidence, and country-by-country monitoring.
CSDDD prevention vs mitigation: potential and actual adverse impacts
CSDDD FAQ on when to prevent or mitigate potential adverse impacts, when to end or minimise actual adverse impacts, and what evidence records to keep.
CSDDD remediation FAQ: when companies must remedy adverse impacts
FAQ on CSDDD remediation: when Article 12 requires remedy, how complaints and stakeholder engagement affect the response, and what evidence to keep.
CSDDD Remediation Plan Template: Article 12, 13 and 14 evidence
A CSDDD remediation plan template for actual adverse impacts, complaint inputs, stakeholder engagement, action records, and monitoring under the Directive as amended in 2026.
CSDDD requirements: scope, due diligence, climate plan, and evidence
A source-backed map of current CSDDD requirements across scope, due diligence policy, impact assessment, complaints, remediation, monitoring, communication, and the removed climate-plan duty.
CSDDD risk prioritisation FAQ: severity, likelihood, and evidence
How to prioritise CSDDD adverse impacts when teams cannot address everything at once, using severity, likelihood, stakeholder evidence, and a reviewable rationale.
CSDDD Scope Thresholds After 2026
Understand amended CSDDD thresholds for EU and non-EU companies, group scope, exclusions, two-year evidence, and the 2029 application date.
CSDDD Supplier Contract Clause Review Workflow
Review supplier contract clauses against CSDDD Articles 10 and 11: contractual assurances, verification, SME fairness, support, action plans, and escalation evidence.
CSDDD Supplier Contract Clauses: Articles 10 and 11 Evidence
How to use CSDDD supplier contract clauses without treating clauses as a substitute for due diligence: contractual assurances, verification, SME support, action plans, limits, and evidence.
CSDDD vs CSRD: Due Diligence and Reporting Compared
Compare CSDDD due diligence duties with CSRD sustainability reporting, including scope, timing, Article 16 reporting, evidence overlap, assurance, and enforcement.
CSDDD vs German LkSG Comparison
Compare the EU CSDDD with Germany's LkSG without mixing directive duties, national-law duties, chain boundaries, complaints, reporting, and enforcement routes.
CSDDD vs OECD Guidelines
Compare the binding EU CSDDD with the OECD Guidelines for responsible business conduct across scope, due diligence duties, business relationships, remediation, and evidence.
Did CSDDD Keep Its Climate Plan Duty?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty. Understand what changed and which separate obligations may remain.
Does CSDDD Still Have Scope Waves?
No separate company scope waves remain after Directive (EU) 2026/470: transposition is due in 2028 and all companies remaining in scope apply from 2029.
Does Franchising Trigger CSDDD Scope?
Directive (EU) 2026/470 retained the CSDDD franchise and licensing scope route but raised its royalty and turnover thresholds. Learn the current test.
How CSDDD overlaps with OECD, UNGP, and ILO standards
FAQ on how OECD responsible business conduct guidance, the UN Guiding Principles, and ILO labour standards inform CSDDD due diligence without being the same legal instrument.
How Does CSDDD Civil Liability Work Now?
Directive (EU) 2026/470 removed the uniform EU liability test but retained compensation and procedural safeguards. Claims still depend on Member State law.
Is a Climate Plan Still Required by CSDDD?
Directive (EU) 2026/470 removed the standalone CSDDD Article 22 climate-transition-plan duty; separate CSRD and national obligations need their own review.
What Did Omnibus Change in CSDDD?
CSDDD Omnibus status as of July 2026: what Directives (EU) 2025/794 and 2026/470 adopted, which dates apply, and which old duties were removed.
What EU Turnover Triggers CSDDD Scope?
A third-country company generally needs more than EUR 1.5 billion net turnover in the EU under Directive (EU) 2026/470; learn the evidence and timing.