Quick summary: EUDR competent authority checks look beyond a DDS reference number: inspectors review the due diligence records, plot geolocation and deforestation evidence an operator can produce, alongside cocoa shipments loaded for export.
EUDR competent authority checks are a central part of how the European Union will verify that relevant commodities and products meet the requirements of the EU Deforestation Regulation (EUDR). For businesses sourcing or trading cattle, cocoa, coffee, oil palm, rubber, soya, wood and covered derived products, compliance cannot stop at submitting a Due Diligence Statement (DDS). Companies need to be able to show how they assessed risk, verified plot-level information, documented supply chains and addressed any identified risk.
Articles 16, 18 and 19 explain how competent authorities select checks and what they may examine. Understanding these provisions helps operators, downstream operators and traders prepare reliable evidence before a request or inspection arrives.
Under Article 16 of Regulation (EU) 2023/1115, each EU Member State designates competent authorities to check whether relevant businesses and products comply with the Regulation. Checks can cover products already placed or made available on the EU market, products intended for the market, and relevant products intended for export.
Authorities follow a risk-based approach rather than selecting every business in the same way. They assess potential non-compliance using factors such as commodity type, supply-chain length and complexity, product processing, mixing of materials, proximity of production plots to forests, country or regional risk classification, previous non-compliance, possible circumvention and other relevant information. Data submitted under the EUDR and information in the EU information system can support this analysis.
In practical terms, businesses should assume that authorities may look beyond a DDS reference number. They may examine whether the underlying data and due diligence process are complete, consistent and supported by evidence.
Learn how Competent Authorities oversee EUDR compliance, conduct checks, and verify the evidence operators and traders must maintain.
Understand the Role of EUDR Competent Authorities
Article 16 sets minimum annual check targets linked to the risk classification of the country or part of a country where the relevant commodities were produced. Under the consolidated text cited below, the minimum targets are:
These targets are not a guarantee that a particular company will or will not be checked. Targets are calculated separately for each relevant commodity, using the previous year’s activity and, where applicable, product quantities. Authorities can also initiate checks when they receive relevant information indicating potential non-compliance, including substantiated concerns submitted by third parties.
The percentages above summarise Article 16 of the consolidated EUDR text available on EUR-Lex. Businesses should confirm the version applicable to their operations and monitor subsequent amendments or official guidance.
Want to understand EUDR Country Risk Classification? Read our blog to learn how country risk benchmarks affect due diligence requirements and what operators and traders need to know to prepare for compliance.
For operators, Article 18 requires authorities to examine the due diligence system and the records that demonstrate it is functioning properly. This includes the company’s risk assessment and risk mitigation procedures. Authorities also examine records showing that specific relevant products comply with the EUDR, including the relevant DDS and evidence supporting any mitigation measures.
Depending on the findings, checks may go further. Authorities may conduct on-the-ground examinations of commodities or products, review corrective measures, use technical or scientific methods to identify a commodity or production location, and examine whether products are deforestation-free using Earth-observation data. Field audits may also be used where appropriate, including in third countries where cooperation with the relevant administration is agreed.
For a company, this means that a defensible compliance file should connect the product placed on the market to its source plots, supplier information, production and transaction records, risk assessment, mitigation evidence and DDS. Data should be traceable across the chain and should not contradict the information submitted to the EU information system.
Article 19, as set out in the relevant text, focuses on documentation and records demonstrating that downstream operators and traders meet their applicable obligations under Article 5. Where initial document checks raise questions, authorities may also conduct spot checks, including field audits.
The exact obligations depend on the business’s role, size and position in the supply chain, as well as the version of the Regulation that applies. Companies should therefore map their legal role for each product and transaction rather than assume that the same due diligence duties apply to every participant.
Downstream businesses should maintain records that allow them to identify relevant suppliers and customers, connect products to the appropriate DDS information where required, and respond promptly to requests from authorities or business partners.
Discover the EUDR obligations for downstream operators, how they differ from other supply chain actors, and what businesses need to know to maintain compliance.

Yes. Article 16 provides that checks are carried out without prior warning, unless notifying the operator, downstream operator or trader is necessary to make the check effective. Businesses should therefore keep records organised and accessible as part of normal operations, not assemble them only after receiving a notice.
Competent authorities must record the nature and results of checks and measures taken in cases of non-compliance. Article 16 states that these records must be retained for at least 10 years and that records and reports are environmental information that may be made available upon request under the applicable rules.
A practical readiness process should focus on evidence quality, consistency and the ability to retrieve records quickly.
A digital compliance workflow can help centralise these records and flag gaps earlier. Technology does not transfer the legal responsibility away from the business, and a software-generated output is not by itself proof of compliance. The underlying data, controls and decisions still need to be accurate and supportable.
Learn how to streamline supplier data collection, geolocation verification, deforestation risk assessment, and risk mitigation to strengthen your EUDR compliance process.
TraceX EUDR Solutions is designed to help businesses organise EUDR compliance workflows, including supplier onboarding, plot-level geolocation management, deforestation-risk checks, risk assessment and mitigation documentation, and DDS-related processes. Bringing these elements into a connected workflow can make it easier to identify missing evidence, maintain traceability between suppliers and products, and prepare a consistent compliance file.
For teams managing large supplier networks or multiple sourcing regions, a structured digital process can reduce reliance on disconnected spreadsheets and email trails. The value comes from improving visibility and evidence management not from assuming that any platform can guarantee a favourable inspection outcome.
No. Authorities may examine the due diligence system, risk assessment and mitigation procedures, supporting records and product-level evidence. Depending on the circumstances, they may also use technical methods, satellite or Earth-observation information, on-the-ground examinations and field audits.
No. Article 16 sets a minimum annual check target for low-risk sourcing, and authorities may still check a business when relevant information indicates potential non-compliance or circumvention.
Article 16(14) says competent authorities must retain records of their checks for at least 10 years. Separately, businesses should apply the recordkeeping requirements that specifically govern their own EUDR obligations and other applicable laws.