Quick summary: Supply chain due diligence made audit-ready: see what EUDR, CSDDD and the Forced Labour Regulation require, the 6-step process, and how software closes gaps.
Supply chain due diligence is the ongoing process of identifying, preventing and documenting human rights, environmental and legality risks across every tier of your suppliers. EUDR, CSDDD, the EU Forced Labour Regulation and national laws such as Germany’s LkSG now require companies to prove that process with records, not policies.
Supply chain due diligence used to mean a supplier code of conduct and an annual audit sample. Regulators now expect a documented, risk-based process that reaches past Tier 1 suppliers and produces evidence on request.
Supply chain due diligence is a structured, repeatable process for finding and addressing risks linked to your suppliers, from deforestation and illegal harvesting to forced labour and unsafe working conditions.
Most laws build on the OECD Due Diligence Guidance for Responsible Business Conduct, so supply chain due diligence follows the same logic in every regime. Companies are expected to:
Several regimes now overlap, each with its own scope and evidence standard.
The practical effect is that one supply chain due diligence program has to satisfy several authorities at once.
| Regulation | Applies from | What it expects |
|---|---|---|
| EUDR, Reg. (EU) 2023/1115 as amended by 2025/2650 | 30 Dec 2026 (large/medium); 30 Jun 2027 (micro/small) | Plot geolocation, deforestation-free and legality evidence, risk assessment, due diligence statement |
| CSDDD, Directive (EU) 2024/1760 as amended by 2026/470 | 26 Jul 2029 (transposition by 26 Jul 2028) | Risk-based human rights and environmental due diligence for EU firms over 5,000 staff and EUR 1.5bn turnover |
| Forced Labour Regulation (EU) 2024/3015 | 14 Dec 2027 | Market ban on forced-labour products; traceability helps defend products in investigations |
| EU Battery Regulation (EU) 2023/1542 | Due diligence 18 Aug 2027 | Raw material due diligence for cobalt, lithium, nickel and natural graphite |
| Germany LkSG | In force since 2023 | Risk analysis, prevention and documentation; BAFA reporting being abolished |
| US UFLPA | In force since June 2022 | Presumption that goods linked to Xinjiang involve forced labour unless rebutted |
Even if your company sits below the CSDDD thresholds, your largest customers do not. Expect their supply chain due diligence requests to reach you first.
EUDR and the Corporate Sustainability Due Diligence Directive (CSDDD) address different aspects of responsible business conduct, from deforestation-free sourcing to identifying and addressing human rights and environmental impacts across value chains. Discover their key differences, overlapping requirements, and how businesses can strengthen compliance processes through better supply-chain visibility, risk assessment, and traceability.
[Read our complete guide to EUDR and CSDDD →]
An audit-ready process moves from mapping to evidence in six repeatable steps.
A global tire manufacturer applied this model to natural rubber, combining remote-sensing risk assessment, geolocation traceability and integration with the EU Information System to support supply chain due diligence for EUDR.
EUDR due diligence requires businesses to collect accurate supply-chain information, verify geolocation data, assess deforestation and legality risks, and take appropriate mitigation measures. Discover the key steps, documentation requirements, and digital solutions that can help your business strengthen EUDR readiness and improve supply-chain transparency.
[Read our complete guide to EUDR Due Diligence →]

Most supply chain due diligence failures trace back to five avoidable habits.
Each gap turns an authority request or customer audit into days of manual work, and under EUDR can mean a blocked shipment and penalties.
Due diligence works when it runs inside daily sourcing, not as a year-end exercise. When supplier onboarding, field data, risk scoring and documentation live in one system, the answer to any regulator or customer request already exists. The TraceX platform is built on that principle, and TraceX EUDR Solutions applies it to EUDR due diligence statements,
Manual processes can record due diligence; they struggle to prove it at scale.
| Capability | Manual (spreadsheets, email) | TraceX platform |
|---|---|---|
| Multi-tier supplier mapping | Tier 1 only, static lists | Suppliers linked to sites, plots and lots |
| Risk assessment | Annual questionnaire review | Automated scoring with satellite and country risk data |
| Evidence collection | Chasing files by email | Supplier and field app capture with validation |
| Monitoring | Periodic audits | Alerts for expired documents and new risk signals |
| Reporting | Days of manual assembly | Audit-ready reports and EUDR DDS workflows |
Moving supply chain due diligence onto a platform shortens response times, reduces audit preparation and gives procurement teams a defensible basis for sourcing decisions
Evaluate vendors on the evidence they produce, not the dashboards they show.
A platform that meets all seven gives you supply chain due diligence you can defend in front of any authority.
Supply chain due diligence is the ongoing process of identifying, preventing and documenting human rights, environmental and legality risks linked to your suppliers.
Key regimes include EUDR, CSDDD, the EU Forced Labour Regulation, the EU Battery Regulation, Germany’s LkSG and the US UFLPA.
After Omnibus I, CSDDD applies from 26 July 2029 to EU companies with more than 5,000 employees and over EUR 1.5 billion turnover, and non-EU firms with over EUR 1.5 billion EU turnover.
Indirectly, yes. In-scope customers will request data and commitments from business partners, although Omnibus I limits how much they can ask of smaller companies.
No. Certifications support risk mitigation, but EUDR still requires plot geolocation, legality evidence and a due diligence statement for each placement.
Continuously. Risk data, documents and supplier status change, so monitoring should run year-round with formal reviews at least annually or when risks change.
Multi-tier mapping, geolocation validation, risk scoring, mitigation tracking, document management, ERP integration and audit-ready reporting.