Embedding Responsible Business Conduct under the CSDDD
The EU Corporate Sustainability Due Diligence Directive (CSDDD) requires in-scope companies to carry out risk-based human rights and environmental due diligence in their own operations and those of their subsidiaries and business partners in their chains of activities.
Due diligence requirements
Companies are expected to follow a risk-based and proportionate approach to due diligence. This involves identifying areas where adverse impacts on people are most likely to occur and could be most severe, assessing these impacts in greater detail and taking appropriate measures to prevent, mitigate and address potential and actual adverse impacts.
Key requirements include:
- Risk identification and assessment: Companies should begin with a scoping exercise using reasonably available information to identify areas of higher risk to people. More in-depth assessments should then be carried out for operations, subsidiaries and both direct and indirect business partners in their value chain where human rights and environmental risks are considered most significant.
- Monitoring and reporting: Companies must monitor the effectiveness of their due diligence measures at least every five years, with additional assessments where circumstances change or new risks emerge. Annual public reporting on due diligence activities is also expected.
- Liability and enforcement: Businesses may face liability at national level for failures to comply with the requirements, including potential fines of up to 3% of net worldwide turnover.
GoodCorporation supports companies in designing, implementing and strengthening their human rights and environmental due diligence processes
CSDDD scope and obligations
The CSDDD applies to an estimated 6,000 EU companies and 900 non-EU companies including:
- EU companies with + 5,000 employees and EUR 1.5bn in turnover
- Non-EU companies with EUR 1.5bn turnover generated in the EU
The CSDDD is now in its transposition window – the period during which EU Member States must incorporate the Directive into national law – following amendments introduced by the Omnibus I Directive, which entered into force on 18 March 2026. The European Commission recently held a public consultation (which closed on 24 July 2026) to help shape its implementation guidelines.
Key dates to watch out for
26 July 2027: EU Commission must publish guidelines to support companies in complying with due diligence obligations
26 July 2029: Enforcement date – CSDDD obligations in force for in-scope companies – no phased approach
26 July 2028: Member state transposition deadline
1 January 2030: Annual due dligence statements must now be published for financial years beginning on or after this date
31 March 2029: EU Commission must adopt delegated acts on the content and criteria for annual statement reporting
26 July 2031:Â EU Commission starts 5-yearly reviews of implementation and effectiveness
Six-step approach to CSDDD due diligence
The CSDDD follows a structured sequence that aligns with the UNGPs and OECD Guidelines.
1: Integrate due diligence: embed due diligence within corporate policies, governance structures, and risk management systems.
2: Identify and assess adverse impacts: conduct a two-step scoping and in-depth assessment process to identify and evaluate the areas in an organisation’s own operations and those of subsidiaries and business partners in the value chain where adverse impacts are most likely to occur and be most severe.
3: Prevent, mitigate, or end adverse impacts: take appropriate measures to address potential and actual impacts.
4: Provide for or cooperate in remediation: participate in or appropriately support efforts to remediate adverse impacts
5. Monitor implementation and progress: periodically assess the implementation of actions and check that measures remain adequate and effective.
6. Communicate on your due diligence activities: publicly report on the measures taken to adequately manage human rights and environmental impacts.
Key components of due diligence best practice
Stakeholder engagement: Meaningfully engage with relevant stakeholders throughout the due diligence process, including those who may be adversely affected and their legitimate representatives.
Grievances and complaints: Establish effective systems for raising concerns and complaints about actual or potential adverse impacts. Grievance mechanisms can also help identify impacts and support access to remediation.
GoodCorporation’s
CSDDD services
GoodCorporation offers expertise in the management of human rights and environmental impacts with a range of services to help companies prepare for and implement the CSDDD. These services include:
Policies, systems and processes: development and integration of human rights and environmental due diligence policies, systems and processes
Identification and assessment of adverse impacts: saliency assessments, supply chain risk assessments, human rights impact assessments, stakeholder engagement, worker welfare assessments, desktop assessments, pre-engagement due diligence, responsible exit assessments and environmental due diligence
Monitoring and KPIs: development of meaningful KPIs and monitoring frameworks to track the implementation and effectiveness of due diligence measures
Action planning and implementation: development, implementation and monitoring of prioritised action plans across the organisation, suppliers and specific value chains as part of continuous improvement
Grievance and complaints mechanisms: development of effective procedures in line with the UNGPs effectiveness criteria, including appropriate escalation pathways
Reporting and disclosure: support for human rights due diligence reporting, including drafting reports based on assessment findings and stakeholder consultation
Human rights and environmental due diligence framework
The GoodCorporation Framework on Human rights and Environmental Due Diligence is used by companies looking to prepare for and comply with the EU Corporate Sustainability Due Diligence Directive (CSDDD). It provides a set of responsible business principles which can help organisations to improve the robustness of their management practices in order to identify, prevent, mitigate and remediate their human rights and environmental impacts across their operations and value chains.
Our framework draws directly on the measures set out in the CSDDD and follows its structure, while also incorporating best practice and international guidelines. It can be used to ensure compliance with the law, which will minimise an organisation’s potential liability for the fines, penalties and compensation available under the CSDDD.
Use our framework as the basis of an analysis against CSDDD requirements, or to identify any gaps in human rights and environmental due diligence processes and procedures. Aligned with international human rights best practice, the framework is used by companies looking to develop and implement robust human rights and environmental due diligence.
How to prepare for the CSDDD
Although the implementation deadline has been extended to July 2029, organisations should begin preparing now. Designing an effective human rights and environmental due diligence programme, developing methodologies and embedding processes across the business can take considerable time.
Steps to achieve this should include:
Designing and testing your scoping methodology
Conducting a gap analysis against the requirements of the legislation
Developing risk assessment methodologies (for own operations and supply chain)
Establishing stakeholder engagement processes
Reviewing grievance mechanisms and its escalation processes
Preparing for reporting and communication requirements, including by developing meaningful KPIs
Related news and insights
Frequently asked questions
The Omnibus I Directive introduced a number of important changes to the original CSDDD, including:
- reducing the number of companies in scope;
- postponing the application of the due diligence obligations until July 2029;
- replacing the phased implementation timetable with a single application date;
- Implementing a specific two-stage scoping and assessment process requiring a scoping exercise based on reasonably available information followed by in-depth assessment of any high or severe risks identified
- extending the monitoring cycle so that companies review the effectiveness of their due diligence measures at least every five years; and
- simplifying certain reporting and administrative requirements.
The Directive’s core requirement to conduct human rights and environmental due diligence remains unchanged.
The CSDDD and the CSRD are complementary but have different objectives. The CSRD is a reporting regime, requiring companies within its scope to disclose information on sustainability-related risks, impacts and performance. The CSDDD is a conduct and governance regime, requiring companies within its scope to undertake due diligence to identify and address adverse human rights and environmental impacts and integrate these processes into their policies and risk management systems.
The two frameworks also interact. The CSRD value chain cap limits the sustainability information that companies can require from smaller value chain partners for reporting purposes, but does not restrict information requests made for CSDDD due diligence. Following the Omnibus I amendments, CSDDD requirements will apply from 26 July 2029, while CSRD reporting requirements apply on different timelines depending on the company concerned.
In simple terms, the CSRD focuses on what companies report, while the CSDDD focuses on how they identify and address adverse impacts.
The CSDDD applies across both the upstream and downstream parts of a company’s chain of activities. This means due diligence is not limited to direct business partners. Companies are required to identify and address adverse human rights and environmental impacts that may occur further along the value chain.
The upstream chain includes activities related to the production of goods or provision of services, such as the sourcing of raw materials, manufacturing, transport and supply. The downstream chain covers the distribution, transport and storage of a company’s products where these activities are carried out for or on behalf of the company, subject to certain exclusions.
No. Following the amendments introduced by the Omnibus I Directive, the CSDDD no longer requires companies to adopt or implement a climate transition plan.
However, companies that are subject to the Corporate Sustainability Reporting Directive (CSRD) may still be required to disclose information about their climate transition plans under the European Sustainability Reporting Standards (ESRS). In practice, many companies will therefore continue to develop and maintain transition plans to meet investor expectations, support decarbonisation strategies and comply with other reporting requirements.
The requirement to conduct human rights and environmental due diligence under the CSDDD remains separate from climate transition planning and climate-related disclosures.
A risk-based approach means that companies are not expected to approach every part of their operations and chain of activities in the same level of detail. Instead, companies should use reasonably available information to identify where adverse impacts are most likely to occur and be most severe and prioritise those areas for further assessment and action.
The focus is therefore on prioritising salient risks and directing resources to where they are most needed.
Yes, potentially.
The CSDDD applies to non-EU companies that generate more than EUR 1.5 billion turnover in the EU, regardless of where they are headquartered. Some UK-headquartered businesses may therefore fall directly within scope.
In addition, UK companies that are not directly in scope may still be affected because customers that are subject to the CSDDD may request information or require certain standards and contractual commitments from their suppliers and business partners.
Companies should be able to demonstrate that they have implemented an effective due diligence process and taken appropriate measures in response to identified risks.
Evidence may include:
- governance arrangements and policies,
- scoping methodologies and risk assessments,
- in-depth impact assessments for higher-risk areas,
- records of meaningful stakeholder engagement,
- action plans and remediation measures,
- progress and impact measurement
- grievance procedures escalation and handling records,
- monitoring activities; and
- internal documentation supporting annual due diligence reporting.
Maintaining clear documentation and audit trails will be essential.
Suppliers and other business partners may play an important role in providing information about potential human rights and environmental impacts and in supporting mitigation and remediation efforts.
Companies are expected to engage with business partners where risks have been identified and may require information, cooperation and corrective action from suppliers as part of their due diligence processes.
Businesses that are not directly in scope of the CSDDD may nevertheless receive requests for information from customers that are subject to the Directive.
Contact Us
Whether you have a question, need more information about our services, or would like to explore how we can help your business, please get in touch.