Skip to content

Supply Chain

How to Answer a CSDDD Supplier Due Diligence Request

If you've noticed your customers' procurement questionnaires getting longer and more demanding, you're not imagining it. That's the CSDDD effect: large companies subject to the Corporate Sustainability Due Diligence Directive need data from every supplier in their chain of activities — including you, regardless of your size.

Here's the thing most suppliers miss: responding well to these questionnaires isn't just about keeping the customer happy. It's a competitive advantage. Suppliers who answer in days instead of weeks, who have their data organised and accessible, consistently rank higher in procurement evaluations.

CSDDD: EU Corporate Due Diligence Rules

The CSDDD (Directive 2024/1760, also called CS3D) is the regulation that turns voluntary ESG commitments into legal obligations with teeth. If your company has >1,000 employees or >€450M turnover, you're legally required to identify, prevent, and remediate human rights and environmental harms in your supply chain — and if you don't, you can be sued.

It closes a gap that's existed for decades: companies could talk about ethical supply chains without any legal framework forcing them to actually do something about problems they found. CSDDD changes that.

EU Deforestation Regulation (EUDR): Enforcement

The EU Deforestation Regulation (2023/1115) is in full enforcement, and it's already reshaping global supply chains. If you deal in cattle, cocoa, coffee, oil palm, rubber, soya, or wood, you need a Due Diligence Statement for every shipment — backed by geolocation coordinates down to the plot level. No exceptions, no phase-ins for small operators.

Most companies underestimate how hard the geolocation requirement is. Your supplier in Côte d'Ivoire needs to provide plot-level GPS coordinates that match satellite imagery. If they can't, your shipment doesn't clear customs.

German Supply Chain Act (LkSG) Compliance Software

If you've got 1,000+ employees in Germany, the LkSG already applies to you — and BAFA isn't messing around. Fines can hit €8 million or 2% of annual turnover, and the seven due diligence obligations (§4–§10) cover everything from risk analysis to complaints procedures to annual BAFA reporting.

Here's the thing: LkSG compliance isn't a one-time project. It's an annual cycle of risk analysis, preventive measures, documentation, and reporting. LkSG compliance software won't replace the human rights expertise you need, but it'll stop you from drowning in paperwork while BAFA asks for your records.

What to Ask Suppliers Before They Get You Fined

If your supplier uses forced labor, the goods are seized at the US border — and you are the importer of record. If your supplier discharges untreated wastewater, your CSRD disclosure is inaccurate, your CSDDD due diligence is incomplete, and your buyer drops you. If your supplier's SMETA audit is expired by six weeks, the procurement system deselects you automatically — and the buyer does not ask why. The legal violation is the supplier's. The commercial and legal consequence is yours.

The regulatory frameworks that impose cascading liability — making a buyer legally responsible for what happens in their supply chain — are multiplying globally. The German Supply Chain Act (LkSG), the EU's CSDDD, the US Uyghur Forced Labor Prevention Act (UFLPA), the UK and Australian Modern Slavery Acts, the Canadian Fighting Against Forced Labour and Child Labour in Supply Chains Act — each of these creates a legal obligation for the buyer to know what is happening in their supply chain and to act on what they find. And each of them starts with the same operational question: what do you ask your suppliers — and what documentation do you demand — before you place the order?

Conflict Minerals: Automate 3TG Due Diligence

Conflict minerals regulations in both the US (Dodd-Frank Section 1502) and the EU (Regulation 2017/821) require companies to trace the sourcing of tin, tantalum, tungsten, and gold (3TG) through their supply chains, conduct due diligence, and file compliant disclosures. With supply chains spanning multiple tiers and continents, manual CMRT collection and verification is error-prone and resource-intensive.

Conflict minerals software automates the collection of Conflict Minerals Reporting Templates (CMRTs), conducts reasonable country of origin inquiries (RCOI), and generates compliant disclosures for SEC and EU filing.

Conflict Minerals (3TG) Compliance

Tin, tantalum, tungsten, and gold — collectively known as 3TG — are present in nearly every electronic product, from the solder on circuit boards to the capacitors in power supplies, from the tungsten vibration motors in smartphones to the gold contact pads in connectors.

But these four metals have a dark side. In certain regions — most notably the Democratic Republic of Congo (DRC) and adjoining countries — the extraction and trade of 3TG minerals has financed armed conflict, enabled forced labor, and caused severe human rights abuses. In response, legislators in the United States and the European Union have created mandatory supply chain due diligence regimes designed to break the link between mineral extraction and conflict financing.

If your product contains tin, tantalum, tungsten, or gold — and if your company is publicly traded in the US or imports these minerals into the EU — you have legal obligations to trace your supply chain, assess risks, and publicly report your findings.

How to Verify a Supplier Certificate

Every manufacturer relies on supplier certificates. A Global Recycled Standard (GRS) certificate proves your recycled content. An FSC certificate validates your wood sourcing. An Oeko-Tex certificate confirms your textiles are free of harmful substances. An ISO 14001 certificate demonstrates your supplier's environmental management credentials.

But here is the uncomfortable truth: not every certificate your supplier sends you is genuine. Certificates can be expired, forged, altered, or simply issued to a different legal entity than the one selling you materials. If your compliance audit file contains a fraudulent certificate, the liability falls on you — not on the supplier who sent it. Market surveillance authorities, customs agencies, and retail buyers hold the importer or manufacturer responsible for verifying their supply chain evidence.

This guide shows you how to independently verify the authenticity of the most common supplier certificates, spot the red flags, and build an audit file that withstands scrutiny.

How to Share an ISO 14001 Certificate

Your company earned ISO 14001 certification. The audit was rigorous. The environmental management system is real. The certificate is valid.

Now every customer, every buyer, and every procurement questionnaire asks you to prove it. And every time, you email the same PDF.

The certificate lives in a folder on your shared drive. It gets attached to emails, forwarded to procurement teams, uploaded to supplier portals, printed for the office wall. Somewhere along the way, someone forwards an expired version. Someone else asks "is this the current one?" Someone prints it and pins it to a corkboard where it fades in the sun.

This is not how a world-class certification should be shared. Here's how to fix it.

EUDR Compliance: Due Diligence & Key Deadlines

In 2025, Dutch authorities conducted pilot inspections across 20 operators and found widespread shortcomings in due diligence documentation. Dry runs led by German, Belgian, Dutch, and French regulators confirmed that authorities expect a complete "paper trail" for each specific shipment — not just a general due diligence system on paper. Rotterdam, Europe's largest port, is now a regulatory checkpoint where shipments without verified geolocation data can be stopped.

A cocoa importer we onboarded last quarter had their entire shipment flagged at Rotterdam port. The problem wasn't that their supply chain was deforestation-linked — it was that they couldn't produce the geolocation data fast enough. On the Sustalium platform, we see this pattern repeat across commodities: the legal burden is on the importer, not the supplier.

The EU Deforestation Regulation (EUDR — Regulation [EU] 2023/1115) is now fully enforced. Unlike voluntary sustainability pledges, it makes it a criminal offense to import commodities produced on land deforested or degraded after December 31, 2020. The burden of proof is entirely on your business.