Skip to main content
Due Diligence Policy Template for CSDD Supply Chain ComplianceSustainability and ESG
6 min readFor CISOs

Due Diligence Policy Template for CSDD Supply Chain Compliance

The Corporate Sustainability Due Diligence Directive mandates that organizations systematically identify, prevent, and mitigate environmental and human rights risks across their operations and supply chains. If your organization is an EU company with 500+ employees and €150 million turnover, or a non-EU company generating €150 million within the EU, you need a documented due diligence policy that meets the Directive's five core requirements.

This template provides a policy framework you can adapt to your organization's scope and risk profile. It's designed for organizations subject to the CSDD published on February 23, 2022, and addresses the directive's requirements for risk identification, mitigation, public reporting, and grievance mechanisms.

Purpose of This Template

Use this policy to:

  • Document your organization's commitment to human rights and environmental due diligence across your value chain.
  • Define roles and responsibilities for conducting supplier assessments.
  • Establish procedures for site visits, policy reviews, and regulatory compliance checks.
  • Create audit trails that demonstrate compliance during supervisory authority reviews.
  • Provide a foundation for your annual sustainability reporting obligations.

This is an operational policy for your procurement, compliance, and sustainability teams to reference when screening suppliers, conducting audits, and responding to identified risks.

Prerequisites

Before customizing this template, ensure you have:

  • Threshold determination: Verified that your organization meets the CSDD employee count and turnover thresholds, including the 50% high-impact sector calculation if applicable.
  • Value chain mapping: Identified your tier-one suppliers and any subsidiaries whose operations fall under your due diligence obligations.
  • Risk taxonomy: Defined what constitutes environmental and human rights risks in your specific industry context.
  • Supervisory authority contact: Identified which national authority will enforce the CSDD in your primary EU operating jurisdiction.
  • Existing grievance channels: Reviewed your current reporting mechanisms to determine gaps.

The Template


CORPORATE SUSTAINABILITY DUE DILIGENCE POLICY
Effective Date: [Insert date]
Policy Owner: [Chief Compliance Officer / Chief Sustainability Officer]
Review Cycle: Annual

1. Purpose and Scope

This policy establishes [Organization Name]'s approach to identifying, preventing, and mitigating environmental and human rights risks in accordance with the Corporate Sustainability Due Diligence Directive.

Scope: This policy applies to:

  • All operations of [Organization Name] and its subsidiaries.
  • Business relationships with suppliers, contractors, and value chain entities where we have established commercial relationships.
  • [Specify geographic scope: EU operations / global operations]

2. Due Diligence Procedures

2.1 Risk Identification

We conduct due diligence through:

  • Supplier questionnaires: Annual assessment of environmental policies, labor practices, and regulatory compliance history.
  • Site visits: On-site inspections of [specify: tier-one suppliers / high-risk suppliers / suppliers in designated sectors] to verify working conditions, environmental controls, and health and safety systems.
  • Document review: Examination of supplier policies addressing anti-slavery regulations, environmental permits, and human rights commitments.
  • Regulatory compliance checks: Verification of supplier adherence to applicable environmental and labor laws, including review of past incidents and remediation actions.

2.2 Risk Assessment Criteria

Suppliers are evaluated against:

  • Compliance with anti-slavery and forced labor prohibitions.
  • Working conditions meeting health and safety standards.
  • Environmental impact management (waste disposal, emissions, resource use).
  • Presence of functional grievance mechanisms for workers.
  • History of regulatory violations or sanctions.
  • Operations in high-risk geographies or sectors.

3. Risk Mitigation

When due diligence identifies environmental or human rights risks, we will:

  • Engage with suppliers: Communicate identified concerns and establish corrective action timelines.
  • Develop mitigation plans: Document specific steps the supplier must take, including policy updates, operational changes, or third-party audits.
  • Monitor progress: Conduct follow-up reviews at [specify frequency: 90 days / 6 months] to verify implementation.
  • Escalate or terminate: Suspend or end relationships with suppliers who fail to remediate within agreed timelines.

4. Public Reporting

We will publish an annual sustainability report containing:

  • Summary of due diligence activities conducted.
  • Material environmental and human rights risks identified.
  • Mitigation actions taken and their outcomes.
  • Metrics on supplier assessments completed.
  • Information on grievances received and resolved.

This report will be available on [Organization Name]'s website by [specify date: March 31 following each fiscal year].

5. Grievance Mechanisms

5.1 Reporting Channels

Workers and stakeholders may raise environmental or human rights concerns through:

  • Confidential hotline: [Insert number]
  • Email: [Insert address]
  • Online portal: [Insert URL]
  • Direct contact with [specify role: compliance officer / sustainability manager]

5.2 Investigation Process

All reports will be:

  • Acknowledged within [specify: 3 business days].
  • Assigned to an investigator within [specify: 5 business days].
  • Investigated according to [reference existing investigation policy].
  • Resolved with documented outcomes within [specify: 30 days for standard cases / 60 days for complex cases].

6. Business Continuity Planning

6.1 Supplier Dependency Assessment

We maintain a register of key suppliers whose disruption would materially impact operations, including:

  • Alternative supplier identification.
  • Inventory buffer requirements.
  • Communication protocols for supply chain disruptions.

6.2 Contingency Activation

When a supplier relationship is suspended or terminated due to CSDD non-compliance, we will:

  • Activate pre-identified alternative suppliers.
  • Implement inventory management protocols.
  • Communicate timeline and impact to affected business units.

7. Roles and Responsibilities

  • [Chief Compliance Officer]: Policy oversight, supervisory authority liaison, annual reporting.
  • [Procurement Director]: Supplier screening, site visit coordination, contract terms.
  • [Sustainability Manager]: Risk assessment methodology, mitigation plan development, public disclosure.
  • [Internal Audit]: Policy compliance verification, procedure effectiveness review.

8. Policy Review

This policy will be reviewed annually and updated to reflect:

  • Changes to CSDD requirements or guidance from supervisory authorities.
  • Lessons learned from due diligence activities.
  • Emerging environmental and human rights risk areas.
  • Feedback from stakeholders and grievance mechanisms.

Customization Instructions

Section 1 (Scope): Replace bracketed placeholders with your organization's legal name, subsidiary structure, and geographic footprint. If you operate in high-impact sectors, explicitly list those operations.

Section 2.1 (Risk Identification): Adjust the frequency and depth of site visits based on your supplier count and risk profile. Organizations with many suppliers may tier their approach.

Section 2.2 (Risk Assessment Criteria): Add industry-specific risks. For textiles, include forced labor in cotton sourcing. For mineral extraction, add artisanal mining and conflict minerals.

Section 3 (Risk Mitigation): Define your escalation thresholds. Specify who has authority to suspend supplier relationships.

Section 4 (Public Reporting): Align your reporting timeline with your fiscal year and existing sustainability disclosure calendar. Cross-reference the Corporate Sustainability Reporting Directive if applicable.

Section 5 (Grievance Mechanisms): Insert your actual hotline number, email address, and investigation timelines. Establish these channels if they don't exist.

Section 6 (Business Continuity): Tailor supplier dependency criteria to your operations. A manufacturer might focus on raw material suppliers; a retailer might prioritize logistics partners.

Section 7 (Roles): Match these to your organization chart. Adjust roles as needed for your organization's size.

Validation Steps

Before implementing this policy:

  1. Legal review: Have counsel confirm the policy addresses all five CSDD requirements and aligns with your national transposition of the directive.

  2. Stakeholder input: Circulate the draft to procurement, operations, legal, and sustainability teams to catch operational conflicts.

  3. Board approval: Present the policy to your board or governance committee, focusing on public reporting and supplier termination authority.

  4. System alignment: Verify that your procurement systems can capture the data this policy requires.

  5. Training plan: Train the teams responsible for executing the policy. Ensure procurement understands risk assessment criteria and compliance knows grievance investigation procedures.

  6. Dry run: Pilot the policy with a subset of suppliers before full rollout. Adjust based on findings.

Once the policy is live, your first annual review should assess whether the procedures are being followed. Update the policy to reflect achievable commitments if necessary.

You Might Also Like