← Back to CSDDD Insights
CSDDD third-party verification, industry initiatives and supplier audits as compliance evidence

Can an Industry Scheme or Supplier Audit Prove CSDDD Compliance? What Third-Party Verification Will and Won't Cover

Most large companies already lean on supplier audits and industry schemes to show they look after their supply chains. The CSDDD does not throw that out, but it does put a question mark over how much weight those tools can carry. The Commission's consultation on the CSDDD guidelines, open from mid-June to 24 July 2026, lists third-party verification and the fitness of industry initiatives among its seven topic areas, with the final guidelines expected in Q1 2027.

What the Commission is asking

According to Covington's summary of the consultation, the seven areas are impact assessment and prioritisation, contractual frameworks and model clauses, remediation, disengagement, third-party verification and industry initiatives (including fitness criteria), conflict-affected areas, and enforcement and penalties. The guidelines are meant to operationalise the directive ahead of its application date. For the wider picture, see our article on why the guidelines are where compliance is decided.

The principle that will not change

The directive lets companies use industry schemes and independent verification to support their due diligence, but responsibility stays with the company. A certificate is evidence, not a defence. That has three practical implications.

First, scope. A scheme covers the sites, topics and tiers it was designed for. Your risk map, built under Article 8, may reach further.

Second, quality. Audits are periodic snapshots, often announced, and are known to miss issues such as forced labour indicators and worker voice. A clean report is weaker evidence than one that includes worker interviews and follow-up on findings.

Third, independence. Who paid for the audit, who accredits the auditor and how conflicts are managed will all matter once fitness criteria are published.

How to assess a scheme now

Because the criteria are not yet final, build your own test and be ready to adjust:

  • Coverage: which human rights and environmental impacts, sites and tiers does the scheme cover, and how do they map to your prioritised risks?
  • Method: does it use unannounced visits, worker interviews and grievance channels, or only document review?
  • Independence: is the verifier accredited, and free from commercial ties to the audited party?
  • Follow-through: does the scheme require corrective action plans with deadlines and re-verification?
  • Transparency: are results and methodology available to you, and to affected stakeholders?
  • Gaps: what is left uncovered, and how will you close it yourself?

Document the outcome. If the guidelines later set fitness criteria, a dated assessment shows you were applying a reasoned standard.

Link to contracts and remediation

Verification results should feed your supplier contracts and remediation plans. Our piece on contractual assurances explains why cascading a code of conduct is not enough, and the same logic applies to relying on a single audit.

What we do not know yet

The guidelines have not been published, and the consultation material does not settle what the fitness criteria will be. Treat any claim that a specific scheme "guarantees" CSDDD compliance with scepticism. Watch for the Commission's draft in the coming months.

FAQ

Does an industry scheme certificate satisfy the CSDDD? No scheme certificate replaces your own risk-based due diligence. It can support it.

Should we stop using social audits? No. Use them as one input, and complement them with worker voice, grievance data and site engagement.

When will criteria be clear? The Commission plans to adopt the guidelines in Q1 2027.

Sources: Covington: European Commission Seeks Public Input on CSDDD Guidelines.

This article is general information, not legal advice. Verify legal provisions against the text of Directive (EU) 2024/1760 as amended.