Skip to main content
Promotional banner for the pentest readiness checklist
CSDDD Non-Compliance: What the First Penalties Will Look LikeThird-Party Risk Management
5 min readFor Risk Managers

CSDDD Non-Compliance: What the First Penalties Will Look Like

The EU's Corporate Sustainability Due Diligence Directive (CSDDD) hasn't seen its first enforcement case yet, with compliance deadlines set for 2027. However, you can anticipate potential failure modes now.

This isn't guesswork. The CSDDD's March 2024 text outlines specific obligations, liability triggers, and penalty structures. When an organization faces a 5% fine of its net worldwide turnover, the breakdown will follow a predictable pattern. Here's what that might look like.

Understanding the Directive's Requirements

The CSDDD imposes four key obligations:

  1. Due diligence on direct operations: Identify and address environmental and human rights risks in your activities.
  2. Supply chain accountability: Extend risk identification and mitigation to your business partners.
  3. Remediation when harm occurs: Take corrective action if your negligence causes environmental damage or labor abuses.
  4. Liability for third-party violations: Accept responsibility when a covered supplier or partner causes harm through actions you failed to prevent.

The directive applies to EU companies with over 1,000 employees and €450 million in global revenue. Non-EU companies face the same obligations if they generated over €450 million within the EU market annually over the past two years.

Phase-in periods range from three to five years based on company size, giving larger organizations less time to establish the required controls.

Anticipating Failure Scenarios

The directive's language suggests three likely failure scenarios:

Scenario one: Inadequate supply chain visibility

Imagine an organization that maintains vendor risk profiles for Tier 1 suppliers but lacks structured processes for sub-tier visibility. A Tier 2 manufacturer in the supply chain commits labor violations. The organization claims ignorance of the sub-tier relationship.

Under CSDDD, that defense doesn't hold. The directive requires you to identify risks "in the chain of activities." If your due diligence stops at direct contractual relationships, you've created a control gap.

Scenario two: Risk identification without mitigation

Your team conducts an annual supplier assessment, flagging environmental risks at a key manufacturing partner. You document the finding but take no corrective action because switching suppliers would disrupt production timelines.

The CSDDD mandates that you "prevent potential adverse impacts" and "bring actual adverse impacts to an end." Documentation without remediation creates liability.

Scenario three: Reactive response after harm occurs

An environmental incident at a supplier facility causes measurable damage. Your organization learns about it through media coverage, not through your monitoring program. You initiate an investigation only after regulators contact you.

The directive's liability provisions activate when your negligence causes harm. If you lacked the monitoring controls to detect the incident promptly, you've established the negligence element.

Control Failures and Standard Requirements

Map these scenarios to specific control deficiencies:

Missing: Ongoing Vendor Monitoring

ISO 37301 (Compliance Management Systems) requires organizations to "establish, implement and maintain processes to monitor, measure, analyze and evaluate compliance performance." For CSDDD, this means continuous monitoring of supply chain risks, not annual questionnaires.

The control gap: Your vendor risk profile contains last year's assessment data, but you have no automated alerts for adverse media, no quarterly check-ins on labor practices, and no mechanism to detect changes in sub-tier relationships.

Missing: Defined Impact Tolerance

The CSDDD requires you to prevent adverse impacts "that should be prevented." This implies you've defined what level of risk is unacceptable. If you haven't documented impact tolerance thresholds for environmental and human rights risks, you can't demonstrate you had a decision framework.

The control gap: Your risk universe includes "supply chain sustainability risk" as a category, but you haven't set quantitative or qualitative thresholds that trigger mandatory remediation.

Missing: Remediation of Deficiencies Process

When your assessment identifies a violation, you need a documented process for corrective action. ISO 31000 (Risk Management) requires treatment plans for identified risks. The CSDDD makes those plans mandatory, not discretionary.

The control gap: Your vendor assessment report lists findings, but there's no workflow that automatically generates remediation tasks, assigns owners, or tracks completion. The findings sit in a spreadsheet.

What EU Member State Enforcement Will Target

Member states must designate enforcement authorities with the power to impose fines of up to 5% of net worldwide turnover. These authorities will need to prove three elements:

  1. You had an obligation under the directive.
  2. You failed to meet that obligation.
  3. The failure caused or contributed to harm.

The easiest cases to prosecute will involve documented control gaps. If your audit trail shows you identified a risk but took no action, you've created the evidence file. If your vendor risk profiles haven't been updated in 18 months, you've demonstrated inadequate monitoring.

The financial sector faces particular exposure. The March 2024 revision removed lower employee thresholds for high-risk industries, but financial institutions remain subject to the regulation with few exceptions. If you're extending credit to manufacturers or logistics providers, you're now responsible for their supply chain practices.

Action Items for Your Team

Before 2027:

  • Build a data processing register that maps your supply chain relationships beyond Tier 1. You need visibility into sub-tier dependencies where environmental and labor risks concentrate.

  • Define impact tolerance thresholds for sustainability risks. Document what level of environmental impact or labor practice violation triggers mandatory remediation versus monitoring.

  • Implement ongoing vendor monitoring that includes adverse media screening, regulatory violation checks, and periodic assessments. Annual questionnaires won't satisfy the directive's "ongoing" language.

  • Create a remediation workflow that automatically generates tasks when assessments identify violations. The workflow should assign ownership, set deadlines, and track completion.

  • Update your vendor contracts to include CSDDD compliance obligations and audit rights. You'll need contractual leverage to require corrective action from suppliers.

Review your current state:

Pull your most recent vendor risk assessment. How many findings remain open without assigned remediation plans? That's your current liability exposure. The CSDDD converts those open findings from risk management issues into regulatory violations with defined penalties.

The directive's liability provisions extend to third parties not in scope making claims against organizations in scope. That means a labor organization or environmental group can bring a case even if the harmed party can't. Your control gaps have an expanded audience.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like