NON PAPER: Observations on effective public supervision under the Corporate Sustainability Due Diligence Directive (CSDDD)

Authors

Nicola Bonucci is the former Director of Legal Affairs at the OECD. He is an associate professor of international law at the University of Paris Cité and works as an international expert for various international organisations.  He is the co-author of the report Human Rights and Competitiveness – Reframing the Business Case for Human Rights commissioned by the Council of Europe in October 2025.

Axel Marx is Deputy Director Leuven Centre for Global Governance Studies, an interdisciplinary research centre at KU Leuven. He is currently also the co-chair of the Academic Advisory Council of the United Nations Forum on Sustainability Standards, a member of the Evidensia Advisory Council and a member of the Jean Monnet Centre of Excellence on Business and Human Rights at FECAP Business School (Brazil). His research interests include inter alia multi-stakeholder initiatives and corporate social responsibility.

Martijn Scheltema is partner at Pels Rijcken (the Netherlands) and chair of the Business Human Rights practice group of his firm. He also is professor at Erasmus University Rotterdam. Beyond this, he holds several international positions amongst which co-chair of the European Working Group for (CSDDD aligned) Model Clauses in supply chains as well as co-chair of the Business Human Rights Lawyers Association. He is the former chair of the Business Human Rights Committee of the International Bar Association and currently member of its advisory board.

 

Table of contents

1. Introduction

2. Independence, budget and capacity

2.1         Legal independence

2.2         Functional independence

2.3         Institutional design

2.4         Adequate human and financial resources

2.5         Advisory boards

3. Effective supervision and CSDDD scope

4. Guidance and capacity building

5. Collaboration at the European level

6. Collaboration at member state level

7. Effective supervision and good practice

8. Sanctions

 

Acknowledgement: The authors thank Michaela Streibelt, Maren Leifker, Kristel Tonstad and Daniel Schönfelder for comments on a previous draft and the participants of the CSDDD-network webinar on supervisory authorities. The CSDDD Network exists to support the effective transposition, application and enforcement of the CSDDD, and of related sustainability due diligence laws, in a manner that delivers meaningful protection for human rights and the environment and is implementable by companies. To this end, the Network brings together business and human rights (BHR) professionals from academia and practice to exchange experience and discuss challenges in the implementation of HREDD and related legislation. The Network aims to include members from all EU Member States and beyond, and to contribute to the development of robust and practical HREDD approaches, including by informing policy debates and monitoring relevant legislative developments in other regions. The Network’s core activity consists of monthly virtual meetings, each dedicated to a specific topic related to the practical application of HREDD or related legislation, with contributions from members and invited external experts.

 

1.   Introduction

Articles 24-28 of the CSDDD[1] provide for public supervision regarding compliance by national supervisory authorities.

Leaving this to each EU member state entails a real risk of fragmentation, despite the foreseen establishment of a European network in charge of coordinating the national supervisory authorities.

Thus, it would be highly advisable to organize early discussions between EU members with a view to assess and coordinate on common challenges such as:

  • budget, independence and capacity of supervisors,
  • effective supervision, bearing in mind that some member states have no or very few in scope companies, dealing with representatives of non-EU in scope companies,
  • role of rightsholder representatives and advisory boards,
  • role of guidance of supervisory authorities and capacity building (with companies),
  • effective collaboration (also between national supervisors of other regulations such as EU Deforestation-free products (EU DR) , Batteries Regulation (BR), Forced Labour Regulation (FLR), as well as European coordination of this),
  • how to prevent ‘tick box’ compliance and role of Multi-stakeholder Initiatives (MSIs), as well as
  • sanctions, including orders to provide remedy.

It is helpful to establish collaboration at the European level in an early stage. If this is postponed until the CSDDD comes into force, supervisors may have developed their own strategies and approaches, and it may be harder to align those once established.

These challenges will be briefly addressed in this Non paper and could further elaborated at request of supervisors or other decision makers.

2.   Independence, budget and capacity

Articles 24 section 9 and 25 section 1 of CSDDD require supervisory authorities to be independent and availing over a sufficient budget. Article 24(9) specifically refers to such independence as being both legal and functional. The requirements under the CSDDD are quite clear and ought to be followed.

The overall EU approach to the question of administrative independence is not, however, easy to read. For example, the EUDR only requires functional independence (Article 14(4) EUDR) while the EUFLR does not refer to the terms legal or functional independence but requires the authority to exercise its powers impartially, transparently and with due respect for obligations of professional secrecy, necessary powers and resources to carry out the investigations, including sufficient budgetary and other resources (Article 12(5) FLR). In addition, neither the Conflict Minerals Regulation nor the Battery Regulation set forth any requirement in relation to the independence of competent authorities.[2]

2.1       Legal independence

Strictly speaking legal independence would mean that the National Supervisory Authority (NSA) would require a separate legal personality.

This may be problematic in certain countries. Indeed, to date not all existing NSAs are independent from regulators such as Ministries.[3] Supervisory authorities in other member states, such as the Netherlands, are fully independent.[4] This different starting point may bear consequences on the institutional design as highlighted below.

2.2       Functional independence

Functional independence is understood as meaning that the NSA shall not and cannot seek nor take instructions from any other public or private entity. This principle is captured by paragraph 75 of the recitals which specifically provides that ‘[i]n order to exercise their powers impartially, these supervisory authorities should neither seek nor take instructions from anybody.’[5]

Both forms of independence are equally important and should be aimed at. However, the functional independence is paramount – whatever the form and status of the NSA – and shall be clearly established in the texts transposing the Directive.

It can also be important to link the question of independence to the institutional design described below. In some countries the existing NSA that would be the best “fit” for the CSDDD may not be seen as legal independent while an existing legally independent NSA may not be compatible, in terms of substance, within the mandate and scope of the CSDDD NSA.

2.3       Institutional design

Institutional design of the NSA provided for in Article 24 is key and should be carefully considered. Indeed, once the NSA is established (most probably by law) it will be quite difficult to amend and improve its structure unless this possibility is explicitly provided for in the law establishing it (review clause). Three design choices for a NSA are possible:

  • a new dedicated NSA
  • integration in an existing NSA
  • dispatching the mandate of the proposed NSA in several existing NSAs

Early indications show that option (i), even though an ideal one, is not really considered within EU members. Also for EU member states that would have only a handful or no companies under the direct scope of the CSDDD this would make little sense. This non paper is therefore focused on options ii and iii.

Integration in an existing NSA has the advantage of being simple and clear. Its effectiveness is however very much dependent on several factors: institutional coherence between the NSA’s existing and expanded mandate, adequate level of additional human and financial resources, and image and reputation of the existing NSA.

Dispatching the mandate of the proposed CSDDD NSA in several existing NSAs may allow for a more tailored approach but presents a number of institutional challenges and will inevitably lead to a complex decision-making system. Hence, this option should not be considered.

A further question is whether one authority should be given the mandate to supervise all EU human rights due diligence related laws in addition to the CSDDD, such as the Deforestation Regulation (EUDR), Batteries Regulation (BR) and Forced Labour Regulation (FLR). Although one supervisory authority may be helpful to acquire knowledge in all these fields and to implement uniform approaches as much as possible, it may not be an option to establish this one entity, whereas the other indicated regulations may already be attributed to other authorities. As a result, multiple supervisors will be involved in due diligence supervision. With multiple supervisors it is important that they collaborate, which will be discussed later.

2.4       Adequate human and financial resources

Legal and functional independence will be empty words if no concrete and verifiable action is undertaken in terms of both human and financial resources.

Adequate budget is pivotal and required by Article 25(1). Failing a sufficient budget, supervision may become illusive or only superficial. In this regard, authorities determining this budget should bear in mind that budget will also be required for collaboration with other supervisors (on the European and national level) and that stakeholders may file substantiated concerns based on Article 26 CSDDD, which require budget as well. Obviously, supervisory authorities cannot supervise everything, but the budget should be sufficient to implement a risk-based approach, which is able to address at least severe adverse impacts. Hence, the budget should be sufficient to allow supervisory authorities to prioritise their efforts effectively (possibly with a limited budget).

Adequate human resources and skills are equally pivotal. Whatever the institution option is chosen the NSA should have a mix of skills including persons with a legal, investigation and forensic background as well as auditing and accounting but also persons with expertise on environment and human rights particular at the company level. This can be complemented with experts from existing institutions such as national human rights institutions and/or EU agencies.

In connection with independence, it is also relevant that supervisory authorities may build capacity within the business community and not only sanction non-compliance. It is important that these functions are clearly separated and NSA staff involved in capacity building should operate autonomously from those in charge of investigations and sanctions. This may be a challenge for smaller supervisory authorities.

A related human resources issue is hiring personnel from business with human rights and environmental expertise by supervisory authorities in order to build relevant capacity. This may be a challenge both in terms of financial attractiveness but also because revolving doors should be carefully framed.

2.5       Advisory boards

Some supervisory authorities, like the German BAFA, have established an advisory board, which provides guidance on implementation questions for the authority. This guidance does not need to be implemented by the authority and builds capacity on substantive issues relevant to the supervisor. The advisory board of BAFA includes members with different backgrounds, such as NGO’s, trade unions, human rights institutions, academia and business. Such an advisory board is a form of stakeholder engagement, which is very relevant for the supervisory authorities to better understand the field they are supervising and receive feedback regarding the practicality of their outputs, such as guidelines and other guidance activities. Although an advisory board may perform a helpful role in this, it is important to prevent regulatory capture of the supervisor, which may challenge independence. Therefore, advisory boards should be balanced in terms of membership by different affected stakeholders.

3.   Effective supervision and CSDDD scope

An issue related to the current scope of the CSDDD is that several member states only have very few or even no companies in scope. This makes effective supervision a challenge, because it is very likely that no separate supervisory authority is established or appointed in such member states, but that supervision will be part of the functions of existing supervisory authorities and a limited budget may be available. This may impact supervision of the (few) in scope companies in this member state and may create an unlevel playing field with companies based in other member states supervised by larger supervisory authorities which implement more thorough supervision. This issue may partially be addressed by involving supervisory authorities in other member states, for example in those in which subsidiaries are based which may support supervision of the authority in the member state with few or no in scope companies. That said, this has budgetary implications and member states may not be inclined to allocate budget for supervisory functions which originate from insufficient budget of authorities in other member states. The European network of supervisory authorities (Article 28) could play a role as well, but it remains to be seen whether it has budgeted for such assistance. It would be advisable to create some budget for this, also in order to create a more level playing field.

A related issue is supervision of non-EU companies with no in scope subsidiaries in the EU. Pursuant to Article 24 section 3 CSDDD such companies are supervised by the authority in the member state in which they have a branch. Failing such a branch, they have to appoint a representative, generally speaking based in the member state in which their turnover is largest. The branch or representative may be located in a member state in which no of very few in scope EU companies are based and this generates supervisory challenges and potentially an unlevel playing field. Moreover, such non-EU companies having appointed a representative may act strategically by filing a motion to change the supervisory authority as Article 24 section 3 CSDDD provides for to a member state in which supervision appears to be most lenient. Furthermore, it is conceivable that a company makes its business out of representing non-EU companies (like trusted companies do in other matters). This may hamper effective supervision as such a representative is less likely to have sufficient knowledge and information of the represented company’s performance regarding human rights due diligence as required by the CSDDD.

4.   Guidance and capacity building

The term ‘guidance’ may be ambiguous to a certain extent. It may include formal guidance (as the European Commission will issue based on Articles 18 and 19 CSDDD), identification of best practices and practical advice.[6] The term ‘guidance’ is hereinunder used for formal guidance. Regarding the German supply chain law, the German supervisor on the German Supply Chain act (Federal Office for Economic Affairs and Export Control (BAFA)) issued (formal) guidance. Such guidance of the supervisor can be important to steer business and may change corporate strategies quite rapidly, where necessary.

The European Commission will issue guidance based on Articles 18 and 19 CSDDD before July 2027. This guidance is likely to be of a more general nature from the outset but may develop in more sector specific guidance over time. European Commission guidance should not reinvent the wheel and build, to the extent the CSDDD does not deviate from these frameworks, on the existing guidance of the UNGPs and OECD Guidelines. It would also be helpful if the European Commission also provides guidance on the interplay between the different European instruments including human rights due diligence, such as the EUDR, BR and FLR. If companies are allowed to implement a comparable approach for all these regulations, this may reduce administrative burdens and may enhance compliance. This guidance should emphasize that human rights and environmental due diligence is not only about building (management) processes and checking whether, for example, training is in place and how many times these are given, audits are undertaken, contractual clauses in supply chains are included in procurement and refer to human rights and environmental obligations, and whether a grievance mechanism is in place. Conversely, it should be outcome oriented, especially focusing on outcomes for rightsholders and the environment. Thus, it could provide guidance on meaningful stakeholder engagement and how it should be conducted, the content of contractual clauses in supply chain contracts, including responsible purchasing practices, how to establish effective grievance mechanisms and regarding effectiveness of multi-stakeholder initiatives in order to assist companies in choosing effective multi-stakeholder initiatives. The guidance could also explain how best practices in specific sectors or regarding specific human rights or environmental issues are relevant and can be identified, as well as how multi-stakeholder mechanisms or certification may play a role in this. It would be helpful if supervisory authorities would not develop guidance on these topics themselves, also to maintain a level playing field. In terms of practical advice to companies this guidance of the European Commission seems less well fit. For this the European Helpdesk as envisaged in Article 21 CSDDD is better positioned.[7]

A further question is whether only the European Commission should provide such guidance or supervisory authorities may do so as well. As a starting point, it would be preferable if only the European Commission provides guidance in order to enhance uniformity and a level playing field and to streamline supervision in the Union as well as to prevent diverging supervisory approaches in member states. That said, it may be conceivable that member state supervisors develop guidance preluding to guidance of the European Commission, for example if a particular issue is of particular relevance for a member state. The European network can play an important role in a harmonized interpretation of the European Commission’s guidance in member states and exchanges on monitoring of CSDDD compliance, including the Commission’s guidance.

In connection with this it is important that guidance is sufficiently specific. This requires sufficient capacity with the European Commission and member state supervisors. It is advisable to engage with relevant stakeholders (including Global South representatives and governments) when developing such guidance. Budgetary constraints may hamper development of such guidance and collaboration with external parties, such as relevant and effective multi-stakeholder initiatives, may be considered as suggested in Article 8(3) CSDDD on risk identification. In this context it is important that supervisory authorities receive guidance on which MSIs can be considered credible in the context of CSDDD and which are not credible. This is important since there are few hundred MSIs which vary significantly in terms of credibility. Setting up a European level recognition system to benchmark MSIs with due diligence fitness criteria is advisable. This can follow and built on initiatives developed by the OECD. That said, regulatory capture has to be prevented in this regard.

In addition to providing (sector-specific) guidance, supervisory authorities may build capacity with individual companies to a certain extent, although the European helpdesk as envisaged in Article 21 CSDDD or member state authorities supporting implementation of the CSDDD are better positioned for this. In this regard supervisory authorities could, for example, implement benchmarks of company performance building on best practices in certain sectors. However, capacity building should not be an important function of the supervisory authorities, also to prevent regulatory capture.

5.   Collaboration at the European level

Whereas the companies governed by the CSDDD are very large and are likely to operate in several member states, collaboration between supervisory authorities is necessary. Article 24 section 4, 25 section 6(b) and 28 (European network) CSDDD provide for this. The European Commission will be in the lead establishing the European network. Such collaboration is pivotal to create a level playing field and to prevent unnecessary administrative burdens for companies if supervisory authorities replicate supervision by other authorities. A collaborative approach is relevant, for example to:

  • determine which authority is in the lead and how other authorities may support,
  • prioritize which human rights and environmental risks will be addressed by the supervisory authorities on the European level,
  • coherently interpret and align interpretation of the CSDDD and European Commission guidance,
  • determine relevance and credibility criteria of multi-stakeholder initiatives (MSIs) or industry initiatives (and criteria to determine their effectiveness, e.g. as developed by the OECD, recognition of MSIs operating in other fields, such as EUDR, BR or FLR) aligned with the criteria which should be developed by the Commission (Article 20(4)),
  • deal with representatives of non-EU companies (e.g. how to secure access to information of the represented company, which criteria are used to assess requests to change the supervisory authority and requiring bank guarantees of representatives in order to secure payment of potential fines),
  • develop protocols for collaboration, align policies of supervisors in member states and exchange effective interventions by supervisory authorities and information,
  • develop effective and coherent supervisory strategies, e.g. based on good/best practice in specific sectors,
  • support of supervisors in member states with no of few in scope companies,
  • assess non-compliance, especially outside the EU (e.g. which level of proof is required),
  • coordinate standards for burden of proof,
  • align sanctions,
  • coordinate with European Commission regarding investigations outside the EU and engagement with Global South stakeholders,
  • enhance aligned supervisory approaches regarding other regulations such as Corporate Sustainability Reporting Directive, the Sustainable Finance Disclosure Regulation, the Deforestation Regulation, the Batteries Regulation and the Forced Labour regulation at the European (coordinate with other European networks of supervisors (if any)) and member state level,
  • develop a common understanding with competition authorities what type of collaboration in the context of HREEDD is permitted,
  • coordinate with the European helpdesk as referred to in Article 21 CSDDD, and
  • coherently and in an aligned fashion, in collaboration with the European Commission respond to CSDDD ‘blocking’ laws stemming from jurisdictions outside the EU.

The collaboration in the European network may be further elaborated building on experience gained in other fields, such as for example consumer law. This may eventually lead to regulation on such collaboration, as has been developed, for example, in the field of consumer law.[8]

It is helpful to establish collaboration at the European level in an early stage. If this is postponed until the CSDDD comes into force, supervisors may have developed their own strategies and approaches, and it may be harder to align those once established.

Finally, it is important that collaboration is sought between European and national networks or supervisors supervising other due diligence laws, such as Corporate Sustainability Reporting Directive, the Sustainable Finance Disclosure Regulation, the Deforestation Regulation, the Batteries Regulation and the Forced Labour regulation, if these regulations are not supervised by one authority.

6.   Collaboration at member state level

Collaboration of supervisory authorities at member state level may not so much regard the CSDDD, although this may be relevant where public supervision is split between a general and an authority in the financial sector, but the different regulations relating to due diligence and reporting, such as the Corporate Sustainability Reporting Directive, the Conflict Minerals Regulation, the Sustainable Finance Disclosure Regulation, the Deforestation Regulation, the Batteries Regulation, and the Forced Labour regulation. In most member states other supervisory authorities will be involved in this. Customs may seem a somewhat unusual regulator in this context, but it plays a role because goods that are brought on the European market when the market actor does not comply with the Deforestation Regulation or the Forced Labour Regulation may be seized at the border, or the export of such goods from the Union can be stopped.

For the effectiveness of the supervision of the aforementioned regulations, it is important that the supervisory authorities collaborate to impose as uniform requirements as possible on companies and to communicate as consistent expectations as possible regarding due diligence. In any case, different supervisory authorities imposing conflicting requirements in the area of due diligence and/or communicating conflicting expectations should be prevented. It is conceivable that good/best practices could be identified in a particular sector and used by all supervisory authorities in their supervision. Furthermore, cooperation appears relevant to ensure the efficient use of the regulators’ limited resources and to prevent unnecessary duplication of effort. This promotes a consistent approach towards this company and saves both the company and the regulators effort and administrative burdens.

Naturally, such cooperation between supervisory authorities is subject to certain conditions. For instance, supervisory information cannot simply be exchanged; there must be proper coordination and prioritization between supervisory authorities (whereby one supervisory authority does not determine the priorities for the other), knowledge transfer and exchange regarding the applicable regulations must take place, and a potential mandate must be granted with proper feedback to the mandating supervisory authority. A statutory framework will be necessary for the exchange of information relating to supervision. This is not necessarily required for the other aspects. Many of these aspects could also be enshrined in a cooperation protocol. An example of this is the cooperation protocol that ACM has concluded with ten other Dutch regulators in connection with the supervision of the Digital Services Act.[9] The difference with regard to due diligence supervision is that the protocol concerning due diligence would not relate to a single law but to various legal frameworks. However, before such a protocol can be established, there must be an understanding of the various types of supervisory situations in which supervisory authorities might find themselves when supervising due diligence under the various legal frameworks. Without such an understanding, it is questionable how effective the cooperation protocol and the cooperation between the supervisory authorities will be. It therefore makes sense to explore, on the basis of realistic scenarios, the supervisory issues and situations that supervisors are likely to encounter. On that basis, it is possible to identify which powers should be exercised by which regulator and for which purposes a mandate should be granted, how priorities can be set, what information needs to be exchanged, and how an approach that is as consistent as possible (preferably based on good/best practices) can be achieved.

7.   Effective supervision and good practice

The CSDDD applies regardless of sectors, countries and covers a broad range of human rights issues as determined in Annex I as well as environmental issues as listed in Annex II. Businesses need to know what is expected from them and in order to impose sanctions it should be clear to them in advance which non-compliance will result in sanctions. It is quite likely that neither the European Commission nor supervisory authorities will be able nor have budgets to develop sufficiently specific policies for all sectors, countries and human rights or environmental issues on which to base sanctions in the case of non-compliance. This may be especially true if the supervisory authorities would prefer to rely on easy observable compliance, such as whether a company has a policy and grievance mechanism in place, deploys a supplier code of conduct, audits suppliers or organizes training. Such supervision would incentivize ‘tick box’ compliance and may not result in improvements for affected stakeholders or meaningful outcomes, and would, conversely, create unnecessary administrative burdens, which the Omnibus I review aimed to prevent. It can be noted that real improvements for affected stakeholders will most likely not follow from imposing sanctions on companies that manifestly (and easily observable) disregard CSDDD requirements, but from engaging with companies that have implemented (part of the) CSDDD aligned measures and incentivizing them to continuously improve by allowing affected stakeholders to raise issues which will be addressed in an effective manner. Benchmarks indicating company performance compared to its peers may support such improvement. Obviously, this does not mean that no sanctions should be imposed on companies manifestly disregarding the CSDDD, but limits expectations of effectiveness of such sanctions for affected stakeholders.

It is advisable to make use of good/best practice that has been developed in sectors, counties and/or for specific human rights or environmental issues. This may make it more easy and practical for companies to implement measures (as they have been applied by themselves or peers) and this may also enhance intrinsic motivation to comply.[10] Implementing this type of supervision may require the supervisory authorities to accept that good/best practices in a certain sector, country or regarding a specific human rights or environmental issue may not yet be fully CSDDD compliant, as long as a credible expectation exists that the good/best practice is continuously improving towards a fully CSDDD compliant practice within reasonable time. A supervisory authority, implementing a risk based supervisory approach, may then less frequently assess companies which have proven to have implemented this good/best practice.

It will not always be easy for public supervisors to assess good/best practices. This may require different expertise than the type of expertise these supervisors normally have. It also begs the question what type of personnel should make these assessments, should these be lawyers or people with (practical) experience in undertaking human rights due diligence. It is most likely both will be needed to assess the level of CSDDD compliance as well as whether it actually is a good/best practice. Furthermore, it is relevant who has developed the good/best practice. A practice developed in an effective multi-stakeholder or industry initiative, in consultation with (Global South) stakeholders, is more likely to be accepted as such compared to a practice developed by an individual company without stakeholder engagement. That said, building on multi-stakeholder or industry initiatives creates an additional layer of complexity, whereas the supervisor has to assess the effectiveness of this initiative. To support supervisory authorities in assessing MSIs and industry initiatives a framework for recognizing MSIs and industry initiatives needs to be developed. This requires additional skills. This framework should take into account at least how these initiatives set standards and commitments (including stakeholder involvement) and the degree to which these are aligned with the obligations under CSDDD (different sustainability commitments as outlined in annexes I and II) and how compliance with standards and commitments is assessed (assurance and conformity assessment systems). An international or European level recognition systems for international MSIs and industry initiatives is recommended. Beyond this, drivers to develop good/best practices will not exist in all sectors (by and large sectors without civil society/consumer pressure). Unless the supervisor finds a way to create such incentives, good/best practice based supervision will be less feasible in such sectors.

Supervisory authorities may use good/best practice also in another way. They will see different approaches between companies in the same sector through a dialogue based approach. They may build capacity with those companies which have implemented less effective measures in comparison with their peers, making use of their knowledge of what other companies in this sector do. This may eventually result in benchmarking. This type of engagement with companies is helpful, but has a risk of regulatory capture, because large companies with huge sustainability/human rights departments may be able to convince the supervisor that they have developed a good/best practice or that it is not viable to implement an approach of a (for example much smaller) peer.

8.   Sanctions

Article 27 section 1 requires sanctions, as is common in EU law, to be dissuasive, proportionate, and effective and should include pecuniary penalties and interim measures. A three-tier escalation process (following the German experience) can be considered before sanctions are applied. First ask companies to change practices. Second, if they do not make use of their right to make changes order them to make changes. If this does not work, apply sanctions. However, before this approach can be applied and sanctions can be imposed, non-compliance has to be assessed. Especially if non-compliance occurs outside the EU, where EU supervisors have no supervisory powers, this may be challenging.

In this regard European coordination is required regarding the threshold triggering an investigation as well as regarding the standard of proof. This standard will be set by the supervisory authorities of the member states, although they have to observe the sincere collaboration principle of Union law. Generally speaking, the standard of proof will be an assessment beyond reasonable doubt, the more likely than not standard or clear and convincing evidence. The standard of proof could be further developed through collaboration between supervisory authorities at the European level (for example, are NGO reports sufficient if a supervisory authority provides reasoning why this report is credible and shows non-compliance). The threshold triggering investigations and the burden of proof require further elaboration. Beyond this, coordination is required to determine which supervisory authority will take the lead in such assessments.

It would also be good to develop criteria at the EU level which requirements substantiated concerns as referred to in Article 26 should meet in order to create a credible assumption of non-compliance as well as how these substantiated concerns are prioritized.

A relatively new type of sanction is the order to provide remedy as referred to in Article 25 section 5 (a)(iii) CSDDD. By and large public supervision aims to secure general compliance with regulation and not individual compensation. Therefore, supervisory authorities may not have much experience with this type of order, which triggers challenging questions like the level of involvement required for contribution, whether a causal link exists between non-compliance and the adverse impact and which damage should be compensated as well as whether the amount of compensation (if so requested) would meet local standards (presuming that damage calculation will be based on the law applicable in the State in which the adverse impact has occurred). This also begs the question whether supervisory authorities would be obliged to use this power if they can also impose other sanctions, like a fine, and may refer affected stakeholders to liability proceedings (in civil courts) under national law. Whereas the overriding mandatory law provision of Article 29 section 7 CSDDD has been deleted, civil proceedings may be less effective, whereas the law of the State in which the adverse impact occurred usually applies according to Article 4 of the Rome-II convention. Such law may not include a due diligence obligation. Therefore, it may be conceivable that such a referral by the public supervisory authority is not accepted in (administrative) courts as it would not create an effective avenue to remedy for non-compliance with the CSDDD. This may be different if member states would implement a mandatory overriding law provision in their national law transposing the CSDDD.

Article 25 CSDDD focusses on sanctions in connection with non-compliance. However, as said, non-compliance may not be easy to observe, especially outside the EU. Therefore, a power to impose certain behaviour in connection with human rights and environmental due diligence, even in cases in which non-compliance has not been observed (yet), may be a helpful addition.[11]

The final question for member states and public supervisors may be the extent to which sanctions for non-compliance have an impact on, for example, public procurement and subsidies. This should probably not be an automatic link, but it may be conceivable under certain conditions.

 

Suggested citation: N, Bonucci, A. Marx and M. Scheltema, ‘Non-paper: Observations on effective public supervision under the Corporate Sustainability Due Diligence Directive (CSDDD)’, NOVA BHRE Blog, 15 June 2026

 

[1] Directive (EU) 2024/1760 as amended by directive (EU) 2026/470.

[2] Streibelt, M. (2026). Article 24. In: Bright, C., Scheltema, M. (Eds.). Shaping Sustainable Business in Europe: A Commentary on the EU Corporate Sustainability Due Diligence Directive.

[3] For example, the German supervisory authority on the German supply chain act, the Federal Office for Economic Affairs and Export Control (BAFA) is embedded within the Federal Ministry for Economic Affairs and Climate Action

[4] This applies to the Dutch Authority for Consumers and Markets (ACM) which will be entrusted with the supervision of the CSDDD

[5] Recital 75.

[6] See for an example of practical advice of supervisory authorities in connection with sanctions in France https://www.tresor.economie.gouv.fr/services-aux-entreprises/sanctions-economiques).

[7] See in connection with the helpdesk for sanctions https://eu-sanctions-compliance-helpdesk.europa.eu/index_en.

[8] Regulation (EU) 2017/2394.

[9] See https://www.acm.nl/nl/publicaties/acm-tekent-samenwerkingsprotocol-over-dsa-met-elf-organisaties.

[10] See on this type of supervision e.g. Robert McCorquodale and Martijn Scheltema, Supervisory Mechanisms and Directors Duties: Innovations in the Proposed EU Directive on Corporate Sustainability Due Diligence, under Best Practice, accessible at https://novabhre.novalaw.unl.pt/supervisory-mechanisms-and-directors-duties-innovations-in-the-proposed-eu-directive-on-corporate-sustainability-due-diligence/.

[11] Supervisory authorities in other fields, e.g. consumer law, avail over such powers. The Dutch transposition proposal of the CSDDD (pre Omnibus) proposed such a power in Article 4.2.1.1. This consultation version is accessible at Overheid.nl | Consultatie Wet internationaal verantwoord ondernemen.