Why Traditional Supply Chain Audits Won't Satisfy CSDDD

For the past thirty years, if a company wanted to prove it took supply chain responsibility seriously, it commissioned an audit. A third party flew in, walked a factory floor, checked a stack of paperwork, and issued a certificate saying everything looked acceptable. Annual reports were filed, codes of conduct signed, and the machinery of ethical trade hummed along.
The European Union's Corporate Sustainability Due Diligence Directive, known as the CSDDD, changes that model at its foundation. Under the CSDDD, an audit is not compliance. The directive does not ask companies to document their intentions once a year. It asks them to actually know what is happening across the full value chain, all year round, and to act on what they find. That is a different job, and it needs a different tool.
The Audit Gap
Due diligence has, for most of modern corporate history, meant audits. A buyer sets a supplier code of conduct. The supplier signs it. An auditor visits once a year, works through a checklist of questions about wages, working hours, health and safety, and environmental practices, then issues a report with a pass grade or a corrective action plan. The buyer files the report, and the cycle repeats the following year.
This model made sense when the goal was a reasonable check that a direct supplier met a basic standard. Audits are good at verifying a factory's payroll records on a given day. They are good at confirming that the fire extinguisher is on the wall and the exit signs work. None of that is worthless. But the model rests on an assumption the CSDDD no longer grants: that a periodic inspection of a direct supplier is enough to know what is happening in a supply chain.
The limits of that assumption are well documented. The 2013 Rana Plaza collapse in Bangladesh, which killed more than 1,100 garment workers, happened in buildings that had been inspected and certified under social compliance audit programs. Nobody set out to deceive anyone. The audits were not designed to see what they missed: the state of the building, the pressures on management, the conditions workers lived with day to day. Regulators in Brussels watched this pattern repeat across industries, and they concluded that the audit industry was answering the wrong question. The question was never "does the certificate exist?" The question is "what is actually happening, and what are you doing about it?"
The CSDDD is the EU's answer. It moves due diligence from assessment to action, and it is deliberately hard to satisfy with paperwork.
What the CSDDD Actually Requires
First, who is in scope. Following the EU's 2025-2026 Omnibus simplification process, the directive now applies to a narrower group than originally enacted: EU companies with 5,000 or more employees and more than €1.5 billion in worldwide turnover, and non-EU companies that generate more than €1.5 billion in turnover inside the EU. This group must comply from 26 July 2029, with national transposition due a year earlier, on 26 July 2028. If your company sells into the EU at scale, or supplies companies that do, this applies to you too, because in-scope companies must carry due diligence through the full chain of their business partners' activities.
Second, what it requires. The core obligation is to identify actual and potential adverse impacts on human rights and the environment across the company's own operations, its subsidiaries, and its value chain. Once impacts are identified, the company must:
- Prevent and mitigate potential impacts, with measures that are actually implemented and monitored, not just written down (Article 10).
- Bring to an end actual impacts, and where they cannot be ended, minimize their extent (Article 11).
- Remediate harm that has occurred, and provide remediation where the company caused or contributed to it (Article 12).
- Engage meaningfully with stakeholders, including workers and affected communities, throughout the process (Article 13).
- Face consequences for non-compliance: national supervisory authorities can impose administrative fines of up to 3% of net worldwide turnover (Article 27), and affected persons can still bring civil damages claims, though the Omnibus process removed the directive's harmonized EU-wide liability standard (Article 29), leaving the exact rules to each member state's national law.
Notice what is missing from that list: "conduct an annual audit." The directive never uses the audit as the unit of compliance. It uses outcomes. Did you identify the risk? Did you take appropriate measures? Did the measures work? Are they still working? The directive requires due diligence to be carried out on an ongoing basis, updated as circumstances change and as new risks appear.
That is the shift from assessment to action, and it is the whole story. An audit is an assessment. The CSDDD is a demand for action, continuously.
Four Problems with the Audit Model
1. Audits are periodic, but impacts are continuous
An audit is a snapshot. It captures what was true on the days the auditor was on site. But the harms the CSDDD targets do not keep office hours. Wage theft happens every pay cycle. Overtime violations peak during order surges. Deforestation happens season by season. Child labor can begin and end between two annual visits.
Article 10 requires ongoing prevention, which requires ongoing awareness. If a regulator asks what happened in your supply chain in March and your answer is "we audited in October," you have not answered the question. The directive expects companies to know about adverse impacts when they occur or shortly after, and to act while there is still time to prevent them. An annual cycle cannot do that. The interval between audits is exactly when the damage happens.
2. Audits stop at Tier 1, but the CSDDD covers the whole value chain
Most audit programs cover direct suppliers: the factories, mills, and processing plants a company contracts with. Tier 1 is where the audit industry has always been most comfortable, because those suppliers are formal businesses with records, staff, and premises.
The CSDDD is not limited to Tier 1. It covers the full chain of activities of business partners, all the way to the commodity source: the fishing vessels catching tuna, the smallholder farms growing cocoa, the rubber plantations, the mines. The most severe human rights and environmental impacts in any value chain sit at exactly these points: the raw material origin, far from any factory, often informal, with no audit trail at all.
Here is the uncomfortable arithmetic: an annual audit model cannot reach millions of smallholders, and no certification scheme can inspect every fishing vessel. Companies that pretend otherwise are building compliance programs that cover the visible part of their supply chain and nothing else. Regulators know this. The directive was written precisely to pull due diligence out to the edges of the value chain, where the impacts are.
3. Audits run on self-reported data
The raw material of most audits is what the supplier tells the auditor. Supplier questionnaires, self-assessments, corrective action plans drafted by the audited party, and for many audit programs, advance notice of the visit so everything can be tidied first. The system depends on the honesty and record-keeping of the party being examined.
That dependency is a legal vulnerability. Civil claims connected to due diligence failures are still possible, and one of the questions a court will ask is whether the company's due diligence measures were appropriate and genuinely implemented. A binder of supplier declarations will not answer that question. It will raise the next one: did you verify any of this, or did you take the supplier's word for it?
Self-reported data also fails in the other direction. It underreports problems because suppliers have incentives to look good, and it overreports compliance because checklists measure paperwork rather than practice. Either way, it is not evidence of what is happening on the ground, only what the supplier says is happening.
4. Audits don't ask the people who know
Article 13 requires meaningful engagement with stakeholders: workers, their representatives, and affected communities. The people who work in a factory, fish on a vessel, or live next to a plantation know more about the conditions there than any visiting auditor ever will.
Traditional audits engage workers only shallowly, if at all. Interviews happen on site, sometimes in the presence of management, with names and answers recorded in the auditor's notes. Workers who fear retaliation learn quickly that the safe answer is "everything is fine." Auditors are guests of the supplier, and everyone in the room knows it. The result is that the most important source of information in the entire supply chain, the people living the conditions, is the least consulted.
The CSDDD makes their participation a legal requirement, not a nice-to-have. Meaningful engagement means workers and communities can raise concerns, in their own language, without management filtering or fear of reprisal, and the company must take what they say seriously.
The Evidence Problem
Put the four problems together and you get the fifth, which is the one that matters most when things go wrong: the audit model produces the wrong kind of evidence.
Think about how a CSDDD investigation actually proceeds. A regulator opens an inquiry, or a plaintiff files a civil claim under national law. The questions are always the same. What did you know about this impact, and when did you know it? What did you do in response? How do you know your measures worked? The answer needs to be evidence: dated records of what was observed, where, by whom, and what the company did next.
A self-reported supplier questionnaire is not that evidence. An annual audit certificate is not that evidence, because it says nothing about the other 364 days. A corrective action plan written by the supplier being corrected is not that evidence. In a civil liability case, the company carries the burden of showing its due diligence was appropriate and actually implemented. Weak evidence is not neutral; it is a liability.
There is also a forward-looking version of this problem. The CSDDD requires companies to demonstrate that their prevention measures worked, which means tracking outcomes over time. Did the wage violations stop? Did the deforestation cease? Did the community confirm the remediation reached them? The audit model generates a report at a point in time. Continuous monitoring generates a record of change.
What Continuous Monitoring Looks Like
Continuous monitoring is not a fancier audit. It is a different architecture for knowing what is happening in a supply chain, built from three layers that reinforce each other.
Community monitoring. The first layer is the people on the ground. Frontline workers and local communities report what they see directly from their phones: unsafe conditions, wage violations, labor abuse, environmental damage. Reports are timestamped and geolocated, made in the reporter's own language, and can be anonymous where retaliation is a real risk. This is Article 13 stakeholder engagement made operational, and it is the earliest warning system a company can have, because information travels from source to company in minutes, not in an annual report.
Satellite verification. The second layer is independent observation from orbit. Commercial constellations pass over the same locations repeatedly, every day. Earth PBC works with Planet Labs, whose constellation makes more than 200 satellite passes daily and covers more than three million square kilometres of the Earth's surface every day. Satellites see land conversion, deforestation, illegal mining, and other environmental impacts at the commodity source, with no reliance on anyone's paperwork. They cannot see inside a factory, which is why the third layer matters.
AI evidence compilation. The third layer ties it together. AI assembles community reports, satellite observations, and company records into structured evidence files: what happened, where, when, who reported it, what the imagery shows. When community reports are cross-checked against satellite data, the verification rate is around 90 percent. What the company receives is not a stack of anecdotes. It is a dated, organized record of impacts and responses, ready to act on and ready to show a regulator or a court.
Continuous monitoring changes the timeline of knowledge. Instead of discovering a problem at the next annual audit, the company learns about it while it is happening, while prevention is still possible, while the harm is still cheap to stop. That is the difference between Article 10 compliance and Article 10 paperwork.
How Earth PBC Replaces the Audit Model
Earth PBC is a public benefit corporation that builds exactly this architecture for companies in scope of the CSDDD and related rules such as the EU Deforestation Regulation, the UK Modern Slavery Act, and the US TVPRA. The platform combines community monitoring, satellite verification, AI reporting, and direct payments to communities, operating in more than 100 countries. Here is how it maps onto the directive's obligations.
- Identify (the core obligation). Community reports and satellite alerts surface adverse impacts across the full value chain, including Tier 3 suppliers and the commodity source, in more than 100 countries. The company sees risks it could not see before, because witnesses report them directly and satellites observe them independently.
- Prevent and mitigate (Article 10). Because monitoring is continuous, risks are caught early, while they are still preventable. Alerts carry location and evidence, so the company can respond with targeted measures instead of broad corrective action plans written after the fact.
- Bring to an end and remediate (Articles 11 and 12). When an impact is confirmed, the platform routes direct stablecoin payments to the affected communities, so remediation money reaches the people harmed rather than stopping somewhere in the middle of the supply chain. Workers and communities are paid for their reporting too, which is what makes sustained engagement possible.
- Meaningful stakeholder engagement (Article 13). Community monitoring is engagement at scale: continuous, in reporters' own languages, independent of management. It gives workers and communities a channel that the traditional audit never offered them.
- Civil liability defense. Every report and every satellite pass is compiled into timestamped, geolocated evidence. When the question is "what did you know and when did you know it," the company has a dated, verified record of knowing, and of acting. That is the strongest defense available, regardless of which member state's liability rules end up applying.
None of this requires a company to abandon audits entirely. Audits still have a role: verifying specific facilities, investigating confirmed incidents, checking remediation work. The point is that audits are no longer the system. They are one tool inside a continuous system, and the continuous system is what the CSDDD demands.
If your company is in scope, the practical question is not whether to build this capability. Companies must comply from 26 July 2029, and the questions regulators and courts will ask are already known: what did you know, when did you know it, and what did you do? The audit model does not produce answers to those questions. Continuous monitoring does.
We would be glad to show you how the platform works in practice, mapped against your specific supply chain and your obligations under the CSDDD. Contact us or book a demo, and let's talk about what your evidence will look like when the compliance date arrives.
