Skip to main content Skip to footer

CSRD and CSDDD: building a joined-up approach to human rights

CSRD and CSDDD ask companies to do different things, but they should not be managed as separate projects. CSRD requires companies to report material sustainability impacts, risks and opportunities. The Corporate Sustainability Due Diligence Directive (CSDDD) requires in-scope companies to identify and address adverse human rights and environmental impacts. Build one coordinated evidence base and governance structure that serves both, while keeping separate legal tests, controls and outputs for each.




Running 2 parallel workstreams, one for reporting and one for due diligence, means duplicating supplier engagement, stakeholder consultation and risk assessment. It also creates a real risk that the 2 processes produce inconsistent findings, which is harder to defend to auditors, regulators or investors than a single, well-evidenced approach.

In short: use due diligence to understand and address impacts. Use CSRD reporting to explain the material impacts, actions, governance and outcomes clearly.

For a full account of what human rights reporting requires under CSRD, see our guide to human rights reporting under CSRD.

This article reflects the EU sustainability reporting and due diligence framework as updated in 2026. The revised ESRS are intended to apply to financial years beginning on or after 1 January 2027, subject to the delegated act’s scrutiny process. The amended CSDDD requires Member States to adopt national measures by 26 July 2028 and apply them from 26 July 2029, with CSDDD reporting requirements applying for financial years beginning on or after 1 January 2030.

 

 

Why CSRD and CSDDD should be designed together

Both frameworks depend on an accurate understanding of the same underlying reality: who the company affects, where adverse impacts may arise, how severe those impacts could be, which groups need engagement, what actions the company has taken, and whether those actions are working.

The practical emphasis differs, and that distinction matters.

  • CSRD asks: what is material, and what should we disclose?

  • CSDDD asks: what adverse impacts must we identify and address?

A company that conflates these questions will either over-report operational detail that belongs in a due diligence file, or under-invest in the action and monitoring CSDDD requires. The overlap should not be overstated. A strong human rights due diligence programme is not a shortcut around materiality assessment, and a good Sustainability Statement is not proof that the company has met its due diligence duties.

What the 2 frameworks share is a need for the same foundational evidence: a clear picture of who the company affects, where the most serious risks sit, and what the company is doing about them. Building that picture once, rigorously, is far more efficient than building it twice for separate audiences.

For a closer look at how materiality assessment works in this context, see our article on human rights in a double materiality assessment.

 

 

The difference matters, and the evidence can be shared

CSRD vs CSDDD: how the two frameworks compare

Area CSRD CSDDD
Main purpose Report material sustainability information Identify, prevent, mitigate, end and, where applicable, remedy adverse impacts
Core question What sustainability impacts, risks and opportunities are material to report? What adverse human rights and environmental impacts must the company address?
Primary output Sustainability Statement Due diligence policies, measures, monitoring, complaints procedures and public communication
Main reporting lens Double materiality Risk-based due diligence
Scope Companies meeting CSRD scope criteria Very large EU and non-EU companies in CSDDD scope
Practical relationship Explains material impacts, risks, opportunities, actions and outcomes Requires operational action and monitoring in response to relevant adverse impacts

The most useful overlap is the evidence base. A company running one process to understand worker, community or consumer impacts for CSDDD, and a separate process to understand the same impacts for CSRD, is paying twice for one answer. The assessment work, the stakeholder engagement, the supplier data collection and the risk prioritisation can all be shared. What changes is what each framework then requires the company to do with that evidence.

A well-evidenced CSRD assessment gives you a lot of what CSDDD needs. CSDDD then requires companies in scope to act on adverse impacts, and that action is the practical test of whether an approach is joined up or only coordinated on paper.

The OECD Guidelines for Multinational Enterprises on Responsible Business Conduct set out a risk-based approach to due diligence that sits underneath both frameworks: assess, prevent, mitigate and track impacts. That sequence is as relevant to CSRD disclosure as it is to CSDDD implementation.

 

 

Build one shared human rights evidence base

The UN Guiding Principles on Business and Human Rights establish due diligence as a continuing process. Both CSRD and CSDDD reflect that. The practical implication is that the shared evidence base needs maintaining and updating between reporting deadlines, rather than being assembled to meet one.

There are 5 core ingredients to get right.

1. Map affected people and business relationships

Start with a clear picture of who the company may affect. This includes:

  • Own workforce, including agency workers and contractors

  • Value chain workers across sourcing regions and manufacturing

  • Communities near operations or affected by products

  • Consumers and end-users

  • Subsidiaries, suppliers and business partners

The ESRS S1 to S4 social standards set out the 4 groups CSRD requires companies to consider. That same structure gives you a logical starting point for mapping due diligence scope under CSDDD.

 

2. Identify actual and potential impacts

Separate impacts that are already occurring from those that could occur. Both matter, and they call for different responses. Actual impacts require remediation or cessation. Potential impacts require prevention or mitigation.

Evidence should cover operations, sourcing regions, business model risks, product use and sector-specific risks. External intelligence, worker feedback and grievance data are often more revealing than internal records alone. 

 

3. Engage stakeholders and maintain accessible grievance routes

Stakeholder engagement supports accurate materiality assessment and effective due diligence at the same time. The groups most relevant to human rights assessment include:

  • Workers and trade unions

  • Community representatives

  • Consumer groups and civil society organisations

  • Vulnerable groups where relevant, including migrant workers, women, and people with disabilities

Grievance mechanisms should reach every affected group, well beyond direct employees. Complaints received through those channels are evidence, and that evidence should feed into both the due diligence process and the Sustainability Statement.

 

4. Prioritise based on severity and likelihood

Prioritisation should reflect:

  • Scale: how serious is the harm?

  • Scope: how many people are affected, or how widespread is the impact?

  • Irremediable character: can the harm be undone?

  • Likelihood: for potential impacts, how probable is it?

For human rights impacts, severity takes precedence over likelihood. A severe potential impact is material whether or not it has ever occurred. Scoring templates that weigh the 2 equally by default will push material human rights impacts down into non-material territory.

Severe harm to a smaller group holds its weight. A risk of forced labour affecting 200 workers in a single supplier facility sits above a lower-severity risk affecting a larger workforce.

 

5. Track actions, outcomes and evidence

Policies and supplier commitments are where this starts. The evidence base needs to capture:

  • Preventative actions taken

  • Mitigation and remediation measures

  • Supplier corrective action plans and their outcomes

  • Grievance outcomes and resolution rates

  • Monitoring of effectiveness over time

  • Known data limitations and plans to close them

This is where human rights KPIs and reporting evidence earn their keep: the metrics that let the company demonstrate its approach is working, rather than assert it.

 

 

How the joined-up process works in practice

An integrated approach needs an operating model. In practice, the process runs as follows:

  1. Sustainability, legal, procurement, HR and risk teams agree the assessment boundary: which operations, geographies, value chain tiers and business relationships are in scope.

  2. The company maps people and risk exposure across those operations and value chains, using the 5-part evidence framework above.

  3. Teams gather evidence from internal records, suppliers, stakeholders and external sources, coordinating so that each team’s findings feed into a single shared picture rather than separate files.

  4. The company prioritises impacts and assigns accountable owners, with clear responsibility for action as well as for data collection.

  5. The business acts to prevent, mitigate, end or remedy impacts, with documented timelines and outcomes.

  6. Material findings feed into the Sustainability Statement, while due diligence actions continue beyond the reporting cycle.

The annual Sustainability Statement is an account of an ongoing human rights management process. The process itself runs underneath it, year-round.

That distinction matters for governance. A process that only runs when a reporting deadline approaches won’t meet the continuous monitoring expectations of CSDDD, and it will produce thinner, less credible CSRD disclosures. The reporting cycle is a useful discipline on top of the work.

 

 

What CSRD reporting should take from due diligence

Due diligence outputs are some of the most credible inputs a company can bring to its CSRD reporting. They’re grounded in operational reality rather than policy intent, and they carry the kind of specificity a materiality assessment needs to be defensible.

Due diligence work can strengthen CSRD disclosures in several ways:

  • Risk maps sharpen materiality conclusions, providing evidence for why certain topics were assessed as material or not.

  • Stakeholder input gathered through due diligence supports the explanation of impacts in the Sustainability Statement, particularly for value chain and community topics.

  • Corrective action plans support disclosure of the actions the company has taken or committed to take.

  • Monitoring data supports targets and metrics, giving disclosures a factual basis that goes past commitments.

  • Grievance information supports transparency on incidents, how they were handled, and what remediation was provided.

The revised ESRS Delegated Act, adopted by the European Commission on 3 July 2026, cut the mandatory datapoints in ESRS by more than 60%, which makes materiality-led reporting the clear expectation. Report on what carries weight, supported by evidence, and leave the rest.

Reporting should reflect material impacts, risks and opportunities. A Sustainability Statement that lists every due diligence activity has lost the plot. What you want is a clear, evidence-backed account of what matters and what the company is doing about it. 

 

 

What CSDDD implementation can take from CSRD reporting

The relationship runs in both directions. A well-structured CSRD reporting process improves CSDDD readiness in ways that are easy to underestimate:

  • Board-level visibility of human rights risks, which CSDDD requires to be embedded in governance rather than delegated entirely to operational teams.

  • Clear governance ownership, with named functions accountable for specific impacts and topics.

  • Consistent definitions and reporting boundaries, so the scope used for CSRD disclosures matches the scope used for due diligence assessments.

  • A disciplined evidence trail, including documentation of how materiality decisions were made and what evidence supported them.

  • A regular review cycle for risks, actions and outcomes.

  • More transparent internal accountability, which makes it easier to assign and track corrective actions across business units and supplier tiers.

CSDDD readiness still turns on whether the company can demonstrate appropriate action on adverse impacts. A company with sophisticated CSRD disclosures and weak corrective action processes isn’t CSDDD-ready. The CSDDD is an action-oriented instrument, and its requirements centre on what companies do.

This is also where double materiality under CSRD creates a useful foundation. A rigorous double materiality assessment, one that tests impact materiality properly across the value chain, produces conclusions far more useful for CSDDD prioritisation than an assessment built to limit disclosure scope.

 

 

Where companies still need separate work

An integrated approach doesn’t make one process sufficient for both frameworks. CSDDD requires specific work that goes past what CSRD reporting demands, and a strong Sustainability Statement doesn’t cover it.

CSDDD in-scope companies will typically need to put in place or demonstrate:

  • A formal due diligence policy, embedded in business operations and reviewed regularly

  • Specific prevention, mitigation, cessation or remediation measures for identified adverse impacts

  • A complaints and grievance procedure accessible to affected persons and their representatives

  • Monitoring of the effectiveness of due diligence measures over time

  • Public communication on the due diligence process, distinct from the CSRD Sustainability Statement

  • Legal analysis of scope, national implementation and accountability, given that the amended CSDDD under Directive (EU) 2026/470 requires Member States to adopt national measures by 26 July 2028

CSRD scope and CSDDD scope are not identical. Assess your position under each framework separately, based on group structure, employee numbers, turnover and relevant EU activity. A company in scope for CSRD is not automatically in scope for CSDDD.

The practical implication is that the shared evidence base reduces duplication but does not eliminate the need for framework-specific implementation work. Both processes need to be designed properly; they simply do not need to be designed in isolation from each other.

 

 

5 actions to take now

You don’t need final national implementation timelines before starting. The evidence-building work pays off now, whichever framework applies first.

  1. Create one cross-functional human rights governance group covering sustainability, legal, procurement, HR and risk. Without shared ownership, the 2 frameworks will default to separate workstreams.

  2. Use one map of affected people and material exposure across operations and value chains, and keep it live between reporting cycles.

  3. Coordinate the evidence you collect so it supports both due diligence decisions and Sustainability Statement disclosures. Data collected for one purpose shouldn’t sit in a silo the other can’t reach.

  4. Track actions and outcomes alongside policies and supplier commitments. The test of effectiveness is what changed on the ground.

  5. Separate what is material to report from what must be acted on, while keeping the underlying evidence connected. Different questions, different standards, same foundation.

 

 

How Kōan supports joined-up CSRD and CSDDD work

Getting this right takes sustainability expertise and a clear read on what each framework requires. That’s what our end-to-end reporting services are built for.

We work with companies to turn that into clear, defensible reporting decisions. For CSRD and CSDDD together, we can support:

  • CSRD and ESRS interpretation and scoping.

  • One shared map of affected people and material exposure across operations and the value chain.

  • Stakeholder engagement design that serves both materiality assessment and due diligence.

  • Severity and likelihood assessment, with documented scoring criteria.

  • Governance structures that give sustainability, legal, procurement and HR a single picture.

  • Sustainability Statement drafting, from materiality findings through to disclosure.

If you’re designing this process or want a second opinion on how your reporting and due diligence work fit together, get in touch, we’re happy to discuss where you are.

FAQ's:

How do CSRD and CSDDD work together?

CSRD requires companies to report material sustainability impacts, risks and opportunities. CSDDD requires companies in scope to identify and address adverse human rights and environmental impacts. They work best together when the company uses one evidence-led assessment process to inform both due diligence actions and reporting, instead of running 2 separate work streams that draw on the same underlying data.

Does CSRD reporting meet CSDDD requirements?

No. A CSRD Sustainability Statement can provide useful evidence for CSDDD readiness, and CSDDD still requires in-scope companies to take appropriate action to identify, prevent, mitigate, end or remedy adverse impacts. Reporting alone is not enough.

Can a CSDDD due diligence process support CSRD reporting?

Yes. Due diligence outputs such as risk maps, stakeholder engagement records, grievance data, corrective action plans and monitoring results can support a company’s CSRD materiality assessment and help produce more credible human rights disclosures.

What human rights evidence can companies use for both CSRD and CSDDD?

Useful shared evidence includes risk assessments, supplier and procurement data, worker and community engagement records, grievance outcomes, audit findings, corrective action records, policies, board oversight records and effectiveness monitoring.

Does CSDDD apply to all companies reporting under CSRD?

No. CSRD and CSDDD have different scope thresholds and application rules. Companies should assess their position under each framework separately, based on their group structure, employee numbers, turnover and relevant EU activity.

What should companies do first?

Start by mapping the people the company may affect across its operations, value chain, communities and products. Then identify actual and potential impacts, test them with evidence and stakeholder engagement, and assign accountable owners for action and reporting.