Who really owns EUDR compliance? Why ESG and supply chain teams both have a role

January 5, 2026
7
min read

Disclaimer: New EUDR developments - December 2025

In November 2025, the European Parliament and Council backed key changes to the EU Deforestation Regulation (EUDR), including a 12‑month enforcement delay and simplified obligations based on company size and supply chain role.

Key changes proposed:

  • New enforcement timeline: 30 December 2026 for large/medium operators, 30 June 2027 for small/micro operators
  • Simplified DDS: One-time declarations for small and micro primary producers
  • Narrowed scope: Most downstream actors and non‑SME traders would no longer need to submit DDSs
  • New DDS requirement: Estimated annual quantity of regulated products must be included

These updates are not yet legally binding. A final text will be confirmed through trilogue negotiations and formal publication in the EU’s Official Journal. Until then, the current EUDR regulation and deadlines remain in force.

We continue to monitor developments and will update all guidance as the final law is adopted.

Key takeaways:

  • EUDR compliance is a shared responsibility: ESG teams own the due diligence framework, risk methodology, and annual reporting, while supply chain teams are accountable for supplier data collection, product traceability, and DDS coordination before shipments.
  • Core EUDR obligations apply from 30 December 2026 for large and medium operators and non-SME traders, and from 30 June 2027 for micro and small operators.
  • Companies that silo ESG and supply chain functions risk incomplete DDS submissions, blocked shipments, and regulatory fines of up to 4% of EU annual turnover.
  • Coolset's EUDR module gives ESG and supply chain teams a shared platform to manage supplier data and risk assessments.

The EU Deforestation Regulation (EUDR) changes how companies handle sourcing and reporting. Following the amendment adopted on 19 December 2025 (Regulation (EU) 2025/2650), the core obligations now apply from 30 December 2026 for large and medium operators and traders. Micro and small operators have until 30 June 2027. From those dates, placing or exporting regulated commodities in the EU will require a Due Diligence Statement (DDS) - or, for micro and small primary operators, a one-time simplified declaration that proves products are both deforestation-free and legally produced. 

But what many businesses are asking is: which department is actually responsible for compliance?

The answer is both. ESG teams can’t meet operational requirements without supply chain support, and supply chain teams can’t manage governance, reporting, and audit-readiness without ESG. This guide explains why, what each team contributes, and how to build a shared responsibility model that keeps shipments moving and meets legal obligations.

Why EUDR compliance is a shared responsibility

What makes EUDR stand out is that it’s not simply a sustainability disclosure or a procurement standard. It’s a compliance control with real operational impact. The law requires companies to prove that their products are deforestation-free and legally produced before they can be placed on or exported from the EU market. In practice EUDR doesn’t just influence reporting; it changes how you run procurement, logistics, and supplier management every day. A shipment cannot be delivered if there is no DDS submitted.

To meet the law, companies must address two interconnected dimensions:

  • Governance and reporting (Article 12): Establishing a due diligence system, aligning internal policies, defining what “negligible risk” means, and preparing for compliance.
  • Operational controls (Articles 9–11): Collecting geolocation and legality data from suppliers, verifying deforestation-free status, running risk assessments, and applying mitigation before shipment deadlines. These tasks sit squarely in procurement and supply chain operations.

Because the regulation blends these two worlds, governance oversight and supply chain execution, no single function can own it outright. ESG teams lack the direct supplier touchpoints to get the data; supply chain teams lack the governance mandate to ensure audit-ready compliance. Only a structured partnership can close the gap.

{{custom-cta}}

How ESG teams contribute to EUDR compliance

ESG teams function as the architects of compliance. Their role is to translate the regulation into a structured system that fits the company’s reality while standing up to regulatory scrutiny. In practice, ESG teams:

  • Create the due diligence system: They design and maintain the internal framework that ensures compliance. This includes mapping legal requirements from the EUDR against the company’s own processes. This system sets the rules of the game: how data is collected, how risks are assessed, and how evidence is stored.
  • Develop and implement risk assessments: ESG defines what “negligible risk” means in practice for the business. They build the methodology, set risk criteria, and craft mitigation processes that suppliers and procurement teams must follow when red flags appear.
  • Set out and standardise data requests: ESG determines the exact supplier information required under the law, from geolocation coordinates to legality documents, and ensures there is a clear protocol for collecting and recording this data in an audit-ready way.
  • Coordinate annual reporting: For non-SME operators, ESG is responsible for producing the annual public report on due diligence activities, showing regulators, investors, and stakeholders that the system is active and effective.

By doing this, ESG teams ensure the company has a defensible compliance backbone. Their frameworks and oversight don’t replace supply chain action, but they make sure every operational step can be traced back to a structured, legally aligned system.

In a practical example the ESG team leads the creation of a scoring framework that weights country risk, plot-level verification, and supplier history. This framework becomes the reference point for every shipment review but ESG needs accurate, timely supplier data from operations to apply it.

What supply chain teams bring to EUDR compliance

Supply chain teams function as the operators of compliance. They work at the frontline of supplier engagement and logistics. In practice, supply chain teams:

  • Manage supplier relationships and data requests: They are the direct link to suppliers collecting geolocation, legality documents, and other required data. Supply chain teams also help suppliers on the day-to-day, guiding them through formats, systems, and deadlines so that information flows smoothly.

  • Provide product traceability: From inbound raw materials to outbound finished goods, supply chain teams maintain the chain of custody. They ensure compliant and non-compliant goods are not mixed, and that every product can be traced back to its verified origin.

  • Execute mitigation with suppliers: When risks are identified, supply chain needs to act by chasing missing documents, requesting corrective actions, or even switching suppliers when mitigation fails. Their responsiveness ensures no risky shipment moves forward unchecked.

  • Organise DDS’ before shipments: Supply chain monitors and coordinates the deadlines for DDS submissions so that all the requirements have been fulfilled before the shipments are ready for departure.
    • For companies sourcing from micro or small primary operators, this may also involve obtaining the reference number of an existing DDS rather than managing a new submission, a process that still requires active coordination with those suppliers.

By doing this, supply chain teams ensure the company’s compliance system works on the ground.  For example, if a supplier in Indonesia provides incomplete plot coordinates, the supply chain is the one following up, standardizing data formats, and ensuring the update reaches ESG for risk assessment all before the shipment is ready to go.

How the shared responsibility model works in practice

The EUDR doesn’t name which job title signs the DDS, it simply states that the operator or non-SME trader placing or exporting the product is responsible. This makes internal clarity essential.

A practical approach is to map responsibilities using a RACI framework (Responsible, Accountable, Consulted, Informed). In this model:

  • ESG is accountable for the due diligence process and methodology.
  • Supply chain is responsible for supplier data collection and execution of mitigation steps.
  • Legal reviews ensure alignment with the regulation.
  • Procurement aligns sourcing decisions with compliance requirements.
  • IT supports data integration and traceability systems.

How to align ESG and supply chain teams for EUDR

EUDR is a challenge to onboard, and without clear organisation it can quickly create conflicts and bottlenecks. Aligning ESG and supply chain from the start is key to avoiding issues. To make this collaboration work in practice:

  1. Dedicate time for training and onboarding: Create internal sessions where both teams learn about the regulation, map responsibilities, and agree on the game plan. Everyone should leave knowing their role in the DDS process.

  2. Work from one system, not scattered files: A central compliance tool, like Coolset’s EUDR module, is essential to stay proactive. It avoids last-minute scrambles by keeping supplier data, risk assessments, and DDS drafts in a single source of truth.

  3. Set timelines and expectations: Define how the teams will handle urgent or fast orders, and build compliance checks into logistics workflows so that no shipment is blocked at the last minute.

  4. Hold regular syncs: Schedule standing meetings, weekly, bi-weekly, or monthly depending on your risk profile, to review open points, supplier issues, and upcoming deadlines.

  5. Start supplier onboarding now: Don’t wait for December 2025. Begin collecting data and engaging suppliers early, so they have time to adapt and you have time to resolve gaps before enforcement kicks in.

By building these habits, ESG and supply chain move from reactive firefighting to a predictable, proactive compliance rhythm.

Common pitfalls when teams work in silos

When ESG and supply chain don’t work in sync, small gaps can quickly snowball into compliance or operational failures. Some of the most common pitfalls include:

  • Missing information and misaligned supplier communication: If suppliers are contacted by different people with conflicting requests, they can become frustrated or confused. In practice, this often leads to incomplete or inconsistent data which means the DDS can’t be filed on time.
  • Compliance issues: Without consistent cross-checks, there’s a risk of submitting a DDS without proper controls. For example, procurement might accept a simple supplier self-declaration as legality evidence, while ESG would have required official permits or government records. This creates exposure if an authority audits the file.
  • Operational blockers: Without clear expectations and responsibilities, EUDR checks can be missed in procurement timelines. The result is shipments held back at the last minute because the DDS isn’t ready, causing delays in logistics and lost revenue.

The consequences are serious: blocked shipments, unsatisfied suppliers and customers, and potential fines of up to 4% of EU turnover. In short, siloed working makes EUDR compliance harder, riskier, and more costly than it needs to be.

How technology can bridge the ESG-supply chain gap

Technology can take much of the friction out of EUDR compliance by bridging the natural gaps between ESG oversight and supply chain execution. With the right system in place, ESG gains visibility into operational workflows, and supply chain gains clear compliance guidance without needing to become legal experts.

In practice, this looks like:

  • Compliant processes built-in: Supplier data needs are pre-set through questionnaires and guides, so supply chain teams know exactly what to collect. Risks are surfaced in a streamlined platform, visible to both ESG and supply chain. Shipments can’t progress until all information is uploaded, checked, and signed off eliminating the need for constant back-and-forth meetings.
  • AI-driven efficiency: Automated checks and risk scoring reduce human touchpoints and highlight potential issues early, minimising errors and delays.
  • One-click DDS generation: Once data is complete, the system produces a Due Diligence Statement in the correct EU TRACES format at the click of a button. Either ESG or supply chain can trigger it with no technical expertise or direct login to TRACES required.

The result is a smoother, faster compliance process where both teams work from the same dataset, stay aligned in real time, and avoid bottlenecks.

By replacing scattered files and email chains with a single platform, both ESG and supply chain teams work from the same real-time dataset which means fewer delays, less duplication, and a stronger audit trail.

{{product-tour-injectable}}

Book a free demo with Coolset today.

FAQs

Who signs off on the DDS under EUDR?

The regulation places responsibility on the operator or non-SME trader placing or exporting the product, not a specific job title. In practice, whoever holds legal accountability in your organisation signs off the DDS. ESG and supply chain teams feed the data; a compliance or legal lead typically owns the submission itself.

Can supply chain teams submit a DDS without an ESG team?

Technically yes, but it's high-risk. Supply chain holds the operational data, but ESG provides the governance structure, audit trail, and legal oversight that makes a submission defensible. Without that layer, a DDS may be operationally complete but fail scrutiny if competent authorities request a review.

Do SMEs need both teams involved?

It depends on size. Micro and small primary operators established as such by 31 December 2024 can use a simplified declaration referencing an existing DDS. Other SME traders still carry full obligations. Either way, some cross-team coordination remains necessary, the scale just differs.

What’s procurement’s role in EUDR?

Procurement determines who enters the supply chain in the first place, making them critical upstream. EUDR turns supplier selection into a legal consideration. Procurement needs to embed deforestation-free and legality criteria into sourcing decisions, working alongside supply chain and ESG from the start, not after risks are flagged.

Can third parties replace internal coordination?

No. Platforms and certification bodies can support data collection and verification, but legal responsibility for the DDS stays with the operator or non-SME trader. External tools reduce operational burden, but governance, sign-off, and audit-readiness still require clear internal ownership that no third party can substitute.

How to operationalize EUDR compliance in 2026

Read our tailored guide, learn how to build traceability and run audit-proof risk assessments

See Coolset in action
Explore Coolset's top features and use cases.
Demo is not supported
on mobile screens
Please come back on a larger screen
to experience this demo.
This is a preview window. Click below to see the demo in a larger view.
See product tour
See product tour
See product tour
See product tour
See product tour
See product tour

↘ Instantly calculate your CBAM cost impact

Use the free calculator to estimate your Carbon Border Adjustment Mechanism costs for any imported goods. Select your product type, volume and country of origin to see projected CBAM charges and understand how upcoming EU rules will shape your import costs and savings through 2034.

↘ Check if your documentation meets PPWR requirements

This free compliance checker scans your packaging documentation and maps it against mandatory PPWR data requirements, giving you a clear view of your compliance status. Get actionable insights on documentation gaps before they become compliance issues.

Unify ESG and supply chain compliance with Coolset

Coolset’s EUDR module gives both teams one platform to collect supplier data, run risk assessments, and generate Due Diligence Statements.

Download our 2026 EUDR playbook

Based on customer case studies our team has developed a realistic timeline and planning for EUDR compliance. Access it here.

🎉 Thank you!
You will receive an email with the playbook
Oops! Something went wrong while submitting the form.

The leading ESG platform for mid-market enterprises