EUDR due diligence rests on three steps: collecting specific information about a product's origin, assessing the deforestation risk that information reveals, and taking action to reduce any risk identified. The output is a due diligence statement, submitted to the EU's Information System before a product is placed on the EU market or exported from it.
That sounds simple written down. In practice, it is the single biggest operational challenge in EUDR compliance for food and beverage businesses, because most supply chain data was never designed to answer this specific question. Here is what each step actually requires.
Step one: information collection
The information requirement has two parts. First, geolocation data identifying the specific plot of land a commodity was produced on, accurate enough to distinguish that plot from its neighbours. This typically means polygon coordinates rather than a point marker, and for cattle, geolocation of the establishment where the animals were raised.
Second, evidence of legal production under the laws of the country of origin. This covers land tenure and land use rights, environmental permits where required, and documentation confirming compliance with local labour and human rights law. If you cannot source it, you cannot include it in the statement.
For food and beverage businesses, the practical bottleneck is almost always geolocation data on the smallholder or first-tier aggregator end of the supply chain, particularly for cocoa and coffee. A single finished product can trace back to dozens of small plots across multiple countries, and that data usually sits furthest from the buyer trying to report it.
Step two: risk assessment
Once the information is collected, it needs to be assessed against deforestation risk. The EU has already done part of this work through a country risk tiering system, classifying countries as low, standard, or high risk per commodity. That classification determines how much scrutiny a given sourcing relationship needs.
Sourcing from a low-risk country allows a simplified due diligence procedure. Standard and high-risk sourcing requires the full assessment: evaluating the geolocation and legality evidence against the complexity of the supply chain, the reliability of the supplier, and any history of non-compliance.
This is not a one-off exercise. A supplier assessed as low-risk two years ago may have expanded into new plots or moved into a different sourcing region since. Ongoing monitoring, not a single point-in-time check, is what actually holds up under scrutiny.
Step three: risk mitigation
Where the risk assessment identifies anything above negligible risk, the operator has to act on it before the product can be placed on the market. That might mean requesting further evidence from a supplier, commissioning an independent verification, or in higher-risk cases, sourcing the commodity elsewhere.
The regulation does not prescribe a single mitigation method. It requires that whatever action is taken brings the risk down to negligible, and that the reasoning is documented well enough to survive an audit from a competent authority.
Who actually has to submit a due diligence statement?
This is where recent changes have made a real difference. Under the current framework, only the operator first placing a commodity on the EU market has to submit a full due diligence statement. A cocoa importer bringing raw cocoa into the EU submits one. A chocolate manufacturer using that cocoa does not need to submit a second statement, they reference the importer's existing one instead.
Micro and small primary operators, typically farmers and smallholder cooperatives in producing countries, have an even lighter route: a simplified, one-time declaration rather than a full statement. The Commission's May 2026 simplification review confirmed this framework will not be reopened before the December 2026 and June 2027 application deadlines.
Downstream operators and non-SME traders that are not the first placer still have obligations, but they are narrower: registering in the Information System to reference the relevant due diligence statement numbers, and flagging any concrete indication of non-compliance to the competent authority if it comes to light.
Common gaps in food and beverage due diligence
A few patterns show up repeatedly across food and beverage supply chains preparing for EUDR:
- Animal feed is frequently missed. Soya used in feed puts a business in scope even when soya never appears as an ingredient on a label.
- Geolocation data arrives in inconsistent formats. Suppliers send coordinates as text in emails, screenshots, or spreadsheets with no standard structure, which makes it hard to verify or aggregate.
- Certification is treated as a substitute for data, not a supplement to it. A valid FSC or RSPO certificate is useful supporting evidence, but it does not remove the requirement to hold plot-level data behind it.
- Due diligence is treated as an annual event rather than a continuous process. Supplier risk changes over time, and a due diligence statement is only as good as the data behind it on the day it is checked.
Building a due diligence process that scales
The organizations that find this manageable are the ones treating due diligence as a data infrastructure problem, not a reporting exercise. That means a central place to collect geolocation data at the required precision, check supplier certification automatically rather than manually, run standardised risk assessments that reflect the EU's own country risk tiers, and store the underlying evidence so it is ready before an authority asks for it.
Ideagen Supply Chain is built around exactly that structure: unlimited supply chain mapping through the tiers, tracing suppliers to source with geolocation polygons to six decimal places at supplier and farm level, automated certification checks against FSC, RSPO, and RTRS, customized or standardized audits that benchmark supplier risk over time, and centralized document storage, including EUDR-specific supplier questionnaires and the ability to reference and audit upstream due diligence statements, for the evidence a due diligence statement depends on. It is worth being direct about the boundary here: this is the supplier due diligence, risk-screening, and documentation layer done well, and the natural system of record for whatever plot data suppliers provide. Verifying an individual plot against satellite deforestation data, and attributing a specific batch to its exact contributing plots, sits a layer deeper than supplier-level mapping and needs its own defined process on top. Getting the supplier layer right once, in one place, is still a smaller job than rebuilding the same data collection exercise for every regulation that follows EUDR.
Explore food & beverage solutions
One contamination event. One missed audit. One gap in your supply chain. That's all it takes to undo years of hard-won consumer trust. One connected platform. Every food and beverage challenge covered.