The United Nations Guiding Principles on Business and Human Rights, endorsed by the UN Human Rights Council in 2011, established that every business enterprise has an independent responsibility to identify, prevent, mitigate, and account for adverse human rights impacts in its operations, supply chain, and business relationships [1]. The OECD Due Diligence Guidance for Responsible Business Conduct, published in 2018, operationalized that responsibility as a six-step process: embed responsible business conduct into policies and management systems; identify and assess adverse impacts; cease, prevent, or mitigate impacts; track implementation and results; communicate how impacts are addressed; and provide for or cooperate in remediation when appropriate [2].
What was guidance is now law across multiple jurisdictions. The European Union's Corporate Sustainability Due Diligence Directive entered into force on July 25, 2024; following the Omnibus simplification package, in-scope companies are those with more than 5,000 employees and net worldwide turnover above EUR 1.5 billion, with phased application beginning July 26, 2027 [3]. Germany's Lieferkettensorgfaltspflichtengesetz (LkSG) has applied to companies with at least 1,000 employees in Germany since January 1, 2024; the Federal Office for Economic Affairs and Export Control (BAFA) conducted 851 ex officio audits in 2024 and initiated administrative fine proceedings in 18 cases [4]. Norway's Transparency Act requires in-scope enterprises to publish an annual due diligence report by June 30 and respond to public information requests, with penalties up to 4% of annual turnover or NOK 25 million [5]. In the United States, U.S. Customs and Border Protection enforcement of the Uyghur Forced Labor Prevention Act detained an average of 428 shipments per month in 2024 with USD 1.34 billion in merchandise detained over the year; approximately 48% of detained shipments were ultimately denied [6].
The architectural question that determines whether a company's diligence holds under operational and enforcement pressure is allocation. Procurement controls the buying decision and the supplier relationship. Sustainability owns the disclosure and the framework. Legal owns the contractual instruments and the litigation exposure. Operations owns the production schedule that drives the sourcing decision. The corporate-responsibility frameworks describe the diligence as a single integrated obligation. The internal organization of every multinational distributes that obligation across four functions whose incentives and reporting lines diverge.
The diagnostic question is no longer whether a company has a supply chain policy. It is which function is accountable for each tier of the diligence, whether the allocation is documented at the level of decision rights rather than at the level of policy text, and whether the operational decisions made under time and cost pressure converge with the diligence the company has publicly committed to perform.
Six instruments now describe the same substantive obligation in different jurisdictions and at different points of legal force.
The United Nations Guiding Principles on Business and Human Rights, unanimously endorsed by the UN Human Rights Council in June 2011, set out the three-pillar framework that has anchored every subsequent regulatory regime in this domain. Pillar II, the corporate responsibility to respect human rights, requires every business enterprise to identify, prevent, mitigate, and account for adverse human rights impacts with which it is involved, whether the involvement is direct, through a business relationship, or through products or services [1]. The instrument is soft law in itself; it has become the substantive content of mandatory law across jurisdictions.
The OECD Due Diligence Guidance for Responsible Business Conduct, published in 2018 under the OECD Guidelines for Multinational Enterprises, operationalizes the UNGP obligation as a six-step risk-based process: embed responsible business conduct into policies and management systems; identify and assess actual and potential adverse impacts; cease, prevent, or mitigate adverse impacts; track implementation and results; communicate how impacts are addressed; and provide for or cooperate in remediation when appropriate [2]. The framework applies across human rights, employment and industrial relations, environment, bribery, consumer affairs, and information disclosure. Sector-specific OECD guidance documents, including the OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas, apply the same six-step methodology to specific risk domains [7].
The European Union's Corporate Sustainability Due Diligence Directive (Directive (EU) 2024/1760) entered into force on July 25, 2024. The directive requires in-scope companies to conduct due diligence across their own operations, their subsidiaries, and their chains of activities, including direct and certain indirect business partners. Following the Omnibus I simplification package adopted in 2025-2026, the in-scope threshold has been raised to companies with more than 5,000 employees and EUR 1.5 billion in net worldwide turnover; non-EU companies are in scope if they generate EUR 1.5 billion in net turnover within the European Union [3]. Phased application begins on July 26, 2027 for the largest companies.
Germany's Lieferkettensorgfaltspflichtengesetz (LkSG, the Act on Corporate Due Diligence Obligations in Supply Chains) applies to companies with at least 1,000 employees in Germany as of January 1, 2024; the threshold was 3,000 employees in 2023. The Federal Office for Economic Affairs and Export Control (BAFA) administers the act. In 2024, BAFA conducted 851 ex officio audits including 638 risk-based controls and 39 occasion-related audits. BAFA initiated administrative fine proceedings in 18 cases. Maximum penalties are EUR 8 million for intentional or negligent violations of due diligence obligations, with separate fines up to EUR 50,000 for failure to take required action [4].
Norway's Transparency Act (Åpenhetsloven), in force since 2022, requires in-scope enterprises to conduct due diligence across their own operations and supply chains under the OECD Guidelines methodology, publish an annual due diligence report by June 30, and respond to public information requests within three weeks. The Norwegian Consumer Authority is the enforcement body; penalties run up to 4% of annual turnover or NOK 25 million, whichever is higher [5].
The Uyghur Forced Labor Prevention Act, in force in the United States since June 2022, establishes a rebuttable presumption that goods produced in whole or in part in Xinjiang or by entities on the UFLPA Entity List are made with forced labor and prohibited from importation under 19 U.S.C. § 1307. U.S. Customs and Border Protection detained an average of 428 shipments per month in 2024 with USD 1.34 billion in merchandise detained; approximately 48% of detained shipments were ultimately denied. The CBP Electronics Center of Excellence and Expertise recorded the highest sector volume; the automotive and aerospace sector recorded the steepest growth, with a roughly 1,000 percent surge in November 2024 detentions [6].
The substantive obligation across instruments converges. The differences sit in scope, in disclosure requirements, in enforcement mechanism, and in penalty exposure. The compliance question is not which instrument applies. It is what the architecture of the company's actual diligence is, and whether that architecture can survive simultaneous evaluation under all the applicable instruments at once.
The corporate-responsibility frameworks describe the diligence as a single integrated obligation belonging to the enterprise. The internal organization of every multinational distributes that obligation across four functions whose incentives and reporting lines diverge.
Procurement owns the buying decision, the supplier relationship, the unit-cost target, and the lead time. Procurement's performance is measured against price, quality, and delivery. The function carries the operational view of the supply base, including the supplier behaviors that are not visible from the disclosure framework. Procurement decisions, made at the level of category strategy, supplier selection, and purchase order, are where the diligence becomes operational or does not.
Sustainability or environmental, social, and governance owns the policy framework, the public disclosure, the supplier code of conduct, and the audit program. Sustainability's performance is measured against framework adoption, disclosure quality, and stakeholder ratings. The function carries the framework view of the supply chain, including the published commitments against which the company will be judged. Sustainability typically does not own the supplier decision and does not control procurement's incentive structure.
Legal owns the contractual instruments, the regulatory interpretation, the litigation exposure, and the response to enforcement inquiry. Legal's performance is measured against risk reduction, defensibility, and absence of escalated proceedings. The function carries the documentary view of the supply chain, including the warranties and representations the company has obtained from suppliers and the indemnification it has secured. Legal typically does not own the operational decision and does not have direct visibility into supplier site practices.
Operations owns the production schedule, the inventory model, the supplier qualification for technical performance, and the engineering specifications. Operations' performance is measured against throughput, quality, and cost. The function carries the production view of the supply chain. Operations decisions, including which supplier to qualify for a new program and how to respond to a supplier capacity constraint under deadline, are where time pressure intersects with the diligence the company has committed to.
The OECD six-step due diligence process is observable as a single integrated process inside the framework. Inside the company, each of the six steps falls across the four functions. Embedding responsible business conduct into management systems is a sustainability and legal effort that becomes operative only when procurement and operations apply it to actual decisions. Identifying and assessing adverse impacts is a sustainability function whose outputs depend on procurement and operations sharing the supplier and operational data. Ceasing, preventing, or mitigating adverse impacts is an operational decision constrained by procurement's category strategy and legal's contractual framework. Tracking implementation requires data flow across all four functions. Communicating how impacts are addressed is a sustainability and legal function whose accuracy depends on procurement and operations sharing what the diligence actually produced. Providing for or cooperating in remediation is a cross-functional decision that requires senior alignment.
The allocation question is whether the four functions hold the six steps as a single integrated obligation or as four overlapping partial obligations. Where the allocation is partial, the diligence becomes the sum of what each function chooses to contribute under its own incentive structure. Where the allocation is integrated, the diligence becomes a process the enterprise can defend as a single coordinated activity.
The OECD Due Diligence Guidance for Responsible Business Conduct describes the six steps in operational terms. Applied to a supply chain at the level of decision rights rather than at the level of policy text, the steps have an architectural anatomy.
Step 1, embedding responsible business conduct into policies and management systems, becomes operative when board-level governance instruments are in place; when a senior executive owns the diligence at the enterprise level; when policy documents are translated into procurement category strategies, supplier qualification criteria, contractual standard terms, and operational decision rules; and when the policy is treated as binding on the operational decision, not as aspirational commentary [2].
Step 2, identifying and assessing actual and potential adverse impacts, requires a mapping of the supply chain across tiers, a risk assessment that incorporates sector, geography, and product-specific risk, and a prioritization that focuses diligence resources on the highest-risk supplier-product-geography combinations. The mapping is operational only if it reaches beyond Tier 1 to the tiers where the most acute risks typically sit, including raw-material extraction in the case of minerals and metals, fiber production in the case of textiles, and component manufacturing in the case of electronics [2, 7].
Step 3, ceasing, preventing, or mitigating adverse impacts, is the operational test. Decisions in this step include disengagement from a supplier, capacity-building programs with a supplier, joint remediation with affected stakeholders, and re-engineering of the procurement specification to remove the risk. The substantive test is whether the company has the operational latitude to make these decisions when the procurement category strategy, the production schedule, and the customer commitment are running in the opposite direction.
Step 4, tracking implementation and results, requires the company to define what success looks like for each diligence activity and to measure progress against that definition. The data systems required include supplier-level performance data, incident and complaint data, audit findings, and remediation status. Where data systems are fragmented across procurement, sustainability, legal, and operations, the tracking step is a reconciliation problem before it is a performance-management problem.
Step 5, communicating how impacts are addressed, is the disclosure step. The instruments include statutory transparency reports under the Norwegian Transparency Act and the German LkSG, the annual statement under the UK Modern Slavery Act, and the disclosures under the EU Corporate Sustainability Reporting Directive and the Corporate Sustainability Due Diligence Directive. The communication step is operational only if its content reflects what steps 1 through 4 produced, not what the disclosure framework requires irrespective of the underlying activity.
Step 6, providing for or cooperating in remediation when the enterprise has caused or contributed to an adverse impact, is the test that distinguishes an integrated diligence program from a ceremonial one. Remediation includes grievance mechanisms, compensation, restoration of affected rights-holders to the position they would have been in absent the harm, and reform of the practice that caused the harm. The instruments under which remediation is now legally required include the CSDDD, the LkSG, the OECD National Contact Point system, and the Norwegian Transparency Act [3, 4, 5, 8].
Supply chain mapping and screening are domains where machine learning and large-scale data extraction have produced operational improvements. Automated supplier discovery against sanctions lists, entity lists, and adverse media data sources is now operationally faster than manual screening. Automated mapping of multi-tier supply relationships through trade, import, and corporate-registry data has reached a point where mapping of supplier networks beyond Tier 1 is possible at scale. Automated monitoring of supplier sites through geospatial data, port data, and labor-condition reporting has expanded what diligence teams can see between formal audit cycles.
What these tools change is the speed and breadth of step 2 (identification and assessment) and step 4 (tracking). What they do not change is the substantive judgment at steps 1, 3, 5, and 6. The decision to embed a particular responsible business conduct standard into procurement category strategy is a corporate decision. The decision to disengage from a supplier, to invest in capacity-building, or to re-engineer a specification is an operational and commercial decision with consequences for customers, suppliers, and affected rights-holders. The decision about what to communicate publicly under the disclosure regimes is a regulatory and reputational decision. The decision about what remediation is owed to affected stakeholders is a corporate, legal, and ethical decision.
The risk of AI-enabled supply chain tools is that the tooling produces an artifact, a multi-tier map, a risk score, a flagged shipment, that has the appearance of diligence and is treated as the diligence. The OECD framework requires the substantive activity. The tools can support steps 2 and 4. They cannot perform steps 1, 3, 5, or 6 on the enterprise's behalf. Where the tools are used as the diligence rather than as inputs to the diligence, the same architectural failure pattern observed in quality systems applies: the artifact remains intact while the operational decision behind it is not made.
The enforcement record across the six instruments documents a consistent pattern. BAFA's 2024 report describes most German LkSG-covered companies as taking due diligence seriously, with administrative fine proceedings initiated in only 18 cases against 851 audits [4]. CBP's UFLPA enforcement record shows growing detentions volume, growing denial rates, and growing sectoral coverage, with electronics, automotive, and aerospace as 2024 focal sectors [6]. The Norwegian Consumer Authority's enforcement record under the Transparency Act has so far emphasized compliance support over fines, with information requests and corrective orders as the primary instruments. The CSDDD's enforcement framework, with administrative penalties up to 5% of net worldwide turnover for the most serious infringements, has not yet been operationalized at member-state level given the 2027 application date [3].
The accountability inquiry that follows is sharper than the enforcement record suggests. The Justice Department's September 2024 update to the Evaluation of Corporate Compliance Programs, while not specific to supply chain due diligence, has established the operational standard that prosecutors now apply to compliance programs across domains: a program is judged on whether it operates against the risk it is designed to address, whether it has the data and resources required, and whether it evolves based on lessons learned [11]. The same standard, applied to supply chain HRDD, asks whether the diligence operates against the human rights and environmental risk it is designed to address.
For boards, the implication is the same allocation question. A supply chain due diligence report that documents policy coverage, supplier code-of-conduct adoption, audit completion rates, and the number of corrective actions opened is the documented program. A report that documents the operational metrics, the share of procurement category strategy decisions that were taken with diligence input, the share of supplier disengagement decisions taken on human rights grounds, the share of remediation cases resolved with affected stakeholder participation, and the cycle time from incident identification to substantive corrective action, is the operational program. The boards that receive only the first report cannot meet the inquiry the six jurisdictional regimes now describe.
A decade after the UN Guiding Principles established the corporate responsibility to respect, six jurisdictions now operate mandatory human rights due diligence regimes in parallel. The OECD six-step process describes a substantive diligence obligation that does not change across the instruments. What changes is which company is in scope, when, and what penalties attach to failure to perform the diligence.
The institutional question that distinguishes credible diligence from ceremonial diligence is allocation. Procurement, sustainability, legal, and operations each hold parts of the six steps. Where the four functions hold the six steps as a single integrated obligation, the diligence becomes a process the enterprise can defend. Where the allocation is partial, the diligence becomes the sum of what each function chooses to contribute under its own incentive structure, and the gap between the disclosure framework and the operational decision is what enforcement, litigation, and reputational scrutiny will reach.
The leadership inquiry is not whether the company has a supply chain policy. It is whether the allocation of the six steps across the four functions is documented at the level of decision rights, whether the operational decisions made under time and cost pressure converge with the diligence the company has publicly committed to, and whether the absence of that convergence is visible to leadership before it is visible to a regulator, a customer, or a litigant.
For boards and senior executives at companies in scope of any of the six instruments described, the 2024-2026 record describes operational implications that are time-bound.
Map the four-function allocation. For each of the six OECD steps, identify which function (procurement, sustainability, legal, operations) is accountable, which is consulted, which is informed, and which has decision rights. Identify the steps where accountability is split, unclear, or absent. The audit question is whether the diligence is owned at the level of decision rights or only at the level of policy text.
Conduct a tier mapping that reaches beyond Tier 1 in at least the highest-risk product-geography combinations. For minerals and metals, the mapping should reach the smelter or refiner tier; for textiles, the fiber tier; for electronics, the component-manufacturing tier. Identify the gap between the mapping the company holds today and the mapping the OECD six-step framework presumes.
Restructure the board-level supply chain or sustainability report to distinguish documented program performance from operational performance. Operational metrics should include the share of procurement category strategy decisions taken with diligence input, the share of supplier disengagement and capacity-building decisions taken on human rights or environmental grounds, the share of remediation cases resolved with affected stakeholder participation, and the cycle time from incident identification to substantive corrective action. Establish a board-level review of supply chain due diligence on at least an annual basis, with the audit or risk committee as the standing forum.
Build feedback loops between supplier-site data, enforcement signals in operating jurisdictions, and the company's own procurement and operational decisions. The CBP UFLPA enforcement data, the BAFA LkSG enforcement data, the Norwegian Consumer Authority transparency reports, and the published CSDDD member-state enforcement positions, once they emerge, should inform the company's risk assessment as a matter of standing process.
A material revision to the CSDDD scope or implementation timeline beyond the current Omnibus position, a material expansion of the UFLPA Entity List or its sectoral coverage, a sector-specific OECD guidance update, or an enforcement matter at a peer institution that materially clarifies the regulatory expectation in any of the six jurisdictions would require recalibration of the allocation, mapping, and reporting design.
CSDDD status: The CSDDD scope and timeline cited reflect the Omnibus I simplification position as of the publish date. Further amendments at EU and member-state level may modify thresholds, applicable sectors, and enforcement provisions. The directive's substantive obligations apply as transposed into national law in each member state; transposition variation should be confirmed for each jurisdiction of operation.
LkSG enforcement scope: The BAFA 2024 audit and enforcement figures cited reflect BAFA's published activity. The relationship between the LkSG and the CSDDD as transposed into German law will be refined as Germany completes its CSDDD transposition; the substantive obligations may evolve during the transition.
UFLPA enforcement scope: The CBP enforcement statistics cited reflect the 2024 calendar year. UFLPA Entity List additions, statutory amendments, and CBP guidance updates issued after the data range may extend or qualify the enforcement positions cited here.
OECD guidance scope: The OECD Due Diligence Guidance for Responsible Business Conduct cited as the operational six-step framework is the 2018 publication. Sector-specific OECD due diligence guidance documents apply specialized methodologies to particular risk domains; the framework's general application across regulated industries does not displace the sector-specific methodologies where they apply.
Cross-jurisdictional application: The six instruments cited reflect the most consolidated current mandatory HRDD regimes. Additional mandatory due diligence instruments are in force or in process in Canada, Australia, France, the United Kingdom (Modern Slavery Act), and at the sub-national level in several U.S. states; the absence of those instruments from the primary citation list reflects scope of analysis, not absence of obligation.
[1] United Nations Office of the High Commissioner for Human Rights, "Guiding Principles on Business and Human Rights: Implementing the United Nations 'Protect, Respect and Remedy' Framework," endorsed by UN Human Rights Council Resolution 17/4, June 16, 2011. URL: https://www.ohchr.org/documents/publications/guidingprinciplesbusinesshr_en.pdf
[2] Organisation for Economic Co-operation and Development, "OECD Due Diligence Guidance for Responsible Business Conduct," 2018. URL: https://www.oecd.org/content/dam/oecd/en/publications/reports/2018/02/oecd-due-diligence-guidance-for-responsible-business-conduct_c669bd57/15f5f4b3-en.pdf
[3] European Parliament and Council, "Directive (EU) 2024/1760 on Corporate Sustainability Due Diligence (CSDDD)," entered into force July 25, 2024, with thresholds and timeline as modified by the Omnibus I simplification package. URL: https://commission.europa.eu/topics/business-and-industry/doing-business-eu/sustainability-due-diligence-responsible-business/corporate-sustainability-due-diligence_en
[4] Federal Office for Economic Affairs and Export Control (BAFA), German Lieferkettensorgfaltspflichtengesetz (LkSG, Act on Corporate Due Diligence Obligations in Supply Chains) administrative activity report for 2024, as published. URL: https://www.bafa.de/EN/Supply_Chain_Act/Overview/overview_node.html
[5] Norwegian Storting, "Act relating to enterprises' transparency and work on fundamental human rights and decent working conditions" (Åpenhetsloven, Transparency Act), in force July 1, 2022. URL: https://www.regjeringen.no/en/dokumenter/the-transparency-act/id2890958/
[6] U.S. Customs and Border Protection, "Uyghur Forced Labor Prevention Act Statistics" and enforcement reporting for calendar year 2024, as published in the UFLPA enforcement dashboard. URL: https://www.cbp.gov/newsroom/stats/trade/uyghur-forced-labor-prevention-act-statistics
[7] Organisation for Economic Co-operation and Development, "OECD Due Diligence Guidance for Responsible Supply Chains of Minerals from Conflict-Affected and High-Risk Areas," Third Edition, 2016 (with supplements). URL: https://www.oecd.org/corporate/mne/mining.htm
[8] OECD National Contact Points for Responsible Business Conduct, multilateral grievance mechanism operating under the OECD Guidelines for Multinational Enterprises, as administered by the participating adhering governments. URL: https://www.oecd.org/en/topics/policy-issues/responsible-business-conduct.html
[9] OECD, "OECD Guidelines for Multinational Enterprises on Responsible Business Conduct" (2023 update). URL: https://www.oecd.org/en/topics/policy-issues/responsible-business-conduct.html
[10] U.S. Customs and Border Protection, "Uyghur Forced Labor Prevention Act," operational and statutory authority page including the UFLPA Entity List and implementing guidance. URL: https://www.cbp.gov/trade/forced-labor/UFLPA
[11] U.S. Department of Justice, Criminal Division, "Evaluation of Corporate Compliance Programs (Updated September 2024)," September 23, 2024. URL: https://www.justice.gov/criminal/criminal-fraud/page/file/937501/dl
[12] UK Parliament, "Modern Slavery Act 2015," as amended, including the section 54 transparency in supply chains provision. URL: https://www.legislation.gov.uk/ukpga/2015/30/contents