“What is the evidence behind your EUDR claim?”
It is a seemingly simple question, but according to National Competent Authorities (NCAs), it is becoming one of the most important questions that companies need to be able to answer as they prepare for the EU Deforestation Regulation (EUDR).
Over recent weeks, the Satelligence team has had the opportunity to hear directly from NCAs and exchange thoughts and ideas with industry peers across industry events. Most recently, we heard insights from the Dutch Food and Consumer Product Safety Authority (NVWA) regarding its latest dry runs. The NVWA shared its experience from the initial dry runs in which companies’ due diligence systems were audited. The message has been consistent: having the information is not the same as carrying out due diligence.
A company needs to be able to show how it has assessed the available information, what it has concluded from this analysis, and why the measures it has taken are sufficient to address any identified risks.
As the 30th December enforcement date approaches, Satelligence has collected these insights into key indications of what companies need to be focusing on right now.
Insight 1: Due diligence goes beyond collecting information
At this point, most companies do have the supply chain data needed for compliance. But data and documentation alone does not demonstrate due diligence.
The question that inspectors are likely to ask is: “What is the evidence for that conclusion?”
That evidence should be verifiable and the reasoning behind the conclusion should be clear. This also stands for cases where information may not align; if two sources produce conflicting results, according to the NVWA, this conflicting evidence should itself be treated as a potential supply chain risk.
Insight 2: A platform cannot replace a due diligence process
Technology can support EUDR due diligence, but using a platform alone is not sufficient. This distinction came through clearly in the NVWA’s dry-run findings. Platforms and external systems are an ideal solution for helping companies to collect, organise, and analyse supply chain data, but it is the due diligence process around the technology that matters.
That includes how the data is selected and assessed, and how conclusions are reached and decisions are documented. A well-designed Due Diligence System (DDS) therefore needs to support a logical and repeatable workflow.
This is also where the NVWA emphasised the importance of integrating due diligence into wider business processes, including procurement. Where EUDR requirements sit separately from sourcing decisions, it can be difficult to make due diligence truly systemic.

By using an API that integrates directly with existing workflows, companies can submit due diligence statements directly to the EU Information System, TRACES.
Insight 3: Chain of custody needs to connect the dots
Another recurring theme was traceability, specifically the connection between a product placed on the EU market and its claimed origin.
During one of the NVWA dry runs, one company underwent both document checks and an onsite assessment of its due diligence system and governance. One of the key lessons shared was the importance of being able to demonstrate the chain of custody connecting the shipment to its claimed source.
For example, knowing that a supplier sources soy from 20 plots does not, on its own, demonstrate that the 1000 tonnes being placed on the EU market came from those plots. If the soy is mixed with volumes from other sources along the supply chain, the company needs to be able to demonstrate the physical link between the product and the origin it assessed. This is where a verifiable chain of custody becomes important.
Insight 4: More documents do not necessarily mean better due diligence
The above principle also applies to legality. When assessing legality, companies need to consider a range of laws and supporting documents. But the NVWA made an important distinction that there is no single document (nor, in fact, fixed set of documents) that automatically demonstrates compliance. Instead, inspectors want to understand the reasoning behind the documents selected.
Consider the following:
- Why were these particular documents requested?
- Why are they relevant to the plot, supplier, or product being assessed?
- What do they tell you about the identified risk?
- How do they support the conclusion that was reached?
The overarching idea is that documentation should support a rationale, rather than become the rationale itself.

The teams best prepared for navigating the NCA investigations will those be able to submit DDS efficiently through a streamlined process.
Insight 5: Certification can support, but not replace, due diligence
Certification schemes can provide valuable information within a due diligence process. The NVWA specifically discussed schemes including FSC, RSPO, and MSPO, whilst also noting that certification is currently being further investigated in the context of the EUDR audits.
Whilst certification is a supporting element, companies need to understand what a particular certification scheme actually demonstrates in the context of their EUDR assessment. The same principle applies to government or industry-wide systems; although potentially valuable thanks to their ability to provide a more structured and harmonised approach, their role still needs to be understood in relation to the operator’s own EUDR responsibilities.
Insight 6: A good DDS needs to work in practice
Perhaps the most obvious lesson is that EUDR compliance is not about having a system in place on paper – the system absolutely must work in practice.
The NVWA described the importance of a DDS that is robust, adaptable, and capable of identifying and addressing issues when they arise. A single mistake does not necessarily indicate that an entire process is falling; what matters is whether the system allows those issues to be identified, investigated, corrected, and then learned from. Meaning: Due diligence is an ongoing workflow rather than a one-off compliance exercise.
It also means that companies need to be looking critically at their existing processes and asking:
- Can our employees follow the process consistently?
- Can the reasoning behind decisions be understood by someone outside of the team?
- Can an inspector follow the chain from source data to analysis to conclusion?
- And if something doesn’t add up, does the process make it clear what happens next?
Enforcement may not necessarily look the same everywhere
With all of the above in mind, another thing that companies should be prepared for is the variation in how EUDR checks are carried out across the different member states. NCAs may take different approaches to when and how they conduct checks, including how they look at shipments, volumes, and documentation.
As enforcement begins, the sector will learn more about how these approaches work in practice. For companies, this makes it even more important to focus on the robustness of their due diligence.
So, what should companies be asking now?
The NCA dry runs suggest that companies have made progress, but that significant gaps remain; in the NVWA’s latest round, only two of ten companies passed the full audit.
For companies that have not yet started preparing, the message is very straightforward: EUDR readiness takes time. Start now.
And for those that already have systems in place, the next step is not necessarily to collect more data, but rather critically assess whether your existing due diligence process can stand up to scrutiny. A useful starting point would be to consider the following questions:
- How robust is our analysis?
- Can we demonstrate the physical link between the product and its origin?
- Why did we select this particular information or documentation?
- How do we provide proof that our mitigation measures address the deforestation risks we identified?
- Is due diligence embedded into our sourcing and procurement process, or does it sit separately?
Ultimately, the strongest EUDR due diligence system is not necessarily the one with the most data, but the one where the journey from analysis to risk to decision is clear, consistent, and defensible.
