EUDR compliance is not only about having the right data, but being able to demonstrate why a due diligence decision was made, what evidence supported it, and how many gaps or inconsistencies were addressed. Here are teh key questions raised during our recent webinar on what defensibility means in practice.
You asked, we answered…
During our recent webinar with our partners EY and Prewave, attendees submitted questions on topics ranging from evidence that needs to be retained, to the role of satellite monitoring, certification schemes, local expertise, and smallholder traceability.
Across these questions, one theme came through repeatedly: defensibility is not about having a perfect set of documentation, but being able to explain and evidence how you reached your conclusion.
For the remainder of this blog, we have grouped together the questions and answers according to core themes.
What makes an EUDR diligence decision defensible?
A defensible decision requires a consistent risk assessment methodology, relevant legality checks, documented mitigation, and a clear rationale for the final conclusion. In practice, this means maintaining a transparent record of how your decision was reached, especially when handling conflicting data sources.
In practice, this means being able to reconstruct the decision-making process (especially if you have different sources telling different stories):
- What information did you start with?
- How reliable was it?
- What risks did you identify?
- What additional checks did you carry out?
- Why did the evidence support the conclusion?
Supplier information, geolocation data, legality documentation, and satellite monitoring may sometimes point in different directions. This may not automatically mean that the DDS process has failed; the crucial thing that National Competent Authorities (NCAs) will be looking for is how you handled that inconsistency.

No singular approach is conclusive – NCAs in dry runs have expressed a lot of focus on protocol, consistency, documentation, and reasoning.
Feedback from NCA dry-runs has reinforced that conflicting evidence can itself be a potential supply chain risk – this is why companies need to be prepared to explain not only the conclusion they reached, but how they got there.
A clear evidence trail should make clear:
- What information was conflicting
- What additional investigation was carried out
- Which sources and methodologies were considered
- What residual uncertainty remained
- Why the final risk conclusion was reasonable and consistent with the company’s documented approach
Assessing legality in the country of production
Deforestation is in fact only one part of EUDR compliance. Companies need to consider relevant legislation in the country of production, including land-use rights, environmental protection, third-party rights, and relevant labour and human rights requirements where these fall within the Regulation’s legality scope.
This makes legality inherently country- and context-specific; there is no universal set of documents that automatically demonstrates compliance. The appropriate evidence depends on the legal framework, the supply chain, the risks identified, and the reliability of the available information.
Legality guidance and country-specific resources can be valuable in helping operators understand what legislation applies, what information is available and where further investigation may be needed. But paperwork alone may not tell the full story; where risks concern land tenure, Indigenous Peoples’ rights, labour or local environmental requirements, desktop research may need to be complemented by local expertise or stakeholder input.
The key is to apply a risk-based approach that considers both what the documents show and what is happening in practice.
Polygon to evidence trail: how different data sources work together
The EUDR requires geolocation of production plots – for plots larger than four hectares, this means polygon coordinates. Satellite imagery does not replace that polygon evidence, but rather helps to assess what has happened within and around the submitted production area.
At Satelligence, we combine multiple sources, including optical and radar satellite imagery, forest, and commodity layers and other contextual datasets, each providing a different piece of the evidence.
When supplier information, geolocation, legal documentation, and satellite monitoring point in different directions, these discrepancies should trigger further investigation rather than selecting only the favorable data.
A robust process documents why sources differ, how their quality was evaluated, and why the final risk conclusion remains sound despite any residual uncertainty.

It is possible for credible sources to disagree, hence the need for a robust process to explain why sources differ, how their quality was evaluated, and how the final conclusion was reached.
Where do certification schemes fit into EUDR due diligence?
Certification schemes such as FSC, RSPO, and MSPO can provide useful information and may contribute to a company’s risk assessment. However, they should be considered as supporting evidence rather than a substitute for EUDR due diligence.
Certification may reduce perceived risk or provide assurance around particular practices, but certified companies can still be subject to checks by NCAs. The same applies when considering certification as evidence of legality: it can form part of the overall evidence base, but it does not remove the operator’s responsibility to conduct due diligence under the EUDR.
The practical question is therefore not whether certification counts for EUDR, but how it fits into the wider evidence trail. Companies should understand what their certification covers, how it relates to the specific risks they need to assess, and what additional information or checks may still be required.
Making EUDR work in complex and smallholder supply chains
Smallholder supply chains can make EUDR traceability particularly challenging, with fragmented sourcing, uncertain plot boundaries, and multiple intermediaries or aggregation points. For smallholder coffee or oil palm, for example, the challenge is often linking available traceability data to the right production areas and identifying where additional investigation is needed.
Combining practical traceability collection with geospatial risk screening can help. Commodity, mill, and concession data can provide additional context around where production and potential land-use risks are concentrated, while plot-level information can connect that landscape picture to individual producers where available.
The same principle applies to cost: a defensible system needs to be robust enough for scrutiny, but practical enough to operate at supply-chain scale. The aim should be to identify and manage risk without making compliance itself a reason to exclude smallholders from EU supply chains.
What should companies expect from December 2026?
For companies preparing for EUDR, the safest assumption is that the Regulation will apply from 30 December 2026. The focus should therefore be on testing whether processes work in practice, rather than waiting for further developments.
The main bottlenecks are likely to be less about submitting a DDS and more about what sits behind it: incomplete traceability data, inconsistent supplier engagement, unresolved legality or risk cases, conflicting sources and weak documentation of decision-making.
NCAs are expected to take a risk-based approach, with greater attention to higher-risk operators, products, and DDSs. Companies should therefore be prepared to demonstrate not only that they submitted the required information, but that they have a coherent process behind their conclusions.
For practical questions about how the EUDR applies, companies should contact their relevant Member State Competent Authority. Technical questions about the EUDR Information System and TRACES should be directed to the European Commission’s dedicated support channel.
Do you truly understand your supply chain?
The questions raised during our webinar reflect a broader shift in how companies are approaching EUDR. The focus is moving beyond “Do we have the required data?” towards “Can we demonstrate that we used that data appropriately to reach a reasonable conclusion?”
A defensible process does not require every uncertainty to disappear or every source to tell exactly the same story. It requires companies to understand the evidence they are working with, investigate relevant inconsistencies, apply a consistent methodology, and keep a clear record of the reasoning behind their decisions.
EUDR readiness is therefore not simply about assembling the right documents or putting a platform in place. It is about building a process in which decisions can be explained, evidenced and defended when they are scrutinised.
