Inside SOP 01: Building a Defensible EUDR Due Diligence System
Updated: Aug 11

EUDR compliance is not only a legal interpretation exercise .. It is an operating challenge.
The real question for many organisations is not simply, “What does the regulation say?” It is: “How do we turn EUDR requirements into a controlled, repeatable and auditable way of working?”
That is where Standard Operating Procedures become critical.
A defensible EUDR Due Diligence System needs to show more than good intent. It needs to demonstrate that product scope, legal role, route selection, evidence collection, risk assessment, identifier handling, release control and review activity are all managed through a structured process.
Without that process control, EUDR can quickly become fragmented across procurement, compliance, operations, logistics, customs, legal and supplier management.
Why EUDR Needs Process Control
EUDR does not operate effectively as a static checklist. It requires route-based decision-making. Before an organisation can decide what evidence is needed, it must first understand whether the product and activity are in scope, what legal role the organisation is performing, and which compliance route applies. That route determines the operating pathway.
For example, a full due diligence route requires Article 9 information collection, Article 10 risk assessment, Article 11 mitigation where required, and a documented conclusion of no or only negligible risk before release.
A simplified due diligence route still requires the mandatory Article 9 information, but does not routinely require the full Article 10 and Article 11 workload unless contrary information or risk indicators arise.
A downstream traceability route requires direct business partner records and identifier retention where received, but should not automatically duplicate upstream operator due diligence.
In other words, the process must prevent two common failures:
1) Applying too little control where due diligence is required.
2) Applying too much control where the organisation is operating under a downstream or reduced-obligation route.
Both create risk. One creates compliance exposure. The other creates unnecessary operational burden and inconsistent records.
The Key Subprocesses in SOP 01
SOP 01 is structured around five practical subprocesses.
1) Scope, Role and Route Gate
This is the front-end control point. It asks three fundamental questions:
Is the product and activity in EUDR scope?
What legal role is the organisation performing in this specific product flow?
Which compliance route applies?
This matters because EUDR obligations are not the same for every actor, every flow or every transaction. The route must be assigned before evidence collection and release decisions begin. If the role is unclear, the case should be escalated before the organisation proceeds.
2) Operator Route Controls
This subprocess manages the operator routes, including full due diligence, simplified due diligence, and micro or small primary operator treatment.
For full due diligence, the focus is on complete evidence collection, risk assessment, mitigation and release only where no or only negligible risk has been demonstrated.
For simplified due diligence, the key control is eligibility. Low-risk status and route conditions must be evidenced. Simplified does not mean no due diligence. Article 9 information still needs to be captured and retained.
For micro or small primary operator treatment, the process must confirm qualification, declaration coverage and identifier control.
3) Downstream and Re-Import Controls
Downstream obligations need careful handling. Downstream operators and traders need to retain relevant direct supplier and direct commercial client records. Where DDS reference numbers or simplified declaration identifiers are received, these need to be linked to the incoming product flow. However, downstream actors should not routinely repeat upstream due diligence unless legally triggered. That distinction matters.
A controlled SOP helps prevent downstream over-control, while still ensuring that substantiated concerns, missing identifiers and reactive verification triggers are handled correctly.
4) Release and Declaration Handover
A due diligence process is only defensible if release is controlled. SOP 01 separates the due diligence system from the formal Declaration Management process, but defines the handover clearly.
The process requires route-specific evidence to be compiled and validated before handover. Returned DDS reference numbers, verification numbers, simplified declaration identifiers or status confirmations should only be recorded and used once returned through the correct process.
The release gate then confirms that the correct route, evidence, identifier linkage, registration status, export pathway and exception closure requirements have been satisfied before product movement or transaction release.
5) Annual Review and Regulatory Tracking
EUDR compliance is not a one-off implementation exercise. Country-risk status, legal interpretation, internal systems, supplier behaviour and operating practices can change.
That is why the Due Diligence System needs an annual review cycle and regulatory-change tracking.
The process should test scope and role decisions, route-control performance, record retention, exception handling, system configuration, audit findings, public reporting requirements and improvement actions.
This is where the SOP moves from a document into a governance mechanism.
Evidence Retention: The Audit Trail Matters
A defensible EUDR process depends on evidence. That evidence needs to be complete, linked, retrievable and controlled.
Key records include scope decisions, role assessments, route rationale, Article 9 information, geolocation evidence, production date or time range, supplier and client data, legality evidence, risk assessments, mitigation records, declaration handovers, returned identifiers, release decisions, exception logs and annual review outputs.
The important point is not just that records exist. They must be linked to the correct product flow, batch, consignment, annual flow, supplier relationship or declaration coverage.
If evidence cannot be retrieved quickly and connected back to the decision it supports, the process becomes difficult to defend.
Exceptions and Escalation
EUDR processes will generate exceptions. That is normal. The issue is whether those exceptions are controlled.
SOP 01 distinguishes between different types of exception, including role ambiguity, missing identifiers, unresolved risk, product blocks and substantiated concerns.
This distinction is important because not every issue should be treated the same way.
A missing identifier from a known upstream operator may need to be handled as a traceability exception.
A substantiated concern is different. It involves credible information suggesting possible non-compliance and may require escalation, investigation, notification and verification activity.
A mature process should therefore separate ordinary operational exceptions from genuine compliance concerns. That helps teams avoid both under-escalation and unnecessary over-escalation.
Why Roles and RACI Matter
EUDR compliance crosses functional boundaries. Procurement may hold supplier information. Operations may understand product flow. Compliance and Legal may interpret role and route obligations. Declaration Management may handle formal submissions. Systems teams may own the workflow, repository and access controls.
Without clear ownership, gaps appear. Who confirms the legal role? Who gathers evidence? Who decides whether risk is negligible? Who blocks release? Who receives returned identifiers? Who handles substantiated concerns? Who owns the annual review?
A RACI model makes these responsibilities visible. It clarifies who is Responsible, who is Accountable, who must be Consulted and who needs to be Informed. That clarity reduces duplication, prevents hand-off failures and supports a more auditable operating model.
Risk Management Built In
EUDR risk is not limited to supplier risk. It includes scope errors, legal-role misclassification, misuse of simplified due diligence, incomplete Article 9 data, unresolved supply-chain complexity, poor identifier linkage, missing escalation, weak retention and outdated regulatory logic.
SOP 01 treats these as operating risks. Each risk needs a clear mitigation, owner, control and evidence trail. That is what turns compliance from a statement of intent into something that can be tested.
Compliance Mapped to the Process
A useful SOP should not simply quote the regulation. It should show how the requirement is operated. SOP 01 links compliance requirements to process steps, records and minimum controls, including: Article 9 information collection, Article 10 risk assessment, Article 11 mitigation and governance, Article 12 public reporting where applicable, EU Information System / TRACES handover, Downstream traceability, Record retention, Annual review and regulatory-change tracking.
This makes the SOP easier to audit because each obligation has a practical process location.
KPIs and Controls
A defensible Due Diligence System also needs performance measures. SOP 01 includes KPIs such as: Scope classification accuracy, Legal role assignment accuracy, Route allocation integrity, Evidence package completeness, Full due diligence risk conclusion completion, Release gate breach rate, Identifier linkage compliance, Exception closure timeliness, Record retrieval success, Article 9 data completeness
These KPIs are supported by minimum controls, including route-specific evidence checklists, release gates, identifier linkage controls, exception logs, retention controls and annual review controls.
The aim is simple: measure whether the process is working before the regulator, customer or auditor finds out that it is not.
Templates, Ratings and Appendices
The appendices are where the SOP becomes operational. They provide practical templates such as: Scope, Role and Route Assessment Record, Approved Partner Information Request Email, Full
Due Diligence Risk Assessment Worksheet, Evidence and Route Validation Checklist, Release and Identifier Handover Checklist, Downstream Traceability and Exception Log, Annual Review and Control Test Pack. User Quick Guide and Scenarios,
The rating logic is particularly important. Evidence responses can be assessed as complete, partially complete, inadequate or requiring escalation. Risk assessments can record criteria, evidence references, mitigation actions, residual risk ratings, reviewer approval and the final conclusion. That final conclusion matters. For full due diligence, the organisation must be able to explain whether no or only negligible risk has been achieved before release.
The Practical Aim of SOP 01
The aim of SOP 01 is simple: Turn EUDR regulation into an operating system that people can actually use.
EUDR readiness is not achieved by policy alone. It is achieved when the regulation is translated into day-to-day controls, evidence standards, decision points, responsibilities and release gates.
That is the purpose of SOP 01: EUDR Due Diligence System. It is the first SOP in the Atoxor EUDR SOP Framework and is designed to help organisations move from regulatory understanding to operational readiness.
SOP 01 is now available as a fully editable template for organisations that need a practical, structured and audit-ready starting point for their EUDR Due Diligence System.
