Aprovall
  • Platform
  • Solutions
    • Purchasing
    • Finance
    • Compliance
    • CSR & ESG
    • Legal
    • Cybersecurity
  • Success
  • Ressources
    • Our webinars
    • Our articles
    • Our news
English
  • English
  • Français
Login
Request a demo

Home | Our articles | Règlementation

  • Règlementation

CSRD Supply Chain Compliance After Omnibus I: What Auditors Will Actually Check

CSRD Supply Chain Compliance

In short

CSRD supply chain reporting now applies to a narrower set of companies after Omnibus I, but the evidentiary bar for those still in scope hasn’t dropped. This piece covers what changed, what ESRS actually requires from supply chain data, the four things a limited assurance auditor checks, and a 5-step roadmap for building audit-ready evidence.

The Omnibus I Directive ((EU) 2026/470) entered into force on 18 March 2026 and changed the terms of CSRD supply chain compliance: fewer companies are formally in scope, and those that remain face a hard cap on what they can ask of their smaller suppliers. Most guidance on supplier ESG data collection was written before that date or straddles it, which means its scope thresholds, reporting deadlines and questionnaire assumptions may no longer hold. What has not moved is the evidentiary bar — a limited assurance auditor tests the same four things, on a population of reporting companies that is now smaller, larger and considerably more visible. This article sets out what Omnibus I changed, what ESRS actually demands from value chain data, what an auditor checks line by line, and how to build a procurement operating model that produces audit-ready evidence rather than a folder of unlinked spreadsheets.

What Does Omnibus I Actually Change for Your Supply Chain Programme?

The Omnibus I Directive ((EU) 2026/470) was published in the Official Journal on 26 February 2026 and entered into force on 18 March 2026. It amends both the CSRD and the CSDDD, and the headline change is scope. Under the revised CSRD, the reporting obligation now applies only to undertakings — or parent undertakings of a group on a consolidated basis — with more than €450 million in net turnover and an average of more than 1,000 employees. Non-EU groups are captured through a separate turnover test tied to their EU subsidiaries and EU-generated revenue. This narrowing is expected to remove a large share of previously in-scope companies from mandatory reporting altogether.

Reporting deadlines have also moved. EU companies that remain in scope will report in 2028, using data from the financial year starting on or after 1 January 2027. Non-EU ultimate parent entities report a year later, in 2029, on financial year 2028 data. These dates build on the earlier “Stop the Clock” Directive (EU) 2025/794, which had already postponed wave two and wave three reporting by two years.

For supply chain teams, the practical consequence is not that the work goes away — it concentrates. Fewer companies are mandatorily in scope, but those that remain tend to be larger, more visible, and under closer scrutiny from auditors and supervisory authorities. A second change matters just as much operationally: the Directive introduces a value chain cap, built around a forthcoming voluntary reporting standard for SMEs (VSME), that limits what an in-scope reporting company can demand from suppliers with 1,000 employees or fewer. The Commission is expected to adopt the delegated act detailing this standard within six months of the Directive’s entry into force. Procurement teams that already run supplier ESG data collection programmes should not read the narrower scope as a signal to relax — they need to re-calibrate what they ask for, from whom, while keeping their own evidence chain fully intact.

CSRD vs. CSDDD: What’s the Real Difference for Your Operating Model?

These two directives are frequently discussed together, but they ask procurement for fundamentally different things, and conflating them is where most supply chain programmes go wrong.

The CSRD is a disclosure obligation. It requires a company to report, through its double materiality assessment, on the sustainability risks and impacts connected to its own operations and its value chain. Non-compliance is sanctioned as a reporting failure, assessed by national competent authorities and tested by an independent auditor who issues an assurance opinion. The CSDDD, by contrast, is an obligation to act: identify adverse human rights and environmental impacts across the value chain, prevent and mitigate them, and remediate where they occur. Its enforcement mechanism is civil liability — third parties harmed by a company’s failure to conduct proper due diligence can bring a claim.

Following Omnibus I, the CSDDD itself now applies only to companies — or EU parent companies of a group — with more than €1.5 billion in net worldwide turnover and an average of more than 5,000 employees, tested over two consecutive financial years. Franchisors and licensors above separate royalty and turnover thresholds are also captured. Member States must transpose the Directive by 26 July 2028, its core provisions apply from 26 July 2029, and the reporting obligations attached to it apply to financial years starting on or after 1 January 2030. The European Commission must publish general due diligence guidelines by 26 July 2027.

For a procurement organisation, this distinction should drive two separate evidence tracks rather than one merged file. CSRD-grade evidence needs to be aggregatable, comparable across suppliers and reporting periods, and ready for external assurance. CSDDD-grade evidence needs to document individual decisions: why a specific supplier was flagged, what mitigation was requested, whether it was implemented, and what happened if it wasn’t. A programme that only produces the first kind of evidence will pass a CSRD assurance review and still fail a due diligence audit — or a court’s scrutiny — the moment a specific supplier relationship is examined in detail.

What Does ESRS Actually Require From Your Supply Chain Data?

Everything a company discloses under CSRD flows from its double materiality assessment — the exercise that determines which sustainability topics are material from an impact perspective, a financial perspective, or both. Supply chain data only becomes a mandatory disclosure item once that assessment flags it as material; it is not a blanket requirement to report on every supplier regardless of relevance.

Where the value chain is flagged as material, ESRS S2 — Workers in the Value Chain — becomes the relevant topical standard. It requires disclosure on policies addressing forced labour, child labour and human trafficking among value chain workers, and on time-bound, results-oriented targets set for the value chain (disclosure requirement S2-5). EFRAG’s amended draft standards, published for consultation in November 2025, go further and introduce an explicit datapoint requiring disclosure of substantiated human rights incidents involving value chain workers specifically — not just policies and intentions, but documented occurrences. These revised standards are not yet legally binding; formal adoption by the European Commission is expected in summer 2026, but the direction of travel — more specific, incident-level disclosure rather than general policy statements — is already clear enough to plan against.

Beyond ESRS S2, the cross-cutting general disclosures standard (ESRS 2) requires a description of the value chain itself and of the due diligence process the company has in place to identify and address its impacts. This is where CSRD and CSDDD data requirements start to overlap in practice, even though the legal obligations remain distinct.

What Will a Limited Assurance Auditor Actually Check?

CSRD sustainability statements are subject to assurance — currently limited assurance, with a path toward reasonable assurance over time, under standards such as ISSA 5000. In practice, auditors testing supply chain disclosures check four things.

First, traceability. Every disclosed figure or statement needs to trace back to a dated, identifiable source — a supplier statement, a certificate, a contract clause, an audit report. “We believe our suppliers comply” is not a position an auditor can sign off on; they are looking for the documented trail underneath the sentence.

Second, methodology documentation. Auditors test whether the double materiality assessment covered all relevant ESRS topics, whether the scoring logic and materiality thresholds applied are documented, and whether any exclusions — a supplier category left out, a topic judged immaterial — are justified and formally approved rather than simply omitted.

Third, internal controls. This covers whether the company has systems in place to prevent unauthorised changes to reported data, and whether there is a segregation of duties between whoever collects supplier information and whoever validates or approves it.

Fourth, reproducibility. Given the same underlying inputs, would an independent reviewer reach the same conclusion or risk score? Weighting schemes and scoring methodologies need to be timestamped and version-controlled, so the company can show exactly which data vintage supported a given disclosed statement — a requirement that becomes considerably harder to meet retroactively than to build in from the start.

Must-Read

On building a scoring model that survives this test : How to Build a Third-Party Risk Scoring Model That Actually Works

Read the article

What Must Procurement Change Operationally to Produce Audit-Ready Evidence?

Most procurement organisations already collect supplier documentation. The gap auditors expose is rarely a lack of data — it is a lack of structure around that data: scattered spreadsheets, email attachments with no version history, certificates that were valid when collected but never checked again.

Closing that gap means three operational changes. First, moving from ad hoc collection to a single, dated, version-controlled record per supplier, so that any figure disclosed can be traced back to a specific document received on a specific date.

Must-Read

On building that record : Building a Centralized Supplier Database: Beyond Document Storage

Read the article

Second, segmenting suppliers into risk tiers before deciding what to request — the depth of evidence needed for a low-risk domestic supplier is not the same as for a high-risk intermediary in an exposed sector or geography, and treating them identically wastes procurement capacity without improving audit readiness where it matters.

Must-Read

On managing that segmentation at scale : TPRM for Large Enterprises: Managing Risk Across Hundreds of Suppliers

Read the article

Third, maintaining a change log that captures not just the current status of a supplier’s risk profile, but why and when it changed — exactly the kind of question an auditor asks when a disclosed figure moves year over year.

This is precisely the shift described by Jean-Salah Ait Benider, Corporate Purchasing Digitalization Project Coordinator at Hutchinson, a French multinational manufacturer and the world’s third-largest producer of non-pneumatic rubber products (testimonial translated from the original French): “Making Ivalua our master supplier database was a structuring decision. Integrating Aprovall into the supplier creation process was a natural fit to secure document collection, make our data reliable, and align procurement, finance and IT around a single source of truth.” He adds: “Automating document collection has significantly reduced manual tasks, strengthened our audit trail, and improved the supplier experience. Procurement teams can now focus on higher-value activities.”

Manufacturing at scale, audit-ready by design

See how Hutchinson secured its supplier onboarding and audit trail with Aprovall & Ivalua

Discover the case study

The Supplier Fatigue Problem and How the Omnibus Changes Affect It

Supply chain ESG data collection has a demand-side problem that predates CSRD and that Omnibus I only partially addresses. More than three-quarters of large corporations now request sustainability data from their suppliers, and a mid-sized supplier serving multiple large customers routinely receives five, ten, or more overlapping questionnaires asking for substantially the same information in different formats. The result is predictable: falling response rates, rushed or copy-pasted answers, and data quality that undermines the traceability auditors are looking for in the first place.

The value chain cap introduced by Omnibus I is a direct policy response to this problem. Reporting companies can no longer request more sustainability information from suppliers with 1,000 employees or fewer than what is covered by the forthcoming VSME standard, and smaller suppliers gain an effective right to decline requests that go beyond it. For procurement teams, this is not simply a compliance restriction — it is an opportunity to redesign supplier questionnaires around a shared, standardised structure that suppliers are increasingly likely to have already prepared for other customers. Pre-screening suppliers using existing data — certifications already held, prior audit results, public registries — before sending a new request, rather than starting from a blank questionnaire, further reduces the burden and tends to improve both completion rates and data reliability. The lesson from the supplier fatigue problem was never that companies should ask for more; it is that asking once, well, beats asking repeatedly and poorly.

Centralising and automating this collection also frees up the buyer time that would otherwise go into chasing suppliers for the same recurring documents. Corinne Petriaux, Technology & Industry Process & Performance Expert and Digital Project Manager at Vallourec, a global manufacturer of tubular solutions for the energy sector, describes the effect (testimonial translated from the original French): “Integrating Aprovall with Ivalua lets us durably strengthen the reliability of our supplier data management. Information is centralized, up to date and immediately accessible, which considerably simplifies the work of our procurement teams.” She adds: “By automating document collection and securing the data, we have significantly reduced the administrative burden on buyers. They can now focus on supplier performance and value creation, rather than on control and follow-up tasks.” That shift — from chasing paperwork to reviewing risk — is exactly what a capped, better-targeted request model is meant to enable.

A 5-Step Implementation Roadmap for Procurement Teams Entering Scope in 2026

For procurement teams whose organisation newly falls into or out of scope under the revised thresholds, five steps structure the transition.

First, confirm scope status under the new rules on both sides of the relationship: recalculate your own consolidated headcount and turnover against the revised CSRD and CSDDD thresholds, and separately check whether your largest customers remain in scope as reporting companies — since their obligations under the value chain cap directly shape what they can still ask of you as a supplier.

Second, map what your value chain data is actually required to support, starting from the double materiality assessment your sustainability or finance function has already run, rather than building a parallel procurement data collection effort that duplicates or contradicts it.

Third, segment suppliers into risk tiers and design questionnaires capped at the VSME-equivalent standard for smaller suppliers, reserving deeper evidentiary requests for the higher-risk tiers where they are proportionate and defensible.

Fourth, build the evidentiary backbone before it is needed: a dated, version-controlled single source of truth per supplier, with full provenance for every document and a change log for every risk status update, so the audit trail exists as a by-product of normal operations rather than as a scramble in the weeks before assurance.

Fifth, run a dry-run assurance readiness check against the four tests an auditor will actually apply — traceability, methodology documentation, internal controls, reproducibility — ideally across two full reporting cycles before the first mandatory limited assurance engagement, so that gaps surface while there is still time to close them rather than during the audit itself.

Teams still building the internal case for procurement ownership of supplier ESG data collection will find that groundwork covered elsewhere in our supply chain reporting content; this piece starts from the assumption that the case has been made, and asks what you can now prove.

Ready to close your evidence gaps before assurance day?

See how Aprovall helps procurement teams build audit-ready supplier evidence

Discover Aprovall for procurement
What Does Omnibus I Actually Change for Your Supply Chain Programme?
CSRD vs. CSDDD: What’s the Real Difference for Your Operating Model?
What Does ESRS Actually Require From Your Supply Chain Data?
What Will a Limited Assurance Auditor Actually Check?
What Must Procurement Change Operationally to Produce Audit-Ready Evidence?
The Supplier Fatigue Problem and How the Omnibus Changes Affect It
A 5-Step Implementation Roadmap for Procurement Teams Entering Scope in 2026

Share

These articles might interest you

  • Réunion autour de schémas de chaîne de valeur et de collecte de données ESG fournisseurs, illustrant le rôle central des achats dans la structuration des données Scope 3 pour la conformité CSRD.
    05 March 2026
    Règlementation
    Scope3 CSRD: Why Procurement Must Lead Supplier ESG Data Collection
    Scope3 CSRD: How to Industrialise Supplier ESG Data in Source-to-Pay Scope3 CSRD forces organisations to collect ESG and emissions data outside their perimeter—across hundreds or thousands of suppliers—while meeting audit-ready traceability expectations. Procurement is best placed to industrialise collection through onboarding, contracts, and recurring supplier governance, improving data quality over time without creating supplier fatigue. […]

    Read more

  • Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029
    14 August 2026
    Règlementation
    Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029
    In short A company operating in Europe can face up to four supply chain due diligence obligations at once — the French Loi de Vigilance, Germany’s LkSG, the EU’s CSDDD, and the CSRD — each with its own threshold and enforcement route. Omnibus I (March 2026) narrowed the two EU-level regimes but left the two […]

    Read more

Logo Aprovall

Created in 2008, Aprovall is a French company that develops software for governance, risk management, and continuous evaluation of third-party compliance for its client organizations. This activity is also known by the acronym TPGRC or TPRM.

Platforms
  • Aprovall Manager
  • Aprovall Portal
  • Donneur d'Ordres
Customers
  • Success
Resources
  • Blog
  • News
  • Webinars
  • Glossary
  • Documentation API
Business
  • About us
  • Contact us
  • Career
  • Partner
Follow us
  • Privacy and data protection policy
  • Trust & Compliance Center
  • Legal notice
  • Cookies policy
  • Performance of our services
  • Whistleblowing
  • Vulnerability disclosure policy