Aprovall
  • Platform
  • Solutions
    • Purchasing
    • Finance
    • Compliance
    • CSR & ESG
    • Legal
    • Cybersecurity
  • Success
  • Ressources
    • Our webinars
    • Our articles
    • Our news
English
  • English
  • Français
Login
Request a demo

Home | Our articles | Règlementation

  • Règlementation

Forced Labour in the Supply Chain: What Buyers Are Now Required to Prove

Équipes en action dans un bureau moderne illustrant la lutte contre le Forced Labour in the Supply Chain

In short

Under the US UFLPA, importers — not regulators — must prove a shipment isn’t linked to forced labour, and a similar evidentiary bar is emerging under the EU’s Forced Labour Regulation. Both mechanisms test traceability several tiers upstream, on a deadline the buyer doesn’t control — making this an operational capability question, not a reporting exercise.

Forced labour is the one area of third-party risk where the burden of proof has quietly flipped. Under the US Uyghur Forced Labor Prevention Act (UFLPA), the importer must demonstrate that a shipment is not made with forced labour — not the authorities that it is. That mechanical difference changes what “supply chain due diligence” means in practice. It moves upstream traceability out of the sustainability report and into the customs process, with a shipment held at port the immediate consequence of getting it wrong. This is not a reporting story. It is a risk story.

Three regimes, one exposure

Three jurisdictions now police forced labour through genuinely different mechanisms — and a single exporter selling into the US, EU and UK at once can be exposed to all three simultaneously, each on its own clock, demanding evidence in its own format.

RegimeLegal instrumentScopeSanction mechanism
United StatesUFLPA, applying section 307 of the Tariff Act of 1930Goods from Xinjiang, or from any entity on the UFLPA Entity List (187 entities as of August 2026, after the largest expansion to date); the underlying Tariff Act provision reaches forced-labour goods from any countryRebuttable presumption. CBP can detain, exclude or seize on suspicion alone; the importer must rebut with “clear and convincing evidence”
European UnionRegulation (EU) 2024/3015, the Forced Labour Regulation (FLR)All products, every sector, any origin — including EU-made goods — no minimum threshold. In force since December 2024; applies from December 2027Product-based market ban. National authorities and customs can investigate, request evidence, and prohibit the product from the EU market
United KingdomModern Slavery Act 2015, s.54; amendments before Parliament since June 2026Annual statement for organisations above £36m turnover. No import ban in forceDisclosure regime today; proposed amendments add financial penalties (up to £1m or 1% of turnover); an import ban has been signalled

These regimes don’t sit in isolation. In March 2026 the US Trade Representative opened Section 301 investigations against 60 trading partners — the UK included — over whether their frameworks adequately ban or enforce forced-labour import prohibitions; tariffs against those economies followed in July 2026. A jurisdiction’s own regulatory gap can become a tariff problem for companies trading with it.

UFLPA and the reversal of the burden of proof

The mechanism at the centre of UFLPA is a rebuttable presumption: goods from Xinjiang, or from an Entity List company, are presumed made with forced labour and barred from entering the US. CBP does not need to establish that forced labour occurred before acting — a plausible link is enough.

CBP’s 2026 guidance splits enforcement into two tracks. Where a connection is only suspected — a “potential input” — CBP can detain the shipment, and the importer has a limited window to respond, either by showing the chain falls outside UFLPA’s scope or by rebutting the presumption directly. Where the connection is confirmed — a “direct input” — the goods are excluded outright, with 180 days to protest, re-export or destroy them.

In both tracks the bar is high: “clear and convincing evidence” means production records reaching to the raw-material stage, transportation records, employment records at every tier, and independent audit findings. None of this can be compiled from memory after the fact — it has to already exist, ready to assemble inside the response window. That is why forced labour compliance behaves like an operational capability, not a disclosure exercise: a cargo can be held, with real commercial consequences, before any authority has proven anything — purely because the importer could not produce the file fast enough.

The Entity List is not static. The August 2026 expansion added 43 companies in one notice — the largest addition since the list was created — pushing the total past 180 and reaching further into aluminium, apparel, copper, cotton and agricultural products. A supplier relationship clean at onboarding can fall inside the presumption later, with nothing about the buyer’s own process having changed.

The EU forced labour regulation: a different mechanism, same direction

The EU’s Forced Labour Regulation works on a different logic. It is not a due diligence obligation and creates no formal rebuttable presumption. It is a market-access ban: products made wholly or partly with forced labour cannot be placed on, made available on, or exported from the EU market, regardless of company size, sector or origin.

The Regulation entered into force on 13 December 2024. Member States had until 14 December 2025 to designate competent authorities. The Commission published implementation guidelines and launched the Forced Labour Single Portal, with a risk database of products, regions and sectors, in June 2026. It applies across the EU from 14 December 2027.

Enforcement runs through national market surveillance authorities and customs at the external border, using a risk-based approach that prioritises high-risk products and sectors — the same enforcement architecture the EU Deforestation Regulation uses for a different upstream risk.

Authorities can request supply-chain evidence within set deadlines. The Regulation doesn’t formally shift the burden of proof as UFLPA does, but the Commission’s own guidance is candid that an inability to produce traceability when asked works against the company under investigation — the practical effect converges with the US mechanism even where the legal architecture doesn’t. The FLR is also designed to sit alongside the CSDDD: a company already building CSDDD-grade governance and evidence trails is largely building what FLR investigations will ask for too.

Why forced labour risk lives beyond tier 1?

Most buyer-side visibility stops at the entity a company directly contracts with. Onboarding checks and scorecards are built around that first relationship. But the risk both regimes target typically sits several tiers upstream — at raw-material extraction, early-stage processing, or a labour intermediary the buyer has never dealt with, which is exactly why assessing upstream suppliers is essential rather than optional.

This is structural, not a matter of effort. UFLPA’s rebuttal standard explicitly asks for employment records “for every tier,” not just tier 1. A company can run a thorough onboarding process on direct suppliers and still be exposed, because the exposure was never at tier 1 — it sat several steps further back, outside the radius ordinary supplier due diligence covers.

Scale compounds this. A buyer with a few dozen strategic suppliers can map upstream by hand; one with thousands across dozens of countries cannot. Africa Global Logistics (AGL), which manages compliance data for 1,300 transport partners across 46 African countries, illustrates the scale at which this challenge plays out — a network dispersed enough that manual, tier-1-only tracking cannot keep pace. As David Fornili, Operations Manager at AGL, put it:

Africa Global Logistics logo - AGL avis client

We can finally rely on a solution that is reliable, stable and fully aligned with our processes.

David Fornili

Operations Manager | AGL

The evidence buyers are actually asked for

Strip away the legal language and both regimes ask for the same things: traceability beyond tier 1, records attributable to a specific site and date, independent verification rather than self-declaration, and the ability to produce it inside a deadline set by someone else.

That last point is usually the real failure mode. Companies caught out by a detention or a market-surveillance request are rarely caught out because the information doesn’t exist anywhere in the organisation — it exists, scattered across supplier emails, local spreadsheets and buyers’ inboxes, in a form nobody can assemble and submit inside a 30-day window. The problem is retrieval speed and evidentiary quality, not the absence of information.

This is where a controlled evidence base earns its keep. Marie-Soisick Floc’h, who leads compliance and internal control for the Société des Grands Projets, described what changed once documentation moved into a single system: “We eliminated duplicate data entry and centralised all our documentary information. We gained traceability, responsiveness in our compliance evaluations, and efficiency day to day — a real change of posture, with much greater visibility over our third parties.” Flavie Tremaudan, procurement counsel at Espacil Habitat, made a related point about evidence that survives scrutiny rather than just existing: “The platform certifies documents directly via official APIs, which reassures our teams a great deal, especially given how decentralised our purchasing is. It’s genuinely a guarantee of security.” Neither organisation was built for forced-labour compliance specifically, but the capability they describe — verified evidence, produced on demand — is exactly what a UFLPA rebuttal or an FLR investigation requires.

Building traceability that survives scrutiny

Three things separate traceability that holds up under scrutiny from traceability that only looks good on paper.

Map beyond tier 1. A flat list of direct suppliers is not a supply chain map. Both regimes test whether a company can connect a specific product back through its intermediate producers to the raw-material stage — for the products actually being questioned, not a portfolio average.

Keep the data current, not just collected. An attestation gathered two years ago at onboarding proves nothing today. Traceability that survives scrutiny treats every document as time-bound, with renewal triggers built in rather than left to memory. Jean-Salah Aït Benider, who led the purchasing digitalisation project at Hutchinson, described the governance decision behind making this possible across roughly 20,000 suppliers: “Making our procurement system the group’s master supplier database was a structuring decision. Building document collection into the supplier-creation process was the natural way to secure it, make the data reliable, and align procurement, finance and IT around a single repository.”

Trace the decisions, not just the documents. When a shipment is detained or an authority opens a file, what gets examined is not only whether the company holds the right certificates, but whether it can show what was requested, received, when, and what judgement was made — that audit trail is itself evidence. Freeing buying teams from manual chasing is what makes that discipline sustainable at scale rather than a one-off exercise before an audit. Corinne Petriaux, who leads digital process performance at Vallourec, described that shift after automating collection across roughly 7,000 suppliers and nine integrated risk dimensions: “By automating document collection and securing the data, we significantly reduced the administrative burden on buyers. They can now focus on supplier performance and value creation, rather than on control and chasing tasks.”

None of this makes a company immune to a detention or an investigation — nothing does, since both mechanisms act on suspicion before guilt is established. What it changes is how long the company takes to answer, and how convincing that answer is. In a domain where the burden of proof already sits with the buyer, that speed and that credibility are the whole compliance programme.

Go further

Map your third-party risk end to end – Comprehensive Methodology for Third-Party Risk Mapping

Read more

Book a meeting at our booth

Don’t miss this opportunity to connect with our team, see our solutions in action, and discuss how Aprovall can help you drive procurement excellence and stronger supplier risk management.

Book a meeting
Three regimes, one exposure
UFLPA and the reversal of the burden of proof
The EU forced labour regulation: a different mechanism, same direction
Why forced labour risk lives beyond tier 1?
The evidence buyers are actually asked for
Building traceability that survives scrutiny

Share

These articles might interest you

  • Réunion autour de schémas de chaîne de valeur et de collecte de données ESG fournisseurs, illustrant le rôle central des achats dans la structuration des données Scope 3 pour la conformité CSRD.
    05 March 2026
    Règlementation
    Scope3 CSRD: Why Procurement Must Lead Supplier ESG Data Collection
    Scope3 CSRD: How to Industrialise Supplier ESG Data in Source-to-Pay Scope3 CSRD forces organisations to collect ESG and emissions data outside their perimeter—across hundreds or thousands of suppliers—while meeting audit-ready traceability expectations. Procurement is best placed to industrialise collection through onboarding, contracts, and recurring supplier governance, improving data quality over time without creating supplier fatigue. […]

    Read more

  • CSRD Supply Chain Compliance
    05 August 2026
    Règlementation
    CSRD Supply Chain Compliance After Omnibus I: What Auditors Will Actually Check
    In short CSRD supply chain reporting now applies to a narrower set of companies after Omnibus I, but the evidentiary bar for those still in scope hasn’t dropped. This piece covers what changed, what ESRS actually requires from supply chain data, the four things a limited assurance auditor checks, and a 5-step roadmap for building […]

    Read more

  • Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029
    14 August 2026
    Règlementation
    Supply Chain Due Diligence in Europe: Your Regulatory Map from 2025 to 2029
    In short A company operating in Europe can face up to four supply chain due diligence obligations at once — the French Loi de Vigilance, Germany’s LkSG, the EU’s CSDDD, and the CSRD — each with its own threshold and enforcement route. Omnibus I (March 2026) narrowed the two EU-level regimes but left the two […]

    Read more

Logo Aprovall

Created in 2008, Aprovall is a French company that develops software for governance, risk management, and continuous evaluation of third-party compliance for its client organizations. This activity is also known by the acronym TPGRC or TPRM.

Platforms
  • Aprovall Manager
  • Aprovall Portal
  • Donneur d'Ordres
Customers
  • Success
Resources
  • Blog
  • News
  • Webinars
  • Glossary
  • Documentation API
Business
  • About us
  • Contact us
  • Career
  • Partner
Follow us
  • Privacy and data protection policy
  • Trust & Compliance Center
  • Legal notice
  • Cookies policy
  • Performance of our services
  • Whistleblowing
  • Vulnerability disclosure policy