Skip to content
Regulation & Market Access

Does Traceability Prove Supply-Chain Due Diligence?

Understand why supply-chain traceability can support due diligence without replacing risk assessment, mitigation and other regime-specific due-diligence duties.

Reading time
5 min
Published by
ActivateDigital
Last verified
Sources
5
Share article
LinkedIn X Email
A split scene, a pile of labels with a dark phone on one side and a product record with dials on the other.

Direct answer

No. A supply chain can be highly traceable and still fail a due-diligence test. Traceability can support due diligence, and it does not by itself prove that the due-diligence process required by a particular regime has been completed.

Traceability can help establish where a product or material came from, which actors handled it, where it travelled and how it changed. Due diligence uses relevant information to identify and assess risks and, where the applicable regime requires it, prevent, mitigate, address, document or report them.

The exact actors, thresholds, risk tests, mitigation duties, statements, audits and reporting requirements come from the applicable law. There is no single cross-product due-diligence workflow that can be inferred from a traceability system.

Activatea Product.
Share
LinkedInXEmail
Jump around this page

Traceability and due diligence answer different questions

LayerCore questionWhat a strong traceability system can doWhat still needs a due-diligence process
Traceability capabilityCan the product, material, actor, location or transformation be followed?Connect identities, locations, custody and eventsDecide which traced information matters to the legal risk test
EvidenceWhat supports an assertion?Carry or reference source recordsEvaluate sufficiency, reliability and applicability where the regime requires it
Risk identificationWhat adverse impacts or prohibited conditions may exist?Surface where to look and which actors or places are involvedDefine the relevant risks under the applicable regime
Risk assessmentHow material or credible is the risk?Supply facts and relationships used in the assessmentApply the legal or policy assessment criteria
MitigationWhat must change because of the risk?Help target suppliers, sites, products or consignmentsChoose, implement and monitor the required response
Reporting / statementsWhat must be disclosed, submitted or retained?Provide underlying data and referencesComplete the regime-specific statement, report, audit or recordkeeping process

The layers overlap operationally, but they are not interchangeable.

What can traceability establish?

Traceability is useful because risk rarely exists in the abstract. It attaches to actors, places, materials, practices, transactions or transformations.

A traceability system can therefore help answer questions such as:

  • Which source, plot, mine, processor, factory or supplier is linked to this product?
  • Which route did a material or consignment take?
  • Which organisations handled it?
  • Which input became which output after a transformation?
  • Which evidence object or declaration is associated with that part of the chain?

OECD’s 2026 comparative due-diligence analysis is explicit on the boundary: traceability can create transparency needed for due diligence, but is not equivalent to due diligence. A product may be completely traceable and still have been produced in problematic circumstances.

That is the central reason not to treat “we can trace it” as a compliance conclusion.

What does due diligence add?

A due-diligence regime can require work that a traceability system does not perform by itself.

Depending on the law, that can include:

  1. identifying the relevant risks or prohibited conditions
  2. assessing those risks against the regime’s criteria
  3. obtaining or checking additional information where risk is not negligible or where enhanced scrutiny is triggered
  4. preventing, mitigating or otherwise addressing identified risk
  5. documenting decisions and retaining evidence
  6. making a statement, report or disclosure
  7. maintaining and reviewing the due-diligence system itself.

A technical traceability standard may help organise the inputs. It does not turn those regime-specific steps into technical requirements and it does not decide whether the legal test has been satisfied.

EUDR shows the distinction clearly

Under the EU Deforestation Regulation, geolocation and supply-chain information are important inputs. The current EUDR framework requires information gathering, risk assessment and, where necessary, risk mitigation before the relevant due-diligence statement is submitted.

A plot coordinate is therefore useful, but it is not the whole process. Even a correct geolocation does not itself establish that the product meets every condition the Regulation tests. The operator still has to perform the legal due-diligence steps that apply to the product and role.

For the current scope, dates, information requirements, risk process and statement rules, use the existing EUDR guide. This page owns only the general boundary between traceability and due diligence.

The Batteries Regulation shows the same boundary in a different form

The Batteries Regulation embeds traceability directly inside a wider due-diligence system. Its due-diligence provisions require covered economic operators to establish supply-chain controls, including a chain-of-custody or traceability system identifying upstream actors. They also require risk identification and assessment, risk-management measures, verification and disclosure obligations.

That is useful because the law itself demonstrates the relationship: traceability is one component of the due-diligence architecture, not a substitute for the rest of it.

Under the current consolidated Regulation, the battery due-diligence obligations are due to apply from 18 August 2027. The detailed battery scope, actor thresholds, implementation status and passport obligations belong with the Battery Digital Product Passport requirements, not here.

A DPP does not automatically close the due-diligence loop

A Digital Product Passport can make governed product information easier to retrieve and can expose identifiers, attributes or evidence references that are useful to a due-diligence process.

That does not mean the passport has completed the legal analysis. A DPP may tell a user the declared origin, material composition or facility associated with a product. The due-diligence regime may still require a separate assessment of risk, further evidence, mitigation, an audit, a statement or reporting.

The opposite is also true. Not every DPP needs complete end-to-end supply-chain event traceability. That question belongs with the existing DPP traceability owner, not this comparison.

A simple acceptance test

Do not ask only: Can we trace the product?

Ask:

  • Can we identify the relevant product, material, actors and locations?
  • Do we have evidence for the facts used in the decision?
  • Have we identified the risks the applicable regime tells us to consider?
  • Have we assessed those risks using the correct legal test?
  • Where required, have we mitigated or otherwise addressed them?
  • Have we completed the required verification, statement, reporting and recordkeeping steps?

If the answer to the first question is yes and the later questions are unknown, you have traceability capability, not proof of completed due diligence.

What would change this page

This page should be reviewed if the EUDR or Batteries Regulation is materially amended, if authoritative guidance changes the relationship between traceability and the relevant due-diligence steps or if a future cross-sector regime creates a materially different legal model.

Sources

Does this reach your products?

Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.