How to use Verdandi to prepare for an EU buyer supplier audit

How to use Verdandi to prepare for an EU buyer supplier audit

EU buyers are conducting supplier audits to meet CSRD and CSDDD obligations, and the regulatory basis of those audits has shifted. This walkthrough shows how a Southeast Asian manufacturer can use Verdandi to prepare with the right sources, not secondhand summaries.

10 min read

This article is for informational purposes only and does not constitute legal advice. Consult a qualified legal professional for advice specific to your situation.

  • The audit is now a regulatory compliance record, not a reputational exercise: EU buyers conducting supplier audits from 2025 onward are building documentation for CSRD assurance auditors and CSDDD supervisory authorities. The questionnaire fields and the audit process have a specific regulatory origin, and understanding that origin changes how you prepare.
  • CSRD and CSDDD are driving different parts of the same audit: Data requests about wages, working hours, and emissions map to ESRS disclosure standards your buyer must report against. Requests to see your grievance mechanism and worker engagement processes map to CSDDD due diligence obligations. Preparing for them as a single undifferentiated requirement means over-preparing in some areas and missing gaps in others.
  • The regulations driving your audit have changed recently: CSDDD was amended by Omnibus I in February 2026, shifting scope thresholds and removing the phased rollout. A preparation approach based on briefings from twelve months ago may be calibrated against requirements that no longer exist in that form. This walkthrough shows how to verify the current position from adopted law before building your response.
  • Verdandi’s Q&A works against official source documents, not summaries: The worked examples below use the Legislation, Guidance, and Proposals streams to answer specific preparation questions. The Consultations stream referenced in the forward-looking section is available on Premium tier only; a manual workaround for Starter and Pro users is noted where relevant.

Why supplier audits changed

A supplier audit from an EU buyer used to be a reputational exercise. The EU company wanted assurance that its supply chain would not produce a damaging headline. The audit was voluntary infrastructure for brand protection, and both sides understood that.

From 2025 onward, the audit is regulatory infrastructure. A large EU company subject to CSRD must report its value chain impacts in its sustainability statement, backed by data it actually collected from suppliers. A company building a CSDDD due diligence programme must demonstrate to a supervisory authority that it identified supply chain risks and took appropriate action. The audit is no longer a courtesy: it is part of a compliance record that an external assurance auditor will review and that an enforcement authority could inspect.

For a Southeast Asian manufacturer, this means the questionnaire in your inbox and the audit team at your factory gate are not serving the same function they served two or three years ago. The questions are more detailed, the documentation requests are more specific, and the consequences of not being able to answer have changed. See how EU buyers are changing their supplier requirements because of CSRD and CSDDD for the full picture of what that shift looks like in procurement practice.

The practical question is what you do with this. If the audit is now a regulatory process, preparing for it means understanding the regulation that is driving it. That is the task Verdandi is built for.

What you are actually being audited against

Before using any tool to prepare for a supplier audit, it is worth being clear about the regulatory basis of what your buyer is asking for.

The questionnaire your EU buyer sends reflects two distinct sets of obligations on their side. The first is CSRD disclosure. If your buyer is a large EU company required to report under CSRD, they need supply chain data to populate the European Sustainability Reporting Standards, specifically ESRS S2 (workers in the value chain), ESRS E1 (climate), and ESRS E2 through E5 (water, biodiversity, resource use, pollution). The data they request from you is not arbitrary: it maps to disclosure requirements in the standards they are legally required to report against.

The second is CSDDD due diligence. Your buyer’s audit of your facility is their mechanism for identifying whether adverse human rights or environmental impacts are occurring or likely in your operation. The CSDDD requires them to identify those impacts and to document what action they took. The audit is the identification mechanism. Their corrective action request after the audit is the documented response the regulation requires.

Understanding which regulation is driving which part of the audit changes how you prepare. A data request about workforce wages and hours is driven by ESRS S2. A request to see your grievance mechanism is driven by CSDDD. A question about your Scope 1 and Scope 2 emissions maps to ESRS E1. These are different instruments with different legal status, different timelines, and different enforcement mechanisms. Preparing for them the same way, as though they were a single undifferentiated compliance requirement, means you are likely to over-prepare in some areas and miss gaps in others.

Starting point: confirm what is currently in force

The first task in Verdandi is confirming the current legal position of the regulations driving your audit. This matters because EU sustainability regulation has been moving. CSDDD was amended significantly by Omnibus I in February 2026. EUDR application dates shifted twice before stabilising. CSRD scope was narrowed by Omnibus I. A manufacturer operating from a briefing that is twelve months old may be preparing for obligations that have since changed.

Open Verdandi and select the Legislation stream. This stream covers adopted EU sustainability regulations and directives currently in force. Ask directly: what are the current scope thresholds for CSDDD? What is the current application date?

The answer will be generated from the adopted text and the Omnibus I amendments, not from a summary that might predate those changes. As of July 2026, the CSDDD applies to EU companies with more than 5,000 employees and worldwide net turnover above 1.5 billion euros, with a uniform application date of 26 July 2029. You can verify this from the source Verdandi surfaces.

Do the same for CSRD. Confirm that your buyer’s wave timing is consistent with the current obligations. Wave 1 companies (those formerly subject to the Non-Financial Reporting Directive) reported for financial year 2024. Wave 2 companies (1,000-plus employees and 450 million euros-plus turnover) report from financial year 2027. This matters because it tells you which obligation is already active for your buyer and which is still in implementation.

For a Southeast Asian manufacturer in garments, electronics, or agricultural commodities, EUDR may also be relevant. Check the current commodity scope and application dates in the Legislation stream.

Understanding what the standards actually require from suppliers

Once you have confirmed what is currently in force, the next task is understanding what the disclosure standards actually require your buyer to report about you.

Switch to the Guidance stream. This covers EFRAG implementation guidance and Commission FAQs on CSRD, ESRS, and the EU Taxonomy. These documents are where the interpretation of principles-based standards becomes concrete. EFRAG has published implementation guidance documents on topics including materiality assessment, value chain information, and detailed ESRS datapoints.

A useful question to ask here: what does ESRS S2 require companies to report about workers in their value chain? The guidance will surface the relevant Q&As and Commission guidance. You are looking for the specific data points your buyer is required to collect: wage data relative to living wage benchmarks, working hour data, health and safety incident rates, freedom of association indicators, and the existence of a grievance mechanism accessible to supply chain workers.

This is not information you need to find to audit yourself. It is information you need so that when your buyer’s questionnaire arrives asking for these specific data points, you understand why each one is being requested and what an adequate response looks like. A manufacturer who understands the ESRS S2 framework will give a more useful answer than one who fills in fields without knowing what they connect to.

Do a similar query about CSRD materiality assessment, specifically how companies apply double materiality to determine which sustainability topics are relevant to disclose. This tells you something important: the topics your buyer asks about are not necessarily those that matter most to you. They are the topics that are material from your buyer’s regulatory perspective. The supplier questionnaire is an instrument for satisfying the buyer’s disclosure obligation, and understanding that framing changes how you respond.

A practical note on stream scope: the Guidance stream covers EU-level interpretive guidance from EFRAG and the European Commission. It does not cover sector-specific guidance or national-level implementing measures. For sector-specific questions, particularly in industries like garments or electronics where sector-specific ESRS standards are in development, check the Proposals stream for the current status of those sector standards.

Understanding the due diligence framework

The CSDDD due diligence audit is procedurally distinct from the CSRD data audit. It is not primarily about data collection. It is about your buyer demonstrating that they have identified whether adverse human rights or environmental impacts exist in your operation and what they are doing about it.

Go back to the Legislation stream and ask: what are the specific due diligence obligations under CSDDD regarding worker stakeholder engagement? The adopted text requires buyers to engage with affected workers, not just to review documents. This is a procedural requirement that shapes what a compliant audit looks like: it is one where workers have been interviewed in appropriate conditions, not just where management has answered questions and supplied paperwork.

For a Southeast Asian manufacturer, this means two things. First, your buyer’s audit team may conduct worker interviews as part of the assessment process. Preparing your workforce for those interviews, in the sense of ensuring workers know about and trust the process, is not coaching: it is part of maintaining an environment where the due diligence process can actually identify what exists.

Second, your existing grievance mechanism is under scrutiny. CSDDD requires buyers to assess whether effective complaints procedures are accessible to supply chain workers. If you have a grievance mechanism that workers do not know about, cannot access in their own language, or do not trust, the buyer’s auditor will likely identify this as a gap.

Ask in the Legislation stream what the CSDDD text says about monitoring requirements. As amended by Omnibus I, monitoring assessments are required at least every five years and after significant changes. For your buyer, this means the audit is not a one-off event. The relationship is now under periodic reassessment, and each assessment needs to be documentable.

The proposals and consultations picture

After establishing what is currently required, the forward-looking streams are worth checking. This is where the preparation advantage from using Verdandi, rather than a static briefing, is most direct.

Switch to the Proposals stream. Ask what Commission proposals are currently moving through the legislative process on CSDDD implementing guidance. The Commission is expected to publish sector-specific due diligence guidelines that will define what adequate due diligence looks like in specific industries. For a garment manufacturer, that guidance will likely address the high-risk areas specific to garment supply chains. Knowing it is coming, and approximately when, means you are not planning your compliance approach on the assumption that the current standards represent the final word.

If you are on the Premium tier, check the Consultations stream for draft regulatory and implementing technical standards from EFRAG and the European supervisory authorities on sustainability-related topics. Draft RTS and ITS are pre-legislative in form but near-certain to become binding law. For an ESRS S2 question, EFRAG consultation documents may show how the Q&A framework is likely to develop. This is the highest-signal forward-looking intelligence in the product: it shows what is definitively coming, not just what has been proposed.

If you are on a Starter or Pro tier, you will not have access to the Consultations stream. A practical workaround is to use the Verdandi Q&A in the Proposals stream to identify which legislative instruments are currently in consultation, then check the EFRAG and relevant agency websites directly for the consultation documents themselves. This is more manual than the in-product experience but gives you directional awareness without the Premium tier.

Building the documentation response

With the regulatory picture clear, the preparation task becomes practical.

Map the questionnaire fields your buyer has sent against the regulatory instruments you have confirmed in Verdandi. Each field should have a clear origin: ESRS S2, ESRS E1, CSDDD Article X. If you cannot trace a field back to a regulatory requirement, ask your buyer for clarification on what obligation they are satisfying with it.

For each ESRS disclosure field, identify whether you have the underlying data. Emissions intensity requires production volume and energy consumption data. Wage data requires payroll records broken down by category. Health and safety data requires incident logs. If the data exists in your operation but in a format that cannot be extracted to answer a specific question, that is an infrastructure gap to address before the next questionnaire cycle, not something to paper over with estimates.

For the CSDDD due diligence elements, the documentation required is different. It is process documentation: evidence that your grievance mechanism exists and is accessible, evidence that workers are aware of it, evidence that your management understands the due diligence process and what the buyer’s auditors will be looking for.

When you are unsure whether a specific process you have in place meets what the regulation requires, go back to the Legislation or Guidance stream in Verdandi and ask a direct question about it. What does CSDDD require in terms of grievance mechanism accessibility? Does ESRS S2 require disclosure of the number of workers who used the grievance mechanism, or only whether one exists? These are the specific questions the source-anchored Q&A is built for.

Using Verdandi during and after the audit

Preparation is the primary use case, but Verdandi is also useful during the audit response process itself.

If the audit team asks you a question about the regulatory basis for a requirement, you can verify the answer in the Legislation stream rather than relying on what you remember from your preparation. If they request a document type you have not encountered before, ask Verdandi what the regulation requires in terms of evidence at that point in the due diligence process. If they issue a corrective action request that references a specific regulatory provision, you can pull the provision directly and understand precisely what it requires of you, rather than relying on the buyer’s characterisation of it.

After the audit, use the Proposals and Consultations streams to understand what is likely to change before the next audit cycle. If sector-specific ESRS standards are due to be finalised in the next twelve months, the data your buyer requests in the next questionnaire will likely expand. Understanding that in advance means you have a year to build the data infrastructure before the request arrives, rather than scrambling after the fact.

Source-anchored Q&A tells you what the regulation says. It does not tell you how a specific fact pattern in your business should be characterised against that text. A question about whether your current wage structure meets the living wage benchmark that your buyer’s ESRS S2 disclosure will reference is a judgement question, not a retrieval question. Verdandi can surface what the ESRS S2 standard says about living wage disclosure. It cannot tell you how a labour standards specialist would characterise your specific payroll structure against that benchmark.

Similarly, if your buyer issues a corrective action request that you believe is based on a misreading of the regulation, Verdandi can help you verify the regulatory position. It cannot substitute for legal advice about how to respond to the request in a way that protects your commercial relationship and your legal position.

The correct use of a source-anchored answer is as the starting point for a conversation with a qualified professional on questions that turn on contested interpretation or carry significant consequences. Not as the end of it.

Verdandi monitors CSRD, CSDDD, EUDR, CBAM, and the EU Taxonomy continuously, so you are preparing for supplier audits against current requirements, not last year’s briefing. Start for free.

📋 Track EU sustainability regulation continuously

Verdandi monitors EU sustainability regulation and delivers personalised alerts anchored to verified official sources.

14-day free trial. No credit card required.