Quick Read
The EU Forced Labour Regulation (FLR) is binding law prohibiting products made with forced labour from the EU market, but it does not prescribe a due diligence methodology, while ISO/DIS 37200 is voluntary guidance that, despite its depth, explicitly uses "should" rather than "shall" and is not itself a certifiable management system standard. This creates a certification gap: neither instrument alone provides organizations with a certifiable way to demonstrate compliance with forced labour risk management. Speeki's SPK DDMS2000:2026 and Speeki Sentinel™ are designed to bridge this gap by offering a certifiable framework aligned to both instruments.
Executive Summary
Two very different documents now define how forced labour risk is expected to be managed by organizations trading with or from the European Union. Regulation (EU) 2024/3015 — the Forced Labour Regulation (FLR) — is binding law: a market-access prohibition on products made with forced labour, enforced through investigation and product withdrawal, with no due diligence process written into the text. ISO/DIS 37200, Managing the risk of modern slavery: Guidance for the prevention, identification and response to human trafficking and forced labour, is a voluntary international guidance document developed by ISO Technical Committee 309 (Governance of organizations), currently at Draft International Standard stage with balloting closed 23 February 2026.
Neither document, on its own, gives an organization a certifiable way to demonstrate it has done the work. The FLR deliberately avoids prescribing a due diligence methodology. ISO/DIS 37200, despite its depth and structure, is explicitly guidance — it uses "should" throughout rather than "shall," and its own introduction states it can be used as a standalone document or within an existing management system, but is not a certifiable management system standard in the way ISO 37001 or ISO 27001 are.
This paper sets out what each instrument actually is, where their underlying logic converges, and why a genuine certification gap exists between them — a gap that SPK DDMS2000:2026 and Speeki Sentinel™ are built to close. It is the first of five papers examining ISO/DIS 37200 in detail against the FLR and against DDMS2000; later papers in this series work through risk assessment and supply chain mapping, governance and criminal liability exposure, operational prevention measures, and remediation and audit practice.
1. A Regulation and a Guidance Document Are Not the Same Kind of Thing
It is worth being precise about category before comparing content. Regulation (EU) 2024/3015 is directly applicable law across all EU member states from 14 December 2027, with no transposition required. It creates one binding prohibition: products made wholly or partly with forced labour may not be placed on, made available on, or exported from the EU market. Breach triggers investigation by a competent authority and, where forced labour is confirmed, product withdrawal, recall, or a customs block, backed by member-state penalty frameworks due to be notified to the Commission by 14 December 2026.
ISO/DIS 37200 is a different kind of artefact entirely. It is a draft international guidance document — its own title says so — prepared by ISO/TC 309 with BSI as secretariat. As of the version dated 8 December 2025, it remains a Draft International Standard: DIS voting ran from 1 December 2025 to 23 February 2026, and the document itself states plainly that it is circulated for comment and approval and may not be referred to as an International Standard until published as such. Its clause numbering, structure, and content can still change before final publication, and any organization citing it should track its progress toward FDIS and eventual publication rather than treating the December 2025 draft as final.
The practical distinction that follows is important: the FLR can end a product's access to the EU market regardless of whether an organization has read a single page of ISO guidance. ISO/DIS 37200 cannot, by itself, satisfy or discharge any FLR obligation, because the FLR does not name it, reference it, or require conformity to it. What ISO/DIS 37200 offers instead is something the FLR conspicuously does not: a structured, detailed articulation of what a credible modern slavery risk management system actually contains, clause by clause, from context-setting through to continual improvement.
2. What ISO/DIS 37200 Actually Covers
The document's scope, set out in Clause 1, is broad by design: guidance for managing modern slavery risk — including preventing, identifying, responding to, mitigating, remediating, and reporting it — across an organization's operations, supply chains, and wider operating environment, generic enough to apply to any organization regardless of type, size, sector, or ownership structure.
Its architecture will be familiar to anyone who has worked with recent ISO governance and compliance guidance: Clause 4 establishes organizational context (including a notably careful distinction in 4.3 between supply chain, value chain, and sphere of influence, and a set of relationship "paths" in 4.4 describing how directly or indirectly an organization is connected to the workers potentially at risk); Clause 5 sets out risk assessment, including stakeholder engagement, risk identification, supply chain mapping, and a defined set of risk indicators; Clause 6 addresses governing-body and top-management leadership and the modern slavery policy itself; Clause 7 covers support functions — resources, competence, awareness, training, communication, and reporting; Clause 8, by far the largest clause, covers operational measures across human resources, procurement, and response to identified risk, including whistleblowing, incident investigation, and remediation; Clause 9 covers monitoring, measurement, and auditing; and Clause 10 covers continual improvement.
Two structural choices are worth flagging early because they recur throughout the rest of this series. First, Clause 3's terms and definitions draw a careful line between forced labour (sourced from the ILO Forced Labour Convention, 1930 — work or service exacted under threat of penalty, not offered voluntarily) and modern slavery (the document's own broader umbrella term, covering forced labour, human trafficking, forced marriage, and the worst forms of child labour, unified by the criterion that the person cannot refuse or leave). Second, Clause 8.1 sets out a cause/contribute/directly-linked framework — drawn from the UN Guiding Principles on Business and Human Rights tradition — that determines what kind of organizational response is appropriate: remedy plus cessation where the organization caused the harm, cessation of contribution where it contributed, and leverage where it is merely linked through a business relationship. This framework matters a great deal for FLR exposure, because it is close in substance to the causation questions an FLR investigation will eventually have to answer about a specific product's supply chain.
3. Where the Two Instruments Converge
The convergence is not accidental. ISO/DIS 37200's own introduction states that its due diligence definition and approach draw on the UN Guiding Principles on Business and Human Rights, ISO 26000, and ISO 20400 — the same UNGP-descended, OECD-adjacent due diligence tradition that the European Commission's own June 2026 guidelines on the FLR point organizations toward when they reference the OECD's six-step due diligence framework.
This shared ancestry means the substantive content lines up more closely than the two documents' legal status would suggest. ISO/DIS 37200's Clause 5 risk assessment structure — identification, analysis, evaluation, feeding into due diligence — mirrors the OECD's identify-and-assess step. Its Clause 8.4.3 operational due diligence and Clause 8.4.6 remediation provisions mirror the OECD's cease-or-mitigate and remediate steps. Its Clause 6 leadership requirements and Clause 7 support requirements mirror the OECD's embed-into-policy step. An organization that builds a system conforming to ISO/DIS 37200 is, in substance, building the kind of system the Commission's FLR guidance describes as mitigating investigation risk and penalty severity — even though no legal instrument formally connects the two.
The definitional discipline in ISO/DIS 37200 is also directly useful for FLR readiness. The FLR's operative prohibition turns entirely on the presence of forced labour in a product's supply chain, and ISO/DIS 37200's Clause 3.21 definition — anchored to the ILO Forced Labour Convention rather than to the document's own broader house definition of modern slavery — gives organizations a precise, internationally recognized standard against which to assess whether a given practice meets the specific threshold the FLR cares about, as distinct from the wider set of exploitative practices (forced marriage, worst forms of child labour, human trafficking generally) that the FLR's forced-labour-specific prohibition does not, strictly, reach.
4. The Certification Gap
Here is the gap. ISO/DIS 37200 is written in the language of recommendation, not requirement: its clauses are built almost entirely around "the organization should," not "the organization shall." This is a deliberate editorial choice consistent with its stated purpose as guidance rather than a set of auditable requirements. Its own text is explicit that it can be implemented as a standalone document or used within an existing management system, and that it is intended to complement other activities addressing modern slavery risk, not to replace them.
That framing has a direct consequence: there is no ISO 37200 certification, and — because the document contains no requirements clause structured for third-party conformity assessment in the way ISO 37001 or ISO 27001 are — there is unlikely ever to be one under its current guidance framing, even once it completes the DIS-to-FDIS-to-publication pipeline. Annex C, a checklist mapping each clause to a yes/no-style question, is explicitly offered as a self-assessment tool for organizations (with a note that SMEs may find it particularly useful), not as an audit criteria set for an accredited certification body.
This is not a criticism of ISO/DIS 37200. A guidance document that tells organizations what good practice looks like, in granular detail, without prescribing a rigid compliance checklist, has real value — arguably more value for a topic as context-dependent as modern slavery risk than a rigid requirements standard would. But it means an organization relying solely on ISO/DIS 37200 self-assessment has no independent, third-party-verified way to demonstrate to an FLR investigating authority, a customer, or an investor that its self-assessment is accurate. Self-declared conformity to a guidance document is, evidentially, a materially weaker signal than independent certification against an auditable standard — a distinction that matters considerably at the point an FLR competent authority is deciding whether a substantiated concern exists.
5. DDMS2000 as the Certifiable Bridge
SPK DDMS2000:2026, Speeki's Due Diligence Management System Standard, is built to occupy exactly this space: a certifiable management system standard whose clause architecture parallels the ISO/DIS 37200 structure closely enough that an organization already working through ISO/DIS 37200's guidance is most of the way toward a DDMS2000-conformant system, while retaining the auditable, requirements-based structure that ISO/DIS 37200 does not attempt to provide.
The parallel runs clause by clause. DDMS2000's planning provisions, which translate inherent risk factors into a defined due diligence tier per subject, sit in the same place in the architecture as ISO/DIS 37200's Clause 5 risk assessment and its Clause 5.3.2 supply chain mapping methodology — but DDMS2000 expresses the tiering logic as an auditable requirement rather than a recommended practice. DDMS2000's subject-specific modules, addressing counterparties, sites, facilities, and vendors, sit alongside ISO/DIS 37200's Clause 8.2 (human resource and labour management) and Clause 8.3 (procurement and supply chain management) — again translating recommended practice into certifiable requirement.
Speeki Sentinel™ is the certifiable system organizations can adopt to operationalize a DDMS2000-conformant due diligence management system. As with the parallel product relationship between Speeki Meridian and CSMS1000, adoption of Sentinel™ and certification against DDMS2000 are each optional and independent of one another — an organization may adopt the standard, adopt Sentinel™, both, or neither, and may seek certification at any stage. Speeki does not operate due diligence on behalf of any client, whether or not that client uses Sentinel™; due diligence execution remains the client's own function, and this separation is what preserves Speeki's structural independence as a certification body.
6. Practical Implications
For an organization with EU market exposure, the sequencing that follows from this analysis is straightforward. ISO/DIS 37200, even in draft form, is a legitimate and detailed reference for what a modern slavery risk management system should contain — its Clause 5 risk indicators, Clause 8.3 procurement guidance, and Clause 8.4.6 remediation provisions in particular are granular enough to use as a build specification today, without waiting for FDIS publication. Organizations should track the document's progress toward final publication, since clause numbering and content may shift, but the substantive guidance is unlikely to be diluted given the maturity of the underlying UNGP and OECD frameworks it draws on.
What ISO/DIS 37200 cannot do is give an organization a certificate to show a regulator, a customer, or an investor. For that, an organization needs a certifiable standard and an accredited certification body applying it. Building toward ISO/DIS 37200's guidance while structuring the resulting system for DDMS2000 certification is, in practical terms, the most direct route from where most organizations sit today to a defensible position ahead of the FLR's December 2027 full application date.
Conclusion
The EU Forced Labour Regulation gives organizations a hard deadline and a severe consequence with almost no procedural detail. ISO/DIS 37200 gives extensive procedural detail with no binding force and no certification mechanism. Read together, the two documents describe almost the entire shape of what a credible modern slavery due diligence system needs to contain — but neither, alone, gives an organization a way to prove to an outside party that its system meets that shape. Closing that gap is the purpose of the four papers that follow in this series, and of SPK DDMS2000:2026 itself.
Speeki is an accredited certification body providing independent assurance and certification of due diligence management systems, including against SPK DDMS2000:2026. Current accreditation scope and certification details are available at speeki.com.
References
Regulation (EU) 2024/3015 of the European Parliament and of the Council of 27 November 2024 on prohibiting products made with forced labour on the Union market (the Forced Labour Regulation).
European Commission, Guidelines on Regulation (EU) 2024/3015 on prohibiting products made with forced labour on the Union market, published 30 June 2026, together with the accompanying online information portal and provisional list of national competent authorities.
ISO/DIS 37200:2025(en), Managing the risk of modern slavery — Guidance for the prevention, identification and response to human trafficking and forced labour, ISO/TC 309 Governance of organizations, Secretariat: BSI. Version dated 2025-12-08; DIS balloting 2025-12-01 to 2026-02-23. Cited as a Draft International Standard, not yet published; clause numbering and content are subject to change prior to final publication.
SPK DDMS2000:2026, Speeki Due Diligence Management System Standard (Speeki standard).
OECD, OECD Due Diligence Guidance for Responsible Business Conduct.
UN Guiding Principles on Business and Human Rights (2011).