Quick Read
The EU Forced Labour Regulation applies to organisations of any size with no employee or turnover threshold, making it a critical compliance obligation that many mid-market companies overlook by assuming they fall outside EU due diligence law based on CSDDD's higher thresholds. Unlike threshold-based regimes, EUFLR imposes strict-liability outcome prohibitions rather than due diligence process obligations, meaning organisations cannot rely on documented compliance procedures alone but must ensure no forced-labour products reach the EU market regardless of their size or sector. SPK DDMS2000:2026 Section 10.9 and Annex D require explicit, separate applicability checks for EUFLR to prevent this common compliance gap.
Why This Whitepaper Exists
Most EU due diligence law that receives public attention comes with a size threshold attached — a company has to be large enough, in employees or turnover, before it applies. The EU Forced Labour Regulation does not work this way, and this single structural fact makes it one of the more consequential due diligence obligations many organisations will encounter, precisely because it is easy to assume it does not apply. SPK DDMS2000:2026 treats this distinction as important enough to require its own explicit applicability check at Section 6.1.2, and this whitepaper sets out why, in enough depth to actually change how an organisation runs that check.
A small or mid-market organisation shall specifically verify EUFLR, EUDR, and comparable no-threshold or low-threshold regimes rather than concluding it is out of scope for EU due diligence law generally because it falls below CSDDD's threshold.
The Threshold Trap, in Detail
Section 6.1.2 requires the organisation to assess applicability of each obligation on its own terms rather than by analogy to a different obligation's thresholds, and states directly that thresholds vary materially between regimes even within the same regulatory family. The reasoning behind this requirement becomes clear once the actual threshold landscape is laid out side by side.
Regime | Size threshold | Consequence for smaller organisations |
|---|---|---|
CSDDD (post-Omnibus I) | 5,000+ employees and €1.5bn+ turnover | Out of scope |
German LkSG | 1,000+ employees, German HQ/branch | Out of scope |
French Duty of Vigilance Law | 5,000+ FR / 10,000+ worldwide employees | Out of scope |
EU Forced Labour Regulation | None — applies to any operator placing, making available, or exporting an in-scope product | In scope regardless of size |
An organisation that checks CSDDD, finds itself well below the 5,000-employee and €1.5bn turnover threshold following the Omnibus I amendment, and concludes it has no EU due diligence exposure has answered the wrong question — a natural one to ask, but the wrong one. The regulation with no threshold at all is the one most likely to actually apply to it, and it is also the regulation least likely to appear on a compliance checklist built around the size-threshold regimes that dominate public discussion of EU due diligence law.
What the Regulation Actually Does
The EU Forced Labour Regulation prohibits placing, making available, or exporting products made wholly or partly with forced labour on the EU market, regardless of the operator's size, sector, or origin. As set out at Section 10.9 of this standard, it is a strict-liability prohibition: it imposes no independent due diligence obligation of its own. This is a genuinely different mechanism from the vigilance-style laws most organisations are more familiar with — CSDDD, LkSG, and the French Duty of Vigilance Law all impose a due diligence *process* obligation. The EU Forced Labour Regulation imposes an *outcome* prohibition instead.
This distinction changes what “compliance” actually means in practice. An organisation cannot demonstrate EUFLR compliance the way it might demonstrate compliance with a vigilance law — by producing a due diligence plan and showing it was followed. What it can do, and what Section 10.9.3 of this standard requires, is maintain voluntary due diligence records, aligned to the OECD six-step framework, that enforcing authorities explicitly take into account when deciding whether to open an investigation, and that can help shorten one already underway. The due diligence is not a compliance defence in the legal sense; it is a mitigating factor in how the organisation is actually treated by the enforcing authority.
Three Operational Features That Demand Specific Preparation
The Forced Labour Risk Database: a proactive monitoring obligation
A public Forced Labour Risk Database is being established under the regulation, and Section 10.9.4 of this standard requires the organisation to monitor it for products or geographies matching its own supply chain, treating a match as a mandatory trigger for enhanced due diligence. This is not a passive resource an organisation consults if a concern arises — it is an active monitoring obligation. An organisation that has never checked the database, and only discovers a relevant match once an investigation is already underway, has missed the entire point of the mechanism.
The 30-working-day evidence deadline: a readiness problem, not a research problem
Evidence-request deadlines under the regulation's enforcement guidance can be as short as 30 working days. Section 10.9.6 of this standard requires evidence retrieval procedures capable of meeting this timeframe, which in practice means the underlying due diligence records need to already exist, in retrievable form, before the request ever arrives. Thirty working days is not enough time to construct a defence from first principles — it is barely enough time to retrieve and organise records that were properly maintained from the start. This reframes forced labour due diligence recordkeeping from a documentation nicety into an operational readiness requirement, tested not by whether the organisation could eventually produce evidence, but by whether it could produce it inside the actual window a real investigation allows.
The return-to-market pathway: remediation has to be sustained, not stated
The regulation provides a path for a banned product to return to market once forced labour is demonstrably eliminated from its supply chain. Section 10.18.7 of this standard requires that documentation supporting a return to market show the remedy was effective and sustained, not merely initiated — connecting this regulation's own return-to-market mechanism directly to the standard's broader remediation discipline at Section 10.18.4, which prohibits closing a remediation case on the basis of an action taken alone, without evidence the underlying harm was actually addressed.
Why This Regulation Is Not Affected by CSDDD's Narrowing
Organisations tracking the EU due diligence landscape may reasonably have registered that CSDDD's scope has been substantially narrowed through the Omnibus I package. It is worth being precise about what that narrowing does and does not affect: the EU Forced Labour Regulation operates independently of CSDDD, was not amended by the Omnibus I package, and its no-threshold scope is entirely unaffected by CSDDD's rising thresholds. These are structurally separate legal instruments with separate legislative histories, not two expressions of the same underlying regime. An organisation's exposure to the EU Forced Labour Regulation should be assessed entirely on its own terms, tracked through Annex D of this standard as its own distinct entry, and never inferred from where CSDDD's threshold currently happens to sit.
Building Readiness in Practice
Assess applicability by product line, not by company size
Because the regulation carries no size threshold, applicability turns entirely on whether the organisation places, makes available, or exports an in-scope product — a product-level question, not a company-level one. An organisation with a single relevant product line can be fully in scope even if the great majority of its business has no connection to the regulation at all.
Build the voluntary due diligence file before it is needed, not in response to a request
Given the 30-working-day evidence deadline, the practical discipline is to maintain OECD six-step-aligned voluntary due diligence records as a standing practice for any in-scope product line, rather than planning to assemble them reactively once an authority's request arrives.
Assign monitoring ownership for the risk database explicitly
The Forced Labour Risk Database monitoring obligation under Section 10.9.4 should have a named, accountable owner and a defined review cadence — not sit as an informal, ad hoc check performed inconsistently.
Common Misconceptions Worth Correcting
“We checked CSDDD and we're too small, so EU forced labour law doesn't apply to us.” The EU Forced Labour Regulation has no size threshold and must be assessed entirely separately.
“Since there's no due diligence obligation under this regulation, due diligence doesn't matter here.” Voluntary due diligence records remain genuinely valuable evidence that can avoid or shorten an investigation.
“We'll build the evidence file if and when an investigation happens.” A 30-working-day response deadline does not allow time to build a defence from scratch — records need to already exist.
“A public commitment to fix the supply chain is enough to restore market access.” The standard requires evidence the remedy was effective and sustained, not merely announced.
Common Gaps Worth Checking
EU due diligence exposure was assessed once, against CSDDD's threshold only, with no separate check against the EU Forced Labour Regulation's own, unrelated scope.
Applicability was assessed at the company level rather than the product level, potentially missing a specific in-scope product line.
No monitoring process exists for the Forced Labour Risk Database, despite the mandatory enhanced-DD trigger this creates under Section 10.9.4.
Evidence retrieval procedures have never been tested against a 30-working-day timeframe.
No voluntary due diligence records are being maintained specifically because the organisation has concluded, correctly, that no independent DD obligation exists — missing that such records remain valuable regardless.
How Speeki Sentinel Certification Assesses This
Certification against SPK DDMS2000:2026 tests whether the organisation's Applicable Obligations Register correctly distinguishes threshold-based EU regimes from no-threshold regimes like the EU Forced Labour Regulation, whether the applicability assessment was performed at the product level, and whether voluntary due diligence records exist in a form that would genuinely support the organisation's position if an authority's evidence request arrived within the regime's actual deadlines.
Speeki Sentinel is the certification product through which this assessment is delivered. Organisations may build their own applicability assessment and evidence base for the EU Forced Labour Regulation on a self-assessed basis, without ever seeking Speeki Sentinel certification. Speeki Sentinel certification — the independent verification of that DDMS against the standard — is available once an organisation believes its approach is ready to be independently tested.
Speeki is an accredited certification body. For current information on the specific accreditations Speeki holds and their scope, please refer to speeki.com rather than relying on this whitepaper, as accreditation status and scope are maintained centrally and can change.
Closing Note
Size-threshold regimes are, in a sense, the easier ones to comply with — an organisation can determine applicability with a single headcount and turnover check, and stop there if the answer is no. A regulation with no threshold at all requires a different discipline entirely: assuming it applies until specifically checked otherwise, product by product, rather than assuming it does not apply because a different, unrelated regulation's threshold was not met. Given how much attention CSDDD's narrowing has received, the regulation most likely to be quietly overlooked by a smaller organisation is precisely the one built to catch it regardless of size.