If your supply chain touches a region with known state-imposed forced labour, the audit you commissioned last year may not count as evidence anymore.
The European Commission has published its implementing guidelines for the EU Forced Labour Regulation, and they’re specific about a category most due diligence programmes weren’t built to handle: state-imposed forced labour, or SIFL.
The audit problem
Here’s the part that affects you directly. A social audit carried out in a region affected by SIFL won’t be treated as credible evidence unless the auditor had unrestricted access to the site and workers were free to speak without supervision. In places where the state is involved, that almost never happens. Management knows when auditors are coming. Workers are briefed. Access is managed.
But there’s a second gap, and it’s separate from the access problem. A standard social audit tells you about conditions at the site being audited. It doesn’t tell you where that site’s raw materials came from. Most SIFL risk doesn’t start at the factory you have a contract with; it sits further upstream, at the raw material and processing stage, which is where most documented cases actually happen. A social audit isn’t built to trace that far back. That’s a different exercise, done through traceability verification rather than a social audit, and it’s usually the piece missing from the file.
The guidelines name other evidence types on top of both of these: open-source research, satellite imagery, trade data, traceability records. None of that replaces an audit programme. But your compliance file needs more than an audit certificate sitting in a folder. And that certificate may not even cover the tier where the risk actually sits.
Why these cases get prioritised
The Regulation works on a risk-based system. Bigger, more severe cases get investigated first. SIFL is rarely a single-factory problem. It reflects a labour system built into how a region operates, which is exactly the kind of large-scale, severe case the Regulation is designed to catch first. That puts SIFL cases at the front of the enforcement queue, ahead of more isolated supplier issues.
Anyone can now report a supplier
Alongside the guidelines, the Commission launched a Forced Labour Single Portal. It will hold the guidelines, the risk database, the list of national competent authorities and every published decision, in one place.
It also holds a single information submission point. This is a free online channel through which any individual or organisation can submit information about a product or company they believe is linked to forced labour, as long as there is a connection to the EU market. Trade unions, NGOs, journalists, former workers.
That changes where scrutiny comes from. The working assumption has generally been that exposure follows from what an authority finds on its own. From here, a submission from someone outside your supply chain entirely can put one of your suppliers on a regulator’s desk. You will not necessarily know it has happened.
Why “fix the supplier” doesn’t work here
Most due diligence assumes you have some influence over the supplier: flag a problem, get them to fix it, check back later. The guidelines acknowledge that doesn’t work when the government is the one mandating the labour. You can’t negotiate a state policy. So the practical question changes from “how do we fix this supplier” to “did we know about this exposure before we signed the contract.”
That’s a different kind of due diligence. It means knowing where your products are actually made, and more specifically, where the raw materials inside them come from. That’s the tier where most SIFL exposure starts, not the finished-goods supplier whose name sits on the invoice.
One region, one finding, many cases
There’s a knock-on effect here too. Evidence the Commission gathers in one case for a specific region will carry weight in other cases involving that same region. Risk doesn’t reset supplier by supplier. It builds regionally. If a factory near yours gets flagged, your exposure just went up too, even if nothing about your own supplier changed. And because most SIFL risk sits at raw material level, that regional exposure can reach you even when you have no direct relationship with the flagged site at all.
What to do before December 2027
Member States have to notify their penalty frameworks by 14 December 2026. The Regulation starts applying from 14 December 2027. Eighteen months sounds like a lot of time. It isn’t, if your current supplier programme can’t tell you with confidence which raw materials your products contain and where they came from.
One thing not to wait for: the Commission’s forced labour risk database, which is meant to flag widespread and severe risks by product and region, is still in development and has already passed its original mid-2026 target. When it lands it will sharpen where enforcement falls first. It won’t tell you anything about your own supply chain that you couldn’t have found out sooner.
The guidelines are built on frameworks most compliance teams already know – the UN Guiding Principles and the OECD Guidelines. So you’re not starting from nothing. But if your sourcing is concentrated in higher-risk regions, it’s worth checking now whether your current verification goes deep enough to hold up under this.
Get in touch and we can guide you through what that means for your supply chain.