Temps de lecture : 8 minutes
📌 Key points to remember :
- The duty of vigilance (French law 2017) requires large companies to identify and prevent serious risks in their supply chain; not just to declare them.
- Compliance no longer relies on a CSR policy: it relies on a system capable of producing verifiable evidence.
- The collapse of Rana Plaza (2013) marked a turning point: major risks often lie outside the walls of the company.
- Three levels of maturity exist: documentary compliance (questionnaire), documented compliance (evidence), risk management (segmentation + monitoring).
- The CSDDD generalizes this logic at the European level between 2027 and 2029.
- SME suppliers are also concerned: their clients subject to the duty of vigilance ask them for ESG data.
The duty of vigilance is no longer limited to the publication of a plan or a CSR report. Since the French law of 2017, and the subsequent European developments (CSRD, CSDDD, sectoral regulations), companies must now demonstrate that they truly know their supply chain and that they act in proportion to the identified risks. A paradigm shift that places suppliers, and the reliability of the data concerning them, at the heart of compliance.
The real change is not legal. It is organizational.
For a long time, companies approached social responsibility issues as an essentially declarative subject. CSR departments published an annual report. Purchasing departments occasionally distributed questionnaires to their suppliers. Legal departments ensured compliance with regulatory obligations.
This organization responded to a simple logic: to demonstrate the existence of commitments.
Today, this approach is reaching its limits.
With the French law on the duty of vigilance, and the European developments around the CSRD, the CSDDD, or sectoral regulations on deforestation, batteries, or forced labor, companies are no longer only expected to fulfill their commitments. They must demonstrate that they know their supply chain, that they prioritize their risks, and that they implement appropriate actions.
They must also be able to demonstrate that the measures taken are proportionate to the identified risks, in accordance with the OECD and United Nations guidelines.
Compliance no longer relies on a CSR policy. It relies on a system capable of producing evidence. This is precisely what makes the duty of vigilance a foundational text.
Vocabulary
Duty of vigilance : French law of 2017 that requires large companies to identify and prevent serious risks to human rights, health, safety, and the environment, including those resulting from the activities of their suppliers and subcontractors.
CSDDD (Corporate Sustainability Due Diligence Directive) : European directive that generalizes the logic of the French duty of vigilance across the European Union, imposing a duty of reasonable diligence on large companies regarding their value chain.
Declarative logic vs proof logic : in a declarative logic, a company claims to have CSR commitments; in a proof logic, it must demonstrate, with supporting documents, that these commitments actually translate into verifiable actions.
The duty of vigilance: a paradigm shift
The Rana Plaza, a tragic turning point
On April 24, 2013, the collapse of Rana Plaza in Bangladesh resulted in the death of more than 1,100 people and injured 2,500. The building housed several subcontracting workshops for international brands.
This disaster highlighted a reality that many preferred to ignore: the most serious risks — to human rights, to safety, to the environment — often lie far from the headquarters, in complex and opaque subcontracting chains.
Rana Plaza has become the symbol of a global awareness and directly fueled the reflections that led to the French law on the duty of vigilance, and then to the European CSDDD directive.
What the law actually requires
The law applies to French companies with more than 5,000 employees in France, or 10,000 worldwide (headquarters and subsidiaries included). It requires them to establish and implement a vigilance plan, made public, covering:
- The identification of risks to human rights and the environment in their activities and those of their suppliers and subcontractors
- Regular risk assessment procedures
- Mitigation or prevention actions that are appropriate
- An alert mechanism and reporting collection
- A system for monitoring and evaluating the measures implemented
The publication of the plan is only the visible part of the system. What matters is being able to demonstrate that the plan is real, implemented, and effective.
(Source: Légifrance, law n°2017-399 of March 27, 2017)
Why suppliers are becoming the center of compliance
New questions to ask about your suppliers
The duty of vigilance requires companies to ask questions that were not in their usual scope:
- Do my suppliers respect fundamental labor rights?
- Under what conditions are my raw materials produced?
- What are the environmental practices of my subcontractors?
- Do my tier 2 and 3 suppliers present risks that I have not identified?
These questions cannot remain unanswered without documentation. A vigilance plan without verifiable data on suppliers is not a vigilance plan; it is a statement of intent.
Why are all companies concerned, even SMEs?
The legal threshold (5,000 employees in France) excludes the vast majority of French companies from the direct obligation. But the reality is more nuanced.
Companies subject to the duty of vigilance pass their obligations down their supply chain. They ask their suppliers (including SMEs) to document their CSR practices, respond to questionnaires, and provide evidence. Not being able to structure this data, it is to take the risk of being delisted or losing markets.
Direct regulatory pressure only concerns a minority of companies. Indirect commercial pressure affects the entire chain.
From declaration to proof: the real challenge
Implementing a vigilance plan is relatively simple. Making it live in operational reality is much more complex.
Companies that take this seriously quickly encounter a reality: their suppliers are numerous, their practices little known, and the available information is often declarative, unverified, and scattered across Excel files, emails, and PDFs.
The logic of proof imposes three things that few organizations master today:
Documenting: having real supporting documents (certifications, audits, internal policies, HR data) and not just self-filled declarations.
Tracing over time : being able to demonstrate that the assessment took place, when, according to which framework, and what corrective actions were taken.
Sharing between functions : the data collected by Procurement must feed into the sustainability report (CSRD), the risk management strategy (Legal), and investment decisions (Finance). It is no longer siloed data.
Three levels of maturity regarding the duty of vigilance
Level 1: documentary compliance
The company collects questionnaires from its suppliers and archives them. It can produce a document certifying that the process exists. But the reliability of the data is limited: the responses are declarative, without verification of evidence. In case of litigation, this level of maturity is insufficient.
Level 2: documented compliance
The company goes further: the questionnaires are accompanied by supporting documents (charters, certifications, reports, contracts), verified and tracked. A score or level of maturity is assigned to each supplier. The data is stored in a centralized tool, accessible to the Purchasing and CSR teams.
This is the minimum level for real compliance with the duty of vigilance.
Level 3: risk management
Suppliers are segmented by risk level (geographic, sectoral, subcontracting rank). The evidence is updated regularly according to a defined schedule. The results of the assessment guide purchasing decisions, improvement plans, and training actions. The Purchasing, CSR, and Legal departments share a common vision.
This level of maturity transforms regulatory constraints into operational leverage.

Why traditional tools show their limits
Most companies still manage their supplier data in Excel files, email boxes, and shared folders. This organization presents structural limits in the face of the requirements of the duty of vigilance:
- Impossible traceability : who collected which data, when, according to which reference?
- Unreliable : the responses are declarative, without verification of the provided evidence.
- Random updates : the data ages without anyone being in charge of monitoring.
- Siloing between functions : Purchasing has its files, CSR has its own, Legal has its own, without a consolidated view.
- Limited scalability : beyond a few dozen suppliers, manual management becomes unmanageable.
In the event of legal action, these limits become vulnerabilities. The burden of proof lies with the company — and an Excel file does not constitute proof.
The duty of vigilance is just the beginning: CSRD, CSDDD, and judicialization
The CSDDD (EU Directive 2024/1760, adopted in May 2024) generalizes a logic similar to the French law of 2017 on a European scale, with a gradual implementation:
- 2027: companies with more than 5,000 employees and revenue exceeding €1.5 billion
- 2028: companies with more than 3,000 employees and revenue exceeding €900 million
- 2029: companies with more than 1,000 employees and revenue exceeding €450 million
(Source: Directive (EU) 2024/1760; Reglementation-environnement.com, February 2026)
The CSRD imposes, in parallel, detailed reporting on the value chain, including the working conditions of suppliers, scope 3 emissions, and the traceability of raw materials. The two texts reinforce each other.
Judicialization is accelerating. The first legal actions against large French companies under the duty of vigilance have taken place. The trend is amplifying as NGOs and unions take ownership of these new avenues for recourse. What was a theoretical risk in 2017 has become a concrete operational risk in 2026.
Conclusion
The duty of vigilance has inaugurated a new era of corporate responsibility: one where compliance is assessed not on statements, but on evidence. An era where the supply chain becomes the primary risk area and, simultaneously, the primary area of action.
Companies that have understood this no longer treat the evaluation of their suppliers as an administrative exercise. They make it a system of knowledge of their ecosystem — powered by verifiable data, updated regularly, shared among the functions that need it.
It is under this condition that the duty of vigilance ceases to be a constraint to become what it can be: a competitive advantage for those who anticipated it.
Une question ?
Because it introduced a new idea into French law: a company can be held responsible for risks that do not materialize in its own activities, but with its suppliers or subcontractors. It has shifted CSR compliance from a declarative logic (stating commitments) to a logic of proof (demonstrating that concrete and proportionate actions have been implemented). It is this principle that today inspires the European CSDDD.
A company must be able to demonstrate that it has a structured approach to identify the most significant risks, regularly assess its suppliers, prevent or mitigate identified impacts, track the actions taken over time, document the entire process, and establish alert and remediation mechanisms. The publication of the plan is only the visible part of the system.
Level 1 (documentary compliance) involves collecting questionnaires and archiving them — the data exists but its reliability is limited. Level 2 (documented compliance) adds verifiable evidence: policies, certifications, audits, indicators. Level 3 (risk management) goes further: suppliers are segmented by risk level, evidence is updated regularly, and the Purchasing, CSR, and Legal departments share a common vision to guide decisions.
No. The French law of 2017 was pioneering, but the movement is now European. The CSDDD directive (EU Directive 2024/1760, adopted in May 2024) generalizes a similar logic across the entire European Union, with a phased implementation between 2027 and 2029 for large companies. In parallel, the CSRD imposes reporting obligations on the value chain, and several sectoral regulations (deforestation, batteries, forced labor) extend these requirements to specific sectors.
(Source: Directive (EU) 2024/1760; Regulation (EU) 2026/470)
🔗 Sources
- Légifrance. Law No. 2017-399 of March 27, 2017, relating to the duty of vigilance.
- Directive (EU) 2024/1760 — CS3D. OJ, July 2024.
- Directive (EU) 2026/470 — Omnibus I / CSRD. OJ, February 26, 2026.
- Reglementation-environnement.com. CS3D and duty of vigilance. February 2026.
- OECD. Guiding principles for multinational enterprises.
- United Nations. Guiding principles on business and human rights (Ruggie).