Risk assessment and mitigation: building an evidence file that holds up
The regulation asks you to conclude that risk is negligible. That is a high bar and a specific word, and the difference between a file that supports it and one that merely asserts it is visible from the first page.

On this page
Of everything in the EUDR, the risk assessment step is where the most compliance effort is spent and the most of it is wasted. Wasted, usually, on producing a document that reads like a policy rather than an argument — pages describing what the company intends to do, and very little establishing what is true about the specific plots a specific consignment came from.
A competent authority reading your file is asking one question: does the evidence here support the conclusion that risk was negligible when the statement was filed? Everything that does not speak to that is padding.
The standard is negligible, and the word is load-bearing
Risk mitigation is not a matter of reducing risk to something acceptable and proceeding. Where the risk assessment finds anything more than a negligible risk of non-compliance, mitigation is required, and the products cannot be placed on the market until the risk has been brought down to negligible.
In practice this means there is no residual-risk category to park difficult suppliers in. Either you can conclude negligible or the goods do not move. A great many supply chains built for cost and speed simply cannot produce that conclusion without being restructured, and the earlier that is confronted the cheaper it is.
There is no 'accepted risk' box
Frameworks imported from other compliance domains often have one. This regulation does not. A documented decision to accept a more-than-negligible risk is a documented decision to place non-compliant goods on the market.
What the assessment has to cover
The regulation sets out the criteria, which is helpful — it means the exercise has a defined shape rather than being a free-form judgement. Broadly, an assessment has to take into account:
- The risk classification of the country or region of production, and of any country the commodity passed through.
- The presence of forest, and the prevalence of deforestation or forest degradation in the area of production.
- The prevalence of indigenous peoples, and whether there are substantiated claims about their rights.
- Concerns about the country of production and origin, including corruption, document falsification, weak law enforcement and armed conflict.
- The complexity of the supply chain, and in particular any difficulty in connecting commodities to the plot where they were produced.
- The risk of mixing with products of unknown origin or from areas where deforestation has occurred.
- Complementary information, including third-party certification and independently verified schemes.
The one that determines whether the rest of the analysis is worth anything is supply chain complexity — specifically, the difficulty of connecting a commodity back to its plot. If you cannot make that connection reliably, every other criterion is being assessed against an unknown, and the file cannot support a negligible conclusion no matter how thick it is.
The assessment is about goods, not about suppliers
This is the most common structural mistake. Companies build a supplier risk assessment, approve a supplier, and treat everything subsequently received from them as covered.
The regulation's question is about the relevant products — this consignment, from these plots, produced in this period. A supplier assessment is useful input to that, and it is not a substitute. A well-governed cooperative can deliver a batch containing material from a plot cleared in 2022 without any bad faith on anyone's part; that is precisely the scenario plot-level evidence exists to catch.
A practical test of your file
Pick a consignment from six months ago at random and try to reconstruct which plots it came from and what was known about them at the time. If that takes longer than an afternoon, the file will not survive a check — an authority will pick the consignment, not you.
What mitigation actually looks like
Mitigation means the steps you take to bring an identified risk down to negligible. The regulation contemplates additional information, independent surveys or audits, supplier capacity support, and other measures adequate to the risk found.
| What the assessment found | Mitigation that speaks to it |
|---|---|
| Plot geometry missing for part of a cooperative's membership | Field collection for the missing plots. Excluding those members from EU-bound volume until it exists. |
| Satellite evidence of clearance inside a supplied plot after 2020 | Investigation of that plot, and exclusion of its output. Not a supplier-wide policy statement. |
| Aggregation point where material from many farms is mixed | Physical segregation, or identity-preserved sourcing. Documentation alone cannot unmix a batch. |
| Weak evidence of legal production in the country of production | Documentary evidence specific to the areas of law the regulation names, or independent verification. |
Common findings and the mitigation that actually answers them
The pattern is that credible mitigation is specific and often commercial. Training programmes and codes of conduct are worth having and do not, by themselves, convert a plot with visible forest loss into a compliant one.
Substantiated concerns reopen everything
A substantiated concern is a duly reasoned claim based on objective and verifiable information. It can come from an NGO report, a competent authority, a journalist, a whistleblower, or your own monitoring.
Once one exists, the position changes immediately. Simplified due diligence is no longer available for the affected goods, the risk assessment has to be revisited, and continuing to place goods on the market without resolving the concern is not defensible. The expected response is to suspend and verify, not to note it and continue.
Because concerns arrive from outside on someone else's timetable, this needs to be a defined process with a named owner before it is needed. Discovering who decides to halt a shipment while a shipment needs halting is not a good position.
Records, and the five-year problem
Documentation is retained for five years, and the retention is not just of conclusions. The file has to show what you knew, when you knew it, and what you did about it — which means the imagery, the datasets, the supplier responses and the dates all have to be preserved alongside the assessment.
Five years is long enough for a satellite data provider's API to change, for a supplier to cease trading, and for everyone involved in the original decision to leave. Anything that is a live link rather than a stored artefact is a gap. So is any conclusion recorded without the evidence that produced it.
Anchor the file to consignments
Supplier-level assessments are inputs. The unit that gets checked is a consignment traced back to plots.
Store evidence, not references to evidence
The imagery and the dataset version as they were on the day, not a link that will resolve differently in 2031.
Record the reasoning, not only the verdict
"Negligible" with no argument behind it is an assertion. The argument is what makes it a finding.
Define the substantiated-concern process in advance
Who assesses, who can halt, how quickly. Before you need it.
A good evidence file is not a long one. It is one where somebody who was not there can follow, for a specific consignment, how you got from plot coordinates to the word negligible — and can see what you would have done differently if the imagery had shown something else.
Primary sources
- 1.
- 2.
Published · Updated · Last reviewed against the sources listed above.
ERWAY Compliance Team
Regulatory research
We read the consolidated text and the Commission guidance so that compliance teams do not have to, and we build the platform that turns the result into filed statements.
Read next

Country benchmarking: what the risk tiers change, and what they don't
How EUDR country benchmarking works, what Implementing Regulation (EU) 2025/1093 classified, what simplified due diligence actually removes, and why the Parliament's objection changed nothing.
6 min read

Does certification make you EUDR compliant?
Why there is no such thing as EUDR certification, what third-party schemes can genuinely contribute to risk assessment, and the gaps you still have to fill yourself.
6 min read

Supplier questionnaires: proving EUDR readiness before the first plot lands
Why EUDR teams should run supplier questionnaires early: readiness signals, dynamic legality questions, risk scoring, and how ERWAY turns builder → send → results into an audit-ready PDF.
3 min read
