Competent Authorities & Member States
Their Role in the EU Deforestation-free Regulation
Imagine you have reached January 2025, EUDR has already been
implemented, your supply chain uses an effective traceability system to collect
the necessary information, execute due diligence and ensure EUDR compliance. Now what?
Well, as every regulation worth its salt requires, you could be scrutinised by competent authorities. Let’s see how it works by analysing Chapter 3 of the Regulation, which defines the obligations of member states and competent authorities, including checks on relevant actors, corrective actions and penalties.
Definition and role of the competent authorities
Competent authorities are institutions nominated by the European Union member states to oversee the correct implementation of EUDR compliance guidelines inside the territory of their respective countries through planned checks, which must be stored for 10 years. These are different for operators and non-SME traders on one side, and SME traders on the other side.
The checks on operators and non-SME traders must be carried out on the due diligence system that the companies decided to use, especially the risk assessment and risk mitigation processes, as well as the documents and records illustrating how the due diligence system works. In addition, they should examine risk mitigation measures and due diligence statements related to the specific product or commodity that the operator is placing or exporting in the European market.
Normally, the checks would be restricted to what is discussed in the previous paragraph. However, in case some doubts emerge during the checks, the competent authorities might decide to inspect the products and commodities to ensure they correspond to what is declared in the due diligence statements, technical and scientific verifications on land plots and deforestation-free claims.
The checks on SME traders are limited to the information related to the relevant products that they are supposed to collect based on EUDR requirements. The information refers to the name, trade name or trademark, physical address, email address and, when applicable, the website of all operators and traders who supplied the concerned goods to them and to whom they supplied the concerned goods, alongside the reference number of the associated due diligence statements.
These checks are defined by competent authorities based on risk criteria, which should be determined through an analysis of aspects that can favour or are linked to non-compliance with EUDR. Some examples of these aspects are:
The EU Commission is expected to periodically validate the European-based risk criteria, while the competent authorities must include the established national risk criteria in an annual plan, along with a systematic addition of suggested risk criteria for high-risk countries and parts thereof. The annual plan should also contain the list of operators and traders that the authorities will check throughout the year, and for each of them potentially also the specific due diligence statements to be verified. These plans should be updated taking into account the acquired experience and the related outcomes, with the objective of increasing their effectiveness year by year.
Collaboration among Member States
The Regulation stresses in several paragraphs the need for a collaborative approach among investigative bodies of different member states, for instance by asking them to share reciprocally their plans and knowledge to coordinate joint efforts. This is especially important when the examined company is an operator stretching its business practices in more than one member state.
Cross-state collaboration should also concern the information about the operators and traders, their due diligence statements, and the description and outcome of the checks, which must all be uploaded to the EU information system. Competent authorities are also expected to cooperate with jurisdictions in third countries, for example in case there is a necessity to conduct field audits.
Relevant products requiring immediate action
Emergencies happen! What if there is a very high risk that the examined products are not compliant with EUDR? In that case, competent authorities must identify such situations as soon as possible and register them into the EU information system, after which they need to act promptly to stop the products from entering the EU market, or require customs authorities to intervene to stop their transit for three days every time. The expected collaboration between customs authorities and competent authorities is laid out in Articles 26 and 27 of the official text.
Reporting
EUDR also demands the various Member States to report on the enforcement results and achievements of the Regulation before 30th April of every year. The reporting should verge on:
How is it all possible?
Up to now, we have discussed that collaboration is defined as a key factor in EUDR’s success. To facilitate the activities of competent authorities, they need to access significant information about operators and traders, communicate with customs authorities, and receive guidance and support from the European Commission. How to accomplish it all? Through the EU Information System, the underlying platform keeps all stakeholders connected and will be available from December 2024.
The EU Information System will be accessible to all actors involved in EUDR compliance with the objective of streamlining the whole auditing procedure. In particular, the system will be used to select the operators and traders to be audited, allowing for cooperation among investigative bodies and optimisation of checks.
The System in fact allows several functionalities:

After the EU Information System is integrated with an electronic interface based on the European Union Single Window Environment, expected to be developed by the end of June 2028, the whole EUDR compliance process will acquire a direct link with the customs data and authorities, fostering collaboration also with those jurisdictions.
What happens if the competent authorities find you non-compliant?
Once the authorities determine a company is violating the EUDR requirements, they have two actions to perform. The first one is applying the penalties depending on the local regulations outlined by each country where the infringement took place. The second one is requiring a remediation of the non-compliance status of the examined products within a period of time that must be acceptable and indicated in the national legislation.
Concerning the penalties, each member state is obliged to lay down rules, following the principles of effective, proportionate and dissuasive sanctions. Penalties may include one or more of the following:
EUDR mandates also that each member state shall ensure to examine the minimum number of companies, based on the country where the products are produced. If the country of production is classified as low-risk, at least 1% of the total companies subject to the Regulation must be checked. For countries classified as standard-risk, this percentage increases to 3%, and for high-risk countries, not only does the percentage reach 9%, but authorities must also check 9% of the quantity of each of the relevant products.
These targets should be achieved individually for each type of commodity, meaning that the targets for each commodity must be met independently from the targets for other commodities. The regulation reports explicitly that the competent authorities cannot give notice to the companies of the imminent checks to avoid the alteration of their practices, unless the warning is imperative to conduct the check.
During their checks, competent authorities incur certain costs, not only related to the investigative activities, but also to the storage and management of confiscated non-compliant products. When companies are found guilty of non-compliance, they can be requested to sustain the costs, if allowed by the national legislation.
The details on the liable company and the penalty incurred will be notified according to current privacy laws to the European Commission, which will publish the list of convicted companies on its website with the necessary information to understand the circumstances of the infringement and the sanctions.
On the other side, the remediating actions to be carried out by the liable company comprise:
If the remediation does not take place within the agreed period of time, competent authorities must intervene to forcefully ensure that the disciplinary actions are implemented on the company side.
RADIX Tree for EUDR compliance
RADIX Tree is an effective due diligence system that enables you to fully meet EUDR requirements, minimising the risk of compliance failure. The intuitive design fosters collaboration and exchange of information among all stakeholders involved. You do not need to be alone in this challenging task. GTS is the partner you can trust to work along with you and help you reach your goals, step by step.






