EUDR Record-Keeping and Audit Readiness: What You Must Retain After Filing Your DDS

Filing your due diligence statement (DDS) in TRACES NT feels like crossing the finish line. It isn't. The moment you submit, a five-year clock starts - and the records you keep (or fail to keep) from that point forward will determine what happens when a competent authority comes knocking.
This guide is for compliance owners who already understand how to file a DDS and want to know what comes next: what to retain, how long to keep it, how the annual review obligation works, and what an audit actually looks like in practice.
The Five-Year Clock: When It Starts and What It Covers
Operators and non-SME traders must retain all EUDR due diligence documentation for at least five years from the date the product is placed on the EU market or exported. This applies equally to operators filing full DDS statements and to non-SME traders who carry the same due-diligence obligations as operators.
The clock starts on the date of placement or export - not the date you filed the DDS, not the date the shipment arrived at customs. If you place a product on the EU market on 15 January 2027, your records for that shipment must be accessible until at least 15 January 2032.
Missing records = non-compliance. Under the EUDR, the inability to produce documentation is treated as a compliance failure in its own right — regardless of how thorough your original due diligence was. A clean DDS reference number is not a substitute for the underlying evidence.
Some practitioners recommend planning for seven years rather than five, noting that adjacent EU regulations have used longer retention windows and that downstream customers sometimes request retrospective documentation.
What You Must Actually Keep: A Record-by-Record Inventory
The EUDR does not prescribe a specific filing format or system - but it is precise about what must be retained. The table below maps each record category to the due-diligence step it supports.
| Record Category | Legal Basis | What to Keep | Who Must Keep It |
|---|---|---|---|
| Due diligence statements & reference numbers | Art. 4 / Annex II | Copies of every DDS filed, plus the unique TRACES reference number linked to each shipment or batch | Operators; non-SME traders |
| Geolocation files | Art. 9 | GPS coordinates or GeoJSON polygons for every production plot; WGS-84 format | Operators; non-SME traders |
| Article 9 information package | Art. 9 | Supplier name, address, email, web address; quantities; country and region of production; HS codes; supporting legality documents | Operators; non-SME traders |
| Risk assessment reports | Art. 10 | Documented analysis of deforestation and legality risk, including data sources, methodology, and conclusion | Operators; non-SME traders (standard/high-risk sourcing) |
| Risk mitigation evidence | Art. 11 | Records of any mitigation measures taken — third-party audits, satellite imagery reports, supplier corrective actions, field visits | Operators; non-SME traders (where risk was non-negligible) |
| Legality / legal-compliance documents | Art. 9(1)(g) | Permits, land titles, harvest licences, export certificates, and any other evidence of compliance with country-of-origin law | Operators; non-SME traders |
| Due diligence system documentation | Art. 12 | Written description of the due diligence system, version history, annual review records, and any updates triggered by material changes | Operators; non-SME traders |
| DDS reference numbers (downstream) | Art. 5(3)–(4) | Reference numbers received from upstream operators, linked to each incoming delivery | First downstream operator in the chain; non-SME traders |
A few points worth emphasising:
- Geolocation is non-negotiable at every risk tier. Even operators sourcing from low-risk countries must collect and retain geolocation data under Article 9. The simplified due-diligence pathway removes the risk-assessment step, not the information-collection step.
- The DDS reference number alone is not enough. The reference number is the pointer; the underlying documentation is the proof. Auditors expect to see both.
- Certifications (FSC, PEFC, Rainforest Alliance) support your records but do not replace them. You still need geolocation, DDS references, and a traceable chain that an auditor can follow.
The Article 12 Annual Review: A Separate, Ongoing Obligation
Many compliance teams treat the due diligence system as a one-time setup task. Article 12 says otherwise.
Under Article 12 of the EUDR, operators must establish, document, and keep up to date a due diligence system, and review it at least once per year - and whenever relevant developments occur. The European Commission's own guidance confirms this: "The system must be updated whenever anything important changes, and operators need to review it at least once per year."
What counts as a "relevant development"? In practice: a country-risk reclassification affecting your supply chain, a change in supplier, a new commodity or product line, a substantiated concern raised by a third party, or a finding from an internal audit.
Non-SME operators are also required to publicly report on their due diligence system on an annual basis under Article 12(3). This public report covers the entire due diligence system - procedures, information collection, risk assessment, risk mitigation, and the result of the annual system review. Companies already subject to CSRD can integrate this report into their sustainability disclosure rather than producing a separate document.
What the annual review should produce:
- A written record confirming the review was conducted, by whom, and on what date
- A log of any changes made to the system and the reason for each change
- Updated risk assessments for any suppliers or origins where the risk profile has shifted
- Archived copies of previous versions of the system (version history)
All of these records must themselves be retained for five years.
What a Competent-Authority Audit Actually Looks Like
EUDR inspections can be unannounced - competent authorities may request documentation, review systems, or inspect facilities without prior notice. This is a meaningful difference from scheduled financial audits, and it has direct implications for how you organise your records.
Enforcement is risk-based. Authorities must check a minimum share of operators each year: 9% of operators sourcing from high-risk countries, 3% from standard-risk countries, and 1% from low-risk countries. A move in your country's risk classification - which can happen without warning - immediately changes your audit exposure. (See our country risk tier guide for the current classification list.)
What auditors actually examine:
Dry runs conducted by Belgian, French, German, and Dutch competent authorities in 2025 offer the clearest picture yet of what inspectors expect. The key findings: competent authorities expect operators to demonstrate a functioning, company-specific due diligence system embedded into day-to-day operations - not a system that exists only on paper. They will not accept outcome statements or executive summaries as proof of compliance; they expect to see all the underlying information used to reach the operator's conclusion.
In practice, a competent-authority check on an operator or non-SME trader will typically cover:
- The due diligence system itself - documented procedures, risk assessment methodology, and evidence that the system is actually applied to every shipment
- Risk assessment and mitigation records - not just the conclusion ("negligible risk") but the data and analysis that support it
- Traceability tests - authorities may ask you to trace a specific product on the market back to its production plot, step by step
- DDS reference chains - the link between each reference number and the underlying Article 9 information package
- Annual review records - evidence that the system has been reviewed and updated as required
Checks can also include physical inspections, sampling of consignments, satellite verification, and cross-checks against reference numbers in the EU Information System.
Audit Readiness: A Practical Checklist
Common Pitfalls That Turn Audits Into Penalties
1. Scattered spreadsheets and email chains The most common failure mode. Geolocation files live in one folder, supplier declarations in another, risk assessments in someone's inbox. When an authority requests records, the scramble to assemble them is itself a red flag - and the gaps it reveals can be fatal.
2. Storing the DDS reference number without the underlying documentation The reference number is a pointer, not a record. Auditors expect the full Article 9 information package, the risk assessment, and the mitigation evidence to be retrievable alongside it.
3. No version history on the due diligence system If your system has been updated - and it should have been, at least annually - you need to be able to show what it looked like at the time each DDS was filed. A single "current version" document with no history fails this test.
4. Treating the annual review as a formality A one-line note saying "system reviewed, no changes" is unlikely to satisfy an inspector. The review should produce a dated record of what was examined, what was found, and what (if anything) was changed.
5. Certifications filed in place of legality documents Third-party certifications are useful supporting evidence, but they are not a substitute for the specific legality documents required under Article 9(1)(g). Both must be on file.
6. Inability to retrieve records quickly Industry practice and vendor guidance consistently cite the ability to produce records within approximately 24 hours of a request as the practical benchmark for audit readiness. If your records require days to assemble, you are not audit-ready.
Penalties for Record-Keeping Failures
The EUDR's penalty framework under Article 25 applies to record-keeping failures just as it does to substantive due-diligence failures. Non-compliance can trigger fines of at least 4% of a company's annual EU-wide turnover, confiscation of products or revenue, exclusion from public procurement and EU funding for up to 12 months, and temporary market bans.
The practical risk for smaller operators is often more immediate: downstream buyers who cannot satisfy their own obligations will stop buying from suppliers who cannot produce clean records. The reputational and commercial consequences can arrive faster than the regulatory ones.
For a full breakdown of the penalty regime, see our EUDR penalties and enforcement guide.
Deadlines: When Record-Keeping Obligations Begin
Large and medium operators and traders must comply from 30 December 2026; micro and small operators from 30 June 2027 - except those already covered by the EU Timber Regulation, who must comply from 30 December 2026. Record-keeping obligations run from the date of first placement, so the clock starts the moment your first compliant shipment hits the EU market.
If you are in the large/medium category, that means your record-keeping infrastructure needs to be in place before December 2026 - not built in response to an audit request.
FAQ
Does the five-year retention period apply to SME traders?
SME traders have lighter obligations than operators — they do not file a DDS and are not required to conduct full due diligence. However, they must still collect and retain certain information (supplier and customer details, and DDS reference numbers where their direct supplier is an operator) for five years. Non-SME traders carry the same full due-diligence and retention obligations as operators.
When exactly does the five-year clock start?
The clock starts on the date the product is placed on the EU market or exported — not the date the DDS was filed, and not the date of customs clearance. For a product placed on the market on 1 March 2027, records must be retained until at least 1 March 2032.
Do I need to keep records for every individual shipment, or can I aggregate?
Each DDS must be linked to the specific shipment or batch it covers, and the underlying Article 9 documentation must be retrievable per DDS. You can use a single DDS for multiple shipments if due diligence procedures have been consistently followed for all commodities covered — but the records supporting each shipment must still be individually traceable.
What format must records be stored in?
The EUDR does not mandate a specific storage format or system — only that records are retained for five years and are rapidly retrievable upon request. Geolocation data must be in a compatible format (GeoJSON or WGS-84 coordinates). In practice, digital storage with clear file naming and linkage between DDS reference numbers and underlying documents is strongly advisable.
What happens if a country's risk tier changes and my records no longer reflect the current risk level?
A risk-tier reclassification is exactly the kind of 'relevant development' that triggers an obligation to review and update your due diligence system under Article 12. You should re-assess risk for affected supply chains, document the review, and update your system accordingly. Records of the previous assessment remain on file — you are adding to the record, not replacing it.
Can a competent authority audit records from before the enforcement deadline?
Competent authorities can audit records from the date of first placement onward. The five-year window runs forward from each placement date, so an authority checking your records in 2028 can request documentation going back to your first compliant shipment in late 2026 or 2027.
Does the Article 12(3) annual public report replace the internal annual review?
No. The public report (required only for non-SME operators) makes the due diligence system visible externally. The internal annual review under Article 12(2) is a separate obligation — it is the process of actually checking and updating the system. The public report is the output; the review is the work.
Stay current: EUDR guidance and country risk classifications are updated regularly. Subscribe to The EUDR Brief - our free monthly newsletter - to get changes delivered to your inbox before they affect your compliance calendar.
Related reading

The EUDR Legality Requirement: What "Legally Produced" Actually Means
Deforestation-free alone is not EUDR compliance. This plain-English guide unpacks the legally produced requirement - all seven areas of law, the evidence you need, and how it fits your due diligence.

EUDR and Composite Products: What You Actually Have to Do When Your Product Contains Multiple Commodities
Your chocolate bar contains cocoa and palm oil. Your sofa has a wooden frame and leather upholstery. Here's exactly how EUDR due diligence works when your product spans multiple supply chains.

The 2026 EUDR Simplification Package Explained: What Actually Changed for Your Business
The May 2026 EUDR simplification package clarifies obligations - it does not delay enforcement. Here is what changed for first operators, downstream operators, and micro/small businesses.