EUDR Risk Assessment Template: Free Downloadable Guide for Exporters
Search for an EUDR risk assessment template and most of what comes back is either a vendor's locked demo, a country-specific forestry framework, or a generic ESG checklist with no real connection to the regulation's actual criteria.
The regulation itself is specific about what a risk assessment needs to cover. It isn't a single deforestation check — it's a structured review across country conditions, supply chain complexity, documentation quality, and several other factors, all analysed together before a shipment can be judged negligible risk.
This guide lays out a complete, practical template built directly around those criteria, along with the reasoning behind each section, so you're not just filling in boxes without understanding what a regulator would actually expect to see behind them.
Think of it less as paperwork and more as a structured argument. Every conclusion you record — negligible risk, or not — needs supporting evidence behind it, the same way a legal brief needs citations rather than assertions. A template only earns its usefulness if the person filling it in understands why each section exists, not just what box to tick.
One clarification before anything else: a risk assessment isn't the same document as a Due Diligence Statement, though the two are closely linked. The risk assessment is the analysis; the DDS is the formal filing that references its conclusion. Our EUDR Information System registration guide covers where that final filing actually happens once your risk assessment is complete.
Whether you need the full version of this template at all also depends on where your commodity originates. Our EUDR country risk classification guide explains which countries currently qualify for a lighter, simplified path that skips the formal risk assessment step entirely.
What follows is the template itself, section by section, along with the practical guidance needed to complete each part correctly the first time.
What an EUDR Risk Assessment Requires
The regulation requires operators to verify and analyse the information they've already collected about a product, then use that analysis to judge whether there's any risk the product is linked to deforestation, illegal production, or an untraceable supply chain.
That analysis has to draw on a defined, though non-exhaustive, set of criteria — country-level conditions, the presence of forests and indigenous communities on or near the sourcing area, deforestation and legality history, governance quality, and the complexity of the supply chain the product passed through before reaching the operator.
The output isn't a pass/fail checkbox. It's a documented conclusion — negligible risk, or not — that has to be defensible if a regulator asks to see how that conclusion was reached. Our DDS submission guide for the EUDR portal covers what happens once that conclusion is ready to be filed alongside a shipment.
It helps to think about why the regulation frames it this way rather than as a simpler checklist. Deforestation risk doesn't come from any single factor in isolation — a country with generally strong governance can still have a specific region under active deforestation pressure, and a well-documented supplier can still sit at the end of a supply chain complex enough to obscure exactly where material originated. The multi-factor structure exists precisely because none of these signals is reliable on its own.
There's also a practical reason to take the documentation seriously beyond the legal requirement itself. A well-maintained risk assessment becomes genuinely useful internal knowledge — a record of exactly which suppliers, regions, and intermediaries carry more risk, built up over time rather than reconstructed from memory every time a buyer asks a pointed question. Companies that treat this as a knowledge base rather than a compliance chore tend to spot emerging problems in their own supply chain well before an external audit ever forces the issue.
Who Needs One (and Who's Exempt)
Not every operator has to complete the full risk assessment process, and understanding the exemption is as important as understanding the requirement itself.
| Sourcing Situation | Risk Assessment Requirement |
|---|---|
| Sourcing exclusively from low-risk countries | Formal risk assessment and mitigation generally not required, unless a specific red flag emerges |
| Sourcing from standard-risk countries | Full risk assessment required, regardless of individual supplier reputation |
| Sourcing from high-risk countries | Full risk assessment required, with heightened scrutiny and documentation expectations |
| Mixed sourcing across multiple risk tiers | Full assessment required for any portion sourced from standard- or high-risk origin |
Even operators sourcing exclusively from low-risk countries aren't entirely exempt from every form of review. They're still expected to assess the complexity of their supply chain, the risk of their product being mixed with material of unknown or higher-risk origin, and the risk of deliberate circumvention — three checks that sit alongside, rather than fully inside, the formal risk assessment most of this guide focuses on.
For exporters shipping from a standard-risk origin such as Côte d'Ivoire, the full assessment isn't optional regardless of how strong an individual supplier relationship looks on paper. Our Ivory Coast cocoa compliance guide covers the country-specific traceability challenges that feed directly into this kind of assessment.
It's worth noting that the exemption for low-risk sourcing applies at the level of the classification, not at the level of any individual exporter's confidence in their own supply chain. An operator can feel entirely certain their specific supplier is clean and still be required to complete the full assessment, simply because the country of origin sits in the standard- or high-risk tier. Confidence in a relationship isn't a substitute for the classification the regulation actually looks at.
The Template: Core Sections
Below is the full working structure. Treat each section as a worksheet: fill in what's known, flag what isn't, and keep the underlying evidence attached to whatever conclusion you record.
| Section | What to Record |
|---|---|
| 1. Product & shipment identification | Product description, HS code, quantity, country/region of production |
| 2. Country-level risk factors | Country risk classification, deforestation trend data, governance and corruption indicators |
| 3. Plot-level risk factors | Forest proximity, presence of indigenous or local communities, land tenure clarity, deforestation history on or near the plot |
| 4. Supply chain complexity | Number of intermediaries, aggregation points, processing steps between farm and export |
| 5. Circumvention and mixing risk | Likelihood of product being blended with unverified or higher-risk material at any point in the chain |
| 6. Supplier and documentation reliability | Completeness of supplier records, history of missing or inconsistent documentation, any past non-compliance |
| 7. Overall risk conclusion | Negligible risk or not, with a clear rationale tying back to the evidence recorded above |
Section three deserves particular care in smallholder-heavy origins. A coffee lot assembled from hundreds of small farms, for instance, needs plot-level evidence behind every contributing farm, not just a general regional risk note. Our Ethiopia coffee compliance guide covers exactly this challenge in a sector where the average holding is a fraction of a hectare.
Sections four and five are the ones most templates online skip entirely, largely because they're harder to reduce to a simple yes/no. Supply chain complexity and mixing risk require genuine judgement about how a specific product physically moved from farm to export, not a lookup against a public database.
Treat the template as reusable infrastructure rather than a document you start fresh each time. Once sections one through four are populated for a given supplier or cooperative relationship, most of that information carries forward largely unchanged from one shipment to the next — it's sections five through seven, the risk conclusion and its supporting rationale, that need genuine reconsideration for each new batch or each scheduled review.
How to Score Each Risk Factor
A risk assessment isn't useful as a wall of unscored notes. Each section needs a working risk rating, alongside the evidence supporting that rating.
| Risk Rating | What It Typically Reflects | Action Required |
|---|---|---|
| Low | Well-documented, low-complexity sourcing with no red flags identified | Proceed with standard documentation retained |
| Moderate | Some gaps in documentation or supply chain visibility, no confirmed violations | Gather additional information before concluding negligible risk |
| Elevated | Significant data gaps, complex intermediated sourcing, or known regional deforestation pressure | Independent verification or audit before proceeding |
| Unacceptable | Confirmed or highly probable link to deforestation or illegality | Product cannot be placed on the EU market until resolved |
A rating of anything above "low" doesn't automatically block a shipment. It triggers the mitigation step — gathering more information, commissioning an independent survey, or working with the supplier to close a specific documentation gap — before the overall conclusion can reasonably move to negligible risk.
It's worth resisting the temptation to round every rating down to "low" simply to avoid the extra mitigation work. A rating exists to reflect the actual state of the evidence, not the outcome you'd prefer to reach. An assessment that consistently rates everything low regardless of genuine gaps in the underlying data is exactly the kind of pattern an audit is designed to catch, and it undermines the credibility of every other assessment a company has filed alongside it.
Step-by-Step: Completing Your Assessment
Working through the template in sequence keeps the process from turning into a scattered collection of half-finished notes.
- Confirm whether the full assessment even applies. Check your sourcing country's current classification before assuming the full process is required, since this can save considerable time on genuinely low-risk sourcing.
- Complete product and shipment identification first. This section is usually the fastest and anchors everything that follows to a specific batch, product description, and quantity.
- Work through country-level factors using published data. Deforestation trend data, governance indicators, and the country's own risk classification all belong here, drawn from publicly available sources rather than assumption.
- Move to plot-level detail using your geolocation records. This is where farm-specific data — forest proximity, tenure documentation, deforestation history — gets recorded against the actual coordinates on file, not a general regional description.
- Map the supply chain honestly, including every intermediary. Skipping a step in the chain to simplify the picture undermines the entire assessment's credibility and leaves a gap an auditor will likely notice.
- Assign a working risk rating to each section. Attach the specific evidence behind each rating rather than a general impression, so the rating can be defended on its own merits later.
- Write the overall conclusion and file it alongside your Due Diligence Statement. The conclusion should read as a reasoned judgement, not a rubber stamp, and should reference the specific sections that drove the outcome.
Once the assessment is complete, it becomes the backbone of whatever gets filed through the Information System. Treat it as a living document reviewed on a set schedule, not a one-time exercise closed the day it's first completed.
Common Mistakes to Avoid
A handful of recurring errors show up across risk assessments regardless of commodity or country, and most are avoidable with a bit of forethought.
The most common is treating a country's risk classification as the entire assessment. Country tier is one input among several, not a substitute for plot-level and supply-chain-level analysis. A low-risk country classification doesn't excuse a genuinely complex, poorly documented supply chain from closer scrutiny if a red flag does surface.
A second common mistake is letting the assessment go stale. Supplier relationships change, new intermediaries enter the chain, and a country's classification itself can shift. An assessment completed once and never revisited stops reflecting the actual risk of shipments moving a year or two later.
A third is under-documenting the supply chain complexity and mixing risk sections specifically. These are the two areas regulators are most likely to probe in an audit, precisely because they require judgement rather than a lookup, and a thin or vague entry here is an easy target for scrutiny.
A fourth, subtler mistake is delegating the entire assessment to a single team member without any internal review. Risk assessments benefit from a second set of eyes, particularly on the judgement-heavy sections, since one person's blind spot about a familiar supplier relationship can easily go unchallenged if nobody else reviews the reasoning before it's filed. Building a simple internal sign-off step into the process catches far more gaps than most companies expect.
A fifth mistake, easy to miss because it feels like diligence rather than a shortcut, is over-relying on a single data source for country-level factors while treating plot-level and supply-chain factors as an afterthought. Country data is the easiest section to complete because it's publicly available and doesn't require chasing anyone down for information. That ease is exactly why it's tempting to let it carry more weight in the overall conclusion than it should, when the regulation actually expects all four factor categories to inform the final judgement roughly equally.
- An EUDR risk assessment is a documented analysis across country, plot, supply chain, and documentation factors — not a single deforestation check.
- Operators sourcing exclusively from low-risk countries can generally skip the formal assessment, but still need to check supply chain complexity, mixing, and circumvention risk.
- The template's seven core sections should each carry a working risk rating and the specific evidence supporting it.
- A rating above "low" triggers mitigation, not automatic rejection — gathering more evidence can still resolve it.
- Assessments need periodic review, generally at least annually, since supplier relationships and classifications both change over time.
- Supply chain complexity and mixing risk are the sections most often under-documented, and the ones most likely to draw regulator attention.
Frequently Asked Questions
Is a risk assessment the same document as a Due Diligence Statement?
No. The risk assessment is the underlying analysis; the Due Diligence Statement is the formal filing that references its conclusion. The DDS doesn't contain the full assessment itself, but the filer must be able to produce it in full if a regulator asks to see it.
Do I still need a risk assessment if my country is classified low risk?
Generally no formal assessment is required, unless specific evidence emerges suggesting a risk of non-compliance. You still need to assess supply chain complexity, mixing risk, and circumvention risk regardless of classification, since those checks sit outside the formal exemption.
How often does a risk assessment need to be updated?
Generally at least annually, and sooner if a supplier relationship, sourcing region, or country classification changes in a way that could affect the original conclusion. Treat it as a living document rather than a one-time filing.
What happens if my risk assessment concludes anything above negligible risk?
The product cannot be placed on the EU market until the identified risk is mitigated, typically through additional information gathering, independent verification, or supplier engagement that resolves the specific gap identified in the assessment.
Can I use a generic ESG or forestry risk template instead of an EUDR-specific one?
Not reliably. Generic templates rarely cover the specific combination of country, plot, supply chain, and documentation criteria the regulation expects, and gaps in coverage are exactly what an audit is likely to catch, regardless of how thorough the template looks otherwise.
A risk assessment done properly isn't paperwork for its own sake — it's the reasoning an exporter can point to when a shipment's compliance is questioned. Building the template into a habit, reviewed on a schedule rather than assembled under deadline pressure, is what makes that reasoning hold up when it's actually tested. The exporters who treat this document as ongoing infrastructure, rather than a box to tick once per supplier relationship, are the ones with the least to worry about when a regulator eventually does ask to see it.
