Level 2 · Decision guide·EU Voluntary Standard 2026 · Disclosure guides
Protected Undertaking Self-Declaration: What Suppliers and Requesters Should Document
A proportionate record for entity identity, value-chain relationship, employee test, reporting period, basis, approval, expiry, correction and requester reliance.
Published passport
Current as at 10 August 2026
Reviewed by
Dr Ross KurinkoLinkedIn
Strategic ESG Advisor · IFRS S1 & S2 / GRI / ESRS expert
GRI Certified Global Trainer · PhD, University of Cambridge · ESG-AI expert
15+ years on FTSE 100 & Fortune Global 500 disclosures
Canary Wharf, London
LRA educational guidance · Not issued or endorsed by European Commission
Edition written against
—
Published
10 Aug 2026
Knowledge Hub guide
Last reviewed
10 Aug 2026
Short answer
The answer, before the reasoning
Use a short, controlled declaration that proves the two statutory criteria - employee threshold and value-chain relationship - and also identifies the employee band needed for Annex II. State the legal entity, period, average employee number, calculation/entity basis, recipient relationship, authorised signatory, issue date, expiry and correction route.
The supplier should retain supporting records. The requester may rely without routine verification unless it knows, or can reasonably be expected to know, that the declaration is manifestly incorrect.
Technical status
EDITORIAL STATUS
<p>The reliance mechanism is grounded in Directive (EU) 2026/470. The proposed declaration fields and evidence controls are implementation recommendations, not a prescribed EU form. Confirm national transposition, the correct entity and employee calculation basis before use.</p>
Why a self-declaration needs design even though verification is not required
Directive (EU) 2026/470 deliberately reduces burden by allowing reporting undertakings to rely on a self-declaration from value-chain undertakings. The requester is not required to verify the information. This is a strong proportionality signal: the mechanism should not be converted into a routine supplier audit.
At the same time, a declaration consisting only of “we have fewer than 1,000 employees” may be difficult to use. It may not identify the legal entity, period, relationship, employee calculation basis or the 10-employee band required for Annex II branching. A practical template should therefore add enough structured information to make reliance safe without demanding the source records that the Directive says need not be routinely verified.
Quick orientation
Figure 1. A protected-status declaration should be prepared, approved, issued, relied on proportionately, monitored and renewed or corrected. London Reporting Academy learning visual.
In practice
| Question | Practical answer |
|---|---|
| What does protected status require? | The undertaking is in a reporting undertaking’s value chain and does not exceed an average of 1,000 employees during the preceding financial year. |
| Can the requester rely on a self-declaration? | Yes. |
| Must the requester verify it? | No, unless it knows or can reasonably be expected to know that it is manifestly incorrect. |
| Why state the 10-employee band? | Annex II has different cap content for 10-or-fewer and more-than-10 employees. |
| Is there a prescribed EU form in the cited text? | No detailed form is prescribed; this article proposes an implementation template. |
| Should payroll files be attached? | Normally no. Retain support internally and use proportionate clarification only when needed. |
The legal core: two criteria and one reliance exception
For the value-chain-cap provisions, a protected undertaking is an undertaking that does not exceed, on its balance-sheet date, an average number of 1,000 employees during the preceding financial year and is in the value chain of a reporting undertaking. Both elements matter. A company with 200 employees is not relying on this status in the abstract; it is declaring status in relation to the relevant reporting-undertaking value-chain request.
The requester may rely on the declaration and is not required to take verification steps. The exception is where the requester knows, or can reasonably be expected to know, that the declaration is manifestly incorrect. The word “manifestly” supports a high-threshold, obvious-error approach rather than routine audit. National transposition and legal guidance should be checked before formalising the exception procedure.
Rule
SOURCE LIMITATION
<p>The cited Directive does not prescribe the detailed declaration form, expiry period or employee calculation methodology used below. Those are implementation controls designed to make the statutory mechanism workable and should be adapted to national law and the relevant entity structure.</p>
Recommended declaration fields
1. Supplier identity
Identify the exact legal entity making the declaration. Include legal name, registration number, registered office or country, and a contact for corrections. Avoid a trading name without the underlying entity. Where a parent issues the declaration for subsidiaries, specify the authority and list the entities covered.
2. Requester and value-chain relationship
Identify the reporting undertaking or requester to which the declaration relates and briefly state the value-chain relationship, such as direct supplier, subcontractor or distributor. The declaration need not disclose commercially sensitive contract terms. It should, however, make clear why the protected-undertaking test is being applied.
3. Balance-sheet date and preceding financial year
State the balance-sheet date and the preceding financial year used for the average employee number. A declaration without a period becomes stale quickly and can be misapplied to later requests. Where the supplier has a non-calendar year, show the exact dates.
4. Average employee number and method
State the average employee number and describe the counting basis used under the applicable accounting or national rules. The cited EU provision does not provide a universal calculation method in the self-declaration clause. Do not invent one in the form. Instead, state whether the number is based on headcount or another legally applicable measure, how the average was determined, which entities were included and who reviewed the calculation.
5. Entity or group basis
The declaration should explicitly state whether the employee figure is for the individual legal entity or another group/consolidated basis and list the entities included. This is a transparency field, not a universal conclusion that group aggregation is always required. The correct legal basis must be reviewed under the transposed rules and the structure of the request.
6. Annex II employee band
The form should show one of three practical outcomes: 10 employees or fewer; more than 10 and no more than 1,000; or more than 1,000 / not protected. The first two protected bands matter because Annex II contains a narrower cap for undertakings with 10 employees or fewer.
7. Declaration statement and limitations
The supplier should state that, based on the information and basis identified, it meets the protected-undertaking criteria for the specified relationship and period. If the conclusion depends on a pending transaction, provisional average or unresolved group-basis question, disclose that limitation rather than giving an unconditional statement.
8. Approval, issue, expiry and correction
Name an authorised signatory and role, issue date, validity period, expiry or next-review date, and contact for corrections. The declaration should require prompt correction or withdrawal if the employee threshold, entity basis or value-chain relationship changes materially.
In practice
| Field | Recommended content | Public/shared evidence? |
|---|---|---|
| Supplier legal entity | Legal name, registration number, country and contact | Declaration |
| Requester / relationship | Reporting undertaking and value-chain relationship | Declaration; contract details usually retained |
| Period | Balance-sheet date and preceding financial year | Declaration |
| Average employee number | Value and applicable counting method | Declaration; calculation retained |
| Basis | Individual entity or stated group basis; entities included/excluded | Declaration summary; organisation chart retained |
| Annex II band | ≤10; >10 to ≤1,000; or outside protected status | Declaration |
| Approval | Authorised signatory, role and date | Declaration |
| Validity | Expiry, event triggers and correction contact | Declaration |
| Source support | HRIS, payroll, calculation, entity and relationship records | Retain; share only proportionately |
Hypothetical scenario
ILLUSTRATIVE WORDING - SUPPLIER DECLARATION
<p>“[Legal entity name], registration number [●], declares in relation to [reporting undertaking / requester] that it is in that undertaking’s value chain as [relationship]. On the basis described below, and as at the balance-sheet date [date], its average number of employees during the preceding financial year [start-end] was [number]. The calculation has been prepared on an [individual legal entity / stated group] basis and covers [entities]; the method used was [brief description under applicable rules]. Accordingly, the undertaking falls within the [10 employees or fewer / more than 10 and no more than 1,000] employee band for the purposes of the protected-undertaking provisions. This declaration is issued on [date], is valid until [date] unless corrected or withdrawn earlier, and must be updated if the entity basis, employee number or value-chain relationship changes materially. Supporting records are retained by the undertaking and may be discussed proportionately if a credible manifest-error concern arises. Contact: [name/function]. Authorised by: [name, role].” Illustrative implementation wording only. It is not a prescribed EU form and requires national legal review.</p>
Illustrative only. It shows how the decision is made, not wording that can be copied or relied on.
Evidence suppliers should retain
The supplier should be able to support the declaration internally without attaching unnecessary employee-level data. An evidence file protects the signatory and enables correction if challenged. It should also record the version of the applicable rule and any judgement about entity basis.
In practice
| Declaration element | Internal evidence | Control |
|---|---|---|
| Legal entity identity | Company register extract and entity master data | Match legal name and registration number. |
| Value-chain relationship | Purchase order, supplier record, contract summary or customer confirmation | Confirm relationship without over-sharing terms. |
| Employee average | HRIS/payroll aggregate, calculation sheet and period reconciliation | Preparer-reviewer check and method note. |
| Entity/group basis | Organisation chart, consolidation/entity list and basis memo | Legal/reporting review where judgement exists. |
| Employee band | Approved calculation outcome | Check both 10 and 1,000 thresholds. |
| Signatory authority | Delegation, board/management authority or policy | Confirm role before issue. |
| Validity and triggers | Calendar control and corporate-action alerts | Renew or withdraw on trigger. |
Data protection and evidence minimisation
A protected-status declaration normally needs an aggregate employee number, not employee names, salaries, contracts or payroll files. The supplier should minimise personal data in both the declaration and any clarification. If evidence is requested after a credible concern, consider a redacted calculation summary, independent confirmation or secure review rather than unrestricted transfer.
Minimise: use aggregate numbers and roles rather than names where possible.
Limit purpose: state that information is used to determine protected status and the Annex II path.
Control access: restrict detailed evidence to authorised personnel.
Set retention: preserve what is needed for reliance, correction and audit, then apply retention policy.
Record onward sharing: understand whether the declaration will be shared with group companies, assurance providers or platforms.
Provide correction route: inaccurate status data should be amendable without circulating a new uncontrolled file.
How requesters should rely proportionately
The requester’s default should be reliance, not verification. A proportionate intake process checks that the declaration is complete, signed, current, related to the correct supplier entity and internally consistent. It may compare the declaration with reliable information already held, but it should not require payroll evidence as a standard condition of acceptance.
In practice
| Requester check | Appropriate action | Over-audit to avoid |
|---|---|---|
| Complete legal entity and relationship | Match supplier master data; ask clarification if unclear. | Requesting full contract or ownership file routinely. |
| Period and employee figure stated | Confirm dates and Annex II band. | Demanding payroll extracts for all suppliers. |
| Basis described | Record individual/group basis and unresolved judgement. | Recalculating the supplier’s employee average without reason. |
| Signature and validity | Check authorised role, issue and expiry. | Requiring notarisation or external assurance by default. |
| No obvious contradiction | Accept and record reliance. | Searching for remote inconsistencies merely to verify. |
| Credible manifest-error indicator | Pause reliance, explain concern and request proportionate clarification. | Automatically rejecting or launching a broad audit. |
What may indicate a manifestly incorrect declaration?
The Directive does not provide a checklist in the cited provision. The requester should therefore use a narrow, documented exception process. A possible indicator might be a declaration of eight employees where reliable current group information already held by the requester shows hundreds in the same legal entity, or a declaration that names an entity unrelated to the supplier contract. A minor difference, public estimate or old website figure is not automatically a manifest error.
1. Record the indicator. Identify the reliable information and why the contradiction appears obvious and material.
2. Check entity and period. Many apparent contradictions arise from group versus legal-entity or current versus preceding-year differences.
3. Ask for clarification. Give the supplier a specific question and reasonable opportunity to correct or explain.
4. Decide reliance. Accept, accept with clarification, request a limited supporting summary, or reject reliance with legal approval.
5. Preserve the record. Keep the declaration, concern, clarification, decision and date.
Validity, expiry and correction
The form should not claim indefinite validity. A practical policy is to align the declaration with the preceding financial year used in the employee test and set a renewal point for the next supplier reporting cycle. Add event triggers for mergers, acquisitions, disposals, major workforce change, new entity coverage, change of requester relationship or discovered calculation error.
Where a declaration changes, the supplier should issue a corrected version with a reference to the superseded document and identify affected recipients. The requester should update questionnaire branching and preserve the prior reliance record rather than overwriting history.
Hypothetical example: a group with three supplier entities
Context. Cedar Services Group has a parent and three operating subsidiaries. One subsidiary with 62 employees supplies a reporting undertaking; the group has 310 employees. The customer asks for a protected-undertaking self-declaration.
Assessment. Cedar identifies that the contracting supplier is the subsidiary but recognises that the correct entity basis requires legal review under the applicable transposed rule. Rather than declaring only “62 employees”, it states the legal entity, the individual-entity figure, the group figure, entities covered and the basis used for the conclusion. It categorises the relevant Annex II band as more than 10 and no more than 1,000.
Requester response. The customer accepts the signed declaration because it is complete and no manifest contradiction exists. It does not request payroll evidence. It stores the basis and expiry and uses the >10 Annex II branch. When Cedar acquires another business, the supplier issues a corrected declaration after reviewing the entity and employee basis.
Learning point. Transparency about basis is safer than hiding judgement. The declaration is not stronger because it asserts certainty; it is stronger because it identifies what was measured, for which entity, for which period and under whose approval.
In practice
Weak versus stronger declarations
| Weak wording | Problem | Stronger approach |
|---|---|---|
| “We are an SME with fewer than 1,000 employees.” | No entity, period, relationship, average or basis. | Identify legal entity, requester relationship, period, average number and calculation/entity basis. |
| “Valid until further notice.” | No renewal or correction control. | Set expiry and event-based triggers. |
| Payroll file attached | Excess personal data and verification burden. | Retain evidence; share aggregate/redacted support only if proportionately justified. |
| “Certified protected undertaking” | Suggests an official certification that the mechanism does not create. | “Self-declaration of protected-undertaking status for the specified relationship and period.” |
In practice
Common mistakes and corrections
| Mistake | Risk | Correction |
|---|---|---|
| Using trading name instead of legal entity. | Requester applies the wrong employee and relationship test. | Use registration details and supplier master data. |
| No preceding-year dates. | Current and prior employee figures are confused. | State balance-sheet date and exact financial year. |
| No 10-employee band. | Questionnaire branch may be wrong even though protected status is right. | Record both Annex II band and 1,000 threshold outcome. |
| Unexplained individual/group basis. | Apparent contradiction and weak reliance record. | List included entities and rationale; flag legal judgement. |
| Requester verifies every declaration. | Defeats proportionality and increases supplier burden. | Use default reliance with a narrow manifest-error exception. |
| Old declaration silently overwritten. | No audit history or affected-recipient correction. | Version, supersede and notify where necessary. |
Myth
“Because no verification is required, a one-line supplier email is enough and the requester has no controls.”
Reality
No routine verification does not mean no governance. The supplier needs a supportable, authorised and renewable statement; the requester needs completeness, entity, period, validity and obvious-contradiction checks. The control is proportionate reliance, not blind acceptance and not a substitute audit.
Readiness
Supplier checklist
- The legal entity and registration details are correct.
- The reporting undertaking/requester and value-chain relationship are identified.
- The balance-sheet date and preceding financial year are stated.
- Average employee number and calculation method are documented.
- Individual or group basis and included entities are explicit.
- The ≤10, >10 to ≤1,000, or outside-protected band is clear.
- The declaration has authorised approval, issue date and expiry.
- Supporting records are retained with appropriate personal-data controls.
- Correction, withdrawal and recipient-notification processes exist.
Readiness
Requester checklist
- The declaration relates to the correct supplier legal entity and value-chain relationship.
- The period, employee figure, method/basis and band are complete.
- The signatory and validity are reasonable for the supplier.
- The requester relies without routine verification.
- Any manifest-error concern is specific, material and documented.
- The supplier receives a proportionate opportunity to clarify or correct.
- The declaration drives the correct questionnaire branch and rights notice.
- Prior versions and reliance decisions remain traceable.
Self-check
- Why should a self-declaration state both the 1,000 threshold and the 10-employee Annex II band?
- What is the difference between a completeness check and verification?
- How should a requester respond to an apparent group-versus-entity contradiction without over-auditing the supplier?
Related learning path
Requester design: How Large Companies Should Redesign Supplier ESG Questionnaires Around the Value Chain Cap.
Supplier response: How to Respond to an Above-Cap Sustainability Data Request Without Damaging the Customer Relationship.
Questionnaire operations: How to Answer Customer and Bank ESG Questionnaires Using the EU Voluntary Standard.
Publication channels: Must an EU Voluntary Sustainability Report Be Public?
Rule
USE OF THIS SECTION
<p>The following material supports technical review, CMS publication, AI retrieval and future updating. It is not intended to appear in full on the public web page.</p>
Take it with you
The checklists as a working spreadsheet
Every checklist and table on this page, with empty status, owner and evidence columns for your team to fill in and keep.
✓ LRA AI Assistant · Human-in-the-loop
Ask about this guide
It answers from this page, and reaches into the linked disclosure cards when your question is about the standard itself. Your first two answers are free without signing in.
Go deeper · EU Voluntary Standard 2026
ESG Reporting Full Stack
There is no standalone LRA course for this framework yet. The Full Stack programme covers the reporting system it sits in — materiality, data, drafting and assurance — with exercises on your own data.
Available as Guided Flex, Live Cohort, 1:1 Expert Mentorship or Corporate Programme.