Two State Council decrees and a Ministry of Commerce order issued this year reach the collect, transfer, and act steps of supplier due diligence. The evidence that stays clean under all three is the kind a buyer generates without asking the supplier.

By Jinal Surti, CEO, Epoch Blue. Last updated 29 September 2026.

An ESG lawyer in Hong Kong wrote to me this month, expressing that China's new supply-chain security rules had made most of the standard due-diligence toolkit a legal risk. Assessing suppliers without asking them anything, she said, might be one of the few routes left. The same week, the head of sustainability at an automotive supplier asked its compliance platform what happens to its China operations if the platform itself lands on a Chinese countermeasure list.

Since 31 March, a question sent into China is a legal-review item. Since 5 August, six of the providers Western importers used to answer that question are off limits to anyone in China. My read on the three rules? The diligence that survives is the evidence you can generate without asking the supplier.

What the three rules restrict

China's rapid regulatory sequence—State Council Decree 834 (restricting in-country supply-chain investigations under Article 13 and supplier terminations under Article 15), Decree 835 (penalizing implementation of declared improper foreign measures), and the Ministry of Commerce’s August order (blacklisting six US due-diligence providers)—creates an acute legal squeeze for Western buyers. This order came two days after the US added 43 companies to the UFLPA Entity List, taking it to 187. While not an explicit ban on questionnaires, these rules penalize collecting, transferring, or acting on supply chain data within China, placing foreign importers in direct conflict with stringent US and EU disclosure demands like the UFLPA, EU Forced Labour Regulation, and CSDDD.

timeline

The US and EU rules are unchanged, and two of them prefer this kind of evidence

The rules that made you send the questionnaire still require an answer. Under the UFLPA, goods touching Xinjiang or a listed entity are presumed made with forced labour, and the importer rebuts that with "clear and convincing evidence". Customs has denied entry to 26,830 shipments since 2022. The EU's Forced Labour Regulation guidelines, in the Official Journal since 3 September, list "satellite imagery and geolocation of facilities" as evidence and say an inability to provide traceability "may weigh negatively". The amended CSDDD tells companies to scope on "reasonably available information" before asking suppliers. In other words, they would rather you did your own diligence than restate what a supplier told you, they accept location and remote evidence, and they count a supplier's silence against you.

Three changes to make to a China diligence programme

Inventory every question your programme sends into China—including questionnaires, audit bookings, document requests, and template uploads to third-party portals. Mark which step each triggers (collect, transfer, or act). Because in-country audits and questionnaires trigger Decree 834 Article 13 restrictions and MOFCOM countermeasure lists, shift toward supplier-prepared summaries reviewed by PRC counsel rather than raw in-country data collection.

Build the Chinese-supplier evidence pack from what needs no request. Moving raw diligence files across borders exposes buyers to Article 13, Data Security Law, and PIPL restrictions. Instead, resolve facilities remotely using registries, logistics, and open sources, recording land-use change, protected areas, water stress, and public forced-labour records from outside China. This approach generates clean evidence without transferring raw in-country records, leaving only a minimal, aggregated dataset requiring legal review before transfer.

Keep the reasoning for any sourcing change on file. Dropping or downgrading a Chinese supplier triggers Decree 835 anti-foreign-measure rules and Article 15 anti-discrimination provisions. Ensure any sourcing change is backed by a documented commercial rationale and risk assessment under named US/EU rules, consulting the supplier first to remain defensible on both sides.

By shifting away from direct supplier questionnaires toward remote, external evidence gathering, companies eliminate legal liabilities under China's collect, transfer, and act restrictions while satisfying US and EU regulatory requirements. Building evidence from the outside is no longer just a workaround; it is the essential foundation for compliant supply-chain due diligence.

If you'd like to learn more about how we assess a supplier from a name and a location without asking it for anything, or put the product to work in your supply chain, reach out to us here.

Or, subscribe to our newsletter to get the latest on supply chain risk management, EUDR, deforestation, water stress, and the latest trends in geospatial AI.