How Cocoa Companies Can Operationalize Supplier Evidence, Geospatial Assessment, Production Traceability, and TRACES Submission
- Marketing Writer

- 1 day ago
- 11 min read
Editor's Note:
A geolocation pin and a supplier declaration used to be enough to call a shipment "EUDR-ready." What regulators and buyers actually want to see now is not just information on who produced or supplied the product and where it was grown, but also whether the plot was legally producing before the applicable cutoff date, how the risk was assessed, and whether the paperwork lines up cleanly enough to survive an audit. Most sourcing teams in cocoa, coffee, palm oil, rubber, soy, and timber are still running this through spreadsheets and one-off reports that go stale fast. The real bottleneck was never collecting data: it's whether it's validated, connected, and audit-ready. This piece also features insight from Michael Wijaya, Head of Data Collection and Climate at KOLTIVA on what that shift looks like in practice. Read the full article and talk to our expert now!
Executive Summary:
EUDR has changed the role of traceability in agricultural and forest-risk commodity supply chains. Companies placing or exporting regulated products on the EU market or exporting them from the EU must be able to demonstrate that relevant products are deforestation-free, legally produced, and covered by a due diligence statement. The European Commission’s EUDR Information System, built on the TRACES platform, allows operators and authorized representatives to create, manage, and submit due diligence statements, including geolocation information that can be uploaded in GeoJSON format.
For sustainability procurement and sourcing teams, this means supplier data can no longer remain disconnected from operational flows. GeoJSON files, legality documents, supplier DDS references, purchase orders, production batches, finished-product shipments, TRACES submission status, and broker-facing DDS references must be connected in one auditable process. Our EUDR operating model positions KoltiTrace as a central platform for supplier evidence intake, geospatial validation, risk assessment, mitigation workflow, DDS/TRACES execution, and audit history.
The real challenge is not simply the traceability, but also operational compliance: making sure that only complete, accepted, traceable, and risk-qualified records proceed to due diligence preparation. This requires data-quality controls, polygon validation, supplier correction workflows, legality evidence management, exception ownership, ERP or Data Lake integration, and a reliable DDS reference return process.
Table of Contents
Cocoa Traceability: The Shift from Origin Tracing to Evidence-Based Verification
The Hidden Problem with “Traceability on Paper”
From Supplier Evidence to a Defensible Due Diligence Record
From GeoJSON to DDS: Why Data Quality Determines Compliance Readiness
The Legal-Production Challenge Most Companies Underestimate
Building an Inclusive Supplier Model Without Lowering Compliance Standards
The Future of EUDR Compliance Is an Operating System, not a Checklist
Cocoa Traceability: The Shift from Origin Tracing to Evidence-Based Verification
The era of treating cocoa traceability as merely a visibility exercise is over. It once focused just on identifying suppliers, mapping cooperatives and collectors, and collecting farm-level coordinates to prove where the beans came from. That approach helped the sector move from opaque, multi-layered sourcing toward more transparent supply chains. But the next phase is much more demanding. Under stricter market expectations, including the EU Deforestation Regulation, traceability is no longer simply about documenting origin. It is about proving, shipment by shipment, that cocoa is deforestation-free, legally produced, traceable to plot level without mixing untraced volumes, and backed by data that can withstand regulatory, buyer, and audit scrutiny (European Commission, n.d.).

This changes the operational reality for sustainability procurement and sourcing teams. Traceability can no longer sit in a sustainability report, a supplier spreadsheet, or a static dashboard. It must become an operating system that connects supplier evidence, geospatial assessment, risk decisions, production traceability, DDS references, TRACES status, and audit history.
The market is moving beyond asking whether companies have traceability. The question buyers and regulators are increasingly asking is whether traceability can withstand scrutiny. Can a company demonstrate where the product came from, how risk was assessed, which evidence supports the decision, and how that evidence is connected to a specific shipment? That is the difference between data collection and operational compliance.
That is why traceability must move upstream into supplier onboarding and downstream into production, shipment, and customs workflows. If supplier evidence is incomplete, if polygons are invalid, if DDS references cannot be tied to the right shipment, or if compliance status is not visible when goods are ready to move, EUDR readiness becomes a supply-continuity risk, not just a sustainability reporting issue.
That operating model starts with a harder question: can every cocoa shipment be traced back through the cooperative or collector to the individual farm plot, with verified supplier evidence, plot-level geolocation, legality documentation, transaction records, risk decisions, and due diligence outputs all linking to the same batch?
The Hidden Problem with “Traceability on Paper”
Many companies already hold useful pieces of compliance evidence: producer lists, GeoJSON files, certification documents, legality records, purchase orders, batch records, supplier declarations, and DDS references. The problem is that these records often sit in different systems, teams, and workflows. A supplier file in an email inbox, a purchase order in ERP, a batch record in production, and a DDS reference in a spreadsheet may each be useful on its own. Together, they may still fail to create a defensible chain of evidence.
A traceability record becomes operationally useful when it connects supplier evidence to the physical and commercial reality of the product. Koltiva’s EUDR platform model addresses this fragmentation by bringing supplier evidence, geospatial assessment, production traceability, and direct TRACES submission into one integrated environment.”
Michael Wijaya, Head of Data Collection & Climate at KOLTIVA, stated, “Many organizations already have much of the data needed for EUDR compliance. The real challenge is operationalizing it, connecting supplier evidence, risk assessments, production records, shipment data, and due diligence workflows into a seamless, auditable process that supports both regulatory requirements and daily sourcing operations. Successful EUDR implementation requires organizations to manage multiple compliance components in parallel, including supplier documentation, geolocation and polygon validation, deforestation and legality assessments, production traceability, DDS preparation, TRACES submission, and audit-ready record keeping. The key is ensuring these elements remain integrated, traceable, and verifiable across the entire supply chain.”
“Our traceability platform positions this as an EUDR operating platform rather than another manual compliance layer. KoltiTrace receives and validates supplier evidence, assesses deforestation and legality risk, manages mitigation, links raw-material deliveries to finished-product shipments, generates DDS, and maintains audit-ready compliance records across the full chain,” added Michael.
From Supplier Evidence to a Defensible Due Diligence Record
For procurement and sourcing teams, one of the most difficult transitions is turning supplier-level evidence into shipment-level assurance. A supplier may submit a GeoJSON file. Another may provide certificates. Another may provide DDS reference numbers from an upstream operator. Some suppliers may have their own digital systems, while others may still rely on email, spreadsheets, or manual uploads. In global commodity supply chains, this variation is normal. The compliance system must be flexible enough to accept supplier evidence from different channels, but strict enough to produce one governed record.
Michael says, “This is where many companies face a hidden risk. Supplier evidence often exists, but it is scattered across different formats and systems. Geolocation files may sit in emails. Purchase orders may sit in ERP. Batch records may sit in production systems. DDS references may be tracked manually. Supporting documentation may be stored in supplier folders. When these records are not connected, companies may have information, but not operational control.”
He added that a defensible EUDR process must link evidence to the commercial and physical reality of the supply chain. That means every supplier submission should be connected to purchase orders (POs), delivery identifiers, material data, production batches, shipment records, and DDS references where relevant. Our traceability platform model explicitly describes the need to connect supplier evidence and geolocation data per delivery with PO and delivery identifiers, then link validated evidence to production and shipment data before DDS generation and TRACES submission.
From GeoJSON to DDS: Why Data Quality Determines Compliance Readiness
Geolocation data is central to EUDR readiness, but not all geolocation data is ready for due diligence. A polygon can be incomplete, duplicated, overlapping, technically invalid, disconnected from a supplier, or formatted in a way that creates downstream submission issues.
This is why data quality must be controlled before risk assessment and DDS preparation. “Our proposed data-quality model includes file and format checks, polygon checks, record checks, correction workflows, notification, reprocessing, and audit-history retention. It also highlights the need to validate GeoJSON in WGS84, identify duplicated plots, detect overlaps and invalid geometries, check mandatory attributes, and retain version history,” said Michael.
This matters because poor data quality can create both compliance and operational risk. Invalid polygons can delay assessment. Missing supplier identifiers can prevent evidence from being tied to the correct delivery. Duplicated plots can distort sourcing visibility. Overlapping polygons can create uncertainty during audits. Missing DDS references can break the downstream compliance chain.
The principle should be simple: only complete, accepted, and traceable records should move forward to risk assessment and DDS preparation. Anything incomplete should enter a controlled correction workflow, with clear ownership, notifications, reprocessing, and audit history.
For procurement teams, this is more than technical hygiene. It is a market-access safeguard. If data issues are detected only when a shipment is approaching customs, the business is already exposed. If they are detected during supplier intake, they become manageable.
GeoJSON Is Necessary, but Data Quality Determines Readiness
Geolocation data is central to EUDR readiness, but not every geolocation dataset is ready for due diligence. The European Commission’s GeoJSON file description for the EUDR Information System states that geolocation files use GeoJSON, WGS84 longitude and latitude in decimal degrees, and defined geometry types. It also lists common GeoJSON errors such as open polygons, crossing lines, invalid geometry types, invalid coordinate ranges, invalid property names, password-protected files, and files exceeding the system’s size limit (European Commission, 2025).
This is directly relevant for cocoa sourcing because poor geospatial data can delay or undermine due diligence readiness. Invalid polygons can block assessment. Duplicated plots can distort sourcing visibility. Overlaps and invalid geometries can create uncertainty during review. Missing supplier, PO, or delivery identifiers can prevent data from being tied to the correct shipment.
“Our system runs data-quality checks on supplier data prior to entry into the EUIS system for DDS generation. These checks span file and format validation, and polygon data and mitigation workflows. They include validation of GeoJSON in WGS84, certificates and supplier DDS references, supplier and purchase-order identifiers, closed polygons, duplicated plots, overlaps, invalid geometries, required attributes, documents, version history, notifications, reprocessing, and audit-history retention,“ said Michael.
The principle is simple: only complete, accepted, and traceable records should proceed to risk assessment and DDS preparation. Anything incomplete should enter a controlled correction workflow, with ownership, notification, source correction, reprocessing, and retained audit history.
The Legal-Production Challenge Most Companies Underestimate
Many EUDR discussions focus on deforestation, but legal production is just as important. A shipment may be fully deforestation-free and still fall short if it cannot be shown to have been produced in line with the applicable laws of the country of origin. Regulation (EU) 2023/1115 requires relevant products to be deforestation-free, legally produced, and covered by a due diligence statement.
For sourcing teams, this broadens what counts as evidence. Depending on the commodity, jurisdiction, and sourcing model, legal-production documentation can include land tenure or ownership rights, permits and authorizations under national law, environmental compliance records, certifications, and chain-of-custody records (European Parliament & Council of the European Union, 2023).
The challenge is that this evidence is far less standardized than geolocation data. It varies by country, supplier type, commodity, and local land tenure system. That's what makes a structured evidence framework essential, rather than something assembled case by case.
Our EUDR solution treats this evidence: tenure documentation, operating and environmental permits, certifications, cadastral records, maps, and chain-of-custody records, as validation inputs that feed directly into risk assessment and due diligence decisions.
For procurement and sustainability teams, the takeaway is that legal-production verification can't sit as an appendix. It needs to be built into the operating workflow: linked to the supplier and plot record, reviewed against risk criteria, and retained with the final decision.
Building an Inclusive Supplier Model Without Lowering Compliance Standards
One of the biggest risks of EUDR implementation is supplier exclusion. Smaller suppliers, aggregators, cooperatives, and smallholder-linked supply chains may not have the same digital maturity as large enterprise suppliers. If compliance systems are designed only for highly digitized suppliers, market access may become harder for the actors most in need of support.
A practical EUDR operating model must therefore support multiple supplier participation pathways. Some suppliers may submit directly through a platform. Others may submit through API or structured exchange. Others may rely on email, spreadsheets, controlled upload, or buyer-managed intake. Where data quality or risk requires additional assurance, field mapping or independent verification can be added.
Koltiva’s data aggregation and verification model supports suppliers through different participation pathways: suppliers whose data is collected through KoltiTrace and KoltiSkills, suppliers directly subscribed to KoltiTrace, and suppliers that do not use KoltiTrace. Where supplier data quality or risk requires additional assurance, KoltiVerify can provide further verification. Regardless of the entry pathway, the model aims to centralize evidence, validation status, and compliance decisions into a single governed EUDR record.
This is critical for inclusive sourcing. Flexibility at the intake layer should not mean inconsistency at the compliance layer. Suppliers can submit through different channels, but every record should still pass through the same evidence, validation, risk, mitigation, and audit controls.
The Future of EUDR Compliance Is an Operating System, Not a Checklist
EUDR compliance is pushing companies to rethink traceability. The goal is no longer simply to map suppliers or collect farm coordinates. The goal is to operate verified, shipment-ready supply chains where every relevant product can be connected to supplier evidence, geospatial assessment, legality documentation, risk decisions, DDS references, and audit history.
For sustainability procurement and sourcing leaders, this is a strategic shift. Compliance is becoming part of procurement execution. Traceability is becoming part of enterprise data architecture. Supplier engagement is becoming part of risk mitigation. DDS readiness is becoming part of shipment planning.
Many companies began their EUDR journey focused on collecting geolocation data and supplier documentation. What we see now is a different challenge: operationalizing those records. The organizations that will be best prepared are not necessarily the ones with the most data, but the ones able to connect supplier evidence, risk decisions, production traceability, DDS processes, and audit history into one governed workflow.
The companies best prepared for EUDR will not be the ones with the most spreadsheets or the largest document folders. They will be the ones with a controlled operating model that can validate evidence, manage exceptions, link upstream data to downstream products, generate DDS-ready outputs, return reference numbers to the right systems, and prove every decision after the fact.
The next generation of traceability must therefore be more than visibility. It must be verifiable, operational, connected, and audit-ready. That is where EUDR compliance is heading: from traceability as documentation to traceability as an operating system for responsible sourcing.
Frequently Asked Questions (FAQ)
What does EUDR-ready cocoa traceability mean?
It means a company can connect supplier evidence, plot-level geolocation, legality documentation, risk assessment, production and shipment records, DDS preparation, TRACES submission status, and audit history into one defensible process.
Why is GeoJSON validation important for EUDR?
Because GeoJSON files must be technically compatible with the EUDR Information System. Errors such as open polygons, invalid geometry, incorrect coordinate format, invalid property names, or file-size limits can create submission and due-diligence issues.
Is collecting coordinates enough for EUDR compliance?
No. Coordinates must be connected to supplier identity, plot records, legality evidence, risk assessment, purchase orders, production batches, shipments, DDS references, and audit trails to support a defensible due diligence process.
Why does legal production matter?
EUDR requires products to be produced in accordance with the relevant legislation of the country of production. This can require evidence such as land-use or tenure documentation, permits, environmental documentation, cadastral information, certifications, and chain-of-custody records, depending on the country and commodity.
What should cocoa companies prioritize first?
Prioritize evidence architecture: supplier intake, GeoJSON validation, legality evidence, PO and delivery identifiers, batch and shipment linkage, DDS workflow, exception ownership, and audit retention.
Editor: Gusi Ayu Putri Chandrika Sari, Social Media Practitioner at KOLTIVA
Subject Matter Expert: Michael Saputra, Head of Data Collection & Climate at KOLTIVA
Gusi Ayu Putri Chandrika Sari combines her expertise in digital marketing and social media with a deep commitment to sustainability, supported by over eight years of experience in communications. Her work focuses on crafting impactful narratives that connect technology, agriculture, and environmental responsibility. She is driven by a passion for promoting sustainable practices through compelling, audience-focused content across a variety of digital platforms.
Michael Saputra is the Head of Data Collection and Climate at KOLTIVA, leading initiatives that integrate climate intelligence with robust field data systems across global agricultural supply chains. With expertise in geospatial analysis, environmental monitoring, and digital traceability, Michael ensures that data collected from the ground up—down to the farm plot—supports compliance with sustainability frameworks like the EU Deforestation Regulation (EUDR). His work bridges technology and climate action to empower businesses and smallholders in building resilient, transparent, and deforestation-free supply chains.
Resources:
European Commission. (2025). EUDR GeoJSON file description: Version 1.5. https://nli.gov.cz/wp-content/uploads/EUDR-EUDR-GEOJSON-FILE-DESCRIPTION-1.5_.pdf
European Commission. (n.d.). Regulation on deforestation-free products. https://environment.ec.europa.eu/topics/forests/deforestation/regulation-deforestation-free-products_en
European Parliament and Council of the European Union. (2023). Regulation (EU) 2023/1115 of the European Parliament and of the Council of 31 May 2023 on the making available on the Union market and the export from the Union of certain commodities and products associated with deforestation and forest degradation and repealing Regulation (EU) No 995/2010. EUR-Lex. https://eur-lex.europa.eu/eli/reg/2023/1115/oj/eng












Comments