The forced labour risk database: What to expect
One of the more consequential pieces of the EU Forced Labour Regulation's infrastructure doesn't exist yet. The forced labour risk database, referenced throughout the Regulation and reaffirmed in the Commission's June 2026 guidelines, is intended to be a shared reference point identifying high-risk geographies, sectors and specific products or product groups linked to forced labour indicators – but as of mid-2026, it remains under development with no confirmed launch date.
Understanding what the database is meant to do helps explain why its absence matters. The Regulation's enforcement model is explicitly risk-based: competent authorities are meant to prioritise investigations using indicators of elevated risk rather than treating every product and every operator identically. The risk database is the mechanism through which that prioritisation is supposed to happen in a consistent, transparent way across all member states and the Commission alike, rather than each authority developing its own informal sense of where the risk sits.
For companies, the database is also meant to be a planning tool – a way to check, in advance, whether a given input, product category, or sourcing geography carries an elevated forced labour risk flag, and to calibrate due diligence effort accordingly. Its absence means companies currently have to build their own risk pictures using other available sources: existing international frameworks like the ILO's forced labour indicators, established human rights and supply chain risk indices, sector-specific reporting and their own supplier-level audit history.
This isn't purely a gap to be anxious about. Building an internal risk assessment now, using the same categories of indicator the Commission's database will eventually formalise – geography, sector, known forced labour typologies, supplier ownership structure, prior adverse findings – means a company's due diligence system won't need a structural overhaul once the database goes live. It will simply gain another input source to plug into an already-functioning process.
There's a reasonable case that the database's absence will accelerate, not delay, the timeline pressure companies feel. With full application in December 2027 and member state penalty frameworks due by December 2026, companies without a functioning risk assessment process today are working against a compressed runway even before the database exists – waiting for its launch is not a viable compliance strategy.
There's also the external pressure dimension: with the EU among roughly sixty economies under review in an active US Section 301 investigation into forced-labour import controls, there's institutional incentive on the EU side to move the database and the broader enforcement architecture along at pace, which may mean less advance notice than companies would like once it does launch.
The practical response is to treat the current gap as a reason to build now rather than wait: a risk assessment methodology that can absorb the Commission's database as one input among several, rather than depending on it as the sole source of truth. Speeki is an accredited certification body supporting organisations in building and certifying exactly this kind of due diligence risk architecture; current accreditation scope is available at speeki.com.