Due-diligence frameworkEPRM23S016 · version 2, as built

Consolidated Autonomous Due Diligence.

CADD is a due-diligence framework for artisanal and small-scale mining (ASM). Its second version is not a document but a working system: one family of forms and one evaluation method, used by the operator that compiles its file, the institution that evaluates it and the monitor that observes the site.

This page describes CADD v2 as it is built into the applications of the project: KOTA, for banks, and Nashiriki, for civil society. It sets out the structure, how it maps to the OECD Due Diligence Guidance, how it is used, how it evolved and where it stands.

01 · What CADD is

Due diligence the operator can do itself, and others can check.

The two words in the name carry the design.

A

Autonomous

The operator compiles its own due-diligence file, once, and holds it. It answers the questions, attaches the evidence and decides which institutions receive the file. The question sets come with powers over the file, which is what makes them autonomous due diligence rather than a survey.

C

Consolidated

The operator's declaration can be read beside independent observation by civil-society monitors and beside the public record, because all three use the same structure. Each item keeps its source, so a reader sees who said it and how well it is corroborated.

Three commitments

One structure, three kinds of user.

01

One family of forms

Organisations, management systems, sites and events are recorded on shared forms, whichever application a user works in.

02

One evaluation method

Criteria are governed centrally and inherited by every institution that uses them, so an evaluation means the same thing everywhere.

03

Shared by consent

The operator decides what to share and with whom. An institution that accepts a file keeps its own copy.

02 · Who it serves

Four users, one record of the same operator and the same site.

01

ASM operators

Cooperatives and other ASM operators compile one structured file and reuse it for each institution they approach. An application to a second institution is pre-filled from the profile already compiled, so the work of compiling once pays off on every later application.

Today in KOTA · later also in the standalone HATUA application, in development

02

Banks and other institutions

A bank receives the operator's file, reviews it and assesses the counterparty against structured information requirements. Each bank applies its own rating policy and its own rules of access to services on top of the common evaluation. The same design serves other institutions: EGC (Entreprise Générale du Cobalt) already has an aggregator interface on KOTA.

KOTA · operating with Trust Merchant Bank (TMB) since March 2026

03

Buyers

A buyer can form a consolidated judgement from three kinds of evidence: the operator's own file, shared with its consent; independent observation by monitors; and the public record gathered in the hubs, where claims are rated by their sources and by how well they are corroborated.

The DRC Cobalt Hub already gives downstream companies upstream insight from public information. Connecting the hubs to monitoring data is outstanding, and no international information client is recorded yet.

Extractive Industries Transparency Initiative (EITI) hub at nashiriki.com/eiti · DRC Cobalt Hub at cobalt.daac.ai

04

Civil society

Local monitors, civil-society organisations and consultants can use Nashiriki to record sites, incidents, activities, corrective actions and testimonials on the same forms. Every incident, activity and testimonial is attached to a named initiative, with the organisation leading it and the organisation funding it kept apart.

Nashiriki · nashiriki.com

03 · Structure, as built

Four question sets, and the two mechanisms that make them comparable.

Section and field names below are those of the applications' own form specifications.

Aoperator

Organisational file

The operator's own file, in ten sections, plus a view of the people and organisations linked to it.

  • Identification
  • Registration
  • Profile
  • Associations
  • Compliance
  • Governance
  • Operations
  • Organisation Policies
  • Scrutiny
  • Trade
BOECD step 1

Management systems

Five sub-assessments of the operator's own management systems. They open once the application is submitted.

  • Supply Chain Policy
  • Internal Management Systems
  • Supply Chain Integrity
  • Supplier Engagement
  • Grievance Mechanism Features
Csites

Site form

One mine-site form of twelve sections, designed to be the same form in every application. Two of its sections carry the environment and gender modules.

  • Identification
  • Access
  • Stakeholders
  • Workforce
  • Operations
  • Human Rights
  • Gender & Inclusion
  • Peace & Security
  • Environmental Impact
  • Health & Safety
  • Community & Society
  • Documentation
Devents

Event form

Incidents, activities and testimonials share one form of eight sections. Six record types are cut from it: Incident, Activity, Testimonial, Training Record, Mitigation Measure and Initiative.

  • Identification
  • Attribution
  • Categorisation
  • Location
  • Parties
  • Victims
  • Incident Resolution
  • Documentation
Eevidence

Evidence

Documents are uploaded with a category and an expiry date, against a list of required documents that depends on the type of operator and that each institution can adapt. For a mining cooperative the list includes, for example, its founding act, its approval, its member register and its cooperative rules.

Every field can be marked "not applicable" or "no information available": a deliberate declaration, distinct from a field left blank. Core identification fields cannot be marked this way.

Fevaluation

Evaluation

Organisations and sites are evaluated by a deterministic method. The same file always gives the same result; a fact backed by a document counts for more than a bare declaration, and one confirmed by another source counts for more still; the result is recalculated whenever the file changes. The criteria are governed centrally, not edited institution by institution.

The evaluation informs a decision. It is not a credit score and does not replace the institution's judgement.

The exchange, in one figure

in usebuilt or planned, not yet in useshared structure
  1. 1The operator shares its file by its own consent. The institution keeps its own copy.
  2. 2The next application, to another institution, is pre-filled from the file.
  3. 3Same site sections and same evaluation, so a monitor's observation and an operator's declaration can be compared.
  4. 4Connecting the hubs to monitoring data is outstanding; for the Cobalt Hub it is planned before 31 December 2026.
  5. 5The operator's file, shared with a buyer by consent: designed, no buyer client recorded yet.
  6. 6Monitor observations for a receiving party: a live EPRM Audience trial is outstanding.
  7. 7Public sources, rated by corroboration: available to buyers now.

04 · OECD mapping

The OECD Guidance, inside the question sets.

The mapping below is the consortium's own reading of what it built, offered so that a reader can see the five-step framework of the OECD Due Diligence Guidance in the forms.

OECD stepWhere the operator, or a monitor, answers it
STEP 1Strong company management systemsManagement systems: Supply Chain Policy, Internal Management Systems. Organisational file: Governance, Organisation Policies. Site form: Identification, Access, Operations.
STEP 2Identify and assess risk in the supply chainOrganisational file: Associations, Compliance, Scrutiny, Trade. Site form: Human Rights, Gender & Inclusion, Peace & Security, Environmental Impact, Health & Safety, Community & Society, Workforce. The operator's trade partners and operating sites.
STEP 3Design and implement a strategy to respond to identified risksIncidents and activities, with Corrective Action as a type of activity; Mitigation Measure records on the event form; Management systems: Supply Chain Integrity, Supplier Engagement; the five-stage incident lifecycle.
STEP 4Independent third-party auditNot performed by CADD, and not claimed. What CADD provides is auditability: every record keeps its source, and independent observation and public-source corroboration sit beside the operator's own declaration.
STEP 5Report on supply chain due diligenceProduction and shipment records; the operator's consented sharing; the public hub pages; testimonials on the event form.
GRIEVANCEGrievance mechanismManagement systems: Grievance Mechanism Features. The incident lifecycle, which includes an explicit mediation stage.
ANNEX IIOECD Annex II risksThe site evaluation scores the risk sections of the site form against the Annex II risks. One human-rights criterion covers cruel and degrading treatment, including gender-based violence.

05 · How it is used

Self-assessment by the operator. Review by the bank.

Today the operator's sequence runs in KOTA, where TMB reviews what operators submit.

Operator · self-assessmentKOTA

  1. 01

    Register

    The operator registers online, describes its organisation and chooses the institutions it wants to approach. For an operator without an e-mail address, the institution can complete the registration on its behalf.

  2. 02

    Apply

    It completes the application and attaches the documents required for its type of operator. It can save part-way and come back.

  3. 03

    Self-assess

    It completes the organisational file and the five management-system sub-assessments. Completion is shown as a percentage, to the operator and at submission.

  4. 04

    Share

    On submission the file goes only to the institutions the operator chose. Nothing is shared by default, and each institution keeps its own copy.

Bank · reviewKOTA

  1. 01

    Receive

    The bank sees each applicant and where its file stands. It can also open a file itself for an operator with no digital access and invite it in later.

  2. 02

    Review

    One person prepares the review and another decides. The decision is dated and gives its reason.

  3. 03

    Decide

    The bank accepts, or declines with a reason. After a refusal the operator can correct its file and resubmit.

  4. 04

    Follow

    The evaluation updates when a document is added or information is corrected, and every version of the file is kept.

Civil society · monitoringNashiriki

A monitor records a site on the twelve-section site form, so that creating a site record is assessing it. Incidents, activities, corrective actions and testimonials are recorded on the event form. An incident moves through five stages, recorded as its state and changed only by the roles allowed to change it:

  1. 1Received
  2. 2Under Verification
  3. 3Validated
  4. 4Mediation in Progress
  5. 5Closed

06 · From v1 to v2

From a framework document to a working system.

The first version of CADD was a framework document. The second is the form structure built into the applications, and the exchange between them. The deliverable was information exchange and interoperability across several applications, which is why it took longer than planned.

  1. v1

    A framework document

    The project plan foresaw handling applications for banking services in an earlier application, MMT. Registrations made there included external parties whose data did not allow a determination about the counterparty.

  2. Project plan

    Three expansions, due 30 September 2024

    Expand the framework to banking-sector compliance expectations, build environmental vigilance into it, and build gender protection monitoring into it.

  3. March 2025

    Delays reported

    The first annual report identified delays in framework expansion, bank onboarding and civil-society registration.

  4. Apr 2025 to Aug 2026

    v2 built as software

    CADD was translated into questions, evidence requirements and assessment workflows covering organisations, management systems and site risks, on shared forms and a shared evaluation method.

  5. March 2026

    In use with TMB

    KOTA, the bank-facing application, began operating with TMB.

  6. May 2026

    One self-assessment

    The bank's earlier self-assessment arrangement was folded into the shared organisational file of ten sections and the five management-system sub-assessments. Feedback from Justice Plus informed improvements to roles, incidents and reporting in Nashiriki.

  7. June 2026

    Incident lifecycle

    The five-stage incident lifecycle, with its mediation stage, was settled out of that feedback round.

  8. 13 July 2026

    Bank manual published

    The French user manual for KOTA's bank interface was published at kota.datastake.io/manuel-utilisateur-tmb.

  9. September 2026

    Revised civil-society application

    Released after the 31 August reporting cut-off. Its uptake and field outcomes remain to be measured.

07 · Status and next step

Delivered as software. Adoption is the work that remains.

01

Framework v2

Delivered as software. Annex II, sheet 1, row 15: target 1, realised 1 in period 2.

delivered

02

Environment and gender modules

Delivered inside the applications, not as separate tools. Rows 26 and 27: realised 1 each. Each has its own one-page description.

delivered

03

In use

KOTA has operated with TMB since March 2026. HIVE and Datastake trained bank staff. Nashiriki records observations, incidents and corrective actions.

in use

04

Outstanding

Cooperative self-onboarding; connecting the hubs to monitoring data; a live EPRM Audience trial. End-to-end consolidation is therefore unfinished.

outstanding

05

Not claimed

The availability of these tools does not by itself show that site-level risks have fallen, that women's participation has improved or that access to finance has grown. Those outcomes need field observations and partner records, and are reported separately.

06

Next step

A standalone HATUA self-assessment application, open to cooperatives independently of banking or buyer applications, is in development. It is a direction, not yet available. The software milestone is distinct from the period of adoption and outcome measurement that will follow it.

direction

Public pageskota.datastake.iokota.datastake.io/manuel-utilisateur-tmbnashiriki.comnashiriki.com/eiticobalt.daac.ai

Consolidated Autonomous Due Diligence (CADD), version 2 as built. Prepared on 21 September 2026 for the project EPRM23S016, "Holistic Due Diligence Framework for Energy Transition Minerals", lead party HIVE asbl, with the support of the European Partnership for Responsible Minerals (EPRM).

Partners named on this page: Trust Merchant Bank (TMB), primary banking partner; La Sentinelle des Ressources Naturelles, local coordination; Justice Plus, co-creator of the civil-society application; Datastake, implementing technology partner. KOTA is developed and maintained by Datastake.