CADD is a due-diligence framework for artisanal and small-scale mining (ASM). Its second version is not a document but a working system: one family of forms and one evaluation method, used by the operator that compiles its file, the institution that evaluates it and the monitor that observes the site.
This page describes CADD v2 as it is built into the applications of the project: KOTA, for banks, and Nashiriki, for civil society. It sets out the structure, how it maps to the OECD Due Diligence Guidance, how it is used, how it evolved and where it stands.
01 · What CADD is
The two words in the name carry the design.
The operator compiles its own due-diligence file, once, and holds it. It answers the questions, attaches the evidence and decides which institutions receive the file. The question sets come with powers over the file, which is what makes them autonomous due diligence rather than a survey.
The operator's declaration can be read beside independent observation by civil-society monitors and beside the public record, because all three use the same structure. Each item keeps its source, so a reader sees who said it and how well it is corroborated.
Three commitments
Organisations, management systems, sites and events are recorded on shared forms, whichever application a user works in.
Criteria are governed centrally and inherited by every institution that uses them, so an evaluation means the same thing everywhere.
The operator decides what to share and with whom. An institution that accepts a file keeps its own copy.
02 · Who it serves
Cooperatives and other ASM operators compile one structured file and reuse it for each institution they approach. An application to a second institution is pre-filled from the profile already compiled, so the work of compiling once pays off on every later application.
Today in KOTA · later also in the standalone HATUA application, in development
A bank receives the operator's file, reviews it and assesses the counterparty against structured information requirements. Each bank applies its own rating policy and its own rules of access to services on top of the common evaluation. The same design serves other institutions: EGC (Entreprise Générale du Cobalt) already has an aggregator interface on KOTA.
KOTA · operating with Trust Merchant Bank (TMB) since March 2026
A buyer can form a consolidated judgement from three kinds of evidence: the operator's own file, shared with its consent; independent observation by monitors; and the public record gathered in the hubs, where claims are rated by their sources and by how well they are corroborated.
The DRC Cobalt Hub already gives downstream companies upstream insight from public information. Connecting the hubs to monitoring data is outstanding, and no international information client is recorded yet.
Extractive Industries Transparency Initiative (EITI) hub at nashiriki.com/eiti · DRC Cobalt Hub at cobalt.daac.ai
Local monitors, civil-society organisations and consultants can use Nashiriki to record sites, incidents, activities, corrective actions and testimonials on the same forms. Every incident, activity and testimonial is attached to a named initiative, with the organisation leading it and the organisation funding it kept apart.
Nashiriki · nashiriki.com
03 · Structure, as built
Section and field names below are those of the applications' own form specifications.
The operator's own file, in ten sections, plus a view of the people and organisations linked to it.
Five sub-assessments of the operator's own management systems. They open once the application is submitted.
One mine-site form of twelve sections, designed to be the same form in every application. Two of its sections carry the environment and gender modules.
Incidents, activities and testimonials share one form of eight sections. Six record types are cut from it: Incident, Activity, Testimonial, Training Record, Mitigation Measure and Initiative.
Documents are uploaded with a category and an expiry date, against a list of required documents that depends on the type of operator and that each institution can adapt. For a mining cooperative the list includes, for example, its founding act, its approval, its member register and its cooperative rules.
Every field can be marked "not applicable" or "no information available": a deliberate declaration, distinct from a field left blank. Core identification fields cannot be marked this way.
Organisations and sites are evaluated by a deterministic method. The same file always gives the same result; a fact backed by a document counts for more than a bare declaration, and one confirmed by another source counts for more still; the result is recalculated whenever the file changes. The criteria are governed centrally, not edited institution by institution.
The evaluation informs a decision. It is not a credit score and does not replace the institution's judgement.
The exchange, in one figure
04 · OECD mapping
The mapping below is the consortium's own reading of what it built, offered so that a reader can see the five-step framework of the OECD Due Diligence Guidance in the forms.
| OECD step | Where the operator, or a monitor, answers it |
|---|---|
| STEP 1Strong company management systems | Management systems: Supply Chain Policy, Internal Management Systems. Organisational file: Governance, Organisation Policies. Site form: Identification, Access, Operations. |
| STEP 2Identify and assess risk in the supply chain | Organisational file: Associations, Compliance, Scrutiny, Trade. Site form: Human Rights, Gender & Inclusion, Peace & Security, Environmental Impact, Health & Safety, Community & Society, Workforce. The operator's trade partners and operating sites. |
| STEP 3Design and implement a strategy to respond to identified risks | Incidents and activities, with Corrective Action as a type of activity; Mitigation Measure records on the event form; Management systems: Supply Chain Integrity, Supplier Engagement; the five-stage incident lifecycle. |
| STEP 4Independent third-party audit | Not performed by CADD, and not claimed. What CADD provides is auditability: every record keeps its source, and independent observation and public-source corroboration sit beside the operator's own declaration. |
| STEP 5Report on supply chain due diligence | Production and shipment records; the operator's consented sharing; the public hub pages; testimonials on the event form. |
| GRIEVANCEGrievance mechanism | Management systems: Grievance Mechanism Features. The incident lifecycle, which includes an explicit mediation stage. |
| ANNEX IIOECD Annex II risks | The site evaluation scores the risk sections of the site form against the Annex II risks. One human-rights criterion covers cruel and degrading treatment, including gender-based violence. |
05 · How it is used
Today the operator's sequence runs in KOTA, where TMB reviews what operators submit.
The operator registers online, describes its organisation and chooses the institutions it wants to approach. For an operator without an e-mail address, the institution can complete the registration on its behalf.
It completes the application and attaches the documents required for its type of operator. It can save part-way and come back.
It completes the organisational file and the five management-system sub-assessments. Completion is shown as a percentage, to the operator and at submission.
On submission the file goes only to the institutions the operator chose. Nothing is shared by default, and each institution keeps its own copy.
The bank sees each applicant and where its file stands. It can also open a file itself for an operator with no digital access and invite it in later.
One person prepares the review and another decides. The decision is dated and gives its reason.
The bank accepts, or declines with a reason. After a refusal the operator can correct its file and resubmit.
The evaluation updates when a document is added or information is corrected, and every version of the file is kept.
A monitor records a site on the twelve-section site form, so that creating a site record is assessing it. Incidents, activities, corrective actions and testimonials are recorded on the event form. An incident moves through five stages, recorded as its state and changed only by the roles allowed to change it:
06 · From v1 to v2
The first version of CADD was a framework document. The second is the form structure built into the applications, and the exchange between them. The deliverable was information exchange and interoperability across several applications, which is why it took longer than planned.
The project plan foresaw handling applications for banking services in an earlier application, MMT. Registrations made there included external parties whose data did not allow a determination about the counterparty.
Expand the framework to banking-sector compliance expectations, build environmental vigilance into it, and build gender protection monitoring into it.
The first annual report identified delays in framework expansion, bank onboarding and civil-society registration.
CADD was translated into questions, evidence requirements and assessment workflows covering organisations, management systems and site risks, on shared forms and a shared evaluation method.
KOTA, the bank-facing application, began operating with TMB.
The bank's earlier self-assessment arrangement was folded into the shared organisational file of ten sections and the five management-system sub-assessments. Feedback from Justice Plus informed improvements to roles, incidents and reporting in Nashiriki.
The five-stage incident lifecycle, with its mediation stage, was settled out of that feedback round.
The French user manual for KOTA's bank interface was published at kota.datastake.io/manuel-utilisateur-tmb.
Released after the 31 August reporting cut-off. Its uptake and field outcomes remain to be measured.
07 · Status and next step
Delivered as software. Annex II, sheet 1, row 15: target 1, realised 1 in period 2.
delivered
Delivered inside the applications, not as separate tools. Rows 26 and 27: realised 1 each. Each has its own one-page description.
delivered
KOTA has operated with TMB since March 2026. HIVE and Datastake trained bank staff. Nashiriki records observations, incidents and corrective actions.
in use
Cooperative self-onboarding; connecting the hubs to monitoring data; a live EPRM Audience trial. End-to-end consolidation is therefore unfinished.
outstanding
The availability of these tools does not by itself show that site-level risks have fallen, that women's participation has improved or that access to finance has grown. Those outcomes need field observations and partner records, and are reported separately.
A standalone HATUA self-assessment application, open to cooperatives independently of banking or buyer applications, is in development. It is a direction, not yet available. The software milestone is distinct from the period of adoption and outcome measurement that will follow it.
direction
Public pageskota.datastake.iokota.datastake.io/manuel-utilisateur-tmbnashiriki.comnashiriki.com/eiticobalt.daac.ai
Consolidated Autonomous Due Diligence (CADD), version 2 as built. Prepared on 21 September 2026 for the project EPRM23S016, "Holistic Due Diligence Framework for Energy Transition Minerals", lead party HIVE asbl, with the support of the European Partnership for Responsible Minerals (EPRM).
Partners named on this page: Trust Merchant Bank (TMB), primary banking partner; La Sentinelle des Ressources Naturelles, local coordination; Justice Plus, co-creator of the civil-society application; Datastake, implementing technology partner. KOTA is developed and maintained by Datastake.