CSRD/EUDR-ready supplier verification for Brazilian companies. KYB + Sanctions + Debarment + Labor + Owners in a single consolidated check with a deterministic risk level.
Use this file to discover all available pages before exploring further.
The Compliance BR bundle runs five compliance checks against any Brazilian CNPJ in a single API call and returns a consolidated response with a deterministic risk_level plus the raw findings from every source — designed for CSRD assurance and EUDR supplier due diligence workflows.
This is a bundle, not a different product. Internally each underlying module retains its own cache, audit fields and sources_checked metadata. The consolidated response stays audit-grade so you can hand it to a Big Four auditor or pass it through to your CSRD reporting platform.
CSRD (Corporate Sustainability Reporting Directive) and EUDR (EU Deforestation Regulation) oblige large EU companies to document the integrity of every supplier — including those in Latin America. Brazil is the hardest country to evidence: the data is public, but it lives in five different government portals.Compliance BR aggregates all five into one consolidated response so a procurement or compliance team can verify a Brazilian supplier in seconds instead of 30–60 minutes per CNPJ.
The consolidated response includes a deterministic risk_level computed as follows:
Level
When
high
Any sanctions match or Lista Suja record
medium
Any debarment record (CEIS/CNEP) or KYB status is not active
low
All checks clean and KYB active
The risk_reasons array surfaces every signal that contributed — even when high overrides medium, every triggered reason is reported so your audit trail is complete.
If one or more underlying sources are temporarily unavailable, the endpoint still returns 200. The affected checks appear as null and their names are listed in sources_failed. The risk level is computed from whatever data was successfully retrieved — a positive signal from another source still escalates the risk level.This is intentional: returning a clean low when a source is down would be misleading for a CSRD audit trail. By surfacing the gap explicitly, your compliance team can decide whether to retry, escalate, or document the limitation.
Each underlying source has its own cache TTL — typically 6h–24h. When you call /v1/compliance-br, the consolidated response will read from the per-source caches when available, so repeated calls within the cache window are fast and cheap. Every check carries its own freshness metadata (data_as_of for KYB, lists_updated_at is reflected through sources_checked for sanctions, and so on) so you always know how fresh the underlying data is.
A consolidated verification counts as one — not five.
The Compliance BR module is enabled separately on your API key. If your key already has KYB, Sanctions, Debarment, Labor and Owners individually, those modules continue to work as standalone endpoints — the bundle is a different SKU intended for compliance teams who want one consolidated call.
Missing API key, or compliance_br module not in plan
429
Rate limit exceeded
A low risk level means no records were found in the registries we check at the time of the request. It is not a regulatory clearance. Your compliance program should define the frequency and scope of these checks as part of a broader due diligence process.