77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Conduct LkSG risk analysis: example, template and seven-step plan
Supply Chain

Conduct LkSG risk analysis: example, template and seven-step plan

1 September 202613 min readBy Dr. Henrik Bauer
CIVAC

The LkSG risk analysis is mandatory for around 4,800 companies in Germany. This article provides an example, a template and a seven-step plan that combines abstract and concrete analysis with the BAFA requirements.

The Supply Chain Due Diligence Act (LkSG) has required companies with 1,000 or more employees to carry out annual due diligence obligations since 2024. The focus is on the risk analysis in accordance with Section 5 LkSG, which records human rights and environmental risks in our own business area and among direct suppliers. The BAFA report must be submitted by April 30 of the following year.

This article shows a tried-and-tested template, an example from medium-sized manufacturing companies and a seven-step plan that combines the abstract and concrete risk analysis, the catalogue of measures and the effectiveness assessment. You will learn how to avoid findings and embed the analysis into the ESG reporting cycle.

Key Takeaways

  • The LkSG risk analysis strictly distinguishes between abstract analysis (industry, country, product) and concrete analysis (individual suppliers, individual risks).
  • The BAFA report requires structured answers to 24 sets of questions that cannot be answered without a documented risk analysis.
  • An integrated platform with LkSG representative, audit templates and action tracking replaces parallel Excel lists and significantly reduces the BAFA reporting effort.

Duties at a glance: who, what, by when

Since January 1, 2024, the LkSG has required companies with a head office, headquarters or statutory seat in Germany and at least 1,000 employees. Group affiliation counts. Around 4,800 companies are directly obliged, many more indirectly as suppliers.

The duties include risk management, appointment of agents, risk analysis, preventive measures, remedial measures, complaints procedures, documentation and reporting. These eight elements are regulated in § 4 to § 12 LkSG and form the minimum framework.

The risk analysis must be carried out annually and on an ad hoc basis in accordance with § 5 LkSG. It includes your own business area and all direct suppliers. Indirect suppliers are only taken into account if there is substantiated knowledge of risks.

According to Section 10 Paragraph 2 LkSG, the report to BAFA must be submitted no later than four months after the end of the financial year, usually by April 30th. The BAFA checks the completeness and carries out in-depth checks in individual cases. Fines according to Section 24 LkSG range up to 8 million euros or 2 percent of group sales.

The personal responsibility of the management is opened up via Section 130 OWiG. Deadline begins as soon as we become aware of it. Anyone who acknowledges risks and does not react appropriately risks personal sanctions in addition to company fines.

The CIVAC platform and officer-as-a-service structure maps these obligations in a workspace and provides a LkSG role with a reporting line to management.

Abstract risk analysis: industry, country, product

The abstract analysis evaluates typical risk patterns by industry, country and product. It is the preliminary stage of the concrete analysis and significantly reduces the effort involved. Instead of evaluating 5,000 suppliers individually, clusters with similar risk profiles are formed.

Industry risks arise from typical working conditions, supply chain structures and raw material dependencies. Textiles, construction, mining, agriculture and electronics manufacturing are considered high-risk industries. This classification is based on public sources such as ILO, OECD guidelines and NGO reports.

Country risks use indices such as the ITUC Global Rights Index, the Corruption Perceptions Index, the Worldwide Governance Indicator or the EITI list. A three or five level rating is sufficient for most analyses. The choice of source is documented.

Product risks relate to raw materials with known risks in the upstream chain: cobalt, tin, coltan, mica, cotton, cocoa, palm oil. These seven groups lead most risk analyses. Industry-specific lists expand the catalogue.

The abstract analysis is condensed into a matrix, with the number of suppliers per risk cluster and with a heat map. This visualization is not an end in itself, but rather the basis for prioritization for the specific analysis.

The appointment certificate, signed, filed, verifiable. The CIVAC audit templates contain a matrix for abstract analysis with the 13 LkSG protected assets and a predefined cluster logic.

Concrete risk analysis: From the cluster to the supplier

The specific analysis evaluates individual suppliers within high-risk clusters. It uses additional information such as self-disclosures, certificates, audits, NGO reports and its own on-site observations. This in-depth analysis typically affects five to 20 percent of the supplier base.

The assessment is carried out according toseverity, scope, irreversibility and probability of occurrence. The severity ranges from mild impairment to irreversible damage. The scope covers the number of those affected. Irreversibility distinguishes between remediable and irremediable. The probability of occurrence results from historical data and indicators.

Self-disclosures are mandatory. Suppliers are asked about working conditions, safety, environmental regulations, complaint systems and supply chain depth. A response rate below 70 percent is a warning signal and should be a reason to ask questions.

Certificates are indications, not proof. An ISO 14001 certification does not exclude human rights risks; an SA8000 audit does not cover all LkSG protected goods. The assessment combines multiple sources rather than trusting a single one.

On-site audits are essential in high-risk supply chains. They can be carried out bysupplier auditors, ordered internally or externally. The audit reports are incorporated into the risk assessment and influence the prioritization of measures.

Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, self-disclosures, certificates, audits and evaluations are bundled in the supplier master record.

Protected goods and risk categories: The 13 fields of the LkSG

The LkSG names thirteen human rights and two environmental protection items in Section 2. This list is exhaustive, but serves as a minimum standard, not an upper limit, of voluntary care. Each protected item is explicitly addressed in the risk analysis.

Human rights protected items include, among other things, child labour (Section 2 Paragraph 2 No. 1), forced labour (No. 3), slavery (No. 4), disregard for occupational safety (No. 5), withholding of appropriate wages (No. 8), impairment of freedom of association (No. 6) and discrimination (No. 7).

There is also a ban employment without compliance with occupational health and safety obligations (No. 5), withholding fair remuneration (No. 8), unlawful deprivation of land (No. 9) and commissioning private or state security forces without protecting human rights (No. 10).

Environmental protection items refer to mercury (Minamata Convention), persistent organic pollutants (POPs Convention) and hazardous waste (Basel Convention). These three are narrowly defined, narrower in comparison to the draft CSDDD.

Each protected item is assessed per supplier cluster. A table with suppliers in the row and 13 protected goods in the column is the simplest representation. The assessment is carried out in three or five stages, with justification and source.

CIVAC provides a template with all 13 protected assets, pre-filled indicators and a link to public data sources. The evaluation is structured instead of being built up from Excel templates every year.

Catalog of measures: prevention and remedy

The risk analysis is followed by prevention and remedial measures. Prevention according to Section 6 LkSG aims to avoid risks in your own business area and with direct suppliers. Remedial measures in accordance with Section 7 LkSG apply if violations have already occurred.

Preventive measures in your own business area include policy statements, training, adjustment of procurement practices and control-based procedures. In the supplier area, contractual assurances, training offers and audit mechanisms are also included.

Remedial measures are based on the severity of the violation. With indirect suppliers, working towards improvement is often enough. For direct suppliers, a concept with a schedule and effectiveness control is mandatory. Termination of the business relationship is the last resort.

Contractual assurances are a classic, but not a panacea. A pure clause without audit or control is not appropriate, but a clause with an audit obligation and a sanction mechanism is effective. The contract design must match the risk assessment.

Training for employees in purchasing, logistics and management is mandatory. In the report, BAFA checks how many people were trained and with what content and methodology. General information is not enough, but documented lists of participants are.

Licence the workspace for your internal representatives or have our representatives order it. CIVAC combines a catalogue of measures, proof of training and effectiveness assessment in a workspace with a reporting line to management.

Complaint procedure and whistleblower protection

§ 8 LkSG requires a complaints procedure that is accessible to information about human rights and environmental risks. It must be confidential, impartial and effectively accessible to those affected, including with indirect suppliers and in the language of those affected.

The procedure overlaps with the Whistleblower Protection Act (HinSchG), which has required an internal reporting point for companies with 50 or more employees since 2023. A combination of both obligations in one system is permissible and reduces the effort.

Requirements are accessibility, confidentiality, impartiality, protection against discrimination and transparent procedural rules. Complaints are documented, processed, forwarded to the representatives and presented in an aggregated form in the report.

The effectiveness of the procedure is checked annually. Indicators are the number of complaints, processing time, completion rate and feedback from complainants. A low number of complaints is not necessarily a good signal, but is often an indication of a lack of awareness.

Language versions are not optional. Anyone active in countries with a relevant supplier base provides the process in the respective national language or a regional lingua franca. A pure German or English version does not fulfil Section 8 LkSG.

CIVAC offers an integrated reporting office that serves the HinSchG, LkSG and collective bargaining law in one workflow. The Reporting Office according to HinSchG is part of the platform and can be staffed externally.

Check and document effectiveness

§ 9 LkSG requires the annual effectiveness assessment of all due diligence obligations, as well as an event-related assessment if there is substantiated knowledge of new risks. This assessment is an independent process, not an appendage of the risk analysis.

Effectiveness is measured using specific indicators. Examples: number of trained people, number of audited suppliers, number of complaints, number of resolved findings, quota of contractually secured suppliers, quota of certified raw materials. These indicators are defined for each measure.

The evaluation follows a simple logic: What was planned, what was implemented, what has improved, what has not? These four questions are answered and documented for each measure. A blanket answer is not enough.

If it is not effective, the measure will be adjusted. Training with a 40 percent participation rate is not effective and needs adjustment. A contractual clause without audit rights is not effective and requires renegotiation. This adjustment is part of the due diligence.

The documentation of the effectiveness assessment belongs in the BAFA report. The report form explicitly asks for indicators, results and adjustments. Anyone who remains vague here risks questions or in-depth examinations.

The auditor calls, the evidence is ready. CIVAC connects measures, indicators, actual values ​​and effectiveness assessment on the measure data set, with an annual snapshot for the BAFA report.

BAFA report 2026: structure and stumbling blocks

The BAFA report 2026 for the 2025 financial year must be submitted by April 30, 2026. The report form includes 24 sets of questions in seven sections: general information, risk management, risk analysis, prevention, remedial action, complaint procedure, documentation.

The questions are partly quantitative (number of suppliers, number of training courses, number of complaints) and partly qualitative (description of the method, justification of the threshold values). Both types of answers need a reliable basis in ongoing documentation.

Frequent stumbling blocks: inaccurate supplier numbers, lack of training certificates, generic descriptions of measures, unclear assessment of effectiveness, insufficient differentiation between direct and indirect suppliers. These weaknesses lead to BAFA queries or in-depth reviews.

Preparation begins in November of the reporting year with the consolidation of all measures, indicators and complaints. The report questions are worked through in January, the report is coordinated internally in February, finalized in March and submitted in April.

The report is published in parallel on the company website. This obligation according to Section 10 Paragraph 3 LkSG increases the public visibility of due diligence practices. NGOs, investors and business partners evaluate the reports and compare companies in an industry.

Audit-proof, documented, § 10-LkSG-proof. CIVAC delivers a BAFA report export that fills in the 24 sets of questions from the ongoing documentation and creates a verifiable appendix.

From example to implementation: your next step

A template does not replace representatives or risk management, but it is the fastest bridge to structured implementation. Anyone who switches from Excel stacks to an integrated workspace gains time, consistency and resilience towards BAFA and customers.

Others run compliance like a filing cabinet. We run it like software. The CIVAC platform bundles the LkSG risk analysis, catalogue of measures, complaint procedures, effectiveness assessment and BAFA report in a workspace with EU data residency.

Licence the workspace for your internal representatives or have our representatives appointed. In the officer-as-a-service model, experienced LkSG officers and supplier auditors take over operational control. SLA for the order: two working days instead of 2 to 6 weeks search.

Concrete first steps: consolidate supplier inventory, carry out abstract risk analysis, identify high-risk clusters, obtain self-disclosure, deepen concrete risk analysis, derive measures, define effectiveness, generate BAFA report from the documentation.

Anyone who interlinks the risk analysis with the ESG report wins additionally. ESRS S2 and LkSG share data objects and indicators. A common database reduces the data collection effort and ensures consistent statements to auditors, investors and BAFA.

Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We check your initial situation, suggest a course of action and appoint the appropriate representative. You can find an overview of the 25 representative roles on the platform.

FAQ

Who has to carry out an LkSG risk analysis?

Since 2024, all companies with headquarters, headquarters or headquarters in Germany and at least 1,000 employees. Group affiliation counts. Around 4,800 companies are directly obliged, many more indirectly as suppliers to their large customers.

What is the difference between abstract and concrete risk analysis?

The abstract analysis assesses risk patterns by industry, country and product and forms clusters with similar profiles. The concrete analysis deepens the assessment of individual suppliers within high-risk clusters, with self-disclosures, certificates and audits.

When is the LkSG risk analysis due?

Annually, additionally on an event-related basis if there is substantiated knowledge of new risks or changed supplier relationships. The BAFA report on the risk analysis must be submitted no later than four months after the end of the financial year, usually by April 30 of the following year.

What fines are there for LkSG violations?

According to Section 24 LkSG, up to 8 million euros or 2 percent of the average group annual turnover. In addition, there is an exclusion from public contracts for up to three years. Section 130 OWiG also opens up personal sanctions against management.

Which protected goods does the LkSG cover?

Thirteen human rights protections in accordance with Section 2 Paragraph 2 (child labour, forced labour, discrimination, freedom of association, occupational safety and others) and two environmental protections with reference to the Minamata, POPs and Basel Conventions. The list is exhaustive, but a minimum standard.

How does CIVAC support LkSG implementation?

CIVAC bundles risk analysis, catalogue of measures, complaint procedures and BAFA report in a workspace with EU data residency. You can either licence the system for your internal LkSG representative or order external representatives with a two working day SLA.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles