Human rights officer: Obligation according to Section 4 Paragraph 3 LkSG and task profile
Since January 1, 2024, the LkSG obligation applies to all companies with 1,000 or more employees in Germany. Section 4 Paragraph 3 LkSG requires a person to monitor risk management. This article explains duties and orders.
The Human Rights Officer has been a formal role in German companies since the Supply Chain Due Diligence Act (LkSG). Section 4 (3) LkSG requires that management appoint a person to monitor risk management and be informed regularly, at least annually, about their work. Since January 1, 2024, the obligation applies to companies with 1,000 or more employees.
This article explains who is responsible, what tasks the profile includes, how the appointment is formally made and how CIVAC's compliance platform and Officer-as-a-Service secures the role. The appointment certificate, signed, filed, verifiable.
Key Takeaways
- Section 4 (3) LkSG obliges all companies with 1,000 or more employees in Germany to entrust a person with monitoring risk management.
- Tasks include risk analysis, prevention and remedial measures, complaint procedures, documentation and the BAFA annual report in accordance with Section 10 LkSG.
- CIVAC provides the human rights officer as an external officer-as-a-service with an appointment certificate, workspace and integrated reporting point.
Legal basis and scope of application
The Supply Chain Due Diligence Act came into force on January 1, 2023 for companies with 3,000 or more employees and has been in force since January 1, 2024 for companies with 1,000 employees or more in Germany. Section 1 Paragraph 1 LkSG defines the scope of application, Section 2 lists human rights and environmental risks.
Section 4 Paragraph 3 LkSG requires: The management determines who monitors risk management. This person must, particularly when a human rights officer is appointed, inform management about the work on a regular basis, at least once a year.
The wording allows for the task to also be taken on by another function, such as the Compliance Officer or the Head of Sustainability. In practice, the term Human Rights Officer has established itself as an independent role.
In addition to the German regulation, the EU Supply Chain Directive (CSDDD) is expected to be added from 2027. It expands the scope of application to companies with 1,000 or more employees and a global turnover of at least 450 million euros and tightens the obligations in several points.
Companies below the threshold values are also covered indirectly via the supply chain because large clients contractually pass on the due diligence obligations to suppliers. The Cascade effect is a key driver in practice.
The scope of application also covers foreign companies with branches in Germany, provided that the number of employees in Germany is exceeded. Section 1 Paragraph 1 No. 2 LkSG is based on this.
Task profile according to the LkSG system
The tasks of the human rights officer arise from the duty of care in Sections 3 to 10 LkSG. They include the establishment of risk management, the annual risk analysis, preventive measures, remedial measures, a complaints procedure, documentation and reporting.
The risk analysis according to Section 5 LkSG is carried out annually and on an ad hoc basis. It identifies human rights and environmental risks in its own business area and among direct suppliers. If there is substantiated knowledge, the analysis also extends to indirect suppliers.
Prevention measures according to Section 6 LkSG include the anchoring of the human rights strategy, training, contractual assurances with suppliers and risk-based controls. Effectiveness must be checked and documented.
Remedial measures in accordance with Section 7 LkSG will be taken if a violation has already occurred. In the case of one's own business activities, the violation must be stopped; in the case of direct suppliers, a concept for termination or minimization is required; a change of supplier is the last resort.
The complaint procedure according to Section 8 LkSG is open to those potentially affected along the entire supply chain. It must be designed to be low-threshold, confidential and linguistically accessible. A set of rules of procedure will be made public.
CIVAC combines these obligations in the workspace. Risk analysis, measures, complaints and reports come together in a workflow. Audit-proof, documented, § 4-LkSG-proof.
Order, reporting line and suspension in the company
Unlike the data protection or emissions control officer, the LkSG does not prescribe a specific form of appointment. Section 4 Paragraph 3 LkSG only requires the identification of the person. In practice, a written appointment certificate is still recommended because it creates clarity of tasks and preservation of evidence.
The appointment certificate contains the name, area of responsibility, authority, reporting line to management, resource commitment and escalation path. An order as a mere job description in the organisational chart is not sufficient because individual responsibility must be stated.
The reporting line to management is explicitly required. At least once a year, and often quarterly, the representative reports on the risk situation, measures taken, complaints and effectiveness tests. The report is recorded and included in the annual report.
An organisational focus in the areas of compliance, law or sustainability is common. It is important to be independent from operational purchasing decisions so that the representative can act without a conflict of interest.
External appointments are permitted and make sense in many companies because the required range of specialist knowledge is rarely available internally. The external officer is installed with an appointment certificate and contract, reporting line and escalation path remain directed to internal management.
CIVAC provides qualified external human rights officers as Officer-as-a-Service. The order is submitted within the CIVAC SLA of 2 working days, with appointment certificate and documented proof of qualification.
BAFA report and external audit
§ 10 LkSG requires annual reporting to the Federal Office of Economics and Export Control (BAFA). The report describes identified risks, measures, effectiveness testing and complaints. It must be submitted and made publicly accessible within four months of the end of the financial year.
The reporting structure follows a questionnaire that BAFA provides as a fillable form. In total, the questionnaire includes around 437 fields, divided into mandatory questions and free description. Completeness is checked by BAFA on a random basis.
If there are deficiencies in the report or in risk management, BAFA can order measures, request information and impose fines of up to 800,000 euros per violation. For companies with an annual turnover of over 400 million euros, a turnover-dependent sanction also applies.
In addition to the LkSG reporting, the human rights officer often makes contributions to the sustainability report according to CSRD, especially to the ESRS S1 to S4 (own workforce, supply chain employees, affected communities, consumers). The dual function relieves the burden on the organisation.
External auditors certify the CSRD report with limited assurance. The LkSG reporting is checked by the BAFA; there is currently no external audit requirement, but is provided for within the CSDDD.
CIVAC maintains the BAFA questionnaire in the workspace, with versions, documents and cross-references to the CSRD report. The auditor calls, the evidence is ready.
Complaints procedure and reporting office
§ 8 LkSG requires a complaints procedure that is accessible to information from the entire supply chain. Unlike the whistleblower reporting point according to the HinSchG, the LkSG procedure is not limited to employees, but is open to external parties, supplier workers and affected communities.
Requirements are low-threshold, confidentiality, language diversity along the procurement regions and protection against reprisals against whistleblowers. Rules of procedure must be publicly available and explain the procedure.
Confirmation of receipt should be given within seven days and initial feedback should be given within three months, in accordance with Section 17 of the HinSchG. The LkSG requirements are less formally strict, in practice the HinSchG standard has become established.
The bundling of whistleblower and LkSG reporting points makes organisational sense as long as the procedural rules clearly separate the two areas of application. Confidentiality and protection against reprisals apply in both procedures.
Complaints must be analysed, documented and, if necessary, treated as a reason for a risk analysis in accordance with Section 5 LkSG. Substantiated references to indirect suppliers trigger a more in-depth analysis.
CIVAC integrates the reporting point in the workspace with encrypted input, a multilingual interface, processing deadline tracking and audit trail. Deadline begins as soon as we become aware of it. Confirmation of receipt and feedback are automatically documented.
Interfaces to data protection, ESG and compliance
The human rights officer works across many interfaces. Personal complaints, employee master data from suppliers and whistleblower information are regularly relevant to data protection according to the GDPR, in particular Article 6 Paragraph 1 Letter c and Article 9.
Cooperation with the data protection officer is therefore mandatory. Data protection impact assessments in accordance with Art. 35 GDPR may be necessary, for example when using supplier audit platforms or complaint software.
In the ESG context, the Human Rights Officer provides data and assessments for the social pillar (S1 to S4 of the ESRS). The materiality analysis according to CSRD incorporates human rights risks into the double materiality consideration.
Compliance interfaces arise when there are corruption risks in supply chains, antitrust violations and suspected money laundering. Section 6 GwG can collide with Section 5 LkSG if risky supplier relationships involve both corruption and human rights risks.
ISO/IEC 27001:2022 applies to IT systems for risk analysis and reporting points. The standard's 93 controls cover access management, encryption, backup, supplier security and incident management. EU data residency reduces data protection transfer risks.
CIVAC bundles 25 representative roles, all live. Licence the workspace for your internal representatives or have our representatives order it. The reporting lines converge in a consolidated workflow.
What the CSDDD will change
The EU directive on companies' due diligence obligations with regard to sustainability (CSDDD), passed in 2024, must be implemented into German law by mid-2027. The federal government is planning to adapt the LkSG or a new master law.
The scope of application of the CSDDD covers companies with 1,000 employees or more and a global turnover of 450 million euros. Foreign companies with corresponding EU sales are also included. The thresholds will be introduced staggered over several years.
In terms of content, the CSDDD tightens the scope of application to the entire value chain, not just direct suppliers. Indirect suppliers are therefore regularly included in the canon of obligations, which significantly expands the risk analysis.
Climate issues are regulated more explicitly. A mandatory component is a climate plan in line with the 1.5 degree path of the Paris Agreement, including interim targets and measures. The link to the remuneration of the management is mandatory.
Civil liability is newly introduced. Injured parties can claim damages before European courts if the duty of care has been breached and there is a causal connection. Liability lies with the parent company.
CIVAC is already preparing the workspace structures for the CSDDD requirements. Advanced supplier analysis, climate plan tracking and claims management will be included in the roll-out phase. Others run compliance like a filing cabinet. We run it like software.
Costs, contract design and insurance
The costs of an external human rights officer vary depending on the scope of suppliers, risk regions and group structure. Flat-rate contracts for medium-sized companies are often between 18,000 and 60,000 euros per year, and significantly higher for large corporations with a global supply chain.
The flat rate typically covers risk analysis, support of the measures, complaint processing, BAFA report and board reporting. Occasion-related special operations, for example after critical complaints, are billed on an hourly basis.
Professional liability insurance for the representative is usual, with coverage of at least 5 million euros per claim. With the introduction of the CSDDD and civil liability, higher coverage amounts will become standard practice.
The service contract must ensure data protection compliance. Personal data from supplier relationships, audits and complaints fall under the GDPR; an order processing agreement in accordance with Art. 28 GDPR is required.
The appointment certificate is an independent document alongside the contract. It creates the individual responsibility of the person appointed and is the central receipt for BAFA and supervisory authorities.
With CIVAC, the order is received within the SLA of 2 working days, compared to 2 to 6 weeks with classic consultant selection. Contract, appointment certificate, order processing agreement and reporting line are processed in one process.
Appoint the human rights officer for an audit with CIVAC
Section 4 Paragraph 3 LkSG cannot be delegated, cannot be replaced by a job description and cannot be covered by a blanket compliance function. Management must appoint a specific person to monitor risk management and report at least annually.
CIVAC bundles the duties in a compliance platform and officer-as-a-service. 25 officer roles, all live, including human rights, ESG, whistleblower protection and compliance officers, plus 490 ready-to-use audit templates and 93 controls according to ISO/IEC 27001:2022.
The workspace manages the appointment certificate, task description, reporting line to management, risk analysis, catalogue of measures, reporting office and BAFA report in one system. Versions, signatures and confirmations of receipt are audit-proof in the EU data residence.
Licence the workspace for your internal representatives or have our representatives order it. The dual model adapts to your internal setup, the legal mandate remains the responsibility of the management in both cases.
The FAQ page answers typical follow-up questions about the obligation to order, the BAFA report and the interface between LkSG and CSDDD. Others run compliance like a filing cabinet. We run it like software.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. The order is submitted within 2 working days, audit-proof and § 4-LkSG-proof.
FAQ
Who has to appoint a human rights representative?
Since January 1, 2024, the obligation under Section 4 Paragraph 3 LkSG applies to all companies with 1,000 or more employees in Germany. The management designates a person who monitors risk management and reports to the management at least annually. Branches of foreign companies are also included.
What qualifications does the person need?
The LkSG does not prescribe any formal qualifications. In practice, knowledge of human rights, supply chain management, compliance, data protection and complaints procedures is required. Linguistic competence for the relevant procurement regions and experience with risk analyses are de facto prerequisites.
What tasks does the role specifically include?
Risk analysis according to § 5, prevention measures according to § 6, remedial measures according to § 7, complaint procedure according to § 8, documentation and report to the management according to § 4, BAFA report according to § 10. The person coordinates internally with purchasing, legal, compliance, data protection and sustainability.
What happens if the LkSG is violated?
The BAFA can order measures, request information and impose fines of up to 800,000 euros per violation. For companies with a turnover of over 400 million euros, a turnover-dependent sanction also applies. In the event of serious violations, there is a risk of exclusion from public contracts in accordance with Section 22 LkSG.
How does the CSDDD change the obligations?
The EU Supply Chain Directive expands the scope of application to the entire value chain, requires a mandatory climate plan and introduces civil liability. Injured parties can sue for compensation in European courts. Implementation into German law is scheduled for mid-2027.
How quickly can CIVAC implement an external order?
CIVAC orders within the SLA of 2 working days, compared to 2 to 6 weeks with classic consultant selection. The appointment certificate, order processing agreement, reporting line and reporting point are in the workspace, and the reporting obligation to BAFA is prepared automatically.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

