77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Human rights officer according to Section 4 LkSG: tasks, appointment and reporting obligation
Supply Chain

Human rights officer according to Section 4 LkSG: tasks, appointment and reporting obligation

11 August 202613 min readBy Dr. Henrik Bauer
CIVAC

Section 4 (3) of the Supply Chain Due Diligence Act requires the appointment of a person responsible for monitoring risk management. Find out what tasks the human rights officer has, how the appointment is documented and how a Workspace bundles BAFA report, risk analysis and complaint procedures in one source.

The Supply Chain Due Diligence Act (LkSG) came into force on January 1, 2023 and has applied to all companies with more than 1,000 employees in Germany since January 1, 2024. According to Section 4 Paragraph 3 LkSG, management must ensure that risk management is anchored in all relevant business processes in order to fulfil due diligence obligations. It must designate a person who is responsible for monitoring risk management within the company. In the language of BAFA and in practice, this person is the human rights officer. The function is not mentioned by name in the law, but is firmly established in the BAFA handouts and in the reports from the first reporting years. The management must be informed at least once a year by the representative about the work of risk management.

This guide shows the operational tasks of the human rights officer, the formal requirements for the appointment, the reporting path to the management and the interfaces to the complaint procedure, BAFA report and supplier management. You will learn which obligations are most often misinterpreted in the first reporting period, how a workspace bundles BAFA reports, risk analysis and complaints in one source and how the function can be interlinked with the CSRD reporting obligation and ESRS S2 without creating duplicate structures.

Key Takeaways

  • Section 4 (3) LkSG requires the appointment of a person to monitor risk management, with an annual reporting obligation to management and sufficient resources to carry out the task.
  • The operational duties include risk analysis, prevention measures, remedial measures, complaint procedures, BAFA report and training, all documented and filed in an audit-proof manner.
  • A workspace with the LkSG data model, supplier questionnaire, complaint module and BAFA report export reduces the annual reporting effort by 40 to 60 percent compared to Excel-based procedures.

Section 4 Paragraph 3 LkSG in the wording: what the law really requires

The central norm is: 'The management must ensure that the measures mentioned in paragraphs 1 and 2 are implemented. It must designate a person who is responsible for monitoring risk management within the company, such as a human rights officer. The management must inform itself regularly, at least once a year, about the work of the responsible person.' The law thus defines four constitutive elements: firstly, the personal responsibility of management for implementation, secondly, the obligation to appoint a person to supervise, thirdly, the freedom of choice in naming (the term human rights officer is a suggestion, not a mandatory term), fourthly, the annual reporting obligation.

The freedom of choice in naming is often used in practice to integrate the function into an existing role, for example with the compliance officer, the sustainability officer or the head of purchasing. It is important that the function is explicitly named, provided with resources and has a direct reporting line to management. The function of the LkSG representative is shown in the CIVAC workspace as an independent role entry with an appointment certificate, task description and reporting path. CIVAC operates as a compliance platform and officer-as-a-service and delivers the appointment certificate as a legally verified template. The appointment certificate, signed, filed, verifiable. The management is allowed to delegate operational responsibility, but the legal liability for the supervisory duty remains with them according to Section 130 OWiG. The appointment certificate therefore documents not only the scope of tasks, but also the reporting obligation, the replacement arrangement in the event of vacation and illness, as well as the resources made available, because all of this is required by BAFA in the audit. A clearly structured order also includes a clear statement about freedom of instruction in technical questions, so that the function is not dissolved in the interests of the line.

The operational tasks: what the human rights officer does specifically

The LkSG lists in Section 3 Paragraph 1 the eight duties of care, the operational management of which the human rights officer is responsible for. Firstly, the establishment of risk management (§ 4). Secondly, carrying out regular risk analyses (§ 5). Thirdly, the submission of a declaration of principles (Section 6 Paragraph 2). Fourthly, the anchoring of prevention measures in your own business area and with direct suppliers (Section 6 Paragraphs 3 and 4). Fifth, taking remedial action if violations are identified (Section 7). Sixth, the establishment of a complaints procedure (§ 8). Seventh, the implementation of due diligence obligations with regard to indirect suppliers (Section 9). Eighth, documentation and reporting to BAFA (§ 10).

In practical terms, this means: The human rights officer coordinates the annual risk analysis, checks suppliers according to defined criteria, includes code of conduct clauses in contracts, documents training, oversees the complaints procedure and prepares the annual BAFA report. He is not the sole person responsible, but rather the coordinator of a cross-departmental process in which purchasing, legal, HR, compliance and management work together. Others run compliance like a filing cabinet. We run it like software. The CIVAC workspace links all eight due diligence obligations in a data model so that a measure in the supplier context is automatically visible in risk analysis, reporting and training planning. This saves duplication of work and avoids inconsistent data situations that lead to complaints in the BAFA report. An additional task that is not expressly mentioned in the law, but is indispensable in practice, is regular reporting to the management and the supervisory board, because the LkSG risks are increasingly becoming part of corporate risk reporting and are mentioned in the management report according to the HGB.

Risk analysis according to § 5 LkSG: annually, event-related, documented

Risk analysis is the heart of the LkSG obligations. According to Section 5 Paragraph 4, it must be carried out once a year and repeated as necessary if the company has to expect a significantly changed or expanded risk situation, for example due to the introduction of new products, projects or a new business area. In terms of content, it covers two levels: your own business area and your direct suppliers. According to Section 9, indirect suppliers only fall into the scope of application if the company obtains substantiated knowledge of violations. This separation is a political compromise in the LkSG and will probably be eliminated with the EU directive CSDDD from 2027, so that indirect suppliers will then also have to be checked regularly.

Methodologically, the risk analysis begins with an abstract risk assessment by industry, country and product category, followed by a concrete assessment of the prioritised suppliers using standardised indicators. The BAFA has published detailed criteria in its handouts, such as country-specific risk indices (ITUC Global Rights Index, EPI Environmental Performance Index), industry-specific risk profiles and product-specific hotspots. The CIVAC workspace automatically integrates these indices and links them to the supplier base so that the risk analysis can be generated for each supplier in minutes. Deadline begins as soon as we become aware of it. If there is substantiated knowledge of a breach in the indirect area, an event-related risk analysis must be carried out immediately and the result must be documented in the BAFA report. Anyone who allows the deadline to pass risks a fine according to Section 24 LkSG. The concept of appropriate measures is expressly mentioned in the LkSG and requires a proportionality test based on the severity of the violation, the probability of its occurrence, the scope of the company's contribution and the possibilities of influencing it.

Prevention and remedial measures: from code of conduct to contractual clause

§ 6 LkSG requires appropriate preventive measures as soon as the risk analysis identifies a risk. In our own business area, this includes a written policy statement, anchoring the human rights strategy in procurement practices, training in relevant areas and risk-based control measures. For direct suppliers, this includes selection based on risk analysis, contractual assurances about compliance with human rights-related expectations, training and further education, and the contractual agreement on appropriate control mechanisms. The code of conduct for suppliers is the central contractual anchor of these obligations.

If the company discovers a violation or has indications of an impending violation, remedial measures must be taken immediately in accordance with Section 7. The violation must be ended in your own business area; for direct suppliers, a concept for termination or minimization must be drawn up with a concrete timetable. According to Section 7 Paragraph 3, termination of the business relationship is the last resort and is only necessary if the violation is classified as serious and no milder means are available. CIVAC provides a tested template for the code of conduct with the clauses recommended by BAFA, including audit rights, notification obligations and escalation levels. Licence the workspace for your internal representatives, or have our representatives order it. In both models, a continuous documentation chain is created from the risk analysis to the corrective action. In the workspace, remedial measures can be filtered by status, person responsible and escalation level, so that management receives a compact view of the progress of the measures on a quarterly basis and unresolved cases do not disappear in a file drawer. In addition, the clauses in the code of conduct are versioned so that it is clear in the audit which version was contractually agreed with which supplier and at what point in time.

Complaint procedure according to Section 8 LkSG: from reporting to case management

§ 8 LkSG requires an appropriate internal company complaint procedure that enables people to point out human rights and environmental risks as well as violations of human rights or environmental obligations. The procedure must be accessible, conducted by an impartial body, maintain confidentiality of identity and ensure protection against discrimination or punishment. Unlike the Whistleblower Protection Act (HinSchG), the LkSG procedure is also open to external persons, i.e. affected employees of suppliers, representatives of NGOs or residents. The rules of procedure must be in writing and publicly accessible.

In practice, the HinSchG reporting office and the LkSG complaint procedure can be combined in one system, with clearly separated input channels and case types. The Internal Reporting Office (HinSchG) covers internal information, the LkSG module also accepts external complaints. The workspace documents each case with date of receipt, processing status, measures and feedback to the whistleblower. The deadline of three months for feedback is not expressly regulated in the LkSG, but is recommended by BAFA as good practice, based on Section 17 HinSchG. The auditor calls, the evidence is ready. Anonymous entry channels are expressly permitted and in many cases are the only way to receive external information because affected employees from supplying countries often fear reprisals. Multilingual input channels, ideally in the languages ​​of the main sourcing countries, significantly increase accessibility and are expressly recommended by BAFA as good practice. The rules of procedure for the complaint procedure are stored in version form in the workspace and are available with a key date query so that the current status can be clearly quoted in the BAFA report. In many cases, an external ombudsman office usefully complements the internal procedure.

BAFA report according to § 10 LkSG: contents, deadline, publication obligation

The annual BAFA report is the central public duty of the LkSG. According to Section 10 Paragraph 2, the report must be submitted to BAFA no later than four months after the end of the financial year and published in parallel on the company website for at least seven years. In terms of content, it includes seven main categories: identified risks and injuries, measures taken to fulfil due diligence obligations, assessment of the effectiveness of the measures, conclusions derived for the future strategy, the complaint procedure and the results of a plausibility check of the complaints received.

Since 2023, BAFA has provided an electronic report form with over 400 questions that must be answered with mandatory information, justifications and references. Anyone who compiles the report in Excel or Word risks formal errors when uploading and content inconsistencies between the answers. The CIVAC workspace maintains the LkSG data all year round in the required structural model and exports the BAFA report form with all mandatory information in the format required by BAFA. Audit-proof, documented, § 10 LkSG-proof. The effectiveness assessment of the measures is the part where most initial reports fail because, without year-round data collection in the workspace, there is no reliable impact measurement and pure activity descriptions are provided, which the BAFA rates as inadequate. Cleanly structured data management reduces the reporting time from an average of three weeks to around three working days. The report is transmitted to BAFA in a structured XML format, and the CIVAC workspace handles the conversion automatically, so that manual steps are no longer necessary and the formal requirements of the BAFA portal are reliably met. The publication on the company website is in PDF/A format, which is required to be retained for seven years.

Interface to CSRD and ESRS S2: double duty, one database

Anyone who is subject to the LkSG and at the same time falls under the CSRD must comply with two parallel reporting obligations. The LkSG requires an annual report to BAFA with operational detail. The CSRD requires the sustainability declaration in the management report with ESRS S2 (employees in the value chain) and ESRS S3 (affected communities), which overlap significantly with the LkSG in terms of content. The data points are partly identical (risks in the supply chain, complaint procedures, remedial measures), and partly structured differently. Anyone who manages the two worlds separately doubles their effort and produces inconsistencies that are criticized in the BAFA process or in the audit.

The solution is a common data model that manages the LkSG data points as a subset of the ESRS data points and generates both reports from one source. The CIVAC workspace uses such a consolidated model in which the LkSG data points are linked to the ESRS data points and are automatically distributed across the BAFA reporting form and the ESRS-XBRL taxonomy. Licence the workspace for your internal representatives, or have our representatives order it. If you only start consolidation in the second or third reporting year, you will lose several hundred hours in the initial report and create an inconsistent database that will appear as a finding in the later audit. Anyone who sets up consolidation early gains a structural efficiency advantage of around 40 to 50 percent because supplier queries, risk analysis and action tracking only have to be carried out once. The same logic applies to the EU taxonomy and sector-specific requirements as long as they access supply chain data, so that the data model serves multiple reporting requirements at the same time. If you set up the consolidation properly, you can also use future CSDDD reporting from the same data master without having to fundamentally restructure the system.

Fines, liability and exclusion from public contracts

§ 24 LkSG provides for fines of up to 8 million euros or up to 2 percent of the average annual turnover of the last three financial years, whichever is higher. The turnover limit only applies to companies with an annual turnover of more than 400 million euros. In addition, according to Section 22 LkSG, there is an exclusion from the award of public contracts for up to three years. Both sanctions are imposed and published by BAFA. The management is also personally liable according to Section 130 OWiG if the organisational supervisory measures were inadequate. According to Section 3 Paragraph 3 LkSG, civil liability towards injured parties is expressly not justified, which is often misunderstood. Claims for damages continue to exist on the basis of the BGB.

The first BAFA proceedings in 2023 and 2024 show a clear pattern: the main complaints are about the inadequate documentation of the risk analysis, the lack of an assessment of the effectiveness of the measures and the inadequate complaint procedure. Fines have so far only been imposed in individual cases; the BAFA mainly works with notices and orders. With the entry into force of the EU-CSDDD, which is expected to take place in 2027, the sanctions regime will be significantly tightened, and indirect suppliers will also fall fully within the scope of application. Anyone who creates clean documentation today is prepared for the European standard. CIVAC maintains complete documentation of all measures in the workspace with a time stamp, person responsible and effectiveness assessment, so that proof is available in minutes in the BAFA process or in the audit. Others run compliance like a filing cabinet. We run it like software. Anyone who consistently documents the effectiveness assessment also gains a management tool for management that goes well beyond the formal BAFA obligation and leads to a clear reputational advantage in investor questions, customer audits and bank discussions.

From Section 4 LkSG to a productive role in the company

Section 4 Paragraph 3 LkSG gives the management a lot of scope for design, but little scope for substance. The responsible person must be named, provided with resources, documented in the appointment certificate and provided with annual reporting to management. Operationally, she coordinates risk analysis, prevention measures, remedial measures, complaint procedures, BAFA reports and training without having to take on all the tasks herself. The right organisational anchoring determines whether the function has an impact in practice or languishes as a formal entry in the compliance manual. That's exactly why we built CIVAC as a compliance platform and officer-as-a-service: a workspace with LkSG data model, supplier questionnaire, complaint module, BAFA report export and EU data residency.

You decide for yourself how deep you want to go: Licence the workspace for your internal representatives, or have our representatives appointed. Turn reading into an assignment. Write to us at info@civac.de or book an initial consultation using the contact form on civac.de. You will receive an honest maturity assessment of your LkSG program, a gap analysis against the BAFA reporting form, a prioritised list of measures and a transparent offer. The appointment certificate, policy statement and risk analysis are created in the first 30 days. In the following 60 days, the supplier questionnaire, complaint module and training courses will be put into production in the workspace. The auditor calls, the evidence is ready. With the EU CSDDD coming into force in 2027, today's clean documentation will become the basis of tomorrow's European compliance program, without having to rebuild the data model. Anyone who plans the transition early avoids duplication of work and positions themselves as a preferred supplier to major customers who are increasingly checking their own suppliers for resilient LkSG and CSDDD structures.

FAQ

Does the human rights officer have to have certain qualifications according to Section 4 LkSG?

The law does not prescribe any specific qualifications. In practice, a combination of compliance, purchasing or sustainability experience with a basic understanding of human rights and supply chains is effective. Management must provide the person with sufficient resources, authority and a direct reporting line so that the function can be carried out effectively and stands up in the BAFA process.

Can the role of human rights officer be combined with compliance officer?

Yes, the function can be combined with other compliance roles, such as compliance, sustainability or money laundering officers. It is important that there is no conflict of interest and that the function is equipped with sufficient resources and reporting channels. A dual role as head of purchasing is possible, but should be secured with escalation clauses in the appointment certificate due to potential conflicts.

How often does the risk analysis have to be carried out according to Section 5 LkSG?

At least once a year and additionally if the company has to expect a significantly changed or expanded risk situation. Triggers include new products, projects, business areas or substantiated knowledge of an infringement by an indirect supplier. The analysis must be fully documented and presented in a summarized form with all essential findings in the annual BAFA report.

What deadline applies for the annual BAFA report according to Section 10 LkSG?

The report must be submitted to BAFA no later than four months after the end of the financial year and published in parallel on the company website for at least seven years. For a fiscal year that corresponds to the calendar year, the deadline is April 30 of the following year. Delays will be sanctioned by BAFA with notices or fines.

What fines are there for a violation of the LkSG?

According to Section 24 LkSG, up to 8 million euros or up to 2 percent of the average annual turnover of the last three financial years, whichever is higher. In addition, there is an exclusion from public contracts for up to three years. The management is also personally liable in accordance with Section 130 OWiG for inadequate supervisory measures.

How can LkSG obligations and CSRD reporting requirements be mapped in one system?

Via a common data model that maintains the LkSG data points as a subset of the ESRS data points. Supplier queries, risk analysis and complaint procedures are carried out once and automatically distributed to the BAFA report and ESRS S2/S3. This saves 40 to 50 percent effort and avoids inconsistent data between the two reporting obligations in the management report and in the annual audit by the auditor.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles