77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Supplier audit: process, obligations according to LkSG and ISO 9001, templates for audit practice
Supply Chain

Supplier audit: process, obligations according to LkSG and ISO 9001, templates for audit practice

2 July 202614 min readBy Dr. Henrik Bauer
CIVAC

Since the Supply Chain Due Diligence Act and the EU Supply Chain Directive, supplier audits are no longer a voluntary practice, but a due diligence measure that requires documentation. This article shows the process, criteria and templates for audits that the BAFA report and the ISO 9001 certifier recognise equally.

With the Supply Chain Due Diligence Act (LkSG) coming into force on January 1, 2023, the supplier audit has changed from a voluntary quality measure to a duty of care that requires documentation. Companies with more than 1,000 employees in Germany are obliged to systematically identify risks in their own supply chain and take preventative and remedial measures, with annual reporting to BAFA. The EU Supply Chain Directive (CSDDD) of July 25, 2024 gradually extends these obligations to additional companies from 2027 and intensifies the requirements for documentation, complaint procedures and civil liability. According to Section 24 of the LkSG, anyone who does not carry out a supplier audit or carries it out inadequately risks fines of up to 800,000 euros for natural persons and up to eight million euros for legal entities, and in the event of a repeat of up to two percent of global group sales.

At the same time, quality management standards such as ISO 9001:2015 in Chapter 8.4 require the control of externally provided processes, products and services with a risk-based depth of examination. Industry standards such as IATF 16949 for the automotive industry, ISO 13485 for medical devices or ISO 27001:2022 for information security further sharpen the requirements. This article shows how a supplier audit is planned, carried out and documented in such a way that it convinces both BAFA as the supervisory authority according to LkSG and the ISO certification auditor, without damaging the supplier as a business partner. CIVAC as a compliance platform and officer-as-a-service delivers the audit templates, reporting lines and the external supplier auditor within two working days.

Key Takeaways

  • Supplier audits are mandatory according to LkSG, ISO 9001 and industry standards: those who do not audit or do so inadequately risk fines of up to eight million euros and certificate revocation.
  • An audit is only effective if preparation, on-site inspection, documentation of findings, action plan and effectiveness control are documented as a closed chain.
  • CIVAC delivers 37 audit templates, the workspace with reporting line to management and, if requested, the external supplier auditor within two working days.

Legal basis: LkSG, CSDDD, ISO 9001 and industry standards

The Supply Chain Due Diligence Act defines the preventive measures in Section 6 LkSG, the remedial measures in Section 7 LkSG and the documentation and reporting obligation to BAFA as the responsible supervisory authority in Section 10 LkSG. In concrete terms, this means: Companies must regularly check their own business activities and those of their direct suppliers for human rights and environmental risks, as well as indirect suppliers along the entire value chain if necessary. The audit must be carried out at least once a year and, if there is substantial knowledge of risks, on an ad hoc basis, which requires the ability to react within a few weeks. The EU supply chain directive CSDDD will apply from July 26, 2027 for companies with more than 5,000 employees and 1.5 billion euros in sales, from 2028 for 3,000/900 million, from 2029 for 1,000/450 million. The German implementation is still pending at the time of publication of this article, but is due by July 26, 2026 at the latest Mandatory.

In parallel, ISO 9001:2015 requires in Chapter 8.4.2 the definition and application of criteria for the evaluation, selection, performance monitoring and re-evaluation of external providers. ISO 9001:2015 does not necessarily require an on-site audit, but accepts evidence of suitability such as self-certifications, certificates and audit reports depending on the provider's level of risk. In regulated industries, on-site audits are actually indispensable: IATF 16949 (automotive) requires periodic supplier audits, ISO 13485 (medical devices) and ISO 14971 require structured supplier qualification with risk management, ISO 27001:2022 Annex A.5.19 to A.5.22 regulate supplier relationships from an information security perspective. Anyone who is certified in several of these standards should set up the audit so that a single on-site appointment covers the requirements of all standards, with joint audit days and topic-specific modules. The appointment certificate, signed, filed, verifiable. This integrated audit logic saves considerable effort on both sides and reduces the burden on the supplier.

Risk-based supplier selection and audit prioritization

No one can audit every supplier. The duty of care according to LkSG requires risk-based prioritization with comprehensible methodology. Section 5 LkSG prescribes the risk analysis as an annual obligation, in the event of significant changes on an event-related basis and immediately if there is substantial knowledge of risks. The risk analysis evaluates two dimensions: the probability of occurrence of a human rights or environmental risk and the potential extent of damage in terms of the people or objects of protection affected by the risk. The drivers are industry, country, product, contract structure, order volume and findings from previous audits or external sources such as NGO reports, BAFA notices or media reports. A textile supplier in Bangladesh has a higher risk of occupational health and safety violations than a German screw manufacturer, a lithium supplier in Chile has a higher risk of environmental damage than a local packaging printer. The risk assessment is documented for each supplier with a traffic light colour or a score number and stored in a versioned manner.

The audit frequency results from the risk assessment. Recommendation: High-risk suppliers are audited on site annually or semi-annually, medium risks every two years, low risks every three years or via self-disclosure with selective on-site verification as part of a sample. Strategically important single-source suppliers should be audited regularly, regardless of the risk, because a failure would have existential consequences and the resilience of the supply chain is an independent protection goal. The audit frequency is documented in the audit program, which management approves annually. If you also use a supply chain representative, he or she will coordinate audit planning with purchasing, quality and compliance in a common reporting line. CIVAC's 490 audit templates already contain the audit program, the risk matrix and the supplier score card in an integrated structure that is prepared for LkSG reporting to BAFA.

Audit preparation: scope, criteria, audit team, supplier communication

A supplier audit begins four to six weeks before the on-site appointment, in high-risk regions with visa requirements and travel preparation even eight to twelve weeks. In the first step, the scope is defined: which topics are examined (quality, occupational safety, human rights, environment, information security), which location is affected, which processes are inspected, which documents are viewed, which employees are interviewed. The scope is agreed with the supplier in writing and serves as the agenda for the on-site appointment. In the second step, the criteria are determined: which standard or legal requirements are the standard for testing, which internal guidelines of the purchasing company apply, which industry standards and which contractual clauses from the supply contract. The criteria are formulated as an audit checklist with clear target statements, each of which refers to the source document with a requirement number.

In the third step, the audit team is put together. A typical team consists of a lead auditor with relevant qualifications (e.g. IRCA Lead Auditor ISO 9001 or certified supply chain auditor with SA8000 or comparable accreditation), a specialist auditor for each subject area and a person accompanying the purchasing company for the commercial side. For pure LkSG audits in high-risk regions, it is recommended to use local auditors with language and cultural knowledge, because otherwise employee interviews are not meaningful and promises of confidentiality do not seem credible. In the fourth step, communication to the supplier takes place: announcement of the audit at least four weeks before the date, transmission of the audit checklist, request for documents to be submitted in advance (organisational chart, quality manual, approvals, number of employees, contracts with your own suppliers, social security certificates). Without this preparation, the on-site audit becomes a sample without depth. In the CIVAC workspace, the audit announcement, checklists and document requirements are stored as templates and can be customized for each supplier.

On-site implementation: opening conversation, inspection, random sampling, survey

An on-site audit follows a fixed choreography. In the opening conversation, the purpose of the audit, scope, criteria, process, confidentiality and escalation methods in the event of abnormalities are discussed and the role of the individual auditors and supervisors is clarified. The supplier's management, the quality manager, the responsible human resources manager and, if applicable, the supplier's compliance officer are present. The opening conversation is recorded, the minutes are signed by both sides and serve as proof of the agreed scope. This is followed by a production and site inspection with a visual inspection of the workplaces, security facilities, warehouses, social rooms and accommodation if migrant workers are employed. Anomalies are documented with a photo (if permitted), timestamp and description, ideally directly in the audit app on the auditor's tablet.

Samples are the heart of the audit. Personnel files (employment contracts, time sheets, wage payment receipts, training certificates, age information to avoid child labour), safety data sheets, maintenance protocols, complaint documents, supplier self-disclosures from the audited company's own suppliers are checked. Sample size and selection logic are determined before the audit, usually at least 10 to 25 data sets per subject area, correspondingly more for high-risk audits and with a targeted selection of conspicuous areas. Employee surveys are the most sensitive element and must be carried out confidentially, without the presence of superiors and in the employee's native language, preferably outside the factory premises. The respondents are documented anonymously; original statements are not passed on to the supplier's management. Anyone who does not adhere to this confidentiality risks not only useless surveys, but also reprisals against the respondents and violations of the protection of whistleblowers. The auditor calls, the evidence is ready. In the CIVAC workspace, the survey results are documented and stored in version form with anonymization protection.

Findings, assessment and audit report according to international standards

Audit findings are classified into four categories: major nonconformity (critical violation of a requirement requiring immediate remediation), minor nonconformity (violation of a requirement that can be remedied in a timely manner), observation (potential vulnerability without a current violation), potential for improvement (indication of better practice without a requirement). The categorization follows the ISO 19011:2018 standard for management system audits and is used consistently in the relevant audit literature. Each finding is documented with the following elements: requirement (law, standard, internal guideline with paragraph or chapter number), current state, target state, evidence (photo, document number, survey result with date), category, recommendation for remediation. A general assessment of how many defects in the area of ​​occupational safety are not sufficient because no measure can be derived without concrete evidence.

In the final meeting, the findings are discussed with the supplier's management, misunderstandings are clarified, the supplier is given the opportunity to comment and can correct any errors immediately. The final conversation is recorded and signed by both sides. The audit report is then prepared within 10 to 15 working days and sent to the supplier with a request to plan measures within a category-dependent deadline. The audit report contains a summary, list of findings, assessment, recommendations and next steps including a date for the effectiveness review. The report is stored in the CIVAC workspace with a version so that the chain of evidence is consistently traceable from the audit announcement through the survey protocols to the final report. Audit-proof, documented, § 10 LkSG-proof. When BAFA checks for a tip, the chain of receipts is available in minutes, not weeks. Others run compliance like a filing cabinet. We run it like software. This means that the structured audit documentation differs measurably from the typical email and Excel practice of many purchasing departments.

Action plan, effectiveness control and escalation

The action plan is the crucial step that causes many supplier audits to fail. Without a documented measure, the finding remains without consequence, which constitutes a breach of duty according to Section 7 LkSG and leads to fines in the BAFA procedure. The supplier creates an action plan for each finding within a period defined in the audit report (usually: 14 to 30 days depending on the category, often immediately in the case of major deviations) with the following mandatory information: corrective action to eliminate the specific defect, root cause analysis using a systematic method (5-Why, Ishikawa, FMEA), preventive measure to avoid recurrence, name of the person responsible, implementation deadline with date. The plan is released by the purchasing company or rejected with additional demands, which is documented in writing.

The effectiveness check is carried out with a delay: In the event of major deviations, a follow-up inspection is carried out within four to eight weeks in which the effectiveness of the corrective measures is verified, often with an on-site follow-up audit. In the case of minor deviations, a written request for evidence with images, protocols or changed procedural instructions is often sufficient. In the case of systemic or repeated violations, escalation follows: written warning, reduction of the order volume, temporary suspension, and in the worst case, termination of the contract in accordance with Section 7 Paragraph 2 Sentence 5 LkSG. Important: According to the LkSG, termination of the contract is only the last resort; an appropriate concept for ending or minimising the risks must have been tried beforehand, with documented escalation in several stages. Deadline begins as soon as we become aware of it. In the CIVAC workspace, the escalation chain is mapped as a workflow with deadlines, responsibilities and reporting lines to management, so that no escalation level is skipped or forgotten. Every decision to maintain or terminate the business relationship is documented with reasons and can be proven to BAFA at any time.

Documentation and BAFA reporting obligation according to Section 10 LkSG

The reporting obligation according to Section 10 LkSG is specific and unyielding. Obligated companies must prepare an annual report on the fulfilment of their due diligence obligations and make it available free of charge on the company website for at least seven years and submit it to BAFA electronically via the reporting portal. The report contains information on risk analysis, identified risks, preventive and remedial measures taken, complaint procedures, effectiveness control and statements about the company's own business activities and direct suppliers. BAFA checks the reports on a random basis, publishes evaluations and industry comparisons and uses the data for supervisory measures. According to Section 24 LkSG, anyone who does not submit the report or submits it incompletely risks a fine of up to 800,000 euros and exclusion from public contracts for three years.

In concrete terms, this means for the audit documentation: Every audit carried out must be recorded with the date, supplier name (in the internal report), topic scope, number of findings by category, status of measures and status of the effectiveness control. The aggregate numbers stated in the published BAFA report must be reconstructable from this internal documentation, otherwise BAFA objects and demands access to the chain of documentation. The audit data is stored in the CIVAC workspace in such a way that the aggregation for the annual report takes place automatically: number of audited suppliers, number of identified risks, proportion with action plan, proportion with effectiveness control, number of escalations and contract terminations. Licence the workspace for your internal representatives or have our representatives order it. Both models provide the aggregation prepared for BAFA without having to merge Excel lists from different sources at the end of the year. The annual report thus becomes a consequence of ongoing day-to-day business, not a separate reporting project under time pressure in the first quarter.

Cost, efficiency and the CIVAC SLA of two business days

A full-fledged on-site audit of a supplier costs between 4,000 and 15,000 euros depending on the location and complexity, and significantly more for foreign audits in high-risk regions with visas, local auditors and translators and in individual cases over 30,000 euros. Added to this are internal costs for preparation, travel, reporting and follow-up, which quickly exceed external costs. A medium-sized company with 200 strategically relevant suppliers and a risk-based frequency logic typically carries out between 30 and 80 audits per year, which quickly adds up to a seven-figure total budget. Efficiency therefore becomes a competitive factor, not just a question of compliance requirements, but a question of margin ability.

CIVAC delivers efficiency on three levels. First, the 490 audit templates provide the recurring work steps as versioned, ready-to-use templates, which typically reduces audit preparation time by 30 to 50 percent while standardizing reporting quality. Secondly, CIVAC deploys the external supplier auditor in the officer-as-a-service model within two business days, instead of the classic two to six weeks, which flexibly scales audit capacity and enables ad-hoc audits in response to reports. Thirdly, the audit data is documented in such a way that the LkSG reporting, the ISO 9001 certification and the QMB function are fed from the same database, which avoids multiple recording. Licence the workspace for your internal representatives or have our representatives order it. This results in consistent, verifiable supplier compliance from parallel audit traces, which stands up to the BAFA procedure and the ISO audit. Scaling from 30 to 80 audits per year is therefore a question of audit team capacity, not tool availability or documentation discipline. The annual BAFA report also becomes a routine aggregation from the current system.

Turn reading into a mandate.: Start a supplier audit program with CIVAC

If you want to set up a systematic supplier audit program, you start with a clearly defined starting package: appointing a supply chain or supplier auditor with an appointment certificate and reporting line to management, setting up the supplier risk matrix with classification of all direct suppliers into three risk levels, defining the audit program with frequency logic and topic scope, creating the audit checklist based on the relevant standards (LkSG, ISO 9001, industry-specific standards). Within 60 to 90 days, an operational program is set up that carries the first BAFA annual report and passes the ISO audit.

CIVAC accompanies this development as a compliance platform and officer-as-a-service in two models. In the workspace model, you licence the platform for your internal representatives and use the 490 audit templates, the audit report formats, the risk matrix and the BAFA aggregation logic as an immediately usable framework with EU data residency. In the officer-as-a-service model, we provide the external supplier auditor or supply chain representative within two working days, instead of the classic two to six weeks for external auditors. Both models use the same workspace, reporting line and templates, allowing for later switching without data migration. If you would like to know what scope of audit is appropriate for your supplier structure and how the 90-day development plan is tailored to your industry, write to info@civac.de or use the contact form on civac.de/faq. Within one working day you will receive an initial assessment with concrete next steps, a recommendation for the right model and an indicative audit program for the next twelve months. This gives you a reliable basis for budget planning and for integrating purchasing into the LkSG reporting line. Turn reading into an assignment.

FAQ

Who is obliged to carry out a supplier audit according to LkSG?

Since January 1, 2024, all companies with headquarters, headquarters or registered office in Germany and more than 1,000 employees have been subject to the Supply Chain Due Diligence Act. The duties include risk analysis, preventive measures and remedial measures, which includes supplier audits as a key tool. From 2027, the EU Supply Chain Directive CSDDD will gradually extend the obligations to smaller companies.

How often does a supplier audit have to be carried out?

According to Section 5 LkSG, the risk analysis must be carried out at least annually and on an ad hoc basis. The audit frequency results from the risk assessment: high-risk suppliers every six months or annually, medium risks every two years, low risks every three years or via self-disclosure with selective on-site verification. Industry standards such as IATF 16949 require additional periodic audits regardless of risk level.

What categories does an audit finding have?

According to ISO 19011, a distinction is made between major deviation (critical violation, immediate remedial action), minor deviation (violation with plannable correction), observation (potential weak point) and potential for improvement. Each finding must be documented with target, actual, proof, category and recommendation. The categorization controls the deadlines for the action plan and effectiveness control.

How much does a supplier audit cost?

Depending on the location, complexity and scope of topics, an on-site audit costs between 4,000 and 15,000 euros, and significantly more for foreign audits in high-risk regions. There are also internal costs for preparation, travel, reporting and follow-up. Self-disclosure audits without an on-site appointment are cheaper, but have lower probative value and are weighted accordingly in the BAFA report.

How is a supplier audit presented in BAFA reporting?

The annual report in accordance with Section 10 LkSG contains aggregated information on the number of audited suppliers, risk categories, identified risks and effectiveness controls. Individual suppliers are not named in the published report. However, BAFA can request individual documentation in the event of an audit, which is why the internal chain of documents with version status and responsibility must be complete.

When is the termination of the business relationship permissible according to LkSG?

According to Section 7 Paragraph 2 Sentence 5 LkSG, termination is only the last resort. Beforehand, the company must develop a concept for ending or minimising human rights or environmental risks and implement it with the supplier. Termination is only justified if this attempt is unsuccessful or if serious violations offer no prospect of being remedied. The escalation steps must be documented.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles