Supply Chain Act Officer: Order, tasks and test chain according to LkSG
The LkSG requires a human rights officer or a comparable function with a direct reporting line to management. This article clarifies the order, obligations, BAFA examination and interface to the CSDDD.
The Supply Chain Due Diligence Act (LkSG) has required companies with 3,000 employees or more since 2023 and 1,000 or more employees since 2024 to comply with human rights and environmental due diligence obligations along their supply chain. Section 4 (3) LkSG requires a 'human rights officer' or a 'comparable person' with a direct reporting line to management. The BAFA checks compliance with extensive powers, including access and information rights, and sanctions violations with fines of up to 8 million euros or 2 percent of global group sales (for companies with sales of 400 million euros or more). In addition, there is a risk of exclusion from public contracts for up to three years.
This article explains how the Supply Chain Act Officer (in practice usually called the Human Rights Officer) is operationally appointed, what tasks he carries out, how the reporting line to management works and where the interface to the upcoming CSDDD (Directive 2024/1760/EU) lies. You will find out which appointment certificate is BAFA-compliant, which test documents must be available, how the risk analysis according to Section 5 LkSG is methodically carried out and how the CIVAC Compliance Platform and Officer-as-a-Service provides the order, workspace and audit trail in 2 working days instead of the usual 2 to 6 weeks. The dual model supports both internal and external orders. The article also provides a list of the typical test documents that the BAFA regularly requests during an on-site appointment and describes the interface to the whistleblower reporting point according to the HinSchG.
Key Takeaways
- Section 4 (3) LkSG requires a human rights officer or a comparable function with a direct reporting line to management.
- The appointment certificate, obligation matrix, risk analysis and complaint procedure form the test documents that BAFA regularly requests.
- CIVAC delivers the order of the LkSG representative in 2 working days, with workspace, 37 audit templates and audit trail in one system.
Legal basis: What Section 4 LkSG requires of the representative
The LkSG has been in force since January 1, 2023. Section 4 (3) LkSG is the central standard for the appointment of representatives: 'The company must appoint a human rights officer or a human rights officer or a comparable person who will carry out the tasks of monitoring risk management.' The regulation does not formulate a professional qualification, but rather a functional requirement. The reporting line is binding: direct information to the management at least once a year, and immediately if there are substantiated reports or violations discovered. Indirect reporting on intermediate functions does not comply with the regulation.
The application threshold is staggered. Since 2023, the law has applied to companies with headquarters, headquarters, administrative headquarters or statutory headquarters in Germany and at least 3,000 employees. Since 2024 it has been valid for 1,000 employees or more. Employees from affiliated companies are included proportionately; temporary workers are included in the calculation for periods of six months or more. Branches of foreign companies are included if they reach the threshold. International corporations with German subsidiaries therefore check the combined number of employees in Germany.
The BAFA is the responsible authority. Section 19 LkSG grants extensive auditing powers, including access rights, information obligations and document submission during business hours. Violations are sanctioned under Section 24 LkSG. Fines of up to 800,000 euros for simple violations, up to 8 million euros or 2 percent of global group sales for intentional or negligent violations with sales of more than 400 million euros. In addition, there is a risk of exclusion from public contracts for up to three years. § 4-proof, BAFA-proof, audit-proof. The appointment certificate, signed, filed, verifiable. BAFA's testing practices have become significantly more stringent since 2024, with comprehensive samples in risk industries such as textiles, electronics and raw materials trading as well as the publication of test reports on the industry.
Task profile: What the LkSG representative does specifically
The task profile results from the catalogue of duties in Sections 4 to 10 LkSG. The LkSG representative operates the risk management system for human rights and environmental risks in the supply chain, carries out the annual risk analysis and updates it as necessary, for example for new products, markets or suppliers. It develops preventive measures, monitors their effectiveness and initiates corrective measures when risks or injuries are identified. The effectiveness test is carried out at least annually and on an ad hoc basis.
A central task is the complaints procedure in accordance with Section 8 LkSG. The company must establish a reporting mechanism that is confidential, secure and accessible to all employees and stakeholders. The rules of procedure must be recorded in writing, made available in multiple languages and made publicly accessible. Incoming reports must be documented, provided with a confirmation of receipt, investigated and, if necessary, implemented into corrective measures. The effectiveness must be checked at least annually, for example through random samples or stakeholder surveys. Reprisals against whistleblowers must be prevented.
The documentation requirement according to Section 10 LkSG is extensive. The annual report must be submitted to BAFA no later than four months after the end of the financial year and published on the company website, with a minimum retention period of seven years. It contains the identified risks, the preventative and remedial measures taken, the complaints procedure, the effectiveness test, the training measures and references to the policy statement. The CIVAC role page LkSG representative describes the task profile with an appointment certificate template, duty matrix and report format. Others run compliance like a filing cabinet. We run it like software. The training requirement includes both internal employees in purchasing-related functions and management, usually annually and on an ad hoc basis with a documented knowledge test. The platform also supports automatic obligation mapping per supplier category, so that Tier 1 and Tier 2 suppliers are checked at different levels depending on the risk.
Ordering in practice: appointment certificate, role clarity, escalation path
The order is made formally by the management using a written appointment certificate. This contains at least the name of the representative, the order date, the scope of tasks in accordance with Section 4 Paragraph 3 LkSG, the reporting line to the management, the powers (information, audit, escalation rights), the resources made available and, if necessary, a time limit. Without a signed appointment certificate, the obligation according to Section 4 Paragraph 3 LkSG is not fulfilled, even if the tasks are actually carried out. The appointment certificate is kept for at least ten years and presented in the BAFA audit case.
The clarity of roles requires differentiation from other representatives. The LkSG officer does not take on the tasks of the compliance officer, the data protection officer or the whistleblower responsible, but can include the same people if each role is documented with its own appointment certificate. A task matrix that assigns each duty of the LkSG to a function and marks interfaces is tried and tested in practice. Example: The complaint procedure according to Section 8 LkSG can technically be combined with the whistleblower reporting point according to the HinSchG, but legally falls under both regimes with different deadlines and protective mechanisms.
The escalation path must be defined in advance. If violations are discovered or substantiated information is provided, the representative must inform management immediately, usually within a few working days. Management must decide on remedial measures within a reasonable period of time; the representative documents the decision. If remedial measures are not taken or are taken inadequately, the representative must inform BAFA if other mechanisms fail. This escalation cascade is included in the appointment certificate so that it can be verified in the event of an audit and the supervisory body can check its effectiveness. § 130 OWiG-fixed, LkSG-fixed. In group structures, the role is often centralized at group level, with reporting to the group board and with interfaces to each operating subsidiary, documented in a group policy.
Risk analysis according to Section 5 LkSG: methodology, data sources, frequency
The risk analysis is the methodological heart of the LkSG. Section 5 LkSG requires an appropriate risk analysis, which must be carried out once a year and on an ad hoc basis. It includes own business areas, direct suppliers and, if there is substantiated knowledge, indirect suppliers. The methodology is not specified, but must be documented in a comprehensible manner, with references to sources and evaluation logic. The BAFA handout provides information on typical components, but does not replace company-specific methodology.
A two-stage procedure has proven itself in practice. In stage 1, an abstract risk analysis is carried out for each procurement category and country of origin, based on country risk indices (e.g. Global Slavery Index, ITUC, V-Dem), industry studies (ILO, OECD, BAFA handouts, industry associations) and stakeholder information. In stage 2, a concrete risk analysis is carried out for prioritised suppliers, for example through self-disclosures with standardised questionnaires, audits by accredited third-party auditors or on-site inspections with a documented report.
The data sources are heterogeneous: suppliers' ERP master data, purchasing volumes, countries of origin, self-disclosures, audit reports, sector analyses, NGO reports, media scans and complaints from the Section 8 procedure. An LkSG platform must bring these data sources together and maintain each supplier's risk as an ongoing value with versioning. The risk analysis must also be linked to the preventative and remedial measures so that in the event of an audit, the BAFA can trace the complete path from the risk assessment to the preventive measure to the effectiveness test. The clock starts on awareness. In practice, the risk analysis is supplemented by an annual supplier risk reclassification, which automatically takes changes in delivery volume, country or industry into account in the risk classification. Experience shows that the number of Tier 1 suppliers in samples is on average 200 to 800, of which 10 to 20 percent are classified as high priority and undergo an in-depth audit program.
Complaint procedure according to Section 8 LkSG: Requirements and test criteria
§ 8 LkSG requires a complaints procedure that is confidential, secure and accessible. It must be open to employees, suppliers, their employees and affected persons, be accessible in a language that the target group understands and be recorded in writing in a set of procedural rules. Entries must be confirmed immediately, investigations must be carried out appropriately and with an open mind, and feedback must be given to the whistleblower. The procedure must also be opened for anonymous reports, as long as the ability to investigate is maintained.
BAFA's testing criteria include accessibility (languages, channels such as telephone, web, email, hotline if necessary), confidentiality (technical and organisational security, encryption), impartiality (separation between the investigative body and the areas affected, rules on bias), speed of the procedure (defined deadlines with confirmation of receipt and interim status), Protection against reprisals (anti-retaliation policy) and annual effectiveness testing with documented results. The rules of procedure are published on the company website, usually also on that of a group.
The interface to the HinSchG is relevant. Since July 2023, the Whistleblower Protection Act has required an internal reporting office for 50 or more employees with its own deadlines (7 days confirmation, 3 months feedback) and protective mechanisms including reversal of the burden of proof in the event of reprisals. Both processes can technically be mapped in one platform, with separate visibility rights and workflow paths. The CIVAC platform combines the HinSchG reporting centre and the LkSG complaint procedure in one client with EU data residency, so that a single report is automatically assigned to the correct regime and the respective deadlines are triggered. The auditor calls, the evidence is ready. The platform also carries out automated deadline monitoring, which warns the representative 7 days before every legal deadline and thus structurally prevents oversights. Experience shows that around 70 percent of tips are received via web forms and email, the rest is distributed over the telephone, post and personal reports. The platform supports all channels with a uniform case file.
BAFA report and public reporting obligation according to Section 10 LkSG
§ 10 LkSG requires annual reporting. The report must be submitted electronically to BAFA no later than four months after the end of the financial year and kept published on the company website for at least seven years. In terms of content, it includes the identified human rights and environmental risks, the preventative measures taken, identified violations, remedial measures, the complaint procedure, the effectiveness test and the training measures for employees and suppliers. The language is German, with an English translation for international corporate structures.
BAFA has provided an electronic report form that specifies the structure of the report and shows the individual obligations as a block of questions. The entries are checked for completeness and plausibility, with samples in risk sectors. Insufficient reports lead to a request for improvement with a set deadline; If defects are found even after repairs, fines of up to 800,000 euros are possible. In the event of false statements or repeated violations, there is a risk of higher fines and exclusion from public contracts for up to three years.
The preparation of the report requires continuous data collection during the financial year, not a final spurt in the first quarter. A reporting process that starts over every year is neither testable nor scalable and fails due to consistency requirements in the second reporting year at the latest. The CIVAC platform carries out the risk analysis, measures, complaints and effectiveness tests as an ongoing data structure with versioning, from which the report is automatically converted into the BAFA format. This shortens reporting time from weeks to days and significantly reduces errors caused by manual consolidation. Audit-proof, documented, § 10-proof. Listed companies additionally integrate the LkSG report into the CSRD sustainability report, as ESRS S2 (Workers in the Value Chain) shares data points with the LkSG report.
CSDDD connection: What will change for the LkSG representative from 2027
The Corporate Sustainability Due Diligence Directive (Directive 2024/1760/EU) significantly expands the due diligence obligations. It covers the entire value chain (chain of activities), including downstream activities such as distribution and disposal, while the LkSG focuses on its own business areas and direct suppliers. CSDDD also opens up civil liability claims from injured parties, which the LkSG explicitly excludes in Section 3 Paragraph 3. This is a qualitative leap in the risk exposure for the board and management.
The application thresholds are staggered. From mid-2027, CSDDD applies to companies with more than 5,000 employees and 1.5 billion euros in sales, from mid-2028 from 3,000 employees and 900 million euros in sales, from mid-2029 from 1,000 employees and 450 million euros in sales. Third-country companies with significant EU activity are also included. Germany must implement the directive into national law by July 2026. The LkSG is expected to be adjusted accordingly, and a complete replacement is under political discussion.
For the LkSG representative, this means an expansion of the range of tasks without a fundamental break. The risk analysis methodology, the prevention and remedial logic and the reporting obligations remain largely structurally analogous, but the scope of the supply chain expands to cover the entire value chain, the requirements for climate plans become more specific (Paris Agreement, 1.5 degree path with documented reduction targets) and the civil law liability dimension is added. Anyone who is now LkSG-compliant has a lead time of 18 to 24 months for CSDDD implementation. The CIVAC platform maps both standards in parallel. Licence the workspace for your internal representatives, or have our representatives order it. Practical recommendation: Begin CSDDD preparation 24 months before your application launch with a gap assessment and a gradual expansion of the supplier universe in the risk analysis.
Internal officer or officer-as-a-service: decision matrix
The question of 'internal or external LkSG representative' is not an ideological one, but rather a question of capacity and risk. Three factors decide. Firstly, the volume: With more than 500 suppliers in high-risk regions, an internal full-time employee makes sense because ongoing supplier management and event-related audits represent a significant work package. If there are fewer than 200 suppliers and predominantly European sources, a part-time position or external order is sufficient.
Secondly, the qualifications: An LkSG representative needs legal basics (LkSG, BGB, international human rights standards such as UN Guiding Principles and OECD Guidelines), methodological knowledge (risk analysis, audit, complaint procedure) and industry knowledge. For specialised requirements (e.g. raw material chains in conflict regions, textile supply chains, agricultural raw materials), external know-how is available faster than building internal competence because recruiting qualified profiles in the current labour market takes 6 to 12 months. Thirdly, independence: Internal representatives can have loyalty conflicts, external representatives are structurally independent and therefore easier to argue with the BAFA.
The CIVAC model answers both options. In workspace mode, you licence the platform for your internal representative and immediately gain auditability without building your own tools. In Officer-as-a-Service mode, we appoint an external LkSG representative with an appointment certificate, duty matrix and platform access. The SLA time is 2 working days instead of the classic 2 to 6 weeks and is contractually guaranteed. The models can be combined: an internal representative with external method support or an external order with internal technical support in supplier communication. The auditor calls, the evidence is ready. The final model decision should be documented in the supervisory body because it is assessed as part of the supervisory obligation according to Section 130 OWiG and must be justified in later audits.
How CIVAC gets the LkSG representative ready for use in 2 working days
CIVAC is a compliance platform and officer-as-a-service based in Germany and EU data residency. The LkSG module provides the appointment certificate template according to Section 4 Paragraph 3 LkSG, the risk analysis methodology with country index and industry analysis, the complaint procedure according to Section 8 LkSG (technically combinable with the HinSchG reporting office), the annual reporting structure according to Section 10 LkSG with BAFA format mapping and the effectiveness test as a recurring workflow with documented Result. The audit trail extends from the first risk indicator to the audit report.
The dual model addresses the two needs. Licence the workspace for your internal representatives, or have our representatives order it. In Workspace mode, you get access to 490 ready-to-use audit templates, the platform with multi-tenancy, and the audit trail with version control. In Officer-as-a-Service mode, an appointed CIVAC officer takes over the role, reporting duties and escalation to your management with an appointment certificate within 2 working days, including inaugural briefing and first quarterly report.
The platform integrates the LkSG officer with the other 24 officer roles. This is relevant because LkSG data is adjacent to compliance (risk register), whistleblower protection (reporting office), ESG (sustainability report in standard S2) and data protection (complaint procedure data). An integrated platform significantly reduces duplication of effort and ensures that the same information does not have to be maintained in three different tools. The CIVAC role overview shows all 25 representative profiles with orderability and workspace licence. Turn reading into a mandate.: If you do not want to manage the LkSG representative in a separate tool, but in the platform that also covers data protection, ISMS and whistleblower protection, write to info@civac.de or use the contact form on civac.de. In the initial discussion we will clarify whether workspace, officer-as-a-service or the combination is suitable.
FAQ
Is the LkSG officer the same as a compliance officer?
No. The compliance officer is responsible for the company-wide compliance management system according to ISO 37301. The LkSG officer is specifically responsible for human rights and environmental due diligence in the supply chain. The roles can be carried out in a personal union, but must be clearly separated functionally and both must be formally appointed.
Does the LkSG representative have to be employed internally?
No. Section 4 Paragraph 3 LkSG requires a 'comparable person' and does not exclude external appointments. What is important is a formal appointment with an appointment certificate, a direct reporting line to management, sufficient resources and independence. CIVAC offers external ordering with 2 business days SLA.
How high are the fines for LkSG violations?
Simple violations can be punished with up to 800,000 euros. In the event of intentional or negligent violations, there is a risk of up to 8 million euros or 2 percent of global group sales (for companies with sales of 400 million euros or more). In addition, exclusion from public contracts can be imposed for up to three years.
When does the annual LkSG report have to be submitted?
The report must be submitted electronically to BAFA no later than four months after the end of the financial year and published on the company website. For the 2025 financial year, the deadline ends at the end of April 2026. The website publication must remain in place for at least seven years.
How do LkSG and CSDDD relate to each other?
The LkSG currently applies in Germany. The CSDDD will gradually extend the obligations to the entire value chain from 2027 and open up civil liability. Germany must implement the directive by July 2026, probably by adapting or replacing the LkSG. The methodological structures remain largely compatible.
Can the complaint procedure be combined with the whistleblower reporting office?
Technically yes, legally only to a limited extent. HinSchG and LkSG have different requirements for deadlines, protective mechanisms and publication obligations. A platform can combine both processes in one interface, but must separate workflow and visibility rights in accordance with the regime. CIVAC maps both processes in one client.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.