LkSG Human Rights Risk Analysis Template: An Audit-Ready Framework for German Supply Chain Compliance
The German Supply Chain Due Diligence Act (LkSG) requires a documented annual human rights risk analysis since 2023. This guide gives you a structured template, the eleven legal risk categories, and the documentation depth BAFA expects when an inspection arrives.
Section 5 of the German Supply Chain Due Diligence Act (LkSG, in force since 1 January 2023) requires every covered enterprise to conduct an annual human rights and environmental risk analysis. Since 1 January 2024, the law applies to companies with 1,000 or more employees in Germany. The Federal Office for Economic Affairs and Export Control (BAFA) supervises compliance and has issued binding guidance (Handreichung Risikoanalyse, August 2022) on documentation depth.
A risk analysis is not a single document and not a one-off exercise. It is a structured, repeatable process that maps your own business operations and direct suppliers against eleven legally defined risk categories, weights the findings, and feeds the result into preventive measures. This guide provides a working template, explains BAFA's expectations on documentation, and shows how a compliance platform and officer-as-a-service make the annual cycle audit-ready instead of a yearly fire drill.
Auf einen Blick
- LkSG Section 5 requires an annual risk analysis across eleven defined human rights and environmental risk categories.
- BAFA expects documented methodology, weighting logic, and ad-hoc analysis triggers, not just a risk matrix.
- Direct suppliers must be analysed annually; indirect suppliers only on substantiated knowledge of violations.
Legal Scope: Who Must Conduct an LkSG Risk Analysis and When
The Lieferkettensorgfaltspflichtengesetz (LkSG) applies to enterprises with their head office, principal place of business, administrative seat, or statutory seat in Germany. The threshold was 3,000 employees from 2023 and dropped to 1,000 employees from 1 January 2024. Section 1 LkSG defines the scope; foreign branches with 1,000+ German employees are also covered.
The CSDDD (Corporate Sustainability Due Diligence Directive, in force June 2024) will replace and partially expand these obligations from 2027 onward. Member states have until 26 July 2026 to transpose. Companies preparing now build directly toward the CSDDD framework instead of running two parallel systems.
Section 5 LkSG mandates an annual risk analysis of the enterprise's own business operations and direct suppliers. Indirect suppliers fall under the analysis only if substantiated knowledge (substantiierte Kenntnis) of a potential violation arises, per Section 9 LkSG.
BAFA published its Handreichung Risikoanalyse (August 2022) and Handreichung Beschwerdeverfahren (July 2022). Both documents define the documentation depth inspectors look for. Fines under Section 24 LkSG reach EUR 8 million or 2 percent of global annual turnover for enterprises with turnover above EUR 400 million.
Where the LkSG officer or supply chain officer is appointed, that role oversees the analysis on behalf of the board, per Section 4 (3) LkSG. The board retains overall accountability and cannot delegate liability.
The deadline runs from awareness (Frist laeuft ab Kenntnis). A substantiated complaint received in October triggers an indirect-supplier analysis with no calendar buffer.
The Eleven Legal Risk Categories: A Working Inventory
Section 2 (2) LkSG defines eleven human rights risk categories and two environmental risk categories, plus a catch-all for behaviour that violates protected legal positions in a way comparable to the listed categories. The exact wording matters because BAFA aligns its inspection checklist to it.
Human rights categories include: prohibition of child labour (under 15 or applicable national age), worst forms of child labour, prohibition of forced labour, prohibition of slavery, disregard for occupational health and safety, disregard for freedom of association, unequal treatment in employment, withholding of an adequate living wage, environmental harm in violation of relevant treaties, unlawful eviction, and the use of private or public security forces in violations.
Environmental categories under Section 2 (3) cover the Minamata Convention (mercury), the Stockholm Convention (persistent organic pollutants), and the Basel Convention (hazardous waste). Each category requires a separate row in the risk matrix.
For each category, the analysis must record: country risk score, sector risk score, supplier-specific factors, gravity (severity, reversibility, scope), and probability. BAFA's Handreichung explicitly cites the OECD Due Diligence Guidance methodology.
CIVAC's 490 audit-ready templates include a pre-configured LkSG risk matrix that maps the eleven categories against supplier master data. Other firms run compliance like a filing cabinet. We run it like software.
The matrix is only the starting point. The methodology that produces the scores, the data sources behind country and sector risk, and the logic for combining them must be documented and reproducible.
Country and Sector Risk: Authoritative Data Sources
BAFA references several public data sources as acceptable starting points. The MVO Nederland CSR Risk Check, the German Federal Foreign Office country reports, the ITUC Global Rights Index, the US State Department Trafficking in Persons Report, and the World Bank Worldwide Governance Indicators are commonly used.
Sector risk draws on the OECD Sectoral Due Diligence Guidances, especially for garment, minerals, agriculture, and finance. The German Federal Ministry of Labour also publishes sector-specific guidance via the Helpdesk Wirtschaft und Menschenrechte.
The methodology has to define which sources feed which category, how scores are normalized (e.g. 1 to 5), and how conflicts between sources are resolved. Documented, traceable, Section-5-fest.
Suppliers in low-risk countries are not exempt from analysis but typically receive a lighter assessment. Suppliers in high-risk countries (e.g. ITUC Rating 5+ or systemic conflict zones) trigger enhanced due diligence with on-site audits or third-party verification.
A supply chain officer appointed under Section 4 (3) LkSG owns the methodology and updates it when sources change. The Helpdesk publishes annual updates that propagate into the scoring model.
Country and sector risk are abstract layers. The analysis becomes concrete when supplier-specific factors (contract value, production location, workforce composition, audit history) are layered on top.
Supplier-Specific Factors and the Weighting Logic
Section 5 (2) LkSG names four weighting criteria: the type and scope of business activity, the ability to influence the direct cause of risk, the typical severity of the violation, and the contribution of the enterprise's own conduct.
In practice this translates into a weighted scoring formula. A common pattern: country risk (30 percent) plus sector risk (20 percent) plus supplier-specific factors (50 percent), with the supplier-specific bucket including spend volume, dependency, production process, prior incidents, audit findings, and certification status.
Spend volume is a proxy for influence (Einflussvermoegen). High-volume relationships generally allow stronger leverage on remediation. Low-volume relationships in high-risk geographies still require attention but justify lighter measures if leverage is genuinely limited and documented.
The weighting logic must be set in advance, not after the fact. BAFA inspectors look for evidence that the methodology was not reverse-engineered to exonerate problematic suppliers. Version control is essential. The auditor calls, the evidence is ready.
CIVAC's workspace lets you configure weighting parameters per category and version every change with a timestamp, reason, and approver. The legacy approach of an annually re-saved Excel file collapses under inspection. Sign the appointment, file it, prove it.
The result of the weighting is a prioritized risk list. The top tier feeds preventive measures under Section 6 LkSG; the lower tiers feed monitoring and supplier development.
Documentation Depth: What BAFA Actually Looks For
BAFA's Handreichung Risikoanalyse lists six documentation expectations. First, scope: which entities and suppliers are covered, with rationale for exclusions. Second, methodology: data sources, scoring, weighting, frequency. Third, results: the prioritized risk list with category-level findings.
Fourth, integration: how the analysis feeds preventive measures and supplier development. Fifth, governance: which role owns the process, how it is reviewed and approved, and how the policy is communicated. Sixth, ad-hoc triggers: when a substantiated complaint or external signal arrives, the analysis is re-run for the affected suppliers within an appropriate timeframe.
Section 10 LkSG requires the annual BAFA report (CSR-RUG-Bericht-Aequivalent), submitted via the BAFA online portal by 1 June of the following year. The report references the risk analysis and shows that preventive measures are linked to identified risks.
Section 11 grants standing to NGOs and trade unions to file complaints on behalf of affected persons. A complaint with substantiated facts triggers Section 9 obligations within reasonable time. The deadline runs from awareness.
CIVAC's LkSG officer-as-a-service handles the report drafting and BAFA submission via the platform. Documented, audit-ready, Section-10-fest.
The most common BAFA finding is a methodology that is not reproducible. Inspectors ask: show me the data source for the country risk score on supplier X as of analysis date Y. If the answer requires a senior analyst to reconstruct it, the documentation depth is insufficient.
The Risk Analysis Template: Structure and Required Fields
A working template has eight blocks. Block 1: Scope definition (entities, supplier universe, exclusions with rationale). Block 2: Methodology statement (data sources, scoring scale, weighting formula, frequency, version, approver).
Block 3: Risk matrix per supplier with the eleven plus three categories on one axis and the scoring fields on the other. Block 4: Aggregated risk list, sorted by weighted score, with cluster definitions (high, medium, low).
Block 5: Linkage to preventive measures under Section 6 LkSG, with action owner, deadline, and verification mechanism. Block 6: Ad-hoc analysis log for complaints and external signals, with date of awareness, scope of re-analysis, and outcome.
Block 7: Approval and review history, with timestamps and accountable persons. Block 8: Communication record showing how the policy and analysis result were communicated internally (Section 6 (2) LkSG) and to affected groups (Section 8 LkSG).
CIVAC ships this template as part of the LkSG workspace module. Configuration time is typically 5 to 10 working days for a midsize enterprise. License the workspace for your internal officers, or have our officers appointed.
The template is only the container. Quality depends on data discipline, accurate supplier master data, and a clear governance loop. The CIVAC SLA covers onboarding in two working days, instead of the classic two to six weeks.
Linking the Analysis to Preventive Measures and Remediation
Sections 6 and 7 LkSG translate the risk analysis into action. Section 6 covers preventive measures: human rights strategy, supplier code of conduct, contractual assurances, training, and ad-hoc complaint handling. Section 7 covers remediation when violations occur or are imminent.
The legal logic is that every identified high or medium risk must have a documented preventive measure. The measure must be reasonable (angemessen), which BAFA interprets as proportionate to severity, probability, and leverage. The reasonableness assessment must be documented.
For direct suppliers in high-risk clusters, typical measures include contractual clauses, supplier code-of-conduct acknowledgement, training, on-site audits, and corrective action plans (CAPs). For the enterprise's own operations, measures focus on policies, training, and grievance mechanisms under Section 8 LkSG.
Section 9 governs indirect suppliers. The threshold is substantiated knowledge, which BAFA defines as factual indications of a potential violation. Once triggered, the enterprise must conduct a risk analysis for the affected indirect supplier, implement appropriate measures, and may need to update its policy.
CIVAC links the risk matrix directly to the preventive measure register and the grievance log via the complaint mechanism under HinSchG, which often serves as the LkSG Section 8 channel.
The integration between analysis, measures, and grievance log is what separates audit-ready compliance from compliance theatre. Filing-cabinet logic does not survive a BAFA inspection.
Annual Cycle and Ad-Hoc Triggers: Operating the Process
The annual cycle should start at least four months before the BAFA report deadline of 1 June. October to January is typical for refreshing country and sector data and re-scoring the supplier universe. February to April covers measure updates and report drafting. May is reserved for board approval and submission.
Ad-hoc triggers cut into the cycle. A whistleblower complaint, an NGO publication, a media report on a supplier, a major incident in a sourcing country, or a contract change with a high-volume supplier can all trigger a re-analysis under Section 5 (4) LkSG.
The trigger criteria must be defined in advance. Otherwise the enterprise has no defensible answer to the BAFA question why a certain signal did or did not trigger re-analysis. CIVAC pre-configures trigger criteria in the workspace and logs every event automatically.
Board engagement is required at least annually. Section 4 (3) LkSG names the management board as the accountable body. The board must approve the policy, the analysis methodology, and the prioritized risk list. Sign the appointment, file it, prove it.
The LkSG officer reports to the board on a defined cadence, typically quarterly. Reports include analysis status, top risks, measure implementation, grievances received, and BAFA correspondence. The officer's appointment letter (Bestellurkunde) is on file.
The auditor calls, the evidence is ready. The deadline runs from awareness. Both phrases describe the same operational discipline that the LkSG process demands year-round, not just before the BAFA submission.
CIVAC: LkSG Compliance Platform and Officer-as-a-Service
CIVAC is a compliance platform and officer-as-a-service for LkSG, data protection, IT security, and 22 other officer roles. For supply chain compliance, that means the risk analysis, supplier register, preventive measure tracker, grievance log, and BAFA report draft live in one workspace.
License the workspace for your internal officers, or have our officers appointed. Both models share the same data structure: 93 controls aligned with ISO/IEC 27001:2022, 490 audit-ready templates, appointment letter, reporting line, EU data residency.
For LkSG specifically, we deliver: pre-configured 14-category risk matrix, country and sector risk data feeds, weighting configurator, ad-hoc trigger workflow, grievance mechanism aligned with HinSchG, supplier code-of-conduct templates, BAFA report draft, and board reporting templates.
The CIVAC SLA is two working days for appointment and onboarding. Classic external officer engagements take two to six weeks. The deadline runs from awareness. Signed appointment, filed, provable.
For enterprises just crossing the 1,000-employee threshold or preparing for CSDDD transposition by 26 July 2026, the recommended starting point is a gap analysis. We map your existing process against Section 5 LkSG and the BAFA Handreichung and deliver a documented gap list with effort estimates.
Turn reading into a project. Email info@civac.de or use the contact form on civac.de. The gap analysis covers methodology, supplier coverage, documentation depth, and reporting templates and forms the baseline for the further build.
FAQ
Which enterprises must conduct an LkSG human rights risk analysis?
Enterprises with 1,000 or more employees in Germany since 1 January 2024 (3,000 or more from 2023). Foreign companies with German branches that meet the threshold are also covered. The risk analysis is mandatory under Section 5 LkSG and runs annually, with ad-hoc re-analysis on substantiated knowledge of violations.
What is the difference between direct and indirect suppliers under LkSG?
Direct suppliers (Tier 1) are contracting partners of your enterprise. Indirect suppliers are everyone further upstream. Direct suppliers are analysed annually. Indirect suppliers fall under Section 9 LkSG and require analysis only when substantiated knowledge of a potential violation arises.
How does the LkSG risk analysis differ from a generic supplier risk assessment?
LkSG focuses on eleven specific human rights categories plus three environmental categories under Section 2 LkSG. Generic supplier risk assessments cover commercial risk, business continuity, or quality. The LkSG analysis is regulated, requires documented methodology, and feeds BAFA reporting under Section 10 LkSG.
What documentation does BAFA expect during an inspection?
BAFA expects a documented scope, methodology with data sources, scoring and weighting logic, prioritized results, linkage to preventive measures, governance approvals, and an ad-hoc trigger log. The Handreichung Risikoanalyse from August 2022 details the depth. Reproducibility of historical scores is essential.
Can I outsource the LkSG risk analysis entirely?
Operational execution can be outsourced to an officer-as-a-service provider like CIVAC. Accountability under Section 4 LkSG remains with the management board. The appointed officer reports to the board and runs the methodology, but the board approves the policy and the prioritized risk list and signs the BAFA report.
How does the LkSG analysis prepare for CSDDD transposition?
The CSDDD (Directive 2024/1760) expands due diligence to the full value chain, lowers thresholds, and introduces civil liability. Member states have until 26 July 2026 to transpose. An LkSG-compliant process is a strong baseline but will need extensions on downstream coverage, climate transition plans, and remediation obligations.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.