77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
LkSG obligation: scope, duty of care and appointment of the representative
Supply Chain

LkSG obligation: scope, duty of care and appointment of the representative

22 July 202612 min readBy Dr. Henrik Bauer
CIVAC

Since 2024, the LkSG has applied to companies with 1,000 or more employees. We explain the nine due diligence obligations, the BAFA reporting requirement, fines of up to 800,000 euros and how to appoint an LkSG representative via the CIVAC Compliance platform and Officer-as-a-Service.

The Supply Chain Due Diligence Act (LkSG) has been in force since January 1, 2024 for companies with at least 1,000 employees in Germany and, according to BAFA estimates, directly affects around 5,200 companies. The EU Supply Chain Directive 2024/1760 (Corporate Sustainability Due Diligence Directive, CSDDD) expands the scope of obligations from 2027 and gradually lowers the thresholds to 1,000 employees and 450 million euros in sales. Anyone who talks about LkSG obligations today has to think about two sets of rules in parallel: the national law and the EU requirements, which will be incorporated into German law in the next few years via the implementation law. Fines according to Section 24 LkSG range up to 800,000 euros per violation, and for high-turnover companies even up to two percent of the annual turnover.

This article answers the central questions about the LkSG obligation: Who is covered, which nine due diligence obligations apply, how is the annual BAFA reporting set up, what risks exist with indirect suppliers and which ordering route leads more quickly to verifiable supply chain compliance. You will receive specific paragraphs, a catalogue of obligations, the escalation channels in the complaint process and an ordering process that can be completed in two working days via the CIVAC compliance platform and Officer-as-a-Service. Audit-proof, documented, § 6-proof, with version status and person responsible for each measure. The report must be sent to BAFA and made available on its own website for at least seven years.

Key Takeaways

  • The LkSG has been in effect for companies with 1,000 or more employees since 2024 and, according to BAFA data, directly covers around 5,200 companies.
  • Nine due diligence obligations according to Sections 3 to 10 LkSG are mandatory, from the risk analysis to the annual BAFA report.
  • The LkSG officer is appointed via the CIVAC Compliance platform and Officer-as-a-Service in 2 working days, instead of the traditional 2 to 6 weeks.

Scope: who falls under the LkSG

According to Section 1 Paragraph 1, the LkSG covers companies with headquarters, headquarters or registered office in Germany and at least 1,000 employees. Foreign companies are recorded through domestic branches if they have 1,000 employees. The threshold applies regardless of sales and regardless of the industry. Within the group, employees of subsidiaries are attributed to the parent company in accordance with Section 1 Paragraph 3 LkSG if the parent company actually exercises controlling influence. This means that a group can be covered even if no individual company reaches the threshold.

Medium-sized suppliers below the threshold are not formally themselves subject to the LkSG, but are in fact integrated into the chain of care via the obligations of their major customers. Anyone who falls into the supply chain of a company subject to the LkSG as a supplier must fill out questionnaires, allow audits and answer risks at their own sub-suppliers. In practice, a cascade effect is created that reaches the entire German medium-sized business environment.

The EU Supply Chain Directive 2024/1760 gradually lowers the thresholds from 2027: initially companies with over 5,000 employees and 1.5 billion euros in sales, from 2028 with 3,000 employees and 900 million euros in sales, from 2029 with 1,000 employees and 450 million euros. Euro turnover. This means that the circle of direct recipients is expanding considerably. Anyone who is now compliant with the LkSG has already created most of the basic building blocks for the CSDDD. The CIVAC Compliance Platform and Officer-as-a-Service supports both duty frameworks in a unified workspace with a common risk and measures architecture, so that duplication of work is avoided in the transition from LkSG to CSDDD. Two thirds of the companies surveyed are medium-sized companies from mechanical engineering, automotive, retail and consumer goods, i.e. industries with dense international supply chains.

The nine duties of care according to Sections 3 to 10 LkSG

The law lists nine specific duties of care in Section 3 LkSG, which are set out in the following paragraphs. Firstly, the risk management system according to Section 4 LkSG with clearly assigned responsibilities. Secondly, the designation of an operational responsibility in accordance with Section 4 Paragraph 3 LkSG, usually a human rights officer or LkSG representative who reports directly to the management. Thirdly, the regular risk analysis in accordance with Section 5 LkSG for your own business area and direct suppliers, and, if necessary, also for indirect suppliers. Fourthly, the management's declaration of principles in accordance with Section 6 Paragraph 2 LkSG on the human rights strategy.

Fifth, the anchoring of prevention measures in accordance with Section 6 Paragraphs 3 to 4 LkSG in the company's own business area and towards suppliers, including contractual assurances and training. Sixth, taking remedial action in accordance with Section 7 LkSG if a violation is identified, with clearly defined escalation levels. Seventh, the establishment of a complaints procedure in accordance with Section 8 LkSG, which is accessible to reports from home and abroad and meets the requirements for confidentiality, independence and effectiveness.

Eighth, the documentation of all measures in accordance with Section 10 Paragraph 1 LkSG must be retained for at least seven years. Ninth, the annual reporting to BAFA in accordance with Section 10 Paragraph 2 LkSG, no later than four months after the end of the financial year. The requirements for form and content are specified in the BAFA questionnaire and in the LkSG reporting requirement appendix. Via the CIVAC role page LkSG representative you will receive the catalogue of duties as a versioned document that can be transferred directly to the workspace. The appointment certificate, signed, filed, verifiable. Anyone who implements a single component incompletely weakens the ability of the entire chain to defend itself against BAFA.

Risk analysis: what Section 5 LkSG specifically requires

Risk analysis is the core of the LkSG obligations. According to Section 5 Paragraph 1 LkSG, it must be carried out once a year and on an ad hoc basis if the supplier structure, business model or risk situation changes substantially. The subject is human rights and environmental risks listed in Section 2 LkSG: child labour, forced labour, slavery, disregard for occupational safety, withholding of appropriate wages, violation of freedom of assembly, discrimination as well as specific environmental risks such as use of mercury according to the Minamata Convention or POPs according to the Stockholm Convention.

Methodologically, the risk analysis is typically carried out in four steps. Firstly, the inventory of the supply chains: supplier list, country allocation, product groups, order volume. Secondly, the risk indicators per country and product group, based on sources such as ILO data, Global Slavery Index, Corruption Perceptions Index or ITUC Global Rights Index. Thirdly, the assessment of the probability of occurrence and the amount of damage in a matrix, supplemented by the ability to influence it by your own company. Fourth, the derivation of prevention and remedial measures with a deadline and responsible person.

In practice, many risk analyses fail due to the data quality in the supply chain. If you do not maintain a complete supplier list, you cannot carry out a reliable risk analysis. The CIVAC Compliance Platform and Officer-as-a-Service structures the database in the workspace, integrates external risk indicators and creates a reporting-ready matrix with a source reference for each risk. Others run compliance like a filing cabinet. We run it like software. This also allows event-related updates to be clearly documented, for example after media reports about a specific supplier. The annual and event-related updates are planned on a calendar basis so that the reporting and audit rhythm remains consistent. Audit reports from individual suppliers can also be linked in the workspace so that the data chain between risk, measure and effect remains unbroken.

Complaint procedure according to Section 8 LkSG and interface to the HinSchG

The complaint procedure according to Section 8 LkSG is an independent obligation that should not be confused with the internal reporting office according to the Whistleblower Protection Act (HinSchG), even if synergies are possible. According to Section 8 Para. 1 LkSG, the LkSG complaint procedure must be accessible to information from domestic and foreign countries, communicated in appropriate language and be open to both our own employees and external persons such as suppliers and affected communities. The rules of procedure must be published, typically in several languages ​​depending on the supply chain geography.

The requirements for confidentiality, independence and effectiveness are specified in Section 8 Paragraph 3 LkSG. The complainant must be protected from discrimination, the process must be transparent and predictable, and processing must take place within a reasonable period of time. The parallel requirements of the HinSchG, such as the seven-day confirmation of receipt according to § 13 HinSchG and the three-month feedback according to § 17 HinSchG, should be applied consistently, even if LkSG does not specify any fixed deadlines.

An integrated solution with a common input channel, separate processing paths and a common reporting structure is efficient, but must be clearly documented. The personal union between the LkSG representative and the internal reporting office according to the HinSchG is possible, but requires a clear demarcation of functions in the appointment document and separate file management. The interfaces between HinSchG, LkSG and CMS Compliance are documented on the role page for the internal reporting office, so that the configuration of the complaint system can be reduced to a single process. This means that the access path for affected people in the supply chain can be maintained via a common portal without losing the functional demarcation. The obligation to regularly check the effectiveness of the procedure, at least once a year, is anchored in Section 8 Paragraph 5 LkSG.

BAFA report: list of questions, deadline, publication requirement

According to Section 10 Paragraph 2 LkSG, the report on the fulfilment of due diligence obligations must be submitted to BAFA no later than four months after the end of the financial year and must be kept accessible on the company's website free of charge and for at least seven years. BAFA provides a binding questionnaire with around 437 questions, which is filled out via BAFA's digital reporting portal. The report must identify the most important risks, present the preventive and remedial measures taken, evaluate the effectiveness of the measures and derive conclusions for the coming financial year.

BAFA practice has become significantly more concrete in the first two reporting years. Standardized answers without specific reference to your own supply chain are rejected. A lack of effectiveness assessments also leads to questions, which BAFA associates with short response times. The report must be consistent with documented internal measures because BAFA can carry out spot checks on the files. According to Section 24 Paragraph 2 No. 8 LkSG, violations of the reporting obligation can be punished with fines of up to 100,000 euros, and significantly higher for intentional false reporting.

In the CIVAC Workspace, BAFA reports are created as a versioned document, with direct reference to the stored risk analyses, measures and effectiveness controls. The auditor calls, the evidence is ready. The 490 audit templates include, among others, the policy statement, the risk analysis protocol, the complaints procedure and the effectiveness assessment report. This means that the BAFA report is not an annual special task, but rather the automated result of ongoing supply chain compliance operations. The deadline runs from the end of the financial year; the files must be complete beforehand. Anyone who creates the report from the ongoing processes avoids inconsistencies with the management report and CSRD declaration.

Sanctions and fines according to Section 24 LkSG

The sanctions are regulated in Section 24 LkSG. In the event of intentional or negligent violation of essential obligations, a fine of up to 800,000 euros per violation may be imposed. For companies with an average annual turnover of more than 400 million euros, an increase comes into force according to Section 24 Paragraph 3 LkSG: The fine can be up to two percent of the average annual turnover. Companies with high sales can face fines in the double-digit million range. In addition, there are possible civil law consequences and an exclusion from public contracts according to Section 22 LkSG for up to three years.

The second layer of sanctions is the exclusion from the award of public contracts according to Section 22 LkSG. In the case of legally established violations with a fine of 175,000 euros or more, public clients can exclude the company from procurement procedures for up to three years. For companies that are highly dependent on public contracts, such as the construction industry, IT service providers or consulting firms, this sanction is often harsher than the fine itself because it permanently impairs market access.

Thirdly, reputational risks arise from the publication obligation and the press work of NGOs that actively monitor the BAFA reporting portal. Poor reporting quality is now systematically evaluated and integrated into sustainable finance ratings, which can have an impact on financing conditions. The CIVAC compliance platform reduces this risk because the reports are generated from documented processes and are therefore consistent, complete and plausible. Audit-proof, documented, Section 24-proof. According to Section 17 OWiG, an early, documented voluntary disclosure of one's own failures can have a mitigating effect on punishment and reduce reputational damage. The possibility of a temporary exclusion from awarding a contract also makes early clarification of internal issues an operational necessity.

Interfaces to compliance, ESG, data protection and purchasing

The LkSG representative does not work in isolation, but rather on at least four interfaces. Firstly, the compliance officer: sanctions checks, corruption prevention and due diligence obligations overlap, which is why common risk registers and action plans make sense. Secondly, the ESG/sustainability officer: The ESRS standards of the CSRD require information on the value chain, which must be congruent with the LkSG data, otherwise contradictions arise between the management report and the BAFA report.

Thirdly, the data protection officer: Supplier data often contains personal information, such as contact persons or audit participants in the supply chain. International data flows, for example in third countries without an adequacy decision according to Art. 45 GDPR, must be secured via standard contractual clauses according to Art. 46 GDPR. Data processing in the complaint procedure must be additionally regulated in special categories in accordance with Art. 9 GDPR.

Fourth, purchasing: This is where most of the LkSG-relevant contractual clauses arise, from due diligence conditions to audit rights to escalation and termination clauses. The supplier classification according to risk must be integrated into the ordering process, otherwise the LkSG function remains an appendage. The CIVAC compliance platform manages the interfaces via common registers and ensures consistency between representatives because 25 representative roles are mapped in one workspace. Licence the workspace for your internal representatives or have our representatives order it. Both models use the same data. In addition, there is an interface to the data protection officer for international supplier data and to law and sales for audit clauses and termination mechanisms. An integrated risk matrix across all four interfaces is the operational basis for a consistent due diligence strategy. The CIVAC reporting line brings together the findings of all representatives in a consolidated quarterly report, which is used by the board for control purposes. This turns the LkSG function from a duty element into a control element and creates the prerequisites for the later CSDDD implementation with an expanded range of duties.

CSDDD transition: what will change from 2027

The EU Supply Chain Directive 2024/1760 (Corporate Sustainability Due Diligence Directive, CSDDD) will gradually supersede the LkSG from 2027 and incorporate it into German law. The main changes are, firstly, the lowering of the thresholds to 1,000 employees and 450 million euros in sales, secondly, the extension of due diligence to the entire value chain, not just direct suppliers, thirdly, civil liability according to Art. 29 CSDDD for damages resulting from insufficient care and fourthly, the obligation to draw up and implement a climate transition plan according to Art. 22 CSDDD in accordance with the 1.5 degree target.

The grading is based on company size. Level 1 from 2027: Companies with over 5,000 employees and 1.5 billion euros in sales. Stage 2 from 2028: over 3,000 employees and 900 million euros in sales. Stage 3 from 2029: over 1,000 employees and 450 million euros in sales. This means that the direct group of addressees is expanding significantly, and medium-sized companies that were previously only covered indirectly via supply chains become direct addressees.

Anyone who is now compliant with the LkSG has the basic building blocks for the CSDDD, but must cover the value chain beyond direct suppliers and integrate a climate transition plan. Interlinking with CSRD and ESRS E1 is therefore mandatory, not an option. The CIVAC Compliance Platform supports the transition in a shared workspace, with EU data residency and ISO/IEC 27001:2022 ISMS in the background. Existing risk analyses and supplier data are mapped to the CSDDD logic without having to re-capture master data. Early preparation in the years before your own validity level avoids pressure situations and enables an orderly transition. The national implementation of the CSDDD will expand and partially replace the LkSG, with transitional regulations that should be planned on a calendar basis.

From obligation to order: the route via CIVAC

If you fall under the LkSG or are involved as a supplier in a supply chain subject to the LkSG, the appointment of an LkSG representative is the operational lever. CIVAC is a compliance platform and officer-as-a-service with two reference models. In the first model, you licence the workspace for your internal representative and use the 490 audit templates, the risk analysis modules, the complaint procedure and the BAFA report export. In the second model, our representatives order your LkSG function and work in the workspace, which your management can view at any time. Licence the workspace for your internal representatives or have our representatives order it.

The SLA for an order is 2 working days, instead of the classic 2 to 6 weeks. You receive the appointment certificate, reporting line and catalogue of tasks in one process, EU data residency and ISO/IEC 27001:2022 ISMS with 93 controls active. The onboarding includes an initial supplier risk matrix, the policy statement template and a configured complaint procedure in at least two languages, so that the function reaches a measurable level from the first month and is prepared for the next BAFA report.

If you would like to specifically check whether your company falls under the LkSG, which due diligence obligations need to be prioritised and which procurement model is economically suitable, write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment within 24 hours with a scope check, ordering method and cost framework. Turn reading into an assignment. A training module for purchasing and sales is also included in the onboarding, because this is where most of the LkSG-relevant contractual clauses arise. This means that the function can be audited from the first month and is seamlessly integrated into the CSRD reporting.

FAQ

At what size does the LkSG apply to my company?

The LkSG has been in effect since January 1, 2024 for companies with headquarters, headquarters or registered office in Germany and at least 1,000 employees. Within the group, employees of subsidiaries are attributed to the parent company if the parent company actually exercises controlling influence. Foreign companies with German branches with 1,000 or more employees are also included. Even suppliers without their own LkSG obligations are actually integrated into the supply chain through the care of their major customers.

Which duties of care specifically apply according to the LkSG?

Sections 3 to 10 LkSG name nine obligations: risk management system, operational responsibility, annual risk analysis, policy statement, prevention and remedial measures, complaint procedure, documentation for seven years and annual BAFA report. The obligations apply to your own business area and direct suppliers, and, if necessary, also to indirect suppliers in the value chain. The documentation period is at least seven years, and the report must be publicly available at the same time.

When does the BAFA report have to be submitted?

According to Section 10 Paragraph 2 LkSG, the LkSG report must be submitted to BAFA no later than four months after the end of the financial year and at the same time be kept accessible free of charge on the company website for at least seven years. The BAFA provides a questionnaire with around 437 questions via the digital reporting portal, which must be answered precisely and with specific reference to the supply chain.

What fines are there for LkSG violations?

According to Section 24 LkSG, intentional or negligent breaches of duty can result in fines of up to 800,000 euros per violation. An increase comes into force for companies with an annual turnover of over 400 million euros: up to two percent of the average annual turnover. In addition, according to Section 22 LkSG, there is an exclusion from public contracts for up to three years with fines of 175,000 euros or more.

Can the LkSG representative also be an external person?

Yes, external appointment is permitted according to Section 4 Paragraph 3 LkSG and is particularly useful for medium-sized companies that do not set up their own human rights department. Via the CIVAC Compliance platform and Officer-as-a-Service, the order is placed in 2 working days with an appointment certificate, reporting line and catalogue of tasks, including onboarding risk analysis for the main delivery countries. A personal union with a compliance officer or an internal reporting office is also possible if the functions are clearly defined.

How will the EU-CSDDD affect existing LkSG structures from 2027?

The CSDDD Directive 2024/1760 gradually lowers the thresholds from 2027 and extends due diligence to the entire value chain with civil liability and a climate transition plan in accordance with Article 22 CSDDD. Anyone who is compliant with the LkSG today has the basic building blocks, but must expand the depth and scope of their due diligence obligations and establish integration with the CSRD. Existing workspaces can be mapped to the CSDDD logic without having to re-enter master data.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles