LkSG report: Contents, deadlines and auditor-proof documentation for BAFA
The Supply Chain Due Diligence Act requires companies with 1,000 or more employees to report annually to the BAFA. Anyone who documents risk analysis, prevention measures and complaint procedures for auditors can avoid fines of up to 8 million euros.
The Supply Chain Due Diligence Act (LkSG) has required companies to comply with human rights and environmental due diligence obligations since January 1, 2023. Since 2024, companies with 1,000 or more employees have also been included. The core element is the annual LkSG report in accordance with Section 10 LkSG, which must be submitted to the Federal Office of Economics and Export Control (BAFA) no later than four months after the end of the financial year. Fines for intentional or negligent breaches of duty range up to 8 million euros or up to 2 percent of global annual turnover.
This article describes the structure and contents of the LkSG report, places the reporting obligations in the context of CSRD and the expected EU supply chain directive and shows how a supply chain officer carries out the operational verification. The focus is on verifiable documentation, not on rhetorical commitments to sustainability.
Key Takeaways
- The LkSG report must be submitted to BAFA within four months of the end of the financial year and published on the company website.
- The content of the report includes risk analysis, preventative measures, remedial measures, complaint procedures and the annual effectiveness test.
- Fines range up to 8 million euros or 2 percent of global annual turnover; In addition, there is a risk of exclusion from public procurement for up to three years.
Legal basis and scope of application
The LkSG has been in force since January 1, 2023 and has been valid since 2024 for companies with headquarters, headquarters or branches in Germany with 1,000 or more employees. This includes temporary workers who have been employed for more than six months. Companies affiliated with the group are included.
The material scope of obligations includes nine steps of the due diligence obligations in accordance with Section 3 Paragraph 1 LkSG. This includes the establishment of risk management, the definition of responsibility, a risk analysis, a statement of principles, prevention and remedial measures, a complaints procedure, documentation and annual reporting.
The reach differentiates according to the company's own business area, direct suppliers and indirect suppliers. In the latter case, the duty of care only applies when there is substantiated knowledge of a violation. The documentation must clearly reflect this differentiation.
BAFA checks the reports and can request information. Violations of the reporting obligation can result in a fine of up to 50,000 euros, and material violations of obligations of up to 8 million euros or 2 percent of global annual turnover. The clock starts on awareness.
CIVAC provides an orderable role for the supply chain representative. Licence the workspace for your internal representatives, or have our representatives order it. More about the role: Supply Chain Representative.
Structure of the LkSG report according to Section 10 LkSG
The LkSG report cannot be freely designed. BAFA provides a binding report format with around 440 questions, which is submitted online via the BAFA portal. The questions follow the structure of the nine duties of care.
First section: Statement of principles and risk management. This describes how the company formulates its human rights-related principles, who is responsible in the company and how risk management is anchored organizationally.
Second section: Risk analysis. The report describes methodology, data sources, identified risks and prioritization. If there is substantiated knowledge of risks from indirect suppliers, an analysis must also be presented here.
Third section: Prevention measures. Training, contractual agreements, audits, controls and adjustments to purchasing behaviour are described quantitatively and qualitatively.
Fourth section: Remedial measures and complaint procedures. This shows how the company responded to identified violations and how the complaint procedure is structured. The appointment certificate, signed, filed, verifiable. The maxim of auditor-proof documentation also applies here.
Risk analysis at the core of the report
The risk analysis is the central component of the LkSG report. Section 5 LkSG requires both a regular (annual) and an event-related analysis, for example in the case of new business relationships or substantiated knowledge of a violation.
Suppliers are methodically assessed according to risk factors. This includes industry, sourcing region, supplier size, tier level, product type and individual factors such as known incidents. The assessment results in a risk prioritization.
Data sources include internal supplier lists, external risk indices such as the UN Human Development Index, studies by NGOs and regulatory authorities, media reports, audit reports from industry initiatives such as amfori BSCI or SEDEX as well as direct queries with suppliers.
The report must disclose how the methodology was chosen, which risks were identified and how they were prioritised. A mere listing without a comprehensible methodology is not enough and regularly leads to BAFA queries.
An integrated platform significantly reduces the effort. CIVAC bundles risk analysis, supplier audits and action tracking in a platform with 490 audit templates. The Supplier Auditor function systematically supplements the LkSG reporting.
Document prevention and remedial measures
Prevention measures are derived from the risk analysis. Section 6 LkSG names contractual assurances, training, controls and the establishment of implementation mechanisms as examples. The report must quantify which measures have been implemented.
Reliable documentation contains the time of implementation, the responsible area, the affected suppliers or locations and the planned effectiveness test date for each measure. General statements about how we train our suppliers are not enough.
Remedial measures in accordance with Section 7 LkSG are required if violations are identified. The report must show whether violations were identified, what corrective steps were taken, and what effect they had. Here too, specification with dates and responsibilities is mandatory.
A common mistake is mixing preventative and remedial measures. Preventive measures are preventative, remedial measures respond to violations that have already been identified. The report must be clearly separated.
CIVAC lists prevention and remedial measures with the date, person responsible and effectiveness test in the platform. Audit-proof, documented, § 10 LkSG-proof. The supply chain officer can transfer the measures directly from the system to the BAFA report.
Complaint procedure according to Section 8 LkSG
The complaint procedure is an independent group of obligations according to Section 8 LkSG. It must be accessible to whistleblowers from your own business area and the supply chain, ensure confidential processing and guarantee protection against reprisals.
In terms of content, the procedure includes written rules of procedure, an input channel (e-mail, telephone, web form, ombudsperson if necessary), clear processing deadlines, feedback obligations and documentation. The rules of procedure must be published on the company website.
The complaint procedure partially overlaps with the internal reporting office in accordance with the Whistleblower Protection Act (HinSchG). Both can be linked organizationally, but must meet the respective requirements in terms of content.
The LkSG report must state how many reports were received, how they were processed and what measures were taken. A zero report over several years is critically examined by BAFA because it can indicate a lack of awareness or gaps in trust.
CIVAC manages the complaint process with an input channel, processing deadlines and effectiveness checks in the platform. Connection with whistleblower protection and reporting office is standardised. The auditor calls, the evidence is ready.
Deadlines, publication and BAFA submission
The LkSG report must be submitted within four months of the end of the financial year. For a fiscal year that corresponds to the calendar year, the reference date is April 30 of the following year. There is no extension of the deadline.
Submission is made via the BAFA portal in a structured question format. Manual reports or PDF submissions will not be accepted. The portal saves drafts and allows multi-user editing.
In parallel with the BAFA submission, the report must be publicly accessible on the company website free of charge and without registration for at least seven years. The link should be accessible from the main navigation or the footer.
Violations of the reporting obligation can result in fines of up to 50,000 euros in accordance with Section 24 (2) LkSG. In the event of material breaches of duty, fines of up to 8 million euros or 2 percent of global annual turnover are imposed. In addition, there is an exclusion from public procurement for up to three years.
CIVAC reminds the supply chain officer in the platform about deadlines, documentation requirements and updates. Licence the workspace for your internal representatives, or have our representatives order it.
Interlinking with CSRD and EU Supply Chain Directive
The LkSG should not be viewed in isolation. The Corporate Sustainability Reporting Directive (CSRD) and the European Sustainability Reporting Standards (ESRS) also require reporting on human rights in the supply chain. The ESRS S2 is particularly relevant here.
Integrated reporting reduces duplication of work. Data on risk analysis, supplier audits and complaint procedures are required in both reports. Anyone who collects the data once for an auditor can use it for CSRD and LkSG reports in parallel.
The EU Supply Chain Directive (CSDDD, Corporate Sustainability Due Diligence Directive, passed in 2024) will gradually replace national supply chain laws. It initially covers companies with 5,000 employees and a turnover of 1.5 billion euros, and from 2029 also companies with 1,000 employees and a turnover of 450 million euros.
The requirements are sometimes stricter than the LkSG. The CSDDD covers the entire activity chain, not just the direct suppliers, and provides for civil liability.
Anyone who sets up LkSG-compliant reporting today is creating the basis for CSDDD. CIVAC accompanies this transition with audit templates that cover both regimes. Others run compliance like a filing cabinet. We run it like software.
Typical BAFA findings and how to avoid them
BAFA has evaluated several thousand reports since 2024. Typical findings can be derived from the publicly communicated focal points.
First finding: blanket risk analysis without a comprehensible methodology. Reports that do not disclose sources or evaluation models will be returned for improvement.
Second finding: Lack of specification of the prevention measures. Statements such as we carry out training without specifying the target group, frequency and content are criticized.
Third finding: Lack of interlinking between risk analysis and measures. If identified risks are not translated into concrete measures, the duty of care is not fulfilled.
Fourth finding: Weakly developed complaints procedure. A web form without multilingualism, without clear processing deadlines and without protection against reprisals is rated as inadequate.
Fifth finding: Unclear responsibilities. If it is not clear which person or function is responsible for LkSG risk management, questions arise. A written order with tasks and authorities is therefore standard. The appointment certificate, signed, filed, verifiable.
How CIVAC carries out the LkSG report operationally
CIVAC is a German compliance platform and officer-as-a-service. For the LkSG scope of duties, CIVAC provides the supply chain officer as an orderable role as well as the workspace with risk analysis, supplier audits and action tracking.
The platform bundles 490 audit templates, including LkSG-specific templates for risk analysis, supplier questionnaires, training certificates and complaint procedures. Data is collected once and automatically transferred to the BAFA reporting format.
The integration of data protection, information security and ESG is standardised across the reporting line. The supply chain officer works in one platform with the ESG officer, the data protection officer and the compliance officer, without the need for redundant data maintenance.
Licence the workspace for your internal officers, or have our officers appoint them. The decision can be made per role and is reversible.
Turn reading into an assignment. If you have a specific request, write to info@civac.de or use the contact form on civac.de. An initial consultation lasts 30 minutes and clarifies whether workspace, appointed supply chain representative or a combination is suitable.
FAQ
By when does the LkSG report have to be submitted to BAFA?
No later than four months after the end of the financial year. For a calendar year fiscal year, this is April 30 of the following year. Submissions are made exclusively via the BAFA portal in a structured format with around 440 questions. There is no extension of the deadline.
Which companies have been covered by the LkSG since 2024?
Companies with headquarters, headquarters or branch in Germany with 1,000 or more employees. Temporary workers who have been employed for more than six months are included. Companies affiliated with the group are included, which is why smaller subsidiaries can also be included.
What fines are there for violations?
In the event of violations of the reporting obligation, up to 50,000 euros. In the case of material breaches of duty, up to 8 million euros or up to 2 percent of global annual turnover. In addition, there is a risk of exclusion from public procurement for up to three years.
How does the LkSG relate to the EU Supply Chain Directive?
The EU Supply Chain Directive (CSDDD) will gradually replace the LkSG. It initially covers very large companies, and from 2029 also medium-sized companies. The requirements are sometimes more stringent and cover the entire chain of activities plus civil liability.
Does the report have to be published on the website?
Yes, parallel to the BAFA submission. The report must be publicly accessible for at least seven years, free of charge and without registration. A link from the main navigation or the footer is standard and makes it easier for stakeholders to find.
What role does the supply chain representative have in the company?
The supply chain officer is responsible for risk analysis, prevention and remedial measures, complaint procedures, documentation and reporting. The role is expressly provided for in Section 4 Paragraph 3 LkSG and should be accompanied by a written appointment document and a clear reporting line to management.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.