77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
LkSG with 1,000 employees or more: Catalog of duties 2024 and transition to CSDDD
Supply Chain

LkSG with 1,000 employees or more: Catalog of duties 2024 and transition to CSDDD

8 September 202613 min readBy Dr. Henrik Bauer
CIVAC

Since January 1, 2024, the Supply Chain Due Diligence Act has also applied to companies with 1,000 or more employees. This article lists the eleven obligations according to Section 3 LkSG, the reporting deadlines and the transition to the EU Supply Chain Directive 2027.

Since January 1, 2024, the Supply Chain Due Diligence Act (LkSG) according to Section 1 Paragraph 1 Number 2 also applies to companies with at least 1,000 employees employed in Germany. This means that the scope of application has expanded from around 700 companies (threshold 3,000) to almost 2,900 companies. Violations are punished by the Federal Office of Economics and Export Control (BAFA) with fines of up to 8 million euros or 2 percent of the annual turnover.

The eleven due diligence obligations according to Section 3 LkSG are not just a reporting obligation. They require an operational structure consisting of a declaration of principles, risk analysis, preventative measures, complaint procedures and annual BAFA reporting. This article provides a structured overview and shows how the implementation remains compatible until the transition to the EU CSDDD from July 2027.

Key Takeaways

  • Since January 1, 2024, the LkSG has applied to companies with at least 1,000 domestic employees; The obligation to report to BAFA applies no later than four months after the end of the financial year.
  • The eleven duties of care according to Section 3 LkSG primarily require operational structures: risk analysis, complaint procedures, preventive and remedial measures, documented processes.
  • From July 2027, the EU Supply Chain Directive CSDDD will gradually replace the LkSG; Anyone who is LkSG compliant has a substantial lead time for implementing the stricter EU requirements.

Which companies have been subject to the LkSG since 2024

According to Section 1 Paragraph 1 LkSG, a company falls under the law if it employs at least 1,000 employees in Germany. The counting takes place at the head office, branch or headquarters level and includes temporary workers if their duration of employment exceeds six months. Subsidiaries belonging to the group are considered separately if they are not centrally controlled.

The employee threshold is checked based on January 1st of the reporting year. Foreign employees do not count, but employees of foreign group companies deployed domestically do. The threshold is absolute; there is no tolerance rule. Anyone who has 999 domestic employees on the deadline is not subject to the law; anyone who has 1,000 is fully affected.

The BAFA list of companies subject to the LkSG is not kept publicly. The company is responsible for correctly classifying itself. Incorrect classification can later be punished as a violation according to Section 24 LkSG, with fines of up to 8 million euros or 2 percent of the annual turnover.

With the expansion of the scope of application in 2024, around 2,200 more companies have been added, many of them medium-sized. These companies had to establish full LkSG compliance within twelve months, from the policy statement to the risk analysis to the BAFA report.

A structured overview of the LkSG role and the operational tasks of the human rights officer can be found on the CIVAC role page of the supply chain officer. The appointment of this function is mandatory according to Section 4 Paragraph 3 LkSG.

The eleven duties of care according to Section 3 LkSG at a glance

§ 3 Paragraph 1 LkSG lists the due diligence obligations in eleven numbers. First: Establishment of risk management (§ 4). Second: Determination of internal responsibility (Section 4 Paragraph 3, Appointment of a Human Rights Officer). Third: Carrying out regular risk analyses (§ 5).

Fourth: Submitting a policy statement (§ 6). Fifth: anchoring prevention measures in your own business area and towards direct suppliers (Section 6 paragraphs 3 and 4). Sixth: Taking remedial measures (Section 7). Seventh: Establishment of a complaints procedure (§ 8).

Eighth: Implementation of due diligence obligations with regard to risks for indirect suppliers (§ 9). Ninth: Documentation and reporting (§ 10). Tenth: annual effectiveness review. Eleventh: Update in the event of significant changes in the risk situation.

The obligations generally relate to the company's own business area and direct suppliers (Tier 1). For indirect suppliers (Tier 2 and beyond), the obligations only apply if there is substantiated knowledge of specific violations. The interpretation of this threshold has been further specified in BAFA's supervisory practice.

Four central artifacts result from the eleven obligations: policy statement, risk analysis report, complaint procedure description and annual BAFA report. These four documents are the minimum set that every company subject to LkSG must maintain in a verifiable manner. Audit-proof, documented, § 3-firm.

Risk analysis: methodology and scope

The risk analysis according to Section 5 LkSG is the operational heart. It includes the systematic identification and assessment of human rights and environmental risks in our own business area and among direct suppliers. The analysis is carried out at least annually and when there are significant changes.

Methodologically, BAFA requires a risk-based approach that combines industry-specific risks, country-specific risks and product-specific risks. Industry-specific risks are recorded via lists such as the OECD Due Diligence Guidance, country-specific risks via indices such as the Children's Rights and Business Atlas or the Global Slavery Index.

Reach: The analysis must cover all direct suppliers who work for the company, regardless of sales share or order volume. For very large supplier inventories, stratification is possible, which analyses high-priority suppliers completely and less critical suppliers in samples. The stratification logic itself must be documented.

The twelve LkSG risks from § 2 paragraphs 2 and 3 include child labour, forced labour, slavery, disregard for occupational safety, violation of freedom of association, discrimination, non-payment of wages, other labour rights as well as environmental risks according to the Minamata, Stockholm and Basel Conventions.

The risk analysis is stored as an audit template in the CIVAC Workspace: supplier master, Risk matrix, evaluation grid, escalation and measures catalogue. The supplier audit workflow connects risk analysis directly with the supplier auditor role and closes the loop on operational supply chain control.

Complaint procedure according to Section 8 LkSG

§ 8 LkSG requires you to set up a complaints procedure that both your own employees and people along the supply chain can use. The process must be accessible, confidential, impartial and non-reprisal. A mere email address or an internal telephone does not meet these requirements.

The minimum requirements include: written rules of procedure, clearly named responsible parties, confidentiality assurance, confirmation of receipt within seven days, regular status information, documented processing and protection against reprisals. The rules of procedure must be publicly available.

Languages: The complaints procedure must be available in the languages ​​spoken in the relevant supply chain. For companies with suppliers in Bangladesh, Vietnam or Mexico, this also means Bangla, Vietnamese and Spanish. A purely German or English speaking hotline is not enough.

There are overlaps with the Whistleblower Protection Act (HinSchG). Anyone who already runs an internal reporting office according to the HinSchG can expand it to include LkSG-relevant topics. But be careful: HinSchG reporting points are primarily for your own employees. The LkSG complaint procedure must also be explicitly accessible to external persons.

The complaint procedure is stored in the workspace as a combined audit template with the HinSchG reporting office. Confirmations of receipt, status information and processing documentation run via the same platform. The auditor calls, the evidence is ready. The reporting line to management is built in.

The BAFA report: contents, deadline, common errors

§ 10 paragraph 2 LkSG requires annual reporting to BAFA. The deadline is four months after the end of the financial year. For the 2024 financial year, the report had to be submitted by April 30, 2025 at the latest, provided that the financial year corresponds to the calendar year.

The report is carried out via the BAFA report questionnaire portal and includes seven mandatory fields: description of risk management, results of the risk analysis, preventative measures taken, remedial measures taken, complaint procedures, due diligence obligations for indirect suppliers, assessment of effectiveness.

Common errors: First, superficial ones Risk analysis description without specific supplier categories. Second, generic prevention measures unrelated to the identified risks. Thirdly, missing statistics on the complaint process (number of receipts, number processed, number with measures). Fourth, no documented effectiveness test.

The BAFA checks the reports on a random basis and subsequently. Defects identified will initially be subject to conditions, and if they repeat, fines will be imposed. In 2024, BAFA opened 38 formal investigation procedures and is expected to open more than 100 in 2025. The intensity of supervision increases with the expanded scope of application.

The first report is usually the most difficult. Experienced external supply chain representatives reduce the preparation time from 8 to 12 weeks to 3 to 5 weeks because the content structure, evaluation standards and typical BAFA expectations are known.

Sanctions, fines and civil consequences

§ 24 LkSG provides for fines of up to 8 million euros or 2 percent of the average annual turnover of the last three financial years, whichever is higher. The fines can cover intentional and negligent violations. For corporations, the consolidated group sales are used.

In addition, according to Section 22 LkSG, the BAFA can impose an exclusion from the award of public contracts for up to three years. This sanction is particularly drastic for companies with public clients such as Bavaria, the Bundeswehr, the railways or municipal authorities, often more severe than the fine itself.

In civil law, the LkSG expressly does not establish its own basis for claims for those affected (Section 3 Paragraph 3 Sentence 1 LkSG). However, the possibility of special legal status under Section 11 LkSG allows NGOs and unions to bring lawsuits against German companies on behalf of those affected, which was used in two well-known cases in 2024.

Reputational risks should not be underestimated. The BAFA publishes fine decisions based on their validity. Negative headlines impact customer relationships, insurance premiums and ESG ratings. Anyone who has an open fine procedure is put on red lists by many institutional investors.

The deadline expires as soon as we become aware of it. Anyone who does not respond substantively to a BAFA inquiry within the set deadline (typically four weeks) risks escalation into the formal fine procedure. External support for BAFA communication noticeably reduces this risk.

Establishing LkSG compliance in 90 days

Companies that have been subject to the LkSG for the first time since January 1, 2024 and have not yet established full compliance should follow a structured 90-day plan. Days 1 to 14: Appointment of a human rights officer in accordance with Section 4 Paragraph 3, reporting line to management, adopting a declaration of principles.

Days 15 to 45: Risk analysis in your own business area and with direct suppliers. Consolidate supplier base, build risk matrix, analyse top 30 percent suppliers in depth. Integrate industry and country risks from official sources. Document the methodology in writing.

Day 46 to 70: Set up a complaint procedure or expand the existing HinSchG procedure, adopt rules of procedure, check multilingualism, implement technical platform. Plan preventative measures for identified risks, add LkSG clauses to contracts with critical suppliers.

Day 71 to 90: Implement effectiveness testing routine, conduct training for purchasing, contract management and compliance, structure preparation of the first BAFA report. Carry out internal audits of the LkSG processes, document findings, initiate measures.

CIVAC is a compliance platform and officer-as-a-service. Licence the workspace for your internal representatives, or have our representatives order it. Both models implement a 90-day plan in a structured manner, with all the templates, reporting lines and audit trails of an ISO/IEC 27001:2022 certified system.

Transition to the EU CSDDD from 2027

The EU Supply Chain Directive (Corporate Sustainability Due Diligence Directive, CSDDD) was passed on June 13, 2024 and will come into force in member states on a phased basis. For very large companies with 5,000 employees and 1.5 billion euros in sales, it applies from July 2027, for companies with 3,000 employees and 900 million euros from July 2028, and with 1,000 employees and 450 million euros from July 2029.

The CSDDD tightens the LkSG in several points: It extends to the entire value chain (not just Tier 1 plus substantiated ones knowledge), introduces civil liability for those affected, requires a climate plan in line with the 1.5 degree target and sets stricter sanctions standards.

The implementation into national German law is expected to take place in an amendment to the LkSG, with application starting in July 2027 at the earliest for the largest companies. During the transition period, the existing LkSG will continue to apply, with announced tightening of BAFA's supervisory behaviour.

Anyone who has robustly established LkSG compliance today meets around 70 percent of the CSDDD requirements. The additional 30 percent primarily relates to the expanded reach across the entire value chain, the climate plan and civil actionability. These elements can be prepared from 2025.

The CSDDD mapping is already stored in the workspace. For each LkSG obligation, it is documented which additional CSDDD requirements must be covered, with a lead indicator per quarter. This means that the compliance investment today remains valuable for the 2027 transition.

Implementing LkSG in a structured way: two ways at CIVAC

LkSG is not a paper act, but an operational discipline. Risk analysis, complaint procedures and BAFA reporting require continuous maintenance, clear reporting lines and reliable documentation. Anyone who manages compliance on the side will fail at the first BAFA review process or an NGO inquiry.

CIVAC is a compliance platform and officer-as-a-service with two clearly separated models. Licence the workspace for your internal representatives, or have our representatives order it. Both ways provide the full LkSG structure: declaration of principles, risk analysis templates, complaint procedure, BAFA reporting structure, effectiveness test.

Model one, workspace licence: Your own human rights officer and purchasing use the platform for supplier master data, risk matrix, assessment, catalogue of measures and BAFA report draft. The EU data residency protects confidential supplier data in the ISO 27001:2022-certified ISMS.

Model two, officer-as-a-service: CIVAC appoints an external supply chain officer who is responsible for LkSG compliance end-to-end. Appointment certificate within two working days, risk analysis methodology drawn up in four weeks, first BAFA report submitted in a coordinated manner.

Both models simultaneously prepare for the CSDDD transition from 2027. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de for a structured initial discussion about LkSG compliance.

FAQ

From what number of employees will the LkSG apply since 2024?

Since January 1, 2024, the LkSG has applied to companies with at least 1,000 employees employed in Germany (Section 1 Paragraph 1 Number 2 LkSG). The reference date is January 1st of the reporting year. Temporary workers with a duration of more than six months count, foreign employees do not.

What fines are there for violations of the LkSG?

According to Section 24 LkSG, up to 8 million euros or 2 percent of the average annual turnover of the last three financial years, whichever is higher. In addition, an exclusion from public procurement can be imposed for up to three years, which is often economically more serious.

When does the annual BAFA report have to be submitted?

Section 10 paragraph 2 LkSG requires submission no later than four months after the end of the financial year. In the case of a calendar year-fiscal year, the reference date is April 30 of the following year. The report is carried out via the BAFA portal and includes seven mandatory fields on risk analysis, measures, complaint procedures and effectiveness testing.

Do I have to appoint a human rights representative?

Yes. Section 4 paragraph 3 LkSG requires the establishment of internal responsibility for monitoring risk management. A human rights officer or supply chain officer is usually appointed. The role can be filled internally or outsourced as officer-as-a-service, both ways are legally permissible.

How many suppliers must the risk analysis include?

All direct suppliers, regardless of their share of sales. For very large supplier inventories, stratification is permitted: analyse top risks in depth, smaller risks on a random basis. The stratification methodology must be justified in writing and comprehensible by BAFA, otherwise there is a risk of objections in the testing process.

How does the EU-CSDDD change the LkSG requirements?

The CSDDD will gradually tighten the LkSG from July 2027: coverage of the entire value chain instead of just Tier 1, civil liability towards those affected, obligation to have a climate plan in line with the 1.5 degree target. Anyone who reliably fulfils LkSG today has already covered around 70 percent of the CSDDD requirements.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles