77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Prevention measures LkSG in your own business area: practical list of obligations
Supply Chain

Prevention measures LkSG in your own business area: practical list of obligations

7 September 202612 min readBy Dr. Henrik Bauer
CIVAC

According to Section 6, the LkSG requires preventive measures first in your own business area. This article shows which measures BAFA examines, how you document them and which structures CIVAC provides for this.

Section 6 paragraph 1 of the Supply Chain Due Diligence Act (LkSG) obliges companies to anchor appropriate preventive measures in their own business area as soon as the risk analysis according to Section 5 LkSG reveals a human rights or environmental risk. The Federal Office of Economics and Export Control (BAFA) has been examining implementation for all German companies with 1,000 or more employees since January 1, 2024. Fines range up to 8 million euros or 2% of global group sales, whichever is higher.

The obligation to prevent is graduated: first the company's own company, then direct suppliers, and, if necessary, also indirect suppliers. This article focuses on the first stage and describes the five mandatory measures according to Section 6 Paragraph 3 LkSG as well as the documentation logic that BAFA expects in the report review. CIVAC is the compliance platform and officer-as-a-service that carries this record keeping in practice.

Key Takeaways

  • Section 6 Paragraph 3 LkSG lists five concrete prevention measures in your own business area: declaration of principles, implementation of procedures, procurement practices, training and control mechanisms.
  • The effectiveness of the measures must be checked annually and as needed; the documentation must be kept for seven years according to Section 10 LkSG.
  • An audit-proof LkSG structure combines the appointment document of the human rights officer, reporting line to management and audit-proof audit trail, as provided by the CIVAC Workspace.

What Section 6 LkSG requires exactly

§ 6 LkSG is entitled Prevention measures and distinguishes between three target groups: the company's own business area (para. 3), direct suppliers (para. 4) and indirect suppliers within the framework of substantiated knowledge (para. 5 in conjunction with § 9). For the first stage, the law names five concrete measures that, according to BAFA's interpretation, must be implemented cumulatively as soon as the risk analysis provides a result.

Firstly, the anchoring in the relevant business processes, i.e. the operational translation of the declaration of principles according to Section 6 Paragraph 2 into processes, work instructions and contractual clauses. Secondly, the development and implementation of suitable procurement strategies that minimise human rights and environmental risks, for example through supplier selection and contract design.

Thirdly, the implementation of training courses in the relevant business areas. Fourth, the implementation of risk-based control measures to verify compliance with the policy statement. Fifth, the establishment of an effective complaints procedure in accordance with Section 8 LkSG, the availability of which is made known to our own employees and external parties.

All five points are not optional. BAFA requires concrete evidence for each of these measures, including effectiveness assessment, in the annual LkSG report (Section 10 Paragraph 2). A mere declaration of intent without demonstrable implementation is not enough.

The LkSG representative is, according to Section 4 Paragraph 3 LkSG, a central figure whose appointment must be documented in writing. Licence the workspace for your internal representatives, or have our representatives order it.

Declaration of principles: the foundation of every prevention structure

The declaration of principles according to Section 6 Paragraph 2 LkSG is the formal basis for all prevention measures. It must be approved by the company management and contains three mandatory elements: the procedure for implementing due diligence, the risks from the risk analysis and the human rights and environmental-related expectations of employees and suppliers.

In terms of content, BAFA expects reference to the eleven internationally recognised conventions in accordance with the appendix to Section 2 Paragraph 1 LkSG, including the ILO core labour standards, the UN covenants on civil, political, economic, social and cultural rights as well as the Minamata Convention on Mercury. A mere reference statement without reference to the specific risks in your own company is not enough.

The policy statement must be actively communicated, internally and externally. Common channels include the intranet, onboarding documents, employee handbook, code of conduct and the public website. Publication itself is not mandatory, but is practically the only way to make the process transparent to external stakeholders.

The appointment certificate, signed, filed, verifiable. BAFA expects exactly this depth of evidence when reviewing the report. The policy statement belongs in the CIVAC Workspace with version number, release date and management signature, visible to every authorised representative and auditor.

In practical use, the policy statement is not a defence document, but rather a work instruction. Anyone who formulates it as a marketing brochure will fail the effectiveness test.

Anchoring in business processes and procurement

The second and third mandatory measures according to Section 6 Paragraph 3 Nos. 1 and 2 LkSG require that the declaration of principles is implemented in operational processes. Specifically, this means: HR processes, purchasing, sales, production and compliance must adapt their own procedures so that human rights and environmental risks are systematically taken into account.

In procurement, this translates into supplier selection criteria, contractual clauses and audit rights. Model contract clauses should contain obligations to comply with the LkSG protected goods, audit rights for the contracting group and termination clauses in the event of proven violations. The BAFA accepts industry standards such as the DICO model contract or the ICC clauses.

In HR and compliance, the anchoring is more subtle: job advertisements without discriminatory wording, onboarding with mandatory training on the Code of Conduct, performance management with ethical components. In manufacturing companies, occupational safety (§ 5 ArbSchG), fire protection and hazardous substances (GefStoffV) are also integrated topics.

CIVAC networks these cross-sectional topics via several representative roles in the same workspace: Occupational safety specialist, data protection, fire protection, hygiene, LkSG. The reporting lines run synchronously, there are no duplicate surveys.

The auditor calls, the evidence is ready. It is precisely this cross-sectional structure that makes the difference between an audit-proof and a fragmented LkSG system.

Training: addressees, content, depth of documentation

§ 6 Paragraph 3 No. 3 LkSG requires training in the relevant business areas. The addressees are all employees whose activities have points of contact with the identified risks, i.e. typically purchasing, HR, compliance, management as well as employees in production-related areas with occupational safety or environmental relevance.

The content follows the risk profile: in purchasing, for example, LkSG protective goods, supplier management, contract drafting and escalation processes; in HR anti-discrimination, minimum wage, working hours; in production, occupational safety, hazardous substances, environmental protection. Experience has shown that the training frequency is annually for affected areas and every two years for cross-sectional topics.

Depth of evidence is crucial here. BAFA not only requires participation, but effectiveness. Usual evidence includes participant lists with dates, training material with versions, comprehension tests with a minimum score and repetition frequency. A pure e-learning requirement without a knowledge test does not meet the requirements.

Digital document management is a clear advantage here. In the CIVAC Workspace, each training session is documented with participants, date, material version and test result. During an audit, samples can be taken in seconds instead of being reconstructed from email attachments.

Others run compliance like a filing cabinet. We run it like software. Training evidence is a textbook example of why the difference counts in the audit.

Control measures and complaint procedures

§ 6 Paragraph 3 No. 4 LkSG requires risk-based control measures. In practice, these include internal audits, random checks, self-assessments of individual business areas and management reviews. The frequency depends on the risk profile: high risks annually, medium risks every two years, low risks on a rotational basis.

The complaints procedure according to Section 8 LkSG is the fifth mandatory measure. It must be documented in writing, accessible internally and externally and confidential. Anonymous entries must be possible; identification of the whistleblower must not be required. The rules of procedure in accordance with Section 8 Paragraph 2 LkSG must be published.

In terms of content, the LkSG complaint procedure overlaps with the Whistleblower Protection Act (HinSchG) of July 2, 2023. An integrated reporting office fulfils both obligations, provided that the rules of procedure cover both areas of application. The internal reporting office according to HinSchG is thus supplemented by the LkSG complaint office.

When a report is received, clear deadlines apply: confirmation of receipt within seven days, feedback on measures taken within three months. Escalation to management takes place according to the internal severity scale.

Deadline expires as soon as we become aware of it. Section 130 OWiG exacerbates this because inaction by management after knowledge of a breach of duty is viewed as a breach of supervisory duty. Audit-proof, documented, § 130 OWiG-proof. That is the operational consequence.

Effectiveness assessment and annual LkSG report

§ 6 Paragraph 5 LkSG requires an annual review of the effectiveness of all preventative measures, supplemented by event-related reviews in the event of significant changes or substantiated information. Section 10 LkSG requires annual reporting to BAFA within four months of the end of the financial year.

According to the BAFA handout (as of 2024), the report must cover eleven content areas, including risk analysis, prevention measures, complaint procedures, remedial measures, documentation and management supervision. Each area is filled out in a standardised online form with free text fields and drop-down selection. Attachments are possible, but not mandatory.

Assessing effectiveness is methodologically the most difficult part. BAFA expects quantitative or qualitative indicators: number of training courses, participation rate, audits carried out, number of complaints, processing time, remediation rate. A mere statement that measures have been taken is not enough.

The annual effectiveness assessment is an opportunity for a structured management review with the participation of compliance, HR, purchasing and management. The CIVAC Workspace manages these review paths automatically, with a deadline monitor and escalation logic.

The appointment certificate, signed, filed, verifiable. It is precisely this chain of documents that is retraced step by step in the BAFA exam. Licence the workspace for your internal representatives, or have our representatives order it.

Interfaces to data protection, occupational safety and the environment

LkSG is not isolated. In its own area of ​​business, it overlaps with the Occupational Safety and Health Act, the General Equal Treatment Act, the Whistleblower Protection Act, the General Data Protection Regulation and several environmental laws. If you don't think about the interfaces systematically, you will double your efforts and produce inconsistent statements in the respective reports.

Specifically: Training on the minimum wage affects LkSG protected goods and at the same time HR obligations according to AGG. Hazardous substance instruction complies with Sections 14 GefStoffV and LkSG. Data protection training for employees covers GDPR obligations and LkSG protection (right to privacy, ILO Convention No. 87) at the same time.

These overlaps are not a coincidence, but systematic. BAFA accepts combined training and audit structures as long as the respective LkSG relevance is documented. A matrix that links each measure to the underlying legal framework is the pragmatic evidence path here.

CIVAC structures this matrix in the workspace using role models: each officer (data protection, occupational safety, environmental protection, supply chains, whistleblower protection) has their own reporting line, but everyone shares the same audit and training data room. In the case of a cross-sectional test, the matrix is ​​available in minutes.

The auditor calls, the evidence is ready. This is what functional cross-sectional compliance looks like.

Fines, BAFA testing practices and reputational risk

According to Section 24, the LkSG recognises fines of up to 800,000 euros for intentional violations by individuals and up to 8 million euros or 2% of global group sales for companies with an annual turnover of 400 million euros or more. In addition, there is the possible exclusion from public procurement according to Section 22 LkSG for up to three years, with a fine of 175,000 euros or more.

BAFA testing practices have become stricter since mid-2024. The focus is on risk analysis quality, training evidence and effectiveness assessment of the complaint procedures. Previous fine proceedings mainly concerned procedural deficiencies, not material human rights violations. The amount of the fine was in the low six-figure range, well below the legal maximum.

The reputational risk is often greater than the financial one. A BAFA sanction is usually published and leads to inquiries from banks, investors and customers. In ESG ratings (MSCI, Sustainalytics) it leads to downgrades, which in turn affects credit conditions. The cross-connection to Sustainability-Linked Loans makes LkSG compliance a treasury issue.

Clean documentation is the simplest protection. There is no discussion about who can provide concrete evidence for each mandatory measure in the BAFA report. CIVAC structures exactly this depth of documentation using 490 audit templates, an appointment document for the human rights officer and a reporting line that runs centrally in the LkSG workspace.

Turn reading into a mandate. Here too, consistency counts before the race with the BAFA inbox.

Turn reading into an assignment

The prevention measures in our own business area are the foundation of LkSG compliance. Anyone who works cleanly here has significantly less effort at the supplier level because procedures, training and complaint channels can be mirrored. The first step is always a robust risk analysis, followed by the formal policy statement and operationalization in processes.

CIVAC is the compliance platform and officer-as-a-service that carries this path into practice. The workspace maintains risk analysis, policy statement, training documentation, audit trail, appointment certificate and reporting line in one place, with EU data residency and ISO/IEC 27001:2022-ISMS.

Licence the workspace for your internal representatives, or have our representatives appointed. Both models generate the same depth of documentation and the same ability to respond to BAFA, banks and corporate customers. The difference lies only in the personnel structure, not in the compliance quality.

If you would like a 90-day plan for your LkSG prevention measures or a second check of your risk analysis, write to info@civac.de or use the contact form on civac.de.

Turn reading into a mandate. We will respond within two working days with a specific proposal.

FAQ

At what size company does the LkSG currently apply?

Since January 1, 2024, the LkSG has applied to companies with 1,000 or more employees in Germany. Before there were 3,000. What is relevant is the average number of employees in the previous calendar year, including seconded group employees. A planned EU CSDDD will further lower the threshold.

Do subsidiaries have to have their own policy statement?

Not mandatory if the group's policy statement clearly includes all subsidiaries and is available in local languages. BAFA accepts group-wide declarations provided that local anchoring in processes and training can be proven.

How often do LkSG training courses have to be repeated?

The law does not specify a fixed frequency. BAFA handouts are based on the level of risk: annually for high-risk areas (purchasing, HR, production in high-risk countries), every two years for cross-cutting topics. Event-related training is mandatory in the event of significant procedural changes.

Can an external service provider take on the role of LkSG representative?

Yes. Section 4 Paragraph 3 LkSG requires a responsible person, but says nothing about internal or external connections. CIVAC offers the role of Officer-as-a-Service with a documented appointment certificate and reporting line to management. The ultimate responsibility remains with the management.

What evidence does BAFA expect for the effectiveness assessment?

Quantitative indicators such as training participation rates, audits carried out, number and processing time of complaints as well as qualitative reports from management reviews. A mere statement that measures are effective without a database is considered a procedural defect.

How does the LkSG complaint procedure connect with the Whistleblower Protection Act?

An integrated reporting office complies with both laws if the procedural rules cover both areas of application, i.e. LkSG protected objects and HinSchG legal areas. CIVAC offers the combined reporting point as a workspace module or as an officer-as-a-service with a clear separation of input categories.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles