Sign the LkSG declaration of principles: template, content and duties of the management
The declaration of principles according to Section 6 Paragraph 2 LkSG is the central anchor of the Supply Chain Due Diligence Act. This article shows the mandatory components, a structural proposal, common errors and the audit-proof signing process by the management, including connection to the LkSG representative.
The declaration of principles according to Section 6 Paragraph 2 of the Supply Chain Due Diligence Act (LkSG) is the company management's mandatory declaration on human rights strategy and a central subject of review by the Federal Office of Economics and Export Control (BAFA). It combines operational risk analysis with an explicit commitment from management to implement due diligence obligations in its own and supplier processes. Since January 2024, companies with 1,000 or more employees have been subject to the LkSG, with sliding requirements over two financial years. With the EU Supply Chain Directive CSDDD (Directive (EU) 2024/1760), the circle of addressees continues to expand and the list of obligations becomes stricter, in particular with regard to civil liability and an increased climate issue. Since 2024, BAFA supervision has been working with samples and specific test profiles that treat the declaration of principles as an input document.
This article shows what content a declaration of principles must contain, what a practical structural proposal looks like, which errors are regularly noticed in BAFA procedures and how the signing process is designed by management to be audit-proof. You will also receive an overview of interfaces with the annual BAFA report, the internal complaints office in accordance with Section 8 LkSG and the appointment of an LkSG representative. The aim is a policy statement that not only fulfils the obligation, but also functions as an operational control document, stands up in the audit and remains resilient even under the stricter CSDDD requirements from 2027. The article primarily addresses management, compliance officers and LkSG officers in companies with more than 1,000 employees.
Key Takeaways
- The policy statement must specifically describe the human rights strategy, the risk analysis process, the identified priority risks and the personnel responsibilities.
- The management's signature is not symbolic, but rather proof of acceptance of the mandate in accordance with Section 4 Paragraph 3 LkSG and a prerequisite for BAFA reporting.
- Without an LkSG representative and a documented release process, the declaration remains contestable. CIVAC delivers the template, appointment certificate and audit trail in one workspace.
What Section 6 Paragraph 2 LkSG requires: the mandatory components
According to Section 6 Paragraph 2 LkSG, the policy statement is an independent document that is approved and published by the company management. It must cover at least five contents. Firstly, the procedure for fulfilling the due diligence obligations according to Section 3 LkSG, i.e. the central processes for risk analysis, prevention measures, remedial measures, complaint procedures and reporting. Second, the priority human rights and environmental risks identified for the company. Thirdly, the human rights and environmental expectations that the company has of its employees and suppliers.
Fourthly, the reference to the relevant international conventions, such as the UN Guiding Principles on Business and Human Rights and the OECD Guidelines for Multinational Enterprises. Fifth, determining who in the company is responsible for monitoring risk management, usually the LkSG representative in accordance with Section 4 Paragraph 3 LkSG. These five points are the basic equipment. A pure declaration of intent without reference to specific risks and processes is generally not considered sufficient by BAFA because it does not allow for an assessment of the due diligence requirements. Instead, a minimum level of specificity is required that stands up to a random sample and enables references to the industry, delivery regions and convention violations.
Whoever prepares the declaration as a LkSG representative should structure the text as a structural document that discloses the interconnection with the risk analysis and contains references to internal guidelines. The declaration is public, but it should also be readable internally. CIVAC provides a template for exactly this structure, which is maintained in a workspace together with the agent's appointment certificate and the risk analysis. Mandatory components are not rigid, but rather refer to underlying data sources that are automatically updated with every update, such as country lists, industry clusters and ILO convention statuses.
Structural suggestion: Building an audit-proof policy statement
A proven structure divides the policy statement into seven sections. Section one: Preamble with self-image and reference to business model and supply chains. Section two: Scope, i.e. which group companies, locations and product categories are included, with reference to consolidated companies. Section three: applicable standards, in particular UN Guiding Principles, OECD Guidelines and ILO Core Labour Standards, each with date and version. Section four: Risk analysis procedures, i.e. methodology, data sources and frequency, as well as the priority risks in list form.
Section five: Expectations of employees and suppliers, ideally with reference to the code of conduct and the supplier code document. Section six: Measures and responsibilities, i.e. preventive measures, remedial measures, complaint procedures according to Section 8 LkSG and reporting. The personnel responsible is named here, usually the appointed LkSG representative. Section seven: Signature with date, place, function and signature of the management as well as a reference to the publication date.
The length is typically between four and eight pages. Shorter is possible, but it quickly seems arbitrary. Longer is not prohibited, but it dilutes the character of a control-relevant document. CIVAC provides a sample template that specifies these seven sections, contains placeholders for company-specific information and is linked to the report fields of the BAFA report. The template has been iterated several times, with information on typical BAFA queries and example texts for standard risks in the respective industry. If you want to produce a complete first draft in less than four weeks, you can usually use this template to produce a document ready for signature in this time. Included is a series of workshops of three dates in which risks, expectations and responsibilities are coordinated together with purchasing, legal and human resources. This is followed by a round of approval by the legal department and an external plausibility check. The appointment certificate, signed, filed, verifiable.
Who signs: management, board, distribution of mandates
The declaration is signed by the company's legal representative. In the case of a GmbH this is the management, in the case of an AG it is the board of directors. Section 4 (3) LkSG also requires that management assume responsibility for risk management and that a specific person responsible be named. This is usually the LkSG representative. The signing of the declaration of principles is formal proof of this acceptance of the mandate.
In practice, three questions arise. First: Do all managing directors sign together or is one person sufficient? It is recommended that all members of the management board sign it because responsibility under the LkSG is joint and several. Second: Is the form predetermined? The LkSG does not prescribe a specific form, but the BAFA report expects a published and dated statement. A handwritten signature or qualified electronic signature is common and recommended. Third, who checks the declaration before signing it? The plausibility check should be carried out by the LkSG representative, supplemented by a legal department or external legal opinion.
CIVAC maps this process as an audit-proof workflow. The draft is created by the external LkSG representative, coordinated internally and released via a qualified electronic signature. Version status, release date and signatories are documented in the workspace. Turn reading into an assignment. The auditor calls, the evidence is ready. In addition, minutes of the board meeting or management meeting in which the declaration was formally decided is recommended, as BAFA explicitly requests templates for resolutions from 2025. This log is linked to the declaration in the workspace and is subject to the same versioning rules. Anyone who documents the decision without minutes must subsequently reconstruct it in the BAFA process, which usually takes several weeks of effort.
Connection to the risk analysis according to Section 5 LkSG
The declaration of principles does not stand alone, but is based on the risk analysis according to Section 5 LkSG. This risk analysis must be carried out at least once a year and as needed. It identifies human rights and environmental risks in its own business area, with direct suppliers and, in cases of suspicion, also with indirect suppliers. The priority risks identified in the policy statement must be consistent with the results of the risk analysis. A common audit finding is the lack of consistency between explanation and analysis.
In practical terms, this means: The risk analysis identifies, for example, risks relating to occupational safety in a specific delivery region, wage payments in an industry, environmental violations in a production stage and discrimination risks in your own company. These points appear word for word or at least have the same meaning in the declaration of principles. If a risk has been prioritised but is not included in the statement, a credibility problem arises. If a risk is included in the declaration but not in the analysis, the declaration is unsubstantiated.
CIVAC links the risk analysis, policy statement and BAFA report in a common data model. Risks are recorded once, documented with sources and consistently incorporated into all mandatory documents. When a new discovery is made, the declaration is marked as a document to be updated, with a version history and approval workflow. This saves duplication of work and reduces the risk of contradictory statements, which is considered a typical source of error in the BAFA audit. Particularly in corporations with decentralized procurement units, a consolidated risk analysis is a prerequisite for ensuring that the parent company's declaration reflects the reality of the subsidiaries. Anyone who works without this consolidation runs the risk that a subsidiary will not cover a risk area that is, however, claimed in the group report.
Interlinking with BAFA report and Section 8 complaint procedure
The annual BAFA report in accordance with Section 10 LkSG calls on companies to present the implementation of due diligence obligations in the past financial year. The policy statement is a central reference point in this regard because it describes the procedure that was implemented in the reporting year. If the content of the declaration and the report differ, BAFA will have questions. Anyone who fills out the report form without reference to the declaration of principles loses the consistency that is expected between the two documents.
The situation is similar with the complaint procedure according to Section 8 LkSG. The policy statement must state that and how the company operates a complaints procedure, who those potentially affected can contact, in which language and with what protection against reprisals. This point is often formulated too briefly. Recommendation: Reference to a separate procedural principle that describes the complaint procedure in detail, with contact details for the internal reporting office according to the HinSchG, insofar as the two procedures are meaningfully linked.
CIVAC offers a template in the workspace for the internal reporting office according to the HinSchG, which is technically and procedurally linked to the LkSG complaint procedure. Licence the workspace for your internal representatives, or have our representatives appoint one if there is no capacity internally. Interlinking the two complaint channels reduces duplication of effort and avoids friction between the LkSG representative and the reporting office representative, a common point of conflict in practice. Clear rules of procedure regulate which representative is responsible for which matter and how handovers between roles are documented, which is critical to success, especially when sensitive information is involved. Confidentiality and protection against reprisals apply in both procedures, but must be operationalized differently depending on the facts of the case. Written rules of procedure for the two functions are a prerequisite for a clean separation vis-à-vis supervisory authorities.
Common mistakes in practice and in the BAFA process
Five errors occur regularly in practice. Firstly, the use of a group declaration for German subsidiaries without adjustment. If the subsidiary falls independently under the LkSG, for example because it has more than 1,000 employees in Germany, it needs its own declaration with reference to German law. An English-language group policy is not enough.
Secondly, the lack of priority risks. A declaration that only contains general statements about human rights and does not name any specific risks is considered inadequate by BAFA. Thirdly, signing by a person who is not authorised to represent you, such as a compliance officer or human resources manager. The signature must come from the legal representative. Fourth, the lack of an update routine. The declaration should be reviewed at least annually and adjusted immediately if there are significant changes. Fifth, the missing connection to the BAFA report: The declaration is created once and is no longer touched, the report is drawn up in parallel without reference.
CIVAC addresses all five points. The platform maintains declaration, risk analysis and BAFA report in one data model, flags outdated versions and automatically initializes the annual update workflow. Others run compliance like a filing cabinet. We run it like software. The LkSG representative's appointment certificate is part of the workspace structure and is subject to the same versioning and audit rules as the declaration itself. The deadline expires as soon as it is known. Anyone who notices a violation and does not adjust the declaration risks the BAFA procedure being tightened because an obligation to update is derived from the precautionary principle of the LkSG. The platform sets reminders as soon as structural changes occur in the risk analysis or complaint system. Even in quiet years, a minimum update makes sense in order to regularly involve management in LkSG issues.
Publishing, retention and update routine
The policy statement must be published, usually on the company website. A separate compliance or sustainability page is common. The language is German, a translation into English is recommended for internationally active companies. The original version with signature is stored in an audit-proof manner, at least for the duration of the retention periods according to Section 257 of the German Commercial Code (HGB), i.e. usually ten years. Previous versions must also remain discoverable because the BAFA traces version history through spot checks.
The update routine should take place at least annually, and more frequently if necessary. The reasons include, in particular, significant changes in business activities or the supply chain, new findings from risk analysis, new legal developments, such as the CSDDD implementation, and complaints that lead to structural adjustments. Each update is accompanied by a date, justification and a new signature. Older versions are archived but remain accessible.
CIVAC maps the update routine in the workspace. Reminders before the annual cycle, templates for justifying changes and automatic version statuses are standard functions. Experience has shown that anyone who does not systematize the process will spend several days reconstructing previous versions during the audit. At the CIVAC FAQ you will find further answers about retention periods, BAFA samples and group regulations. The platform keeps previous versions available for the legally required periods even after the end of the contract, provided this has been contractually agreed, so that there is no risk of data loss when changing providers. The export is structured in a machine-readable format and contains all version histories and the associated appointment certificates. Audit-proof, documented, § 130-OWiG-proof. The publication should also be carried out separately for each company in groups with central communication in order to clearly signal the applicability of the LkSG and to distinguish between group and subsidiary responsibilities. A central compliance portal with a company filter is common.
Connection to contracts and supplier code
The policy statement alone does not change a supplier relationship. It only takes effect when the expectations of suppliers are anchored in contracts and supplier codes. Common mechanisms include code of conduct clauses in framework contracts, self-disclosures from suppliers, audits by our own or external auditors and contractual consequences for violations, from improvement plans to contract termination. These mechanisms must be at least outlined in the policy statement.
A good practice is to link the policy statement to a separate supplier code that contains detailed requirements. The supplier code refers to the declaration of principles, lists specific requirements regarding working conditions, environmental protection, anti-corruption and complaint mechanisms and provides for an obligation for the supplier to confirm. For larger suppliers, audit rights and continuous improvement are added. This interlinking is explicitly the subject of BAFA supervision.
CIVAC not only provides the template for the declaration of principles, but also links it to the supplier code, self-disclosure templates and an audit workflow. Supplier audits are documented in the same workspace, with findings, measures and follow-ups. An external supplier auditor can be ordered upon request and works directly in the workspace. This creates a closed chain from the political commitment in the declaration of principles to the operational audit at the supplier, with a complete audit trail and a uniform role concept. The connection to SAP Ariba, Coupa or similar procurement systems is possible via API, so that supplier evaluation and contract management do not have to be managed in separate systems. This means there are no duplicate data sets and the LkSG assessment is incorporated directly into operational procurement decisions, for example when selecting new suppliers or extending contracts. Suppliers thus experience consistent expectations, which increases the acceptance of self-disclosures and audits and reduces frictional losses.
From document to resilient LkSG organisation
The policy statement is not the goal, but the starting point. A signed document without a risk analysis, without a complaint procedure, without a supplier code of conduct and without an LkSG representative remains a paper requirement. BAFA checks the practice, not just the declaration. Effective LkSG compliance requires both: a clear, signed commitment from management and a documented organisation that implements the commitment on a daily basis. Both must be managed in a system, otherwise gaps arise between expectations and reality.
CIVAC, as a compliance platform and officer-as-a-service, is built precisely for this dual task. Licence the workspace for your internal representatives, or have our representatives appoint one if there is no capacity internally. Both models bring together the template, appointment certificate, risk analysis grid and BAFA reporting structure in one system. Others run compliance like a filing cabinet. We run it like software. The SLA for appointing external assignees is two business days, well below the market standard of two to six weeks.
Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de to arrange a platform demo or an initial meeting to appoint an external LkSG representative. You will receive feedback within two working days, including a suggestion for a suitable licence or mandate model and an indication of the effort required for the next BAFA reporting. If you wish, we will send you an anonymized sample declaration in advance so that you can formulate specific questions before the initial consultation. Initial discussions are usually conducted by an authorised LkSG representative, so that both methodological and organisational questions can be answered directly. The platform demo can take place separately or at the same time, depending on the company's level of preparation. The appointment certificate, signed, filed, verifiable.
FAQ
Does each group company have to have its own policy statement?
Yes, as soon as the individual company reaches the LkSG threshold. A pure group declaration from the parent company is not sufficient if the subsidiary is required to report as an independent company with more than 1,000 employees in Germany. The individual declaration must specifically describe the scope of application, the specific risk analysis and the personnel responsibilities of this company and must be signed in German.
Who must sign the policy statement?
The legal representation of the company, i.e. management of the GmbH or board of directors of the AG. It is recommended that all members sign together because responsibility under the LkSG is joint and several and Section 4 Paragraph 3 LkSG requires the assumption of the mandate. A signature by a compliance officer or HR manager alone is not enough and is regularly objected to by BAFA.
How often does the policy statement need to be updated?
At least once a year, more often if necessary. The reasons are significant changes in business activities or supply chain, new findings from risk analysis, new legal developments such as the CSDDD implementation and structurally affecting complaints from the Section 8 procedure. Each update must be signed again and provided with a version number and date; older versions remain accessible in an audit-proof manner, usually for ten years.
What happens if the policy statement is missing or incomplete?
The BAFA can impose fines and issue orders for improvements. As part of the LkSG supervision, fines of up to 800,000 euros per violation are possible, and significantly higher in serious cases involving sales. A missing or incomplete declaration is usually the first entry in BAFA's circulation catalogues and entails further checks.
Do we absolutely need an LkSG representative?
Section 4 Paragraph 3 LkSG requires a responsible person for monitoring risk management. In practice, this is the LkSG representative or human rights officer. The function can be filled internally or appointed externally. External appointments have the advantage of immediate methodological expertise and a clear reporting line to management. CIVAC orders within two working days with a documented appointment certificate.
How do we interlink the policy statement and the complaint procedure in accordance with Section 8 LkSG?
The declaration must specify the complaint procedure; the procedural principle according to Section 8 LkSG describes it in detail. Both documents should refer to each other. Interlinking with the internal reporting office according to HinSchG is possible and reduces effort, but requires a clear separation of responsibilities between the LkSG representative and the reporting office representative as well as a common escalation protocol with defined reaction deadlines.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.