Supply Chain Act Compliance in Germany: A Practical Guide for International Companies
The German LkSG has applied to companies with 1,000 or more employees since 2024 and demands a documented risk analysis, a complaints mechanism, and an annual BAFA report. This guide explains what international groups must operationalise to remain audit-ready.
The German Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) entered into force on 1 January 2023 and has applied to companies with 1,000 or more employees in Germany since 1 January 2024. The Act creates binding human-rights and environmental due-diligence duties that cover the company's own business operations, its direct suppliers, and, in defined circumstances, indirect suppliers. Non-compliance triggers administrative fines up to EUR 8 million or, for groups with an annual turnover above EUR 400 million, up to 2 percent of global group turnover, plus a public exclusion from German public-procurement procedures for up to three years.
This guide explains the operational duties under the LkSG for international companies with a German legal entity in scope. It covers the nine due-diligence steps under sections 4 to 10 LkSG, the risk-analysis methodology, the complaints mechanism under section 8 LkSG, the annual report to the Federal Office for Economic Affairs and Export Control (BAFA) under section 10, and the role of the human-rights officer. The text is written for group counsel, compliance officers, and supply-chain leads who need a working framework to align international processes with German requirements without duplicating effort against the upcoming EU Corporate Sustainability Due Diligence Directive (CSDDD).
Auf einen Blick
- The LkSG applies to companies with 1,000 or more employees in Germany since 2024, with fines up to EUR 8 million or 2 percent of global turnover.
- Compliance requires a written risk analysis, a documented complaints mechanism, preventive and remedial measures, and an annual BAFA report by 1 June each year.
- The human-rights officer is the operational anchor of the LkSG programme and must report directly to the management board on a regular basis.
Scope and Trigger Thresholds under the LkSG
Section 1 LkSG defines the scope by employee headcount in Germany. Since 1 January 2024, companies with 1,000 or more employees in Germany are within scope, regardless of whether the parent is German or foreign. The headcount includes regular employees, seconded employees, and temporary workers used for more than six months. Branches of foreign companies are included once they exceed the threshold in Germany. The Act also covers companies that are part of a group, although the duties apply to the individual legal entity rather than to the group as a whole, with practical consequences for governance models in matrix organisations.
The substantive duties under sections 4 to 10 LkSG apply within the company's own business operations and to direct suppliers, and, where a substantiated risk arises, to indirect suppliers under section 9 LkSG. The Act distinguishes between human-rights risks (e.g. forced labour, child labour, slavery, occupational health, freedom of association, discrimination, withholding wages, environmental impacts affecting health) and environmental risks (Minamata Convention on mercury, Stockholm Convention on persistent organic pollutants, Basel Convention on hazardous waste). For each risk category, the company must demonstrate that it has implemented appropriate due-diligence measures. CIVAC ist eine Compliance-Plattform und Officer-as-a-Service: licence the workspace for your internal officers or have our officers appointed, in both cases the LkSG officer works with audit templates aligned to the BAFA inspection guide and to the upcoming CSDDD requirements. The threshold is calculated at the level of the German legal entity, not at the group level, which can create unexpected outcomes for companies with several smaller German subsidiaries that individually remain below the threshold but together exceed it.
The Nine Due-Diligence Duties under Sections 4 to 10 LkSG
Sections 4 to 10 LkSG define nine due-diligence duties that together form the LkSG compliance system. They are: (1) establishing a risk-management system; (2) designating a person responsible for human rights (often called the human-rights or LkSG officer); (3) conducting a risk analysis at least annually and ad hoc; (4) adopting a policy statement on the human-rights strategy; (5) implementing preventive measures in the company's own business operations and at direct suppliers; (6) taking remedial action when violations occur; (7) operating a complaints mechanism accessible to internal and external persons; (8) implementing risk-based due diligence at indirect suppliers when a substantiated risk is known; (9) documenting and reporting annually to BAFA.
The duties are obligations of conduct, not of result. The Act does not require the company to eliminate every risk in its supply chain, but to act diligently, transparently, and progressively to identify, prevent, and mitigate adverse impacts. This distinction matters because BAFA inspections focus on whether the company has implemented appropriate processes, not on whether risks still exist. Bestellurkunde, unterschrieben, abgelegt, belegbar. The audit trail is therefore the central artefact of LkSG compliance. The CIVAC workspace links each of the nine duties to the relevant evidence, owners, deadlines, and review cycles. Other organisations run compliance like a filing cabinet. We run it like software. The prosecutor calls and the evidence is ready. Each of the nine duties has its own evidentiary cadence and its own review responsibility, and the workspace enforces this cadence with automated reminders to the responsible officers and to the management board sponsor.
Risk Analysis: Methodology, Frequency, and Documentation
The risk analysis under section 5 LkSG is the foundation of the compliance system. It must cover both the company's own business operations and direct suppliers, and must be conducted at least annually and on an ad-hoc basis when a substantial change occurs (new business activity, new supplier, new geography, public reporting, complaints). The analysis follows a structured five-step process: (1) map the supply chain by category and geography; (2) assess inherent risks for each human-rights and environmental category; (3) apply weighting factors such as severity, irreversibility, and the company's contribution; (4) prioritise risks and identify focus suppliers; (5) document the methodology, results, and decisions for BAFA review.
The Act explicitly references human-rights and environmental risks, but in practice the assessment also touches data-protection, cyber-security, and economic-sanctions risks where they interlink with labour or environmental conditions. The 490 audit templates in the CIVAC workspace include LkSG risk-analysis structures aligned to the BAFA inspection methodology. Bestellurkunde, unterschrieben, abgelegt, belegbar. Licence the workspace for your internal officers or have our officers appointed, in both cases the risk analysis is versioned, the decisions are linked to evidence, and quarterly updates are tracked automatically. The risk analysis also feeds the general compliance officer work to ensure consistency with the company's overall compliance risk register and with the EU Taxonomy and CSRD reporting obligations. The structured five-step process is supplemented by an annual benchmark exercise that compares the company's risk profile against peer companies in the same industry, drawing on public BAFA reports and CSRD disclosures.
The Complaints Mechanism under Section 8 LkSG
Section 8 LkSG requires every in-scope company to operate a complaints mechanism that is accessible to internal staff, suppliers, and external rights-holders such as affected communities or workers in supplier facilities. The mechanism must be accessible in a way that takes into account the language and digital literacy of the user, must guarantee confidentiality, must protect against retaliation, and must allow anonymous submissions. Section 8 paragraph 1 requires written rules of procedure that describe the intake, processing, and feedback steps and that are publicly available, typically on the company website in German and in the local languages of key supplier countries.
The complaints mechanism is functionally close to the whistleblower channel under the German Whistleblower Protection Act (HinSchG), and many companies operate both through one technical platform. The CIVAC workspace combines both regimes in a single intake with rule-based routing into the appropriate process, so that complainants do not have to choose the legal basis themselves. The audit trail respects both the LkSG documentation duties and the HinSchG confidentiality obligations. The prosecutor calls and the evidence is ready, whether the prosecutor is BAFA, a data-protection authority, or a state public-prosecutor's office. Licence the workspace for your internal officers or have our officers appointed. Both models follow the same operational logic and use the same template architecture, with full English and German language support to accommodate international group operations. Audit-fest, dokumentiert, complaints-fest. The procedural rules are reviewed annually and updated when BAFA publishes new guidance or when court decisions clarify the requirements of section 8 LkSG.
Preventive and Remedial Measures
Sections 6 and 7 LkSG require the company to take appropriate preventive measures in its own business operations and at direct suppliers, and to take remedial measures when violations are identified or substantiated. Preventive measures include the adoption and communication of a policy statement (section 6 paragraph 2), training for relevant employees, due-diligence procedures in procurement, contractual assurances from suppliers, and supplier audits. Remedial measures depend on the severity and proximity of the violation: in the company's own operations, the violation must be brought to an end immediately; at a direct supplier, the company must develop and implement a concept with concrete steps and time horizons; at an indirect supplier, the company must take appropriate measures to minimise or end the violation.
The Act explicitly permits companies to use the leverage they have, including business termination, but does not require it as a first response. BAFA expects a graduated approach that prefers engagement and improvement over termination, except in cases of serious and unresolvable violations. The CIVAC workspace integrates the preventive and remedial measures into a coherent action plan with owners and deadlines and tracks each step until closure. Audit-fest, dokumentiert, BAFA-fest. The 490 ready audit templates include training modules, supplier-contract clauses, audit checklists, and remedial-action plans, all aligned with BAFA inspection guidance. The 24-month CIVAC review cycle ensures that measures are reviewed, refined, and re-approved with the management board annually. Remedial measures must be documented with start date, milestones, owner, and a defined closure criterion so that the BAFA reviewer can follow the trajectory from identification to resolution without additional explanation.
Annual BAFA Report under Section 10 LkSG
Section 10 LkSG requires every in-scope company to submit an annual report to BAFA by 1 June of each year, covering the previous business year. The report must describe the company's risk analysis, the identified risks, the preventive and remedial measures taken, the complaints mechanism, the lessons learned, and the planned measures for the coming year. The report must be submitted electronically through the BAFA portal and must be publicly available on the company's website for at least seven years. BAFA reviews the reports on a risk-based sampling basis and can initiate further inquiries, on-site inspections, or fine proceedings.
The reporting template was streamlined in 2024 to reduce administrative burden, but the substantive expectations remain demanding. BAFA expects measurable, specific descriptions rather than generic statements. Companies that publish vague reports face follow-up requests and, in repeated cases, fine proceedings under section 24 LkSG. The CIVAC workspace generates the BAFA report directly from the risk analysis, the measures register, and the complaints log, so that the report is consistent with the underlying evidence. The prosecutor calls and the evidence is ready. Licence the workspace for your internal officers or have our officers appointed, in both cases the LkSG officer reviews and signs off the report before submission, and the management board countersigns it as required by good corporate governance. The CIVAC SLA of two working days enables fast iteration during the busy April and May submission window. Frist läuft ab Kenntnis. Companies that delay the report until the final week risk procedural errors that trigger follow-up requests.
The Role of the Human-Rights Officer
Section 4 paragraph 3 LkSG requires the company to designate a person responsible for monitoring the risk-management system. This person, often called the human-rights officer or LkSG officer, has a defined mandate, direct reporting line to the management board, and dedicated resources. The officer is responsible for the day-to-day operation of the LkSG programme, including the risk analysis, the complaints mechanism, the policy statement, the measures register, and the BAFA report. The officer must be informed of relevant business decisions and must have access to the necessary functional units (procurement, legal, HR, ESG, sustainability).
The officer can be internal or external. An internal officer offers proximity to the business and continuity. An external officer offers independence, specialised expertise, and immediate availability without recruitment lead time. CIVAC operates a compliance platform and officer-as-a-service, allowing both models. In the external model, CIVAC provides the appointed officer with a written appointment letter, a defined reporting line, a service-level agreement, and integration into the CIVAC workspace, all hosted in the EU with ISO/IEC 27001:2022 controls. Other organisations run compliance like a filing cabinet. We run it like software. The officer participates in the management-board meetings on a defined cadence, typically quarterly, and produces a written annual report that complements the BAFA submission and informs the supervisory board. The officer is independent in the exercise of the role and reports without instruction in matters of substance, while remaining integrated into the company's overall governance framework. This balance is documented in the appointment letter and in the company's compliance manual.
Interface with CSDDD, CSRD, and the Whistleblower Protection Act
The LkSG does not exist in isolation. It interfaces with three major regulatory regimes: the EU Corporate Sustainability Due Diligence Directive (CSDDD, adopted 2024, transposition by mid-2026), the EU Corporate Sustainability Reporting Directive (CSRD, with ESRS reporting from 2025 for large non-listed companies), and the German Whistleblower Protection Act (HinSchG, in force since 2023). Each regime adds requirements or shifts existing ones, and a coherent compliance architecture treats them as parts of one programme rather than as three separate projects.
The CSDDD extends due-diligence duties to a broader range of companies, including foreign companies with EU activities, lowers the headcount threshold over time, and adds climate-transition plan obligations. The CSRD requires extensive disclosures on social, environmental, and governance topics that overlap with LkSG risk-analysis data. The HinSchG governs the protected status of whistleblowers and applies to many of the same channels used for LkSG complaints. The CIVAC workspace maps the data points across all regimes and routes evidence to the correct workflow, so that one supplier audit can produce LkSG documentation, ESRS data points, and CSDDD evidence in a single pass. Licence the workspace for your internal officers or have our officers appointed. The whistleblower channel is integrated by default, and the LkSG complaints flow is differentiated by routing rules rather than by separate intake forms, which improves user experience and operational consistency. Companies that prepare the architecture now will avoid a costly retrofitting exercise when the CSDDD transposition arrives and when the German legislator aligns the LkSG with the CSDDD baseline, expected in the 2026 to 2027 timeframe.
Building an Audit-Ready LkSG Programme with CIVAC
LkSG compliance is operational compliance. It is not enough to have a written policy. The duties under sections 4 to 10 LkSG require continuous activity throughout the year: a risk analysis that is reviewed at least annually, a complaints mechanism that is monitored, preventive measures that are implemented and trained, remedial measures that are tracked to closure, and an annual report that is submitted on time and that reflects the underlying evidence. Companies that approach LkSG as a once-a-year reporting exercise will not pass a BAFA on-site inspection. Companies that integrate LkSG into their daily operations will pass the inspection and will be ready for the upcoming CSDDD transposition.
CIVAC is a compliance platform and officer-as-a-service: you licence the workspace for your internal officers or you have our officers appointed, depending on the maturity of your organisation. In both models you receive the written appointment letter, the reporting line to the management board, the EU data residency, and the ISO/IEC 27001:2022 hosting environment with 93 controls. The CIVAC SLA is two working days rather than the customary two to six weeks. Aus dem Lesen einen Auftrag machen. Write to info@civac.de or use the contact form if you want to assess, redesign, or fully outsource your LkSG programme. We provide an initial gap analysis at no cost and a concrete twelve-month roadmap with owners, milestones, and a budget envelope. The roadmap is reviewed quarterly with the management-board sponsor and updated when new BAFA guidance or CSDDD-related decisions affect the assumptions.
FAQ
Which companies are in scope of the LkSG in 2026?
Companies with 1,000 or more employees in Germany are in scope, regardless of whether the parent is German or foreign. The headcount includes regular employees, seconded employees, and temporary workers used for more than six months. Branches of foreign companies are included once they exceed the threshold in Germany. The threshold is calculated at the level of the German legal entity.
What are the fines for non-compliance with the LkSG?
Section 24 LkSG allows administrative fines up to EUR 8 million or, for groups with an annual turnover above EUR 400 million, up to 2 percent of global group turnover. In addition, the company can be excluded from German public-procurement procedures for up to three years following a fine of at least EUR 175,000.
How often must the risk analysis be conducted?
Section 5 LkSG requires the risk analysis at least once a year and on an ad-hoc basis when a substantial change occurs, such as new business activities, new suppliers, new geographies, public reports, or complaints. The methodology, results, and decisions must be documented and made available to BAFA on request.
Can the complaints mechanism be combined with the whistleblower channel?
Yes, and it is recommended. A combined intake with rule-based routing into the LkSG and HinSchG processes improves accessibility and operational consistency for users while keeping the legal regimes and confidentiality scopes separated in the back-end workflow. The CIVAC workspace supports both regimes in a single technical platform with full multilingual access and EU data residency.
What does the human-rights officer do under the LkSG?
The officer monitors the risk-management system, oversees the risk analysis, ensures that preventive and remedial measures are implemented, manages the complaints mechanism, and prepares the annual BAFA report. The officer reports directly to the management board, typically on a quarterly cadence, with a written annual report that informs the supervisory board.
Can CIVAC act as the external LkSG officer for our German entity?
Yes. In the officer-as-a-service model, CIVAC provides an appointed external LkSG officer with a written appointment letter, a defined reporting line to the management board, a service-level agreement of two working days, and full integration into the CIVAC workspace. The workspace is hosted in the EU and operates under ISO/IEC 27001:2022 controls with 93 implemented safeguards.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.