Germany's Supply Chain Due Diligence Act is now in full effect. The Federal Office of Economic Affairs and Export Control (BAFA) can impose fines up to eight million euros or 2% of annual global turnover for companies with revenue exceeding 400 million euros. In April 2023, the National Garment Workers Federation filed the first legal complaint under the law, targeting garment companies for safety and labor violations in Bangladesh factories. The compliance window is closing: companies with more than 1,000 employees fall under the law's scope on January 1, 2024.
What Changed
The LkSG has transformed supply chain ethics from voluntary corporate social responsibility into enforceable regulatory obligations. Since January 1, 2023, companies with at least 3,000 employees operating in Germany must implement risk management systems, conduct annual risk analyses, and report findings to BAFA. The law covers the entire supply chain, from raw material extraction to end-customer delivery, and protects against child labor, forced labor, discrimination, wage withholding, occupational health violations, mercury use, and hazardous waste mishandling.
Key Findings
Enforcement has teeth. BAFA can enter business premises, demand information, inspect documents, and exclude non-compliant companies from public contracts. The first legal complaint shows that advocacy groups will use the law to enforce accountability.
Risk management requirements are specific. Section 4 mandates an "appropriate and effective risk management system" and requires the appointment of a human rights officer. Section 5 requires annual risk analyses and ad hoc assessments when you introduce new products, projects, or business fields. Section 10 requires annual reports to BAFA within four months of fiscal year-end, published on your website for seven years.
Indirect supplier violations trigger obligations. You can't limit due diligence to direct suppliers. Section 9 requires risk analysis and preventative measures for indirect suppliers when you have "substantiated knowledge" of violations. Your complaint mechanism under Section 8 must accept reports about indirect suppliers.
Remedial action timelines are compressed. Section 7 requires you to act "without undue delay" when violations surface. In some circumstances, you must terminate business relationships. Your procurement strategies and purchasing practices must prevent or minimize identified risks.
The scope expands in 2024. Companies with more than 1,000 employees fall under the law in three months. If you're approaching that threshold, you're building your compliance program under time pressure.
What This Means for Your Team
You're integrating ethics into operational risk management, not running a parallel CSR program. Your risk universe now includes human rights and environmental violations across multiple tiers of suppliers. Your control objective mapping must connect procurement decisions to impact tolerance for supply chain disruptions caused by forced labor, unsafe working conditions, or environmental harm.
Your complaint mechanism becomes a critical control. It must guarantee reporter confidentiality, protect against retaliation, and accept external reports about indirect suppliers. If you're using an external service provider for complaints, you need documented evidence of their impartiality and accessibility.
Your vendor risk profiles need human rights and environmental risk indicators. You can't assess a supplier's information security posture while ignoring their labor practices. Ongoing vendor monitoring must include triggers for ad hoc risk analysis: new product lines, geographic expansion, or changes in subcontractor relationships.
Action Items by Priority
Immediate (if you're at 3,000+ employees or approaching 1,000):
Map your supply chain tiers. Identify direct suppliers and the indirect suppliers you have substantiated knowledge about. Document the steps from raw material extraction to customer delivery for your primary product lines.
Designate your human rights officer. This role monitors your risk management system and coordinates cross-functional response to violations. Don't assign this as a side responsibility to someone already managing financial controls or information security.
Stand up your complaint mechanism. Ensure it accepts reports about indirect suppliers, protects confidentiality, and includes retaliation protection. If you're using an external provider, document their impartiality and accessibility.
Next 90 days:
Conduct your first risk analysis under Section 5. Weight and prioritize human rights and environmental risks in your business and at direct suppliers. Document your methodology and findings.
Draft your policy statement under Section 6. Define human rights and environmental expectations for employees and suppliers. Make it specific: what behaviors you require, what violations trigger remediation, and how you'll verify compliance.
Review your procurement strategies. Identify where your purchasing practices create or amplify human rights or environmental risks. Consider payment terms that pressure suppliers to cut corners on safety, or volume commitments that incentivize subcontracting to unvetted facilities.
Ongoing:
Build ad hoc risk analysis triggers into your vendor management workflow. When procurement introduces a new supplier, launches a product, or enters a business field, your system should flag the need for human rights and environmental risk analysis.
Prepare your annual BAFA report. You must answer BAFA's questionnaire completely and truthfully within four months of fiscal year-end. Plan for the seven-year publication requirement on your website.
Compare your LkSG program against France's Duty of Vigilance Law, the UK Modern Slavery Act, and California's Transparency in Supply Chains Act. If you operate across these jurisdictions, you need a unified approach that meets the strictest requirements.
Cross-reference your controls:
If you're implementing ISO 27001 Annex A.5.19 (information security in supplier relationships), extend your due diligence to human rights and environmental criteria. If you're subject to DORA's ICT third-party risk requirements, integrate human rights into your vendor risk assessments rather than maintaining separate programs.




