Blog

Supply Chain Act (LkSG): Obligations and Current Status

Janina Schmieds
Product Manager, Compliance College, Haufe Akademie
Reading time: 5 min
LKSG
On this page
table of contents

The Supply Chain Due Diligence Act requires larger companies to systematically address human rights and certain environmental risks in their supply chains. As of September 2026, the LkSG will remain in effect. However, there are discrepancies between the published text of the law, current administrative practice, and an ongoing legislative process regarding reporting requirements. This article clarifies what companies need to know now and how they should implement these requirements within their organizations.

Share this article

What is the Supply Chain Due Diligence Act?

The Supply Chain Due Diligence Act—known as the LkSG for short and often referred to as the Supply Chain Act—is a German law governing corporate due diligence in supply chains. It requires covered companies to establish appropriate processes to identify, prevent, minimize, or put an end to human rights violations and certain environmental risks.

The LkSG does not guarantee a completely risk-free supply chain. The decisive factor is whether a company effectively implements the risk-based and appropriate measures required by law. Key factors include the nature and scope of business activities, the company’s ability to exert influence, the severity and likelihood of a violation, and the company’s own contribution to the cause. These principles are set forth in Section 3 of the LkSG.

LkSG Update: What Will Apply in September 2026?

To ensure a reliable classification, three levels must be distinguished:

  1. Applicable Law: The LkSG remains in effect. In addition to operational due diligence obligations, the published text of the law also contains documentation and reporting requirements.
  2. Current administrative practice: The Federal Office for Economic Affairs and Export Control (BAFA) does not currently review corporate reports. The Federal Ministry for Economic Affairs has also urged the agency to exercise restraint in imposing sanctions; fines are to be focused on particularly serious human rights violations.
  3. Proposed Legislative Change: A bill proposes to retroactively eliminate the reporting requirement and narrow the scope of offenses subject to fines. Until the legislative process is complete and the amendment is officially enacted, this bill must not be treated as current law.

In practice, this means that companies should continue their operational due diligence processes. The temporary suspension of report reviews does not generally waive risk management, preventive and corrective measures, complaint procedures, or documentation requirements. Legal and compliance officers should closely monitor the progress of the legislative process. Official information is available from the Federal Ministry of Labor regarding the amendment bill and the notice on current BAFA practice.

To which companies does the LkSG apply?

Effective January 1, 2024, the law generally applies to companies that have their head office, principal place of business, administrative headquarters, or statutory seat in Germany and employ at least 1,000 workers in Germany. The law also applies to domestic branches of foreign companies if they meet the employee threshold.

Certain special considerations must be taken into account when performing the calculation: For affiliated companies as defined by law, the number of employees working in Germany at all group companies is included in the parent company’s count. Temporary workers are included if their assignment lasts longer than six months. Details are governed by § 1 LkSG.

In case of doubt, a legal review should be conducted to determine whether a company actually falls under the scope of the law. The threshold alone does not answer every question—for example, in cases involving corporate group structures, branch offices, or fluctuating employee numbers.

What risks does the LkSG cover?

The law addresses human rights and certain environmental risks. These include, for example, child labor, forced labor, violations of occupational safety and health standards, violations of the right to freedom of association, discrimination, the withholding of fair wages, and certain environmental hazards related to mercury, persistent organic pollutants, and hazardous waste.

Environmental impacts may also be relevant if they affect protected human rights—for example, when harmful changes to the soil, water pollution, air pollution, excessive water consumption, or noise impair the natural foundations of life. The legal definitions and protected legal rights are set forth in § 2 of the LkSG.

What due diligence obligations does the LkSG require?

The LkSG groups the requirements into nine categories of obligations. Companies must:

  1. establish an appropriate and effective risk management system,
  2. define an internal responsibility,
  3. conduct regular and ad hoc risk analyses,
  4. issue a policy statement on its human rights strategy,
  5. Embed preventive measures within our own business unit and with regard to direct suppliers,
  6. take corrective action in the event of actual or imminent violations,
  7. establish a grievance procedure,
  8. Observe due diligence obligations regarding risks posed by indirect suppliers and
  9. document compliance with due diligence obligations and report on them in accordance with the applicable law.

These responsibilities are interlinked: A risk analysis without clear lines of responsibility has little impact; similarly, a statement of principles without operational measures is insufficient. The system should therefore be designed as an ongoing management process, not as a one-time assessment.

Own business unit, direct and indirect suppliers

The scope of a specific obligation also depends on where in the supply chain a risk arises.

Range What does that mean? Key Requirements
Separate Business Unit The company’s own activities aimed at achieving its corporate objective; in the case of parent companies, this may include group companies over which the parent exercises a controlling influence. Regular and situation-specific risk assessments, preventive measures, and, in the event of injuries, immediate corrective action as a matter of principle.
Direct suppliers Contractual partners whose supplies are necessary for the manufacture of the product or the provision and use of the service in question. Regular risk analysis and appropriate preventive and corrective measures; contractual assurances alone are not sufficient.
Secondary Suppliers Companies with which there is no direct contractual relationship, but whose supplies are nevertheless necessary for the product or service. If there are concrete indications that a violation may have occurred, a situation-specific risk analysis, preventive measures, and a plan to prevent, stop, or minimize the violation are required.

For indirect suppliers, the law therefore does not require identical, comprehensive monitoring of all lower levels of the supply chain. In particular, “substantiated knowledge” is the decisive factor. The details are governed by § 9 LkSG.

What does the LkSG mean for small and medium-sized businesses?

Small and medium-sized enterprises that fall below the statutory employee threshold are not direct recipients of the LkSG solely for that reason. However, they may be indirectly affected as suppliers if a covered enterprise requests information, documentation, or cooperation regarding preventive measures.

Large customers may not indiscriminately transfer their own legal obligations to suppliers. Requests and contractual requirements should be risk-based, reasonable, and tailored to the specific business relationship. SMEs should therefore neither accept every far-reaching standard clause without scrutiny nor ignore legitimate requests. It is advisable to establish clear responsibilities, provide reliable information on one’s own risks and measures, and conduct a documented review of the required commitments. The BAFA guidelines on cooperation in the supply chain offer guidance.

Putting the LkSG into Practice: A Possible Process

The specific structure depends on the business model, industry risks, procurement structure, and opportunities for influence. In many companies, the following sequence has proven effective:

  1. Clarify responsibilities and governance: Define roles and responsibilities within senior management, procurement, compliance, sustainability, human resources, and operational units. The human rights officer oversees risk management; senior management must be briefed at least once a year.
  2. Structuring the supply chain and database: Record your own locations, direct suppliers, product categories, countries, services, and known lower-level supply chain stages in a traceable manner.
  3. Identify, weight, and prioritize risks: Link abstract industry and country risks to specific company and supplier data. When prioritizing, consider severity, probability, impact, and your own contribution.
  4. Embedding Prevention: Align procurement strategies, selection processes, contract drafting, controls, supplier development, and internal guidelines with prioritized risks.
  5. Organizing Complaints and Remedies: Establish confidential, accessible reporting channels and define in advance how reports will be investigated, how those affected will be protected, and how violations will be stopped or minimized.
  6. Assess effectiveness and make adjustments: Review measures at least once a year and as needed, document the results, and adapt processes in response to new risks or insufficient effectiveness.

A common mistake is to collect as much supplier data as possible without first defining what decisions are to be made based on that data. A risk-based approach sets priorities and links each query to a clear audit or control objective.

What role do training programs play at LkSG?

Training is not merely an add-on to risk management. Section 6 of the LkSG explicitly lists training and continuing education as possible preventive measures—both within relevant areas of the company’s own operations and for the implementation of contractual assurances by direct suppliers.

Training programs are most effective when they are role-specific. For example, the purchasing department needs criteria for making risk-based supplier decisions; complaint handling departments need secure processes and escalation procedures; managers must understand their responsibilities; and employees in particularly relevant areas should be able to recognize warning signs. Content, target audiences, and learning assessments should be derived from the risk analysis and reviewed regularly.

Digital learning resources can support this training. The “Compliance College ” (Compliance Academy) at Haufe Akademie brings together learning content on topics such as compliance, sustainability, and the LkSG, among others. Whether and how a particular resource is used should be based on the company’s specific roles, risks, and existing processes.

Inspection by the BAFA and Possible Sanctions

The BAFA monitors compliance with the LkSG and, for this purpose, may request information and documents, order corrective measures, and enter business premises. The agency takes a risk-based approach and may also take action in response to requests from affected individuals.

The published text of the law provides for fines of up to eight million euros for certain violations. For companies with an average annual revenue of more than 400 million euros, certain violations may result in a revenue-based fine of up to two percent of average global annual revenue. Under the conditions specified by law, exclusion from public procurement for up to three years may also be considered.

These statutory limits must be distinguished from current enforcement practices. Regulatory restraint does not automatically alter the body of law. Companies should therefore not conclude that their obligations have ceased to exist simply because there has been a reduction in inspections or sanctions.

LkSG and CSDDD: What are the differences between the regulations?

The EU Supply Chain Directive ( CSDDD ) establishes a European framework for corporate due diligence obligations. It was significantly amended again in 2026. Member states must transpose the new version into national law by July 26, 2028; the directive is scheduled to apply to companies starting in July 2029. For German practice, therefore, it is crucial how the legislature adapts the LkSG to the European requirements.

Aspect LkSG – As of September 2026 CSDDD following the 2026 amendment
Scope of Application As a general rule, at least 1,000 employees within the country; additional requirements under § 1 LkSG. Generally, more than 5,000 employees and more than 1.5 billion euros in global net revenue; special rules apply.
Risk-Based Approach Appropriate measures throughout one's own business unit, as well as among direct suppliers and, under certain conditions, indirect suppliers. Focus on areas where negative impacts are most likely and most severe; requirements for information requests should limit the ripple effect on smaller business partners.
Climate Plan The LkSG does not establish a separate requirement for a climate transition plan. The previously mandated requirement for a climate transition plan was eliminated in 2026.
Civil Liability The LkSG does not in and of itself give rise to civil liability; any liability that exists independently of it remains unaffected. The EU-wide harmonized liability rules have been removed; the respective national liability rules remain applicable.
Schedule In effect; a German amendment bill is currently going through the legislative process. Transposition into national law by July 26, 2028; application to companies beginning in July 2029.

The CSDDD is therefore not generally “stricter” or “weaker” than the LkSG. Their scope of application, reference to value chains, regulatory oversight, liability, and sanctions differ in their structure. The Council of the European Union provides a current summary of the final amendments; the binding text is published in Directive (EU) 2026/470.

Challenges and Criticism in Practice

The LkSG is intended to strengthen human rights and certain environmental concerns in global supply chains. However, companies face practical limitations in implementing it: information from lower levels of the supply chain is often incomplete, the extent to which companies can exert influence varies depending on their market position, and standardized questionnaires can place a heavy burden on smaller suppliers in particular.

Criticism is also directed at bureaucratic costs, legal uncertainty, and overlaps with European sustainability requirements. Conversely, human rights and environmental organizations warn against reducing reporting requirements, oversight, and liability mechanisms to such an extent that those affected are left with less protection. For companies, the main takeaway is this: A proportionate system requires clear priorities, reliable responsibilities, and demonstrably effective measures rather than purely formal documentation.

Due diligence processes remain relevant

As of September 2026, the LkSG will continue to apply to companies within its statutory scope. Even though reports are not currently being reviewed and a legislative amendment is planned, the operational due diligence processes remain at the core of the law. Companies should therefore not suspend their risk analysis, prevention, remedial action, complaint procedures, and effectiveness monitoring.

At the same time, it’s worth taking a closer look at future legislation: The German reform is not yet complete, and the amended CSDDD must be transposed into national law by 2028. Those who design existing processes in a risk-based, role-based, and traceable manner will create a solid foundation for both sets of regulations.

FAQ

What is the LkSG, in simple terms?

The Supply Chain Due Diligence Act requires larger companies to systematically identify and appropriately address human rights and certain environmental risks in their supply chains. It mandates an effective procedure but does not guarantee that every violation will be prevented.

To which companies does the LkSG apply?

The LkSG generally applies to companies with their registered office or principal place of business in Germany and at least 1,000 employees in Germany. Domestic branches of foreign companies may also be covered. Special counting rules apply to corporate groups and temporary staffing arrangements.

Does the LkSG also apply to SMEs?

SMEs that fall below the employee threshold are generally not direct recipients of the LkSG. As suppliers, however, they may still receive inquiries or contractual requirements from covered customers. Such requirements should be risk-based, proportionate, and tailored to the specific business relationship.

What due diligence obligations does the LkSG require?

The law lists nine categories of obligations: risk management, internal responsibility, risk analysis, policy statement, preventive measures, corrective measures, complaint procedures, obligations regarding indirect suppliers, and documentation and reporting in accordance with the applicable statutory provisions.

What are the current requirements for LkSG reporting?

As of September 2026, the published text of the law still includes a reporting requirement. However, the BAFA is not currently reviewing reports. A draft bill provides for the retroactive elimination of the reporting requirement; until the legislative process is completed, this change is not yet law.

What is the difference between LkSG and CSDDD?

The LkSG is a current German law and generally applies to companies with 1,000 or more employees in Germany. The EU CSDDD Directive, as amended in 2026, generally applies to significantly larger companies with more than 5,000 employees and global net revenue exceeding 1.5 billion euros. It must be implemented at the national level by July 2028 and is scheduled to take effect for companies starting in July 2029.

Janina Schmieds
Product Manager, Compliance College, Haufe Akademie
With a clear focus on innovative learning solutions, Janina, as Product Manager for Compliance College Haufe Akademie , is driving Haufe Akademie expansion of the portfolio and the further development of modern features and services. Her goal: to design learning programs that provide companies with efficient and practical support for training.
Key topics:
Compliance & sustainability
-
Adaptive learning
-
Mandatory Training & Processes
-
All articles by
Janina Schmieds