LkSG Sections 4-5 - risk management system + risk analysis. SECTION 4 RISK MANAGEMENT SYSTEM: companies must establish an APPROPRIATE + EFFECTIVE risk management system to identify + prevent + mitigate + remediate human rights and environmental risks arising from own business operations + direct suppliers + (where substantiated knowledge) indirect suppliers; the system must be PROPORTIONATE + COMMENSURATE WITH the company's specific risk profile + size + sector + geographies. IN-HOUSE RESPONSIBILITY (Section 4(3)): companies must designate a HUMAN RIGHTS OFFICER or equivalent position with DIRECT REPORTING to senior management + adequate resources + independence + cross-functional authority. SECTION 5 RISK ANALYSIS (Annual + Ad-hoc): (a) ANNUAL risk analysis covering own business + direct suppliers; (b) AD-HOC analysis whenever new product + new business activity + new geography + substantial change + substantiated knowledge of risks; (c) WHEN: priority on high-risk geographies + sectors + commodities; (d) METHODOLOGY: identify + assess likelihood + severity + irreversibility + own contribution to risk; (e) RESULTS feed into POLICY STATEMENT (Sec.6) + PREVENTIVE MEASURES (Sec.6) + REMEDIAL ACTION (Sec.8) + COMPLAINTS PROCEDURE (Sec.9) + REPORTING (Sec.10). DATA SOURCES: industry intelligence + NGO reports + supplier surveys + audits + grievance data + government reports.
This control maps to 213 controls across 105 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 213 it maps to, and the evidence behind each claim, over MCP and REST.