German Supply Chain Due Diligence Act (LkSG)
LkSG: Section 4 Risk Management System + Section 5 Annual Risk Analysis

German Supply Chain Due Diligence Act (LkSG) LkSG-Sec4-RiskMgmt-Sec5-RiskAnalysis: Section 4 Risk Management System + Section 5 Annual Risk Analysis

LkSG Sections 4-5 - risk management system + risk analysis. SECTION 4 RISK MANAGEMENT SYSTEM: companies must establish an APPROPRIATE + EFFECTIVE risk management system to identify + prevent + mitigate + remediate human rights and environmental risks arising from own business operations + direct suppliers + (where substantiated knowledge) indirect suppliers; the system must be PROPORTIONATE + COMMENSURATE WITH the company's specific risk profile + size + sector + geographies. IN-HOUSE RESPONSIBILITY (Section 4(3)): companies must designate a HUMAN RIGHTS OFFICER or equivalent position with DIRECT REPORTING to senior management + adequate resources + independence + cross-functional authority. SECTION 5 RISK ANALYSIS (Annual + Ad-hoc): (a) ANNUAL risk analysis covering own business + direct suppliers; (b) AD-HOC analysis whenever new product + new business activity + new geography + substantial change + substantiated knowledge of risks; (c) WHEN: priority on high-risk geographies + sectors + commodities; (d) METHODOLOGY: identify + assess likelihood + severity + irreversibility + own contribution to risk; (e) RESULTS feed into POLICY STATEMENT (Sec.6) + PREVENTIVE MEASURES (Sec.6) + REMEDIAL ACTION (Sec.8) + COMPLAINTS PROCEDURE (Sec.9) + REPORTING (Sec.10). DATA SOURCES: industry intelligence + NGO reports + supplier surveys + audits + grievance data + government reports.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 213 controls across 105 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27005 · 6 controls

ISO 31000 · 6 controls

ISO/IEC 23894:2023 · 6 controls

  • CPS230-11 Identification, Assessment and Management of Operational Risk
  • CPS230-16 Internal Audit Review of the Business Continuity Plan
  • CPS230-37 Service Provider Management Policy
  • CPS230-46 Ongoing Risk Management of Each Material Arrangement

Japan AI Guidelines · 4 controls

API 1164 · 3 controls

BSI IT-Grundschutz · 3 controls

  • BSI-13 Risk assessment procedures
  • BSI-15 Security categorization
  • BSI-17 Continuous monitoring strategy
  • FFIEC-03 Risk appetite and tolerance for IT risk
  • FFIEC-18 Ongoing monitoring and assessment
  • FFIEC-20 Exit strategy and transition planning

IEC 62443 · 3 controls

IEEE 1686 · 3 controls

ISO 26000:2010 · 3 controls

ISO 27019 · 3 controls

ISO/IEC 27003:2017 · 3 controls

ISO/IEC 29134:2023 · 3 controls

  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • NGCB-5 Technical Security Controls - Access + Network + Encryption + Vulnerability + Logging
  • NGCB-8 Annual Independent Cybersecurity Assessment + Reporting + Board Oversight
  • CRM-1 AML/CFT Compliance
  • CRM-3 Risk Management Framework
  • CRM-4 Business Risk Assessment

APRA CPS 234 · 2 controls

  • CPS234-16 Assessment of Related Party and Third Party Capability
  • CPS234-20 Information Asset Classification
  • ICP-16 Enterprise Risk Management for Solvency Purposes
  • ICP-8 Risk Management and Internal Controls

IEEE 7000 · 2 controls

ISO/IEC 27014:2020 · 2 controls

  • NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment
  • NISTPF-2 Govern-P - Governance Policies, Risk Management Strategy, Awareness Training, and Monitoring
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • OCCHS-3 Risk Appetite Statement, Risk Limits, Concentration Risk, and Limit Breach Protocols
  • OCCHS-7 Risk Data Aggregation, Reporting, Talent, Compensation, and Strategic Planning
  • ASTWO-1 Audit Planning, Scaling, Risk Assessment, and Integration
  • ASTWO-3 Entity-Level Controls and Period-End Financial Reporting Process
  • 2.4.4 Hazard Analysis and Risk Assessment
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CH-FADP-21 Data protection impact assessments
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • 4.3.1 Risk Assessment and Impact Analysis

Bahrain PDPL · 1 control

  • BB-DPA-20 Sections 50-60 - Registration and Responsibilities

GDPR · 1 control

GLBA · 1 control

  • CBPR-9-APEC-Privacy-Principles Global CBPR Forum: 9 APEC Privacy Principles (Notice + Collection + Uses + Choice + Integrity + Security + Access + Accountability + Preventing Harm)

HKMA SPM · 1 control

ISMAP (Japan) · 1 control

ISO 13485 · 1 control

  • ISO13485-06 Security management process and risk analysis

ISO 22000 · 1 control

ISO 22320:2018 · 1 control

ISO 27017 · 1 control

ISO 27018 · 1 control

ISO 27799 · 1 control

  • ISO27799-06 Security management process and risk analysis

ISO 45001 · 1 control

ISO/IEC 27031:2011 · 1 control

ISO/IEC 29147:2018 · 1 control

  • 29147-5.11 Researcher Safe Harbour and Legal Posture

India DPDP Act · 1 control

Indonesia PDP Law · 1 control

LGPD · 1 control

Liechtenstein DPA · 1 control

  • OECDMNE-1 Concepts and General Policies, Risk-Based Due Diligence Framework
  • AUPRV-6 Sensitive Information, PIA, Privacy by Design, Children
  • PSPF24-1 Security Culture, Governance, Risk Management
  • AIGF-1.1 Risk Management and Internal Controls

South Korea PIPA · 1 control

Turkey KVKK · 1 control

  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 213 it maps to, and the evidence behind each claim, over MCP and REST.