LkSG Sections 7-8 - indirect supplier due diligence + remedial action. SECTION 7 INDIRECT SUPPLIER DUE DILIGENCE: full due diligence NOT REQUIRED at outset for indirect suppliers; instead, RISK-BASED + SUBSTANTIATED KNOWLEDGE-TRIGGERED approach. SUBSTANTIATED KNOWLEDGE (Sec.9(3)): factual indications of human rights or environmental risks at indirect suppliers including: media reports + NGO investigations + audit findings + supplier-self-reports + government findings + whistleblower reports + civil society reports; once substantiated knowledge is triggered + the company must conduct RISK ANALYSIS of the indirect supplier + take PREVENTIVE + REMEDIAL ACTION + reflect findings in policy + reporting. INDIRECT SUPPLIER MEASURES: cascading contractual obligations through direct suppliers + multi-stakeholder initiatives + sector-collaboration + industry programs (e.g. amfori BSCI + SAI SA8000 + Sedex SMETA + Fair Wear Foundation) + capacity-building. SECTION 8 REMEDIAL ACTION: for ACTUAL or IMMINENT VIOLATIONS in (a) OWN BUSINESS - cessation + correction + concrete remedial steps with timelines; (b) DIRECT SUPPLIERS - same with extended timelines + escalation including supplier relationship suspension or termination as last resort; (c) INDIRECT SUPPLIERS - reasonable measures including direct engagement + sector collaboration + grievance processing. REMEDIAL TIMELINES: typically 3-12 months depending on severity + with concrete milestones + monitoring.
Maintained by Gerard Blokdyk·Verified against the published standard ·Control text last updated
What else in your programme already covers this
This control maps to 104 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety
IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development
GS1-EPCIS-CBV-EventBasedDataSharing GS1 EPCIS (Electronic Product Code Information Services) and CBV (Core Business Vocabulary) Event-Based Data Sharing