German Supply Chain Due Diligence Act (LkSG)
LkSG: Section 7 Indirect Supplier DD + Substantiated Knowledge Trigger + Section 8 Remedial Action

German Supply Chain Due Diligence Act (LkSG) LkSG-Sec7-IndirectSupplier-Sec8-Remedial: Section 7 Indirect Supplier DD + Substantiated Knowledge Trigger + Section 8 Remedial Action

LkSG Sections 7-8 - indirect supplier due diligence + remedial action. SECTION 7 INDIRECT SUPPLIER DUE DILIGENCE: full due diligence NOT REQUIRED at outset for indirect suppliers; instead, RISK-BASED + SUBSTANTIATED KNOWLEDGE-TRIGGERED approach. SUBSTANTIATED KNOWLEDGE (Sec.9(3)): factual indications of human rights or environmental risks at indirect suppliers including: media reports + NGO investigations + audit findings + supplier-self-reports + government findings + whistleblower reports + civil society reports; once substantiated knowledge is triggered + the company must conduct RISK ANALYSIS of the indirect supplier + take PREVENTIVE + REMEDIAL ACTION + reflect findings in policy + reporting. INDIRECT SUPPLIER MEASURES: cascading contractual obligations through direct suppliers + multi-stakeholder initiatives + sector-collaboration + industry programs (e.g. amfori BSCI + SAI SA8000 + Sedex SMETA + Fair Wear Foundation) + capacity-building. SECTION 8 REMEDIAL ACTION: for ACTUAL or IMMINENT VIOLATIONS in (a) OWN BUSINESS - cessation + correction + concrete remedial steps with timelines; (b) DIRECT SUPPLIERS - same with extended timelines + escalation including supplier relationship suspension or termination as last resort; (c) INDIRECT SUPPLIERS - reasonable measures including direct engagement + sector collaboration + grievance processing. REMEDIAL TIMELINES: typically 3-12 months depending on severity + with concrete milestones + monitoring.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 104 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • AQAP2110-1 Quality Management System Aligned to ISO 9001 plus NATO Supplementary Requirements
  • AQAP2110-2 Government Quality Assurance Representative (GQAR) Authority and Access
  • AQAP2110-6 Subcontractor Supply Chain Control plus Counterfeit Material Prevention
  • AQAP2110-7 Production, Special Processes, Inspection, Testing, and Records
  • AQAP2110-8 Internal Audit, Management Review, Corrective Action, CofC, and Continual Improvement
  • ISO-20400-6.5 Monitoring and continuous improvement
  • ISO-20400-7.3 Supplier selection
  • ISO-20400-7.4 Contract management and review
  • ISO-20400-7.5 Reviewing and learning

ISO/IEC 27003:2017 · 4 controls

API 1164 · 3 controls

  • API1164-21 TSA Pipeline Security Directive Alignment
  • API1164-22 Configuration management for OT systems
  • API1164-23 Change management procedures
  • IATF16949-Clause10-Improvement-Nonconformity-CorrectiveAction-Problem-ErrorProof IATF 16949 Clause 10 - Improvement + Nonconformity + Corrective Action + Problem Solving + Error Proofing + Continual Improvement
  • IATF16949-Clause4-Context-Scope-CustomerSpecific-ProductSafety IATF 16949 Clause 4 - Context of Organization + QMS Scope + Customer Specific Requirements + Product Safety
  • IATF16949-Clause8-Supplier-QMS-Development-Externally-Provided IATF 16949 Clause 8 Supplier - Control of Externally Provided Processes + Type and Extent + Supplier QMS Development

IEC 62443 · 3 controls

  • IEC62443-21 Supply chain risk management for critical components
  • IEC62443-22 Configuration management for OT systems
  • IEC62443-23 Change management procedures

IEEE 1686 · 3 controls

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills
  • IEEE1686-Section5.5-5.6-5.7-5.8-Firmware-ConfigSW-TimeSync-DataAtRest IEEE 1686 Section 5.5-5.8 - Firmware Quality + Configuration Software Security + Time Synchronisation + Data Protection at Rest + Patch + Malware + Hardening + Vulnerability
  • IEEE1686-SupplyChain-Documentation-Procurement-ComplianceTable-Physical IEEE 1686 Section 6 IED Security Documentation + Supply Chain + Procurement Specification + Appendix A Compliance Table + Physical and Tamper
  • A.1 Point-of-Care Testing Additional Requirements
  • ISO-15189-6.8 Externally provided products and services
  • ISO-15189-8.1 General requirements

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-22 Configuration management for OT systems
  • ISO27019-23 Change management procedures
  • ISO27019-24 Vulnerability assessment for critical systems
  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AS9100D-10.2 Nonconformity and Corrective Action
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • IEC62304-4.1 Quality Management System
  • IEC62304-9.6 Analyze Problems for Trends
  • ISO28001-PC-03 Supply Chain Incident Reporting
  • ISO28001-PC-04 Supply Chain Continuity Planning
  • ISO-41001-10.1 Nonconformity and corrective action
  • ISO-41001-8.4 Control of outsourced processes and services
  • ISO-17025-8.1 Options
  • ISO-17025-8.7 Corrective actions
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • DSOMM-4 Test and Verification - SAST, DAST, IAST, SCA, Penetration Testing
  • 2.5.2 Verification Activities
  • 2.7.2 Food Fraud Plan

SWIFT CSCF · 2 controls

  • SWIFTCSCF-1 Restrict Internet Access and Protect Critical Systems (Objective 1)
  • SWIFTCSCF-3 Physically Secure the Environment (Objective 3)

South Korea ISMS-P · 2 controls

  • ISMSP-MS-04 Management Review and Improvement
  • ISMSP-PI-03 Third-Party Provision and Outsourcing
  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • ACQS-8-3 Continuous Improvement
  • Clause 3 Suppliers and service providers
  • ACQ.4 Supplier Monitoring
  • DIQ-2 Data Quality Management
  • IS.AR.210 Findings and Corrective Actions
  • CJIS-19 Supply Chain Risk Management
  • Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A)
  • GGAP-IFA-AllFarmBase-Mgmt-Workers-Env-Trace GLOBALG.A.P. IFA v6 All Farm Base (AF): Management, Workers, Environment, Traceability and Food Safety
  • ICAO-ANX17-Chap3-QualityControl-Audits-Inspections-Tests-Certification-Training ICAO Annex 17 Chapter 3 - National Quality Control Programme + Audits + Inspections + Tests + Surveys + Certification + Aviation Security Training Programme (ASTP)
  • IMO-MSC-FAL-Recover-BackupRestore-ContinuityOfNavigation-LessonsLearned-Drills IMO MSC-FAL Recover Function - Backup and Restore + Continuity of Navigation + Continuity of Cargo Operations + Continuity of Propulsion + Lessons Learned + Drills + Resilience
  • IRM-RiskCategories-Strategic-Financial-Operational-Knowledge-FOIL-External-Internal-DownsideUpside IRM Four Risk Categories - Strategic + Financial + Operational + Knowledge + FOIL Typology + External vs Internal + Downside Threats and Upside Opportunities + Risk Universe
  • ISO-14064-1-8 Quality management of the GHG inventory

ISO 22316 · 1 control

  • ISO22316-14 Supply chain continuity

ISO 26000:2010 · 1 control

  • ISO-26000-6.6 Fair operating practices

ISO 30401 · 1 control

  • ISO30401-15 Nonconformity and corrective action
  • ISO-39001-10.1 Nonconformity and corrective action
  • ISO-50001-8.3 Procurement

ISO 56002 · 1 control

  • ISO-56002-10.2 Deviation, nonconformity and corrective action

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.6 AI System Security

ISO/IEC 27010:2015 · 1 control

  • 27010-15.1 Incident Management

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27014:2020 · 1 control

  • 27014-5.6 Continuous improvement

ISO/TS 22317:2021 · 1 control

  • ISO22317-14 Supply chain continuity

ISO/TS 22318:2021 · 1 control

  • ISO22318-14 Supply chain continuity
  • ITAR-CompliancProgram-ICP-EmpoweredOfficial-Recordkeeping-5Years-Training-IT-Cloud-SupplyChain-Coord-EAR-OFAC-Wassenaar ITAR Compliance Program + Internal Compliance Program (ICP) + Empowered Official + 5-Year Recordkeeping + Training + IT/Cloud (GovCloud + Azure Gov + GCC High) + Supply Chain + Coord EAR + OFAC + Wassenaar + MTCR
  • OWASPLLM-4 Supply Chain and Vector/Embedding Weaknesses (LLM03 + LLM08)

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-3 A03:2025 Injection Including Cross-Site Scripting
  • AODACAN-2 Accessible Procurement of Goods, Services, Facilities
  • IM8-TPM.4 Supply Chain Risk Management
  • USMCADIGITAL-4 Government Data, Cybersecurity, Interoperability
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 104 it maps to, and the evidence behind each claim, over MCP and REST.