German Supply Chain Due Diligence Act (LkSG)
LkSG: Section 9 Complaints Procedure + Whistleblower Protection + Section 10 Documentation + Annual Report

German Supply Chain Due Diligence Act (LkSG) LkSG-Sec9-Complaints-Sec10-Doc-Report: Section 9 Complaints Procedure + Section 10 Documentation + Annual Reporting

LkSG Sections 9-10 - complaints + documentation + reporting. SECTION 9 COMPLAINTS PROCEDURE: company must establish or participate in an APPROPRIATE COMPLAINTS PROCEDURE accessible to (a) individuals affected by human rights or environmental risks/violations in own business + supply chain; (b) employees; (c) workers in supply chain; (d) civil society + NGOs + journalists + advocates. PROCEDURE REQUIREMENTS: (i) RULES OF PROCEDURE published + transparent + fair + bias-free + confidential; (ii) ACCESSIBILITY in multiple languages relevant to supply chain + via multiple channels (web + phone + email + paper + in-person); (iii) CONFIDENTIALITY + PROTECTION against retaliation against complainants + whistleblower-protection-law alignment; (iv) ACKNOWLEDGEMENT + STATUS-UPDATES + RESPONSE within defined timelines; (v) DOCUMENTATION + tracking + trend analysis. WHISTLEBLOWER PROTECTION: Sec. 9 alignment with EU Whistleblower Directive 2019/1937 + German Hinweisgeberschutzgesetz (HinSchG) of 2 July 2023 (effective 2 July 2023 + for >50 employees 17 December 2023). SECTION 10 DOCUMENTATION + REPORTING: (a) DOCUMENTATION of due diligence including risk analysis + preventive + remedial measures + complaints + reviews + retained 7+ years; (b) ANNUAL REPORT to BAFA + on company website (free + publicly accessible) within 4 months of fiscal year end; must address: identified risks + measures taken + measures planned + complaints received + complaints handling + outcomes + escalations + supplier changes. BAFA SUBMISSION PORTAL launched 2023; reports indexed + made publicly searchable.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 22 controls across 17 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 26000:2010 · 3 controls

  • ISO-26000-6.3.1 Due diligence
  • ISO-26000-6.3.2 Human rights risk situations
  • ISO-26000-6.3.3 Avoidance of complicity
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-4.3 Core subjects of sustainable procurement

API 1164 · 1 control

  • API1164-18 Field Device Security
  • BB-DPA-22 Sections 70-75 - Commissioner Functions
  • ICP-20 Public Disclosure
  • ICMM-MP-P3-P4-HumanRights-RiskMgmt-UNGP-DueDiligence ICMM Mining Principles 3 + 4 - Human Rights (UNGPs Alignment) + Risk Management + Due Diligence

IEC 62443 · 1 control

  • IEC62443-18 Reporting obligations to authorities

IEEE 1686 · 1 control

  • IEEE1686-IR-Recovery-Reporting-Exercises-Drills-RECOV IEEE 1686 - Incident Response + Recovery from Failed Update + Reporting to Authorities + Coordination with Sector-Specific Agencies + Exercises and Drills

ISO/IEC 27019:2024 · 1 control

  • ISO27019-18 Reporting obligations to authorities
  • NGCB-1 Regulation 5.260 Scope, Applicability, and Licensee Categories
  • OECDMNE-1 Concepts and General Policies, Risk-Based Due Diligence Framework
  • UAEVARA-1 Activity Licensing (Advisory, Exchange, Custody, Broker-Dealer, etc.)
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 22 it maps to, and the evidence behind each claim, over MCP and REST.