Back to Frameworks

German Supply Chain Due Diligence Act (LkSG)

Germany
v2023
7 domains
11 controls

The Lieferkettensorgfaltspflichtengesetz (LkSG, German Supply Chain Due Diligence Act) was enacted 22 July 2021 + entered into force 1 January 2023 for companies with MORE THAN 3,000 EMPLOYEES + 1 January 2024 for companies with MORE THAN 1,000 EMPLOYEES (including German branches of foreign entities). The Act establishes statutory HUMAN RIGHTS + ENVIRONMENTAL DUE DILIGENCE OBLIGATIONS in supply chains. SCOPE: covers (a) the company's OWN OPERATIONS; (b) DIRECT SUPPLIERS - full due diligence required; (c) INDIRECT SUPPLIERS - risk-based + SUBSTANTIATED KNOWLEDGE-triggered due diligence (not full due diligence at outset). KEY STATUTORY DUTIES (sections 4-10 of LkSG): (1) RISK MANAGEMENT SYSTEM with appropriate + effective procedures; (2) IN-HOUSE RESPONSIBILITY - designated human rights officer or equivalent with direct reporting to senior management; (3) RISK ANALYSIS - annual + ad-hoc + covering own business + direct suppliers + (if substantiated knowledge) indirect suppliers; (4) POLICY STATEMENT - human rights strategy + senior management commitment; (5) PREVENTIVE MEASURES - integrating human rights into business processes + training + supplier commitments + contractual obligations + audit rights; (6) REMEDIAL ACTION - for actual + imminent violations in own operations + direct suppliers; (7) COMPLAINTS PROCEDURE - accessible + confidential + bias-free + with rules of procedure; (8) DOCUMENTATION OF DUE DILIGENCE; (9) ANNUAL REPORT to BAFA + on the company's website. PROTECTED LEGAL POSITIONS: human rights covered include forced labour + child labour + slavery + discrimination + freedom of association + collective bargaining + occupational health and safety + minimum wage + exclusive land rights + security forces conduct + others. ENVIRONMENTAL OBLIGATIONS: covers specifically Minamata Convention on Mercury + Stockholm Convention on POPs + Basel Convention on Hazardous Waste; broader environmental impacts to the extent they lead to human rights violations. ENFORCEMENT: BAFA (Bundesamt fur Wirtschaft und Ausfuhrkontrolle) - inspection + complaints handling + monitoring + administrative fines + public-procurement exclusion. SANCTIONS: administrative fines up to EUR 8 MILLION + UP TO 2% OF GLOBAL ANNUAL TURNOVER FOR COMPANIES WITH MORE THAN EUR 400 MILLION TURNOVER + PUBLIC PROCUREMENT EXCLUSION UP TO 3 YEARS for significant violations. EU CSDDD COORDINATION: the EU Corporate Sustainability Due Diligence Directive (CSDDD - Directive (EU) 2024/1760) entered into force July 2024 + phased transposition deadlines 2027/2028/2029; EU CSDDD will substantially supersede LkSG + expand to value-chain due diligence + civil liability + alignment expected during 2025-2029 transposition; Germany was central in CSDDD negotiation; some LkSG provisions may be tightened or aligned during transposition.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (7)

LkSG: BAFA Enforcement, EUR 8M + 2% Sanctions, Public Procurement Exclusion

1 controls
Controls in the LkSG: BAFA Enforcement, EUR 8M + 2% Sanctions, Public Procurement Exclusion domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-BAFA-Enforcement-SanctionsBAFA Enforcement, EUR 8M + 2% Sanctions and Public Procurement Exclusion

LkSG: Protected Human Rights + Environmental Risks + EU CSDDD Coordination and 2024-2025 Status

5 controls
Controls in the LkSG: Protected Human Rights + Environmental Risks + EU CSDDD Coordination and 2024-2025 Status domain of German Supply Chain Due Diligence Act (LkSG)5 controls
CodeTitle
LkSG-Coord-Hinweisgeberschutz-SectoralCoordination with German Whistleblower Protection (HinSchG), Sectoral Frameworks and ESG
LkSG-Crosswalk-CSDDD-UNGPs-OECDCrosswalk to EU CSDDD, UN Guiding Principles, OECD MNE Guidelines and German NAP
LkSG-EU-CSDDD-Coordination-StatusEU Corporate Sustainability Due Diligence Directive (CSDDD) Coordination + LkSG 2024-2025 Status
LkSG-HumanRights-Environmental-RisksProtected Human Rights + Environmental Risks (Sections 2(2)-(3))
LkSG-Implementation-Roadmap-OrgLkSG Compliance Program Implementation - Organizational Roles, Tooling and Metrics

LkSG: Scope, Applicability Thresholds, Phased Effective Dates and Group Cascade

1 controls
Controls in the LkSG: Scope, Applicability Thresholds, Phased Effective Dates and Group Cascade domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-Scope-Threshold-GroupCascadeScope, Applicability Thresholds (>3,000 then >1,000 employees) and Group Cascade

LkSG: Section 4 Risk Management System + Section 5 Annual Risk Analysis

1 controls
Controls in the LkSG: Section 4 Risk Management System + Section 5 Annual Risk Analysis domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-Sec4-RiskMgmt-Sec5-RiskAnalysisSection 4 Risk Management System + Section 5 Annual Risk Analysis

LkSG: Section 6 Policy Statement + Preventive Measures (Own + Direct Suppliers)

1 controls
Controls in the LkSG: Section 6 Policy Statement + Preventive Measures (Own + Direct Suppliers) domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-Sec6-Policy-PreventiveSection 6 Policy Statement and Preventive Measures (Own + Direct Suppliers)

LkSG: Section 7 Indirect Supplier DD + Substantiated Knowledge Trigger + Section 8 Remedial Action

1 controls
Controls in the LkSG: Section 7 Indirect Supplier DD + Substantiated Knowledge Trigger + Section 8 Remedial Action domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-Sec7-IndirectSupplier-Sec8-RemedialSection 7 Indirect Supplier DD + Substantiated Knowledge Trigger + Section 8 Remedial Action

LkSG: Section 9 Complaints Procedure + Whistleblower Protection + Section 10 Documentation + Annual Report

1 controls
Controls in the LkSG: Section 9 Complaints Procedure + Whistleblower Protection + Section 10 Documentation + Annual Report domain of German Supply Chain Due Diligence Act (LkSG)1 controls
CodeTitle
LkSG-Sec9-Complaints-Sec10-Doc-ReportSection 9 Complaints Procedure + Section 10 Documentation + Annual Reporting

Your Compliance Coverage

If you comply with German Supply Chain Due Diligence Act (LkSG), you already cover:

Maps to 140 other frameworks

11 total controls
Voluntary Principles on Security and Human Rights (VPs)
4 source controls mapped|1 target controls covered
36%
36%
IEEE 1686
4 source controls mapped|4 target controls covered
36%
ISO 26000:2010
4 source controls mapped|4 target controls covered
36%
ISO 20400:2017 - Sustainable Procurement
4 source controls mapped|7 target controls covered
36%
API 1164
4 source controls mapped|6 target controls covered
36%
ISO 27019
4 source controls mapped|6 target controls covered
36%
IEC 62443
4 source controls mapped|6 target controls covered
36%
UN Guiding Principles on Business and Human Rights (UNGPs)
3 source controls mapped|1 target controls covered
27%
Nevada Gaming Control Board Cybersecurity Requirements
3 source controls mapped|3 target controls covered
27%
ICMM Mining Principles (2024 Update)
3 source controls mapped|1 target controls covered
27%
ICH E6(R3) - Good Clinical Practice
3 source controls mapped|3 target controls covered
27%
Barbados Data Protection Act 2019
3 source controls mapped|2 target controls covered
27%
ISO/IEC 23894:2023
3 source controls mapped|7 target controls covered
27%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
3 source controls mapped|1 target controls covered
27%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
3 source controls mapped|1 target controls covered
27%
IRM Enterprise Risk Management Framework (Institute of Risk Management)
3 source controls mapped|2 target controls covered
27%
IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2)
3 source controls mapped|2 target controls covered
27%
IATF 16949:2016 - Quality Management System for Automotive Production
3 source controls mapped|5 target controls covered
27%
GLOBALG.A.P. Integrated Farm Assurance (IFA) Standard v6
3 source controls mapped|1 target controls covered
27%
ISO 27005
3 source controls mapped|7 target controls covered
27%
ISO 31000
3 source controls mapped|7 target controls covered
27%
ISO 45001
3 source controls mapped|2 target controls covered
27%
EASA Part-IS - Information Security in Aviation
3 source controls mapped|6 target controls covered
27%
APRA CPS 230 Operational Risk Management
3 source controls mapped|6 target controls covered
27%
ISO/IEC 27014:2020
3 source controls mapped|3 target controls covered
27%
ISO 41001:2018 - Facility Management Systems
3 source controls mapped|6 target controls covered
27%
ISO 39001:2012 - Road Traffic Safety Management
3 source controls mapped|6 target controls covered
27%
ISO 22313:2020 - Guidance on Business Continuity Management Systems
3 source controls mapped|6 target controls covered
27%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
3 source controls mapped|5 target controls covered
27%
AS9100D - Aerospace Quality Management System
3 source controls mapped|10 target controls covered
27%
ISO/IEC 27003:2017
3 source controls mapped|10 target controls covered
27%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|5 target controls covered
27%
ISO 22000
3 source controls mapped|2 target controls covered
27%
FBI CJIS Security Policy
3 source controls mapped|2 target controls covered
27%
27%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|2 target controls covered
27%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|3 target controls covered
27%
French Sapin II Law (Law No. 2016-1691)
3 source controls mapped|2 target controls covered
27%
IAIS Insurance Core Principles (ICPs)
2 source controls mapped|3 target controls covered
18%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
2 source controls mapped|1 target controls covered
18%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
2 source controls mapped|2 target controls covered
18%
Turkey KVKK
2 source controls mapped|1 target controls covered
18%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
18%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
2 source controls mapped|2 target controls covered
18%
NIST Privacy Framework
2 source controls mapped|2 target controls covered
18%
Lloyd's of London Cyber Insurance Requirements and Underwriting Standards
2 source controls mapped|2 target controls covered
18%
Liechtenstein DPA
2 source controls mapped|1 target controls covered
18%
LGPD
2 source controls mapped|1 target controls covered
18%
Ley Orgánica de Protección de Datos Personales (LOPDP)
2 source controls mapped|1 target controls covered
18%
Law No. 172-13 on the Protection of Personal Data
2 source controls mapped|1 target controls covered
18%
South Korea PIPA
2 source controls mapped|1 target controls covered
18%
Kentucky Consumer Data Protection Act
2 source controls mapped|1 target controls covered
18%
Japan AI Guidelines
2 source controls mapped|4 target controls covered
18%
Jamaica Data Protection Act 2020
2 source controls mapped|1 target controls covered
18%
ISMAP (Japan)
2 source controls mapped|1 target controls covered
18%
Iowa Consumer Data Protection Act
2 source controls mapped|1 target controls covered
18%
Indonesia PDP Law
2 source controls mapped|1 target controls covered
18%
Indiana Consumer Data Protection Act
2 source controls mapped|1 target controls covered
18%
India DPDP Act
2 source controls mapped|1 target controls covered
18%
India CERT-In Cyber Security Directions 2022
2 source controls mapped|1 target controls covered
18%
IEEE 7000
2 source controls mapped|2 target controls covered
18%
18%
HKMA Cyber Resilience Assessment Framework (C-RAF)
2 source controls mapped|2 target controls covered
18%
Ghana Cybersecurity Act
2 source controls mapped|2 target controls covered
18%
Bahrain PDPL
2 source controls mapped|1 target controls covered
18%
GDPR
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
2 source controls mapped|7 target controls covered
18%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|1 target controls covered
18%
ISO 27018
2 source controls mapped|1 target controls covered
18%
BSI IT-Grundschutz
2 source controls mapped|3 target controls covered
18%
NIST AI Risk Management Framework (AI RMF 1.0)
2 source controls mapped|4 target controls covered
18%
ISO 27017
2 source controls mapped|1 target controls covered
18%
ISO/IEC 29134:2023
2 source controls mapped|3 target controls covered
18%
18%
AWS Well-Architected Security Pillar
2 source controls mapped|1 target controls covered
18%
APPI
2 source controls mapped|1 target controls covered
18%
ISO 13485
2 source controls mapped|1 target controls covered
18%
Azure Security Benchmark
2 source controls mapped|1 target controls covered
18%
IEC 62304:2015 Medical Device Software Lifecycle Processes
2 source controls mapped|4 target controls covered
18%
Aged Care Quality Standards (Australia)
2 source controls mapped|2 target controls covered
18%
ISO/IEC 27031:2011
2 source controls mapped|1 target controls covered
18%
ISO/IEC 29147:2018
2 source controls mapped|1 target controls covered
18%
ISO 27799
2 source controls mapped|1 target controls covered
18%
ISO 26262:2018 - Functional Safety for Road Vehicles
2 source controls mapped|1 target controls covered
18%
AML/CTF Act 2006 (Australia)
2 source controls mapped|2 target controls covered
18%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
2 source controls mapped|1 target controls covered
18%
OWASP Top 10:2025
2 source controls mapped|1 target controls covered
18%
OWASP Top 10 for LLM Applications 2025
2 source controls mapped|1 target controls covered
18%
OWASP DevSecOps Maturity Model (DSOMM)
2 source controls mapped|2 target controls covered
18%
GS1 Global Standards - Supply Chain Traceability and Data Security
2 source controls mapped|2 target controls covered
18%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
2 source controls mapped|2 target controls covered
18%
ISO 22318
2 source controls mapped|1 target controls covered
18%
Automotive SPICE (ASPICE) v4.0 - Process Assessment Model
2 source controls mapped|1 target controls covered
18%
21 CFR Part 211 - Current Good Manufacturing Practice
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27006:2024
2 source controls mapped|1 target controls covered
18%
BRCGS Global Standard for Food Safety Issue 9
2 source controls mapped|3 target controls covered
18%
Space ISAC (Information Sharing and Analysis Center) - Threat Framework
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27011:2024
2 source controls mapped|1 target controls covered
18%
ISO 22317
2 source controls mapped|1 target controls covered
18%
Authorised Economic Operator (AEO) Programmes - Global Standards
2 source controls mapped|2 target controls covered
18%
ISO 22316
2 source controls mapped|1 target controls covered
18%
ISO/IEC 27010:2015
2 source controls mapped|1 target controls covered
18%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
9%
Kids Online Safety Act (KOSA)
1 source controls mapped|1 target controls covered
9%
Protective Security Policy Framework (PSPF) Release 2024
1 source controls mapped|1 target controls covered
9%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|2 target controls covered
9%
HKMA SPM
1 source controls mapped|1 target controls covered
9%
Global Cross-Border Privacy Rules (Global CBPR) Forum
1 source controls mapped|1 target controls covered
9%
GLI-33 - Gaming Laboratories International Event Wagering Systems
1 source controls mapped|1 target controls covered
9%
GLBA
1 source controls mapped|1 target controls covered
9%
BS 65000:2014 - Guidance on Organizational Resilience
1 source controls mapped|2 target controls covered
9%
ISO 37000:2021 - Governance of Organizations
1 source controls mapped|2 target controls covered
9%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
9%
FFIEC IT Examination Handbook
1 source controls mapped|3 target controls covered
9%
APRA CPS 234
1 source controls mapped|3 target controls covered
9%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
1 source controls mapped|2 target controls covered
9%
FFIEC Cybersecurity Assessment Tool (CAT)
1 source controls mapped|2 target controls covered
9%
ISO 22320:2018
1 source controls mapped|1 target controls covered
9%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|3 target controls covered
9%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
9%
SWIFT CSCF
1 source controls mapped|2 target controls covered
9%
ITAR - International Traffic in Arms Regulations
1 source controls mapped|1 target controls covered
9%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
9%
ISO 37001
1 source controls mapped|1 target controls covered
9%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
1 source controls mapped|1 target controls covered
9%
ISO 56002
1 source controls mapped|3 target controls covered
9%
ISO 37002:2021 - Whistleblowing Management Systems
1 source controls mapped|3 target controls covered
9%
ISO 9001
1 source controls mapped|3 target controls covered
9%
ISO 30401
1 source controls mapped|1 target controls covered
9%
ISO 19011
1 source controls mapped|1 target controls covered
9%
ISO 37301
1 source controls mapped|1 target controls covered
9%
ISO 55001
1 source controls mapped|1 target controls covered
9%

Frequently Asked Questions

What is German Supply Chain Due Diligence Act (LkSG)?

German Supply Chain Due Diligence Act (LkSG) is a compliance framework from Germany with 7 domains and 11 controls. The Lieferkettensorgfaltspflichtengesetz (LkSG, German Supply Chain Due Diligence Act) was enacted 22 July 2021 + entered into force 1 January 2023 for companies with MORE THAN 3,000 EMPLOYEES + 1 January 2024 for companies with MORE THAN 1,000 EMPLOYEES (including German branches of foreign entities). The Act establishes statutory HUMAN RIGHTS + ENVIRONMENTAL DUE DILIGENCE OBLIGATIONS in supply chains. SCOPE: covers (a) the company's OWN OPERATIONS; (b) DIRECT SUPPLIERS - full due diligence required; (c) INDIRECT SUPPLIERS - risk-based + SUBSTANTIATED KNOWLEDGE-triggered due diligence (not full due diligence at outset). KEY STATUTORY DUTIES (sections 4-10 of LkSG): (1) RISK MANAGEMENT SYSTEM with appropriate + effective procedures; (2) IN-HOUSE RESPONSIBILITY - designated human rights officer or equivalent with direct reporting to senior management; (3) RISK ANALYSIS - annual + ad-hoc + covering own business + direct suppliers + (if substantiated knowledge) indirect suppliers; (4) POLICY STATEMENT - human rights strategy + senior management commitment; (5) PREVENTIVE MEASURES - integrating human rights into business processes + training + supplier commitments + contractual obligations + audit rights; (6) REMEDIAL ACTION - for actual + imminent violations in own operations + direct suppliers; (7) COMPLAINTS PROCEDURE - accessible + confidential + bias-free + with rules of procedure; (8) DOCUMENTATION OF DUE DILIGENCE; (9) ANNUAL REPORT to BAFA + on the company's website. PROTECTED LEGAL POSITIONS: human rights covered include forced labour + child labour + slavery + discrimination + freedom of association + collective bargaining + occupational health and safety + minimum wage + exclusive land rights + security forces conduct + others. ENVIRONMENTAL OBLIGATIONS: covers specifically Minamata Convention on Mercury + Stockholm Convention on POPs + Basel Convention on Hazardous Waste; broader environmental impacts to the extent they lead to human rights violations. ENFORCEMENT: BAFA (Bundesamt fur Wirtschaft und Ausfuhrkontrolle) - inspection + complaints handling + monitoring + administrative fines + public-procurement exclusion. SANCTIONS: administrative fines up to EUR 8 MILLION + UP TO 2% OF GLOBAL ANNUAL TURNOVER FOR COMPANIES WITH MORE THAN EUR 400 MILLION TURNOVER + PUBLIC PROCUREMENT EXCLUSION UP TO 3 YEARS for significant violations. EU CSDDD COORDINATION: the EU Corporate Sustainability Due Diligence Directive (CSDDD - Directive (EU) 2024/1760) entered into force July 2024 + phased transposition deadlines 2027/2028/2029; EU CSDDD will substantially supersede LkSG + expand to value-chain due diligence + civil liability + alignment expected during 2025-2029 transposition; Germany was central in CSDDD negotiation; some LkSG provisions may be tightened or aligned during transposition. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does German Supply Chain Due Diligence Act (LkSG) have?

German Supply Chain Due Diligence Act (LkSG) has 11 controls organised across 7 domains. The largest domains are LkSG: Protected Human Rights + Environmental Risks + EU CSDDD Coordination and 2024-2025 Status (5 controls), LkSG: BAFA Enforcement, EUR 8M + 2% Sanctions, Public Procurement Exclusion (1 controls), LkSG: Scope, Applicability Thresholds, Phased Effective Dates and Group Cascade (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does German Supply Chain Due Diligence Act (LkSG) map to?

German Supply Chain Due Diligence Act (LkSG) maps to 140 other compliance frameworks. The top mapping partners are Voluntary Principles on Security and Human Rights (VPs) (36% coverage), ILO Declaration on Fundamental Principles and Rights at Work (Core Conventions) (36% coverage), IEEE 1686 (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with German Supply Chain Due Diligence Act (LkSG) compliance?

Start your German Supply Chain Due Diligence Act (LkSG) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about German Supply Chain Due Diligence Act (LkSG) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 11 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required