AI Guide

Supply Chain Due Diligence Act (LkSG): Germany's human rights and environmental due diligence law

The Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) is a German law, in force since 1 January 2023, requiring large companies to identify and address human rights and environmental risks in their own operations and supply chains. It is a general corporate due diligence law, not an AI-specific regulation, though many obligated companies now use automation to manage the resulting supplier data. Learn below what the LkSG requires, how BAFA enforces it, and how it relates to the EU's Corporate Sustainability Due Diligence Directive (CSDDD).

Key Facts
  • The LkSG has applied since 1 January 2023 to companies with at least 3,000 employees in Germany, and since 1 January 2024 to companies with at least 1,000 employees.
  • BAFA (Bundesamt fuer Wirtschaft und Ausfuhrkontrolle) enforces the LkSG and can order remediation, conduct inspections, and impose fines.
  • Fines can reach 8 million euros, or 2 percent of average annual global group turnover for companies above 400 million euros in turnover, plus exclusion from public procurement for up to three years.
  • A 2024 LBBW/DIHK Mittelstandsradar survey found about three-quarters of surveyed Mittelstand companies see themselves directly or indirectly affected by the LkSG, even though only large companies are directly obligated.
  • The EU's Omnibus I amendment, in force since March 2026, raised the CSDDD's own threshold to companies with more than 5,000 employees and over 1.5 billion euros in global net turnover, and Germany has announced plans to narrow the LkSG's scope to match.

Definition: Supply Chain Due Diligence Act (LkSG)

The Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) is a German law that obligates large companies to identify, prevent, and remediate human rights and environmental risks within their own operations and across their supply chains.

Core characteristics of the LkSG

The LkSG created Germany’s first mandatory human rights and environmental due diligence regime. It follows a risk-based approach, so due diligence depth scales with actual risk exposure.

  • Applies to companies with a head office or branch office in Germany employing at least 1,000 people
  • Covers human rights risks like child labor and forced labor, plus environmental risks tied to hazardous substances
  • Requires a documented risk management system, a responsible person, and a grievance mechanism
  • Reaches direct suppliers as a baseline, extending further only on substantiated knowledge of a violation

LkSG vs. the EU Corporate Sustainability Due Diligence Directive (CSDDD)

The LkSG is often confused with the EU’s Corporate Sustainability Due Diligence Directive, but the two differ. The LkSG is national German law effective since 2023, while the CSDDD is an EU directive member states must transpose, and since its Omnibus I amendment of 18 March 2026 only reaches companies above 5,000 employees and 1.5 billion euros in turnover, well above the LkSG’s 1,000-employee bar. Germany plans to align the LkSG with that higher threshold, but until enacted, the current rule stands.

Importance of the LkSG in enterprise AI

The LkSG’s reach extends beyond the roughly 900 companies BAFA counted as directly obligated in 2023, since those companies pass due diligence questionnaires down through suppliers. A 2024 LBBW/DIHK Mittelstandsradar survey found about three-quarters of Mittelstand companies see themselves directly or indirectly affected (LBBW/DIHK, 2024), making reliable data governance over supplier data a competitive requirement even for companies never directly bound by the law.

Methods and procedures for the LkSG

Obligated companies implement the LkSG through a recurring cycle.

Risk analysis and prioritization

Companies run an annual risk analysis across operations and direct suppliers, prioritizing by severity and probability.

  • Map suppliers by sector and country risk
  • Score risks by severity and likelihood
  • Update the analysis when conditions change

Preventive and remedial measures

Where a risk is identified, companies adopt preventive measures such as supplier codes of conduct, and take remedial action where a violation occurred. AI vendor risk management tools increasingly flag suppliers whose risk profile changes between cycles.

Documentation and complaints procedure

Companies document their measures internally and operate a complaints procedure accessible to workers and third parties across the supply chain.

Important KPIs for the LkSG

Compliance teams track process and outcome indicators.

Operational compliance metrics

  • Direct suppliers risk-screened: target 100 percent annually
  • Complaints procedure response time: target under a defined threshold
  • Preventive measures per high-risk supplier: target at least one
  • Supplier code of conduct signature rate: target 100 percent

Strategic risk indicators

Compliance leaders track supplier concentration in high-risk countries. Gartner reported in 2025 that supply chain organizations expect AI and agentic capabilities to become the strongest driver of operating performance within two years, pushing due diligence toward the same automation curve (Gartner, 2025).

Documentation quality

Auditors and BAFA reviewers assess whether findings are traceable to evidence, not narrative alone. An AI risk register linking each supplier risk to its mitigation step gives reviewers that trail.

Risk factors and controls for the LkSG

Non-compliance with the LkSG creates regulatory and commercial risk.

Enforcement risk

BAFA can order companies to correct deficiencies and impose fines for serious violations.

  • Fines up to 8 million euros or 2 percent of global turnover
  • Exclusion from public procurement for up to three years
  • Reputational damage from public proceedings

Supply chain visibility gaps

Many companies struggle to see beyond direct suppliers, especially in multi-tier manufacturing. Without structured data, risk analysis becomes manual and hard to defend during an AI audit or BAFA review.

Overreliance on unverified data

Regulators do not accept automated data alone as proof of compliance. Companies relying purely on AI-generated scores without human verification risk an inadequate due diligence finding.

Practical example

A 1,100-employee specialty chemicals manufacturer in North Rhine-Westphalia, sourcing from over 300 suppliers across Asia and Eastern Europe, crossed the LkSG’s 1,000-employee threshold in 2024. Its compliance team had tracked supplier risk in scattered spreadsheets, turning the annual analysis into a six-week project. The company built a company brain consolidating supplier data, audit findings, and country risk ratings from its ERP, with an AI assistant drafting a first-pass risk profile per supplier for a human reviewer to confirm, cutting the annual cycle to under two weeks.

  • Automated first-pass risk scoring against country and sector databases
  • Centralized supplier documentation pulled from ERP records
  • Structured complaints log with defined escalation paths
  • Audit-ready evidence trail for each identified risk

Current developments and effects

The LkSG’s scope and enforcement intensity are both shifting through 2026.

Deregulation and scope narrowing

Germany proposed dropping the LkSG’s annual reporting obligation and restricting fines to severe violations in a 2025 draft bill, and BAFA stopped reviewing reports under sections 12 and 13 as of 1 October 2025.

  • Government plans to align the threshold with the CSDDD’s 5,000-employee bar
  • Fines now reserved for cases tied to serious human rights violations

Convergence with the EU CSDDD

As Germany implements the CSDDD domestically, companies below the future threshold may see LkSG obligations lapse, while large groups face both frameworks during the transition.

Automation of supplier due diligence

Compliance teams increasingly fold supplier screening into broader AI compliance programs that use AI-supported tools to check sanctions lists, but human review of flagged cases remains a legal necessity.

Conclusion

The LkSG established Germany’s first binding human rights and environmental due diligence regime, and its reach through supplier questionnaires touches far more companies than those directly obligated today. BAFA’s enforcement and the law’s scope are both narrowing as Germany aligns with the EU’s revised CSDDD, but obligations are not disappearing for companies that remain covered. Automation speeds up risk screening but supplements human judgment rather than replacing it. Companies exposed to the LkSG benefit from treating supplier risk data as a standing asset, not an annual scramble.

Frequently Asked Questions

What is the LkSG in simple terms?

The LkSG is a German law requiring large companies to identify, prevent, and remediate human rights and environmental risks in their operations and supply chains. It has applied since 2023 and covers companies with at least 1,000 employees.

Does the LkSG apply to a company with 200 employees?

Not directly, since the threshold is 1,000 employees, but smaller suppliers often feel it indirectly when a larger customer passes down due diligence questionnaires as contract terms.

Is the LkSG an AI regulation?

No. It is a general corporate due diligence law focused on human rights and environmental risk. Companies increasingly use automation to manage the supplier data it requires, but the obligations themselves are not AI-specific.

How does the LkSG relate to GDPR when screening suppliers?

Supplier screening can involve personal data from adverse media or sanctions checks, bringing GDPR into play alongside LkSG obligations. Companies need a documented legal basis and data minimization approach for that data.

What does LkSG compliance cost a Mittelstand company?

Costs vary with supplier base size and data quality, but typically include risk analysis tooling, staff time, and supplier engagement. Companies with centralized supplier data spend far less per cycle than those starting from spreadsheets each year.

Do we need dedicated IT staff to manage LkSG compliance?

Not necessarily a dedicated team, but someone needs ownership of supplier data quality and screening tools. Centralizing that data once, rather than rebuilding the analysis annually, reduces the ongoing workload most.

Further Resources

The Best AI Tools for Supply Chain Planning and S&OP: An Honest 2026 Buyer Comparison
AI in Supply Chain

The Best AI Tools for Supply Chain Planning and S&OP: An Honest 2026 Buyer Comparison

An honest 2026 comparison of the AI supply chain planning and S&OP tools that matter - SAP IBP, Blue Yonder, o9, Kinaxis, ToolsGroup, Flowlity and John Galt, plus ChatGPT and Claude as a baseline - with real capabilities and pricing reality. Every suite forecasts and optimises, but none keeps how your planners actually decide - the driver assumptions, override reasoning and exception rules - nor runs the S&OP cycle end to end across your ERP. The durable win is a Company Brain that keeps your planning logic when the demand or supply planner leaves, plus an AI employee that owns the routine S&OP cycle across ERP, email and the planning tool. Includes the EU AI Act Article 50 transparency line, DSGVO and CLOUD Act realities most comparisons skip.

The AI Employee for Third-Party and Vendor Risk: Continuous Monitoring Instead of the Annual Questionnaire
AI in Compliance

The AI Employee for Third-Party and Vendor Risk: Continuous Monitoring Instead of the Annual Questionnaire

How an AI employee owns third-party and vendor risk end to end - intake checks, continuous monitoring of security, financial, sanctions and news signals, questionnaire chasing and re-assessment - grounded in your GRC stack and a Company Brain that keeps how you assess suppliers.

The Best AI Tools for Compliance and Audit Management: An Honest 2026 Buyer Comparison
AI in Compliance

The Best AI Tools for Compliance and Audit Management: An Honest 2026 Buyer Comparison

An honest 2026 comparison of AI compliance and audit tools - Vanta, Drata, Secureframe, Sprinto, AuditBoard/Optro, ServiceNow GRC, OneTrust, LogicGate and Hyperproof, plus generic ChatGPT and Microsoft Copilot - with real capabilities and pricing tiers. Every tool tracks controls and stores evidence but none keeps how your company actually assesses compliance - control rationale, exception decisions and past-audit reasoning - nor runs the routine evidence collection end to end across your real systems. The durable win is a Company Brain that keeps that reasoning when the compliance owner leaves, plus an AI employee that runs the routine evidence and questionnaire work across cloud, identity, HR, ticketing and email. Includes the ISO/IEC 42001, EU AI Act and DSGVO realities most comparisons skip.

Building better software Contact us together