Definition: Supply Chain Due Diligence Act (LkSG)
The Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) is a German law that obligates large companies to identify, prevent, and remediate human rights and environmental risks within their own operations and across their supply chains.
Core characteristics of the LkSG
The LkSG created Germany’s first mandatory human rights and environmental due diligence regime. It follows a risk-based approach, so due diligence depth scales with actual risk exposure.
- Applies to companies with a head office or branch office in Germany employing at least 1,000 people
- Covers human rights risks like child labor and forced labor, plus environmental risks tied to hazardous substances
- Requires a documented risk management system, a responsible person, and a grievance mechanism
- Reaches direct suppliers as a baseline, extending further only on substantiated knowledge of a violation
LkSG vs. the EU Corporate Sustainability Due Diligence Directive (CSDDD)
The LkSG is often confused with the EU’s Corporate Sustainability Due Diligence Directive, but the two differ. The LkSG is national German law effective since 2023, while the CSDDD is an EU directive member states must transpose, and since its Omnibus I amendment of 18 March 2026 only reaches companies above 5,000 employees and 1.5 billion euros in turnover, well above the LkSG’s 1,000-employee bar. Germany plans to align the LkSG with that higher threshold, but until enacted, the current rule stands.
Importance of the LkSG in enterprise AI
The LkSG’s reach extends beyond the roughly 900 companies BAFA counted as directly obligated in 2023, since those companies pass due diligence questionnaires down through suppliers. A 2024 LBBW/DIHK Mittelstandsradar survey found about three-quarters of Mittelstand companies see themselves directly or indirectly affected (LBBW/DIHK, 2024), making reliable data governance over supplier data a competitive requirement even for companies never directly bound by the law.
Methods and procedures for the LkSG
Obligated companies implement the LkSG through a recurring cycle.
Risk analysis and prioritization
Companies run an annual risk analysis across operations and direct suppliers, prioritizing by severity and probability.
- Map suppliers by sector and country risk
- Score risks by severity and likelihood
- Update the analysis when conditions change
Preventive and remedial measures
Where a risk is identified, companies adopt preventive measures such as supplier codes of conduct, and take remedial action where a violation occurred. AI vendor risk management tools increasingly flag suppliers whose risk profile changes between cycles.
Documentation and complaints procedure
Companies document their measures internally and operate a complaints procedure accessible to workers and third parties across the supply chain.
Important KPIs for the LkSG
Compliance teams track process and outcome indicators.
Operational compliance metrics
- Direct suppliers risk-screened: target 100 percent annually
- Complaints procedure response time: target under a defined threshold
- Preventive measures per high-risk supplier: target at least one
- Supplier code of conduct signature rate: target 100 percent
Strategic risk indicators
Compliance leaders track supplier concentration in high-risk countries. Gartner reported in 2025 that supply chain organizations expect AI and agentic capabilities to become the strongest driver of operating performance within two years, pushing due diligence toward the same automation curve (Gartner, 2025).
Documentation quality
Auditors and BAFA reviewers assess whether findings are traceable to evidence, not narrative alone. An AI risk register linking each supplier risk to its mitigation step gives reviewers that trail.
Risk factors and controls for the LkSG
Non-compliance with the LkSG creates regulatory and commercial risk.
Enforcement risk
BAFA can order companies to correct deficiencies and impose fines for serious violations.
- Fines up to 8 million euros or 2 percent of global turnover
- Exclusion from public procurement for up to three years
- Reputational damage from public proceedings
Supply chain visibility gaps
Many companies struggle to see beyond direct suppliers, especially in multi-tier manufacturing. Without structured data, risk analysis becomes manual and hard to defend during an AI audit or BAFA review.
Overreliance on unverified data
Regulators do not accept automated data alone as proof of compliance. Companies relying purely on AI-generated scores without human verification risk an inadequate due diligence finding.
Practical example
A 1,100-employee specialty chemicals manufacturer in North Rhine-Westphalia, sourcing from over 300 suppliers across Asia and Eastern Europe, crossed the LkSG’s 1,000-employee threshold in 2024. Its compliance team had tracked supplier risk in scattered spreadsheets, turning the annual analysis into a six-week project. The company built a company brain consolidating supplier data, audit findings, and country risk ratings from its ERP, with an AI assistant drafting a first-pass risk profile per supplier for a human reviewer to confirm, cutting the annual cycle to under two weeks.
- Automated first-pass risk scoring against country and sector databases
- Centralized supplier documentation pulled from ERP records
- Structured complaints log with defined escalation paths
- Audit-ready evidence trail for each identified risk
Current developments and effects
The LkSG’s scope and enforcement intensity are both shifting through 2026.
Deregulation and scope narrowing
Germany proposed dropping the LkSG’s annual reporting obligation and restricting fines to severe violations in a 2025 draft bill, and BAFA stopped reviewing reports under sections 12 and 13 as of 1 October 2025.
- Government plans to align the threshold with the CSDDD’s 5,000-employee bar
- Fines now reserved for cases tied to serious human rights violations
Convergence with the EU CSDDD
As Germany implements the CSDDD domestically, companies below the future threshold may see LkSG obligations lapse, while large groups face both frameworks during the transition.
Automation of supplier due diligence
Compliance teams increasingly fold supplier screening into broader AI compliance programs that use AI-supported tools to check sanctions lists, but human review of flagged cases remains a legal necessity.
Conclusion
The LkSG established Germany’s first binding human rights and environmental due diligence regime, and its reach through supplier questionnaires touches far more companies than those directly obligated today. BAFA’s enforcement and the law’s scope are both narrowing as Germany aligns with the EU’s revised CSDDD, but obligations are not disappearing for companies that remain covered. Automation speeds up risk screening but supplements human judgment rather than replacing it. Companies exposed to the LkSG benefit from treating supplier risk data as a standing asset, not an annual scramble.
Frequently Asked Questions
What is the LkSG in simple terms?
The LkSG is a German law requiring large companies to identify, prevent, and remediate human rights and environmental risks in their operations and supply chains. It has applied since 2023 and covers companies with at least 1,000 employees.
Does the LkSG apply to a company with 200 employees?
Not directly, since the threshold is 1,000 employees, but smaller suppliers often feel it indirectly when a larger customer passes down due diligence questionnaires as contract terms.
Is the LkSG an AI regulation?
No. It is a general corporate due diligence law focused on human rights and environmental risk. Companies increasingly use automation to manage the supplier data it requires, but the obligations themselves are not AI-specific.
How does the LkSG relate to GDPR when screening suppliers?
Supplier screening can involve personal data from adverse media or sanctions checks, bringing GDPR into play alongside LkSG obligations. Companies need a documented legal basis and data minimization approach for that data.
What does LkSG compliance cost a Mittelstand company?
Costs vary with supplier base size and data quality, but typically include risk analysis tooling, staff time, and supplier engagement. Companies with centralized supplier data spend far less per cycle than those starting from spreadsheets each year.
Do we need dedicated IT staff to manage LkSG compliance?
Not necessarily a dedicated team, but someone needs ownership of supplier data quality and screening tools. Centralizing that data once, rather than rebuilding the analysis annually, reduces the ongoing workload most.