DACH Compliance & LawLast reviewed: 2026-07-31

Supply Chain Act (LkSG)

The German Supply Chain Due Diligence Act (LkSG) obliges large companies to identify human-rights and environmental risks in their supply chain, address them through prevention and remedial measures, and document how they meet these due-diligence duties.

The Supply Chain Act (LkSG) – officially the "Act on Corporate Due Diligence Obligations in Supply Chains" (Lieferkettensorgfaltspflichtengesetz) – obliges large companies based in Germany to systematically identify human-rights and environmental risks along their supply chain, address them with prevention and remedial measures, and document how they meet these due-diligence duties in a traceable way. It has applied since 1 January 2023 and is enforced by the Federal Office for Economic Affairs and Export Control (BAFA).

The act establishes a so-called obligation of effort, not a guarantee of success: a company does not have to ensure that a violation never occurs anywhere in its supply chain, but it must demonstrably act appropriately to identify and mitigate risks. The scope of the duties is graduated – strongest for its own business area and direct suppliers, and event-driven for indirect suppliers. For procurement and supplier management this means: due diligence becomes a documented, auditable process that ERP systems can support.

At a glance

  • Obliges large companies to exercise human-rights and environmental due diligence in the supply chain
  • In force since 1 Jan 2023; since 1 Jan 2024 it applies from 1,000 employees in Germany
  • Core duties: risk management, risk analysis, prevention, remediation, complaints procedure, documentation and reporting
  • An obligation of effort, not of success – graduated by own area, direct and indirect suppliers
  • Enforced by BAFA; fines up to EUR 8 million or 2% of annual turnover

What the Supply Chain Act (LkSG) governs and to whom it applies

The Supply Chain Act addresses companies above a certain size. When it took effect in 2023 it initially applied to companies with at least 3,000 employees in Germany; since 1 January 2024 the threshold has been lowered to 1,000 employees in Germany. What matters is having a registered office or branch in Germany, regardless of legal form. Smaller businesses are also indirectly affected when, as suppliers to an obligated company, they have to provide evidence and declarations.

The protected legal positions are specifically named: human-rights concerns such as the prohibition of child and forced labour and of discrimination, respect for freedom of association, appropriate wages and occupational safety, as well as environmental obligations, for example under the Minamata Convention (mercury), the Stockholm POP Convention, and the Basel Convention on the transboundary movement of hazardous waste.

How the Supply Chain Act works: the nine due-diligence duties

The LkSG spells out due diligence in a catalogue of elements that together form a continuous management cycle. They range from setting up a risk-management system to annual reporting and are not a one-off project but a recurring process.

Risk management, risk analysis and policy statement

At its core is an appropriate risk-management system anchored in all relevant business processes – above all procurement – including clear responsibility (e.g. a human-rights officer). At least once a year and on an event-driven basis, the company carries out a risk analysis for its own business area and its direct suppliers, weights and prioritises the results, and adopts a policy statement on its human-rights strategy.

Prevention, remediation and complaints procedure

The analysis leads to preventive measures (such as contractual assurances, training, and selection and monitoring mechanisms for suppliers). If the company identifies a violation, it must take remedial measures to end or minimise it. In addition, a complaints procedure must be set up through which affected persons and whistleblowers can flag risks and violations. Everything is documented on an ongoing basis and summarised in an annual report to BAFA.

Why the Supply Chain Act matters for companies

Violations carry sanctions: BAFA can impose fines of up to EUR 8 million and, for companies with more than EUR 400 million in annual turnover, up to 2% of average worldwide annual turnover. In addition, substantial fines can lead to exclusion from public contracts for up to three years. While the LkSG does not create new civil liability, it does open a special right of action (Prozessstandschaft) that allows trade unions and non-governmental organisations to represent affected persons before German courts.

Beyond mere compliance, the act works as a signal to customers, investors and the public. Companies that make their supply chains transparent and document risks robustly reduce reputational and default risks and are also better prepared for stricter EU requirements that will significantly expand the scope in the future.

The Supply Chain Act in the ERP system

The LkSG is not purely an ERP topic, but the ERP system provides the data foundation without which a robust risk analysis is barely possible. The supplier master holds countries of origin, product groups, purchasing volumes and contact data – exactly the information needed to prioritise risks per supplier. Assurances, certificates and audit results are stored via procurement processes and supplier evaluation and taken into account when selecting suppliers.

For the burden of proof, documentation is decisive: an audit trail records when a given check took place, which measures were taken, and who approved them. This makes it possible to provide the evidence needed for the BAFA report in an audit-proof way. Many companies supplement their ERP with specialised LkSG or ESG software for risk screening and complaints management and connect it via interfaces; whether a given setup meets the legal requirements depends on processes, configuration and the accompanying documentation – responsibility remains with the company.

Distinctions: LkSG, EU Supply Chain Directive and CSRD

The LkSG is the German act, but it is increasingly overlaid by EU law. The European supply chain directive (Corporate Sustainability Due Diligence Directive, CSDDD) was adopted in 2024 and must be transposed into national law by the member states. Over time it will cover more companies, extend due diligence more strongly to the entire value chain, and – unlike the LkSG – provide for its own civil liability. The national LkSG is not immediately replaced but is gradually being aligned with the directive.

This should be distinguished from the CSRD (Corporate Sustainability Reporting Directive): it governs sustainability reporting, that is, what a company reports on, whereas the LkSG governs operational due diligence in the supply chain. In practice the two interlock, because the same supply-chain and risk data are needed both for LkSG documentation and for the sustainability report.

DACH specifics: Germany, Austria, Switzerland

So far, a dedicated supply chain act exists in the DACH region only in Germany. Austria has not enacted a comparable national law, but Austrian companies are indirectly affected via the EU CSDDD directive and as suppliers to German LkSG-obligated companies, and must provide corresponding evidence.

Switzerland has no comprehensive supply chain act either, but has anchored its own, more narrowly focused due-diligence and reporting duties in the Code of Obligations (Art. 964j et seq. CO) and in the Ordinance on Due Diligence and Transparency (DDTrO) – in particular regarding minerals and metals from conflict areas and child labour. Companies operating across borders should observe the applicable duties separately per legal entity and structure their supplier data accordingly in a multi-tenant ERP.

Example

Example: a mid-sized manufacturer builds up its LkSG processes

An industrial company with around 1,200 employees has fallen under the Supply Chain Act since 2024. Procurement pulls a report of all direct suppliers by country of origin and product group from the ERP and flags suppliers from regions with elevated human-rights risk as well as raw materials with known environmental risks. For this group, codes of conduct are agreed contractually, certificates are requested and stored in the supplier master.

In parallel, the company sets up a complaints procedure and trains procurement. Every risk assessment, every measure and every approval is logged in the system with a date and responsible person. At year-end, the report to BAFA can be compiled from this – seamlessly from the identified risk through the preventive measure to the effectiveness check. In this way the manufacturer demonstrably meets its due-diligence duties without paralysing the supply chain.

Frequently asked questions

When it took effect in 2023, the LkSG applied to companies with at least 3,000 employees in Germany. Since 1 January 2024 the threshold has been lowered to 1,000 employees. Smaller companies are often indirectly affected as suppliers to obligated firms.
Obligated companies must set up a risk-management system, carry out a risk analysis annually and on an event-driven basis, issue a policy statement, take preventive and remedial measures, provide a complaints procedure, and document everything and report annually to BAFA.
BAFA can impose fines of up to EUR 8 million; for companies with more than EUR 400 million in annual turnover, up to 2% of worldwide annual turnover is possible. In addition, substantial fines can lead to exclusion from public contracts for up to three years.
The LkSG is the German act in force since 2023. The 2024 EU CSDDD directive is transposed nationally, covers more companies, extends due diligence to the entire value chain, and – unlike the LkSG – provides for its own civil liability. The LkSG is being gradually aligned.

Questions about Supply Chain Act (LkSG) in your ERP project?

We advise vendor-neutrally – and implement it ourselves on request.

Free consultation