Germany's Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz, LkSG) entered into force on 1 January 2023 for companies with 3,000 or more employees in Germany, and on 1 January 2024 for those with 1,000 or more employees. The Federal Office of Economics and Export Control (BAFA) is the supervisory authority responsible for enforcement. The first two years of application provide important signals for organisations preparing for CSDDD.
How has BAFA enforced the LkSG?
BAFA has taken a risk-based enforcement approach, prioritising sectors with identified high-risk supply chains and companies where public complaints have been filed. The authority has powers to request documentation, conduct inspections, and impose fines of up to €8 million or, for companies with an annual turnover exceeding €400 million, up to 2% of global annual turnover. BAFA can also exclude non-compliant companies from public procurement for up to three years.
In the first two years, BAFA focused enforcement activity primarily on the documentation and policy obligations – the foundational requirements – rather than pursuing companies for failures deep in their supply chains. This approach reflects the practical reality that upstream risk identification takes time, and that regulators have prioritised establishing a culture of compliance before moving to substantive enforcement.
What are the most common LkSG compliance gaps?
Practical experience from the first enforcement cycle reveals five recurring gaps.
Risk analysis: Many companies conducted risk analyses at too high a level of abstraction, failing to assess risks at the level of specific suppliers, product categories, or countries. A risk analysis that concludes "there are some risks in our supply chain" without identifying which relationships present which types of risk does not meet the LkSG standard.
Preventive measures: Companies frequently failed to translate risk findings into specific preventive measures. Adopting a supplier code of conduct is a starting point, not a complete preventive measure. BAFA expects companies to demonstrate how the code is communicated, monitored, and enforced.
Complaints mechanisms: Many companies established complaints mechanisms that were either inaccessible (requiring employees of suppliers to navigate complex corporate websites) or inadequate (with no defined process for reviewing, investigating, and responding to complaints).
Documentation: The LkSG requires a policy statement, annual reports, and documentation supporting the risk analysis and its methodology. Missing or inadequate documentation was the most frequently cited deficiency in BAFA guidance.
Scope of supply chain: Companies consistently underestimated the required scope of the risk analysis, focusing on tier-one suppliers while ignoring indirect suppliers where the LkSG also applies upon indication of risk.
What does LkSG experience signal for CSDDD readiness?
The LkSG is narrower in scope than CSDDD – it covers human rights and some environmental risks, but not the full range of environmental obligations in CSDDD, and it applies only to German operations rather than the entire EU subsidiary structure. Nevertheless, three lessons transfer directly.
First, the risk analysis is the foundation of everything. Organisations that have not yet mapped their supply chains at a level sufficient for the LkSG will need substantially more work to meet CSDDD requirements.
Second, complaints mechanisms require genuine operational design. They cannot be drafted documents – they must be accessible, promoted, and functional.
Third, documentation discipline is not optional. Regulators will assess the evidence trail, not the company's self-assessment of compliance.
What this means for your organisation
- If you are subject to LkSG, the first two years of enforcement provide a clear signal: documentation gaps and superficial risk analyses are the most common reasons companies fall short. Both are fixable with the right process.
- LkSG compliance is not CSDDD readiness – the German Act is narrower in both scope and obligation depth. Organisations that are LkSG compliant should treat that as a starting point, not a finishing line.
- Tier-one supplier focus is insufficient. Both LkSG and CSDDD require risk analysis to extend to indirect suppliers upon indication of risk. Supply chain mapping must go deeper than most organisations currently go.
- The grievance mechanism is a compliance requirement, not a reputational gesture. BAFA and, in due course, CSDDD supervisory authorities will assess whether it functions, not merely whether it exists.
What you should do now
- Review your existing LkSG risk analysis for specificity – does it identify risks at the level of individual suppliers, product categories, and countries, or at an abstract level?
- Assess whether your grievance mechanism is genuinely accessible to workers in your supply chain, including in relevant languages and through channels they can practically use.
- Confirm your annual reporting and documentation obligations are met and that records are current.
- Begin CSDDD gap analysis now, using your LkSG programme as the baseline and identifying where CSDDD extends the obligation.
- Engage your tier-one suppliers on their own supply chain visibility – your CSDDD obligation will require knowledge of risks that they currently hold.
How Priventia helps
Priventia's Corporate Due Diligence module maps LkSG and CSDDD obligations in parallel, identifying where the German Act satisfies CSDDD requirements and where additional measures are needed. Supply chain risk mapping, grievance mechanism assessment, and BAFA-aligned documentation are built into the platform's controls architecture.