LkSG Risk Analysis: Supply Chain Due Diligence Under § 5

ADVISORI designs and conducts your LkSG risk analysis under § 5 of the German Supply Chain Act: from abstract country and sector screening to concrete supplier assessments and prioritized measures. You receive a defensible, BAFA-oriented methodology that anchors human rights and environmental due diligence in your procurement processes.

  • Systematic LkSG risk analysis methodology
  • Supply chain risk assessment and classification
  • BAFA-compliant due diligence processes

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Systematic Risk Analysis Under the Supply Chain Act

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

Melanie Düring

Melanie Düring

Head of Risk Management

Our Services

We offer you tailored solutions for your digital transformation

Abstract and Concrete Risk Analysis

We design and conduct the two-stage risk analysis under § 5 LkSG: an abstract screening of country, sector and commodity risks, followed by a concrete assessment of prioritized suppliers and business areas. The methodology is fully documented and repeatable.

  • Country, sector and commodity risk screening
  • Concrete supplier-level risk assessment
  • Prioritization by severity, likelihood and leverage
  • Appropriateness criteria per § 3 (2) LkSG
  • Audit-ready methodology documentation

Supplier Risk Assessment and Classification

We build a data-driven supplier segmentation that focuses due diligence effort where risk is highest. Questionnaires, evidence checks and external risk data are combined into a consistent supplier risk score.

  • Risk-based supplier segmentation model
  • Due diligence questionnaires and evidence review
  • Human rights and environmental risk indicators
  • Integration of external risk data sources
  • Escalation logic for high-risk suppliers

Preventive and Remedial Measures

We translate risk analysis results into effective measures: supplier codes of conduct, contractual assurances, training and structured remediation plans, including the effectiveness reviews required by §§ 6 and 7 LkSG.

  • Supplier code of conduct and contract clauses
  • Training and capacity-building concepts
  • Remedial action plans per § 7 LkSG
  • Effectiveness reviews and measurable KPIs

LkSG Governance and CSDDD Readiness

We anchor the risk analysis in a sustainable operating model with clear responsibilities, an annual and event-driven cycle, and interfaces to the complaints procedure — designed to transition smoothly to the EU Corporate Sustainability Due Diligence Directive.

  • Annual and event-driven analysis cycle
  • Interface to the complaints procedure per § 8
  • Management reporting and documentation
  • Transition planning towards the EU CSDDD

Our Competencies

Choose the area that fits your requirements

Reporting and Disclosure Requirements

Navigate safely through the growing requirements for sustainability and climate reporting. We support you in meeting regulatory disclosure obligations, optimizing your reporting processes, and strategically using sustainability information for your stakeholder communication.

Frequently Asked Questions about Supply Chain Act (LkSG) Risk Analysis

How does the LkSG risk analysis under § 5 of the Supply Chain Act work?

The LkSG risk analysis under § 5 is a systematic procedure for identifying, assessing, and prioritising human rights and environmental risks across the entire supply chain. It forms the core element of risk management under the German Supply Chain Due Diligence Act.

The process consists of three main steps:

1. Risk identification: Capturing all potential risks in your own business area and at direct suppliers through country risk assessments, industry analyses, and supplier-specific assessments.

2. Risk assessment and prioritisation: Evaluating identified risks by severity, probability of occurrence, and the company’s degree of influence. The BAFA guidance recommends a multi-level methodology.

3. Deriving measures: Developing appropriate prevention and remediation measures based on risk prioritisation, with clear responsibilities and timelines.

The results of the risk analysis must be documented and reported to management. ADVISORI supports the development of a structured risk analysis methodology that covers both legal requirements and industry-specific considerations.

What steps does supply chain risk assessment under the LkSG involve?

Supply chain risk assessment under the LkSG involves five essential steps that must be completed systematically.

1. Supply chain inventory: Mapping all direct suppliers with capture of locations, product categories, and sub-suppliers. Prioritisation by procurement volume and strategic importance.

2. Abstract risk analysis: Evaluation of country risks, industry indices, and external data sources to identify high-risk suppliers. Use of risk indices such as the BAFA country risk report.

3. Concrete risk analysis: In-depth review of prioritised suppliers through self-assessments, on-site audits, and document reviews. Assessment of actual human rights and environmental risks.

4. Risk classification: Categorisation of risks by severity, reversibility, and number of affected persons. Creation of a risk map with prioritisation levels.

5. Measure derivation: Development of appropriate prevention measures per risk class. Definition of KPIs for effectiveness measurement.

ADVISORI guides companies through implementing this risk assessment methodology and integrating it into existing risk management processes.

How often must the risk analysis under the Supply Chain Act be conducted?

The regular risk analysis under the Supply Chain Act must be conducted at least once annually. In addition, an event-triggered risk analysis is required when substantiated knowledge of potential violations emerges.

The LkSG distinguishes two analysis types:

1. Regular risk analysis (annual): Covers the company’s own business area and all direct suppliers. Involves updating the risk map and reviewing existing measures.

2. Event-triggered risk analysis: Triggered by substantiated knowledge of risks at indirect suppliers, significant changes in business activities, complaints through the grievance mechanism, or new insights into industry risks.

In practice, the BAFA recommends continuous monitoring to supplement the annual mandatory analysis. Companies should establish a monitoring system that detects changes at suppliers early.

ADVISORI supports the establishment of a structured analysis calendar and automated early warning systems for your supply chain.

What due diligence obligations does the LkSG risk analysis examine at direct suppliers?

The LkSG risk analysis at direct suppliers examines compliance with the due diligence obligations defined in § 2 of the Supply Chain Act in two core areas.

Human rights due diligence:

Prohibition of child labour and forced labour
Occupational health and safety
Freedom of association and right to collective bargaining
Prohibition of discrimination in employment
Adequate remuneration (minimum wage)
Prohibition of unlawful forced evictions
Prohibition of engaging private security forces in human rights violations

Environmental due diligence:

Prohibition of causing harmful soil and water contamination
Prohibition of unlawful emissions
Prohibition of excessive water consumption
Compliance with the Minamata, Stockholm, and Basel Conventions

The risk analysis must be appropriate and effective, meaning the type and scope of the analysis must correspond to the identified risk potential. ADVISORI develops industry-specific risk analysis frameworks that systematically cover all due diligence obligations.

What is the difference between abstract and concrete risk analysis under the LkSG?

The LkSG provides for two levels of risk analysis that differ in depth, scope, and trigger.

Abstract risk analysis:

First level of risk assessment
Uses country risk indices, industry reports, and publicly available data sources
Identifies potential risks based on supplier location and industry
Result: Classification of suppliers into risk categories (low, medium, high)
Conducted for all direct suppliers

Concrete risk analysis:

In-depth review of identified high-risk suppliers
Uses supplier-specific data such as self-assessments, audit reports, and on-site inspections
Assesses actual risks and specific violations
Result: Detailed risk assessment with action plan
Conducted on a risk-oriented basis for prioritised suppliers

The BAFA expects companies to methodically conduct and document both analysis levels. ADVISORI supports the development of a multi-level analysis methodology that efficiently connects both levels.

Latest Insights on Supply Chain Act (LkSG) Risk Analysis

Discover our latest articles, expert knowledge and practical guides about Supply Chain Act (LkSG) Risk Analysis

AI Governance for Banks: Connecting Data, Models, and Internal Structures
Künstliche Intelligenz - KI

AI governance does not replace what banks already do well. It builds on it. This article shows how data governance, model governance, and internal governance combine into a framework that satisfies supervisors and enables AI at scale: from dataset suitability and continuous monitoring to accountability across the three lines of defense.

9th MaRisk Amendment 2026: What Changes for Banks Now
Risikomanagement

The 9th MaRisk Amendment is final: more proportionality, SNCI reliefs, new size categories. All changes, deadlines and an implementation roadmap to 2027.

The EU Benchmarks Regulation Tightens Again: What ESMA's 2026 Internal Control Guidelines Mean for Benchmark Administrators
Risikomanagement

The EU Benchmarks Regulation has acquired another layer. On 5 May 2026, ESMA published new Guidelines on Internal Controls that apply from 1 October 2026 — the latest step in a regulatory story running straight back to the LIBOR scandal. Here's what benchmark administrators and credit rating agencies now have to demonstrate.

The EBA Climate Stress Test: The New 2027 Climate Risk Module and What Banks Should Do
Risikomanagement

The draft 2027 EBA stress test introduces a dedicated climate risk module, layering transition and flood shocks onto the adverse macro-financial scenario. It leaves capital ratios untouched for now, but it produces exactly the kind of supervisory dataset that shapes future cycles, so the draft is best treated as a dry run.

PD Model Backtesting in the Spotlight: What the EBA's 2026 Paper Means for European Banks
Risikomanagement

For two decades, the performance of banks' PD models stayed inside confidential supervisory channels. The EBA's April 2026 Staff Paper changes that — applying systematic PD model backtesting across EU IRB banks, sharpening the binomial test for both asset and serial correlation, and putting a Tier 1 capital number on the result.

Credit Risk Modeling Trends 2026: Five Shifts Risk Managers Should Prepare For
Risikomanagement

The credit risk function of 2026 looks materially different from the one most banks still operate. Here are the five shifts, from generative AI to ESG integration, that risk managers should plan for now.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Steel trading company from Germany

Digital Transformation in Steel Trading

Case Study

Results

Over 2 billion euros in annual revenue through digital channels
More than half of revenue through online channels as a strategic goal
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Industrial group from Germany

Smart Manufacturing Solutions for Maximum Value Creation

Case Study

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Automation specialist from Germany

Intelligent Networking for Future-Proof Production Systems

Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Technology group from Germany

AI Process Optimization for Improved Production Efficiency

Case Study

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance