Risk Center
LkSG Supplier Monitoring: What §2 Requires
By Laurits Aae Mouritsen, Founder · July 2026 · 1258-word read
This article is general information for procurement and supply chain teams, not legal advice. Interpretation of specific LkSG sections and their overlap with the EU CSDDD should be confirmed with qualified counsel against the current statute text.
Key takeaways
- •The LkSG makes supplier due diligence a legal obligation, and most of the operational load lands on procurement.
- •§2 defines a fixed risk catalogue every supplier must be assessed against, with evidence — not just whichever risks made the news.
- •§5 frames risk analysis as an ongoing duty, so continuous monitoring beats the annual questionnaire.
- •§10 requires documentation of what you knew and when; an append-only, timestamped event log satisfies it by construction.
Germany's Supply Chain Due Diligence Act, the Lieferkettensorgfaltspflichtengesetz or LkSG, turned supplier due diligence from good practice into legal obligation for in-scope companies. Much of the operational load lands on procurement, because procurement owns the supplier relationships the law is about.
Scope is defined by headcount: the act applied to companies with at least 3,000 employees in Germany from 2023, and dropped to 1,000 employees from 2024. Even below the threshold, many smaller firms feel it indirectly, because in-scope customers push due-diligence expectations down their own supply chains. Enforcement sits with BAFA, the Federal Office for Economic Affairs and Export Control, which can request documentation and impose penalties.
Three ideas from the act shape the day-to-day work: a defined catalogue of risks to assess suppliers against (§2), an ongoing duty of risk analysis rather than a one-off exercise (§5), and a documentation and retention duty that makes your records part of your compliance (§10). And the direction of travel is broader still: the EU's Corporate Sustainability Due Diligence Directive (CSDDD) extends comparable duties across the single market, so a program built for the LkSG is largely a head start on the EU regime.
The §2 risk catalogue
Section 2 of the LkSG defines the risk positions due diligence must cover. The catalogue spans human-rights and environmental risk positions, and it functions as a checklist: your risk analysis is expected to consider these defined categories, not whichever risks happened to make the news.
The practical implication is structural. Every supplier needs to be assessed against the same catalogue, and the assessment needs to point at evidence. This is why Intellens maps every supplier to the LkSG §2 risk catalogue with a citation chain back to the underlying signals, so the mapping is something you can hand to your legal team, not the other way around.
Continuous due diligence vs the annual questionnaire
The traditional compliance instrument is the annual supplier questionnaire. It has a place, but as a due diligence method it has an obvious gap: it documents a self-reported moment, and risk does not wait for the next survey round.
Consider a supplier factory where local-language media begins reporting unrest or labor problems. Continuous monitoring that scans 200,000+ news sources daily in more than 40 languages can surface a local-language story about a specific supplier long before it reaches the international press, translate it, and raise a supplier-level alert. A questionnaire sent eight months later would have missed the entire event, along with the window in which acting early was cheap.
Continuous due diligence therefore means monitoring that runs at the speed of the risk: reputational and media signals, sanctions and watchlist changes, transport disruptions, and geographic risk across climate, conflict, energy, and compliance, all resolved to the individual supplier. The Intellens risk modules cover exactly this spectrum.
§10 documentation and retention
Section 10 is where many programs quietly fail. It is not enough to have done the due diligence; you need documentation that shows what you knew, when you knew it, and what you did about it, retained for the statutory window.
Reconstructing that from email threads and spreadsheet versions is miserable. The robust pattern is an append-only event log: every state change recorded with a timestamp and an actor, with comments, attachments, and evidence preserved for the full LkSG retention window. Built that way, the documentation duty is satisfied by the system of record itself rather than by a year-end archaeology project.
The reporting side follows the same logic. LkSG report packs that auto-build from live supplier data every 24 hours and export as audit-grade PDF mean the document your reviewer asks for is always current, and always traceable to the signals underneath it.
Enforcement, penalties, and the complaint mechanism
The LkSG is not a voluntary framework with a reporting formality attached; it has teeth. BAFA can request documentation, investigate on its own initiative or on the basis of a substantiated complaint, order companies to take remedial action, and impose fines that scale with company turnover for serious breaches — with the possibility of temporary exclusion from public contracts on top. The point of the penalty regime is behavioral: it makes demonstrable diligence cheaper than the risk of being found without it.
The act also requires an accessible complaints procedure (§8) so that people affected along the supply chain — including workers at suppliers — can flag human-rights or environmental concerns. In practice that means signals about your suppliers can now originate from outside your own monitoring: a complaint, an NGO report, or media coverage. A monitoring setup that already ingests external, local-language signals about each supplier is the natural place for those inputs to land and be actioned, rather than arriving cold through a regulator.
From the LkSG to the EU CSDDD
The LkSG is increasingly best understood as Germany's early implementation of a direction the whole EU is taking. The Corporate Sustainability Due Diligence Directive (CSDDD) sets comparable risk-based due-diligence duties across member states, to be transposed into national law on a staged timeline. The specifics — thresholds, civil-liability provisions, and dates — have been the subject of active simplification discussion at EU level, so they should be confirmed against the current directive and each country's transposition.
For a procurement team, the strategic implication is stable even while the details move: the capability the LkSG demands — know your suppliers, assess them against defined risk positions with evidence, monitor continuously, document what you did — is the same capability the EU regime will demand more broadly. Building it well for the LkSG is not a one-country compliance cost; it is a head start on the European baseline.
From alert to auditable task
Due diligence under the LkSG is judged by responses, not just detection. That makes the alert-to-task chain the backbone of the audit trail:
- •Every risk signal lands in a single hub with deduplication and severity, instead of scattering across dashboards and inboxes.
- •Routing rules assign tasks per supplier, region, or risk class, and SLA timers escalate to a backup owner before a deadline lapses.
- •One click converts an alert into an owned task with a due date and checklist. When the source signal lifts, the closure links back automatically.
- •Every step of that chain is written to the timestamped event log, so the response history exists without anyone maintaining it by hand.
What to do now
If the LkSG applies to you, or to customers who will pass its expectations down their supply chain, the sequence is: know your suppliers, assess them against the §2 catalogue with evidence, monitor continuously rather than annually, and let every alert and response write itself into a retained audit trail.
To see how supplier mapping, monitoring, and §10-ready documentation work in one platform, request a demo, or continue reading in the Risk Center.
Frequently asked questions
Is an annual supplier questionnaire enough for LkSG due diligence?
A questionnaire documents a self-reported moment. The act frames risk analysis as an ongoing duty, and risks change between survey rounds, so continuous monitoring of external signals is the safer operational posture.
What should LkSG documentation contain?
A record of what was detected, who acted, and when: timestamped state changes with an actor, plus the evidence, comments, and attachments behind each decision, preserved for the full retention window.
What is the LkSG §2 risk catalogue?
Section 2 defines the human-rights and environmental risk positions due diligence must cover. It functions as a fixed checklist: every supplier is assessed against the same defined categories, with evidence behind each mapping.
How long must LkSG documentation be retained?
Section 10 requires records of what you knew, when you knew it, and what you did about it, retained for the statutory window. An append-only, timestamped event log keeps that trail current without manual upkeep.
Sources & references
Related reading
About the author
Laurits Aae Mouritsen is the founder of Intellens. His master's thesis at Copenhagen Business School — Open Source Intelligence (OSINT) in Supply Chain Risk Management (Cand.merc.it., 2024) — built software to gather intelligence on hundreds of millions of companies and automatically analyse supplier risk across a supply network. Intellens is that research put into practice. More on the about page · LinkedIn.
Published 2026-07-07 · Back to the Risk Center