Germany’s Supply-Chain Law Turns Complaints Into Risk Intelligence

Germany’s Supply Chain Due Diligence Act requires a complaints process that reaches beyond employees and headquarters. It is meant to reveal human-rights and environmental risks across the operating chain.

The Lieferkettensorgfaltspflichtengesetz, or LkSG, first applied on 1 January 2023 to companies with at least 3,000 employees in Germany. From 1 January 2024, the threshold fell to 1,000. Covered companies must organise risk management, analysis, prevention, remediation, documentation and a complaints procedure for specified human-rights and environmental risks.

That procedure is not merely a whistleblower mailbox. It is an input to the due-diligence system.

The audience includes people outside the company

Section 8 requires a procedure through which people can report risks or violations arising from the company’s own business area or the activities of a direct supplier. The rules for indirect suppliers connect the same mechanism to information about deeper-tier risks.

Potential users can therefore include supplier workers, local communities, unions and civil-society organisations. A German-only portal hidden on the corporate intranet may be technically live and practically inaccessible to the people most likely to see a problem.

The company must publish clear and understandable information about access, responsibility and procedure. Accessibility should be tested against language, literacy, disability, connectivity, local trust and fear of retaliation. A voice route or trusted local intermediary may be more effective than a sophisticated web platform in some supply chains.

Independence and confidentiality are functional requirements

People handling complaints must offer a guarantee of impartial action, act independently, not be bound by instructions in their case work and maintain confidentiality. The process must protect identity and provide effective protection against disadvantage or punishment because a complaint was made.

Those requirements have system consequences. Access should be limited by case role. Reports should not flow automatically to the local manager or buyer implicated in the allegation. Identity data should be separated where possible, and translation or external investigation providers should receive only what they need.

The company must acknowledge receipt and discuss the facts with the reporting person. A one-way form that cannot support safe follow-up therefore misses an important part of the procedure.

Complaints should change the risk model

The LkSG requires companies to assess the effectiveness of the complaints procedure at least annually and when a materially changed or expanded risk situation arises. The procedure is valuable only if its output reaches risk management.

Suppose several reports describe excessive recruitment fees at labour agencies serving different suppliers. Closing each case separately may overlook a systemic sourcing risk. The case platform should support aggregation by risk type, geography, supplier tier and business unit while maintaining appropriate confidentiality.

That does not mean turning sensitive reports into a broad analytics dataset. Access to trends can be separated from access to identities and narratives. The goal is to let the company see recurring conditions, evaluate prevention and update the risk analysis without exposing complainants.

Suppliers cannot be made the compliance owner

Covered companies often need information and cooperation from suppliers. The German regulator, BAFA, has stressed that this cooperation does not expand the statute’s direct scope or permit the covered company to transfer all of its duties down the chain.

A contract requiring every supplier to “comply with the LkSG” can be both overbroad and operationally empty. Better provisions define proportionate actions: publicising the channel, protecting users, preserving relevant evidence, providing information and participating in remediation. The covered company retains responsibility for its due-diligence decisions.

An effective procedure leaves evidence

Companies should be able to demonstrate:

  • how likely users were consulted when the channel was designed;
  • which languages and reporting methods are available;
  • how impartiality, confidentiality and anti-retaliation are protected;
  • how receipt, dialogue, investigation and outcome are documented;
  • how complaints influence risk analysis and preventive measures; and
  • how effectiveness is reviewed and the process improved.

Metrics should go beyond the number of cases. Awareness, accessibility, time to safe contact, remediation completion and repeat patterns are more informative. A low report count can indicate a healthy supply chain—or a channel nobody trusts.

The LkSG makes complaints a sensor for the due-diligence programme. The technology matters, but confidence, reach and organisational response determine whether that sensor detects anything useful.

Official sources

Continue the series

This article provides general information and is not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *