Briefing Note · ESG & Supply Chains

3. Conducting Regular Risk Analyses

Companies in scope must analyse human rights and environmental risks in their own operations and at direct suppliers, prioritise the findings, report them to decision-makers, and repeat the analysis annually or when the risk situation changes.

28 March 20224 dk okumaBy Mehmet Köksal · ESG & Supply Chains

As part of risk management, the company must carry out a risk analysis in accordance with the Law or the Directive in order to identify human rights-related risks and environmental risks arising from its own area of activity as well as from its direct suppliers. The company’s responsibility towards its direct suppliers is substantial.

Scope, prioritisation and repetition of the analysis

If the company abuses the direct supplier relationship or circumvents the law in order to evade the requirements of the due diligence obligation relating to the direct supplier, indirect suppliers will also be treated as direct suppliers.

The human rights-related and environmental risks identified in the risk analyses must be appropriately assessed and prioritised according to their weighting.

The company is obliged to ensure that the results of the risk analysis are communicated within the company to those authorised to make decisions, such as the management board or the purchasing department.

The risk analysis must be reviewed once a year and on an ad hoc basis where a significantly changed or expanded risk situation in the company’s supply chain must be taken into account, for example because new products, projects, or a new line of business are being taken on. Pursuant to Section 8(1) of the Law, the findings obtained from the processing of information must be taken into account.

How to approach regular risk analyses in practice

For the regular risk analysis, a defensible method matters more than volume. In a first step, suppliers are grouped by country risk, sector risk, and the nature of the goods or services procured; abstract risk scores are then refined with company-specific information such as audit results, certifications, media reports, and complaints received. The findings must be weighted and prioritised — the Law does not expect every risk to be addressed at once, but it does expect the prioritisation to be justified.

The occasion-related analysis should not be overlooked alongside the annual routine: new products, new procurement markets, or changes at a supplier trigger a fresh look at the affected part of the supply chain. Documenting each analysis — method, sources, findings, and decisions — is what later allows the company to demonstrate compliance to the competent authority. Structured support for this cycle is part of our LkSG/CSDDD compliance programme service.

The questions the analysis has to answer

In practice a small number of questions drive the analysis. Which countries, and which production or service processes, do we work with? Who are our direct suppliers, and which of those relationships are new? Is there a finding from an earlier audit, from a complaint received, or from a publicly available source? Who would be affected if a risk materialised, and how much influence does the company have over it? Once the answers are written down, the analysis stops being a spreadsheet exercise and becomes a chain of decisions that can be traced afterwards.

Asking suppliers for information

Requesting information is the most sensitive step. The scope of the request should be proportionate to the risk identified; documents the supplier already holds — audit reports, certifications, internal policies — should be reviewed first, and the same information should not be requested again by different departments. What was asked, what was answered, and what the company did when no answer came should all be recorded: what the company can show later is its own method rather than the supplier’s reply.

What this means for suppliers in Türkiye

The Act reaches suppliers established outside Germany indirectly, through the purchasing company, rather than directly (as of July 2026). For suppliers in Türkiye this means the requirement arrives not as a piece of legislation but as contract clauses, a code of conduct and an annual supplier questionnaire. Preparation works at the same level: assembling the information likely to be asked for, naming someone responsible for it, and keeping the answers consistent from year to year all reduce repeated rounds of questions.

This step sits in the middle of the due diligence chain: an established risk management system gives the analysis its foundation, and documentation and reporting carry the findings forward.

This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Mehmet Köksal

Author

Mehmet Köksal

Founder and Managing Partner

Combining legal practice with academic work since 1987, Prof. Dr. iur. Mehmet Köksal advises on corporate and commercial law, contracts, employment, foreign direct investment, ESG and supply-chain due diligence, dispute resolution, consumer law and family law.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.