Briefing Note · ESG & Supply Chains

What the Company (for Which Work Is Performed) Must Do

The ten steps a company within the scope of the German Supply Chain Due Diligence Act must take: due diligence strategies, risk management and analyses, remedial measures, training and audits, an accessible complaint mechanism, and reporting.

28 March 20224 dk okumaBy Sven Köksal · ESG & Supply Chains
Köksal Attorney Partnership — ESG, supply chain, logistics and export work

The ten steps a company within scope must take

1. Preparing the core principles, the code of conduct and the due diligence strategies;

2. Establishing the risk management system and designating a responsible person;

3. Applying risk analyses both internally and at the direct and indirect suppliers within the supply chain;

4. Conducting risk analyses at least once a year (both internally and at suppliers);

5. Taking remedial measures;

6. Updating the remedial measures whenever necessary, and at least once a year;

7. Conducting training and audits at direct or indirect suppliers under the due diligence obligation regarding human rights and the environment;

8. Establishing an accessible complaint mechanism;

9. Establishing written procedural rules on the operation of the complaint mechanism;

10. Fulfilling the reporting and documentation obligation.

Putting the steps on a timetable and taking stock

Each of these steps should be tied to a timetable, bearing in mind that the Act has been in force since 1 January 2023 and, since 1 January 2024, applies to companies with at least 1,000 employees in Germany. In practice, the first task is a stocktake: the company should map its supply chain end to end, classify its direct and indirect suppliers, and prioritise the areas it considers risky in terms of human rights and the environment.

Building the structures and writing them into contracts

In the second stage, the structural elements — the code of conduct, the risk management system and the complaint mechanism — should be put in place; a responsible person should be appointed and regular reporting to management set in motion. Purchasing contracts should likewise be reinforced with compliance, audit and recourse clauses. This preparation in the field of supply chain due diligence matters not only for the German companies within the scope of the Act but also for the Turkish companies in their supply chains, since the obligations are passed down the chain through contracts. Companies that start early will be better placed to meet their customers’ requests and to scale an LkSG/CSDDD compliance programme to their own size.

How the ten steps reach suppliers in Türkiye

Because the obligations travel down the chain through contracts, the same ten-step list reaches a Turkish supplier working for a German customer within scope, only in a different guise: signing up to a code of conduct, completing supplier questionnaires, accepting audit and on-site inspection undertakings, making declarations about sub-suppliers, and notifying the customer if something goes wrong. As of July 2026, these requests usually arrive as a supplier undertaking annexed to the purchase agreement.

For the supplier, the right instinct is to build a durable arrangement of its own rather than answer each customer’s form from scratch. A policy set prepared once, a supplier list kept current, a documented complaints channel and orderly records will answer most of what different customers ask, from the same file. That shortens response times and presents a consistent picture in customer audits.

Questions to answer before you start

  • Which of our customers are within scope, and what undertakings are they asking of us?
  • How many tiers of our supply chain can we actually see, and is our list of direct and indirect suppliers current?
  • Do we have a code of conduct, and is it accepted by our suppliers contractually?
  • Who will run the risk analysis, who receives the findings, and who decides?
  • Is our complaints mechanism open to our suppliers’ workers as well as to our own staff?
  • Do our purchase contracts contain information, audit, corrective-action and termination rights?
  • Do we document our work in a form we could show in a customer audit?

Three common mistakes

First, treating the steps as a one-off project: the risk analysis and the remedial measures are designed to be repeated at least once a year. Second, setting up a complaints mechanism without telling anyone about it; a channel nobody can reach exists only on paper. Third, neglecting documentation: work that was never recorded cannot be shown in an audit or in answer to a customer’s questionnaire.

This content is for general information only and does not constitute legal advice. Please contact our team for an assessment of your specific circumstances.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all
Knowledge Centre

Get a legal assessment on this matter.

Get in touch with our team for an assessment of your specific situation.