For companies doing business with Germany and the EU, identifying supply chain risks, putting contractual safeguards in place and reporting on them matter more each year.
ESG and supply chain due diligence
This note sets out in general terms the points a company should weigh when taking these decisions. How they apply will depend on the sector and on the structure of the particular transaction.
Practical takeaways for companies
- Assess the legislation and the practice as they currently stand.
- Treat the contractual, compliance and operational strands together, not separately.
- Take legal advice on the concrete facts of the file.
Concrete steps: preparing for supply chain due diligence
Turkish companies supplying Germany and the EU usually come within the reach of the German Supply Chain Due Diligence Act (LkSG) not directly but through their customers’ contractual demands: acceptance of a code of conduct, self-assessment questionnaires, audit rights and graduated sanctions for breach. The EU’s Corporate Sustainability Due Diligence Directive (CSDDD) was rewritten by Omnibus I ((EU) 2026/470) in February 2026: it must be transposed by 26 July 2028, applies from a single date of 26 July 2029, and its scope has been raised to more than 5,000 employees and more than EUR 1.5 billion in turnover.
The preparation that matters most: map your own supply chain and identify the higher-risk sourcing countries; consolidate customers’ code-of-conduct and questionnaire requests into a single compliance file; write human rights and environmental expectations into your own supplier contracts; set up complaint channels and record-keeping; and build the data base you will need to answer reporting requests. Working out which of these comes first for a particular company is the core of our ESG and sustainability focus area.
How customer demands arrive in practice
The demands that reach Turkish suppliers usually arrive in the same order: first a request to sign a code of conduct, then a self-assessment questionnaire, and at renewal the audit-right and information clauses. When they land in different departments, the company gives different answers to the same question — the weakness we see most often. Collecting the requests in a single compliance file, answering them from one desk and keeping a copy of every answer given buys both consistency and time.
Questions to settle before answering a questionnaire or audit request
Before responding to an incoming request, settle the following:
- Which customer is asking, under which contractual provision, and how long is the response window?
- Does the information requested concern the company’s own operations or its sub-suppliers?
- Is the answer consistent with what other customers have been told and with public statements?
- If an audit right is to be accepted, are its scope, frequency, cost and confidentiality safeguards written into the contract?
- Are the graduated sanctions foreseen for non-compliance proportionate, and is a reasonable period allowed for remediation?
- Can the same expectations be passed on in your own supplier contracts?
Timing: what to prioritise
(As of July 2026) two separate clocks are running. Demands arriving through customer contracts apply today and follow the contract renewal calendar; the structural expectations flowing from the CSDDD depend on transposition (26 July 2028) and application (26 July 2029). That gives a practical order of priority: contractual demands are today’s work, while directive-driven preparation is a multi-year programme. A company outside direct scope may still have to meet its customer’s contractual demand — the chain works downward through contracts.




