As part of risk management, companies must prepare a concept — covering both their own area of activity and their direct suppliers — so that the due diligence obligation can also be sustained over the long term. Part of this concept is the body of rules that sets out the policies and principles governing what the conduct obligations are and how the due diligence obligation is to be fulfilled.
The Law contains a specific rule on this (Section 6(1) and (2)). This provision also parallels Article 7 of the Directive. In addition to what must be done to prevent a risk from arising, the code of conduct must also set out which measures or precautions are to be taken when a risk materialises.
Companies must update these policies without undue delay after a significant change occurs, and must review and, where necessary, update them at least every 24 months (Article 7(3) of the Directive).
If a company identifies a risk under the Law or the Directive in the course of a risk analysis, it must take appropriate preventive measures.
The company must issue a policy statement on its human rights strategy. The company management is obliged to issue a policy statement. With regard to a company’s human rights strategy, the policy statement must contain at least the following elements:
- A description of the procedures for fulfilling the company’s obligations set out in the Law (Sections 4(1), 5(1), 6(3) to (5), and 7 to 10),
- The human rights-related and environmental risks identified as priorities for the company on the basis of the risk analysis, and
- The determination, on the basis of the risk analysis, of the human rights-related and environmental expectations that the company places on its employees and suppliers in the supply chain.
How should a policy statement be prepared in practice?
A policy statement is not an abstract declaration of intent but a concrete strategy document fed by the company’s own risk analysis. Three things matter in preparing it: that the statement is adopted and signed by the company’s management; that the human rights and environmental risks the analysis treats as priorities are named explicitly; and that the conduct expected of employees and suppliers is set out in terms they can actually follow.
Communicating the statement, inside the company and outside it, is part of the duty too: it has to reach employees, suppliers and other affected parties through appropriate channels, and be accessible on the company’s website. The code of conduct, the purchasing terms and the supplier agreements all have to be brought into line with it. As the risk picture changes the statement has to be updated, and that update cycle belongs with the annual risk analysis. Our LkSG/CSDDD compliance programme service page sets out how this process is put together.


