BAFA published FAQs on the Risk-Based Approach under the German Supply Chain Act. Notably, the FAQ indicates that ‘from now on BAFA will pay particular attention to the implementation of the risk-based approach by companies in its inspections and sanction violations.’ The tone and messaging in the FAQs are consistent with the recent Omnibus Directive proposal — emphasising that companies should avoid placing unnecessary burdens on their suppliers.
- On 19 February, the German Federal Office of Economics and Export Control (BAFA) published an FAQ on the Risk-Based Approach under the German Supply Chain Due Diligence Act. The FAQ also takes into consideration requirements under the CSDDD. The FAQs are currently only available in German, and this alert is based on an unofficial translation.
- Importantly, the FAQ flags that ‘From now on BAFA will pay particular attention to the implementation of the risk-based approach by companies in its inspections and sanction violations. Those who do not take a risk-based approach or who attempt to pass on their due diligence obligations to other companies are neither acting appropriately nor effectively and are therefore not fulfilling their own obligations.’
- The underlying message of the FAQ is that companies should not needlessly burden suppliers. Specifically, BAFA is looking to limit sweeping information requests to a company’s full supply base – and will investigate cases where they believe companies have done this. Rather, companies are expected to only target high-risk suppliers. While the approach is different, the overall intent is very much in line with the proposed Omnibus Directive, which would restrict companies from requesting sustainability information from suppliers with less than 500 employees, unless it is necessary due to potential risks in that part of the supply chain and alternative sources are unavailable.
Key messages
The following key points are set out in the FAQ and stand out to us as particularly relevant to clients.
- A company’s initial risk mapping is high-level, based on desktop analysis, and does not need to involve suppliers. External sources such as media reports, studies, or industry initiatives can inform this assessment, and suppliers do not need to be contacted at this step. Similarly, traceability is not required to carry out this step. Nonetheless, companies cannot replace risk analysis by referring to contractual assurances or corresponding certificates of ‘risk-free supply chains’ from suppliers.
- Companies have flexibility in how they prioritise human rights risks, so long as they align with the Act’s overarching criteria. In their prioritisation, companies should take into account the nature and extent of the business activities, the leverage over the business partners, the potential severity of the violation, and the extent of their contribution to the risk. Companies may also consider risk factors at a company or supplier level, geographical and contextual risk factors, risk factors linked to the products and services and industry specific risk factors. Companies must be able to justify their prioritisation.
- Companies should prioritise collecting information from suppliers with serious and/or probable risks or with an unclear risk situation. This means that companies should not send out blanket questionnaires, which ‘create unnecessary effort for both companies and suppliers’ and ‘companies must check whether extensive requests for information from suppliers are actually necessary in individual cases.’ IT tools, which generate automatic requests for information, should also only target high-risk suppliers.
- BAFA considers it inappropriate and generally ineffective to impose preventative measures — such as training, contractual obligations, or codes of conduct — on all suppliers without regard to their risk profile. Prevention measures, such as training, should be targeted specifically where risks have been identified rather than implemented across all suppliers. The FAQ does not clarify whether companies can implement preventative measures when risks are identified at the sector or country level but not at a specific site. BAFA informed us that they could not provide a specific response to this scenario. However, they noted that the Supply Chain Due Diligence Act allows companies “plenty of leeway when conducting a risk analysis and taking appropriate and effective measures in their supply chain.” As a result, we expect that companies could choose to interpret the Act and guidance to allow companies to take preventative steps in this case.
About BAFA Guidance
- This Guidance supplements existing BAFA Guidance on Identifying, Weighting and Prioritising Risks, which includes technical guidance on how to carry out a risk assessment and prioritisation. BAFA Guidance is not legally binding, but it does set out how BAFA will interpret the law in reviewing company performance.

