What the UNGPs Are
The UN Guiding Principles on Business and Human Rights are a set of 31 principles, developed by the Special Representative of the UN Secretary-General and endorsed by the Human Rights Council in June 2011, implementing the "Protect, Respect and Remedy" framework. They are organized into three pillars: the state duty to protect human rights, the corporate responsibility to respect human rights, and access to remedy for victims of business-related abuse. The UNGPs apply to all states and to all business enterprises, "regardless of their size, sector, location, ownership and structure" — and, notably, they create no new binding international law obligations on their own. Their influence instead comes from what came after: they are the direct ancestor of a wave of national mandatory human-rights-due-diligence laws, Germany's LkSG (Section 13) among them, that took the UNGPs' voluntary expectations and wrote them into enforceable statute.
Pillar One: The State Duty to Protect
The first pillar addresses states, not companies: governments must protect against human rights abuse within their territory by third parties, including businesses, through effective policies, legislation, regulation, and adjudication. States should enforce the laws they already have that touch on human rights (labour, environmental, anti-discrimination), ensure that corporate and securities law doesn't inadvertently constrain businesses from respecting rights, and provide clear guidance on what respecting human rights actually requires operationally. The UNGPs give particular attention to the "state-business nexus" — situations where a state owns, controls, or substantially supports a business enterprise (through export credit agencies or investment guarantees, for instance) — on the reasoning that the closer a business is to the state, the stronger the state's obligation to ensure it respects human rights. This pillar is largely outside a company's direct control, but it explains why national laws like LkSG exist at all: they are states exercising exactly this duty to protect.
Pillar Two: The Corporate Responsibility to Respect
The second pillar is the one that actually falls on companies, and it's the one this primer focuses on. Its core statement is simple: business enterprises should respect human rights, meaning they should avoid infringing on the rights of others and should address adverse impacts with which they are involved. This is described as a "global standard of expected conduct" that exists independently of whether a state enforces it, and independently of a company's other commitments — supporting a human rights cause elsewhere doesn't offset a failure to respect rights in one's own operations. Crucially, the responsibility to respect extends beyond a company's own activities to impacts "directly linked to its operations, products or services by its business relationships" — meaning a company's responsibility doesn't stop at its own factory gate if a supplier, contractor, or business partner is causing harm the company is connected to. This is the conceptual root of every modern supply-chain due-diligence law, including LkSG (Section 13).
The Policy Commitment
Meeting the responsibility to respect requires three things in place: a policy commitment, a human rights due-diligence process, and processes to enable remediation of any harm caused or contributed to. The policy commitment is the foundation: a statement, approved at the most senior level of the enterprise, informed by relevant expertise, that sets out the enterprise's human rights expectations of its own personnel, business partners, and other parties directly linked to its operations. It needs to be publicly available, communicated both internally and externally, and — this is the part organizations most often skip — actually reflected in the operational policies and procedures that embed it throughout the business, not filed away as a standalone document nobody reads.
Step 1 — Identify: Assessing Actual and Potential Impacts
Human rights due diligence itself is a four-part cycle: identify, prevent and mitigate, track, and account. The first step is identifying and assessing any actual or potential adverse human rights impacts a company may be involved with, whether through its own activities or through its business relationships. This should draw on internal or independent external human rights expertise and involve meaningful consultation with potentially affected groups and stakeholders, proportionate to the size of the enterprise and the context of its operations. Assessments aren't a one-time exercise: they should happen before a new activity or relationship begins, before major decisions (a market entry, a product launch, a policy change), and periodically throughout the life of an activity, because human rights risks change as operations and operating contexts evolve. Particular attention goes to individuals or groups at heightened risk of vulnerability or marginalization — indigenous peoples, women, ethnic or religious minorities, children, migrant workers.
Step 2 — Prevent and Mitigate: Acting on What You Find
Identifying a risk means nothing without integrating the findings across the relevant internal functions and taking appropriate action — assigning responsibility to the right level of the organization and making sure internal decision-making and budget allocations actually enable an effective response. What "appropriate action" means depends on two questions: does the company cause or contribute to the impact, or is it only linked to it through a business relationship; and how much leverage does the company have to change the situation? Where a company causes or contributes to an impact, it should take the necessary steps to cease or prevent it. Where it's linked to an impact only through a relationship — a supplier's own conduct, say — the UNGPs describe using leverage to influence that party, and, if leverage doesn't exist, looking for ways to increase it (capacity-building, collaborating with other buyers) before considering ending the relationship. Ending a relationship is treated as a last resort, not a first move, and the more severe the abuse and the less crucial the relationship, the faster that step should be considered.
Step 3 — Track: Verifying the Response Actually Works
The third step closes the loop: tracking whether a company's response is actually working, based on appropriate qualitative and quantitative indicators, drawing on feedback from both internal and external sources — including the people affected. This is what turns human rights due diligence into a genuine management system rather than a one-off checklist: without tracking, a company has no way of knowing whether its policies are being implemented as intended or whether an identified risk has actually been addressed. Operational-level grievance mechanisms (Section 10) are one of the more useful sources of this tracking feedback, since they surface problems directly from the people experiencing them.
Step 4 — Account: Communicating Externally
The final step is being prepared to communicate externally how impacts are being addressed, particularly when concerns are raised by or on behalf of affected stakeholders. Companies whose operations pose risks of severe human rights impacts are expected to report formally, in a form and frequency accessible to their intended audience, with enough detail to actually let a reader evaluate whether the response is adequate — without, in turn, creating new risks for affected people or breaching legitimate confidentiality. This is the step Germany's LkSG turns into a hard legal requirement rather than a voluntary expectation: an annual public report is mandatory, not optional (Section 14).
When Harm Has Already Happened: Remediation
Identify/prevent/mitigate/track/account addresses potential impacts going forward, but the UNGPs are explicit that even the best process won't catch everything. Where a company identifies that it has caused or contributed to an adverse impact that has already occurred, its responsibility to respect requires it to provide for or cooperate in remediation through legitimate processes — which can mean operating its own grievance mechanism, cooperating with a judicial process, or otherwise engaging directly with those harmed. Where an impact is only linked to the company through a business relationship, rather than caused or contributed to by the company itself, the UNGPs don't require the company to provide remediation directly, though it may still choose to play a role.
Pillar Three: Access to Remedy
The third pillar returns to states: as part of the duty to protect, states must ensure that people affected by business-related human rights abuse have access to effective remedy, through judicial, administrative, legislative, or other appropriate means. Remedy can take many forms — apologies, restitution, rehabilitation, financial or non-financial compensation, punitive sanctions, or guarantees against repetition — and the UNGPs distinguish between state-based mechanisms (courts, labour tribunals, national human rights institutions), non-state mechanisms (industry or multi-stakeholder grievance processes), and operational-level mechanisms that a business itself establishes or participates in for the people directly affected by its own activities. Effective non-judicial mechanisms, whether state-based or not, are expected to be legitimate, accessible, predictable, equitable, transparent, rights-compatible, and a source of continuous learning — a checklist worth applying to any grievance channel a company sets up under Section 4's policy commitment, not just a formality.
Mapping to Standard ESG Subject S3
Standard ESG's Social pillar organizes human rights and due diligence under its own dedicated core subject, S3 — Human rights & due diligence, distinct from S1's SA8000-derived labour practices and S2's ISO 45001-derived occupational health and safety. Where S1 and S2 cover specific, enumerable workplace conditions, S3 is the subject that captures the broader due-diligence process the UNGPs describe: whether a company has a human rights policy commitment, whether it identifies and assesses its actual and potential impacts (including in its supply chain, not just its own operations), and whether it has a functioning grievance and remediation channel. A company can score well on S1's specific labour indicators and still have a real S3 gap if it has never systematically assessed human rights risk in its supply chain — the two subjects test different things, even though they draw on overlapping international labour and human rights norms.
How S3 Is Checked at Level 3
Two of the eight Level 3 on-site checklist domains map directly onto human rights due diligence, and not coincidentally — they're the same two domains SA8000 verification relies on, because the underlying evidence (personnel records, worker testimony) overlaps heavily with human rights due diligence even though the frameworks are distinct. Labour records cross-checks examine sampled personnel files against payroll and working-hours records, including age verification and contract terms — evidence of whether declared policy matches documented practice. Worker interviews, conducted confidentially and away from management, cover freedom of association, discrimination, disciplinary practices, and — specifically relevant to S3 — whether workers actually know how to access a grievance mechanism, not just whether one exists on paper. This second point matters more than it might first appear: the UNGPs' effectiveness criteria for grievance mechanisms (Section 10) require that a mechanism be accessible, and the only reliable way to check accessibility is to ask the people the mechanism is meant to serve, which is exactly what a confidential worker interview is designed to do that a document review alone cannot.
Germany's LkSG: The UNGPs Turned Into Binding Law
The Lieferkettensorgfaltspflichtengesetz (Act on Corporate Due Diligence Obligations in Supply Chains, universally shortened to LkSG) took effect on 1 January 2023 and is one of the clearest examples anywhere of the UNGPs' voluntary framework becoming enforceable national law. It applies to enterprises headquartered or with a qualifying branch in Germany with at least 3,000 employees domestically (including those posted abroad); that threshold dropped to 1,000 employees from 1 January 2024, sharply widening the law's reach. LkSG defines a "human rights risk" as a condition where, based on factual circumstances, a violation of one of twelve enumerated prohibitions is sufficiently probable — child labour, forced labour, disregard of occupational safety obligations, suppression of freedom of association, discriminatory treatment, withholding of an adequate living wage, and unlawful land or water seizure among them — alongside a parallel list of environment-related risks (mercury handling, hazardous waste trafficking, and prohibited persistent organic pollutants under the Minamata and Stockholm Conventions). The specificity is deliberate: unlike the UNGPs' principle-level language, LkSG gives companies (and regulators) an enumerated, checkable list rather than a general standard to interpret case by case.
LkSG's Due Diligence Obligations, Mapped to the UNGPs Cycle
- Identify — an annual (and ad hoc, where risk materially changes) risk analysis of the company's own business area and its direct suppliers, with results communicated to relevant decision-makers such as the board or the purchasing department.
- Prevent — a board-adopted policy statement on the company's human rights strategy, plus preventive measures in its own business area (procurement practices, staff training, risk-based controls) and vis-à-vis direct suppliers (contractual assurances, supplier training, agreed control mechanisms).
- Mitigate — remedial action without undue delay where a violation has occurred or is imminent: ending the violation directly where it's within the company's own German operations, or, where a direct supplier is responsible and the company can't end the violation outright, drafting and implementing a concrete, timetabled plan to end or minimise it. Ending the business relationship entirely is treated as a last resort, required only where the violation is very serious, the improvement plan has failed, and no less severe option remains — the same leverage-first logic the UNGPs themselves describe (Section 6).
- Account — continuous internal documentation (retained at least seven years) plus an annual report, published on the company's own website within four months of the financial year's end, stating what risks were identified, what measures were taken, how their effectiveness was assessed, and what the company concluded for future action. This is the UNGPs' voluntary "account" step made into an unconditional, publicly checkable legal filing.
A mandatory internal complaints procedure — accessible, confidential, and protecting complainants from retaliation — runs across the whole cycle, functioning as both an identification channel (a way to surface risks the company's own risk analysis missed) and, per Section 10 above, one of the UNGPs' own core criteria for what a legitimate grievance mechanism has to provide.
Beyond Your Own Walls: LkSG's Supply-Chain Reach
LkSG's most consequential feature, and the one most directly inherited from the UNGPs' "directly linked...by its business relationships" language (Section 3), is that its due diligence obligations don't stop at a company's own operations. The law defines the supply chain as covering all steps needed to produce a company's products or provide its services, from raw-material extraction to delivery to the end customer, split into three tiers: the company's own business area, its direct suppliers (contract partners whose supplies are necessary for the company's product or service), and its indirect suppliers (everyone further upstream). The obligation depth differs by tier and mirrors the UNGPs' own graduated, leverage-based approach precisely: full risk analysis and preventive measures are required proactively for the company's own operations and its direct suppliers, while indirect suppliers only trigger a duty to act — a risk analysis, preventive measures, and where needed a prevention or minimisation concept — once the company has "substantiated knowledge" of a possible violation there, typically surfaced through the complaints procedure. This tiered structure is a practical answer to a problem the UNGPs themselves acknowledge: enterprises with large, layered value chains often can't reasonably conduct full due diligence across every tier at once, so the law concentrates proactive obligations where a company has the most direct relationship and leverage, and reserves reactive obligations for where credible evidence of a problem actually surfaces further upstream. Enforcement carries real weight: Germany's Federal Office for Economic Affairs and Export Control (BAFA) can order corrective-action plans, and large enterprises face fines of up to 2% of average annual global turnover for the most serious violations — a scale of exposure that has made LkSG a template other jurisdictions have since drawn on for their own mandatory human-rights-due-diligence legislation.
Getting Started
- Draft a short policy statement naming the human rights risks most relevant to your operations and supply chain, and get it approved at the most senior level available — even a founder's sign-off, for a small company.
- Run a basic risk assessment of your own operations and your direct suppliers, focused on the areas SA8000 and this primer both flag as highest-risk: child and forced labour, health and safety, freedom of association, and living wages (see Labour Practices and Decent Work for the detailed criteria).
- Set up an accessible complaints channel and confirm — by actually asking workers, not just by publishing a policy — that people know it exists and trust it.
- Document what you find and what you do about it, even informally; this is exactly the record that would substantiate an S3 answer at Level 2 and that an auditor would cross-check at Level 3.
- Revisit the assessment at least annually, and whenever your operations or supply chain change materially — a due-diligence process that's run once and never updated isn't meeting the UNGPs' own "ongoing" requirement (Section 5).
Standard ESG (standardesg.org) organizes human rights and due diligence under Social pillar subject S3, checked at Level 3 through labour-records cross-checks and confidential worker interviews. See The Standard ESG Certification Protocol: A Public Overview for how S3 fits into the full pillar and subject architecture.
Was this page useful?