A designated responsible person should own the programme, but effective compliance usually depends on a cross functional working group. Legal, compliance, sustainability, and procurement each contribute to risk identification, prioritisation, and remediation. Clear accountability matters because supply chain due diligence fails when ownership is fragmented, and no single team can see the full operational and regulatory picture.
Who should own LkSG compliance when responsibilities are split?
LkSG compliance works best when one named accountable owner coordinates the programme, even if legal, procurement, and sustainability each carry part of the operating burden. The main risk is not that teams contribute, but that no one is answerable for deadlines, evidence, escalation, and remediation when supplier issues surface across multiple functions.
A useful operating model is to separate accountability from execution. One owner should be able to make decisions, assign actions, and escalate gaps, while the contributing functions provide the specialist inputs needed for due diligence, supplier engagement, contract changes, and monitoring. Without that split, compliance becomes a coordination exercise with no clear decision point.
For the underlying governance pattern, the question is less about which team “does” the work and more about who can close the loop when conflicting priorities arise. Procurement may hold supplier relationships, legal may interpret obligations, and sustainability may drive the broader human-rights and supply-chain lens, but a single accountable person or role must integrate those views into one programme record.
What shared responsibility should look like in practice
The most effective model is a cross functional working group with a designated programme owner. That owner should not be a passive coordinator; they need authority to set the reporting cadence, require evidence, and push unresolved supplier issues to the right decision maker. Cross functional participation matters because LkSG obligations typically span policies, supplier assessments, remediation plans, and documentation.
Legal usually anchors interpretation and defensibility, procurement owns supplier leverage and commercial follow through, and sustainability often tracks broader due diligence expectations and stakeholder reporting. The programme fails when these duties are treated as separate workstreams instead of one chain of accountability. A governance and audit perspective on identity and access controls reinforces the same structural lesson: distributed tasks are fine, but responsibility must remain traceable.
That model is especially important when supplier remediation touches multiple approval paths. If a high risk supplier is missing required controls, one owner must decide whether to accept the residual risk, escalate for executive review, or trigger contractual and operational changes. Otherwise, each team can point to another team while the compliance gap remains open.
A practical analogy comes from broader compliance programmes: the most durable arrangements use a single accountable lead plus defined contributors, not a committee with shared ownership and no final decision maker. Cloud compliance governance follows the same pattern, because evidence collection and control ownership break down when no one owns the outcome.
Risk and Threat Considerations
When accountability is split across legal, procurement, and sustainability without one named owner, the main failure mode is drift: tasks get completed locally, but no one sees whether the full due diligence obligation has actually been met. That creates exposure in supplier screening, remediation tracking, audit evidence, and escalation timing, especially when issues move between commercial and compliance teams.
Failure mechanism: Fragmented responsibility creates handoff gaps, inconsistent risk prioritisation, and missing or delayed escalation, so supplier issues can remain unresolved even though each team believes it has done its part.
Impact: The organisation can miss statutory obligations, weaken its audit trail, and lose the ability to show that risk decisions were timely, consistent, and properly owned.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 and NIS2 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-18 — Service Provider Management | LkSG compliance depends on governing third-party supplier obligations and follow-through. |
| Recommendation — Track supplier obligations centrally and enforce remediation deadlines across service providers. | ||
| NIST CSF 2.0 | GV.RM-04 — Risk Management Strategy | This asks who owns compliance risk when multiple functions share work. |
| GV.OV-01 — Organizational Context | The answer hinges on defining roles and decision rights across legal, procurement, and sustainability. | |
| GV.SC-02 — Cyber Supply Chain Risk Management Strategy | Supplier due diligence and remediation are central to the question’s supply-chain compliance context. | |
| Recommendation — Assign one accountable risk owner who can resolve conflicts across contributing teams. Define decision rights and accountability so compliance tasks do not fragment across functions. Maintain a supplier risk strategy with clear ownership for due diligence and corrective actions. | ||
| ISO/IEC 42001:2023 | 4.2 — Needs and expectations of interested parties | LkSG compliance requires aligning obligations across internal functions and external stakeholder expectations. |
| 5.3 — Roles, responsibilities and authorities | The question is fundamentally about accountable ownership across a cross-functional programme. | |
| Recommendation — Map stakeholder obligations to one accountable owner and coordinated supporting roles. Define one accountable role and document supporting responsibilities for each function. | ||
| NIS2 | 21(2)(d) — Supply chain security measures | The subject involves supply-chain due diligence and supplier-risk governance. |
| Recommendation — Assign supply-chain security ownership so supplier risks are assessed and remediated consistently. | ||
Practitioner Guidance
What to prioritise: Assign one accountable programme owner and document which team is responsible for legal interpretation, supplier engagement, remediation tracking, and reporting. The first check is whether that owner can force a decision when procurement and legal disagree on supplier risk or remediation timing.
What to verify: Make sure the operating model has a single evidence trail, a defined escalation path, and a named approver for exceptions. If supplier issues are being tracked in multiple systems or by multiple teams without a shared status view, the programme is already at risk of losing control of deadlines and proof.
Practitioner takeaway: Cross functional participation improves LkSG compliance, but only one role should be accountable for the outcome; shared work without single-point ownership usually weakens both remediation speed and defensibility.
Related resources from NHI Mgmt Group
- Who is accountable for cybersecurity compliance under Chile’s framework law when responsibilities span multiple teams?
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- Who is accountable when privacy obligations span identity, data, and compliance teams?