Skip to main content

Manage risks with the BISS/CAIGO software—the comprehensive solution in the cloud!

Document management

Questionnaire administration, risk assessment evaluations and management

Evaluated suppliers

according to the risks defined by the company; critically evaluated suppliers have the opportunity for improvement

BISS as service provider

provides the software as SaaS solution

The German Supply Chain Due Diligence Act (LkSG), which is still in force, will be replaced at the EU level by the Corporate Sustainability Due Diligence Directive (CSDDD, also: CS3D). This directive includes the requirements of the LkSG and even goes further.

For risk management in the supply chain, you need intelligent technical support. BISS/CAIGO is a unique cloud-based risk management software for the largely automated and legally compliant fulfillment of your due diligence obligations. With this powerful software, you can manage risks along entire supply chains.

Manage risks with the BISS/CAIGO software—the comprehensive solution in the cloud!

The German Supply Chain Due Diligence Act (LkSG), which is still in force, will be replaced at the EU level by the Corporate Sustainability Due Diligence Directive (CSDDD, also: CS3D). This directive includes the requirements of the LkSG and even goes further.

For risk management in the supply chain, you need intelligent technical support. BISS/CAIGO is a unique cloud-based risk management software for the largely automated and legally compliant fulfillment of your due diligence obligations. With this powerful software, you can manage risks along entire supply chains.

Document management

Questionnaire administration, risk assessment evaluations and management

Evaluated suppliers

according to the risks defined by the company; critically evaluated suppliers have the opportunity for improvement

BISS as service provider

provides the software as SaaS solution

With BISS/CAIGO, you can easily implement risk management for your supply chain in accordance with LkSG and CSDDD

The main features of BISS/CAIGO:
  • You recognize the risk profiles of your supply partners
  • You prioritize risks and counteractive measures
  • You manage risks of complete(!) supply chains
  • You implement the measures for risk elimination
  • You receive support in the legally required annual effectiveness review of your measures
  • You fulfill the reporting obligation to Bafa

Your decision for BISS/CAIGO is future-proof

BISS/CAIGO already meets the EU requirement to review entire supply chains from 2026/2027. In addition to direct supply partners, indirect supply partners will also have to undergo a risk analysis.

With BISS/CAIGO, you are therefore opting for a future-proof solution now.

Overall risk assessment by region and country in terms of probability of occurrence and severity

    With BISS/CAIGO you keep the overview!

    The dashboard presents the evaluated risk profile of your supplier relationships with regard to selected risks (here: child labor). The weighting of the purchasing volume is broken down for direct and indirect suppliers.
    The CAIGO portal allows you to see the project status at a glance.
    The supplier portal brings together all the information about your supply partners.
    The supplier list provides an overview of key data on your supply partners and their respective risk profiles.
    Intuitive creation of a new questionnaire with the questionnaire designer
    Modification of a selected question catalog with translation function into one of the 24 stored target languages
    Risk-adequate measures can be stored for each supplier and their implementation can be monitored

      This is how BISS/CAIGO supports you in implementing risk management

      The requirements for supply chain risk management are complex. Intelligent risk management software is essential to fulfill supply chain and sustainability due diligence. With BISS/CAIGO, companies can rely on a future-proof solution from the outset.

      In brief: The background

      What is the LkSG/CSDDD about?

      The aim of the German LkSG of July 16, 2021 is to improve the international human rights situation, the sustainability of the economy and the protection of the environment. The LkSG governs the economic activities of companies based in the Federal Republic of Germany with more than 1,000 employees in Germany. Companies must comply with their duty of care and scrutinize their global supply relationships to determine the extent to which certain standards are observed during production.
      The benchmark for this are seven of the seventeen ESG sustainability goals of the United Nations (UN), which primarily affect human rights. They also pursue ecological goals, as soil contamination or air and water pollution can directly affect the quality of life of people in the producing countries. In the event that companies do not comply with this duty of care (to a sufficient extent), sanctions for the companies are written into the law. This is why we speak of "risks" that must be assessed.

      Tightening of the LkSG through CSDDD

      An extension and tightening of the LkSG is the Corporate Sustainability Due Diligence Directive (CSDDD, also: CS3D) of the European Commission. As part of the European Green Deal, the CSDDD is a requirement that aims to promote sustainable corporate governance in the EU. This EU directive on corporate due diligence to comply with ESG criteria was launched at the end of 2023 by the European Council and the European Parliament.

      In brief: The procedure

      Risk analysis

      Knowing the human rights and environmental risks in your own supply chain is key to fulfilling due diligence obligations. The procedure: First, an abstract risk analysis is carried out: In which countries and sectors are there generally which risks? This is based on the Sustainable Development Goals (SDG goals) and 17 ESG criteria. In the next step, the supply partners are subjected to a concrete risk assessment. These are identified using questionnaires.

      Establish preventive measures

      Companies can use suitable and appropriate contractual agreements to ensure that the supplier introduces measures to avoid identified risks in the future. The philosophy of the LkSG is based on the idea of cooperation between companies within the supply chain. It is important to note that "the LkSG does not establish independent liability standards between contractual partners along the supply chain. Obligated companies should flank contractual assurances with control measures, training and further education on their own responsibility."
      (www.bafa.de, page 5)

      Establish remedial measures

      If risks have been identified in a specific individual case, a proposal for remedial measures should be developed in close consultation with the supply partner in accordance with the criteria of appropriateness and effectiveness.

      In this context, it is worth noting that "companies do not have to guarantee that their supply chains are free from risks to and violations of human rights or adverse effects on the environment as part of the duty of care stipulated by the LkSG. Rather, they must be able to prove that they have implemented the due diligence obligations described in more detail in Sections 4 to 10 LkSG."
      (www.bafa.de, page 1f.; emphasis added by us)

      Reporting/complaints procedure for whistleblowers

      The companies affected by the LkSG are obliged to establish a procedure that is accessible at all times and protects the confidentiality of the identity of whistleblowers.

      Notification to the Bafa
      The companies obliged to implement the LkSG are to document their efforts to comply with the due diligence obligation and provide evidence of this to the Bafa on an annual basis. A reporting procedure is established for this purpose. Baja can initiate a review on its own initiative.

      BISS/CAIGO modules at a glance

      BISS/CAIGO has a modular structure and is offered as a SaaS solution. All data is backed up in the cloud and therefore accessible worldwide. The main modules and features of the BISS/CAIGO supply chain/CSDD software are briefly explained here:

      Risk-Hub

      A central module that serves as the hub for all risk management activities. The Risk Hub enables the creation and adaptation of risk models based on predefined and customizable models for various legal requirements and different industries. The risk profile of each supplier can be created automatically in the hub.

      Supplier module

      Supplier management with supplier-specific risk analysis and measures. Suppliers can be loaded into the system either manually or via UpLoad or interface.

      Questionnaire module

      This module is used to create detailed questionnaires with a variety of question types, including digital signatures and automatic translation into 31 languages, which can be saved in an audit-proof manner. The basis are prepared, modifiable questionnaires with automatic evaluation of the answers.

      Measures manager

      Action Manager stands for every action in the direction of suppliers. The module is used to efficiently manage measures to remedy identified risks or critical incidents. It offers individually definable action types and workflows so that you can keep track of all actions. Catalogs of measures with different types of measures for risk elimination and prevention are prepared.

      Complaint management

      This module fulfills the requirements of the EU directives. It also complies with the German Whistleblower Protection Act (HinSchG). It offers all functions for whistleblower and complaint management - in 31 languages - which enables automated and manual processing. It can be adapted to the company's CI guidelines.

      Supplier portal

      Suppliers have their own portal to view, edit and upload the documents relevant to them.

      Dashboard

      The dashboard presents the evaluated risk profile of your supplier relationships with regard to selected risks. The weighting of the purchasing volume is broken down for direct and indirect supply partners.

      Workflow-/GUI-Designer

      A module for defining automated business processes that offers interactive and graphical workflow definitions as well as functional workflow components. The module is also used to create interactive, graphical dialogs. It is fully integrated into workflows and enables a simple connection to the BISS/CAIGO data model.

      User/rights management

      Flexible definition of user roles and access rights, including visibility settings for groups.

      Incident management

      AI-supported research in news and specialist portals to identify incidents within the supply chain.

      ERP interface (e.g. SAP)

      Existing interface for connecting ERP systems. The connection to SAP has already been implemented by a partner.

      Reporting function to Bafa*

      The interface has already been prepared on the program side.

      Risk-Hub

      A central module that serves as the hub for all risk management activities. The Risk Hub enables the creation and adaptation of risk models based on predefined and customizable models for various legal requirements and different industries. The risk profile of each supplier can be created automatically in the hub.

      Supplier module

      Supplier management with supplier-specific risk analysis and measures. Suppliers can be loaded into the system either manually or via UpLoad or interface.

      Questionnaire module

      This module is used to create detailed questionnaires with a variety of question types, including digital signatures and automatic translation into 31 languages, which can be saved in an audit-proof manner. The basis are prepared, modifiable questionnaires with automatic evaluation of the answers.

      Measures manager

      Action Manager stands for every action in the direction of suppliers. The module is used to efficiently manage measures to remedy identified risks or critical incidents. It offers individually definable action types and workflows so that you can keep track of all actions. Catalogs of measures with different types of measures for risk elimination and prevention are prepared.

      Complaint management

      This module fulfills the requirements of the EU directives. It also complies with the German Whistleblower Protection Act (HinSchG). It offers all functions for whistleblower and complaint management - in 31 languages - which enables automated and manual processing. It can be adapted to the company's CI guidelines.

      Supplier portal

      Suppliers have their own portal to view, edit and upload the documents relevant to them.

      Dashboard

      The dashboard presents the evaluated risk profile of your supplier relationships with regard to selected risks. The weighting of the purchasing volume is broken down for direct and indirect supply partners.

      Workflow-/GUI-Designer

      A module for defining automated business processes that offers interactive and graphical workflow definitions as well as functional workflow components. The module is also used to create interactive, graphical dialogs. It is fully integrated into workflows and enables a simple connection to the BISS/CAIGO data model.

      User/rights management

      Flexible definition of user roles and access rights, including visibility settings for groups.

      Incident management

      AI-supported research in news and specialist portals to identify incidents within the supply chain.

      ERP interface (e.g. SAP)

      Existing interface for connecting ERP systems. The connection to SAP has already been implemented by a partner.

      Reporting function to Bafa*

      The interface has already been prepared on the program side.

      * As soon as Bafa has completed the interface, the function can also be used.

      With BISS/CAIGO you manage the entire workflow:

      1

      Identify risks

      • Which risks are relevant for our company?
      • According to which criteria are the risks weighted?
      2

      Assess risks

      • Individual evaluation of country risks and commodity group risks
      • Aggregation of country and commodity group risks; classification of risks per supplier
      • Formation of supplier risk classes
      3

      Develop countermeasures

      • Derivation of standardized processes for preventive and remedial measures per supplier risk class
      4

      Implement countermeasures

      • Conduct supplier audits and sustainability workshops
      • Query risk strategies and management plans on supplier side
      5

      Risk review

      • Continuous risk tracking and risk analysis carried out at least annually
      • Documentation of results, e.g. as human rights and sustainability report
      • If necessary: Adaptation of processes and measures

        Do you need advice on the topic of LkSG implementation?

        We support you in meeting the challenges of the LkSG.

        Our partners in development and consulting

        scrm Consulting

        SCRM Consulting GmbH is an experienced partner for effective risk management in the supply chain, with a particular focus on sustainability. They understand that compliance with supply chain law can be a challenge. That's why they offer customized advice that focuses on your company-specific needs. The approach is designed to effectively utilize your existing tools, processes and documents. With SCRM Consulting, you navigate safely and efficiently to successful implementation of the due diligence obligations of the Supply Chain Act.

        Advist

        advist AG supports its customers as a partner in the digital transformation of all business-relevant process and IT topics. The focus is on companies from the fashion sector. With the foundation in April 2022, relevantly experienced managers join forces to support and advise their customers on their digital transformation journey in different roles.

        Ososoft

        ososoft is a pan-European consulting company with a focus on large IT, SAP and digitalization projects. For years, we have been working trustfully and intensively with our numerous and well-known customers, who are among the "big players" of our focus sectors Retail, Automotive and Industry. We understand their processes and the technologies behind them very well. That is why we usually provide full support, both with strategy and process consulting as well as with technical implementation, thus creating practical solutions.