77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Building compliance guidelines: architecture, hierarchy and audit-proof maintenance
Governance & Compliance

Building compliance guidelines: architecture, hierarchy and audit-proof maintenance

1 August 202612 min readBy Dr. Henrik Bauer
CIVAC

Compliance guidelines are the skeleton of every compliance management system. Find out which three levels ISO 37301:2021 requires, why maintenance in SharePoint fails and how a workspace code of conduct, procedural instructions and work instructions combine in an audit-proof manner.

Compliance guidelines form the normative backbone of a compliance management system according to ISO 37301:2021. In Section 5.2, the standard requires a documented compliance policy that is approved by top management, communicated within the company and regularly reviewed. In addition, Section 130 OWiG requires the organisational supervisory measures that management must take to prevent violations. A robust set of guidelines translates these abstract obligations into concrete instructions that every employee can know and apply. In its Neubürger judgment of May 8, 2017 (5 StR 50/16), the Federal Court of Justice determined that written guidelines are a necessary but not sufficient component of an effective CMS. They actually have to be lived, trained and monitored.

This guide shows which three document levels a modern set of guidelines includes, where German medium-sized companies typically fail and how code of conduct, procedural instructions and work instructions can be interlinked in a workspace in an audit-proof manner. You will receive a concrete structural template, an overview of the mandatory guidelines per sector and a maintenance plan with which you can build up the guidelines in twelve weeks and keep them permanently up to date. In the end, you know which guidelines you need today, how often they need to be checked and how a workspace replaces manual maintenance in SharePoint.

Key Takeaways

  • ISO 37301:2021 requires three document levels: an overarching compliance policy, topic-specific procedural instructions and specific work instructions, each with versioning and release processes.
  • Section 130 OWiG requires not only the existence but also the demonstrable effectiveness of the guidelines, with proof of training, knowledge and documented violations as well as corrective measures.
  • A workspace with version status, release workflow and awareness tracking replaces SharePoint and Excel and reduces maintenance effort by 40 to 60 percent.

The three document levels: policy, procedure, work instructions

A professional set of guidelines follows a three-tier hierarchy. At level one is the compliance policy, a two to four page policy document signed by top management. It names the values, the commitment, the responsibilities and the consequences for violations. Level two contains the procedural instructions, topic-specific documents of ten to thirty pages that completely regulate a compliance area. Typical topics include gifts and invitations, donations and sponsorship, conflicts of interest, money laundering prevention, data protection, information security and supplier relationships. Level three contains work instructions, short operational documents of one to five pages that describe a specific process step, such as releasing an invitation for 100 euros or reporting a data protection incident.

The three levels are not arbitrary. ISO 37301:2021 requires documented information in Section 7.5 that is differentiated according to scope, liability and level of detail. Anyone who bundles everything into one document produces a 400-page manual that no one reads and that has to be completely re-released when the law is first changed. On the other hand, if you separate the levels clearly, you can review the policy once a year, adjust the procedural instructions every six months and adjust the work instructions as needed. As a compliance platform and officer-as-a-service, CIVAC provides a structural template with 12 procedural instructions and over 40 work instructions that can be modularly adapted to the industry and size. Detailed role descriptions can be found at Compliance Officer, where responsibility for the set of guidelines is also documented. The three levels are consistently linked: The Code of Conduct refers to the procedural instructions, which refer to the work instructions, so that the employee goes from the abstract statement to the concrete rule of action in two clicks. If you maintain this link properly, you will significantly reduce the search time in everyday life and increase the likelihood that the policy will actually be applied instead of disappearing in SharePoint.

Mandatory guidelines per sector: what is really needed

Not every company needs every policy. Which procedural instructions are indispensable depends on the register of obligations and the risk profile. A German medium-sized company in mechanical engineering typically has twelve to fifteen mandatory procedural instructions, including code of conduct, anti-corruption, data protection, information security, money laundering prevention (if required under the AMLA), whistleblower protection under the HinSchG, gifts and invitations, conflicts of interest, supplier due diligence (LkSG for 1,000 employees or more), export control, antitrust law and occupational safety. There are also sectoral obligations, such as MaRisk for banks, GMP for pharmaceuticals or NIS-2 for critical and important institutions. Anyone who properly sets up the register of obligations will receive a reliable list of the necessary guidelines instead of deciding based on gut instinct which topics should be regulated.

A common pitfall is the uncritical adoption of a group guideline from the English-speaking parent company. The German legal situation differs in details, such as co-determination according to the BetrVG, the implementation of the GDPR in the BDSG or the whistleblower reporting point according to the HinSchG. A directly translated guideline is assessed as inadequate in the audit because it does not reflect the German specifics. A bilingual approach makes sense: the policy remains consistent with the group and the procedural instructions are localized for Germany. The Internal Reporting Office (HinSchG) is an example of this because the HinSchG contains several requirements that are missing from many corporate guidelines, such as the seven-day confirmation of receipt and the three-month feedback. The appointment certificate, signed, filed, verifiable. The principle applies analogously to every mandatory directive: the corporate logic provides the framework, the German implementation fills it with the national obligations and ensures that the auditor and authority see the same version as the employee in day-to-day business. A consolidated mandatory matrix that links each mandatory procedural instruction with the law, standard, need for co-determination and owner is the tool of choice for this.

Code of Conduct: what really belongs and what doesn't

The Code of Conduct is the flagship of the set of guidelines. It is addressed to all employees, is linguistically understandable, is usually between 10 and 25 pages long and is signed by management. In terms of content, there are six areas: firstly, the values ​​and self-image of the organisation, secondly, behaviour towards colleagues and the prohibition of discrimination according to AGG, thirdly, behaviour towards customers and business partners including anti-corruption and gift rules, fourthly, the handling of information, data and property, fifthly, the avoidance of conflicts of interest and sixthly, the reporting channels in the event of tips or suspicions. Each of these areas refers to the relevant procedural instructions in which the details are regulated.

What doesn't belong is at least as important as what does. The Code of Conduct is not a manual for every individual case. Specific thresholds, such as the 35 euro limit for gifts, belong in the procedural instructions for gifts and invitations, not in the Code of Conduct. Otherwise the code will have to be re-released every time it is adjusted. Marketing language and non-binding wish formulations are also not included because they dilute the obligation and will be judged to be unenforceable in court in the event of a dispute. A clear, precise code with concrete references to the procedural instructions is the basis on which the entire set of guidelines is built. Others run compliance like a filing cabinet. We run it like software. In the CIVAC workspace, the code is linked to all referenced procedural instructions, so that employees can jump from the general statement to the specific rule with just one click. The code is also bilingual because many medium-sized companies today work in mixed international teams and expect a uniform formulation of values ​​in German and English.

Procedural instructions: structure, content, level of detail

A procedural instruction follows a recurring structure: purpose and scope, definitions of terms, legal basis, responsibilities with RACI matrix, described process with decision points, interfaces to other processes, documentation requirements, applicable documents, training requirements, review cycle and change history. These eleven components are the minimum that an auditor expects. Without a RACI matrix, responsibility remains unclear, without a review cycle there is no evidence of ongoing maintenance, and without a change history it cannot be proven which version was valid at the time of the crime. The level of detail is based on the risk: procedural instructions for anti-corruption must contain concrete thresholds, decision-making processes and escalation rules because the risk is high. A procedural instruction for internal travel expense accounting remains leaner because the risk is limited.

A volume of 10 to 30 pages per procedural instruction has proven to be useful in practice. Longer documents are not read, shorter ones leave gaps. The language is factual, in you form, with short sentences and clear terms. Marketing language, double negatives and subjunctives should be avoided because they make interpretation difficult in the event of a conflict. CIVAC supplies a tested template with the eleven components for each process instruction, which only needs to be filled out in a company-specific manner. Licence the workspace for your internal representatives, or have our representatives order it. In the second model, an experienced compliance officer takes over the creation of the procedural instructions and the coordination with the works council in accordance with Section 87 BetrVG, so that the documents can be transferred directly to the company instead of hanging in committee loops for months. On average, two to four weeks should be planned for each procedural instruction from the first draft to formal approval, depending on the complexity of the topic and the number of areas affected.

Release, versioning and the question of the deadline

A policy is only effective once it has been approved, communicated and acknowledged. The release process must be documented and include at least four steps: technical preparation by the compliance officer, technical review by the affected areas (legal, HR, IT, finance depending on the topic), formal release by management with date and signature, and publication on the intranet or workspace. In the case of content requiring co-determination, the works council is also involved in accordance with Section 87 BetrVG, for example in regulations on order, behaviour or technical monitoring devices. A violation of co-determination makes the directive ineffective, as the Federal Labour Court has made clear in several decisions.

Versioning is the most common stumbling block in audits. If an auditor asks which version of the Anti-Corruption Policy was in effect on March 15, 2025, that question must be answerable within minutes. SharePoint usually cannot do this because the version history there is not audit-proof and protected against manipulation. The CIVAC workspace lists each policy with a unique version number, release date, start and end of validity, so that the deadline status can be reproduced at the push of a button. The auditor calls, the evidence is ready. In addition, all information received by employees is logged with a time stamp, so that in the event of a dispute it can be proven that and when the employee read the applicable version. This feature is particularly relevant in employment disputes where management must prove that they were actually aware of the policy. In addition, the key date query makes the annual audit process easier: upon request, the external auditor receives the version valid on the key date as well as a complete history of all changes with date and reason.

Communication, training and awareness

A policy that is only released but not communicated has no effect. ISO 37301:2021 requires in Section 7.4 the communication of internal and external compliance requirements in a target group-appropriate manner. In practice, this means three steps: firstly, the initial communication to all employees when it comes into force, secondly, the role-based training with learning success monitoring and thirdly, the regular refresher, at least once a year for standard guidelines and every six months for high-risk areas such as anti-corruption or export control. Training is not fulfilled if only an email with the policy is sent. Documented learning success is required, for example through e-learning with a test or face-to-face training with a list of participants. The training content must be versioned so that it is clear in the audit which training was completed with which version of the guidelines and at what point in time.

The employee's knowledge is relevant under labour law. Only those who have demonstrably taken note of a directive can be sanctioned for violations. Mere publication on the intranet is not enough if the employee has not been asked to take note. The CIVAC workspace combines publication, training and information in one workflow: When a new version is published, the affected employees receive a notification with an obligation to acknowledge it by a deadline. Acknowledgment is logged with a time stamp and IP address. If there is no response, the system automatically escalates to the manager. Audit-proof, documented, § 130 OWiG-proof. This creates complete proof that the directive was actually known, which ensures that sanctions can be imposed in the event of a dispute and makes it easier for management to provide evidence of the supervisory obligation. Anyone who additionally couples the acknowledgment with a question of understanding significantly increases the impact of the directive and reduces the burden of argumentation in labour law proceedings.

Care plan: review cycles, event reference and law enforcement

A set of guidelines is only as good as its maintenance. ISO 37301:2021 requires regular review of compliance obligations and the documents derived from them. A three-part care plan has proven itself: firstly, a fixed review cycle for each document level (annually for the policy, semi-annually or annually for procedural instructions, event-related for work instructions), secondly, reference to changes in the law, incidents or organisational changes, thirdly, a law watchdog who actively observes relevant innovations and enters them into the register of obligations. Anyone who neglects one of these three components runs the risk of working with outdated documents that will be assessed as inadequate in the audit.

In practice, the care plan is often underestimated. Medium-sized companies often manage the guidelines with great discipline in the development phase, but let ongoing maintenance slide as soon as other priorities come to the fore. After two years, half of the documents no longer correspond to the current legal situation. CIVAC integrates a deadline monitor into the workspace, which automatically writes review cycles into the calendar of the responsible officer and sets lead times before the deadline. Deadline begins as soon as we become aware of it. In addition, a regulatory news feed feeds changes in the law into the register of obligations so that the affected procedural instructions are automatically marked for review. This creates a quarterly report for the management on the updated status of the guidelines, which flows into the management review according to ISO 37301 and documents the supervisory obligation according to Section 130 OWiG. A consolidated status report shows the maturity level, the last review date, the next review date and the number of outstanding corrective actions for each procedural instruction, so that the status of the entire set of guidelines can be recorded in five minutes.

Typical mistakes and how to avoid them

Six errors occur particularly frequently in German medium-sized organisations. First: The guidelines are too long. A 400-page manual is not read, not understood and not used. Solution: Separate policies, procedures and work instructions according to the level of detail. Second: The responsibilities are unclear. Without a RACI matrix, gaps and overlaps arise. Solution: Each procedure instruction contains a RACI matrix with specific roles, not departments. Thirdly: the co-determination of the works council is forgotten. A directive issued without participation is ineffective if it contains content requiring participation. Solution: Check during the creation phase whether Section 87 BetrVG is relevant and document the coordination.

Fourth: The versioning is inadequate. SharePoint and file servers do not provide an audit-proof version history. Solution: A dedicated workspace with versioning, release protocol and deadline query. Fifth: Training is forgotten. A policy without proof of training has no sanctioning effect. Solution: Include training requirements in every policy, document learning success, plan refreshers. Sixth: Nursing falls asleep. After two years, the documents are no longer current. Solution: Deadline monitor, legal news feed and management review appointments in the compliance officer's calendar. CIVAC addresses all six errors in the workspace, from the modular structure template to the RACI matrix to the deadline monitor and the legal news feed. Others run compliance like a filing cabinet. We run it like software. Anyone who systematically avoids the six errors significantly reduces the liability risk of management because the set of guidelines then not only exists formally, but actually has an effect. The combination of workspace, clear hierarchy and practiced care is the difference between a compliance façade and a resilient system that will also convince a public prosecutor in an emergency.

From the guidelines paper to the lived system

A set of guidelines thrives on repeatability. Publication, training, information and maintenance must come together in a system that management can provide information at any time. This is exactly why we built CIVAC as a compliance platform and officer-as-a-service: a workspace with over 50 policy templates, a release workflow with versioning, a training and awareness module, a deadline monitor with legal news feed and EU data residency. You decide for yourself how deep you want to go: licence the workspace for your internal representatives, or let our representatives do the work. Both models use the same system with identical documentation, and they can be switched between internal and external staffing at any time without losing the documentation history.

Building up a reliable set of guidelines takes twelve to twenty weeks using a structured approach, depending on the initial situation and sector. Turn reading into an assignment. Write to us at info@civac.de or book an initial consultation using the contact form on civac.de. You receive an honest inventory of your current policies, a gap and overlap analysis, a prioritised action list and a transparent offer. In the first 30 days, a new Code of Conduct, a consolidated mandatory matrix and a care plan for the next 24 months are created. In the following 60 days, the mandatory procedural instructions will be structured modularly and put into production in the workspace. Training, awareness and the first management review will roll out in the last 30 days. The auditor calls, the evidence is ready. A well-maintained set of guidelines is not the goal, but the foundation for the entire compliance management system. Once you have set it up cleanly and transferred it to a workspace, you not only gain audit security, but also operational speed, because every new obligation can be integrated into the inventory without filing cabinet exercises.

FAQ

How many compliance guidelines does a German medium-sized company need?

Typically a Code of Conduct plus twelve to fifteen procedural instructions, supplemented by around 30 to 50 work instructions. The exact number depends on the duty register, the sector and the risk profile. Mechanical engineering, pharmaceuticals and financial services have more mandatory procedural instructions than IT services or retail. A reliable inventory as part of a duty analysis provides the exact number and avoids both over- and under-regulation.

Is a corporate policy from the English-speaking parent company sufficient for the German subsidiary?

No. The German legal situation differs in details, for example when it comes to co-determination according to the BetrVG, the BDSG or the HinSchG. A directly translated corporate directive is often assessed as inadequate in the audit because it does not reflect the German specifics. A bilingual approach with a consistent policy and localized procedural instructions that preserves the corporate logic and at the same time covers German obligations makes sense.

How frequently do compliance policies need to be reviewed?

The policy once a year, procedural instructions annually to semi-annually depending on the risk, work instructions as needed for process changes. In addition, there are extraordinary reviews in the event of changes to the law, incidents or organisational changes. A documented review cycle is mandatory according to ISO 37301:2021, and proof of this is part of every audit and the annual management review of the management, without which the supervisory obligation according to Section 130 OWiG cannot be proven.

How is knowledge of a directive documented in a legally secure manner?

Simply publishing on the intranet is not enough. What is required is active acknowledgment with a time stamp, ideally with an IP address, documented access to the current version and confirmation by the employee. For high-risk areas, additional training with learning success monitoring is required, and the learning success must be linked to the applicable guideline version so that the historical evidence works.

What happens if the works council was not involved in a directive requiring co-determination?

The directive is ineffective in this respect, as the Federal Labour Court has made clear in several decisions. Sanctions against employees based on a directive issued without co-determination are then untenable under labour law. Participation must be made up before it is issued or replaced by a conciliation board decision, which takes time and, in the worst case, delays the planned effect by months.

What advantage does a Workspace offer over SharePoint for compliance policies?

A dedicated compliance workspace offers audit-proof versioning, automated release workflows, notice tracking, deadline monitor, legal news feed and deadline queries with clear version status. SharePoint generally cannot map these functions in an audit-proof manner and leads to considerable manual maintenance effort and audit risks because the version history is not protected against manipulation, information cannot be systematically requested and there is no reference to the key date.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles