CMS obligation: When a compliance management system becomes legally mandatory
A compliance management system is not prescribed in a single law, but results from Section 130 OWiG, the BGH case law and a large number of special laws. This article classifies from what size and in which sectors the obligation applies.
There is no legally expressly defined mandatory CMS for all companies in Germany. In fact, however, a compliance management system (CMS) has become unavoidable for a large proportion of medium-sized and large companies due to Section 130 OWiG, the constant BGH case law (e.g. BGH 1 StR 265/16 of May 9, 2017) and numerous special laws (GwG, KWG, MaRisk, LkSG, NIS2UmsuCG, EU-AI-Act). It is virtually impossible to fulfil management's supervisory duties without documented processes, responsibilities and controls. Insurers are increasingly linking D&O coverage to proof of an effective system, so that the obligation is also economically secured.
This article classifies the legal bases, describes the essential triggers for a specific CMS obligation and explains the minimum components that an audit-proof system must have. You will find out how the seven building blocks according to IDW PS 980 work together, what role the compliance officer plays, when the personal liability of managing directors according to Section 43 GmbHG, Section 91 Paragraph 2 AktG and Section 130 OWiG applies and how CIVAC as a compliance platform and officer-as-a-service enables the development of a resilient CMS in weeks instead of months. The appointment certificate, signed, filed, verifiable. Those who structure early avoid additional demands, fines and personal liability risks and at the same time secure their negotiating position with customers, insurers and supervisory authorities.
Key Takeaways
- There is no explicit, general CMS obligation, but Section 130 OWiG and special laws result in a de facto obligation for most medium-sized companies.
- The BGH recognises a documented CMS as reducing the fine (BGH 1 StR 265/16); conversely, its absence significantly increases the sanctions.
- An audit-proof CMS follows the seven building blocks according to IDW PS 980 and should be tested for effectiveness at least annually.
Legal basis: Section 130 OWiG, Section 30 OWiG and the management's duty of supervision
Section 130 Paragraph 1 OWiG obliges the owners of a business or company to take the supervisory measures that are necessary to prevent violations of business-related obligations. Anyone who intentionally or negligently fails to take these measures is themselves committing an administrative offense, with a possible fine of up to 1 million euros (Section 130 Paragraph 3 OWiG). In addition, Section 30 OWiG provides for an association fine against the company, in intentional cases up to 10 million euros, in negligent cases up to 5 million euros, in each case without limitation to the economic benefit from the act.
Which measures are required depends on the type, size and risk profile of the company. In decision 1 StR 265/16, the BGH expressly made it clear that the establishment of an effective compliance management system is suitable for reducing the fine or eliminating it entirely. Conversely, the lack of a CMS regularly leads to a tightening of the sanction because the breach of supervisory duty then becomes obvious. This was also confirmed in later case law and supplemented by specific requirements, in particular for testing effectiveness and assigning responsibility to the management.
The duties of the management bodies are anchored in Section 43 GmbHG, Section 91 Paragraph 2 AktG and Section 76 Paragraph 1 AktG. The Compliance Officer as an operational function is not legally mandatory, but in fact it can hardly be dispensed with because the management can delegate the supervisory duty, but cannot completely hand it over. If you don't have an internal candidate, you can order this role as an officer-as-a-service externally and thus bring in an experienced role with an appointment certificate, reporting line and demonstrable industry knowledge.
Special legal CMS obligations: Where the law becomes specific
Numerous special laws contain explicit or implicit CMS obligations. Section 4 of the Money Laundering Act (GwG) requires obligated parties to have effective risk management, which includes risk analysis, internal security measures and a money laundering officer. In the Banking Act (KWG), Section 25a specifies the obligation to have a proper business organisation, differentiated in the minimum requirements for risk management (MaRisk). In the Securities Trading Act (WpHG), an obligation for a compliance function follows from Section 80. The Insurance Supervision Act (Section 23 VAG) also requires a corresponding compliance function.
The Supply Chain Due Diligence Act (LkSG) has required risk management along the supply chain for companies with 1,000 or more employees since 2023, including complaint procedures, risk analysis and reporting obligation to BAFA. The NIS2UmsuCG, which implements the NIS 2 Directive into German law, establishes mandatory cybersecurity risk management in accordance with Section 30 BSIG for around 29,500 companies, including 24-hour early warning and 72-hour follow-up reporting to the BSI. The EU AI Act requires a quality and risk management system for high-risk AI systems from August 2026, which requires a documented compliance system. Violations are sanctioned with fines of up to 35 million euros or 7% of group sales.
In data protection, the duty of accountability follows from Art. 5 Para. 2 GDPR and the implementation of appropriate technical and organisational measures from Art. 32 GDPR. The 72-hour reporting period for data breaches in accordance with Art. 33 GDPR is practically impossible to comply with without CMS structures. This means that the range of special legal obligations is wide enough that almost every medium-sized company has to combine at least three relevant areas of law, which in turn can only be efficiently controlled via a central CMS. Others run compliance like a filing cabinet. We run it like software. Medium-sized companies that have to report on several regimes in parallel benefit particularly because there is no duplication of work between AMLA, NIS-2 and LkSG and receipts are only deposited once.
Case law: BGH 1 StR 265/16 and the subsequent judgments
The BGH decision 1 StR 265/16 of May 9, 2017 (so-called AUB judgment) is considered a turning point. The BGH determined that the establishment of an effective compliance management system as well as subsequent improvements after a violation was discovered must be taken into account when calculating the association's fine. Specifically: An effective CMS can reduce the fine by up to 50%. However, the prerequisite is that the system is actually lived and not just formally exists. The BGH particularly requires risk analysis, training, clear responsibilities, a whistleblower system and regular effectiveness testing. Evidence is provided regularly via training registers, audit reports and reporting lines.
The meaning of the documentation was specified in subsequent decisions (including BGH 1 StR 19/19 of June 11, 2020). It is not the presence of a file folder that is crucial, but rather the anchoring of the system in real business processes. Mere compliance guidelines without training, without a whistleblower system and without reporting lines to management do not meet the requirements. In this context, the BGH speaks of a compliance culture that must be demonstrably promoted. Indikatoren sind etwa regelmäßige Botschaften der Geschäftsleitung, ein dokumentiertes Tone-from-the-Top und nachvollziehbare Sanktionen bei Verstößen.
Die Anwaltspraxis hat darauf reagiert: Ein CMS gilt nur dann als wirksam, wenn es einer Wirksamkeitsprüfung nach IDW PS 980 standhält, die seit 2011 als Marktstandard etabliert ist. Insurers are increasingly linking D&O coverage to proof of such a system. Anyone standing on a filing cabinet CMS risks both the penalty and liability coverage. Others run compliance like a filing cabinet. We run it like software. The auditor calls, the evidence is ready. These requirements can hardly be met in a filing cabinet CMS because the currency of the documents cannot be systematically proven and the proof of effectiveness then fails due to random samples that the auditor does not accept. As a result, the compliance effort increases without any measurable increase in legal security or insurability with the D&O provider.
IDW PS 980: The seven building blocks of an audit-proof CMS
The IDW auditing standard 980 (principles of proper auditing of compliance management systems) has been the established assessment framework for CMS in Germany since 2011. He describes seven building blocks that build on each other. First: compliance culture, i.e. the basic attitude practiced by management. Second: compliance goals, derived from the business model and risk profile. Third: Compliance risks, identified through a systematic risk analysis, updated at least annually and adapted to significant business events as required.
Fourth: Compliance program, i.e. the specific measures to prevent and detect violations, including guidelines, training and controls. Fifth: Compliance organisation, with a clear organisational structure, appointment certificates, reporting lines and escalation paths. Sixth: Compliance communication, i.e. the flow of information between operating units, compliance function, management and supervisory board, supplemented by a whistleblower system according to HinSchG. Seventh: Compliance monitoring and improvement, with documented controls, effectiveness tests and adjustments based on internal findings and external developments.
The test of a CMS according to IDW PS 980 takes place in three stages: concept test (consistency and completeness), adequacy test (suitability for risks) and effectiveness test (actual functionality over a period of typically six to twelve months). A complete certificate for all three levels is not mandatory, but is increasingly the market standard in regulated industries. CIVAC provides the templates, controls and reports necessary for each stage as an integrated platform, with 490 audit templates and an ISMS according to ISO/IEC 27001:2022 with 93 controls. The EU data residency ensures the confidentiality of documents relevant to the examination and relieves the IT department of its own hosting decisions. The platform also supports the gradual achievement of the three test levels because gaps between conception and effectiveness are automatically identified and the reporting structure clearly reflects the components of the IDW PS 980 test, from the conception to the documented effectiveness according to IDW PS 980, which can be verified in the audit.
CMS obligation depending on size and industry: Who is specifically affected
It is not possible to make a general statement about the CMS obligation based on the number of employees, but rules of thumb can help. According to the prevailing opinion, corporations with around 250 employees or a turnover of 50 million euros or more are obliged to maintain a documented CMS. The same applies to group subsidiaries that are included in a consolidated risk management report in accordance with Section 91 (2) AktG. For listed companies, the CMS from Section 76 Para. 1 AktG and the German Corporate Governance Code (Principle 5) is mandatory anyway, as is the case for companies with bond issues or debentures on the organised capital market.
On the industry side, banks (Section 25a KWG, MaRisk), insurance companies (Section 23 VAG), securities service providers (Section 80 WpHG), and MLA obliged entities are included (Section 4 GwG, in particular notaries, lawyers, real estate agents, goods dealers with a threshold of 10,000 euros or more), KRITIS operators and NIS 2 affected companies (around 29,500 in Germany according to Section 28 BSIG), LkSG affected companies (1,000 or more employees) and high-risk AI providers (EU AI Act from August 2026) are explicitly obliged to provide an effective Operate a CMS or functionally comparable risk management system. Public clients are also increasingly checking CMS evidence before awarding decisions.
Smaller companies can also be liable if they are part of a supply chain to a company subject to the LkSG or act as a processor for a GDPR controller with a high risk profile. In practice, companies with 100 employees are often subject to an indirect CMS obligation, mediated through contractual chains and audit rights of their clients. Suppliers who cannot prove that they can support their customers' obligations will lose orders. There is also the reputation factor: A visible compliance structure is now part of the due diligence in M&A transactions and financing rounds, in which institutional investors explicitly request compliance evidence and base their assessment on it.
Role of the Compliance Officer: Appointment Certificate, Reporting Line, Protection
The compliance officer is the operational hub of a CMS. He coordinates risk analysis, training, controls and reporting to management. There is no legal obligation to make an appointment outside of the special laws mentioned (AMLA, KWG, WpHG, BSIG), but in fact the function is unavoidable. It is important to place a written order using an appointment certificate that clearly defines tasks, authorities, reporting lines and resources. The appointment certificate, signed, filed, verifiable. Without sufficient resources, the function cannot be carried out effectively in practice.
The compliance officer typically reports directly to management and has a so-called escalation duty: In the event of significant violations, he must inform management and, if necessary, the supervisory board. From the BGH judgment 5 StR 394/08 of July 17, 2009 (so-called BSR judgment) it follows that the compliance officer himself occupies a so-called guarantor position according to Section 13 of the Criminal Code, i.e. he can be criminally liable for failure to prevent crimes, to the extent that he becomes aware of it. This liability can only be limited through clear distribution of tasks, documented escalation and adequate resources. D&O insurance for the compliance officer is therefore recommended in practice.
If you do not have a suitable internal person, you can fill the position externally. In the officer-as-a-service model, CIVAC provides experienced compliance officers with an appointment certificate, reporting line and demonstrable industry experience. Licence the workspace for your internal representatives, or have our representatives order it. The order SLA is 2 business days instead of the industry standard 2 to 6 weeks. The external officer works integrated with the other 25 officer roles that CIVAC runs live, so that interfaces between data protection, information security, money laundering and supply chain are mapped in a single platform.
Building a CMS in twelve weeks: A pragmatic sequence
The structure of an exam-proof CMS is divided into four phases of three weeks each, as has been proven in practice. Phase 1 (weeks 1 to 3): inventory. Recording of all existing guidelines, training, controls, representatives and risk analyses. Creation of a gap analysis between the current state and the seven building blocks according to IDW PS 980. Definition of the CMS goals in coordination with management and the supervisory board. Determination of scope boundaries, for example with regard to subsidiaries, foreign locations and joint ventures.
Phase 2 (weeks 4 to 6): Risk analysis and conception. Structured survey of the main compliance risks in the business areas, assessment based on probability of occurrence and amount of damage. Derivation of the compliance program (guidelines, training, controls). Definition of the compliance organisation, appointment of representatives with appointment documents. Phase 3 (Weeks 7 to 9): Implementation. Rollout of the guidelines, training of employees, setting up the whistleblower system according to the HinSchG, setting up the reporting lines and dashboards. Test emails and pilot messages check the functionality of the escalation paths.
Phase 4 (weeks 10 to 12): testing and validation. Carrying out the first effectiveness tests, correcting identified vulnerabilities, creating compliance reporting and preparing the external effectiveness test according to IDW PS 980. The CIVAC workspace shortens this sequence significantly because 490 audit templates, preconfigured reporting lines, an integrated whistleblower system and the ISMS according to ISO/IEC 27001:2022 are already included. The auditor calls, the evidence is ready. Twelve weeks of project work result in a permanently functional system, which then only needs to be updated in regular reviews. The reports generated with the CIVAC workspace are already format-compliant for submission to DPM auditors, BAFA, BSI or BaFin, so that there is no duplication of work for external reporting obligations and the reporting line is already in audit format.
Liability of the management: Section 130 OWiG, Section 43 GmbHG, Section 91 AktG
The personal liability of managing directors and board members is based on several standards. Section 43 (2) GmbHG obliges managing directors to exercise the care of a prudent businessman; In the event of breaches of duty of care, they are personally liable to the company. Section 91 (2) AktG requires the board of directors to take appropriate measures, in particular a monitoring system, in order to identify developments that threaten the continued existence of the company at an early stage. Section 93 AktG norms the personal liability of the board of directors. Section 130 OWiG also establishes the sanctionability of breaches of supervisory duties. Even in the event of insolvency, liability applies according to Section 64 GmbHG or Section 15b InsO.
In case law, the so-called Business Judgment Rule (Section 93 Paragraph 1 Sentence 2 AktG, analogous for GmbH) has established itself as a protective area: Anyone who acts on the basis of appropriate information and in the well-understood interests of the company is not liable for incorrect business decisions. However, this protection fails in the event of compliance violations because legal obligations are not at issue. A documented CMS is therefore the best evidence that the supervisory duty has been carried out appropriately. Documentation is particularly important in the company's compensation process against the former managing director.
Insurers increasingly require proof of an effective CMS for D&O coverage, often specifically with confirmation of effectiveness according to IDW PS 980. Anyone who cannot prove such a system not only risks fines and personal liability, but also loses insurance coverage in the event of damage. The risk of being sued for damages internally by one's own company is usually greater leverage than the external risk. Audit-proof, documented, Section 130-proof. Anyone who actively maintains protection not only secures their own professional future, but also their negotiating position with insurers and supervisory authorities.
Building a CMS with CIVAC: Platform or external representatives
CIVAC combines compliance platform and officer-as-a-service in one offer. The workspace provides the seven building blocks according to IDW PS 980 as integrated modules: risk analysis, guidelines, training, whistleblower system according to HinSchG, appointment certificates, reporting lines, effectiveness test. 490 audit templates, preconfigured reports and an ISMS certified according to ISO/IEC 27001:2022 with 93 controls form the technical basis. EU data residence ensures GDPR conformity, documented appointment certificates and reporting lines ensure § 130 OWiG conformity. The platform also covers the 24h-72h reporting path according to NIS-2.
Licence the workspace for your internal representatives, or have our representatives order it. In the first model, your company retains operational responsibility, but benefits from the complete toolbox and standardised workflows. In the second model, CIVAC officers take on the role of compliance officer and, if necessary, another 25 officer functions from a single source, including reporting obligations to management and the supervisory board. The order SLA is 2 working days instead of the industry standard 2 to 6 weeks, so that even acute gaps can be closed at short notice after the departure of an internal representative.
Turn reading into a mandate. Write to info@civac.de or use the contact form. Within two working days, you will receive an initial finding of your current CMS maturity, a prioritised roadmap to § 130 OWiG conformity and, if desired, an external compliance officer with an appointment certificate, reporting line and demonstrable experience in IDW PS 980 audits. This turns the CMS obligation from a filing cabinet exercise into a software-supported routine. If you would also like to cover data protection, information security or whistleblower protection from a single source, CIVAC bundles these mandates in a single reporting line to management, supplemented by the NIS 2 reporting paths with 24-hour early warning and 72-hour follow-up reporting.
FAQ
Is there a general legal CMS requirement in Germany?
There is no obligation expressly formulated for all companies. However, Section 130 OWiG, the BGH case law (in particular 1 StR 265/16) and a large number of special laws such as the AMLA, KWG, LkSG, BSIG (NIS-2) and EU AI Act result in a de facto obligation for almost all medium-sized and large companies to operate an effective CMS.
What fines are threatened without an effective CMS?
Section 130 (3) OWiG provides for fines of up to 1 million euros for the natural person responsible. Section 30 OWiG supplements association fines of up to 10 million euros (intentionally) or 5 million euros (negligently). In addition, there are sanctions from the respective special laws, such as up to 10 million euros or 2% of group sales according to NIS-2.
Is a compliance policy sufficient to fulfil the obligation?
No. The BGH requires a system with risk analysis, training, a whistleblower system, clear responsibilities, documented controls and a regular effectiveness check. A pure directive without these supporting structures does not meet the requirements and, in the event of a sanction, leads to an increase in the fine instead of a reduction. The effort for policies without a system is therefore hardly worth it, neither legally nor from an insurance perspective.
What exactly does the test according to IDW PS 980 achieve?
IDW PS 980 is the market standard for external auditing of compliance management systems. The test takes place in three stages: concept test, adequacy test and effectiveness test. A complete certificate of effectiveness for at least six months is considered reliable evidence and is increasingly expected by D&O insurers, business partners and supervisory authorities. In regulated industries it is effectively mandatory.
Does a compliance officer have to be appointed?
A legal obligation to order only exists in the special laws mentioned such as the AMLA, KWG, WpHG and BSIG. In fact, the function can hardly be dispensed with because management can delegate its supervisory duties, but cannot give them up completely. The appointment is made in writing via an appointment certificate with clear tasks, authorities, reporting lines and resources. Without an appointment document, the representative is deemed not to have been effectively employed in the event of a conflict.
How quickly can an audit-proof CMS be set up?
With standardised templates and a clear sequence, twelve weeks are realistic, divided into inventory, risk analysis, implementation and testing. The CIVAC platform bundles 37 audit templates, preconfigured reporting lines and an ISMS according to ISO/IEC 27001:2022 with 93 controls, so that the preparation time is significantly reduced compared to building it yourself. When building your own home, projects lasting less than six months are rarely realistic.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.