77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Compliance audit: process, obligations and verification in German medium-sized companies
Governance & Compliance

Compliance audit: process, obligations and verification in German medium-sized companies

23 August 202612 min readBy Dr. Henrik Bauer
CIVAC

A compliance audit checks whether the organisation knows, documents and implements its regulatory obligations. Anyone who manages appointment certificates, reporting lines and action tracking reliably will get through every audit without becoming hectic in day-to-day business.

A compliance audit checks whether a company is aware of, documented and demonstrably fulfilling its legal and contractual obligations. In Germany, the legal basis is in particular Section 130 OWiG, which imposes fines of up to 10 million euros for breaches of supervisory duties. There are also industry-specific requirements from the GDPR, AMLA, LkSG, KWG and NIS-2, compliance with which is checked in internal and external audits.

This article describes the process of a compliance audit from the perspective of management and the compliance officer. It classifies the relevant standards ISO 19600 and ISO 37301, shows typical test areas and describes how CIVAC, as a compliance platform and officer-as-a-service, manages audit preparation and execution in one reporting line. The focus is on verifiable evidence, not on abstract compliance doctrines.

Key Takeaways

  • A compliance audit is not a one-time event, but a recurring cycle with planning, execution, reporting and action tracking.
  • ISO 37301 has replaced ISO 19600 since 2021 and sets binding requirements for a compliance management system instead of just recommending guidelines.
  • Appointment certificate, documented reporting line and 37 interlinked audit templates noticeably reduce the audit effort.

Legal framework for compliance audits in Germany

The central anchor for compliance in Germany is Section 130 OWiG. Management is liable if they fail to take supervisory measures that would have prevented breaches of duty by the company. Fines range up to 10 million euros, in conjunction with Section 30 OWiG also against the legal entity.

There are also industry-specific obligations. The KWG, WpHG and AMLA apply in the financial sector, and the GDPR with Art. 33 (obligation to report within 72 hours) and Art. 5 (accountability) applies to data protection. For KRITIS and particularly important facilities, NIS-2 is added with 24-hour early warning and 72-hour follow-up reporting.

The Supply Chain Due Diligence Act requires companies with 1,000 or more employees to report to the BAFA, including risk analysis, prevention measures and complaint procedures.

Across all areas, supervisory authorities require proof that responsibilities are clearly assigned, processes are documented and measures are effectively implemented. Deadline begins as soon as we become aware of it. Anyone who cannot provide evidence in the event of an incident risks fines and personal liability for management.

CIVAC maintains appointment certificates, task descriptions and reporting lines for all 25 representative roles in one platform. Licence the workspace for your internal representatives, or have our representatives order it. Further information: Compliance Officer.

Internal versus external Compliance-Audit

Compliance audits can be divided into internal and external audits. Internal audits are carried out by the compliance officer or an internal auditor, external audits are carried out by certification companies, auditors or supervisory authorities.

The internal audit follows ISO 19011 as a guideline for management system audits. It plans frequency, scope and methods based on risk. High-risk areas are audited more frequently, such as sales, purchasing, IT security, human resources.

The external audit can be voluntary (ISO 37301 certification) or mandatory (BaFin audit, BSI audit according to NIS-2, BAFA report according to LkSG). The preparation is not fundamentally different, but the external pressure is higher.

Both audit types follow a similar phase model: planning, implementation, report, measures, effectiveness test. If you separate the phases clearly, you gain transparency and reduce the number of discussion points in the final discussion.

A common mistake is mixing advice and testing. The internal auditor must not also be the person responsible for the process because this violates independence. The model of an appointed external compliance officer who carries out the audit independently is helpful here.

The auditor calls, the evidence is ready. This maxim applies equally to internal and external audits.

Preparation: What evidence must be ready before the audit

Audit preparation does not begin the day before the audit, but rather during ongoing operations. A well-managed compliance management system produces evidence automatically because every measure, every training and every report is documented in the system.

The basic equipment includes appointment certificates for all representative roles that are relevant in the company. The appointment certificate, signed, filed, verifiable. This applies equally to the compliance officer, the data protection officer, the money laundering officer and other roles.

There are also risk analyses. According to Article 35, the GDPR requires a data protection impact assessment in the event of high risk, the AMLA requires an institution-specific risk analysis, and the LkSG requires a risk analysis of the supply chain. All three must be updated regularly.

Training is a common checkpoint. The auditor checks whether employees have been trained on GDPR, AMLA, corruption prevention and information security. Training lists with date, content and participants must be available.

Measure tracking is the fifth pillar. Every finding from previous audits, every complaint from the reporting office, every data breach case must be documented with status, person responsible and deadline. CIVAC has 490 ready-to-use audit templates that are linked to the aforementioned areas of responsibility.

The audit is carried out in five phases

A professional compliance audit follows five phases: initialization, data collection, on-site inspection, report and follow-up. Each phase has clear responsibilities and results.

The initialization includes order clarification, test field definition, schedule and list of contact persons. The audit plan is coordinated with management to avoid operational bottlenecks.

Data collection is carried out remotely. The auditor requests documents such as appointment certificates, list of procedures in accordance with Art. 30 GDPR, risk analyses, proof of training and management assessment protocols. A central platform significantly reduces the time required.

The on-site inspection combines interviews with random samples. The auditor speaks with compliance officers, data protection officers, IT security officers, human resources management and individual employees. Random samples check the practice behind the documents.

The report contains findings, minor deviations, main deviations and potential for improvement. Major deviations will result in suspension of certifications until they are resolved. Audit-proof, documented, § 130-proof.

The follow-up includes the action plan, the effectiveness test and reporting to the management. CIVAC manages this cycle in a reporting line. Audit findings are transferred directly to the system of measures, without media disruption.

Typical test areas and common findings

In practice, compliance audits fall into five test areas in which findings accumulate. Anyone who knows these areas can prepare specifically.

First test area: orders and responsibilities. A common finding is that the appointment certificate is missing or outdated, especially for the compliance officer, money laundering officer and data protection officer. Unclear representation regulations are also criticized.

Second test area: list of procedures in accordance with Art. 30 GDPR. Common findings include outdated entries, a lack of legal basis, incomplete TOM descriptions or undocumented processors.

Third test area: training. A common finding is a lack of training planning, incomplete evidence or a lack of training for new employees within the first 90 days.

Fourth test area: incident processing. A common finding is the missing or late reporting of data breaches in accordance with Art. 33 GDPR (deadline 72 hours from knowledge) or NIS 2 incidents (24 hour early warning).

Fifth test area: suppliers and processors. A common finding is the lack of risk classification, lack of AV contracts in accordance with Art. 28 GDPR or lack of verification of sub-processors. The Supplier Auditor function specifically addresses this area.

ISO 37301 and the step from guide to management system

ISO 37301:2021 has replaced ISO 19600:2014 and, for the first time, sets certifiable requirements for a compliance management system. It replaces recommended formulations with binding target specifications.

The standard follows the high-level structure and can therefore be linked to ISO 9001:2015, ISO/IEC 27001:2022 and ISO 14001. Anyone who operates multiple management systems can manage context, leadership, planning, support, operation, evaluation and improvement in an integrated manner.

Essential requirements are the definition of compliance obligations, a documented compliance policy, a risk assessment, a system of measures and controls as well as a reporting path for tips. The latter corresponds to the Whistleblower Protection Act, which has been in force in Germany since December 2023.

The certification is voluntary, but can be a requirement in tenders. ISO 37301 is increasingly being accepted as evidence, particularly in the public sector and in regulated industries.

CIVAC accompanies the implementation pragmatically. Instead of a complex staff department, we recommend a step-by-step introduction, starting with appointment certificates, risk analysis and whistleblower protection. Licence the workspace for your internal representatives, or have our representatives order it. ISO 37301 allows both ways.

Whistleblower protection and internal reporting office

The Whistleblower Protection Act (HinSchG) has been in effect in Germany since July 2, 2023. Companies with more than 50 employees are obliged to set up an internal reporting office. Violations are punished with fines of up to 50,000 euros.

The reporting office must accept confidential reports, document them and confirm receipt within seven days. Feedback on measures taken must be provided within three months. In practice, these deadlines can only be met with a structured platform.

In terms of content, the reporting office can be managed internally or externally. The external variant via an independent ombudsman or service provider has the advantage of greater independence, especially if there are allegations against the management.

In the compliance audit, the auditor checks whether the reporting office has been set up, made known and can actually be reached. A common finding is a technically existing but practically unused reporting point, which is classified as ineffective in the audit report.

CIVAC provides the reporting point as a module of the platform and can alternatively manage it as an appointed role. Details can be found at Whistleblower Protection and Reporting Office. In this way, you fulfil HinSchG obligations and at the same time create a central entrance gate for ISO 37301 reports.

Documentation, retention requirements and audit trail

The documentation of a compliance audit must be complete for two reasons. Firstly, Section 257 of the German Commercial Code (HGB) requires commercially relevant documents to be retained for six to ten years. Secondly, in the event of a dispute, supervisory authorities require proof that management has fulfilled its supervisory obligations in accordance with Section 130 OWiG.

A reliable audit trail contains an audit plan, data requirements, interviews, sample results, report, action plan and effectiveness test. Each step should have a time stamp, person responsible and status.

Retention periods vary. Appointment certificates and lists of procedures are generally retained for as long as they are valid plus three to six years. Training certificates are usually retained for six years. Whistleblower reports are subject to special protection requirements according to the HinSchG.

Storing them in local mailboxes or network drives is risky. Personnel changes, hardware failures or migration projects regularly lead to data loss. A central, audit-proof storage with EU data residency is standard.

CIVAC keeps all audit traces in the platform with audit-proof logging. At the audit appointment, the auditor can trace the trail in real time. Others run compliance like a filing cabinet. We run it like software.

How CIVAC carries out compliance audits operationally

CIVAC is a German compliance platform and officer-as-a-service. It covers 25 officer roles, including compliance officer, data protection officer, money laundering officer, information security officer and supplier auditor.

For compliance audits, the platform provides 490 ready-to-use audit templates that are interlinked with Section 130 OWiG, GDPR, ISO 37301, AMLA, NIS-2 and LkSG. Measures from an audit are transferred directly to the system of measures and linked to the management assessment.

The reporting line is clear. Every appointment certificate, every order, every escalation has a documented recipient. The EU data residency is standard, the ISMS according to ISO/IEC 27001:2022 with 93 controls runs continuously.

Licence the workspace for your internal representatives, or have our representatives order it. The decision is not final. You can decide for each role, for example keeping the internal DPO and appointing the compliance officer externally.

Turn reading into a mandate. If you have a specific request, write to info@civac.de or use the contact form on civac.de. An initial consultation lasts 30 minutes and clarifies whether workspace, appointed compliance officer or a combination is suitable.

FAQ

How frequently should an internal compliance audit take place?

The frequency is risk-based according to ISO 19011. High-risk areas are checked at least once a year, less risky areas in two to three-year cycles. Audit planning with documented justification is mandatory and standard.

What are the penalties for insufficient compliance?

Section 130 OWiG provides for fines of up to 10 million euros, in conjunction with Section 30 OWiG also against the legal entity. There are also industry-specific penalties, for example under the GDPR of up to 20 million euros or 4 percent of global group sales.

What role does the compliance officer have in the audit?

The compliance officer plans, coordinates and accompanies the audit. He is the contact person for internal and external auditors, ensures the availability of evidence and monitors the implementation of measures. A written appointment certificate is mandatory.

What is the deadline for reporting data breaches?

According to Art. 33 GDPR, a data breach must be reported to the supervisory authority within 72 hours of becoming aware of it. If the risk is high, those affected must also be informed. The deadline begins when we become aware of it, not when the incident occurs.

Is ISO 37301 certification mandatory?

No, the certification is voluntary. However, it may actually become necessary in tenders and in the regulated sector. Even without certification, most of the requirements of ISO 37301 are derived from Section 130 OWiG and industry-specific laws.

How does CIVAC differ from classic advice?

CIVAC combines compliance platform and officer-as-a-service. You receive an ordered role plus workspace, instead of just advice. Consultation ends with the report, CIVAC carries the role permanently with an appointment certificate, reporting line and 37 audit templates.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles