Appointing a compliance officer: duty, tasks, liability and ordering method
According to Section 130 OWiG, managers are liable for failure to supervise. We show when a compliance officer needs to be appointed, what tasks he takes on and how you can document the appointment in a legally compliant manner with a certificate, reporting line and catalogue of tasks.
The management's duty of supervision arises from Section 130 OWiG and, in the event of a violation, can be punished with fines of up to 10 million euros per offense. Although a compliance officer is not explicitly required by law in many industries, the Federal Court of Justice made it clear in its decision of July 17, 2009 (ref. 5 StR 394/08) that an appointed compliance officer has a legal guarantor position. Anyone who does not fill the office bears the responsibility themselves, personally as a board member or managing director. The question is not whether a representative makes sense, but rather in what form and with what reporting line the function is set up. In addition, there are industry-specific requirements from Section 25a KWG, Section 23 VAG or Section 80 WpHG, which expressly prescribe the function in regulated sectors.
This article answers the five key questions that managers, supervisory boards and HR managers have when appointing a compliance officer: When is there a de facto obligation, which tasks belong in the order catalogue, how is the reporting line set up in an audit-proof manner, how is it distributed Liability and which ordering method leads to reliable proof more quickly. You will receive specific paragraphs, a catalogue of tasks, an escalation path and an ordering process that can be completed in two working days via the CIVAC compliance platform and Officer-as-a-Service. Deadline begins as soon as we become aware of it. Audit-proof, documented, Section 130-proof. The goal is not abstract conformity, but rather reliable evidence to authorities, auditors and business partners at any time.
Key Takeaways
- An express legal obligation to have a compliance officer only exists in regulated industries, but in fact in every medium-sized company and above due to Section 130 OWiG.
- An appointment certificate, a reporting line to management and a documented catalogue of tasks are the three minimum building blocks that every supervisory authority checks.
- Using the CIVAC compliance platform and Officer-as-a-Service, the order is verifiably completed in 2 working days, instead of the traditional 2 to 6 weeks.
When does a compliance officer have to be appointed?
German law only recognises an express obligation to appoint a compliance officer for individual regulated industries. According to Section 25a Para. 1 KWG, credit institutions must set up an appropriate compliance function; according to Section 23 VAG this applies to insurers and according to Section 80 Para. 1 WpHG to securities service providers. BaFin's MaComp specifies the requirements in the modules AT 4.4.2 and BT 1, including independence, reporting line and resources. For the majority of companies outside these sectors, however, Section 130 OWiG applies: Management must set up a supervisory organisation that is suitable for ensuring operational-related obligations.
If it violates this supervisory obligation and a business-related act occurs, there is a risk of a fine of up to 10 million euros per offense as well as the confiscation of the economic advantage in accordance with Section 17 (4) OWiG. In its decision of July 17, 2009, the BGH expressly confirmed the criminal law guarantor status of an appointed compliance officer. Anyone who does not appoint an agent remains their own guarantor. This line has been consolidated in further decisions and is now considered established case law.
In practice, this means: for employees of 50 or more, for international business activities, for public contracts or for activities in sanctions-relevant markets, the appointment of a Compliance Officer is the clean way to delegate the supervisory obligation and at the same time provide evidence of it. Through the CIVAC Compliance Platform and Officer-as-a-Service, business managers receive an appointment certificate, a reporting line and a list of tasks in one process. The appointment certificate, signed, filed, verifiable. The advantage over a purely voluntary commitment by the management lies in the documented delegation, which can be proven in court or authorities in the event of a dispute and remains valid in the event of changes in the management.
Tasks and obligations in the order catalogue
A compliance officer is not a generalist, but is defined by his catalogue of tasks. The appointment certificate regulates which duties are specifically transferred. There are seven common areas of responsibility: risk analysis, policy architecture, training, tip processing, third-party review, incident management and reporting. Each field is backed by measurable obligations, such as the annual risk analysis, the quarterly training documentation, the seven-day deadline for recording a report in accordance with Section 13 HinSchG or the three-month deadline for reporting back to the whistleblower.
The representative advises the management, checks business processes for compliance risks, documents the supervisory measures and trains the workforce. It does not replace the responsibility of the board of directors, but demonstrably relieves them. The risk analysis typically follows an assessment of the probability of occurrence and the extent of damage in a matrix, supplemented by an assessment of the control effectiveness. The policy architecture includes Code of Conduct, Anti-Corruption Policy, Gifts Policy, Sanctions Policy and industry-specific supplements. Training is differentiated according to risk roles so that sales, purchasing and management receive tailor-made modules with documented learning controls.
It is important to differentiate from the internal reporting office according to HinSchG: A staff union is possible, but the functions must be clearly documented separately because the reporting office has its own confidentiality obligation according to § 8 HinSchG. The CIVAC audit templates include 37 ready-to-use documents, from the task list to the training log to the incident report and the third-party checklist. Others run compliance like a filing cabinet. We run it like software. This means that tasks can not only be defined, but also planned, escalated and documented on a recurring basis, with a clear version status and owner for each process. The platform sorts tasks by deadline, risk indicator and responsible party so that bottlenecks are visible before they become an incident.
Appointment certificate, reporting line and catalogue of tasks: the three minimum building blocks
If you want to prove an order, you need three documents that every supervisory authority and every auditor wants to see in that order. Firstly, the appointment certificate with date, scope, compensation regulations, insurance coverage and termination clause. Secondly, the reporting line, which regulates that the representative reports directly to the management, without intermediate hierarchies, so that the guarantor position is not diluted by operational chains of command. Thirdly, the catalogue of tasks, which describes the delegated duties in a concrete and measurable way, ideally with frequency, person responsible and type of proof for each duty.
In practice, many orders fail not because of the content, but because of the form. We regularly see email orders with no date, verbally agreed reporting lines, or lists of tasks copied from a job description. The auditor calls, the evidence is ready., or not. An appointment certificate without a date is as worthless in a dispute as an unsigned contract because the guarantor status cannot be pinpointed in time. An order without a termination clause also leads to disputes about handover times and subsequent liability.
In the CIVAC Workspace, the three modules are created as a coherent process, digitally signed and stored with the version status. The EU data residency is secured, the ISO/IEC 27001:2022 ISMS controls are active in the background, all 93 controls documented. Licence the workspace for your internal representatives or have our representatives order it. In both models you receive the same file status. A later transfer from external to internal functions is possible in the workspace without interrupting the evidence path because all documents remain versioned and under clear authorisation. Changes in management or representatives are shown with a handover protocol.
Internal versus external compliance officer
The question of internal or external is not an ideological one, but a business one. An internal representative knows the processes, is available and can anchor them culturally. However, it brings with it the risk of bias while having operational responsibility, and it requires training, representation and budget for external audits. A full-time position is rarely used to capacity in smaller medium-sized companies; a part-time position often clashes with other functions such as HR, legal or finance. Independence according to MaComp BT 1 is difficult to maintain in these constellations.
An external representative is immediately ready for action, has methodological distance and brings cross-industry experience. However, he is dependent on a clean interface to the company, otherwise he remains an advisor instead of a guarantor. Availability, response times and representation regulations belong in the appointment certificate, as does the obligation to attend management meetings. A contractually agreed reporting cadence and a defined escalation path are indispensable because they are the only way to operationalize the guarantor position.
The cost question can be answered specifically: An internal compliance officer as a full-time employee, including training, software and representation, typically costs 110,000 to 160,000 euros per year. An external representative in the officer-as-a-service model starts at around 1,200 euros per month for SMEs and scales according to company size and risk situation. For many medium-sized companies, a hybrid model makes sense: an externally appointed compliance officer plus an internally responsible interface, such as compliance coordination in the legal area. The CIVAC compliance platform supports both models and switching between them, the FAQ page answers the most frequently asked detailed questions about representation, vacation regulations and handover at the end of the mandate. The question of selection is also often underestimated: the selection decision, aptitude test and contract documents form the cura in eligendo and must also be documented in order to ensure the relief effect.
Liability of the management according to Section 130 OWiG and Section 43 GmbHG
The liability landscape consists of three layers. The first layer is Section 130 OWiG: If the management violates its duty of supervision and a business-related offense occurs, there is a risk of a fine of up to 10 million euros per offense, plus the loss of the economic advantage in accordance with Section 17 Paragraph 4 OWiG. The fine affects natural persons, i.e. managing directors and board members personally. According to Section 81 Paragraph 2 VVG, D&O insurance cannot replace the payment of a fine because this would be a violation of private criminal law purposes. A declaration of exemption from the company is also legally limited here.
The second layer is Section 30 OWiG: The legal entity itself can be fined up to 10 million euros; in conjunction with Section 17 Paragraph 4 OWiG, the economic advantage can also be skimmed off. The third layer is Section 43 Paragraph 2 GmbHG or Section 93 Paragraph 2 AktG: personal liability of the managing director or board of directors towards the company for damages resulting from breach of duty, with reversal of the burden of proof. Anyone who cannot prove that they acted carefully is liable.
The appointment of a compliance officer relieves the burden on management, provided that the selection, instruction and monitoring of the officer are properly documented. The BGH speaks here of three-stage care: cura in eligendo, cura in instruendo, cura in custodiendo. Anyone who appoints a representative but cannot provide evidence of training, no reporting and no specification of risk indicators has no relief. The CIVAC reporting line documents exactly these three levels with date, addressee and content. Audit-proof, documented, Section 130-proof. This is not just a line of defence, but also operational discipline in day-to-day business, because it makes failures visible early on and can therefore be actively controlled.
Reporting line and escalation: how the representative works
The reporting line is the daily tool of the compliance officer. It defines when, how and to whom reports are made. The standard provides for three frequencies: an annual report to the management and, if necessary, the supervisory board, a quarterly report on ongoing measures and risks, and ad hoc escalation in the event of incidents that could represent a material breach of duty. Deadline begins as soon as we become aware of it. An escalation that only takes place weeks after knowledge is reached can hardly be justified in a dispute and can call into question your own guarantor position.
In escalation, the chain is important. The representative informs the management in writing, documents the information, suggests measures and monitors their implementation. If management delays or rejects the measure, the representative documents the process and, in extreme cases, can resign his mandate. A written, dated escalation is the representative's most important defence against his own liability risks, because the guarantor position falls back to the management once the information has been provided to the board.
In the CIVAC Workspace, escalations are recorded with a time stamp, addressee and reaction. The reporting line is configured in a binding manner, the evidence is available at any time at the push of a button. Reports can be exported as PDF with digital signature, with table of contents, sources and attachments. If you want to know more about operational integration, you can find the catalogue of tasks, reporting obligations and ordering method in detail on the Compliance Officer role page. A clean reporting line is also the most important lever for turning compliance from a cost factor into a control instrument because boards can take concrete risk indicators into account in ongoing business planning. Anyone who standardises the report gains comparability across quarters and can identify trend changes at an early stage.
Interfaces to DSB, ISB, whistleblower reporting office and LkSG
A compliance officer does not work in a vacuum, but rather on at least four interfaces. Firstly, the data protection officer: According to Article 38 Para. 6 GDPR, the DPO may not carry out any tasks that lead to a conflict of interest. A personal union is possible, but must be justified in a documented manner. In practice, this means that the compliance officer thinks about GDPR issues, but the formal assignment remains with the DPO. The reporting lines ideally run parallel to management, with common points in third-party testing and training.
Secondly, the information security officer: ISB and compliance officer share topics such as risk analysis and training; responsibility is delimited in the appointment certificate. The ISB is responsible for ISO/IEC 27001:2022 ISMS, the compliance officer is responsible for the overarching compliance management system. Thirdly, the internal reporting office according to Section 14 HinSchG: The compliance officer can head the reporting office, but must comply with the special confidentiality obligations according to Section 8 HinSchG and document processes separately. Separate file management with separate authorizations is standard here.
Fourth, the LkSG representative: Since 2024, the Supply Chain Due Diligence Act has also applied to companies with 1,000 or more employees. The LkSG representative carries out the risk analysis in the supply chain, documents the measures and reports annually. Compliance and LkSG officers work closely together because interfaces in sanctions checks, corruption prevention and due diligence obligations overlap. The CIVAC compliance platform manages all roles in a workspace and creates the interfaces via common risk and action registers. The Role overview shows all 25 representative roles with their respective interfaces, reporting lines and task catalogues, so that duplication of work and gaps are avoided and synergies become visible. The transition to the NIS 2 requirement for affected companies is also mapped via the platform because incident management and 24-hour early warning are neatly linked to the existing compliance reporting line.
Audit preparation: what is actually required during an audit
Auditors, external auditors and regulators examine compliance functions according to a recurring pattern. First: Proof of existence, i.e. appointment certificate with date, signature and order scope. Second: proof of suitability, i.e. proof of qualifications of the representative and training documentation. Third: proof of activity, i.e. risk analysis, catalogue of measures, reports to management and evidence of training for the workforce. Fourth: Evidence of incidents, i.e. documented escalations, investigations and measures with the date and person responsible. This four-layer model covers around 90 percent of typical audit questions.
In practice, audits rarely fail because of a lack of content, but rather because of a lack of discoverability. A representative who takes three days to find the risk analysis from the previous year loses the trust of the auditors in the entire function. A missing training matrix that does not differentiate between compulsory and elective modules also leads to follow-up questions that prolong the audit. Versioning, source references and a clear person responsible for each document are the inconspicuous details that convince auditors of a function.
All 490 audit templates are stored in versioned form in the CIVAC Workspace, with a search function and export protocol. When making a request, the auditor receives the complete evidence path with source reference, version status and person responsible within 24 hours. The auditor calls, the evidence is ready. This is the operational standard that a modern compliance platform must deliver, not a pile of PDF files on a network drive. For annual audits, the preparation effort typically drops from several person-weeks to a few days because the evidence was not collected for the audit but documented during ongoing operations. This shifts the effort from crisis mode to routine, and the representative gains time for actual risk control instead of file reconstruction.
From reading to ordering: the route via CIVAC
If you have read this far, you know the legal situation, the three minimum building blocks and the interfaces to the DSB, ISB, reporting office and LkSG. The next step is operational. CIVAC is a compliance platform and officer-as-a-service with two reference models. In the first model, you licence the workspace for your internal representatives and use the 490 audit templates, the reporting line, the risk register and the digital appointment certificate. In the second model, our representatives assign their function and work within the workspace, which your management can view at any time. Licence the workspace for your internal representatives or have our representatives order it.
The SLA for an order is 2 working days, instead of the classic 2 to 6 weeks. You receive the appointment certificate, reporting line and catalogue of tasks in one process, EU data residency, ISO/IEC 27001:2022 ISMS in the background and 93 controls active. A risk analysis, a training matrix and an initial report to management are included in the onboarding, so that the function reaches a measurable level from the first month. An ongoing reporting rhythm with quarterly and annual reports is included in the service and shown in the audit templates.
If you would like to specifically check whether your company needs a compliance officer, what scope of orders makes sense and which model is suitable, write to info@civac.de or use the contact form on civac.de. You will receive an initial assessment within 24 hours with the ordering method, draft catalogue of tasks and cost framework. If you wish, you will also receive an overview of the relevant interfaces to the DSB, ISB, reporting office and LkSG so that the role architecture in your company can be set up cleanly. Turn reading into an assignment.
FAQ
Are companies legally obliged to appoint a compliance officer?
An explicit obligation only exists in regulated industries, for example according to Section 25a KWG for banks, Section 23 VAG for insurers or Section 80 WpHG for securities service providers. For most companies, however, the order is actually necessary because Section 130 OWiG stipulates a supervisory obligation for management, the violation of which can be punished with up to 10 million euros per act. Anyone who does not appoint a representative remains a guarantor according to BGH case law.
Which tasks belong in the order catalogue of a compliance officer?
Seven areas of responsibility are standard: risk analysis, policy architecture, training, tip handling, third-party review, incident management and reporting. Each field is backed by measurable obligations, such as the annual risk analysis, quarterly training documentation or the three-month deadline for reporting back to whistleblowers in accordance with Section 17 of the HinSchG. The CIVAC audit templates provide the catalogue of tasks as a versioned document for direct inclusion in the appointment certificate.
What liability does the compliance officer bear personally?
In its decision of July 17, 2009 (ref. 5 StR 394/08), the Federal Court of Justice confirmed that the appointed compliance officer was a criminal guarantor. Anyone who becomes aware of a company-related crime and does not escalate it can be punished for aiding and abetting by omission. The clean reporting line, a written dated escalation to management and documented action follow-up are his most important defence.
How much does an external compliance officer cost?
In the officer-as-a-service model, external compliance officers start at around 1,200 euros per month for smaller medium-sized companies and scale with company size and risk situation. A full-time internal representative typically costs 110,000 to 160,000 euros per year including training, software and representation. For many medium-sized companies, a hybrid model with an external representative and an internal interface makes the most economic sense.
Can the compliance officer also be a data protection officer?
A personal union is possible, but a conflict of interest must be ruled out in accordance with Article 38 (6) GDPR. If the compliance officer had a say in data processing, the conflict would be indicated. The dual function should be justified in a documented manner and clearly delineated in the appointment document, with separate reporting lines to management and a representation arrangement in the event of conflicts of interest in day-to-day practice.
How quickly can a compliance officer be appointed?
Through the CIVAC Compliance Platform and Officer-as-a-Service, the SLA for the full order is 2 business days. You receive the appointment certificate, reporting line and catalogue of tasks in one process; traditional methods usually take 2 to 6 weeks. The onboarding includes a risk analysis, a training matrix and an initial report to management, so that the function works measurably from the first month.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.