77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Compliance in the company: duties, roles and the operational structure
Governance & Compliance

Compliance in the company: duties, roles and the operational structure

2 August 202613 min readBy Dr. Henrik Bauer
CIVAC

In Germany, compliance is not a recommendation, but a requirement: Section 130 OWiG, Section 91 (2) AktG, Section 43 GmbHG and the LkSG regulate the due diligence obligations of management. This article shows which obligations apply, which roles arise and how a compliance system is operationally set up.

Compliance in Germany is not a voluntary initiative, but rather an obligation derived from several laws. Section 130 OWiG requires companies to carry out proper supervision to prevent breaches of duty, Section 91 (2) AktG requires boards of directors to have a monitoring system for the early detection of developments that threaten the continued existence, Section 43 GmbHG standardises the managing director's duty of care. There are also special legal obligations from the GDPR, AMLA, HinSchG, LkSG, NIS2UmsuCG and industry-specific regulations such as KWG, MaRisk, medical device law or food hygiene. Any management who violates these obligations is personally liable, often with their private assets, and the company risks association fines of up to 10 million euros according to NIS-2 or up to 4 percent of group sales according to the GDPR. Damage to reputation, loss of orders and contract terminations also occur.

This article explains which obligations specifically apply, which roles are mandatory for which topics, how a compliance risk analysis serves as a foundation, how a compliance management system according to IDW PS 980 or ISO 37301 is operationally set up, which audit expectations auditors and authorities have and which tools the CIVAC compliance platform provides for medium-sized and large companies. The appointment certificate, signed, filed, verifiable. The structure follows a practice-oriented sequence from the legal framework to the role concept through to ongoing audit operations and concludes with concrete steps for mandating.

Key Takeaways

  • Compliance obligations in Germany arise from Section 130 OWiG, Section 91 AktG, Section 43 GmbHG plus special laws such as GDPR, LkSG and NIS2UmsuCG.
  • A compliance management system according to IDW PS 980 or ISO 37301 consists of seven building blocks from culture to improvement.
  • CIVAC combines a compliance platform with officer-as-a-service and appoints designated officers within 2 business days.

Legal obligations: What Section 130 OWiG, Section 91 AktG and Section 43 GmbHG require

The core of the corporate compliance obligation in Germany lies in three standards. Section 130 OWiG obliges the owner of a business or company to take the supervisory measures necessary to prevent violations of obligations that affect the owner and the violation of which is punishable by a penalty or fine. If the owner fails to do this intentionally or negligently, he or she may face a personal fine of up to 1 million euros. Section 30 OWiG supplements the association fine against the legal entity, linked to the act of a management person, with a limit of up to 10 million euros in cases of intent.

Section 91 Paragraph 2 AktG requires the board of a stock corporation to set up a monitoring system that detects developments that endanger its existence at an early stage. This obligation is interpreted in case law and commentary literature as an obligation to set up a compliance management system, at least if the company's risk profile requires corresponding measures. Section 43 Paragraph 1 GmbHG standardises the duty of care of a prudent businessman for GmbH managing directors; injuries lead to personal liability according to Section 43 Paragraph 2 GmbHG. In several decisions, such as BGH II ZR 234/09 (Siemens-Neubürger), case law has derived the obligation to set up a compliance system from these general duties of care. For the compliance officers in companies, this means: The obligation is there, the specific design must be determined based on risk. In addition, Section 130 OWiG has an effect beyond the management level: the term owner also includes people with management functions, so that department managers and plant managers can carry out their own supervisory duties. In multi-level corporations, the supervision of subsidiaries must be contractually and organizationally regulated, otherwise liability gaps arise. The supervisory board risk according to Section 116 AktG (supervisory board's duty of care) must also be addressed in the compliance concept because supervisory board members are increasingly being called upon themselves. This multi-level structure can be represented in the CIVAC workspace as a group compliance model.

Special laws: GDPR, AMLA, HinSchG, LkSG, NIS2UmsuCG

In addition to the general duty of care, special laws apply, each of which has its own designation requirements and fine limits. The GDPR requires the appointment of a data protection officer under certain conditions in Article 37, supplemented by Section 38 BDSG with the 20-person threshold in Germany. Fines according to Art. 83 GDPR range up to 20 million euros or 4 percent of global group sales, whichever is higher. The deadline for reporting data breaches is 72 hours in accordance with Art. 33 GDPR and begins with knowledge. The clock starts on awareness.

The Money Laundering Act (GwG) obliges certain obliged entities to appoint a money laundering officer in accordance with Section 7 GwG with a fine limit of up to 5 million euros. Since 2023, the Whistleblower Protection Act (HinSchG) has required the establishment of internal reporting points for companies with at least 50 employees and fines of up to 50,000 euros. The Supply Chain Due Diligence Act (LkSG) has covered companies with 1,000 employees or more since 2024 and requires risk management, a human rights officer or comparable function and annual reporting to BAFA with fines of up to 800,000 euros. The NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG) imposes obligations for risk management implementation, reporting obligations with 24-hour early warning and 72-hour follow-up notification as well as fines of up to 10 million euros or 2 percent of group turnover for essential facilities for around 29,500 German companies. CIVAC bundles the appointment of these special representatives in a workspace with an EU data residence and provides an appointment document plus reporting line for each role. Industry-specific regulations supplement the catalogue: KWG and MaRisk for banks, VAG and MaGo for insurers, MDR for medical devices, REACH and CLP for chemicals, BImSchG for plant operators. Each of these regulations can impose its own representative roles, such as the pollution control officer, the radiation protection officer or the incident officer. The duty analysis before mandating lists all relevant regulations and assigns them to the 25 CIVAC roles so that no legal duty remains unfilled.

Compliance management system according to IDW PS 980 and ISO 37301

If you want to build compliance systematically, you should follow established frameworks. IDW Audit Standard 980 describes the principles of proper auditing of compliance management systems and defines seven elements: compliance culture, compliance objectives, compliance risks, compliance program, compliance organisation, compliance communication and compliance monitoring. This structure is the industry standard and is used by auditors in audits according to Section 317 of the German Commercial Code (HGB) as well as in special investigations into compliance effectiveness.

ISO 37301:2021 is the international standard for compliance management systems and follows the high-level structure of all ISO management system standards. It can be integrated efficiently after setting up an ISMS structure because many requirements (documentation, audit program, management review, corrective measures) are identical. The standard is certifiable; certification is not yet standard on the market, but is becoming increasingly important for large companies and international business. The structure of a compliance management system follows a sequence: risk analysis, definition of the compliance fields (antitrust law, corruption, data protection, labour law, tax law, supply chain), definition of responsibilities in a RACI matrix, creation of guidelines and procedural instructions, development of the communication and training structure, implementation of a whistleblower system and establishment of the audit program. CIVAC provides templates for each step that are connected to the workspace. Others run compliance like a filing cabinet. We run it like software. The operational implementation is not primarily legal, but organisational. Anyone who introduces a CMS first defines governance: who reports to whom, with what frequency, in what format. Only then do content, templates and training come. This order is often mixed up in practice, with the result that documents are created that have no clear responsibility and are not convincing in the audit. ISO 37301 explicitly makes governance the first point to be clarified, thereby establishing a consistent structure that auditors and reviewers will recognise. Cleanly documented governance significantly reduces audit effort and the risk of fines.

Role concept: Which representatives have which duties

Compliance is not a task for a single person, but is spread across named roles. CIVAC supports 25 representative roles that typically need to be filled in medium-sized and large companies. The core roles are: compliance officer (CO) as coordinator of the CMS, data protection officer (DSB) for the GDPR topics, information security officer (ISB) for ISO 27001 and NIS-2, money laundering officer (AMB) for the AMLA, internal reporting office (IMB) for the HinSchG and LkSG officer for the supply chain.

In addition, there are industry-specific officers: Hygiene officer (HB) in the health and food sector, dangerous goods and hazardous substances officer in chemistry and logistics, occupational safety specialist (SiFa) and fire protection officer (BSB) in occupational safety, quality management officer (QMB) for ISO 9001, ESG officer for sustainability reporting according to CSRD, AGG complaint centre for equal treatment. The roles are partly legally mandatory (DSB from 20 employees with constant data processing, IMB from 50 employees), sometimes contractually or normatively expected (QMB in the certification system). The appointment is made by the management, documented in an appointment certificate with a catalogue of duties, reporting line and authorities. CIVAC offers the dual model: Licence the workspace for your internal representatives, or have our representatives order it. Both paths produce the same audit evidence and documentation; the difference lies in the deployment path. The mandate structure can be changed after 6 or 12 months without disruption because the workspace and templates are identical. It is important to separate reporting lines: special officers such as DSB and IMB report directly to management, without the intervention of other functions, in order to maintain independence and confidentiality. These reporting lines are explicitly named in every appointment certificate. In group structures, the interface to the group compliance function must also be regulated so that local representatives can report to operational management and to group compliance at the same time without conflicts of loyalty arising.

Compliance risk analysis as a foundation

The compliance management system is based on a documented risk analysis. Without this analysis, there is no justification for why certain compliance areas are prioritised and which controls are appropriate. IDW PS 980 calls for risk analysis as the second element after compliance culture. The analysis systematically identifies compliance risks according to probability of occurrence and amount of damage, supplemented by reputational and fine risks.

In practice, a well-managed risk register works with five columns: compliance field, specific risk, assessment (e.g. low, medium, high, critical), existing controls, measures with responsible person and deadline. The assessment is carried out annually and, in the event of significant changes, on an event-related basis. Important data sources include internal information, external incidents in comparable companies, official circulars and industry standards. CIVAC provides a risk register template that links the 25 representative roles with the respective mandatory catalogues. With every change in obligations, for example due to the NIS2UmsuCG or the CSRD, the risk analysis in the workspace is updated with versioning and those responsible. Risk analysis is not only mandatory, but also a management tool. It determines which training courses have priority, where audits start, which suppliers are examined more closely and where the whistleblower system needs special attention. During an audit, the risk analysis is regularly requested by the auditor as the first document because it reveals the logic of the entire CMS. The auditor calls, the evidence is ready. A missing or outdated risk analysis leads to the main deviation in the IDW-PS-980 audit. In the fine procedure, the authority evaluates a documented, current risk analysis as evidence of proper organisation and mitigates the sanction. Conversely, the lack of risk analysis regularly leads to the assumption of organisational negligence. A well-conducted risk analysis is also the basis for insurability via D&O policies, because insurers check the existence of documented risk analyses in the event of a claim.

Policies, training, communication

Compliance only works if obligations are formulated into guidelines, communicated to employees and anchored through training. A typical policy portfolio includes Code of Conduct, Anti-Corruption Policy, Gifts and Entertainment Policy, Data Protection Policy, IT Security Policy, Whistleblower Policy, Supplier Code and Travel and Expenses Policy. Each policy has an owner (usually the respective representative), a version number, an effective date and an approval path to management.

Training is planned according to target group. Mandatory training for all employees covers data protection, IT security, anti-corruption and the whistleblower system. Specialists and managers with increased compliance exposure (purchasing, sales, human resources, finance) receive in-depth training. Participation in training is documented; a training matrix with employees, topics, last training date and next appointment is common. The storage period for training certificates is at least three years, and often longer in fine proceedings. CIVAC integrates the training matrix into the workspace and connects it to the compliance policies so that changes to a policy automatically generate a training recommendation. In addition to training, communication also includes the compliance intranet, regular newsletters, town hall briefings by management and the management's active commitment to the CMS (tone from the top). This communicative framework is element 1 according to IDW PS 980 and is checked in the audit through employee interviews and random samples. Anyone who only keeps documents here without employees knowing the central compliance issues will fail the effectiveness test. A good practice is the annual compliance declaration, in which employees confirm knowledge of key guidelines and disclose specific conflicts of interest. These declarations are managed in a versioned manner in the workspace and are presented randomly during audits. The declaration contains three mandatory fields: confirmation of knowledge of the guidelines, disclosure of secondary employment and declaration of acceptance of gifts within the threshold.

Whistleblower system and investigations

The Whistleblower Protection Act (HinSchG) has required companies with 50 or more employees to set up an internal reporting office since December 2023, immediately from December 2023, while the transitional regulation for those with 50 to 249 employees had a deadline of December 2023. The reporting office must enable anonymous reports, confirm incoming reports within 7 days and provide feedback on measures taken within 3 months. According to Section 40 HinSchG, violations are punished with fines of up to 50,000 euros.

The setup can be done internally (by our own compliance function) or externally (by a law firm, ombudsperson or specialised service provider). External solutions lower the inhibition threshold for whistleblowers because confidentiality towards one's own employer is maintained. CIVAC offers the external internal Whistleblower Protection Reporting Office as an officer-as-a-service with a documented receipt and processing process, deadline control in accordance with Section 17 HinSchG and reporting line to management. Every report is recorded in the workspace with an anonymous case code, which protects the whistleblower and at the same time ensures the documentation required by Section 11 of the HinSchG. Retention period: three years after completion of the procedure. If there is substantial evidence, an internal investigation follows, which uses a structured approach to collect evidence, conduct interviews, examine facts and prepare an investigation report. This report is the basis for follow-up measures under labour law, civil law or criminal law and for informing management. The documentation of the investigation is audit-critical because, in case of doubt, it proves that the company has fulfilled its supervisory obligation in accordance with Section 130 OWiG. In the event of criminally relevant information, management is obliged to involve external consultants and, if necessary, file a report. The threshold at which a report is required depends on the degree of suspicion and the item being protected; it should be defined in advance in the investigation guidelines.

Audit, reporting, effectiveness testing

A compliance management system only becomes resilient through an audit and effectiveness test. IDW PS 980 distinguishes between three types of testing: concept testing (are the elements set up appropriately), adequacy testing (are the measures taken suitable to address the identified risks) and effectiveness testing (does the CMS work in practice). The effectiveness test is the most demanding level and is typically only carried out after 12 to 18 months of operation.

The internal audit program follows a multi-year plan that covers all compliance fields at least once per certification cycle, critical fields more frequently. Each audit produces a report with findings, actions and deadlines. Measures are tracked in the workspace until completion. The annual management review summarizes audit results, risks, incidents, training status and improvements and is presented to management for evaluation. This document is central to the audit because it demonstrates continuous improvement according to IDW PS 980 Element 7. External effectiveness tests are often carried out by auditing firms for larger companies and end with an audit opinion according to Section 322 of the German Commercial Code (HGB). In fine proceedings or in sanction cases, an effective CMS is taken into account to mitigate punishment, which is why documentation of effectiveness is of great importance. CIVAC supports the entire audit cycle with 490 audit templates, a measures module and a management review template that covers all elements 1 to 7 requirements according to IDW PS 980. Audit-proof, documented, § 130-OWiG-proof. The reporting line to management is permanently stored in the workspace. In the case of special official audits, for example by BaFin, BAFA or state data protection authorities, relevant evidence can be compiled within hours because the link between obligation, measure and evidence is stored in the workspace. This speed of reaction is a significant advantage when dealing with authorities and reduces the risk of escalation in ongoing investigations.

CIVAC as a compliance platform and officer-as-a-service

The duties are clear, the roles are diverse, the documentation is extensive. What companies need is an operational infrastructure where orders, policies, audits, notices and reports converge. CIVAC is a compliance platform and officer-as-a-service that delivers exactly this interaction. The platform bundles appointment certificates, 490 audit templates, guidelines, training matrix, risk register, notification receipt, action control and management assessment in a workspace with EU data residency and ISO/IEC-27001:2022 certified operation (93 controls).

The second path is the external order: 25 representative roles, all live, appointment certificate within 2 working days instead of the industry standard 2 to 6 weeks. Licence the workspace for your internal representatives, or have our representatives order it. Both paths can be combined: typical is the external filling of the specialised roles (DSB, GwB, IMB, ESG, ISB) and the internal filling of the compliance coordinator, who controls the CMS at management level. The workspace is identical for both paths, so that a later change is possible without loss of data and without reorganization. Turn reading into an assignment. Contact: info@civac.de or the contact form on civac.de. We recommend a 45-minute inventory meeting in which we compare your company's responsibilities based on size, industry and international positioning with the available roles and modules. You will then receive a roadmap with the next 90 days, the first orders and the workspace configuration. Audit-proof, documented, provable. The roadmap prioritises according to legal pressure (deadlines, amount of fines, frequency of official inspections) and operational effort. In the first 30 days, the mandatory special roles are usually filled and the risk analysis is drawn up, in days 31 to 60 guidelines and training matrix are created, in days 61 to 90 the internal audit program and the first management assessment start.

FAQ

What compliance obligations apply to a company with 100 employees?

If there are 50 employees or more, the obligation to have an internal reporting office under the HinSchG applies. If there are 20 or more employees with constant data processing, a data protection officer must be appointed in accordance with Section 38 BDSG. In addition, there are Section 130 OWiG (duty of supervision), GwG for obliged status, NIS2UmsuCG depending on the sector and size, occupational health and safety obligations with SiFa and fire protection officer. A duty analysis reveals which roles are specifically mandatory.

What differentiates IDW PS 980 from ISO 37301?

IDW PS 980 is a German auditing standard from the Institute of Public Accountants and describes the principles of proper auditing of CMS, ISO 37301 is an international, certifiable management system standard based on a high-level structure. Both have seven or ten core elements, are largely compatible and are combined in practice. ISO 37301 facilitates international recognition, IDW PS 980 shapes auditing practice in Germany.

Can a single compliance officer cover all specialist topics?

No, statutory special roles require your own qualifications and order. Data protection, money laundering, NIS-2, supply chain and HinSchG each require a designated representative with professional qualifications. The compliance officer coordinates the entire system and reports consolidated to the management; the special officers bear technical responsibility for their domain. In smaller companies, one person can hold multiple mandates as long as qualifications and capacity are documented for each mandate.

What fines are there for compliance violations?

The range is wide: GDPR up to 20 million euros or 4 percent of group sales, NIS2UmsuCG up to 10 million euros or 2 percent group sales for essential facilities, AMLA up to 5 million euros, LkSG up to 800,000 euros, HinSchG up to 50,000 euros. In addition, there are association fines according to Section 30 OWiG of up to 10 million euros and personal fines against managing directors according to Section 130 OWiG of up to 1 million euros.

How quickly can CIVAC set up a compliance structure?

Orders from individual representatives are processed within 2 working days via the CIVAC SLA. Depending on the size of the company, the complete development of a CMS according to IDW PS 980 with risk analysis, guidelines, training, whistleblower system and audit program takes between 90 and 180 days. CIVAC provides templates for every step and accompanies the introduction with clear milestones and a roadmap.

Where is the data and evidence in the CIVAC workspace?

The CIVAC workspace is operated in a data centre with EU data residency and follows an information security management system with 93 controls aligned to ISO/IEC 27001:2022. Data is stored encrypted, access is logged, retention periods can be configured according to legal requirements. At the end of the mandate, data is returned to the client in accordance with the contractual agreement or deleted in an audit-proof manner, documented in a deletion protocol, which serves as proof of data repatriation in the audit.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles