Compliance Management: From filing cabinets to audit-proof operating systems
A compliance management system is not a collection of guidelines, but a demonstrable organisational performance. The article shows how management sets up a CMS according to IDW PS 980, covers the seven basic elements and documents the appointment of representatives in an audit-proof manner.
Section 130 paragraph 1 OWiG obliges the owner of a business to supervise compliance with business-related obligations. Anyone who intentionally or negligently fails to carry out this supervision and a violation therefore occurs is liable for a fine of up to one million euros, or up to ten million euros in conjunction with Section 30 OWiG. The Federal Court of Justice made it clear in several decisions between 2017 and 2024 that an effective compliance management system can both reduce the amount of fines and limit the personal liability of management. Compliance management is therefore not an option, but an organisational obligation, the non-fulfilment of which has concrete financial and criminal consequences.
This article is aimed at management, board members, commercial management and compliance officers in medium-sized companies with 50 to 5,000 employees. You will find out which seven basic elements a compliance management system according to IDW PS 980 must contain, how the appointment of individual representatives is documented in a legally compliant manner, how risk analysis, code of conduct and reporting line are practically interlinked, and how the annual maintenance effort can be reduced to two working days per representative order using the CIVAC Compliance Platform and Officer-as-a-Service. The text does not replace legal advice in individual cases, but rather provides a reliable framework for discussions with the supervisory board, auditors and supervisory authorities.
Key Takeaways
- An effective compliance management system according to IDW PS 980 includes seven basic elements and is a prerequisite for reducing fines according to Section 30 OWiG.
- The appointment of representatives must be documented by an appointment certificate, task description and reporting line, otherwise the management alone bears the risk.
- A CMS does not survive in filing cabinets, but in a workspace with versioning, audit logs and a defined escalation chain.
What a compliance management system must legally achieve
The term compliance management system has no legal definition. The decisive factor is the auditing standard IDW PS 980 of the Institute of Public Accountants, which has been the de facto benchmark since 2011 and was published in a revised version in 2022. It describes seven basic elements: compliance culture, compliance goals, compliance organisation, compliance risks, compliance program, compliance communication and compliance monitoring and improvement. Each element must be described conceptually, anchored in the structure and process organisation and its effectiveness can be verified.
The management bears ultimate responsibility. It can delegate tasks to a Chief Compliance Officer or several specialist officers, but not the supervisory duty itself. This is exactly where Section 130 OWiG comes in: In the event of a violation, the fine procedure is used to check whether the supervision was carried out within the scope of what is reasonable. This demonstrably includes that a risk analysis has been drawn up, appropriate controls have been set up, those responsible have been appointed and training has been carried out. Anyone who cannot prove this effectively has no defence in the proceedings.
The Compliance Officer is the central lever for fulfilling this obligation. His appointment must be made in writing, the reporting line to management must be free of instructions on compliance issues, and the resources must correspond to the risk exposure. An order without an appointment certificate, without a task description and without a documented reporting line is an order that does not contribute to the audit. The Federal Ministry of Finance has confirmed in the application decree for Section 153 AO that a documented internal control system supports the acceptance of a tax adjustment notice and can thus refute the accusation of tax evasion. This exculpatory effect extends to internal civil liability of the management in accordance with Section 93 AktG and Section 43 GmbHG, provided that the CMS is documented, implemented and checked. A CMS on paper is not enough; demonstrable effectiveness over several financial years is required.
The seven basic elements according to IDW PS 980 in practice
Compliance culture is the first and most underestimated element. It describes the tone-from-the-top, i.e. the demonstrable attitude of the management to compliance with the law and ethical principles. Evidence includes board resolutions, a Code of Conduct signature by all managers, the selection criteria for staffing and the sanctioning behaviour in the event of identified violations. A compliance culture without documented consequences is an assertion, not a fact.
Compliance goals are derived from compliance risks, not the other way around. Typical risk areas include corruption, antitrust law, data protection, money laundering, sanctions law, occupational safety, tax law and supply chain care. The compliance organisation defines roles, reporting lines and escalation paths. The compliance program includes guidelines, training, advisory and control measures. Compliance communication regulates how employees are informed about obligations and how they can report violations. Compliance monitoring closes the loop through internal audits, key figures and external checks.
In practice, companies fail less because of the conceptual description than because of the integration. A risk analysis that is not included in the training program is a list. A Code of Conduct that is not stored in the personnel file is a paper. A reporting line that is not used in a crisis is an organisational chart line. The CIVAC workspace connects these elements as a coherent data model with 93 controls according to ISO/IEC 27001:2022, supplemented by specific compliance risks from Section 130 OWiG, the Whistleblower Protection Act and the Supply Chain Due Diligence Act. This creates an operating system from seven basic elements instead of a collection of folders. The integration via a common data model is the real lever: a risk position with assigned control, assigned training and versioned reporting document represents the verifiable supervision that Section 130 OWiG requires. Anyone who does not establish this interlinking is operating parallel isolated solutions, the effectiveness of which can neither be proven nor refuted in the fine procedure.
Risk analysis: From business model to prioritised control
Compliance risk analysis is the foundation of every CMS. Without it, all other elements are unfounded. Methodologically, a three-stage approach is recommended. First: inventory of the relevant legal areas along the business model and the value chain. Second, assess each risk based on the probability of occurrence and the potential amount of damage, both financial and reputational. Third: derive prioritised controls that reduce the risk to an acceptable residual level.
A manufacturer of mechanical components with exports to Switzerland, the USA and Saudi Arabia has a different risk profile than a local bakery. In the mechanical engineering example, export controls under EU Dual-Use Regulation 2021/821, US sanctions under EAR and OFAC as well as corruption risks under the UK Bribery Act and FCPA dominate. In the bakery, food hygiene in accordance with VO (EC) 852/2004, allergen labelling in accordance with LMIV and occupational safety in accordance with DGUV regulation 1 dominate. The risk analysis determines which representatives must be appointed.
In the mechanical engineering example, at least data protection officer, export control officer, money laundering officer for cash transactions, compliance officer and whistleblower protection office come into consideration. The CIVAC role overview lists 25 live representative roles and describes the reason for the order, the legal basis and the typical reporting line for each. A risk analysis without this role assignment remains abstract; a role assignment without a risk analysis is rejected in the audit as incomprehensible. Both belong in the same document, with versioning and approval by management. Anyone who reviews the analysis annually will recognise shifts in good time and avoid the classic pattern where a new subsidiary in a risk country is only included in the compliance scope for the first time after three years. A versioned risk analysis with date, author and release note is the auditor's first question in the audit, even before the guidelines. Anyone who cannot present anything here is starting the conversation with a structural weakness.
Appointment of agents: what the appointment document must prove
The appointment of a representative is a unilateral act of the management with a constitutive character. It is made in writing and names the person, tasks, authorities, resources and reporting line. For some roles, the written form is required by law, for example for the data protection officer according to Art. 37 GDPR, the dangerous goods officer according to Section 1 Paragraph 1 GbV or the occupational safety specialist according to Section 5 ASiG. For other roles, the written form results from the management's duty of care.
The appointment certificate documents the takeover and is the first document in the audit. If it is missing, the supposed representative is deemed not to have been appointed and responsibility falls back to the management. The appointment certificate, signed, filed, verifiable. The task description supplements the appointment certificate with the operational duties, such as training, audits, reports and interfaces to other functions. The reporting line regulates the frequency and channel through which the representative reports to the management, usually at least once a year and on an ad-hoc basis in the event of significant events.
Practice shows three recurring errors. First: The appointment certificate is undated or not signed by an authorised person. Second: The task description is missing or makes a general reference to the law. Third: The reporting line is described in the organisational chart, but not in a specific procedure, so there are no verifiable reports. The CIVAC platform provides a template for the appointment certificate, task description and reporting line for each of the 25 roles, checks the completeness when creating it and reminds the management of the annual update. The ordering process does not end with the signature date, but with the receipt for the first reporting loop. Licence the workspace for your internal representatives, or have our representatives order it.
Reporting line and escalation: the backbone of an effective CMS
A reporting line is more than a line in the organisational chart. It defines who reports what to the management and at what frequency and what powers apply in the event of an escalation. In its decision of May 9, 2017 (ref. 1 StR 265/16), the Federal Court of Justice decided that the effectiveness of a CMS also depends on whether the reporting line is actually used in the event of a crisis. A reporting line that only exists in good weather times is worthless in the audit.
In practical terms, this means: Every representative has an annual report to the management with standardised content. Risk exposure, controls carried out, violations identified, measures taken, outlook. In addition, there are event-related reports for significant incidents, such as data breaches with an obligation to report in accordance with Art. 33 GDPR within 72 hours, NIS 2-relevant security incidents with 24-hour early warning and 72-hour follow-up notification or corruption tips via the internal reporting office in accordance with HinSchG.
Deadline expires as soon as we become aware of them. This rule of thumb applies to almost all event-related reports and makes the real-time availability of the reporting line critical. An email address that is only read once a week does not meet the deadline requirements. In the CIVAC workspace, the reporting line is implemented as a technical routing object: When a reportable event is triggered, a process is automatically opened to the responsible functions, with deadlines, templates and an audit log. The auditor calls, the evidence is ready. This structural security significantly reduces management's personal liability because supervisory actions do not depend on the attention of a single mailbox. Anyone who uses Officer-as-a-Service receives the reporting line including 24-hour availability as part of the service. The reporting line includes a documented replacement policy for vacation and sickness, so that no deadline depends solely on one individual.
Training, Code of Conduct and whistleblower protection
Training is the operational side of the compliance program. They must be planned, carried out and documented based on roles. A blanket annual training is not sufficient if the risk analysis identifies specific roles with special duties. Sales needs training on antitrust law and anti-corruption, accounting on money laundering prevention according to the AMLA, and IT on data protection and information security. The documentation includes training content, list of participants, date and proof of effectiveness, such as a learning check.
The Code of Conduct is the company's written behavioral expectations of its employees and business partners. It must be up-to-date, understandable and available in the relevant languages. In practice, signing by all employees is standard; for business partners, code of conduct clauses in the supplier contract or a separate supplier code are often used. The Supply Chain Due Diligence Act has tightened the requirements for suppliers since 2026; a LkSG representative is mandatory for affected companies.
Whistleblower protection has been mandatory in Germany for companies with 50 or more employees since the Whistleblower Protection Act of May 31, 2023. The internal reporting office must accept confidential reports, send a confirmation of receipt within seven days and provide feedback on follow-up measures taken within three months. Violations of the HinSchG are punished with a fine of up to 50,000 euros per case. The CIVAC platform provides the reporting office technically, with encrypted communication, EU data residency and audit-proof logging. If desired, CIVAC can take over the reporting office completely as an external officer-as-a-service. Others run compliance like a filing cabinet. We run it like software. Linking the reporting office with the reporting line allows management to gain insight into ongoing processes at any time without violating confidentiality protection.
Measuring effectiveness: key figures, audits, external review
A CMS is effective not by its existence, but by its measurable impact. Suitable key figures are the number of training courses carried out with participation rate, the number of whistleblower reports processed with average processing time, the rate of audited suppliers, the rate of confirmed violations with sanctions initiated and the rate of reporting obligations to supervisory authorities fulfilled in a timely manner. These key figures belong in the management's annual report and are the subject of internal auditing.
Internal audits check the effectiveness of individual elements. For example, the compliance program is checked for current guidelines, training coverage and sanctions practices. The compliance organisation is checked for completeness of orders, functionality of the reporting line and conflicts with other functions. Internal audits should be conducted in an annual plan that fully covers the seven basic elements over three years.
External audits are not mandatory, but are strong evidence. Certification according to IDW PS 980 by an auditor takes place in two stages: concept testing and effectiveness testing. The effectiveness test requires an observation period of typically six to twelve months. According to the guidelines of the BMJ and established case law, a successful examination significantly reduces the risk of a fine and is an important sentencing factor in the procedure. Audit-proof, documented, § 130 OWiG-proof. Anyone who uses the CIVAC workspace has the 490 ready-to-use audit templates that are typically required for a PS 980 audit and the audit logs that the auditor needs for the effectiveness test. This reduces the preparation time from typically two to three months to a few weeks. This is not a marketing advantage, but a direct consequence of the uniform data storage across all agent roles, which is usually in separate systems without a platform.
Realistically estimate and plan compliance costs
The costs of an effective CMS depend on size, risk profile and internationality. The number of mandatory representatives and the scope of training provide a rough guide. For a medium-sized company with 250 employees and national operations, at least six to eight officer roles usually need to be filled: data protection, compliance, IT security, occupational safety, fire protection, company doctor and, depending on the industry, money laundering, dangerous goods or hygiene. With a classic staffing with internal employees, external service providers and training, the full costs are often in the six-figure range per year.
External ordering via an officer-as-a-service provider such as CIVAC changes the cost structure. Instead of a full-time position for each area, the role is represented in a bundle of platform, templates and personal representative order. The CIVAC SLA guarantees the order within two working days of placing the order instead of the classic two to six week lead time for individual orders. The costs scale with the number of roles, not with the number of full-time positions.
Economically, for many medium-sized companies this means a cost reduction of thirty to sixty percent compared to the classic model, while at the same time increasing audit security thanks to the uniform platform documentation. If you want to carry out a clear cost comparison for your company, list the current staffing of the representative roles, the full costs per role including holiday replacement and the annual documentation performance. This comparison typically reveals double staffing, unclear responsibilities and unfilled mandatory roles before a decision is even made about CIVAC. In most cases, an honest inventory saves more than switching to an external model later. Licence the workspace for your internal representatives, or have our representatives order it.
From reading to an organised CMS: a concrete next step
Anyone who has read the article up to this point knows the seven basic elements according to IDW PS 980, the obligation to appoint representatives, the requirements for risk analysis, reporting lines and training as well as the key figures for effectiveness. The next step is not another white paper, but an orderly inventory. Which representatives are currently appointed? Are the appointment certificate, task description and reporting line complete? When was a risk analysis last updated? What training has been documented in the last twelve months?
CIVAC works as a compliance platform and officer-as-a-service. The platform maintains the appointment certificates, task descriptions, reporting lines, risk analyses, proof of training and audit templates for all 25 representative roles in a common workspace with EU data residency and ISO/IEC 27001:2022 controls. Licence the workspace for your internal representatives, or have our representatives order it. In the Officer-as-a-Service variant, our external representatives take over the order, the annual reporting line and the preparation of external audits, regularly within two working days of placing the order.
Turn reading into a mandate. A short email to info@civac.de with the industry, number of employees and existing compliance structure is enough for the first appointment. If you prefer to use the contact form, you can find it linked via the FAQ page. What you don't get: a generic consulting offer without a clear service. What you get: concrete feedback about which representative roles are missing or incompletely filled in your organisation, with a prioritised list of the first three orders and the documents required for them. Verifiable, documented, with appointment certificate as soon as the basis for the order is in place. If you do not want to book the appointment directly, you can receive the inventory checklist in advance as a PDF with an overview of all mandatory roles according to industry classification.
FAQ
Is a compliance management system required by law for my company?
An explicit obligation to introduce a CMS only exists in individual sectors, for example in banks according to MaRisk or in listed companies according to IDW PS 980. However, Section 130 OWiG, Section 91 Paragraph 2 AktG and the general duty of care of management actually result in a duty of effective supervision, which cannot be proven in the audit without a documented CMS.
Which representatives do I have to appoint?
That depends on size, industry and activity. According to Art. 37 GDPR, the data protection officer is mandatory for 20 or more people involved in personal data processing. The occupational safety specialist follows from Section 5 ASiG, the fire protection officer from the state building regulations, and whistleblower protection from the HinSchG for 50 or more employees. CIVAC maintains an overview of the 25 roles with order reasons and threshold values.
How long does it take to appoint an external representative via CIVAC?
The CIVAC SLA guarantees the order will be delivered within two working days of the signed order. The appointment certificate, task description and reporting line are coordinated with the management and stored in the workspace. The classic lead time for individual orders via law firms or recruiters is typically between two and six weeks. For multiple orders, the SLA per role is adhered to and implemented in parallel.
How much does an effective CMS cost in medium-sized businesses?
With a classic staffing of internal employees and external service providers, the full costs for a 250-person company are typically in the six-figure range per year. When using Officer-as-a-Service via CIVAC, the effort is reduced by thirty to sixty percent, while at the same time increasing audit security thanks to the uniform platform documentation and the SLA-supported availability of the officers.
What role does the IDW PS 980 play in the supervisory authority’s audit?
The IDW PS 980 is a voluntary testing standard, not a legal requirement. According to established case law and the guidelines of the Federal Ministry of Justice, a successful examination according to PS 980 significantly reduces the risk of a fine and is an important sentencing factor. Regulatory authorities accept it as proof of effectiveness, but do not require certification. Even without a certificate, the seven basic elements are considered a recognised benchmark in the audit.
Can CIVAC take over the entire compliance function or just individual representatives?
Both are possible. CIVAC provides individual external representatives as an officer-as-a-service or the entire compliance organisation including platform, templates, reporting line and external audit support. Alternatively, you only licence the workspace and fill the roles with internal employees. The decision depends on size, risk profile and existing personnel structure. A mixed form with partly internal and partly external orders is also common.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.