Building a compliance management system: architecture, roles, evidence
A compliance management system is more than a collection of guidelines. Find out which seven building blocks ISO 37301:2021 requires, where German medium-sized companies fail and how a modern workspace brings together appointment certificates, audit templates and reporting lines in an audit-proof manner.
A compliance management system (CMS) is, according to ISO 37301:2021, a documented, managed and auditable framework with which an organisation manages its legal and ethical obligations. Since the standard was published in April 2021, the standard has established itself as a reference in Germany because it supplements the older IDW PS 980 testing concept with certifiable requirements. Anyone who sets up a CMS today has two recipients in mind at the same time: the external auditor and the public prosecutor's office, which, in an emergency, asks in accordance with Section 130 OWiG whether the management has fulfilled its supervisory duty. The requirements have increased significantly in recent years because NIS-2, the LkSG and the EU AI Act push additional obligations into the existing compliance framework.
This guide shows which seven building blocks a resilient CMS contains, where medium-sized companies typically fail and how appointment certificates, audit templates and reporting lines can be bundled in one workspace. You will receive concrete maturity indicators, an overview of the most important areas of responsibility and a plan with which you can make the system productive in twelve weeks without the appointment of an external compliance officer becoming a dead end. In the end, you know which evidence you need today, which you will need tomorrow and where a workspace with EU data residency replaces manual maintenance.
Key Takeaways
- ISO 37301:2021 requires seven building blocks, from context analysis to continuous improvement, and has been the certifiable reference for a CMS in Germany since 2021.
- A CMS without a documented appointment certificate, reporting line and catalogue of fines can neither withstand Section 130 OWiG nor an IDW PS 980 audit.
- The platform logic replaces the filing cabinet: audit templates, deadlines, incidents and roles are located in a workspace that includes EU data residency and versioning.
What a compliance management system must achieve according to ISO 37301:2021
ISO 37301:2021 replaced the non-certifiable ISO 19600:2014 in April 2021 and follows the high-level structure of all modern management system standards. Seven building blocks form the framework: organisational context, leadership, planning, support, operations, performance assessment and improvement. Each building block contains concrete requirements that result in a documented compliance policy, a register of obligations, a risk analysis and reporting to top management. The standard explicitly requires an independent compliance function with a defined reporting line, sufficient resources and access to all areas. It is therefore significantly more precise than the old ISO 19600, which only made recommendations.
In Germany, IDW PS 980, the auditing standard of the Institute of Auditors for Compliance Management Systems, works in parallel. Both standards overlap in the basic elements of compliance culture, goals, risks, program, organisation, communication and monitoring. Anyone who certifies ISO 37301 automatically meets most IDW PS 980 requirements. The reverse does not apply. The sequence is crucial for the structure: first the duty register and risk analysis, then the program and organisation, and finally communication and monitoring. Anyone who starts training without knowing the obligations produces expensive activity with no effect. Detailed role descriptions can be found at Compliance Officer, where the separation of duties from management is clearly shown. It is also worth taking a look at the role overview because in practice a CMS is almost always linked to data protection, information security and money laundering prevention and documents, risks and audits can be shared between the representatives instead of maintaining separate filing cabinets in each discipline. A clear separation of duties also protects against conflicts of interest and ensures that the compliance function actually retains its independence from the operational line, which is one of the first questions in the audit.
The seven building blocks in practice: from the register of obligations to the reporting line
Component one is context analysis. They list internal and external stakeholder groups, document legal obligations per country and business area and evaluate risks according to the probability of occurrence and the amount of damage. A German mechanical engineering company with a subsidiary in Poland typically has between 180 and 240 obligations in its register, from the Money Laundering Act to the LkSG to the GDPR. Building block two, management, requires a written compliance policy signed by top management, plus a documented appointment document from the compliance officer with protection against dismissal, reporting path and resources. These two building blocks are the foundation because they show that management is serious about compliance and actively fulfils its supervisory duty.
Building blocks three to five, planning, support and operations, contain training, the whistleblower system according to the HinSchG, supplier due diligence and incident management. Module six requires internal audits at a planned frequency, at least once a year for each risk area, and a documented management review. Building block seven concludes with corrective measures and continuous improvement. CIVAC bundles these building blocks in a workspace that includes 490 ready-to-use audit templates, appointment certificate templates and an incident register with a deadline monitor. The appointment certificate, signed, filed, verifiable. Anyone who keeps the modules in Excel and SharePoint loses time searching for versions during the first check instead of defending content. In practical terms, this means: Each building block has a responsible owner, a maturity status and a documented review date. The platform logs every change with a time stamp and version status, so that in the audit the question about the status as of the deadline is answered within minutes, not after days of searching for files in SharePoint. In addition, a predefined reporting set helps, which transmits the situation for each module to the management at the push of a button, with traffic light status, open measures and an overview of deadlines, so that the management review does not get lost in the preparation of the data.
§ 130 OWiG: Why management is personally responsible for the CMS
Section 130 of the Administrative Offenses Act obliges the owner of a business or company to take the supervisory measures necessary to prevent violations. If the management violates this supervisory obligation, a fine of up to 1 million euros can be imposed on the natural person and, according to Section 30 OWiG, up to 10 million euros on the company. In addition, there is the skimming off of economic benefits, which in practice exceeds the fine many times over. In 2017, the Federal Court of Justice made it clear in the so-called Neubürger judgment that an effective CMS must be taken into account in order to reduce fines and that management bears personal organisational responsibility for this.
In practical terms, this means: Management must be able to show which risks it has identified, which controls it has implemented and how it checks their effectiveness. A mere policy collection is not enough. Evidence of training participation, audit results, incident reports and corrective actions is required, ideally with a time stamp and version status. CIVAC maintains this evidence in the workspace so that in the event of a crisis, management can hand over complete documentation to the defence within 24 hours. Anyone who understands compliance as a group of representative roles reduces the liability risk of management because responsibility is delegated and documented. Important: Delegation does not completely relieve management, but rather shifts the obligation to select, instruct and monitor the representatives. Exactly these three steps are documented in the workspace, with reasons for selection, appointment certificate, reporting obligation and verifiable management review. In this way, an abstract norm creates a concrete protective shield against personal liability that can also withstand criminal investigations. In case of doubt, the burden of proof lies with the company, not with the authority, and that is precisely why verifiable documentation is not an end in itself, but the crucial difference between a lenient assessment and a fine in the double-digit million range.
Risk analysis: heatmap, register of obligations and the bridgehead to NIS-2 and GDPR
Risk analysis is the heart of every CMS. It connects the abstract duty with the concrete process. For each obligation, you document the responsible role, the probability of occurrence, the amount of damage and the control implemented. A typical heatmap uses five levels per axis, creating 25 risk classes. Fields colored red require immediate action, yellow requires planned action, green fields are monitored. The connection to other management systems is important: A GDPR obligation from Art. 32 GDPR is often identical to a requirement from Appendix A of ISO/IEC 27001:2022, for example regarding access rights or encryption. Anyone who documents both worlds separately doubles the effort and produces inconsistencies that are noticeable in the audit.
Since October 2024, NIS-2 has brought additional obligations for risk treatment, reporting channels with 24-hour early warning and 72-hour follow-up reporting and management liability for around 29,500 German companies. Anyone who interlinks their CMS with the ISMS world according to Information Security Officer avoids double mandatory assessments. CIVAC automatically maps the 93 controls from ISO/IEC 27001:2022 Annex A to the NIS-2 requirements and to the GDPR TOMs, so that a control is only documented once and works in three management systems. Deadline begins as soon as we become aware of it. This saves between 40 and 60 percent documentation effort for medium-sized structures. In practice, this means: You maintain a consolidated register of obligations, a consolidated risk inventory and a consolidated control directory from which every standard view can be generated using a filter, instead of maintaining three parallel files that sooner or later diverge and thus destroy auditor security. If you prioritise risks clearly, you can also brief management with a compact top 10 list, which is updated quarterly and draws attention to the few risks that actually threaten your existence, instead of getting lost in micro details.
Appointment of the compliance officer: certificate, protection against dismissal, reporting path
The appointment of a compliance officer is not legally mandatory, but is in fact essential as soon as a company employs over 250 people or operates in regulated sectors. The appointment certificate regulates the scope of tasks, powers, reporting channels to top management, resources and protection against dismissal. Unlike the data protection officer or whistleblower protection officer, there is no legal standard that specifies the form and content. This is precisely why the document is often assessed as inadequate in the event of a dispute. At a minimum, the following must be included: name of the role, factual and local responsibility, freedom of instruction in technical matters, direct reporting to management, commitment to resources and protection against discrimination. It is also recommended to have a regulation for representation in the event of vacation or illness, as well as a clear statement on how to deal with conflicts of interest.
A common mistake is the dual role: the head of legal or finance is appointed compliance officer and runs into conflicts of interest when he has to examine his own areas. ISO 37301:2021 explicitly requires separation. If you cannot fill the function independently internally, you outsource it to an external compliance officer. CIVAC offers both: Licence the workspace for your internal representatives or have our representatives order it. In both models, the appointment certificate is delivered as a legally tested template, with a clear reporting line and integrated representation regulations for vacation and illness. Others run compliance like a filing cabinet. We run it like software. The advantage lies not only in the form, but in the repeatability: If the representative changes, the successor takes over a fully documented history of tasks, risks and corrective measures and can be able to work the next day without the management losing knowledge.
Whistleblower system according to HinSchG: from reporting channel to case management
The Whistleblower Protection Act (HinSchG) came into force on July 2, 2023 and requires companies with 50 or more employees to have an internal reporting office with independent, confidential processing. The reporting office must accept written, oral and, if requested, personal reports, send the whistleblower a confirmation of receipt within seven days and provide feedback on follow-up measures taken within three months. The identity of the whistleblower and affected persons must be treated as strictly confidential, with clearly regulated exceptions for law enforcement authorities. Violations of the duty to protect can be sanctioned with fines of up to 50,000 euros per individual case, and the reputational consequences of a public escalation are often more serious than the fine itself.
In practice, many reporting centres fail not because of the input channel, but because of case management. Anyone who receives a tip must document an initial investigation, take action if necessary, secure evidence and communicate with human resources, legal and management without violating the whistleblower's protection. A documented workflow with deadline control, dual control principle and audit-proof filing is therefore mandatory. The Internal Reporting Office (HinSchG) function includes an anonymous reporting channel, a case management module and automatic deadline reminders. This means that the reporting office is not just an email address, but a verifiable process that fulfils legal obligations and at the same time informs management of compliance risks in a timely manner. In the workspace, cases can be evaluated anonymously so that patterns can be recognised without jeopardizing the confidentiality of the individual report, and the reporting line to the compliance officer remains clearly documented. Anyone who outsources the reporting office externally to an independent ombudsman service documents the assignment in the workspace with a contract, SLA and representation regulations, so that management can also provide complete evidence of the selection, instructions and monitoring of the external service provider.
Training, communication, verification: the often underestimated third
ISO 37301:2021 dedicates a separate module to training and communication. Employees must know their obligations, understand the compliance policy and know where to report information. The training requirement is not fulfilled with a one-time onboarding email. Risk-based modules are required, differentiated by role and business area, with documented participation and repetition frequency. Sales, purchasing and management have different risks than accounting or production. Annual compulsory training with a test is the minimum standard. High-risk areas such as export control, corruption prevention or sanctions require semi-annual or ad hoc refreshers, and if necessary also specific training for the management itself, whose level of knowledge is checked in the event of a crisis.
Proof of evidence is the most common stumbling block in audits. Anyone who keeps training lists in Excel and files confirmations of participation via email loses traces of every personnel change. A modern CMS links training participation to the employee master data system, documents learning success and confirmation with a time stamp and, in audit mode, makes a list of all training participants in a specific date range available at the push of a button. The auditor calls, the evidence is ready. CIVAC brings these functions into the workspace, including versioning of the training content, so that subsequent changes to a training course do not invalidate proof of historical participation. Audit-proof, documented, § 130 OWiG-proof. In addition, communication events such as all-hands meetings, newsletters and mandatory notifications can be logged centrally, so that the audit also provides evidence that relevant information was actually distributed and was not just left in a drawer. Anyone who integrates training requirements into the onboarding process avoids gaps in new hires, and anyone who automatically links change events such as promotions or department changes with mandatory training closes one of the most common audit weaknesses.
Maturity model: where your CMS stands today and where it needs to go
Maturity models help to objectively assess the current status and derive a roadmap plan. A five-stage model has proven successful: stage 1 reactive, stage 2 documented, stage 3 structured, stage 4 controlled, stage 5 optimised. At level 1 there are no written policies; compliance is managed on an ad hoc basis. At level 2, the duties are documented but not systematically monitored. At level 3 there are roles, reporting lines and regular audits. At level 4, the CMS is integrated into the business processes, with KPIs and management review. At level 5, the CMS is continuously adapted to risk changes, with data-driven control and its own compliance analytics, which also automatically transfers external signals such as changes in laws or market trends to the register of obligations.
According to studies by DICO and Bitkom, German medium-sized companies are typically between levels 2 and 3. Corporations in regulated sectors reach level 4. Level 5 is rare because it requires an integrated data platform and a practiced compliance culture. Experience has shown that the jump from level 2 to level 3 is the most economical because it reduces management's liability the most. CIVAC accompanies this leap with structured onboarding in four to eight weeks, depending on the number of employees and risk profile. A concrete maturity assessment is part of the initial discussion and leads to a prioritised list of measures instead of an abstract reading of the norms. This results in visible progress in the first 90 days: documented appointment certificates, a consolidated register of obligations and an initial internal audit with documented corrective measures. Only then does the step towards certification follow, which only produces costs without existing maturity. Maturity does not mean perfection, but repeatability, and it is precisely this repeatability that the auditor sees in the end and that protects management from personal liability.
Turn the CMS concept into a running system
A compliance management system thrives on repeatability. Appointment certificate, duty register, training records, audit reports and incident files must be available every day, not just during the audit week. That's exactly why we built CIVAC as a compliance platform and officer-as-a-service: a workspace with 490 audit templates, 93 controls according to ISO/IEC 27001:2022, deadline and incident module, appointment certificate generator, NIS-2 24/72 reporting path and EU data residency. You decide for yourself how deep you want to go: Licence the workspace for your internal representatives or have our representatives order it. Both models use the same system, with identical verification, and they can be switched between internal and external staffing at any time without losing the documentation history.
The transition from concept to running system takes four to twelve weeks in a structured procedure, depending on the initial situation. Turn reading into an assignment. Write to us at info@civac.de or book an initial consultation using the contact form on civac.de. You will receive an honest maturity assessment, an action plan and a clear offer as to whether you licence the workspace or add Officer-as-a-Service. Others run compliance like a filing cabinet. We run it like software. Anyone who takes this step today will not only postpone a project by three months, but will also gain three months of audit security, three months of documented supervision and three months less liability risk at management level. We recommend taking a brief inventory before the interview: which representatives are currently appointed, where are the appointment documents, is there a register of obligations and when was the last internal audit carried out. With these four answers, you can create a reliable maturity assessment in a 45-minute initial consultation, derive a rough estimate of time and effort, and decide which model of workspace licence and officer-as-a-service is viable for your organisation. The auditor calls, the evidence is ready. This sentence is not a slogan, but the result of an architecture that moves compliance from the filing cabinet to the workspace, thereby turning a duty into a controllable system.
FAQ
Which standard is the standard for a compliance management system today?
ISO 37301:2021 has been the certifiable international standard since April 2021 and has replaced the non-certifiable ISO 19600:2014. In Germany, the auditing standard IDW PS 980 from the Institute of Public Accountants works in parallel. Anyone who meets ISO 37301 automatically covers most IDW PS 980 requirements.
Does every company have to appoint a compliance officer?
There is no general legal obligation. From around 250 employees, in regulated sectors such as finance, pharmaceuticals or energy and in international business, an appointment is in fact indispensable in order to fulfil the supervisory obligation according to Section 130 OWiG and to protect the management against personal liability.
How high are the fines for an inadequate CMS?
According to Section 130 OWiG, there is a threat of up to 1 million euros against the natural person and according to Section 30 OWiG, up to 10 million euros against the company. In addition, there is the skimming off of economic benefits, which in practice often exceeds the fine many times over, and reputational consequences that cannot be measured in euros.
How long does it take to set up a CMS in a medium-sized company?
With a structured approach and the basics in place, four to twelve weeks until go-live. Certification according to ISO 37301 also requires at least three months of operating time so that auditors can demonstrate the effectiveness of the processes based on real operations.
Can a CMS cover GDPR, NIS-2 and ISO 27001 at the same time?
Yes, if the risk analysis and controls are documented in such a way that they work for all three sets of rules. The 93 controls from ISO/IEC 27001:2022 Annex A largely overlap with the GDPR TOMs and the NIS-2 requirements. An integrated platform saves 40 to 60 percent documentation effort.
What differentiates Officer-as-a-Service from the Workspace licensing model?
With the Workspace licence model, your internal representatives operate the system themselves. With Officer-as-a-Service, CIVAC provides the external representative with an appointment certificate, reporting obligation and representation. Both models use the same workspace and provide identical evidence.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.