Compliance officer for crafts and production: What medium-sized companies really need
Craft and production companies are caught between Section 130 OWiG, GwG, LkSG and EU supply chain law. We explain which compliance obligations actually apply and how the CIVAC model with workspace and officer-as-a-service relieves the burden on medium-sized businesses.
The compliance obligations for craft and manufacturing companies have fundamentally shifted over the last five years. Section 130 OWiG with fines of up to 10 million euros, the Money Laundering Act (GwG) for companies with cash transactions of 10,000 euros or more, the Supply Chain Due Diligence Act since January 1, 2024 also for companies with 1,000 employees or more, plus the Whistleblower Protection Act (HinSchG) since December 17, 2023. The regulatory burden also affects medium-sized businesses full force.
This article explains which compliance obligations really apply in craft and production companies, how ordering obligations and actual risks differ and which models an external compliance officer can cover. You will find out why the duty of supervision according to Section 130 OWiG is the central bridge to management liability and how CIVAC offers a realistic solution with Workspace and Officer-as-a-Service instead of an open-ended consulting project.
Key Takeaways
- Section 130 OWiG requires management to take supervisory measures against breaches of duty in the company. Fines of up to 10 million euros, plus confiscation of profits.
- Appointment obligations apply to money laundering officers from defined thresholds, to HinSchG reporting offices from 50 employees, to LkSG officers from 1,000 employees.
- External Compliance Officer from CIVAC: Workspace with 37 audit templates, officer model with SLA 2 working days. The appointment certificate, signed, filed, verifiable.
Compliance obligations in craft and production: The real map
Unlike banks and insurance companies, craft and production companies do not have any central compliance regulations such as KWG or VAG. The duties are spread across several special laws. Section 130 OWiG forms the bracket because the supervisory obligation of the management extends to all legal regulations, the violation of which is threatened with a penalty or fine.
At least five regulatory areas come together in production companies. Occupational safety according to ArbSchG and BetrSichV, environmental protection according to BImSchG, KrWG and WHG, product safety according to ProdSG, supply chain according to LkSG (from 1,000 employees), data protection according to GDPR (from 20 employees with data processing).
In the trades, there are additional industry-specific obligations. Construction and expansion companies are subject to the Construction Site Ordinance, food trades are subject to the Food Hygiene Ordinance, metal processing companies are subject to the GefStoffV. The list is long and the overview is rarely given.
A compliance officer does not take on the individual duties, but rather the structural control. He identifies, documents and monitors the chain of obligations and ensures that the management complies with the supervisory obligation in accordance with Section 130 OWiG. This function is linked to the individual special representatives via the CIVAC compliance officer role.
The workspace provides a duty matrix that filters all relevant laws by industry and size class. Instead of consulting days, the system produces an immediate overview of existing obligations and open gaps.
Others run compliance like a filing cabinet. We run it like software.
§ 130 OWiG: The central supervisory obligation
§ 130 OWiG obliges the owner of a business or company to take supervisory measures that are necessary to prevent breaches of duty in the company. The regulation forms the legal bridge between individual obligations (such as occupational safety or data protection) and the personal responsibility of the management.
Fine of up to 10 million euros, plus profit confiscation according to Section 17 OWiG, plus entry in the central commercial register. In the case of repeat offenses or particularly serious offenses, the upper limit of fines can be exceeded because profit skimming is possible without limit.
The supervisory measures are not conclusively defined. Appointment of supervisors, organisational instructions, training, spot checks and documentation are common. Anyone who, as a management, trusts that employees will act correctly is not fulfilling their obligation.
The burden of proof in the fine proceedings lies with the authority, but with a low threshold. If a breach of duty is discovered in the company, it is obvious that there has been a breach of supervisory duty. The management must then prove that all reasonable supervisory measures have been taken.
A specific supervisory measure is taken via the internal whistleblower system. Anyone who ignores notices of breaches of duty or does not even accept them risks assuming a breach of supervisory duty.
CIVAC documents all supervisory measures in the workspace with a time stamp, responsibility and approval workflow. In the event of a fine check, the complete supervisory certificate is available.
AMLA obligations in trade: Where cash transactions come into play
The current version of the Money Laundering Act (AMLA) has been expanded several times. Section 2 Paragraph 1 No. 16 GwG covers goods traders who conduct cash transactions starting from 10,000 euros. This threshold particularly affects the construction, automotive and precious metal trades. Section 4 GwG requires risk management, Section 6 GwG requires internal security measures, Section 7 GwG requires a money laundering officer if there is a higher risk.
Appointing a money laundering officer is not mandatory for every goods dealer. If the risk is low, it is sufficient for management to carry out their duties. If there is a higher risk, for example due to foreign transactions or cash transactions close to the threshold, the appointment is recommended or even mandatory.
The risk analysis according to Section 5 GwG is mandatory even without a representative. It includes customer risks, business risks, product and sales risks and country risks. The analysis must be updated annually and approved by management.
Violations of the AMLA are punished with fines of up to 1 million euros or 10 percent of the previous year's turnover, whichever is higher. The FIU (Financial Intelligence Unit) receives around 350,000 suspicious activity reports every year, many from the craft sector.
For the Money Laundering Officer role, CIVAC provides an appointed officer with proof of specialist knowledge in accordance with Section 7 Para. 5 GwG. The workspace contains the risk analysis template, the identification form according to Section 11 GwG and the suspicious activity report template for the FIU.
The auditor calls, the evidence is ready. Also with the FIU exam.
Whistleblower protection: reporting office and whistleblowing
The Whistleblower Protection Act (HinSchG) has required companies with 50 or more employees to set up an internal reporting office since December 17, 2023. The obligation fully affects the classic middle class. Violations are punished with fines of up to 50,000 euros, in serious cases up to 500,000 euros.
The reporting office must accept confidential reports, confirm receipt within 7 days, communicate follow-up measures within 3 months and actively prevent reprisals. The formal requirements are regulated in Section 17 HinSchG, the whistleblower's protective rights in Sections 33 to 41 HinSchG.
External appointments are expressly permitted under Section 14 HinSchG. The external officer takes over the operational task, the management remains responsible for the formal setup. CIVAC provides the reporting office as a service, with its own hotline, web entry form and multilingual processing.
It is important to distinguish between receiving reports and clarifying the facts. The external reporting office documents the report, clarifies the context with the whistleblower and passes it on to the responsible office in the company. The information itself remains with the company.
There is an indirect connection via the EU AI Act obligations. If AI systems are used in personnel decisions, they must be classified as high-risk systems and are subject to transparency requirements. Information about incorrect AI decisions falls under the HinSchG.
The appointment certificate, signed, filed, verifiable. The HinSchG reporting centre operation is fully documented in the workspace.
Supply chain: LkSG for larger medium-sized businesses
The Supply Chain Due Diligence Act has been in effect since January 1, 2024 for companies with 1,000 or more employees. From 2027, the EU-CSDDD will replace the German regulation and gradually expand it to smaller companies. Anyone who has between 500 and 1,000 employees today should prepare.
The LkSG obligations include risk analysis, prevention measures, remedial measures, complaint procedures, documentation and annual reports to BAFA. The risk analysis addresses eight human rights risks plus two environmental risks according to Section 2 LkSG.
The appointment of a LkSG representative or human rights officer is recommended according to Section 4 Paragraph 3 LkSG. This person monitors risk management and reports to management at least annually. Ordering is also possible externally, provided access to purchasing, sales and quality assurance is guaranteed.
Fines of up to 8 million euros or 2 percent of annual sales, whichever is higher, can be imposed for violations. In addition, there is an exclusion from public contracts for up to 3 years. BAFA has been actively auditing since 2024 and the first fines have been imposed.
Through the Supply Chain Officer role, CIVAC offers an external order with audit templates for risk analysis, supplier assessment and BAFA report. The templates are updated according to the 2024 reporting requirement and contain the BAFA's FAQ answers.
Audit-proof, documented, § 10 LkSG-proof.
Compliance officer on staff or specialised
The question of whether a compliance officer can cover all special topics or whether specialised officers are required depends on the size of the company and its risk profile. In companies with fewer than 250 employees, compliance control can often be bundled in one hand, with special officers for data protection, money laundering and occupational safety.
In larger companies, a breakdown is recommended. The compliance officer is responsible for strategic management and the specialist officers are responsible for operational work in their area. The reporting line converges with the compliance officer and leads to the annual compliance report to the management.
The combined order in one hand is possible in particular for data protection, money laundering and compliance. Other functions, such as pollution control or radiation protection, require specific specialist knowledge and can rarely be combined.
CIVAC offers both models. In the officer-as-a-service model, we provide a compliance officer with a clearly defined scope of mandate. In the workspace model, you licence the platform for your internal representatives. Both models use the same workspace, the same templates, the same EU data residency.
Using the Role overview you can see the 25 representative roles that CIVAC has in its portfolio. Which combination is right for your company depends on its size, industry and existing compliance maturity. Licence the workspace for your internal representatives or have our representatives order it.
The clock starts on awareness. The development phase of a compliance program should not exceed 6 to 12 months, otherwise there will be a gap in the supervisory obligation.
Costs and evaluation of the external model
The costs of an external compliance officer for medium-sized craft and production companies are between 1,500 and 5,000 euros per month, depending on size, industry and scope of duties. Complex multi-site operations with an international supply chain cost between 5,000 and 12,000 euros per month.
In comparison, an internal compliance officer with a full personnel cost position costs between 85,000 and 130,000 euros annually. There is also further training, representation and IT infrastructure. The external solution is economically attractive for companies without full-time requirements and also leads to greater depth of expertise through client diversification.
The CIVAC SLA of 2 working days differs from classic consulting firms, which have a response time of 2 to 6 weeks. When it comes to fine proceedings, BAFA inquiries or data breaches, speed is critical to success. The 72-hour reporting requirement according to Art. 33 GDPR does not allow weekly work planning.
The workspace model alone, without an officer, starts at significantly lower monthly flat rates and is suitable for companies that already have staff but are looking for the documentation platform. The 490 audit templates, the 93 controls and the EU data residency make the workspace model a professional basis.
You can find the most common pricing questions in the CIVAC FAQ. The fixed monthly flat rate replaces daily rates and allows for planning. Unlike classic compliance consulting, there are no open-ended projects.
Others run compliance like a filing cabinet. We run it like software.
Build a compliance program in 90 days
A realistic compliance program for medium-sized companies can be set up in 90 days if Workspace and Officer start in parallel. Days 1 to 14 are used to take stock. Which representatives have been appointed, which obligations apply, which documentation exists? CIVAC provides an inventory checklist with 84 check points.
Days 15 to 45 are used to build the obligation matrix. Which laws affect the company, which representatives are required, which risk analyses need to be carried out? The duty matrix is displayed in the workspace and linked to responsibilities.
Days 46 to 75 are used for ordering and documentation. Appointment documents for the necessary representatives, notifications to the responsible authorities, establishment of reporting lines. The appointment certificate is versioned in the workspace and linked to your CV, proof of qualifications and declaration of compliance.
Days 76 to 90 are used for the first routine recording. Training, sampling programs, whistleblower system in operation, first inspections. The operational work begins with documented evidence, not with subsequent constructions.
The ISO/IEC 27001:2022 transition notes result in a parallel structure logic for IT security. Anyone who starts both topics synchronously saves duplication of work and creates consistent documentation.
Audit-proof, documented, § 130 OWiG-proof. After 90 days, you have a robust compliance program that can withstand a fine review.
From the consultation to the ordered function
The step from diffuse compliance risk to structured fulfilment of duties is a question of discipline and tools. The company delivers discipline with clear management decisions. CIVAC provides tools with a compliance platform and officer-as-a-service.
The workspace provides 490 audit templates, 93 controls according to ISO/IEC 27001:2022 and integrated reporting lines for 25 officer roles. The EU data residency and the certified ISMS ensure confidentiality and integrity. The templates are updated in accordance with applicable law and will be adjusted if the law changes.
Licence the workspace for your internal representatives or have our representatives order it. The Officer-as-a-Service model brings appointed compliance officers with proof of expertise, professional liability insurance and an SLA of 2 working days. In the hybrid model, you combine your own specialists with an external officer for the formal role.
CIVAC provides all the necessary documents for the official notification, from the appointment certificate to proof of qualifications to the declaration of availability. The reporting obligations according to the AMLA, BImSchG and HinSchG are fulfilled within deadlines.
The 25 representative roles cover all relevant functions for craft and production companies. Data protection, compliance, money laundering, supply chain, occupational safety, fire protection, environmental protection, hazardous substances, quality management and HinSchG reporting office.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. We check the obligation matrix of your company in 2 working days and discuss the appropriate model, without daily rate logic.
FAQ
Do craft businesses really need a compliance officer?
There is no legal obligation to appoint a compliance officer as such. However, Section 130 OWiG requires management to take supervisory measures. An appointed compliance officer is the most effective supervisory measure and protects against fines of up to 10 million euros.
Which ordering obligations specifically apply to medium-sized businesses?
Data protection officer from 20 employees with data processing, HinSchG reporting office from 50, security officer according to § 22 SGB VII from 21, LkSG officer from 1,000. Money laundering officer depending on the risk profile, emissions control and waste officer depending on the asset class and quantity thresholds.
Can an external compliance officer take on multiple functions?
Yes, data protection, compliance and money laundering in particular can be combined in the personal union. Special functions such as pollution control, radiation protection or company doctor, on the other hand, require specific specialist knowledge and are usually ordered separately. CIVAC checks the personal union in the consultation.
How quickly can CIVAC be reached in an emergency?
The SLA is 2 working days for standard inquiries and 24 hours for reportable incidents in accordance with Article 33 of the GDPR or Section 4 of the Major Incident Ordinance. For those subject to NIS 2, the 24/72 reporting path applies with early warning within 24 hours and follow-up reporting within 72 hours.
What differentiates the CIVAC model from classic compliance consulting?
CIVAC combines platform and appointed officer. Classic advice provides daily rates without formal assumption of responsibility. CIVAC provides an appointed function with an appointment certificate, professional liability insurance of 10 million euros per claim and documented performance of duties in the workspace.
Which sectors does CIVAC cover in trade and production?
Metal processing, mechanical engineering, construction, expansion, automotive trade, food trade, furniture, printing, chemical medium-sized businesses and production of consumer goods. The obligation matrix is configured industry-specific and linked to the applicable special laws in the workspace.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.