77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Compliance officer is mandatory for how many employees? The legal situation in 2026
Governance & Compliance

Compliance officer is mandatory for how many employees? The legal situation in 2026

2 August 202613 min readBy Dr. Henrik Bauer
CIVAC

There is no fixed number of employees in the law. What triggers the obligation is a combination of size, industry, risk and company structure. This article explains the legal situation and shows when a compliance officer in medium-sized companies becomes useful and actually mandatory.

The frequently asked question as to what number of employees requires a compliance officer does not have a simple answer. German law does not recognise a general threshold, such as 250 or 500 employees, above which the appointment of a compliance officer is legally required. Rather, the obligation arises from Section 130 of the Administrative Offenses Act (OWiG), which obliges management to take appropriate supervisory measures, as well as from industry-specific regulations such as Section 7 of the Money Laundering Act (GwG), Section 25a of the Banking Act (KWG) for banks or the Supply Chain Due Diligence Act (LkSG) for companies with 1,000 or more employees in Germany. The BGH ruling of May 9, 2017 (Az. 1 StR 265/16) also made it clear that an effective compliance management system (CMS) is taken into account as a way to reduce the fine when assessing sentences.

This article explains when a compliance officer actually becomes mandatory, which sectors have explicit thresholds, what Section 130 OWiG means for management and how the obligation applies can be practically implemented in medium-sized businesses without setting up a full-time position. The article is aimed at managing directors, board members and shareholders who are considering whether the appointment of an internal or external compliance officer for their company is necessary, sensible or unavoidable in the medium term. Others run compliance like a filing cabinet. We run it like software.

Key Takeaways

  • There is no rigid employee threshold for the obligation to become a compliance officer in German law; The obligation arises from Section 130 OWiG, the industry and the risk profile.
  • Industry-specific obligations apply explicitly: Money Laundering Act, Banking Act, Securities Trading Act and the LkSG for more than 1,000 employees in Germany.
  • According to BGH case law, a documented compliance management system according to IDW PS 980 reduces fines and personal liability risks for management.

The legal framework: Section 130 OWiG as a general clause

The central regulation for the compliance obligation in Germany is Section 130 OWiG (violation of the duty of supervision in companies and companies). The standard obliges owners of businesses and companies to take the supervisory measures necessary to prevent violations of obligations that affect the owner as such and the violation of which is punishable by a penalty or fine. Anyone who intentionally or negligently violates this supervisory obligation is themselves acting in an unlawful manner and can be fined up to 1 million euros; in conjunction with Section 30 OWiG, further company-related sanctions are added.

Section 130 OWiG deliberately does not contain any threshold values. The question of which supervisory measures are required depends on the size, industry, complexity and risk profile of the company. In a craft business with ten employees, written work instructions with annual training are sufficient. In an industrial company with 500 employees, international sales and export business, however, a structured compliance management system with clear assignment of responsibility and documented supervision is required. The appointment of a compliance officer is one, not the only, way of fulfilling this obligation, but is considered appropriate when a certain level of complexity is involved.

The BGH ruling of May 9, 2017 (ref. 1 StR 265/16) introduced the term CMS into criminal case law and expressly recognised that the introduction of an effective compliance management system must be taken into account in order to reduce fines. Compliance is therefore not only mandatory, but also protection for the personal liability of management. The external compliance officer can also cover this function in companies that do not want to set up their own position. In subsequent jurisprudence, regional and higher regional courts have further specified the standard: an effective CMS requires more than a PDF on the intranet; it must be lived, trained and checked, otherwise it will have neither a mitigating effect on punishment nor an exonerating effect under civil law.

Industry-specific obligations: the law sets explicit thresholds here

While Section 130 OWiG is a general clause without a threshold, individual sectors have clear obligations to appoint a compliance officer. These obligations apply regardless of the number of employees and are usually linked to the business activity, not the size of the company. Anyone who works in one of these regulated areas cannot avoid a formal appointment, even if the company only has ten employees. In practice, the industry obligations are the most common trigger for a first-time appointment in medium-sized companies and are regularly checked by the respective supervisory authorities (BaFin, BAFA, customs, state data protection officer).

Examples: According to Section 7 of the Money Laundering Act (GwG), obliged entities must appoint a money laundering officer if they fall within the scope of application, which includes, among other things, credit institutions, insurance companies, real estate agents, precious metal dealers and lawyers in certain activities. According to Section 25a Paragraph 1 Sentence 6 of the Banking Act (KWG), credit institutions must set up a compliance function and appoint a compliance officer. According to Section 80 of the Securities Trading Act (WpHG), a comparable obligation applies to investment services companies. In the food sector, EU Regulation 178/2002 requires a HACCP system with documented responsible persons; in the area of medical devices, the MDR (EU 2017/745) requires a person according to Art. 15 (Person Responsible for Regulatory Compliance, PRRC).

The Supply Chain Due Diligence Act (LkSG) has been in effect since January 1, 2024 for companies with 1,000 or more employees Domestic (previously from 3,000) and, according to Section 4 Paragraph 3 LkSG, requires the appointment of a responsible person, usually referred to as LkSG representative. This obligation is tied to the number of employees and is therefore the clearest example of a threshold-based ordering obligation. In addition, there is the EU supply chain directive CSDDD, which will gradually cover additional companies from 2027. The appointment certificate, signed, filed, verifiable.

Rules of thumb from practice: at what size a compliance officer makes sense

Even if there is no general threshold, rules of thumb have been established in consulting practice. Up to around 50 employees, the management itself is responsible for compliance; A documented set of procedural instructions, a code of conduct and annual training are usually sufficient, unless an industry-specific obligation applies. If you have 50 to 250 employees, it is recommended to appoint a part-time compliance officer, often combined with other functions such as legal or human resources. For 250 or more employees, the function is usually designed as an independent role; for 1,000 or more employees, it is designed as a department with several specialists.

These rules of thumb are not binding, but they help with arguments to supervisory boards, investors and insurance companies. In the event of a claim, D&O insurance (Directors and Officers Liability) checks whether the management has adequately organised its supervisory duties. Fehlt ein Compliance-Beauftragter in einem Unternehmen mit 400 Mitarbeitern und internationalem Vertrieb, kann die Versicherung Leistungen kürzen oder verweigern. Banks are increasingly taking the CMS into account when assessing loans according to MaRisk, and ESG ratings directly assess governance structures.

Another aspect is business activity. Anyone who is active in exports, works with public clients, has foreign subsidiaries or is active in the healthcare sector has a higher risk profile and needs a compliance officer sooner. The CIVAC platform supports 25 representative roles that can be activated depending on the risk profile without the company having to set up a separate position for each role. The amount of time required also plays a role: experience shows that in a company with 200 employees, between 0.3 and 0.5 full-time equivalents of compliance work are required, an amount that rarely justifies a separate position, but is too much for part-time work in day-to-day business.

What Section 130 OWiG specifically requires of management

§ 130 OWiG describes the supervisory obligation abstractly, but leaves scope for the concrete design. Case law has specified some requirements over the years. According to BGH case law, at least four components are required: risk analysis, written code of conduct, employee training and compliance monitoring. If one of these components is missing, the supervisory obligation is considered to have been violated, even if no specific violation is proven.

The risk analysis must be documented and capture the compliance risks relevant to the company: corruption, antitrust law, money laundering, criminal tax law, occupational safety, data protection, export control, supply chain. The rules of conduct must be understandable for employees, linguistically adapted and actually communicated. The training must be carried out regularly (at least annually), target group-specific and verifiable. The control includes both random samples (internal audits) and a whistleblower system in accordance with the Whistleblower Protection Act (HinSchG), which is mandatory for companies with 50 or more employees.

The appointment of a compliance officer is not mandatory for the fulfilment of Section 130 OWiG, but it makes compliance considerably easier. Without a designated function, supervision often runs into day-to-day business, is not documented and cannot be verified in an emergency. With a designated compliance officer, there is clear responsibility, a reporting line and a documentation structure that visibly fulfils the supervisory obligation according to Section 130 OWiG. The auditor calls, the evidence is ready. This visibility is crucial because, in an emergency, it allows management to prove that supervision was organised, which makes it much more difficult to assume that there has been a culpable breach of duty and, in practice, relieves the burden on many procedures during the investigation phase. Without a named function and without a reporting line, this evidence regularly ends in disputes over the interpretation of Outlook emails and calendar entries.

Internal or external: which solution is suitable for which size of company

The decision between an internal and an external compliance officer depends on the size, complexity and budget of the company. An internal compliance officer is common in larger companies with around 500 employees or more because the function there generates enough volume to justify a dedicated position. Advantages: deep knowledge of the business, short distances, high availability. Disadvantages: Dependency on one person, risk of representation, training effort for the person himself.

An external compliance officer is often chosen as a pragmatic solution in small and medium-sized companies. Advantages: no separate position required, established templates and methods, guaranteed replacement arrangements, ongoing training in the role, experience from other mandates. Disadvantages: less presence in the company, higher effort for familiarization with the specific business. In practice, the external compliance officer is the most economical solution from around 50 employees to around 500 employees.

Hybrid models combine both: an internal compliance manager (often as an additional function in legal, HR or management) is supplemented by an external compliance officer who takes on the formal appointment, provides the methodology and provides on-site support if necessary. CIVAC offers both models: Licence the workspace for your internal representatives, or have our representatives order it. In both cases, the appointment certificate is available within the CIVAC SLA of two working days, instead of the industry standard two to six weeks. The hybrid approach has proven particularly useful for companies with 100 to 500 employees because it combines the advantages of both models and at the same time guarantees replacement arrangements in the event of illness or vacation. Experience has shown that the annual costs of this magnitude are significantly lower than those of an in-house office and higher than those of a purely internal solution, but the methodological expertise is available from day one.

Personal liability of management: why compliance is relevant even without an obligation

Even if there is no express obligation to appoint a compliance officer, the personal liability of management is a strong argument for a documented compliance system. According to Section 43 GmbHG (managing director) and Section 93 AktG (board of directors), the management is liable to the company with its private assets if it breaches its duty of care. The appointment and monitoring of a compliance system is part of these duties of care as soon as the company's risk profile requires it.

Personal liability can be covered by D&O insurance, but only if the management has not breached its duties through gross negligence. A grossly negligent breach of duty is regularly assumed if there is no response to known compliance risks, for example after an internal tip or a supervisory certificate. A documented CMS with a named compliance officer protects management in two directions: firstly, because risks are identified earlier, secondly because in an emergency it can be proven that supervision was organised.

Insurers have tightened their requirements in recent years. The application forms increasingly ask whether a CMS according to IDW PS 980 or ISO 37301 has been implemented, whether a compliance officer has been named and whether a whistleblower system exists. Anyone who cannot answer these questions positively will pay higher premiums or will not receive insurance coverage for certain offenses such as corruption or antitrust violations. Turn reading into a mandate.: an external compliance officer is often the quickest way to turn these answers into a positive one and thus reduce insurance costs or extend insurance coverage to previously excluded circumstances. Banks in the MaRisk environment deal with comparable questions in the annual credit check and can offer better conditions if there is a verifiable CMS.

Compliance management system according to IDW PS 980 and ISO 37301

If you want to build a CMS that meets the requirements of Section 130 OWiG and is at the same time documented in an auditor-proof manner, you should follow two standards: IDW PS 980 (principles of proper auditing of compliance management systems) and ISO 37301:2021 (compliance management systems). Both standards describe seven basic elements: compliance culture, compliance objectives, compliance risks, compliance program, compliance organisation, compliance communication and compliance monitoring and improvement. The seven elements are not optional and must be verifiably documented in the audit, otherwise the CMS is not formally IDW-PS-980-compliant.

The IDW PS 980 is primarily relevant for the audit by an auditor and is increasingly establishing itself as a de facto standard for medium-sized companies in Germany. ISO 37301 is internationally recognised and is particularly relevant for companies with foreign subsidiaries because it can be certified and conformity is visible to the outside world. Both standards require the designation of a compliance function, a documented risk analysis, a written compliance program, a whistleblower system in accordance with the HinSchG and a reporting system to management with at least one annual compliance report.

The CIVAC workspace provides 490 ready-to-use audit templates that are based on both standards. The templates cover typical compliance risks (corruption, antitrust, money laundering, data protection, supply chain, occupational health and safety, taxes, sanctions, export controls) and are linked to each other so that a risk in one template is automatically incorporated into other templates, eliminating duplicate maintenance. An external compliance officer from CIVAC can set up the CMS in four to six weeks, instead of the industry-standard six to twelve months for classic consulting. Audit-proof, documented, § 130 OWiG-proof. The set-up phase includes a risk analysis, the definition of central controls, the training of key personnel and the first reporting period to management.

Appointment certificate and reporting line: the formal side of the order

The appointment of a compliance officer is a formal act with clear requirements. A written appointment document is required that describes the duties, reporting line and powers of the compliance officer. The certificate must be signed by the management and handed over to the person appointed. Without an appointment certificate, the function is not considered formally established, which in the event of damage calls into question the supervision according to Section 130 OWiG.

The reporting line is a central element. The compliance officer must be able to report independently, usually directly to management or to the chairman of the supervisory board. A reporting line through the general counsel or the head of finance is possible, but must be justified and must not impair independence. In credit institutions, Section 25a KWG explicitly requires a direct reporting line to the management and an annual reporting right to the supervisory board.

The powers include at least the right to inspect all business areas, question employees, call in external consultants and, in an emergency, escalate measures directly to the management. These powers must be listed in the appointment certificate. CIVAC provides a sample appointment certificate template that is adapted to the specific industry, company size and legal form. The appointment certificate, signed, filed, verifiable. In the CIVAC workspace with EU data residency, the certificate is stored in an audit-proof manner and can be found in the follow-up audit within 60 seconds. The appointment certificate is confirmed annually and signed again when there is a change in management so that the formal effectiveness is maintained and no gaps arise in the chain of responsibility. If the compliance officer changes, the handover is recorded and the status of ongoing processes is recorded in a structured handover protocol, which in turn is stored in an audit-proof manner.

From reading to order: CIVAC as a platform and as an officer-as-a-service

The question of whether and when a compliance officer is mandatory cannot be answered with a single number of employees. It depends on Section 130 OWiG, the industry, the risk profile and the company's strategy. Anyone who waives an appointment should at least be able to document why the supervisory obligation is fulfilled without a named function. Anyone who is unable to do this faces a growing liability risk, which is increasingly being asked by insurers, banks and ESG ratings.

CIVAC is a compliance platform and officer-as-a-service that is built precisely for this decision-making situation. Licence the workspace for your internal representatives, or have our representatives order it. In the first model, your own employees receive access to 490 audit templates, 93 controls according to ISO/IEC 27001:2022 and the reporting line for 25 representative roles. In the second model, CIVAC provides an experienced compliance officer who is appointed as an external officer for your company, establishes the reporting line to management and is ready for action within the CIVAC SLA of two working days.

Both models use the same platform, the same storage, the same templates. A later switch between the models is possible without loss of data. Turn reading into a mandate.: write to info@civac.de or use the contact form on civac.de. You will receive an assessment within five working days as to whether your company needs a formal order under Section 130 OWiG, which industry-specific obligations apply and which model is best suited to your situation. There is no contractual obligation and you will receive the assessment regardless of whether you subsequently work with CIVAC or not. The assessment contains a recommendation for an internal or external solution, a suggestion for the reporting line and an effort estimate for the first twelve months.

FAQ

Is there a legal threshold in the number of employees above which a compliance officer becomes mandatory?

No, there is no blanket threshold in German law. Section 130 OWiG requires supervision, but leaves the specific form open. Industry-specific obligations such as the Money Laundering Act, the Banking Act or the LkSG with more than 1,000 employees in Germany have clear thresholds. In all other cases, the risk profile determines the need for a formal order.

What happens if management violates its duty of supervision according to Section 130 OWiG?

There is a risk of a fine of up to 1 million euros according to Section 130 OWiG, in conjunction with Section 30 OWiG there are additional company fines that can amount to up to ten million euros. The personal liability of the management according to Section 43 GmbHG or Section 93 AktG also applies if the company has suffered damage. D&O insurance often does not cover grossly negligent breaches of duty.

Can an external compliance officer take over the function completely?

Yes, as long as the appointment certificate, reporting line and powers are formally regulated. The external compliance officer is appointed like an internal one and assumes the function with the same legal effect. What is important is appropriate availability, a clear interface to management and documented access to all relevant company areas. CIVAC provides external compliance officers with an appointment certificate within two working days.

How much does an external compliance officer cost in a medium-sized company?

The costs depend on the size of the company, the industry and the scope of the tasks. For a company with 100 to 250 employees, experience shows that the expenditure is between 800 and 2,500 euros net per month. There are also one-off installation costs for the CMS in the first few months. CIVAC offers package prices with clear service boundaries that are transparently documented in the workspace.

How does a compliance management system affect the personal liability of management?

A verifiable CMS reduces liability in two directions. Firstly, risks are identified earlier and breaches are prevented. Secondly, in the event of damage, management can prove that supervision was organised, which makes it more difficult to assume a breach of duty. The BGH ruling of May 9, 2017 expressly recognised this protection and included it in the sentencing.

Do small companies have to appoint a compliance officer without an explicit industry obligation?

Not necessarily. Documented procedural instructions, a code of conduct and annual training are usually sufficient for around 50 employees, unless an industry-specific obligation applies. However, as soon as international business, public clients or regulated industries come into play, appointing an external compliance officer becomes the lowest-risk option because it significantly improves liability and insurability and documents the supervisory organisation in the event of damage.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles