77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Compliance tool for corporations with subsidiaries: multi-client capable, audit-proof, EU sovereign
Platform & Strategy

Compliance tool for corporations with subsidiaries: multi-client capable, audit-proof, EU sovereign

16 July 202613 min readBy Dr. Henrik Bauer
CIVAC

Corporations with two to fifty subsidiaries need a single tool that separates per client and consolidates per group. This article explains the requirements of Section 130 OWiG, Art. 26 GDPR and ISO/IEC 27001:2022 and how CIVAC maps them in a platform.

§ 130 OWiG obliges the management of every independent company to take the supervisory measures necessary to prevent violations. In a group with subsidiaries, the obligation applies per legal unit, not per group. The holding company becomes jointly liable if it structurally fails to supervise the subsidiaries. This results in the need for a compliance tool that separates per client and at the same time consolidates at the group level: same templates, same reporting lines, separate evidence, a single dashboard for the management of the holding company, and a single contact person for the group audit and for each supervisory authority, without breaks between clients and without parallel tools per subsidiary.

This article explains the regulatory requirement in detail, compares the three common market architectures (Excel consolidation, Individual tools per subsidiary, multi-client capable platform), names the twelve core functions that a group tool actually needs and shows how CIVAC covers exactly these functions as a compliance platform and officer-as-a-service. The focus is on the operational separation of clients, legally compliant consolidation at group level, the audit robustness of the reporting line in accordance with Art. 38 GDPR and ISO/IEC 27001:2022 as well as the practical introduction in 30 days without vacancies among the representatives. The article concludes with a concrete sequence of steps and a call to request the group mapping as a template.

Key Takeaways

  • Section 130 OWiG requires supervision for each unit; the holding company is jointly liable in the event of structural failure, which is why the group tool needs a clear separation of clients and a consolidated view in one tool.
  • Compared to n individual tools, a multi-client platform saves n times maintenance, n times training and n times audit initiation, and it provides a uniform reporting line to the corporate audit department.
  • Audit robustness at the group level is created from three building blocks: uniform appointment certificate per role, EU data residency for all clients, tamper-evident audit trail with version status per document.

The obligations: Section 130 OWiG, Art. 26 GDPR and ISO/IEC 27001:2022

§ 130 OWiG (Administrative Offenses Act) obliges the owners of every business or company to take the supervisory measures that are necessary to prevent violations of obligations affecting the company. The standard applies regardless of legal form and affects every independent unit in the group. If supervision is not carried out, there is a risk of fines of up to 10 million euros per violation in accordance with Section 30 OWiG, in connection with the respective offense. In the holding-subsidiary constellation, the supervisory obligation also applies at the level of the holding company as soon as it structurally organises supervision of the subsidiaries or simply fails to do so. In recent years, case law has consistently interpreted the obligation in a restrictive manner.

Art. 26 GDPR regulates joint responsibility as soon as two group companies jointly determine the purposes and means of processing, which is practically always the case with central HR systems, central CRMs or central marketing stacks. The agreement must transparently regulate who bears which obligation and the essential extracts must be accessible to those affected. Without a documented agreement, each company is also liable for the other's breach of duty, and the supervisory authority addresses both together.

ISO/IEC 27001:2022 requires the definition of the scope for each organisation in clause 4.3. If you want a group certificate, you should clearly define the scope and continue the 93 controls in each included subsidiary in a comprehensible manner. The information security officer of each subsidiary reports to the ISMS management of the holding company; The platform must technically map the reporting line and prove it in the audit trail. Anyone who still has the scope change to the 2022 version ahead of them should plan the migration for each subsidiary with a date and responsibility, instead of announcing it centrally across the board. The three standards intertwine, and a corporate tool must incorporate this interlinking in a data model.

Three architectures in comparison: Excel, individual tools, multi-tenant platform

Architecture 1: Excel consolidation. Each subsidiary maintains its compliance in tables, the holding company collects information once a quarter by email. Advantages: low licence costs, can be used immediately, familiar tools. Disadvantages: no versioning, no audit trail, no timeliness, no role concept, no evidentiary value in disputes, no automatic deadline monitoring. With three subsidiaries it is still manageable, from five onwards the model falls apart, from ten onwards it is a risk that will appear as a systemic deficiency in the next group audit. After one to two years, the manual effort for consolidation regularly exceeds the licence costs of a professional platform.

Architecture 2: Individual tools per subsidiary. Each subsidiary procures its own solution, often developed historically through acquisitions or through local representative recommendations. Advantages: local responsibility, quick implementation per unit. Disadvantages: n times training, n times maintenance, n different data models, n separate audit processes, no consolidated view at group level, no uniform template base. The holding company has to compile a report from n data exports without the templates or definitions matching. Group audits become expensive and slow, and the supervisory authorities notice the inconsistency at the first cross-connection at the latest.

Architecture 3: Multi-client platform. One technical instance, separate data rooms for each subsidiary, common templates and consolidation at group level. Benefits: unified reporting line, one-time training, one-time maintenance, verified EU data residency, a single point of contact for the group auditor and a unified role library. The prerequisite is a technical architecture that ensures real data separation and enables the consolidation views on a role-based basis. As a compliance platform and officer-as-a-service, CIVAC is designed precisely for this third architecture, with 25 preconfigured officer roles across all clients and a uniform consolidation view for group compliance. The decision for Architecture 3 is not a technology project, but an organisational decision; technology follows the decision, not the other way around. In practice, the change pays for itself within twelve to eighteen months.

Twelve core functions that a corporate tool actually needs

Firstly, client separation with its own data room for each subsidiary and role-based consolidation at group level. Secondly, a uniform role library for all representatives (DSB, ISB, compliance, money laundering, ESG, hygiene, fire protection, dangerous goods, hazardous substances, SiFa and others) so that the appointment certificate, role description and reporting line are identical across all subsidiaries. Third, audit templates with version status and release workflow that accepts a group audit without questions. Fourth, a reporting path for security incidents with the NIS 2 deadlines of 24 hours early warning and 72 hours follow-up notification, preconfigured for each federal state supervisory authority.

Fifth, the GDPR reporting path according to Art. 33 for the 72-hour period with automatically generated supervisory authority addressing for each federal state and per subsidiary. Sixth, a list of processing activities per subsidiary, which can be aggregated at group level and linked for joint responsibility in accordance with Art. 26 GDPR. Seventh, a training and awareness function that is centrally managed, locally distributed and documented individually in each subsidiary, with proof for each employee and for each compulsory training.

Eighth, a whistleblower channel in accordance with the Whistleblower Protection Act with separate input for each client and a group-wide second instance for escalations. Ninth, a supplier module with GDPR order processing contracts and LkSG risk analyses consolidated at group level. Tenth, EU data residency and ISO/IEC 27001:2022 hosting for the platform itself. Eleventh, an audit trail with tamper evidence mechanics so that every click and every signature is immutably logged and can stand up in court in the event of a dispute. Twelfth, a reporting line to Group Audit in machine-readable form. CIVAC covers all twelve functions from a single source. If you look for a shorter list, you postpone the problem until later audits; Each of the twelve functions is regularly relevant in at least one supervisory audit. The shortness of the list is the result of many corporate audits, not marketing simplification.

Client separation in practice: What needs to be separated technically and organizationally

Technical separation means that each subsidiary receives its own logical data room, that authorizations are assigned separately for each client, and that a view at group level is only activated on a role-based basis via a consolidation function. Employees of a subsidiary only see data from their own daughter. The group compliance officer sees aggregated key figures across all clients, but no individual personal data records without explicit local access. This separation is proven by an authorisation audit before each group audit and is recorded in the audit trail.

Organizational separation means that each subsidiary maintains its own appointment certificate for each representative role, with its own date, its own reporting line and its own signature from the subsidiary management. Even if the same person is appointed as an agent for several subsidiaries, there are n appointment documents, n role descriptions and n separate reports to the relevant supervisory authorities. Otherwise, the supervision of a subsidiary will be ineffective as soon as the central order is formally challenged, and liability will fall back to the management of the respective subsidiary.

CIVAC manages each subsidiary as a separate client with its own contract, its own appointment certificate series, its own URL and its own audit trail. The consolidation view for group compliance is an additional role with read-only access to key figures, document status and deadlines of all linked clients. The Role Catalog shows the standard reporting line for each of the 25 representative roles, which can be adapted for each subsidiary if desired. The appointment certificate, signed, filed, verifiable, in every subsidiary, without exception. This double separation is proven separately in every ISO audit, in every GDPR audit and in every group audit, and it saves the recurring clarification loop in subsequent audits. The clients are configured once during onboarding and are then only adjusted if the group structure changes.

Consolidation at group level: Which key figures the holding company actually needs

Corporate compliance requires fewer metrics than most tools offer. Six is ​​enough in practice. First: Number of appointed representatives per role and per subsidiary with status (active, vacant, in representation). Second: Number of open audit findings per subsidiary, broken down by severity (critical, medium, low) with average processing time and oldest open find. Third: Number of reportable incidents in the last twelve months per subsidiary, per reporting path (NIS-2 BSI, GDPR supervisory authority, HinSchG internal reporting office, ESG complaints), each with status of processing.

Fourth: Training coverage per compulsory training and per subsidiary in percent, with deadline and next obligation to repeat. Fifth: Status of the records of processing activities per subsidiary, with last review date and number of open updates. Sixth: Supplier risk per subsidiary from the LkSG and GDPR-AVV assessments, with the number of high-risk suppliers and the next reassessment due. These six key figures fit on an A4 page and are sufficient for a group audit for the quarterly meeting of the Audit Committee.

The platform must derive the six key figures on a daily basis from the clients' operational data, without the subsidiaries having to work manually or fill out Excel templates. As soon as a subsidiary signs an appointment certificate or closes an audit find, the group view is updated in real time. CIVAC delivers this consolidation as a standard function, together with a machine-readable interface for ERP or GRC connectors. The auditor calls, the evidence is ready., per subsidiary and per group, without a day of preparation. The six key figures are also kept in a historical time series so that trends become visible and do not only become noticeable when comparing the years. Negative developments automatically trigger a notification to Group Compliance, with a suggestion for escalation to the affected subsidiary management.

Officer-as-a-Service vs. Licence: The dual model for corporations

Models mix in corporations. One daughter has an internal DPO; the next does not have a suitable internal resource and uses an external DPO; the third is a GmbH acquisition with an old contract that is to be terminated. A group tool must support both models in parallel, without breaking the reporting line to the holding company and without the templates being reinvented for each subsidiary. Licence the workspace for your internal representatives, or have our representatives appointed, individually configured for each subsidiary and documented in the same audit trail.

In practical terms, this means: in the subsidiaries with internal staff, the respective internal representative has full access to the client workspace, with the 490 audit templates, the 93 ISO controls and the reporting paths. In the subsidiaries without internal staff, a CIVAC representative takes over the order, works in the same workspace and reports to Group Compliance along the same line. The SLA for the external order is two business days, measured from the signed contract, and the appointment certificate is in the audit trail on the third business day.

The mixed configuration is the rule, not the exception. It reflects the reality after acquisitions, restructuring and differences in maturity between the subsidiaries. Others run compliance like a filing cabinet. We run it like software. The dual model is the only one that works without disruption in a corporate reality, and it is already reflected in CIVAC's standard contract, without additional clauses. A change between models is possible for each subsidiary at any time, without data migration and without renewed training in corporate compliance. This flexibility is essential because personnel situations in subsidiaries change more quickly than a classic change of provider would be possible.

EU data residency, ISO/IEC 27001:2022 and Schremser printing

Corporations with European regulatory authorities, with pharmaceutical approvals, with public clients or with US cloud avoidance clauses in customer contracts need a documented EU data residency for every compliance tool. Schrems II (ECJ, C-311/18, July 16, 2020) has tightened the requirements for international data transfers. A compliance tool hosted or administered in the USA creates a data transfer that must be independently justified, with standard contractual clauses and additional measures per processing activity. In many corporate compliance reviews, this point becomes the knockout criterion for provider selection.

CIVAC is hosted in the EU, administration is carried out by European employees, and the underlying infrastructure is certified according to ISO/IEC 27001:2022. The 93 controls of this standard are not only compliance content of the platform, but also a requirement for the platform itself, regularly audited and demonstrably maintained. This means that the platform meets the requirements it places on clients and can write a corresponding confirmation into the order processing contracts without having to renegotiate clauses.

For corporations with subsidiaries outside the EU, the EU parent's client remains in the EU; A separate data transfer impact assessment block is maintained for a US or UK subsidiary. The separation is clean and verifiable; each processing activity is assigned to a data category and a legal area for each client. The deadline expires as soon as we become aware of it; the tool itself must not become an opportunity to write a report to a supervisory authority. The annual update of the transfer impact assessment is stored in the workspace as a recurring task and is escalated automatically. The platform thus fulfils the holding company's duty of care towards the data protection authorities without the subsidiary representatives having to keep additional appointments in the calendar.

Introduction in 30 days: sequence, responsibilities, risks

Day 1 to 5: Group mapping. All subsidiaries are listed, the current status of representative orders is recorded for each subsidiary, and the target is defined for each role and per subsidiary. Group compliance is responsible, supported by the subsidiaries' HR and legal functions. The mapping is documented in a single table, which is later imported into the tool, and it is approved in writing by the corporate board, with a date and signature. The released table is the basis for the client creation.

Day 6 to 15: Client creation and migration. Each subsidiary is created as a separate client in the tool, the existing appointment certificates are uploaded to the respective client, and the reporting line is configured. The subsidiary management is responsible together with CIVAC onboarding. Risks in this phase include unclear old contracts with external agents that run in parallel; these will expire in an orderly manner in a transition plan without creating vacancies or blocking supervisory reports. A clearly documented handover protocol for each representative is mandatory.

Days 16 to 30: Consolidation and initial group view. The six key figures from the group perspective are activated, the first quarterly report to the group audit department is prepared, the open audit findings are prioritised for each subsidiary and given deadlines. By day 30 at the latest, a consolidated A4 page will be available, which the Group Executive Board signs off on. From this day on, the group works in one platform instead of in n filing cabinets, and the next group audit will have a uniform database, which measurably reduces audit costs and audit duration. The empirical values ​​from previous corporate implementations show a reduction in audit preparation time by sixty percent from the second audit cycle.

Turn reading into an assignment

If your group consists of three or more subsidiaries and the supervisory obligation according to Section 130 OWiG, the joint responsibility according to Art. 26 GDPR and the ISO/IEC 27001:2022 requirements are currently distributed across Excel, n individual tools or an improvised mixture, the next step is to take stock of the twelve core functions of this article. CIVAC delivers the inventory as a two-page template and the group mapping as an Excel template, both without contractual commitment and without paid workshops in advance.

CIVAC is built as a compliance platform and officer-as-a-service so that the holding company and all subsidiaries work in the same tool without violating client boundaries. Licence the workspace for your internal representatives, or have our representatives order it individually for each subsidiary. The SLA for external orders is two working days instead of two to six weeks, the EU data residency is documented in the standard contract, and the 25 representative roles are preconfigured identically across all clients. A group audit uses a uniform database instead of n different tables, which measurably shortens the duration of the audit.

Turn reading into a mandate. Write to info@civac.de with the number of your daughters, the affected representative roles and your desired start date, or use the contact form on civac.de. The first response contains a group mapping template, a cost indication for the number of clients and a proposal for the 30-day implementation plan, in writing within two working days, signed by the responsible representative. A telephone consultation is not required, but can be requested at any time, and a pilot operation with a selected subsidiary is the standard option. The pilot is usually started with the subsidiary whose next audit is closest; so the first value becomes visible before the group rollout is completed.

FAQ

Is it enough to buy a single compliance licence for the entire group?

No. According to Section 130 OWiG, each subsidiary is its own supervisory unit, each appointment certificate must be signed for each subsidiary, and each supervisory authority is addressed for each subsidiary. A technically common platform makes sense and is common practice, but the legal separation of clients remains mandatory. CIVAC maps both in a platform with separate clients and a group consolidation view.

How is joint responsibility according to Art. 26 GDPR reflected in the tool?

As soon as two subsidiaries jointly determine the purposes and means of processing, a reference to the joint agreement will be stored in the list of processing activities of each participating subsidiary. The agreement itself is available as a template for each participating subsidiary, with identical content, signed separately. This means that consolidation at group level remains possible without violating client boundaries or traces of evidence.

Can Group Compliance see the subsidiaries’ personal data?

Only if there is a written basis, such as an intra-group order processing agreement or a legitimate balancing of interests in accordance with Article 6 (1) (f) GDPR. By default, Group Compliance receives an aggregated view of key figures without reference to individuals. Individual data accesses are approved locally in the subsidiary and logged in the audit trail, with a time stamp, reason and recipient so that the justification can be proven at any time.

What happens during an acquisition if the acquired company already uses a different tool?

The acquired company is created as a new client on the group platform, its appointment certificates and directories are migrated, and the old contract for the previous tool is terminated on the next termination date. CIVAC accompanies the migration with a transition checklist so that there is no gap in supervision between the old system and the new system, no deadline is lost and no open report is lost in the handover.

How is EU data residency ensured for a US subsidiary?

The US subsidiary receives its own client whose data room is located on an EU authority; The administration by the US subsidiary takes place via VPN on the EU hosting. If data flows from the USA to the EU client, the transfer impact assessment applies; If data from EU mothers comes into US access, the standard contractual clauses plus additional measures according to Schrems II apply, documented in the client contract.

How quickly can the consolidation view be activated?

As soon as all subsidiary clients have been created, the group view is activated within 48 hours by default. For ten subsidiaries, full consolidation is typically live on day 16 of the rollout plan; The six standard key figures will be used in the first quarterly report to the group audit department from day 30, without further manual preparation by the subsidiary representatives.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles