77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Compliance training: measure effectiveness and provide complete evidence of it in the audit
Governance & Compliance

Compliance training: measure effectiveness and provide complete evidence of it in the audit

12 July 202612 min readBy Dr. Henrik Bauer
CIVAC

Participation is not proof. If you want to pass the audit, you have to show that compliance training actually changes behaviour. This guide explains KPIs, documentation and reporting lines for robust effectiveness controls.

According to Section 130 OWiG, company management is liable for failure to take supervisory measures, which expressly include training and effectiveness monitoring. ISO 37301:2021 requires in clauses 7.2 and 7.3 not only the delivery of training, but evidence of its effectiveness, including awareness, competence and documented information. Anyone who only presents attendance lists in the audit risks being found out because mere attendance is not an indicator of behaviour change. Depending on the special law, the fine ranges from 50,000 euros to 10 million euros, and in data protection up to 4 percent of global group sales, and they affect the company regardless of the individual culpability of the management.

This article shows how you can set up compliance training so that you can prove three things in the audit: Firstly, that the right people have received the right knowledge. Second, that this knowledge has been tested and understood. Third, that the training has a proven impact on behaviour and compliance metrics. You will receive concrete KPIs, a documentation structure, a suggestion as to what the reporting line to management should look like, as well as an overview of typical audit findings including measures to avoid. CIVAC provides a compliance platform and officer-as-a-service that maps exactly this interaction of software, appointment certificate and audit templates and automatically generates the reporting line on a quarterly basis.

Key Takeaways

  • Participation rates are not proof of effectiveness: Section 130 OWiG and ISO 37301 require awareness, competence and documented impact.
  • Measure at least three KPI levels: coverage, understanding (test score) and behavioral indicator such as whistleblower receipts per 1,000 employees.
  • The appointment certificate, signed, filed, verifiable: proof of training belongs in a central, audit-proof reporting line, not in local folders.

Why participation rates in audits are not enough

The most common finding in compliance audits is: Training has been carried out, but there is no proof of effectiveness. Auditors rely on ISO 37301:2021, clause 7.3, which explicitly requires awareness, competence and documented information, as well as Section 130 OWiG, which requires management to take necessary supervisory measures. A pure participation list only proves presence, neither understanding nor application, neither transfer into everyday work nor reaction to specific risk scenarios. Even 100 percent coverage remains meaningless on its own as long as the level of understanding and the level of behaviour are not collected in addition.

In practice, this means: Anyone who reports 95 percent coverage but does not show a test score, a sample interview or a behavioral indicator has an effectiveness problem as soon as the supervisory authority or an internal auditor takes a closer look. It becomes particularly critical when an incident occurs and management has to explain afterwards why the training did not prevent the violation. In damages cases and fine proceedings, courts regularly examine whether the company maintained an effective training system, not whether it only had a formal one. Anyone who only submits lists loses the opportunity to reduce fines according to Section 30 OWiG and weakens their own defence position.

Only a three-stage model of coverage, understanding and behaviour can help here. CIVAC structures exactly this three-level logic in the workspace. Training is assigned via the compliance platform and Officer-as-a-Service, learning successes are automatically recorded and reflected in the quarterly report to management. Anyone who needs external responsibility can appoint the Compliance Officer from CIVAC instead of setting up an internal position. Others run compliance like a filing cabinet. We run it like software.

Legal framework: Section 130 OWiG, ISO 37301 and industry-specific obligations

§ 130 OWiG is the central norm in German administrative offense law for the so-called breach of supervisory duty. The management of a company must take supervisory measures necessary to prevent violations. The case law also interprets this as an organisational obligation for training and effectiveness monitoring, not as a one-off but as a continuous requirement. Fines can amount to up to 10 million euros, or several times more in the case of intentional violations, and they are usually imposed in addition to the fine against the company in accordance with Section 30 OWiG. In addition, there is the personal liability of organs.

ISO 37301:2021 systematizes the same concern internationally. Clause 7.2 requires that employees have the necessary competence, Clause 7.3 requires awareness of the compliance policy and the consequences of violations, Clause 7.5 requires documented information. Clause 9.1 adds the obligation to monitor, measure, analyse and evaluate. These four clauses together form proof of effectiveness in the narrower sense, because they require that the company not only trains, but also methodically collects and evaluates the success of this training.

Other industry-specific obligations supplement the framework: Section 6 GwG for money laundering prevention, Section 12 AGG for employee training, Art. 39 GDPR for advice by the data protection officer, Section 9 HinSchG for the internal reporting office. Anyone who operates a money laundering officer or an internal reporting office must conduct the training in accordance with the relevant special laws and also meet the ISO requirements. CIVAC bundles these layers into a template system with 490 ready-to-use audit templates, so you don't have to design every training course from scratch and still cover all special laws cleanly.

Three KPI levels: Coverage, Understanding, Behaviour

Reliable effectiveness measurement is based on three levels. The first level is coverage: What proportion of the target group completed the training within the given deadline? Sensible targets are 95 percent for general compulsory training and 100 percent for security-critical roles, such as money laundering officer, data protection officer or information security officer. The metric is broken down by area, location, role and start date to reveal gaps before the auditor finds them. A pure overall quota hides weak points and is not meaningful as a sole indicator.

The second level is understanding. Final tests with randomly changing question pools, a minimum score of usually 80 percent, and 90 percent for safety-critical roles, as well as random in-depth interviews by the compliance officer are suitable here. In addition, a short awareness survey six to eight weeks after the training helps to measure what has actually been remembered. Anyone who falls below 70 percent on these levels should revise the module didactically, not simply force repetition, because repeating a bad module does not bring any gain in knowledge.

The third level is behaviour and is therefore the most demanding. What counts here are indicators such as the number of reports to the internal reporting office per 1,000 employees, the rate of self-reported near-violations, hits in random mystery checks or the response time to simulated phishing campaigns. In practice, a moderate increase in reports after training roll-out is considered a positive signal because it indicates increased awareness, not more violations. These behavioral KPIs must be coordinated with the data protection officer so that the collection of personal indicators remains legally clean and no inadmissible behavioral controls arise according to Section 26 BDSG.

Documentation and reporting line to management

In order for proof of training to stand up to the audit, four components must be present: the training concept with defined target groups, learning objectives and repetition cycles, the participation documentation per person with date and final score, the effectiveness measurement on the three levels described and the quarterly report to the management. If one of these building blocks is missing, the evidence is incomplete. The fourth component is particularly often missing because internal compliance functions submit their reports orally or by email without the management formally acknowledging and countersigning in writing.

The reporting line to the management is not a formalism, but a strict requirement from ISO 37301 clause 5.1.1 and from Section 130 OWiG. Management must have demonstrable knowledge of compliance effectiveness and respond to vulnerabilities. In practice, this means a written quarterly report with traffic light status, trend analysis, suggested measures and a concrete escalation path for red indicators. The report is countersigned by the compliance officer, acknowledged by management, dated and filed in the appointment certificate file so that any subsequent audit can fully understand the flow of information.

CIVAC maps this reporting line natively in the workspace. A quarterly report is automatically created from participation data, test scores, awareness surveys and behavioral indicators, which is signed and filed in the appointment certificate file. The auditor calls, the evidence is ready. If you would like to combine this setup with an external order, you can find further information in the CIVAC FAQ. The solution meets both the German special laws and the ISO requirements with the same data basis, which avoids duplication of work and ensures consistent data statuses. Licence the workspace for your internal representatives, or have our representatives order it.

Mix of methods: compulsory modules, microlearning, scenarios

Effectiveness does not come from a single annual training, but rather from a mix of methods of compulsory modules, microlearning and scenario training. Compulsory modules cover basic knowledge, usually last 30 to 60 minutes and are repeated annually. They cover topics such as anti-corruption, data protection, whistleblower protection, money laundering prevention or ESG obligations depending on the industry and risk profile. Compulsory modules are the necessary, but not sufficient, part of an effective program because they ensure the minimum legal coverage without actively promoting the transfer into everyday work or training behaviour.

Microlearning supplements the compulsory module with short learning units of three to seven minutes, which are played out during the year. They address current topics, such as a new BaFin interpretation, a change in case law or an internal incident that leads to lessons learned training. Microlearning significantly increases memory performance compared to pure annual training because it uses the spacing effects of learning research and refreshes knowledge exactly when it is about to fade. Ideally, microlearning units are integrated into everyday work, for example as short compulsory modules in the intranet login or as a weekly impulse via corporate communication.

Scenario training is the most effective, but at the same time the most complex method. Realistic situations are simulated here, such as an attempted bribe by a supplier, a suspicious transaction in accounting, a phishing email or a discriminatory comment at work. The participants have to decide and then receive differentiated feedback including the legal consequences of a wrong decision. In safety-critical industries, such as banks or the pharmaceutical industry, scenario training is now the market standard. The external data protection officer can bring in real but anonymized cases from client practice, which makes training courses much more concrete than any standard video and emotionally binds participants.

Common audit findings and how to avoid them

Internal and external auditors repeatedly come across the same weak points. First: target groups are not clearly defined. Training courses are distributed across the board to everyone, although sales, purchasing and IT carry different risks. A training matrix helps here, in which the mandatory modules, refresher cycles and minimum scores are defined for each role. The matrix is ​​reviewed annually and adapted to organisational changes. Second: repetition periods are not monitored. Training is only considered effective as long as it is current, 12 months for most mandatory topics, and annually for money laundering prevention according to BaFin's interpretation.

Third: New entries are not systematically recorded. Anyone who does not complete compliance training during onboarding will fall through the cracks until the next annual cycle starts. An automated assignment via the HR system, triggered at the start of the contract, closes this gap. Fourth: External employees and temporary workers are forgotten. This group does not appear in many training systems, but is legally subject to the same treatment as long as they work under instructions. Working students, interns and temporary employees also fall into this group of people.

Fifth: There is no connection between the incident and the training. If a data protection incident, suspected money laundering or an accident at work occurs, the lessons learned training should roll out within 30 days, otherwise the learning effect will be lost. CIVAC connects the incident module directly with the training module: A documented report automatically creates a training suggestion including a target group, which is approved by the compliance officer. Audit-proof, documented, § 130-OWiG-proof. Sixth and finally: language variants are missing. Anyone who operates locations in Poland, the Czech Republic or France must offer training in the respective national language, otherwise the effectiveness argument does not apply and the auditor is regularly the first to determine this.

External vs. internal responsibility: officer model or platform

Many companies are faced with the decision of whether to establish an internal compliance officer or choose an external appointment. Both ways are legally permissible, the difference lies in the speed, costs, specialist knowledge and availability of representation. An internal position usually takes six to nine months from the job advertisement to training, often longer in the current skilled labour market. An external order via CIVAC is placed with an SLA of 2 working days instead of the classic 2 to 6 weeks. The choice between the two models is not final; many companies start externally and later transfer the function internally as soon as the structures are sustainable.

The officer model is particularly suitable for companies with fewer than 500 employees, for subsidiaries of international corporations without their own German compliance infrastructure, and for regulated industries with a particularly high level of specialist knowledge, such as financial service providers or pharmaceutical production. Here, a certified representative takes over the function with an appointment certificate, a fixed reporting line and defined accessibility. Advantage: Special knowledge is immediately available, representation regulations are built into the contract, and the representative brings templates and benchmarks from other mandates, which significantly reduces the effort for the company.

The platform variant, on the other hand, licences the workspace to the existing internal representatives and thus supplements audit templates, reporting lines, training modules and reporting paths. Both ways can be combined: Some companies licence the workspace for data protection and information security, but also have the compliance officer appointed externally. Licence the workspace for your internal representatives, or have our representatives order it. The EU data residence and the ISMS certified according to ISO/IEC 27001:2022 are included in both variants, so that particularly sensitive training data can also be processed there.

Practical example: Effectiveness measurement in a medium-sized industrial company

A medium-sized mechanical engineering company with 850 employees at three locations in Germany and Poland carried out a complete overhaul of its compliance training in 2024. The reason was an external ISO 37301 preparation, in which the auditor determined that training was documented, but effectiveness was not proven. The management gave six months' notice and named the commercial manager as responsible. The budget included the connection to the existing HR suite, the licensing of a compliance platform and daily rate-based support from the external compliance officer over twelve months.

Step one was the definition of a training matrix with eleven compulsory modules and four role-specific additional modules for sales, purchasing, IT and factory management. Step two was the introduction of final tests with a minimum score of 80 percent and an awareness survey six weeks after completion. Step three was the link with behavioral indicators, in this specific case whistleblower receipts and random mystery calls during purchasing, carried out by the external compliance officer while maintaining employee data protection. Step four was the introduction of a written quarterly report with traffic light status, which was referenced by management at the supervisory board meeting and noted in the resolution minutes.

The result after two quarters: coverage was 97 percent, the average test score was 86 percent, and reports to the reporting office increased from 3 to 14 per 1,000 employees, 11 of which had constructive content unrelated to violations, such as suggestions for improvement to processes. The subsequent ISO 37301 audit no longer found any findings regarding training effectiveness. The managing director received an eight-page quarterly report with traffic light status, trend analysis and concrete suggestions for measures and was able to reference it at the supervisory board meeting. The appointment certificate, signed, filed, verifiable, checkable at any time.

This is how CIVAC supports: Platform, Officer and Audit Templates

CIVAC bundles compliance platform and officer-as-a-service in one system. In the workspace you manage 25 representative roles, store the 93 controls according to ISO/IEC 27001:2022, draw from 490 ready-to-use audit templates and automatically route the reporting line to the management. Evidence of training, effectiveness measurement and incident history are in one system, with EU data residency and demonstrably separate client management. The system is designed for the German legal framework and at the same time maps ISO clauses 7 and 9 with the same data basis without the need for double documentation.

If you do not want to appoint an internal compliance officer or need to fill a vacancy at short notice, use the officer model with an SLA of 2 working days instead of the classic 2 to 6 weeks. The appointment certificate is signed within this period, the reporting line is established, and the audit templates are activated in the workspace. Licence the workspace for your internal representatives, or have our representatives order it. Both methods comply with § 130 OWiG and ISO 37301 and are reciprocally convertible during ongoing operations if the organisational situation shifts due to growth, M&A activities or regulatory changes.

If you would like to specifically check whether your current training system holds up in the audit, arrange a 30-minute conversation with a CIVAC representative. You will receive an initial assessment of the training matrix, KPI set and reporting line as well as a recommendation as to which of the three levels should be closed first in your case. You will also receive an excerpt from the audit templates that illustrates the typical structure of a quarterly report and can check whether the formats fit your internal governance before commissioning. Turn reading into an assignment. Write to info@civac.de or use the contact form on civac.de.

FAQ

Which legal basis requires proof of effectiveness for compliance training?

Section 130 OWiG is relevant for the supervisory obligation of company management as well as ISO 37301:2021, in particular clauses 7.2 (competence), 7.3 (awareness), 7.5 (documented information) and 9.1 (monitoring and evaluation). Sec. 6 GwG, Art. 39 GDPR and Sec. 9 HinSchG supplement the framework for specific industries depending on the training topic and target group, supplemented by special occupational health and safety standards.

Is annual compulsory training with confirmation of participation sufficient?

No. A confirmation of participation only documents attendance, neither understanding nor application. The training only becomes audit-proof through final tests with a minimum score, an awareness survey six to eight weeks after completion, and a behavioral indicator that is included in the quarterly report to management. Only this triad model fully complies with ISO 37301 Clause 7.3 and withstands audit findings.

What should the minimum score be in a final test?

In practice, 80 percent has established itself as a reliable lower limit. For security-critical roles, such as money laundering officers or data protection officers, 90 percent is appropriate. What is important is a randomly changing question pool with at least three times as many questions as were drawn in the test so that participants cannot memorize the test, as well as a limited number of repeat attempts.

How do I integrate external employees and temporary workers into the training system?

According to Section 14 AÜG and the special laws, external and temporary employees are to be treated largely equally legally, provided they work in accordance with instructions. In practice, this means a separate target group in the training matrix with its own onboarding path, documented confirmation from the borrower and a regular comparison with the personnel deployment list in order to identify gaps early on.

What role does the compliance officer play in measuring effectiveness?

The compliance officer is responsible for the training concept, defines the KPIs, randomly checks understanding and prepares the quarterly report to the management. At CIVAC, this role can either be filled internally and supported by the workspace or fully covered externally via Officer-as-a-Service, with an appointment certificate within 2 working days, a documented reporting line and a built-in representation policy.

How quickly can CIVAC set up a training and effectiveness system?

The appointment certificate for the officer will be issued within 2 working days and the workspace will be active on the same day. The training matrix with the mandatory modules and the first KPI reports are typically available within 4 to 6 weeks, depending on the size and complexity of the company. The first full quarterly report will be delivered after 3 months.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles