77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
DWS, ESG and the lessons for German companies with ESG obligations
ESG & Sustainability

DWS, ESG and the lessons for German companies with ESG obligations

7 August 202614 min readBy Dr. Henrik Bauer
CIVAC

The DWS case has put ESG compliance on the board agenda: greenwashing allegations, regulatory investigations, reputational damage. Anyone who is responsible for ESG today needs risk analysis, documented controls, a reporting line to management and an ESG officer with a clear mandate.

The DWS Group case has suddenly put ESG compliance on the board agenda of German companies. In 2022, the US Securities and Exchange Commission (SEC), BaFin and the Frankfurt public prosecutor's office initiated investigations into alleged greenwashing in the marketing of investment products. In 2023, DWS paid around $25 million to the SEC, followed by another agreement with German authorities in 2025. The case is not primarily a fund management issue, but rather a fundamental lesson for every company with ESG statements: Anyone who communicates sustainability must be able to document the underlying processes, data and controls in a verifiable way. Greenwashing risks today exist in marketing, investor relations, supplier communication, product labels and contractual clauses.

For companies with CSRD reporting requirements, EU taxonomy reference, LkSG application or voluntary sustainability statements in advertising and contract documents, this results in specific requirements: a named ESG/sustainability officer, documented ESG data flows, a double materiality analysis, a risk analysis on greenwashing risks, a reporting line to management and audit-proof evidence according to ISAE 3000 or in the future ISSA 5000. This article explains the legal obligations, summarizes the lessons from the DWS case, describes the double materiality analysis, classifies interfaces to the GDPR, LkSG and HinSchG and shows how CIVAC works as a compliance platform and Officer-as-a-Service ESG compliance is operationally secured. The appointment certificate, signed, filed, verifiable. The structure follows the practical sequence from duty analysis through role concept to audit and reporting.

Key Takeaways

  • The DWS case shows: ESG statements without documented processes, data and controls lead to greenwashing procedures with fines worth millions.
  • CSRD, ESRS and EU taxonomy require companies to provide audit-proof ESG reporting with clear accountability.
  • CIVAC appoints the ESG officer within 2 working days and delivers ESG risk analysis, ESRS data catalogue and audit templates in the workspace.

The DWS case: What happened and what breaches of duty were assumed

The DWS Group is one of the largest asset management companies in Europe and a subsidiary of Deutsche Bank. In 2021, a former sustainability officer publicly accused DWS of making ESG statements in sales documents, website and annual report without sufficient operational basis. The allegations triggered investigations by the US Securities and Exchange Commission (SEC), BaFin and the Frankfurt public prosecutor's office. In September 2023, DWS paid $19 million to the SEC for ESG misstatements and another $6 million for inadequate anti-money laundering controls.

The SEC order listed specific deficiencies: lack of documented procedures for integrating ESG factors into investment decisions, differences between external communications and internal practices, inadequate risk management oversight, lack of escalation channels for ESG concerns. The Frankfurt public prosecutor's office also carried out raids. In 2025, another agreement was reached with German authorities. What is relevant for the compliance context is that the allegations were not aimed at the individual investment product, but at the governance structure. ESG statements were communicated without the underlying processes being consistently documented and controlled. This gap between communication and operational reality is the classic greenwashing pattern that is also vulnerable in other industries. Anyone who makes ESG statements as a management assumes responsibility for their verifiability. The appointment certificate, signed, filed, verifiable. The auditor calls, the evidence is ready. The operational consequence of the DWS case is a double dividing line: between marketing statements and operational ESG implementation and between ESG business operations and independent ESG compliance control. Anyone who draws and documents both lines significantly reduces the risk of greenwashing. Anyone who doesn't pull it risks exactly the situation that led DWS to multi-year proceedings and millions in payments. The damage to reputation is usually higher than the fines.

CSRD, ESRS and EU taxonomy as a framework of obligations

The Corporate Sustainability Reporting Directive (CSRD, Directive (EU) 2022/2464) has been in force since January 5, 2023. It obliges around 50,000 European companies to carry out standardised sustainability reporting in accordance with the European Sustainability Reporting Standards (ESRS, Delegated Regulation (EU) 2023/2772). The application takes place in stages: financial years from 2024 for large companies relevant to balance sheet ratios with an existing non-financial declaration, from 2025 for other large companies, from 2026 for listed SMEs. The EU Commission's omnibus initiative from February 2025 postponed parts of the application and proposed simplifications, but the mandatory nature remains.

The ESRS require twelve topic-specific standards (E1 climate change, E2 environmental pollution, E3 water, E4 biodiversity, E5 circular economy, S1 own workforce, S2 value chain, S3 affected communities, S4 consumers, G1 business behaviour plus the overarching ESRS 1 and ESRS 2). The EU taxonomy (Regulation (EU) 2020/852) is supplemented with criteria for ecologically sustainable economic activities and requires information on taxonomy-compliant sales, CapEx and OpEx. Anyone who is required to report must carry out a double materiality analysis (impact materiality plus financial materiality), document data flows, disclose assumptions and map them for auditors. The sustainability reports are initially audited with limited assurance by an auditor or an approved independent body, with a higher level of audit assurance in the future. Others run compliance like a filing cabinet. We run it like software. The reporting must be integrated into the annual report according to the ESEF schema and provided with XBRL tags so that the data becomes machine-readable. This technical component must be planned organizationally and coordinated with IT, controlling and external reporting. Anyone who underestimates them will lose a lot of time in the last month before the report is due for technical corrections instead of checking the plausibility of the content.

Greenwashing risks beyond the reporting requirement

Greenwashing risks arise not only through the sustainability report, but at every point where a company makes statements about environmental, social or governance factors. Climate neutrality advertising, sustainability-related product labels, contractual clauses on ESG standards, investor relations materials and employee communications are all vulnerable if the underlying data and processes cannot be verified. The EU directive to strengthen the consumer position for ecological change (Empowering Consumers Directive, Directive (EU) 2024/825) has tightened the requirements for green advertising claims since March 2024.

German case law has specified the standard in several judgments (BGH I ZR 98/23 on climate neutrality, OLG Düsseldorf on CO2-neutral products): statements such as climate-neutral, CO2-neutral or environmentally friendly must be made clarify whether they refer to reduction, compensation or both, and which compensation mechanisms are used. Missing or misleading information can lead to warnings under competition law, injunctions and claims for damages. Providers in the B2C sector are particularly exposed because consumer associations actively litigate. In the B2B sector, risks arise from supplier codes, tender responses and ESG clauses in contracts. Anyone who agrees to ESG criteria and does not comply with them risks breach of contract and compensation. CIVAC supports with an ESG statement register in which all public and contractual ESG statements are linked to source, date, responsible party and supporting documents. For inquiries from consumer associations, investors or authorities, proof is available without having to search. Greenwashing risks are further exacerbated by the planned Green Claims Directive, which will require advance verification of environmental claims. Anyone who sets up structures today will be prepared for the coming tightening, instead of having to re-document under time pressure. In the insurance and investment sector, the SFDR regulation also tightens the requirements for the classification of sustainable financial products and for the disclosure of negative sustainability impacts.

The ESG/Sustainability Officer: Role and Appointment

Unlike the data protection officer, there is no mandatory legal obligation to appoint an ESG/sustainability officer. In practice, the role has nevertheless become established because CSRD, ESRS, EU taxonomy and LkSG require a central coordination function. The ESG officer controls the double materiality analysis, coordinates data collection, is responsible for method documentation, oversees the audit dialogue with the auditor and reports to the management. In large companies, the role is often set up as a separate staff position, in medium-sized companies either in the compliance area, in controlling or as an external mandate.

The appointment is made by the management with an appointment document that defines duties, authorities, reporting line and scope. Duties typically include coordinating CSRD reporting, maintaining the ESG risk register, interfacing with LkSG obligations, managing EU taxonomy analysis, validating external ESG statements, training departments and monitoring ESG data quality. The reporting line goes directly to management, ideally to the CFO or CEO, to ensure the connection to financial reporting. CIVAC appoints the ESG representative externally within 2 working days or licences the workspace for internal representatives. Licence the workspace for your internal representatives, or have our representatives order it. Both ways provide an appointment certificate, reporting line, ESG audit templates and data catalogue in a unified system. The qualifications of the appointed person typically include ESG methodology, reporting practices, relevant industry knowledge and audit experience. This qualification is verifiably documented in the CIVAC pool. For listed companies, we also recommend a written declaration from the ESG officer on their own independence and conflicts of interest, which is considered proof of governance substance in the audit. This declaration is updated annually and stored as a version in the workspace. The reporting obligations to the supervisory board and audit committee are also specified in the appointment document so that no reporting path remains informal.

Dual materiality and ESG data flows

Dual materiality is the methodological heart of CSRD reporting. ESRS 1 requires that companies systematically analyse both the impact of their activities on people and the environment (impact materiality) and the impact of sustainability issues on the company's value (financial materiality). Topics that are significant from one or both perspectives must be reported. Topics that are immaterial from both perspectives may be excluded from reporting, but must be methodically documented.

The materiality analysis takes place in five steps: identification of potential topics from the ESRS, stakeholder consultation, assessment of the impacts according to severity and probability, assessment of financial risks according to time horizon and probability of occurrence, consolidation of material topics with a threshold value. Every assessment must be justified and reproducible. ESG data flows typically include climate data (Scope 1, 2 and 3 emissions according to the GHG Protocol), energy data, water consumption, waste, human resources data, supplier data, accident statistics, diversity metrics and governance indicators. The data origin, the calculation method and the assumptions must be documented. CIVAC delivers an ESG data catalogue with the data points required by ESRS, linked to the ESG risk register and audit templates. Audit proof, documented, ESRS proof. Every time a data point is updated, the version history is kept so that the audit can track which value was reported on which database. This versioning is audit-critical because auditors randomly check the origin of the data and require evidence. Scope 3 data is particularly methodologically sensitive because it is based on estimates and supplier data. A documented list of assumptions with a reference to the source is mandatory. A total of several hundred data points are planned for the ESRS disclosure requirements, of which the materiality-dependent points vary greatly depending on the business model. A materiality matrix links data points to ESRS disclosures and mandatory comments so that the report is created systematically rather than through collection and sorting at the end of the period.

ESG risk analysis: What would be examined in the DWS-style process

A robust ESG risk analysis not only addresses climate risks or supply chain risks, but also greenwashing and compliance risks. The analysis identifies the probability of occurrence, amount of damage, financial impact and reputational risk for each material ESG issue. It links the risk to existing controls and to measures that bear responsibility and deadlines. ESG risks often have a medium to long-term time horizon (5 to 20 years), compliance risks are short-term (12 months).

Four concrete audit dimensions can be derived from the DWS case against which every ESG compliance structure must be measured: Firstly, the ESG statements in external communication can be verified by internal processes, data and controls. Secondly, there is an escalation route for ESG concerns from the investment decision-making process or from the operational area. Third, methods and assumptions are documented so that external auditors can understand them. Fourth, there is an independent supervisory body that does not itself operationally drive ESG measures. CIVAC implements these four dimensions via the ESG statement register, a documented escalation line to management, a versioned catalogue of methods and the separation of operational ESG functions and compliance monitoring. The ESG risk analysis is linked in the workspace to the compliance officer's risk register, so that thematic intersections (e.g. supply chain, corruption, data protection in the ESG data flow) are managed consistently. This link prevents duplicate or contradictory risk entries and reduces the effort in the materiality analysis. Anyone who sets this up properly will receive approval in the audit because the methodological consistency is understandable. In fine proceedings or in a special official audit, consistent risk analyses have a mitigating effect on punishment because they document the proper organisation of ESG compliance. The ESG risk analysis is updated annually if there are significant changes. In regulated industries such as financial services, the risk analysis is also compared with the MaRisk risk inventory in order to avoid duplication of work and ensure consistency with the overall risk map.

ESG audit and audit practice

The sustainability report is initially audited with limited assurance. The auditor or an approved independent body checks whether the report complies with the ESRS, whether the materiality analysis is plausible, whether the reported data is verifiable in the underlying systems and whether the methods are disclosed. The depth of the audit is less than that of a financial audit, but the requirements for traceability are high. ISAE 3000 (Revised) and ISSA 5000 (from 2026) form the international framework for non-financial audits.

In practice, auditors require at least five document groups: materiality analysis with method documentation, ESG data catalogue with sources and calculation logic, internal control framework for ESG data, governance documentation with ESG responsibilities and reporting material with cross-references ESRS Disclosure Requirements. CIVAC structures these five document groups in the workspace and links them to the ESRS standards. The external auditor receives access to the relevant documents via a separate audit account. Audit preparation typically begins three months before the reporting date and includes an internal mock audit in which the ESG officer runs through the likely auditor questions and closes gaps. The auditor calls, the evidence is ready. CIVAC offers 490 audit templates, including Materiality Analysis Template, ESG Data Catalog Template, Method Catalog Template, Audit Letter Template and Limited Assurance Audit Protocol. These templates are structured according to ESRS logic and are updated in the workspace with every ESRS update. This means that the audit infrastructure remains current even with future ESRS expansions or omnibus adjustments. The selection of auditors must be clarified in advance because certain audit firms have particular experience with ISAE 3000 or with industry-specific ESG topics. Early communication with the auditor reduces surprises at the reporting date. Audit planning should start at least six months before the reporting date and include a formal audit kickoff in which expectations, sample sizes and delivery deadlines are clarified.

Interfaces to GDPR, LkSG and HinSchG

ESG compliance is not isolated, but rather intertwines with other compliance domains. The GDPR applies to personal ESG data, such as diversity metrics, health statistics or supplier employee data. Lawful processing must be documented in a processing directory, data minimization must be observed, order processing contracts must be concluded with ESG data service providers. The data protection officer works here with the ESG officer.

The Supply Chain Due Diligence Act (LkSG) has covered companies with 1,000 employees or more since 2024 and requires risk management along the company's own business activities and those of direct suppliers. The LkSG obligations overlap with ESRS S2 (value chain workers) and S3 (affected communities). Integrated control via a LkSG representative in close coordination with the ESG representative reduces duplication of work and ensures consistent reporting. The Whistleblower Protection Act (HinSchG) requires an internal reporting office that must also record ESG concerns from the workforce or external whistleblowers. In the DWS case, public information from a former sustainability officer was a central trigger, so the existence of a functioning internal reporting office is a direct greenwashing early warning system. CIVAC links these three representative roles in a common workspace with a common risk register, integrated audit program and common escalation paths to management. In this way, ESG, supply chain and whistleblowing issues can be managed without any interface losses. Turn reading into an assignment. The link is provided by default in the workspace and does not require separate configuration. A quarterly joint meeting between the three representatives and the management ensures that comprehensive risks are identified early and treated uniformly. In the case of multinational corporations, interfaces to the corporate audit department and to national authorities in the USA, Great Britain or other relevant jurisdictions are also regulated. These international interfaces are ESG relevant because the SEC, the UK FCA and comparable regulatory authorities have formulated their own ESG requirements.

Set up ESG compliance operationally with CIVAC

If you take ESG compliance seriously, you can't avoid three building blocks: a named ESG officer with an appointment document and a direct reporting line to management, a double materiality analysis with documented methodology and an ESG statement register in which all public and contractual statements are linked to evidence. CIVAC is a compliance platform and officer-as-a-service that bundles all three building blocks in a workspace with EU data residency and interlinks them with the other 24 officer roles.

Licence the workspace for your internal officers, or have our officers appoint them. The order is processed within 2 working days; 2 to 6 weeks are standard in the industry. In the first month, the double materiality analysis is set up, the ESG data catalogue is linked to your sources, and the ESG statement register is filled. Training for the departments begins in the second month, followed by an internal trial exam in the third month. The external auditor receives structured access to the documents versioned in the workspace during the audit period. Turn reading into an assignment. Contact: info@civac.de or the contact form on civac.de. We recommend a 30-minute inventory meeting in which we review your CSRD reporting level, your material ESG issues and your existing ESG governance and propose a 90-day plan. The appointment certificate, signed, filed, verifiable. For multi-location and group structures, we supplement the model with a group ESG module that enables consolidation across subsidiaries and at the same time documents local responsibilities. This means that ESG reporting can be presented consistently and in an auditor-proof manner across the entire reporting group, including the link with the LkSG reporting to BAFA. If requested, CIVAC can also prepare the sustainability report in ESEF-compliant XBRL format and provide the machine-readable report to the auditor and management for approval before publication. ESG compliance is thus transformed from a one-off mandatory reporting exercise into an ongoing process that is continuously updated between reporting dates and is meaningful at any time in the audit.

FAQ

What does the DWS case have to do with ESG compliance in my company?

The DWS case is a lesson for every company with ESG statements, not just fund managers. Advertising with climate neutrality, ESG clauses in contracts, sustainability information in the annual report or on the website must be verifiable through documented processes, data and controls. Where there is a discrepancy between statements and operational reality, there is a risk of official proceedings, warnings under competition law, claims for damages and reputational damage that significantly exceed the original marketing advantage.

Is my company required to report on CSRD?

The CSRD covers staggered data: from the 2024 financial year, large companies with a previous NFE obligation, from 2025, other large companies (thresholds: 250 employees, 25 million euros in total assets, 50 million euros in sales), from 2026, listed SMEs. The EU Omnibus Initiative 2025 has postponed parts. Those who are not directly required to report may be indirectly affected by supply chain requirements and should clarify the status.

Do I have to appoint an ESG representative?

There is no mandatory legal obligation to appoint a data protection officer, as is the case with the data protection officer. But anyone who is required to report on CSRD, applies LkSG or makes ESG statements in advertising and contracts needs clear accountability. Appointing an ESG/sustainability officer with an appointment document, catalogue of duties and reporting line to management is best practice and provides strong evidence of proper governance in the audit. External mandates via CIVAC expire in 2 working days.

How does limited assurance differ from a financial audit?

In the case of limited assurance, the auditor examines with reduced depth and comes to a negatively worded statement (there are no indications that the report does not comply with the ESRS). A financial audit is a reasonable assurance with a positive statement. ISAE 3000 and, from 2026, ISSA 5000 form the framework. In the future, the audit requirements will develop towards reasonable assurance.

How quickly does CIVAC set up an ESG compliance structure?

The ESG representative will be appointed within 2 working days. The double materiality analysis, the ESG data catalogue and the ESG statement register will be set up in the first month, and the training for the specialist departments will be set up in the second month. An internal trial audit takes place in the third month so that the company is ready to work with sufficient lead time before the first external audit cycle and gaps can be closed before the auditor.

Are ESG data and workspace content stored in a GDPR-compliant manner?

Yes, the CIVAC workspace is operated in a data centre with EU data residency, the ISMS follows ISO/IEC 27001:2022 with 93 controls. Personal ESG data such as diversity metrics or accident statistics are documented in the processing directory, and order processing contracts are available. Accesses are logged, retention periods can be configured and audited according to legal requirements, so that GDPR inquiries can also be answered smoothly.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles