77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
The Pflichten-Check: four profile fields, three levels, one statute per role, and what the indication does not decide
Platform & Strategy

The Pflichten-Check: four profile fields, three levels, one statute per role, and what the indication does not decide

16 September 20268 min readBy CIVAC Redaktion
CIVAC

The Pflichten-Check in CIVAC matches the company profile against the role catalogue and returns one finding per role: mandatory, recommended or monitor, with the statute, the profile fact that triggers the duty, and a next step. This article describes which four fields go in, how a finding is structured, what the traffic light at the end means, and why the result is only as good as the profile.

Key takeaways

  • The input is the company profile from the setup wizard, not a questionnaire at the moment of the check. Whoever filled in the profile roughly when setting up gets a rough indication; the check does not ask follow-up questions.
  • The severities are bound to three classes in the instruction to the model: critical and high mean mandatory, medium means recommended, low and info mean optional or monitor. The class therefore sits in the severity, not in a field of its own.
  • Every finding names the specific legal basis and the profile fact that triggers the duty. A finding without a statute is not provided for in the schema; a finding whose trigger is not in the profile is a reason to check the profile.
  • The traffic light at the end rates not the company but the assessment: green means the profile supported the assessment, red means it did not. If the traffic light is missing from the answer, the system sets amber.
  • A headcount in the profile is not the same as the counting unit a statute uses. Where an act refers to regularly employed persons, to employees per legal entity or to persons engaged in a particular activity, the check can only be as precise as the profile, and the profile has exactly one field for it.
  • CIVAC is not a law firm. The check is a risk and duty indication, as its instruction states. Whether an appointment duty exists in the specific case is decided by the company, with a law firm where in doubt.

What goes in: four fields, no questions

On the interface the check has only one parameter, the output language. Everything else comes from the organisation's profile, created when the workspace was set up: industry, headcount, country and a free-text context in which the company describes what it does. The instruction to the model is unambiguous on this point: assess solely on the basis of the company profile. The check asks no follow-up questions and reads no documents. That has a consequence worth knowing before the first run: the result cannot be better than the four fields. An industry chosen as Other at setup, an estimated headcount and an empty context yield an indication that mostly reflects what applies to every company of that size.

How a finding is structured

The output is a fixed schema: a summary, a list of findings and a traffic light. Every finding carries a role key from the platform's catalogue, so that it refers to a role page and to a bookable role, a title, a severity from five values, a category, the legal basis as a statute citation, the profile fact that triggers the duty, and a recommendation as the next step, for instance the appointment of a particular role. Required fields are title, severity, category, legal basis and recommendation; the role key and the triggering fact are optional, but the instruction requires every finding to be mapped to a role and to cite the specific statute.

The three classes the check distinguishes are not in a field of their own but in the severity. The instruction lays down: critical and high for roles that are mandatory; medium for roles that are recommended; low and info for roles that are optional or should be monitored. Whoever reads the list therefore sorts by severity and obtains the sort by bindingness. A finding rated medium is not a weak mandatory finding but a recommendation.

The triggering fact: the part worth checking

The most useful field in a finding is the fact that triggers the duty. It is meant to name the fact from the profile to which the statute attaches: the headcount, the industry, an activity named in the context. Against it every finding can be checked in seconds. Is the trigger actually in the profile, and is it correct? If the finding names an activity the company does not carry out, either the context is worded ambiguously or the model has inferred more from the industry than the profile supports. In both cases the correction is not the finding but the profile, followed by a new run.

The traffic light at the end rates the assessment, not the company

Beside the findings the check returns a traffic light, green, amber or red. It is easy to misread. It does not say how well the company is positioned but how reliable the assessment is that the model could draw from this profile. Green means the four fields supported the assessment. Red means they did not, for instance because industry and context contradict each other or because the decisive details are missing. If the traffic light is missing from the model's answer, the system sets amber. A red light above a list with five mandatory findings is therefore not an alarm about five duties but the note to complete the profile before the list is taken seriously.

Why the headcount is not the counting unit of the statutes

The profile has one field for the company's size. The statutes that trigger appointment duties count differently: some count regularly employed persons, some employees per legal entity, some persons engaged in a particular activity, some domestic employees across affiliated companies. A group with three companies of forty employees each has either forty or one hundred and twenty in the profile, and for some statutes both figures lead to a different result than the actual structure. The check can make that distinction only if it is in the context. That is why the context should hold what the number field cannot: the number of legal entities, sites, whether employees regularly work with personal data or with hazardous substances, whether consumers are supplied. Each of those sentences changes which triggers the model can recognise.

What the check is not

The instruction to the model opens with the legal framing: the check gives a risk and duty indication citing the relevant statute, not a legally binding assessment, and phrases findings as indications. CIVAC is not a law firm. Whether an appointment duty exists in the specific case, which person is suitable and whether an exemption applies is decided by the company, with a law firm where in doubt. The check is also not a free pre-sales tool: it requires active access for the organisation and runs behind a cost budget and rate limiting, like the workspace's other assessment functions. And it is a language model under an instruction, not a rule engine with a threshold table; two runs over the same profile can differ in wording and order. The triggering fact per finding is what keeps the list verifiable regardless.

How to use the check sensibly

Profile first, then the run. Industry as precise as possible, headcount as the actual figure, and in the context the sentences that concern the statutes' counting units: legal entities, sites, activities, customer groups. Then read the findings by severity, hold each triggering fact against the profile, and take the mandatory findings as the list of roles for which a decision on appointment is due. The decision itself, internal or external, which person, with what expertise, is the next step and not part of the check.

Which details does the Pflichten-Check use?

Four, from the organisation's profile: industry, headcount, country and the free-text context. The check asks no follow-up questions and reads no documents. The instruction requires assessment solely on the basis of those details.

What do mandatory, recommended and monitor mean in the result?

The three classes sit in the severity of each finding: critical and high for mandatory, medium for recommended, low and info for optional or monitor. Sorted by severity, the list is sorted by bindingness.

What does the traffic light at the end say?

The reliability of the assessment, not the state of the company. Green: the profile supported the assessment. Red: it did not, usually because details are missing or contradict each other. Amber is also the value the system sets if the model supplies no traffic light.

Is a mandatory finding a legal determination?

No. Every finding is a duty indication with a statute citation and a triggering fact; that is fixed in the check's instruction. Whether an appointment duty exists in the specific case is decided by the company, with a law firm where in doubt; CIVAC is not one.

Can I use the check before signing a contract?

No. The check requires active access for the organisation. For orientation before signing, the role pages and the tool on appointment duties on the website are available.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles