77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
News & Insights

What officers need to know.

Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.

Latest
ISSESG decoded: ISSB, ESRS and the ESG representative in German medium-sized companies
ESG & Sustainability6 August 202613 min read

ISSESG decoded: ISSB, ESRS and the ESG representative in German medium-sized companies

ISSESG brings together three worlds: ISSB IFRS S1/S2, ESRS according to CSRD and operational ESG responsibility in the company. Find out which obligations apply to German medium-sized companies from 2025, which data must be provided and how a workspace reflects the ESG reporting requirement without Excel sprawl.

Read more
GDPR, NIS-2 and ISO 27001 on One Platform: The German Compliance Stack
Platform & Strategy6 August 202614 min read

GDPR, NIS-2 and ISO 27001 on One Platform: The German Compliance Stack

Three regulations, one workspace. This briefing explains why GDPR, NIS-2 and ISO/IEC 27001:2022 share 60 percent of their controls, how a unified platform cuts documentation effort by half, and what German enterprises should require before signing any vendor contract.

Read more
Compliance Automation: From filing cabinets to verifiable software
Platform & Strategy6 August 202613 min read

Compliance Automation: From filing cabinets to verifiable software

Compliance Automation replaces file folders and isolated solutions with a tested platform. This article shows which obligations can be automated, what limits are set by law and supervision and how you can recognise an audit-proof solution.

Read more
DataGuard, another provider, OTRIS and CIVAC in comparison: Compliance platforms 2026
Platform & Strategy6 August 202614 min read

DataGuard, another provider, OTRIS and CIVAC in comparison: Compliance platforms 2026

DataGuard, another provider and OTRIS each address a part of the German compliance reality: tool, service or file archive. This comparison ranks 14 criteria from role appointment to NIS 2 reporting path and shows where CIVAC comes in as a compliance platform and officer-as-a-service.

Read more
AI-Driven Drafting Engine for Compliance Reports: Practical Guide for German Operations
Platform & Strategy6 August 202612 min read

AI-Driven Drafting Engine for Compliance Reports: Practical Guide for German Operations

Compliance reports under GDPR Art. 33, NIS-2 24h/72h notifications and ISO/IEC 27001:2022 audits share a structural pattern. An AI-driven drafting engine accelerates the first 70 percent of the text, while officers retain accountability for review, sign-off and submission.

Read more
Compliance training platform: What distinguishes mandatory training from a click course
Platform & Strategy5 August 202612 min read

Compliance training platform: What distinguishes mandatory training from a click course

A compliance training platform needs to do more than play videos. Supervisors and courts require participation, understanding, repetition and evidence that is still reliable three years after the incident. This post shows how you can recognise this.

Read more
Compliance platform for medium-sized companies in the DACH region: selection criteria and evaluation grid
Platform & Strategy5 August 202613 min read

Compliance platform for medium-sized companies in the DACH region: selection criteria and evaluation grid

Medium-sized companies in the DACH region face 25 representative obligations, NIS-2, ISO 27001:2022 and LkSG. This comparison uses seven evaluation criteria and ranks CIVAC, classic GRC tools and filing cabinet solutions along these axes.

Read more
Create AI training based on roles: AI Act, GDPR and obligation to provide evidence
Platform & Strategy5 August 202613 min read

Create AI training based on roles: AI Act, GDPR and obligation to provide evidence

Since February 2, 2025, Art. 4 AI Act requires operators and providers to have sufficient AI competence. Anyone who does not structure training in a role-based, documented and GDPR-compliant manner risks fines and supervisory orders. This guide shows the structure.

Read more
§ 26 BDSG: Implement employee data protection correctly and document it in an audit-proof manner
Platform & Strategy5 August 202612 min read

§ 26 BDSG: Implement employee data protection correctly and document it in an audit-proof manner

Section 26 BDSG regulates employee data protection in the employment relationship. We explain the permissible purposes, the consent requirements, the limits when solving crimes and how you can document the implementation in the CIVAC workspace in an audit-proof manner.

Read more
Hygiene in the doctor's office: The practical guide 2026
Health & Hygiene5 August 202612 min read

Hygiene in the doctor's office: The practical guide 2026

Hygiene in the doctor's office needs a plan, representatives and evidence. This guide shows how you can document the 2026 RKI recommendations, IfSG, MedHygVO and appointment certificate in an audit-proof manner, who takes on which role and how the effort can be sensibly bundled per quarter.

Read more
Understanding KRINKO: Recommendations, commitment and obligations for institutions
Health & Hygiene4 August 202612 min read

Understanding KRINKO: Recommendations, commitment and obligations for institutions

The KRINKO at the RKI publishes the relevant recommendations on hospital hygiene. Anyone who ignores them risks liability and fines according to IfSG. This guide classifies mission, liability and operational duties.

Read more
Hygiene in the school kitchen: Obligations, HACCP and the path to a reliable hygiene plan
Health & Hygiene4 August 202612 min read

Hygiene in the school kitchen: Obligations, HACCP and the path to a reliable hygiene plan

School kitchens are subject to food hygiene regulations, IfSG instructions and HACCP. Anyone who looks after children must take extra care. We show the hygiene plan, the instructional obligations and the role of the hygiene officer in a practical way.

Read more
Hygiene in the doctor's office: The reliable checklist for the inspection
Health & Hygiene4 August 202612 min read

Hygiene in the doctor's office: The reliable checklist for the inspection

The reliable hygiene checklist for private practices, MVZs and day clinics: 9 areas, reference to paragraphs, clear responsibilities and a procedure that will survive the next inspection by the health department without any complaints.

Read more
Hygienic hand disinfection according to RKI: indications, obligations and evidence
Health & Hygiene4 August 202612 min read

Hygienic hand disinfection according to RKI: indications, obligations and evidence

Hygienic hand disinfection is the single most effective measure against nosocomial infections. This article describes the five RKI indications, the KRINKO recommendation, the hygiene officer's documentation obligation and how CIVAC maps the entire evidence in an audit-proof manner.

Read more
Hygiene training for catering: Implement IfSG, LMHV and HACCP in a legally binding manner
Health & Hygiene4 August 202612 min read

Hygiene training for catering: Implement IfSG, LMHV and HACCP in a legally binding manner

Hygiene training for the catering industry is not a marketing topic, but is mandatory according to IfSG, LMHV and VO (EC) No. 852/2004. This guide shows content, frequency and evidence and when an external hygiene officer is more economical.

Read more
AI-Powered Compliance Software in Germany: Capability Map for 2026 Procurement
Plattform & Strategie4 August 202613 min read

AI-Powered Compliance Software in Germany: Capability Map for 2026 Procurement

AI-powered compliance software promises faster audits, leaner officer teams, and continuous control monitoring. Under the EU AI Act (Regulation (EU) 2024/1689) and NIS-2, the German market now also expects evidence of safe AI use inside the tool itself. This guide gives you the capability map and the procurement checklist.

Read more
Hygiene in hospitals: obligations, KRINKO recommendations and governance
Health & Hygiene3 August 202613 min read

Hygiene in hospitals: obligations, KRINKO recommendations and governance

Hygiene in hospitals is legally regulated by Section 23 IfSG and the recommendations of KRINKO at the RKI. This article bundles duties, roles, hygiene plan and verifiable documentation.

Read more
Hygiene specialist: tasks, qualifications and distinction from a hygiene officer
Health & Hygiene3 August 202612 min read

Hygiene specialist: tasks, qualifications and distinction from a hygiene officer

The hygiene specialist (HFK) has been an integral part of hospital hygiene since Section 23 IfSG. This article clarifies qualifications, tasks, number guidelines and the clear demarcation between hygiene officers and hospital hygienists.

Read more
Hygiene officer: tasks, duties and appointment according to IfSG and KRINKO
Health & Hygiene3 August 202612 min read

Hygiene officer: tasks, duties and appointment according to IfSG and KRINKO

A hygiene officer is more than a training formality. We show the legal anchors, the operational tasks, the interfaces to the company doctor and ABS team and how you can manage orders, hygiene plans and audit evidence in one system.

Read more
External Compliance Officer in Germany: A Practical Guide for Foreign Subsidiaries
Governance & Compliance3 August 202614 min read

External Compliance Officer in Germany: A Practical Guide for Foreign Subsidiaries

German law does not require a single statutory Compliance Officer role, yet § 130 OWiG, § 130 LkSG, the HinSchG and supervisory expectations create de facto staffing duties. This guide explains when an external officer is the right choice and what a defensible contract looks like.

Read more
EU AI Act Compliance: Obligations, Risk Tiers, and Operational Playbook
Governance & Compliance3 August 202613 min read

EU AI Act Compliance: Obligations, Risk Tiers, and Operational Playbook

The EU Artificial Intelligence Act entered into force on 1 August 2024 with staggered application dates running to August 2027. This guide explains the risk-based regime, the obligations for providers and deployers, and the operational steps that make AI Act compliance audit-ready.

Read more
CMS obligation: When a compliance management system becomes legally mandatory
Governance & Compliance2 August 202613 min read

CMS obligation: When a compliance management system becomes legally mandatory

A compliance management system is not prescribed in a single law, but results from Section 130 OWiG, the BGH case law and a large number of special laws. This article classifies from what size and in which sectors the obligation applies.

Read more
Compliance officer is mandatory for how many employees? The legal situation in 2026
Governance & Compliance2 August 202613 min read

Compliance officer is mandatory for how many employees? The legal situation in 2026

There is no fixed number of employees in the law. What triggers the obligation is a combination of size, industry, risk and company structure. This article explains the legal situation and shows when a compliance officer in medium-sized companies becomes useful and actually mandatory.

Read more
Conducting compliance risk analysis: template, method and assessment
Governance & Compliance2 August 202613 min read

Conducting compliance risk analysis: template, method and assessment

Compliance risk analyses are required by IDW PS 980, ISO 37301 and § 130 OWiG. Read how to identify, assess, document and convert risks into a test-proof template that passes an audit.

Read more