What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
ISSESG decoded: ISSB, ESRS and the ESG representative in German medium-sized companies
ISSESG brings together three worlds: ISSB IFRS S1/S2, ESRS according to CSRD and operational ESG responsibility in the company. Find out which obligations apply to German medium-sized companies from 2025, which data must be provided and how a workspace reflects the ESG reporting requirement without Excel sprawl.
GDPR, NIS-2 and ISO 27001 on One Platform: The German Compliance Stack
Three regulations, one workspace. This briefing explains why GDPR, NIS-2 and ISO/IEC 27001:2022 share 60 percent of their controls, how a unified platform cuts documentation effort by half, and what German enterprises should require before signing any vendor contract.
Compliance Automation: From filing cabinets to verifiable software
Compliance Automation replaces file folders and isolated solutions with a tested platform. This article shows which obligations can be automated, what limits are set by law and supervision and how you can recognise an audit-proof solution.
DataGuard, another provider, OTRIS and CIVAC in comparison: Compliance platforms 2026
DataGuard, another provider and OTRIS each address a part of the German compliance reality: tool, service or file archive. This comparison ranks 14 criteria from role appointment to NIS 2 reporting path and shows where CIVAC comes in as a compliance platform and officer-as-a-service.
AI-Driven Drafting Engine for Compliance Reports: Practical Guide for German Operations
Compliance reports under GDPR Art. 33, NIS-2 24h/72h notifications and ISO/IEC 27001:2022 audits share a structural pattern. An AI-driven drafting engine accelerates the first 70 percent of the text, while officers retain accountability for review, sign-off and submission.
Compliance training platform: What distinguishes mandatory training from a click course
A compliance training platform needs to do more than play videos. Supervisors and courts require participation, understanding, repetition and evidence that is still reliable three years after the incident. This post shows how you can recognise this.
Compliance platform for medium-sized companies in the DACH region: selection criteria and evaluation grid
Medium-sized companies in the DACH region face 25 representative obligations, NIS-2, ISO 27001:2022 and LkSG. This comparison uses seven evaluation criteria and ranks CIVAC, classic GRC tools and filing cabinet solutions along these axes.
Create AI training based on roles: AI Act, GDPR and obligation to provide evidence
Since February 2, 2025, Art. 4 AI Act requires operators and providers to have sufficient AI competence. Anyone who does not structure training in a role-based, documented and GDPR-compliant manner risks fines and supervisory orders. This guide shows the structure.
§ 26 BDSG: Implement employee data protection correctly and document it in an audit-proof manner
Section 26 BDSG regulates employee data protection in the employment relationship. We explain the permissible purposes, the consent requirements, the limits when solving crimes and how you can document the implementation in the CIVAC workspace in an audit-proof manner.
Hygiene in the doctor's office: The practical guide 2026
Hygiene in the doctor's office needs a plan, representatives and evidence. This guide shows how you can document the 2026 RKI recommendations, IfSG, MedHygVO and appointment certificate in an audit-proof manner, who takes on which role and how the effort can be sensibly bundled per quarter.
Understanding KRINKO: Recommendations, commitment and obligations for institutions
The KRINKO at the RKI publishes the relevant recommendations on hospital hygiene. Anyone who ignores them risks liability and fines according to IfSG. This guide classifies mission, liability and operational duties.
Hygiene in the school kitchen: Obligations, HACCP and the path to a reliable hygiene plan
School kitchens are subject to food hygiene regulations, IfSG instructions and HACCP. Anyone who looks after children must take extra care. We show the hygiene plan, the instructional obligations and the role of the hygiene officer in a practical way.
Hygiene in the doctor's office: The reliable checklist for the inspection
The reliable hygiene checklist for private practices, MVZs and day clinics: 9 areas, reference to paragraphs, clear responsibilities and a procedure that will survive the next inspection by the health department without any complaints.
Hygienic hand disinfection according to RKI: indications, obligations and evidence
Hygienic hand disinfection is the single most effective measure against nosocomial infections. This article describes the five RKI indications, the KRINKO recommendation, the hygiene officer's documentation obligation and how CIVAC maps the entire evidence in an audit-proof manner.
Hygiene training for catering: Implement IfSG, LMHV and HACCP in a legally binding manner
Hygiene training for the catering industry is not a marketing topic, but is mandatory according to IfSG, LMHV and VO (EC) No. 852/2004. This guide shows content, frequency and evidence and when an external hygiene officer is more economical.
AI-Powered Compliance Software in Germany: Capability Map for 2026 Procurement
AI-powered compliance software promises faster audits, leaner officer teams, and continuous control monitoring. Under the EU AI Act (Regulation (EU) 2024/1689) and NIS-2, the German market now also expects evidence of safe AI use inside the tool itself. This guide gives you the capability map and the procurement checklist.
Hygiene in hospitals: obligations, KRINKO recommendations and governance
Hygiene in hospitals is legally regulated by Section 23 IfSG and the recommendations of KRINKO at the RKI. This article bundles duties, roles, hygiene plan and verifiable documentation.
Hygiene specialist: tasks, qualifications and distinction from a hygiene officer
The hygiene specialist (HFK) has been an integral part of hospital hygiene since Section 23 IfSG. This article clarifies qualifications, tasks, number guidelines and the clear demarcation between hygiene officers and hospital hygienists.
Hygiene officer: tasks, duties and appointment according to IfSG and KRINKO
A hygiene officer is more than a training formality. We show the legal anchors, the operational tasks, the interfaces to the company doctor and ABS team and how you can manage orders, hygiene plans and audit evidence in one system.
External Compliance Officer in Germany: A Practical Guide for Foreign Subsidiaries
German law does not require a single statutory Compliance Officer role, yet § 130 OWiG, § 130 LkSG, the HinSchG and supervisory expectations create de facto staffing duties. This guide explains when an external officer is the right choice and what a defensible contract looks like.
EU AI Act Compliance: Obligations, Risk Tiers, and Operational Playbook
The EU Artificial Intelligence Act entered into force on 1 August 2024 with staggered application dates running to August 2027. This guide explains the risk-based regime, the obligations for providers and deployers, and the operational steps that make AI Act compliance audit-ready.
CMS obligation: When a compliance management system becomes legally mandatory
A compliance management system is not prescribed in a single law, but results from Section 130 OWiG, the BGH case law and a large number of special laws. This article classifies from what size and in which sectors the obligation applies.
Compliance officer is mandatory for how many employees? The legal situation in 2026
There is no fixed number of employees in the law. What triggers the obligation is a combination of size, industry, risk and company structure. This article explains the legal situation and shows when a compliance officer in medium-sized companies becomes useful and actually mandatory.
Conducting compliance risk analysis: template, method and assessment
Compliance risk analyses are required by IDW PS 980, ISO 37301 and § 130 OWiG. Read how to identify, assess, document and convert risks into a test-proof template that passes an audit.