What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
ISO 27001 internal audit: checklist, template and process for the entire ISMS
The internal audit is a mandatory part of every ISMS according to ISO/IEC 27001:2022. The frequent question about a PDF checklist shortens the requirement. The article provides structure, questions per Annex A chapter and a flowchart that holds up in the recertification audit.
ISO 27001:2022 Transition in Germany: What the October 2025 Deadline Means in 2026
The official transition window from ISO/IEC 27001:2013 to the 2022 edition closed on 31 October 2025. Certificates not migrated have expired. This article explains what that means for German organisations in 2026, what auditors now expect, and how to recover lost certification without a multi-quarter delay.
ISO 27001 consulting in Germany 2026: hourly rates, daily rates and realistic project costs
Hourly rates for ISO 27001 consulting in Germany in 2026 will be between 140 and 320 euros net, daily rates between 1,200 and 2,400 euros. We show what drives the price and when a platform-plus-officer model remains below the hourly rate.
ISMS software 2026: selection criteria, obligations and EU data residency
ISMS software is more than a document archive: It operationalizes 93 controls according to ISO 27001:2022, documents the 24/72 reporting path according to NIS-2 and provides audit templates. What a resilient platform does and what buyers need to pay attention to in 2026.
ISO 27001:2022 Transition: What exactly is changing and how you can follow suit
The transition from ISO/IEC 27001:2013 to 27001:2022 runs until October 2026. This article explains the structural changes, the eleven new controls and the operational consequences for ISB, risk management and audit planning.
Generation ESG: How the next generation of representatives anchors sustainability operationally
ESG is changing from a reporting exercise to an operational compliance role. This article shows how the ESG generation is structured, which obligations apply and how you can organise the function properly.
Vanguard All-World ESG: What the ETF term means for ESG obligations in the company
Anyone looking for Vanguard All-World ESG usually ends up with the FTSE All-World ESG ETF. But there is a much bigger question behind this: What ESG obligations apply to my company in 2026, who has to report and who is liable? This article organises the ETF term, SFDR classification and CSRD obligations in an overview.
ESG funds at Union Investment: What companies should know about the selection criteria
Union Investment's ESG funds are subject to clear regulatory requirements from the SFDR, EU taxonomy and MiFID II suitability test. This article explains the criteria and classifies them for ESG managers in companies.
Vanguard Global All Cap ESG: What index exclusions mean for your corporate ESG
ESG index funds filter out thousands of stocks every year. Anyone who is excluded as a company loses access to capital. This article shows which criteria apply and how an ESG officer sets up the data and reporting line that keeps you in the index.
Vanguard ESG Emerging Markets All Cap: What compliance can learn from it
Vanguard's emerging markets ESG ETF excludes around 1,200 companies for ESG violations. The article explains the screen logic, assigns it to ESRS and LkSG and shows how you can make the process usable for your ESG officer.
Vanguard FTSE All-World ESG: What the index approach means for your ESG compliance
The Vanguard FTSE All-World ESG follows an exclusion-based ESG index approach. This article explains the methodology, classifies it in the European regulatory environment according to CSRD, ESRS and SFDR and shows what obligations this creates for companies whose data is included in such indices.
ESG and SRI: Difference, reporting obligations and the ESG officer
ESG and SRI are often confused, but are different concepts. We explain the definitions, the CSRD obligations according to Directive 2022/2464, the role of the ESG officer and the ordering process via the CIVAC Compliance platform and Officer-as-a-Service.
ESG sustainability criteria: obligations, ESRS and operational implementation
ESG sustainability criteria are no longer marketing, but rather measurable obligations from CSRD, ESRS and the Taxonomy Regulation. This guide explains the relevant criteria, double materiality and how to document operational implementation in a resilient workspace.
Compliance Officer as a Service in medium-sized companies: prices, models, hourly rates
Compliance Officer as a Service replaces the internal full-time position. We show what medium-sized companies will pay in 2026, which services must be included in the price and how you can recognise an audit-proof provider. No estimates, no marketing.
Compliance tool for corporations with subsidiaries: multi-client capable, audit-proof, EU sovereign
Corporations with two to fifty subsidiaries need a single tool that separates per client and consolidates per group. This article explains the requirements of Section 130 OWiG, Art. 26 GDPR and ISO/IEC 27001:2022 and how CIVAC maps them in a platform.
Compliance Training Platform for Multi-Role German Operations: A Buyer's Guide
A German mid-cap typically operates 8 to 12 statutory officer roles in parallel: DPO, ISO, fire safety, hazardous goods, hygiene, ESG, whistleblower, and more. A multi-role compliance training platform consolidates curricula, evidence, and audit exports into one system of record.
Officer-as-a-Service in Germany: How External Compliance Roles Actually Work
Officer-as-a-Service in Germany means appointing an external person to a statutory officer role under German law, with a written appointment letter, defined reporting line and documented duties. This guide explains the legal basis, the appointment workflow and the operational reality.
CIVAC Demo: From filing cabinet to audit-proof platform in 45 minutes
A CIVAC demo is not a sales pitch, but a technical tour. In 45 minutes you will see the workspace, audit templates, appointment certificate and reporting line using a specific representative example from your company.
AI-powered compliance software for training: What counts, what doesn't
What are the requirements for AI-supported compliance training? How do you differentiate marketing from robust technology? And what evidence does the platform have to provide in order for the training to pass the audit? A methodical guide for DPOs, COs and management.
Drafting engine for compliance reports: templates, logic, audit trail
A drafting engine doesn't write reports, it structures them. We show how 37 audit templates, parameterized clause libraries and a versioned processing directory turn days of work into hours and why the author still draws personally in the end.
Gastronomy and hygiene products: selection, documentation and HACCP compliance
Cleaning agents, disinfectants, pest monitoring and disposable hygiene are not a procurement issue, but a compliance issue. This guide shows which hygiene products LMHV and HACCP require in the catering industry and how they can be documented in an audit-proof manner.
Guideline for applied hygiene in dialysis: What facilities must check
Hygiene in dialysis follows KRINKO recommendations, IfSG and MPBetreibV. What the hygiene plan must cover, who manages it and how the hygiene officer ensures proof.
Hygiene in the kitchen workplace: duties, HACCP and the auditable hygiene plan
Hygiene in the kitchen workplace is not just a question of cleanliness, but a documented obligation according to LMHV, VO (EG) 852/2004 and IFSG. The article shows what evidence a food inspection expects and how the hygiene plan holds up reliably in the audit.
Institute for Medical Microbiology and Hygiene: Tasks, interfaces, representative duties
Microbiological institutes are the silent early warning system for patient safety. Anyone who translates findings into clinical processes in a timely manner prevents outbreaks. This article explains tasks, reporting channels according to Section 7 IfSG and the role of the hygiene officer.