What officers need to know.
Regulatory shifts, framework updates and operational guidance, curated for Data Protection, IT Security, Compliance and AI Governance leads. Written from the field, verified against primary sources.
External occupational safety service provider in comparison: selection without gut feeling
Seven criteria with which you can reliably compare external occupational safety service providers: operating times according to DGUV regulation 2, qualifications, accessibility, documentation and SLA. Including decision matrix, tender text and instructions for the appointment certificate.
Risk assessment for psychological stress: template, obligations and procedure
Section 5 Paragraph 3 No. 6 ArbSchG has required the assessment of psychological stress in the workplace since 2013. This guide shows obligations, an audit-proof template structure and how CIVAC documents the assessment with the occupational safety specialist in an audit-proof manner.
Classify hazardous substances according to GHS and CLP: classification, labelling, evidence
Hazardous substance classification according to GHS and CLP is mandatory for every manufacturer, importer and downstream user. This guide shows the classification logic, labelling elements and when an external hazardous materials officer provides audit assurance.
Whistleblower Hotline Provider in Germany: How to Pick an English-Capable Reporting Channel
German subsidiaries with 50 or more employees must run a confidential reporting channel under HinSchG. International groups need an English-capable provider that also meets BfJ supervision. This guide explains the legal floor, the must-have features, and how CIVAC delivers both.
Annual instruction on hazardous substances: mandatory, content and sample documentation
Section 14 GefStoffV requires workplace and activity-related hazardous substance instruction at least once a year. This article provides obligations, minimum content and sample documentation.
Create an explosion protection document: template and obligations according to the Industrial Safety Ordinance 2026
The explosion protection document according to § 6 BetrSichV is mandatory for every employer with dangerous, explosive atmospheres. This article provides the legally secure structure, the TRGS references and the practical template for the hazardous substances officer.
Water protection officer according to Section 64 WHG: Duties, appointment and service provider models
The Water Resources Act obliges system operators to appoint a water protection officer as soon as the threshold of Section 64 WHG is exceeded. This guide explains the duties, the areas of responsibility and the options between internal and external appointments.
Water protection officer: From what quantity is the order mandatory?
Section 64 WHG obliges operators of certain systems to appoint a water protection officer. The threshold values do not relate directly to a quantity of water, but rather to discharge quantities or system types. This guide clarifies the threshold values precisely and shows the operational implementation.
Anti-Money Laundering Officer in Germany: Finance and Real Estate Compliance Without Gaps
Banks, asset managers, and real estate firms in Germany must appoint an AML officer under § 7 GwG. This guide explains scope, liability, and how CIVAC operates the role end-to-end.
Environmental Management Officer Germany: Services, Statutory Roles, and Outsourcing
Germany requires several statutory environmental officers, each anchored in a different federal act. We outline the roles, the appointment process, the typical service models, and how to use a workspace-plus-officer-as-a-service approach to close gaps within two business days.
Dangerous Goods Labelling under ADR 2025: Symbols, Duties, Responsibilities
Dangerous goods labelling follows ADR Chapter 5.2 and 5.3. We show which symbols are mandatory, who must apply them, how the dangerous goods safety advisor keeps the records, and what fines apply for mistakes.
Building an ISO 14001 environmental management system: PDCA, HLS and certification in twelve steps
Building an ISO 14001 environmental management system requires a clear sequence of context analysis, environmental aspects, processes and PDCA cycle. This article describes the procedure in twelve steps and classifies the role of the environmental officer in the system.
Environmental protection officer: when is the appointment mandatory?
The collective term environmental protection officer includes several legally regulated functions in Germany. Who is subject to an order requirement depends on the type of system, quantity of material and process. This article organises the obligations and shows when an external solution makes sense.
LkSG audit and BAFA report form: How to fill out the mandatory 2026 report in an audit-proof manner
The LkSG report to BAFA includes over 400 mandatory pieces of information. We show you how to fill out the report form step by step in an audit-proof manner, which documents need to be kept and how the compliance platform and officer-as-a-service CIVAC shortens the process to two working days.
LkSG representative: Duties, appointment and report to BAFA
Since 2024, the Supply Chain Due Diligence Act (LkSG) has required companies with 1,000 or more employees to have risk management along the supply chain, a designated responsible person and an annual report to BAFA. Fines range up to 800,000 euros plus a procurement ban.
Supply Chain Act Compliance in Germany: A Practical Guide for International Companies
The German LkSG has applied to companies with 1,000 or more employees since 2024 and demands a documented risk analysis, a complaints mechanism, and an annual BAFA report. This guide explains what international groups must operationalise to remain audit-ready.
Human rights officer according to Section 4 LkSG: tasks, appointment and reporting obligation
Section 4 (3) of the Supply Chain Due Diligence Act requires the appointment of a person responsible for monitoring risk management. Find out what tasks the human rights officer has, how the appointment is documented and how a Workspace bundles BAFA report, risk analysis and complaint procedures in one source.
Patch management process NIS-2 compliant: SLA, roles, evidence
Art. 21 NIS-2 requires an effective patching and vulnerability process. Find out which SLA windows authorities expect, how patch cycles interlink with ISO/IEC 27001:2022 Annex A 8.8 and what evidence the ISB must provide during the first BSI audit.
External ISB: When the information security officer is worthwhile as a service
An external information security officer closes a gap that many companies only notice during the NIS 2 audit. This article shows when ordering externally is faster, cheaper and more audit-proof than an internal solution.
NIS-2 for SMEs: Threshold, exceptions and the operational path for SMEs
Not every SME is affected by NIS 2, but the threshold of 50 employees and 10 million euros in annual sales already applies to medium-sized businesses in eleven sensitive sectors. This analysis organises sectors, obligations, deadlines and operational implementation with CIVAC.
Is My Company in Scope for NIS-2 in Germany? A Practical Test
Germany transposes Directive (EU) 2022/2555 (NIS-2) via the NIS2UmsuCG. Approximately 29,500 entities are estimated in scope, far more than the previous KRITIS regime. This guide walks you through a three-step scoping test: sector annex, size threshold and supply-chain exception, with documentation requirements for officers.

AGG Complaints Office: How to Meet the Posting Obligation
Announcing the AGG Complaints Office is mandatory under Section 12(5) AGG. Learn how to legally implement this posting obligation in your company.

AGG Complaints Office: Confidentiality and Protection (§ 13 AGG)
Learn how to implement the AGG Complaints Office in a legally secure manner: Everything on confidentiality, § 13 AGG, and the Whistleblower Protection Act.

Handling AGG Complaints: Processes under § 13 AGG
Learn how to process AGG complaints under § 13 in a legally compliant manner. A guide to operational case management, deadlines, and documentation.