Compliance Management System (CMS)

A compliance management system (CMS) is the whole set of principles, responsibilities and controls with which a company ensures, monitors and evidences observance of the rules that apply to it. In Germany a CMS is not generally prescribed, but it is the yardstick for whether management discharged its duty of supervision.

GRCLast reviewed:

Two audiences, two kinds of proof

A compliance management system is the same thing everywhere: a control loop that answers three questions durably and demonstrably. Which rules apply to us? What do we do so that they are kept? How do we know it is working?

What differs between markets is who reads the proof. In Germany the audience is a supervisory board, an insurer, a prosecutor or a court, and the artefact they recognise is an auditor's attestation under IDW PS 980. Outside Germany the audience is more often a customer or a parent company, and the artefact they recognise is an ISO 37301 certificate. A group operating in both places is not choosing between two levels of quality. It is choosing between two readerships, and it can serve both from one system.

Why the system matters where it is not required

For most German companies a CMS is not expressly prescribed. It becomes the yardstick as soon as something goes wrong: against it is measured whether management discharged its duty of organisation and supervision. The Federal Court of Justice recognised this expressly in its judgment of 9 May 2017 (1 StR 265/16): in assessing a corporate fine under § 30 of the German Act on Regulatory Offences (OWiG), it matters whether the company had an effective compliance management in place and whether it tightened that management after the incident so that comparable breaches become markedly harder.

That is what makes the difference between a system and a folder of policies more than a question of taste.

The seven basic elements under IDW PS 980

The audit standard IDW PS 980, issued by the Institut der Wirtschaftsprüfer (IDW), the Institute of Public Auditors in Germany, is the most widely used structural template for a CMS in the German market. The version that applies is the revised IDW PS 980 n. F. (09.2022), adopted by the IDW's technical committee in December 2022. It carried the seven basic elements over unchanged:

Basic elementGuiding question
Compliance cultureHow credibly does the leadership level behave itself?
Compliance objectivesWhat is the system meant to achieve, concretely?
Compliance risksWhich rule breaches are realistic and material for us?
Compliance organisationWho is responsible, with what resources and authority?
Compliance programmeWhich policies and controls address those risks?
Compliance communicationHow do the people affected learn about rules, roles and reporting channels?
Compliance monitoring and improvementHow do we review and improve the system?

The order is not accidental. Without a documented risk analysis there is no later basis for explaining why one area is controlled more intensively than another.

Audit and certification

Two routes are usual, and they do not exclude each other.

IDW PS 980 n. F. A public auditor issues an attestation. One change here is missing from most accounts, English-language ones included: the 2022 revision expressly abolished the design-only engagement (Konzeptionsprüfung). Anyone commissioning an engagement today chooses between the adequacy review (are the measures suitable to control the risks?) and the effectiveness review, which additionally assesses whether they in fact worked over the audit period and therefore presupposes a completed operating period. The change was driven by the revision's alignment with the international framework ISAE 3000 (Revised).

ISO 37301. An accredited body certifies the management system against the international standard ISO 37301:2021, published in April 2021, which superseded ISO 19600:2014. Unlike its non-binding predecessor it states requirements, and that is what makes it certifiable. For international customers and parent companies this evidence is usually easier to read than a German attestation.

What separates a CMS from a collection of policies

In an examination the decision falls almost always at the same place: proof of effectiveness. Holding a policy is design. Showing that the associated control was performed every quarter, documented, and escalated on deviation, is effectiveness. Which comes down to four things:

  1. Every material requirement is assigned to a named control.
  2. Every control has an owner, a frequency and an expected result.
  3. Every performance leaves a dated record.
  4. Deviations run into an action procedure with a date and an owner.

Relationship to other systems

A CMS does not stand alone. It shares its operational level with the internal control system and its prioritisation with risk management. Build those systems separately and you maintain the same access or approval control several times over, with the versions drifting apart. In a GRC model it is maintained once and used several times.

Typical triggers for building one

  • customer requirements out of tenders or supplier audits
  • an incident or an investigation by an authority
  • supervisory requirements, for instance in the financial sector
  • the Hinweisgeberschutzgesetz, which requires an internal reporting office from 50 employees
  • shareholders wanting demonstrable relief of management from liability
  • a buyer's due diligence, where the absence of a system surfaces as a priced risk

Judging the effort realistically

The expensive part is rarely the rulebook. The ongoing production of evidence is what costs. Plan a first cycle across several months (risk analysis, policies, control definition) and after that at least one complete run of every control frequency, before an effectiveness review can sensibly be commissioned.

Compliance programme and monitoring in Rizzqo

Rizzqo carries the compliance programme and compliance monitoring, the two elements generating most of the ongoing effort. Requirements from the catalogues held in the platform are dispatched to the objects they apply to, with a named assignee, a reason and evidence on the object, and a finalisation under a name and a timestamp. Monitoring is then not a separate survey but a calculation: coverage per object, category and framework, risk exposure in euros, and a daily snapshot turning it into a trend.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework