Compliance

Compliance (regulatory compliance) is the organised and demonstrable observance of all laws, contracts, standards and internal rules that apply to a company. In German law it rests on § 130 OWiG, which requires the owner to take the necessary supervisory measures. A compliance management system is the organisation a company uses to steer this observance.

GRCLast reviewed:

What is compliance?

Compliance is a company's duty to observe the rules that apply to it and to organise, monitor and evidence that observance. In German law the core is § 130 of the Administrative Offences Act (OWiG). Under it, an owner commits an administrative offence by failing to take the supervisory measures that prevent violations within the business. The offence requires intent or negligence and a violation that proper supervision would have prevented or made substantially more difficult.

When this organisation is run as a system of rules, controls and reports, it is called a compliance management system.

Which rules does compliance cover?

Compliance covers every rule that is binding on the company, whatever its source. Which rules these are follows from the industry, the size of the company and its contracts.

AreaExamplesEvidence
Laws and regulationsGDPR, Whistleblower Protection Act (HinSchG), Money Laundering Actpolicies, training records, registers
Supervisory lawKWG and MaRisk, DORA, BSIG for NIS2 entitiesreports, audit reports
Contracts and customer requirementsdata processing agreements, supplier requirementscontract register, audits
Standards, where agreed or pursuedISO/IEC 27001, ISO 37301certificate, management review
Internal rulescode of conduct, approval limitsapprovals, four-eyes principle

There is therefore no catalogue that applies to everyone. Each company's catalogue follows from its own obligations.

There is no general compliance act. The duty follows from several provisions that require care, supervision and, for certain companies, explicit control systems:

ProvisionWho it applies toWhat it requiresConsequence of a breach
§ 43 GmbHGmanaging directors of a GmbHthe care of a prudent businesspersonjoint and several liability to the company; limitation period of five years
§ 93 AktGmembers of the management boardthe care of a diligent and conscientious managerjoint and several liability; in a dispute the board member bears the burden of proof
§ 91(3) AktGmanagement board of a listed companyan appropriate and effective internal control system and risk management systembreach of duty under § 93 AktG
§ 130 OWiGowner of a business or companythe necessary supervisory measures, including the selection and supervision of supervisory stafffine of up to EUR 1 million where the duty breached carries a criminal penalty
§ 30 OWiGthe company as a legal personapplies where a person in a management position commits a criminal or administrative offence that breaches the company's dutiescorporate fine of up to EUR 10 million for an intentional, up to EUR 5 million for a negligent criminal offence
§ 12(2) HinSchGemployers with "as a rule at least 50 employees"an internal reporting channelfine under § 40(2) no. 2 HinSchG

The organisation counts when a corporate fine is set. In its judgment of 9 May 2017 (1 StR 265/16), the Federal Court of Justice (BGH) held that "efficient compliance management" affects the amount. Rules a company improves as a result of the proceedings can also play a role.

Five building blocks of a compliance programme

No provision prescribes the same structure for every company; what is appropriate depends on size, industry and risk profile. A programme can be divided into five building blocks that build on one another:

  1. Risk analysis: determine which areas of law can affect your company and how serious a breach would be.
  2. Rules: write a code of conduct and policies for exactly these risks.
  3. Controls: enforce the rules with an internal control system of preventive and detective controls.
  4. Reporting channels: set up a channel for reports that meets the requirements of the Whistleblower Protection Act.
  5. Evidence: record training, control logs and reports to management.

Four roles with separate responsibilities

Compliance works only if the executing and the reviewing role are kept apart. A company that lets one function enforce the rules and confirm their effectiveness gets a self-assessment instead of a control.

RoleResponsible forNot responsible for
Managementsetting up, resourcing and overseeing the organisation; deciding on risks that are acceptedoperational execution
Compliance functionframework, risk analysis, advice, reporting to managementperforming the duties within the business units
Business unitsday-to-day compliance, operating the controls, producing the evidenceassessing their own controls
Internal auditindependent review of appropriateness and effectivenessdesigning and operating the controls it reviews

Compliance, risk management and GRC: three scopes

Compliance is one part of a wider management framework. The three terms differ in which risks they look at.

TermWhat it looks at
Compliancethe risk of breaching binding rules
Risk managementall of the company's risks, including market, operational and IT risks
GRCthe joint management of governance, risk and compliance

Rizzqo keeps the evidence on the requirement

Rizzqo keeps the evidence of compliance on the individual requirement: the owner answers it, justifies the answer, attaches the evidence and finalises it under name and timestamp. The requirements come from held catalogues such as ISO/IEC 27001, DORA or the Cyber Resilience Act and appear on the assets they apply to, such as systems, service providers and staff functions.

Rizzqo computes the degree of compliance from these finalised answers. Daily snapshots record it for each day, so months later it is still possible to show the state that applied on a given date.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework