What is compliance?
Compliance is a company's duty to observe the rules that apply to it and to organise, monitor and evidence that observance. In German law the core is § 130 of the Administrative Offences Act (OWiG). Under it, an owner commits an administrative offence by failing to take the supervisory measures that prevent violations within the business. The offence requires intent or negligence and a violation that proper supervision would have prevented or made substantially more difficult.
When this organisation is run as a system of rules, controls and reports, it is called a compliance management system.
Which rules does compliance cover?
Compliance covers every rule that is binding on the company, whatever its source. Which rules these are follows from the industry, the size of the company and its contracts.
| Area | Examples | Evidence |
|---|---|---|
| Laws and regulations | GDPR, Whistleblower Protection Act (HinSchG), Money Laundering Act | policies, training records, registers |
| Supervisory law | KWG and MaRisk, DORA, BSIG for NIS2 entities | reports, audit reports |
| Contracts and customer requirements | data processing agreements, supplier requirements | contract register, audits |
| Standards, where agreed or pursued | ISO/IEC 27001, ISO 37301 | certificate, management review |
| Internal rules | code of conduct, approval limits | approvals, four-eyes principle |
There is therefore no catalogue that applies to everyone. Each company's catalogue follows from its own obligations.
Is compliance a legal requirement in Germany?
There is no general compliance act. The duty follows from several provisions that require care, supervision and, for certain companies, explicit control systems:
| Provision | Who it applies to | What it requires | Consequence of a breach |
|---|---|---|---|
| § 43 GmbHG | managing directors of a GmbH | the care of a prudent businessperson | joint and several liability to the company; limitation period of five years |
| § 93 AktG | members of the management board | the care of a diligent and conscientious manager | joint and several liability; in a dispute the board member bears the burden of proof |
| § 91(3) AktG | management board of a listed company | an appropriate and effective internal control system and risk management system | breach of duty under § 93 AktG |
| § 130 OWiG | owner of a business or company | the necessary supervisory measures, including the selection and supervision of supervisory staff | fine of up to EUR 1 million where the duty breached carries a criminal penalty |
| § 30 OWiG | the company as a legal person | applies where a person in a management position commits a criminal or administrative offence that breaches the company's duties | corporate fine of up to EUR 10 million for an intentional, up to EUR 5 million for a negligent criminal offence |
| § 12(2) HinSchG | employers with "as a rule at least 50 employees" | an internal reporting channel | fine under § 40(2) no. 2 HinSchG |
The organisation counts when a corporate fine is set. In its judgment of 9 May 2017 (1 StR 265/16), the Federal Court of Justice (BGH) held that "efficient compliance management" affects the amount. Rules a company improves as a result of the proceedings can also play a role.
Five building blocks of a compliance programme
No provision prescribes the same structure for every company; what is appropriate depends on size, industry and risk profile. A programme can be divided into five building blocks that build on one another:
- Risk analysis: determine which areas of law can affect your company and how serious a breach would be.
- Rules: write a code of conduct and policies for exactly these risks.
- Controls: enforce the rules with an internal control system of preventive and detective controls.
- Reporting channels: set up a channel for reports that meets the requirements of the Whistleblower Protection Act.
- Evidence: record training, control logs and reports to management.
Four roles with separate responsibilities
Compliance works only if the executing and the reviewing role are kept apart. A company that lets one function enforce the rules and confirm their effectiveness gets a self-assessment instead of a control.
| Role | Responsible for | Not responsible for |
|---|---|---|
| Management | setting up, resourcing and overseeing the organisation; deciding on risks that are accepted | operational execution |
| Compliance function | framework, risk analysis, advice, reporting to management | performing the duties within the business units |
| Business units | day-to-day compliance, operating the controls, producing the evidence | assessing their own controls |
| Internal audit | independent review of appropriateness and effectiveness | designing and operating the controls it reviews |
Compliance, risk management and GRC: three scopes
Compliance is one part of a wider management framework. The three terms differ in which risks they look at.
| Term | What it looks at |
|---|---|
| Compliance | the risk of breaching binding rules |
| Risk management | all of the company's risks, including market, operational and IT risks |
| GRC | the joint management of governance, risk and compliance |
Rizzqo keeps the evidence on the requirement
Rizzqo keeps the evidence of compliance on the individual requirement: the owner answers it, justifies the answer, attaches the evidence and finalises it under name and timestamp. The requirements come from held catalogues such as ISO/IEC 27001, DORA or the Cyber Resilience Act and appear on the assets they apply to, such as systems, service providers and staff functions.
Rizzqo computes the degree of compliance from these finalised answers. Daily snapshots record it for each day, so months later it is still possible to show the state that applied on a given date.