Adresse:
Location Werft 16
Werftstraße 16
40549 Düsseldorf
Kontakt:
Tel: +49 211 545532 80
Fax: +49 211 545532 99
Email: anchor@reef-legal.com

Compliance

Compliance in the Company

Why a Functioning Compliance Management System Is Indispensable Today.

In an increasingly regulated business environment, compliance has become indispensable for companies of all sizes. The term refers to the systematic adherence to all applicable laws, regulations, official requirements and internal company policies. Yet compliance goes far beyond mere legal conformity: it is about creating a culture of integrity, minimising risk, protecting reputation and safeguarding long-term company value.

Companies without functioning compliance management systems (CMS) risk:

  • Fines running into millions (GDPR up to EUR 20 million, LkSG up to EUR 8 million)
  • Criminal consequences for management
  • Personal liability of senior management
  • Reputational damage and loss of important business relationships
  • Exclusion from public contracts for up to three years

Compliance as a Business Requirement: Supplier Codes of Conduct

A functioning compliance system is increasingly a mandatory prerequisite for contracts with large corporations and public authorities. Companies such as Telekom, Siemens, EnBW and many others require their suppliers to comply with stringent Supplier Codes of Conduct. Violations can lead to immediate loss of contracts.

Personal Liability of Management Tightened

The personal liability of management has intensified dramatically in recent years:
OLG Nuremberg, judgment of 30.03.2022 (Az. 12 U 1520/19): The court expressly confirmed for the first time that managing directors are obliged to establish a compliance management system – and can become personally liable for damages if they fail to do so. In the decided case, the managing director was ordered to pay damages in excess of EUR 700,000.
BGH, judgment of 23.07.2024 (Az. II ZR 206/22 and II ZR 222/22): The Federal Court of Justice has further tightened managing director liability: a managing director’s liability does not automatically end upon leaving office. If the risk situation created by the breach of duty still exists at the time the damage arises, the former managing director is also liable for losses suffered by new creditors.
At Reef Rechtsanwälte in Düsseldorf, we support companies of all sizes and industries in the setup, implementation, training and review of compliance management systems. We do not regard compliance as a bureaucratic obstacle, but as a strategic business factor that creates competitive advantages, minimises risks and protects management from personal liability.

Compliance Advisory

What is Compliance? Definition and Legal Significance

Legal Definition and Scope

Compliance refers to the rule-compliant and ethical fulfilment of all legal, regulatory and internal company standards by a company, its governing bodies and employees. The term encompasses:

  • Statutory requirements at national, European and international level
  • Regulatory requirements and administrative provisions
  • Internal company guidelines and policies
  • Ethical standards and integrity requirements
  • Industry-specific standards and certification requirements

The Legal Basis: Duty of Legality pursuant to § 43 GmbHG

The management of a GmbH is obliged under § 43 para. 1 GmbHG (or § 93 AktG for stock corporations) to act in accordance with the law and to create the necessary organisational structures to prevent legal violations. This duty of legality is the central legal basis for compliance.

The OLG Nuremberg stated in its landmark judgment of 30.03.2022 (Az. 12 U 1520/19):
“The duty of legality gives rise to the managing director’s obligation to establish a compliance management system, i.e. organisational precautions to prevent the commission of legal violations by the company or its employees.”
The court made clear: the managing director must create an internal organisational structure that ensures the lawfulness and efficiency of the company’s conduct. A breach of this duty occurs where employees are enabled or facilitated in wrongdoing through inadequate organisation, instruction or supervision.

| Reef Rechtsanwälte Düsseldorf
Compliance Advisory

Why Compliance Is Indispensable – The Four Central Reasons

1. Risk Minimisation and Prevention of Harm – Fines Running into Millions

The most serious motivation for compliance is the avoidance of existential damage. The figures speak for themselves:
Data protection (GDPR):

  • Fines of up to EUR 20 million or 4% of worldwide annual turnover (Art. 83 GDPR)
  • In 2024, German supervisory authorities issued 266 fine notices with a total volume of EUR 89.1 million
  • Highest German GDPR fine in 2025: EUR 45 million against Vodafone for inadequate control measures regarding processors and security vulnerabilities
  • Across Europe, GDPR fines totalling EUR 1.2 billion were imposed in 2024

Supply Chain Due Diligence Act (LkSG):

  • Fines of up to EUR 8 million or 2% of worldwide annual turnover
  • Exclusion from public contracts for up to three years for fines exceeding EUR 175,000

Anti-Money Laundering Act (GwG):

  • Fines of up to EUR 100,000 for negligent violations
  • Up to EUR 5 million or 10% of annual turnover for intentional violations
  • Obligation to report immediately to the Financial Intelligence Unit (FIU)

Breach of supervisory duty (§ 130 OWiG):

  • Fine of up to EUR 1 million for business owners who fail to supervise
  • Also covers managing directors who enable employees to commit criminal offences or regulatory violations through inadequate supervision

2. Exoneration of Management – Protection from Personal Liability

A central aspect is the personal liability of senior management. Case law has tightened considerably in recent years:
OLG Nuremberg, judgment of 30.03.2022 (Az. 12 U 1520/19):

  • The court ordered a managing director to pay damages of over EUR 700,000 because he had failed to establish a functioning compliance system.
  • The managing director is personally liable to the company for failure to establish an adequate CMS.
  • Management need not perform all tasks personally, but may delegate them to suitable employees through appropriate organisational structures.
  • A functioning compliance management system can exonerate management from personal liability.
  • Mere supervision “under normal circumstances” is not sufficient – management must intervene immediately when indications of misconduct arise.
  • The burden of proof lies with the managing director: they must demonstrate and prove that they have fulfilled their duties of care.

BGH, judgment of 23.07.2024 (Az. II ZR 206/22 and II ZR 222/22):

  • A managing director’s liability does not automatically end upon leaving office.
  • If the risk situation created by the breach of the filing obligation still exists at the time the damage arises, the former managing director is also liable for losses suffered by new creditors.
  • The new managing director, who assumes office at a time when an insolvency filing obligation already exists, is also liable for the resulting damages.

§ 130 OWiG – Breach of supervisory duty:

  • Pursuant to § 130 para. 1 OWiG, the owner of a business or company (typically management) is liable for breaches of supervisory duty where employees commit criminal offences or regulatory violations that would have been prevented or substantially impeded by proper supervision.
  • Fine of up to EUR 1 million.
  • Required supervisory measures include: appointment, careful selection and monitoring of supervisory personnel.
  • A functioning compliance system can preclude a breach of supervisory duty.

3. Prerequisite for Contracts with Large Corporations and Public Authorities

An often underestimated but enormous practical pressure for compliance implementation comes from large corporations and public procurement bodies, which systematically review their suppliers for compliance conformity.
Supplier Code of Conduct:

  • Large corporations require their suppliers to sign and comply with Supplier Codes of Conduct:
  • Telekom: Supplier Code of Conduct with strict requirements on anti-corruption, human rights, environmental protection, including LkSG requirements
  • EnBW: Supplier Code of Conduct for all business partners with binding sustainability standards
  • HGK AG: Detailed Supplier Code with requirements on compliance, sustainability and ethics

Consequences of violations:

  • Violations of the Supplier Code are assessed as a “material impairment of the contractual relationship” and can lead to immediate loss of contracts.
  • Companies without a functioning compliance system may be excluded from major tenders, regardless of their technical competence.
  • Compliance requirements are increasingly mandatory in public procurement.

4. Trust, Reputation and Competitive Advantages

Compliance is a trust factor and creates measurable competitive advantages:

  • Customers and investors expect ethical conduct and transparent business dealings.
  • Talented professionals want to work for companies that live by integrity.
  • Business partners prefer companies with functioning compliance systems.
  • Cost savings through avoidance of fines, criminal proceedings and reputational damage.
  • Operational efficiency through better processes and fewer errors.
Compliance Advisory

The Most Important Compliance Areas at a Glance

A functioning compliance system must cover the specific risks of the company. Depending on the industry, size and business activities, different areas are relevant.

1. Data Protection and Information Security (GDPR, BDSG)

Legal bases: EU General Data Protection Regulation (GDPR), Federal Data Protection Act (BDSG)
Core obligations:

  • Privacy policy and transparency obligations
  • Records of processing activities (RoPA) – documentation of all data processing operations
  • Data protection impact assessments for high-risk processing
  • Employee data protection – careful handling of employee data
  • Data subject rights (access, erasure, rectification)
  • Technical and organisational measures (TOMs)
  • Data processing agreements pursuant to Art. 28 GDPR

Sanctions: Fines of up to EUR 20 million or 4% of annual turnover

2. Anti-Corruption and Integrity Compliance

Legal bases: § 299 StGB (bribery and corruption in commercial transactions), §§ 331 ff. StGB (granting of advantages and bribery), UN Convention against Corruption
Core obligations:

  • Code of Conduct with clear anti-corruption requirements
  • Gifts and hospitality guidelines
  • Conflicts of interest management
  • Reputational due diligence – screening of business partners
  • Documentation of consultancy contracts and intermediary arrangements

3. Anti-Money Laundering (GwG)

Legal basis: Anti-Money Laundering Act (GwG)
Core obligations:

  • Risk analysis and risk management
  • Customer identification (KYC – Know Your Customer)
  • Continuous transaction monitoring
  • Suspicious activity reports to the Financial Intelligence Unit (FIU)
  • Appointment of a money laundering officer
  • Employee training

Sanctions: Fines of up to EUR 5 million or 10% of annual turnover

4. Supply Chain Due Diligence Act (LkSG)

Legal basis: Supply Chain Due Diligence Act (LkSG), applicable from 2023 for companies with 3,000+ employees, from 2024 for companies with 1,000+ employees
Core obligations:

  • Risk analysis in the supply chain (human rights, environmental risks)
  • Preventive measures for risk mitigation
  • Remedial measures for known violations
  • Complaints procedure for affected persons
  • Supplier Code of Conduct – contractual obligation of suppliers

Sanctions: Fines of up to EUR 8 million or 2% of annual turnover

5. Competition Law Compliance

Legal bases: § 1 GWB (cartel prohibition), Art. 101 TFEU (EU competition law)
Core obligations:

  • Competition law compliance programme
  • Employee training (particularly sales, procurement)
  • Avoidance of price-fixing, bid-rigging, market allocation
  • Review of contracts for competition law permissibility

Sanctions: Fines of up to 10% of worldwide turnover

6. Employment Law and Health & Safety

Legal bases: Occupational Health and Safety Act (ArbSchG), Working Hours Act (ArbZG), General Equal Treatment Act (AGG), Works Constitution Act (BetrVG)
Core obligations:

  • Compliance with working time legislation and minimum wage
  • Occupational safety and health protection
  • Anti-discrimination (AGG)
  • Works agreements with works councils
  • Prevention of mobbing and harassment

7. ESG Compliance and Sustainability

Legal bases: Corporate Sustainability Reporting Directive (CSRD), EU Taxonomy Regulation, German Corporate Governance Code (DCGK)
Core areas:

  • Environmental: CO₂ emissions, resource efficiency, biodiversity
  • Social: Working conditions, diversity, human rights
  • Governance: Compliance, transparency, remuneration systems
  • CSRD reporting obligation: Detailed sustainability reporting pursuant to European Sustainability Reporting Standards (ESRS)

8. IT Security and Information Security

Legal bases: IT Security Act (IT-SiG), NIS-2 Directive
Core obligations:

  • ISO 27001 – Information Security Management System
  • Cybersecurity (protection against hacking, malware, ransomware)
  • Cloud security
  • Identity & Access Management
  • OT security – security of production systems in Industry 4.0
Compliance Management System

Building a Compliance Management System pursuant to IDW PS 980 and ISO 37301

A compliance management system (CMS) is the structured totality of all measures, processes and structures that a company puts in place to ensure compliance.

The Applicable Standards

IDW PS 980 (revised 2022):
The IDW Auditing Standard 980 is the leading standard in Germany for the audit of compliance management systems. It was developed by the Institute of Public Auditors in Germany (IDW) and comprehensively revised in 2022:

  • Describes seven basic elements of a CMS
  • Provides a framework for audit by auditors
  • Three engagement types: adequacy audit and effectiveness audit (concept audit was removed in 2022)
  • Takes into account international standards (ISAE 3000 Revised)

ISO 37301 (published 2021):
ISO 37301 is an international standard that sets out requirements for compliance management systems:

  • Replaces ISO 19600
  • Internationally certifiable
  • Comprises 10 chapters following the Harmonized Structure (High Level Structure)
  • Focus on compliance culture, top management commitment and continuous improvement (PDCA cycle)
  • Specific requirements for whistleblowing systems and investigation processes

The 8 Elements of a Functioning CMS

Pursuant to IDW PS 980 and ISO 37301, an effective CMS consists of the following elements:

1. Compliance Culture and Tone from the Top

The foundation of every CMS is a culture of integrity that is demonstrated by senior management:

  • Clear company values: definition of integrity, trustworthiness and ethical standards
  • Demonstrated by management: what management preaches, it must also practise (“Tone from the Top”)
  • Open communication: employees must be able to raise compliance concerns without fear of retaliation
  • Regular communication of the importance of compliance by management

ISO 37301 emphasises in particular: the compliance culture must be established and promoted by the supreme body (board, management).

2. Risk Analysis and Risk Identification

A CMS must be based on the specific risks of the company:

  • Identify compliance obligations: which laws and regulations apply?
  • Assess compliance risks: which business areas and processes are particularly risk-prone?
  • Determine risk levels: critical, high, medium, low
  • Regular update: at least annually

ISO 37301 refers to ISO 31000 (risk management) and IEC 31010 (risk assessment techniques) for detailed recommendations.

3. Compliance Objectives and Scope

The company must clearly define what is to be understood by “compliance”:

  • Definition of objectives: “Our company will act in accordance with the law in areas X, Y, Z”
  • Business areas: which areas are included?
  • SMART objectives: Specific, Measurable, Achievable, Relevant, Time-bound
  • Documentation: in a management resolution or board decision

4. Organisation and Responsibilities

A functioning CMS requires clear organisational structures:
Compliance Officer / Head of Compliance:

  • Central contact person for all compliance matters
  • Direct reporting line to management or supervisory board
  • Independence from operational objectives
  • Adequate resources (budget, personnel)

Responsibility of management:

  • Management bears overall responsibility
  • It may delegate tasks, but not responsibility
  • Delegation transforms into duties of selection and supervision

ISO 37301 requires a clear compliance function with defined powers and independence.

5. Policies and Procedures

Rules must be set out in writing and be accessible and comprehensible to all employees:
Central policies:

  • Code of Conduct – fundamental ethical and behavioural rules
  • Anti-corruption policy
  • Data protection policy
  • Competition law compliance policy
  • Supplier compliance policy
  • Anti-money laundering policy
  • Sanctions and disciplinary measures

Procedural instructions should specify:

  • Who may approve what? (four-eyes principle, limits)
  • How are decisions documented?
  • What escalation routes exist?

6. Communication and Training

Training is essential to ensure employees understand compliance requirements:
Training concept:

  • All-employee training: Code of Conduct, anti-corruption, data protection
  • Specialist training: for high-risk groups (procurement, sales, finance)
  • New employees: onboarding training
  • Refresher training: at least annually
  • E-learning platforms: flexible delivery and documentation

Checking effectiveness:

  • Tests and quizzes after training
  • Review of training results
  • Behavioural observation

ISO 37301 sets out detailed requirements on competence and training in section 7.2.

7. Monitoring and Control

Regular control mechanisms must be established:
Types of controls:

  • Operational controls: in ongoing operations (four-eyes principle, approval processes)
  • Detective controls: spot checks, automated alerts
  • Internal audits: systematic review of areas
  • Compliance tests: validation of individual processes
  • Key Performance Indicators (KPIs)

IDW PS 980 distinguishes between adequacy audit (is the system correctly designed?) and effectiveness audit (does the system actually work?).

8. Whistleblowing Systems

The Whistleblower Protection Act (HinSchG) requires companies with 50 or more employees to establish an internal reporting system:
Requirements:

  • Internal reporting office: compliance officer or ombudsman
  • Anonymous reporting: employees must be able to report anonymously
  • Protection from retaliation: clear assurance
  • Acknowledgement deadline: within 7 days of receipt
  • Final notification: within 3 months

ISO 37301 dedicates a separate section to the whistleblowing system (section 8.3 “Raising concerns”) and additionally requires investigation processes (section 8.4).

Compliance Officer

Compliance for SMEs – DIN SPEC 91524 as a Guide

Small and medium-sized enterprises (SMEs) often cannot match the resources of a large corporation. DIN SPEC 91524 provides a pragmatic guide specifically for SMEs.

Key features:

  • Simplified approaches: not all the complexity required for DAX-listed companies
  • Self-check: a tool with 30 questions for risk identification
  • Pragmatic measures: focus on the greatest risks
  • Cost-efficient solutions: no expensive IT systems where simple spreadsheets suffice

The core idea: even with limited resources, SMEs can build functioning CMS – it just needs to be risk-adapted and proportionate.

DIN SPEC 91524 was published in May 2025 and emerged from the “MiCo” project (Empirical Development and Testing of a Compliance Standard for Medium-Sized Enterprises).

Mitarbeiter | Reef Rechtsanwälte Düsseldorf
CMS Implementation

Compliance Audits and Effectiveness Review

A key component of compliance monitoring is regular compliance audits.

What is a Compliance Audit?

A compliance audit is an independent, systematic review of whether a company complies with all applicable laws, regulations and internal policies:

  • Independent: Conducted by persons without operational responsibility
  • Systematic: Based on checklists and defined procedures
  • Comprehensive: Covering all relevant areas
  • Documented: With written findings and recommendations

The Course of a Compliance Audit

Step 1: Planning and Preparation

  • Definition of audit scope
  • Resource planning
  • Informing the employees involved

Step 2: Document Review

  • Review of policies, procedures and guidelines
  • Review of contracts and approvals
  • Review of training materials

Step 3: On-Site Review and Interviews

  • Inspection of business premises
  • Interviews with employees
  • Observation of processes
  • Control of controls: do the controls actually work?

Step 4: Assessment and Findings Report

  • Documentation of findings
  • Risk assessment (critical, high, medium, low)
  • Root cause analysis
  • Specific recommendations

Step 5: Follow-Up

  • Tracking of implementation
  • Validation of effectiveness

Effectiveness Audit pursuant to IDW PS 980

The effectiveness audit is the highest level of compliance review:

  • Demonstrates that a CMS not only exists, but is actually effectively implemented and lived
  • Decisive factor in audit relief and liability matters
  • Fine reduction factor: a functioning CMS can reduce fines by up to 50%
Compliance Lawyer Düsseldorf

REEF Rechtsanwälte – Your Compliance Law Firm in Düsseldorf

The implementation and optimisation of a compliance management system requires legal expertise, process know-how and practical experience. At Reef Rechtsanwälte in Düsseldorf, we support companies in all aspects.

Our Services

Building Compliance Management Systems:

  • Compliance risk analysis pursuant to IDW PS 980 and ISO 37301
  • Building CMS from scratch or optimising existing systems
  • Adaptation to DIN SPEC 91524 for SMEs
  • Policy development and harmonisation
  • Implementation according to industry-specific standards

Training and Education:

  • Development of tailored training concepts
  • Delivery of compliance training (in-person and e-learning)
  • Specialist training for high-risk groups
  • Management training for exoneration from liability

Audit and Compliance Review:

  • Internal compliance audits
  • Preparation for external audits pursuant to IDW PS 980
  • Gap analyses and identification of weaknesses
  • Effectiveness review of existing CMS
  • Regular compliance monitoring

Specialist Compliance Areas:

  • Data protection compliance (GDPR, BDSG): records of processing activities, data protection impact assessments
  • Anti-corruption compliance: Code of Conduct, reputational due diligence
  • Anti-money laundering (GwG): risk analyses, KYC processes
  • Supply chain compliance (LkSG): Supplier Codes of Conduct, supplier audits
  • Competition law compliance: training, competition law controls
  • ESG compliance: integration of sustainability and ESG criteria, CSRD reporting
  • Customs law and export control: sanctions screening, compliance systems
  • IT security and ISO 27001

Whistleblowing Systems:

  • Implementation of anonymous reporting channels pursuant to HinSchG
  • Ombudsman services
  • Investigation of compliance incidents

Management Exoneration from Liability:

  • Advisory on minimising personal liability risks
  • Documentation of compliance measures for exoneration
  • Defence against damages claims

Our Approach

At Reef Rechtsanwälte, we combine high professional expertise with pragmatic business understanding:

  • Not dogmatic: We regard compliance as a lived practice, not an academic concept
  • Risk-adapted: We focus on the real risks of your company
  • Resource-realistic: We create CMS that function within your available resources
  • Long-term partnership: We support you not only during implementation, but also in ongoing optimisation
  • Human, creative, effective: With a new-work mentality and genuine entrepreneurial spirit

Team Compliance

  • Urs Breitsprecher

    Attorney-at-Law & Solicitor

    Specialist Lawyer for Tax Law Specialist Lawyer for Commercial & Corporate Law

  • Urs Breitsprecher
  • Henrik Behnke

    Attorney-at-Law

    Specialist Lawyer for Employment Law, Data Protection and IT Law

  • Henrik Behnke
Logo Anfrage starten
Logo
Kanzlei-Assistent
Online