It is now largely undisputed that companies must have a compliance management system in place. The key issue in this context is the nature and scope of the compliance function.
In principle, the objectives of a compliance function within a company are clearly defined: on the one hand, the aim is to prevent compliance breaches (arising from within the company) in order to avert damage (both financial and reputational) to the company. On the other hand, the compliance function is also intended to minimise, if not entirely prevent, the personal liability – under criminal and civil law – of management.
Ever since the issue of compliance has attracted significant media attention and numerous corporate scandals have come more firmly to the attention of an increasingly critical public, the question of establishing and implementing compliance management systems (CMS) has also been discussed in circles that had not previously felt it concerned them.
Risk landscape and risk strategy
Every company – regardless of sector, products or business model – faces risks that may materialise and thereby cause damage to the company. In the wake of globalisation and internationalisation, regulatory requirements have increased. Some sectors are particularly affected by this. One example is the energy sector, which is grappling with a flood of new legislation in the context of significant market changes. However, the proliferation of regulations within companies, particularly within corporate groups, is also steadily increasing, meaning that an ever-greater number of internal guidelines must be observed.
As the number of regulations increases, so does the risk that unwittinglyto breach statutory, regulatory and internal requirements. This does not affect cases of wilful breach.
Not every risk has critical or existential consequences should it materialise. Against this background, defining the risk landscape and the risk strategy form an essential basis for the future structure of the compliance management system. The first step is to identify the risks; this establishes the risk landscape (which risks exist in which business context). The second step involves assessing the risks by quantifying potential losses and estimating the probability of occurrence. In a third step, the risks are prioritised and assigned to a strategic approach (as a rule, risk strategy distinguishes between risk avoidance, risk minimisation, risk transfer and risk retention). Low-risk events are often borne by the company itself, whilst risks involving high losses are transferred to third parties (e.g. insurance). In the case of non-transferable risks, the company attempts to minimise or even avoid them through appropriate measures.
Obligation to establish a compliance function
Every manager would be well advised to protect their company – and themselves – against the risks arising from compliance breaches. This is usually achieved through a specific compliance management system (CMS). To what extent, however, is there an obligation to establish such a compliance function?
Opinions on this matter are far from unanimous. Explicit legal obligations exist only in specific cases, such as Section 33 of the WpHG[1] and Section 25a of the German Banking Act (KWG)[2]. The provisions referred to expressly require the establishment of compliance functions; this applies to companies that provide investment services or financial services.
Supporters assume that there is a general obligation to establish a compliance function. This follows from a holistic interpretation of existing statutory provisions such as Sections 76, 91(2) and 93(1) of the German Stock Corporation Act (AktG) and Sections 35, 41, 43 and 85 of the German Limited Liability Companies Act (GmbHG) (statutory management function).[3].
It also follows from the provisions of the OWiG (Sections 3, 9 and 130 OWiG) that itself derive an obligation to establish a compliance function[4].
Finally, the German Corporate Governance Code (DCGK) that the Executive Board must ensure compliance with statutory provisions and the company’s internal guidelines, and must work to ensure that the group companies adhere to them[5].
Critics do not share this view. Their main argument is that – apart from the aforementioned provisions of the WpHG and KWG, and, in addition, the provision in Section 64a of the VAG[6] – there are no explicit statutory provisions. If the legislator had intended compliance functions, of whatever kind, to be mandatory, it would have included this in the relevant statutory provisions.
The interpretation of the AktG and the GmbHG as implying an obligation to establish a compliance function is also regarded as excessive.
Finally, the DCGK is also rejected as a legal basis, as it is merely advisory in nature and is therefore not legally binding. Furthermore, it applies exclusively to listed public limited companies and thus does not take all other companies into account.
All the arguments put forward are valid and well-founded. Nevertheless, they lose their impact when it comes to the question of whether members of management are willing to expose themselves to the risk of civil and criminal liability due to a lack of compliance management.
The compliance management system must be tailored to the organisation
When it comes to this question, the first thing to note is simply this: there are no specific legal or regulatory requirements for a compliance management system. In this respect, every company’s management is, in principle, free to choose the functional and organisational structures for the compliance function within their organisation. Nevertheless, there are a number of aspects which are worth considering when setting up a CMS and which may – directly or indirectly – have implications for the design of the CMS. After all, such a function ties up human and material resources and therefore represents a not inconsiderable cost factor.
The compliance function can only be truly effective if it is integrated into the overall corporate organisation as a management system. It is therefore essential to put in place a system that is appropriate for the company in question. This requires, at a minimum:
- Staff allocation
Responsibility for compliance must be assigned to specific individuals; in other words, responsibility in this area must be delegated to specific people. In small businesses, this responsibility may be combined with other roles (e.g. financial control), whilst large companies employ dedicated compliance officers for this purpose. Outsourcing this function to a specialist consultant is also a possibility. - Organisational integration
The compliance function must be firmly embedded within the organisation. This aspect, too, depends on the size and structure of the company: in practice, all options are represented, ranging from a staff unit to a dedicated compliance department. However the compliance function is organised, it is important that it does not operate in isolation. It is essential to ensure that there is close integration with other management systems (quality management, risk management, etc.). - Definition of tasks
Defining the responsibilities of the compliance function involves two aspects. On the one hand, the specific operational tasks must be set out (e.g. advising senior management and other departments within the company, developing and implementing internal policies, training staff, and monitoring for and detecting compliance breaches). Secondly, care must be taken to ensure that the responsibilities of the compliance function are suitable for ensuring that the management’s obligations (organisational, control and investigative obligations) are fulfilled – after all, this involves the delegation of supervisory duties and, in this context, the relevant interplay between the act of delegation, the selection decision and the supervision of the delegate. - Monitoring, control and reporting
A compliance function requires monitoring and control. This is usually achieved through a reporting system, which, in its broader context, also includes the conduct of internal and external audits.
The CMS must be tailored to the individual company, taking into account its specific requirements and concerns, as well as its unique risk profile. In this respect, it is essential to carry out a thorough analysis of the key parameters before establishing or expanding a CMS.
[1] In Section 33 of the Securities Trading Act (WpHG), the legislator has imposed specific organisational obligations on securities trading firms (establishment of an independent compliance function)
[2] Section 25a of the German Banking Act (KWG): An institution must have a proper organisational structure that ensures compliance with the statutory provisions applicable to the institution and meets its business requirements (extract)
[3] Section 91(2) of the AktG (German Stock Corporation Act), for example, stipulates that the management board must take appropriate measures, in particular by establishing a monitoring system. The same applies to a GmbH.
[4] Under Section 9 of the OWiG (Administrative Offences Act), „ownership“ of the undertaking within the meaning of the OWiG is attributed to the persons acting directly. In practice, therefore, liability for organisational negligence under the OWiG does not lie with the company itself, but with its management.
[5] Section 4.1.3 of the DCGK (German Corporate Governance Code)
[6] Section 64 of the Insurance Supervision Act (VAG) is not relevant here
The second blog post will examine business practice and the resulting requirements.
About the author

Eckart Achauer studied law and business administration, followed by postgraduate studies leading to a Master of Business Administration (MBA). He undertook further professional development alongside his work to qualify as a European Quality Manager (DGQ), a mediator specialising in commercial mediation, and a Certified Compliance Manager (TÜV).
He spent around 10 years in the international insurance industry, holding various management positions within a Swiss insurance group (claims department, sales, assistance), before moving into management and business consultancy in 1997.
As a consultant and managing director of various consultancy firms, Mr Achauer has specialised in organisational and process optimisation, as well as in the development and implementation of management systems – quality management, risk management and compliance management.
At Senator Executive Search Partners, Mr Achauer is responsible for the Compliance Management division. As part of compliance audits, he analyses organisations„ “compliance fitness’, raises awareness and provides training for management, executives and staff, and supports companies in developing and implementing bespoke compliance management systems. In doing so, he always takes into account the specific risk profile of each company. Thanks to his many years’ experience as a manager and consultant, he is thoroughly familiar with the practical challenges faced by businesses.


