REQUIREMENTS FOR SENIOR MANAGEMENT WHEN ESTABLISHING A COMPLIANCE FUNCTION
One question that repeatedly arises in business practice is that of the scope for discretion in establishing and operating a compliance management system. In this context, a distinction must be made between decisions that are legally binding and those that are business-related decisions taken by senior management.
There is no room for discretion when it comes to complying with legal requirements. These must be complied with without exception. These are binding decisions.
When it comes to defining and implementing organisational measures, however, there is certainly scope for discretion. After all, company management does not usually regard ensuring compliance with laws and regulations as one of its primary responsibilities, but rather delegates this to a specific group of individuals whilst setting out the organisational framework. Even monitoring and control can be delegated to supervisory staff. In this respect, these are core management and organisational tasks that fall within the scope of corporate responsibilities – and there is undoubtedly scope for corporate discretion in this regard.
The following requirements apply when establishing a compliance function:
- Organisational requirements
Liability for breaches of the law does not constitute strict liability. Liability rests with the company’s management personally if they fail to take appropriate organisational measures. Case law[1] This is based on the assumption that company management has a duty to put in place the organisational conditions necessary to ensure that the compliance officer can actually fulfil their duty to prevent compliance breaches. The scope of this duty is linked to the size and structure of the business. Case law does not provide further details on the „how“ of a compliance organisation, which suggests that it regards the establishment and organisation of a compliance function as an inherent corporate responsibility.
The key organisational requirements include – in addition to the aspects already mentioned regarding staff allocation, organisational integration, definition of responsibilities and Control / Monitoring – integration with other management functions within the organisation. These include, in particular, general risk management, quality management, as well as financial control and internal audit. The form this integration takes depends on the organisational structure; however, it is essential that the compliance function does not operate as an isolated „stand-alone solution“.
- Requirements for monitoring and control
In principle, the organisational structure in place (both within the meaning of Section 130 of the OWiG and Section 43 of the GmbHG) requires appropriate supervision and monitoring of the persons to whom the duties of the compliance function have been delegated. Random checks on staff therefore constitute a fundamental function of the company’s organisational structure.
However, the monitoring and control measures must be practicable and reasonable. The exact limits of what is practicable and reasonable are not clearly defined. They are likely to be exceeded, however, if the intensity of the monitoring and control is so great that it effectively amounts to the supervisor carrying out the supervised party’s own tasks. This would effectively undermine the right to delegate tasks.
- Requirements for investigations and enquiries
The lawsdiscussion[2] assumes that – although no explicit obligation to do so can be inferred from the law – a company will then implement internal Investigations / Inquiries must initiate where there are concrete indications of a breach of the rules, even if these indications do not arise from the regular, ongoing monitoring carried out as part of the compliance function’s remit. If the compliance function identifies breaches of the rules in the course of its regular activities, an appropriate investigation must undoubtedly be launched so as not to call into question the very purpose of the compliance function.
Summary and Outlook
A sense of proportion is required when designing, implementing and operating compliance management systems. Cost considerations, on the one hand, and the issues of organisational proportionality and internal acceptance, on the other, are compelling arguments for implementing not what is possible, but what is necessary within the compliance function. The permissible exercise of corporate discretion should therefore also be applied in this context.
However, this leeway must not obscure the fact that the implementation of a compliance management system is a business imperative, as the mere absence of such a compliance function can in itself give rise to personal criminal and civil liability on the part of the company’s management.
Dealing with a compliance management system is a complex undertaking and requires expertise across a range of different disciplines. On the one hand, a legal perspective is necessary; however, viewed in isolation, this is not sufficient. Breaches of regulations can occur anywhere within the organisation. Therefore, in-depth knowledge of organisational structures and of how functions and processes interact is essential in order to identify and define the requirements for an adequate compliance management system within the context of the organisation’s specific risk landscape; and on this basis, the appropriate measures for establishing and implementing the CMS are then derived and put into practice. Furthermore, knowledge and experience of other management systems, such as risk or quality management systems, is beneficial in ensuring the necessary integration of systems within the organisation.
[1] Higher Regional Court of Düsseldorf, 12 November 1998
[2] Federal Court of Justice (BGH), 8 October 1984 – II ZR 175/83, WiJ – Journal of the Association for Economic Criminal Law, 03-2012, 9 July 2012
About the author

Eckart Achauer studied law and business administration, followed by postgraduate studies leading to a Master of Business Administration (MBA). He undertook further professional development alongside his work to qualify as a European Quality Manager (DGQ), a mediator specialising in commercial mediation, and a Certified Compliance Manager (TÜV).
He spent around 10 years in the international insurance industry, holding various management positions within a Swiss insurance group (claims department, sales, assistance), before moving into management and business consultancy in 1997.
As a consultant and managing director of various consultancy firms, Mr Achauer has specialised in organisational and process optimisation, as well as in the development and implementation of management systems – quality management, risk management and compliance management.
At Senator Executive Search Partners, Mr Achauer is responsible for the Compliance Management division. As part of compliance audits, he analyses organisations„ “compliance fitness’, raises awareness and provides training for management, executives and staff, and supports companies in developing and implementing bespoke compliance management systems. In doing so, he always takes into account the specific risk profile of each company. Thanks to his many years’ experience as a manager and consultant, he is thoroughly familiar with the practical challenges faced by businesses.


