Organisations can have their compliance management system certified in accordance with ISO 19600. Whether and when this is appropriate must be carefully assessed.
The standard can be applied in both businesses and other organisations. Small and medium-sized enterprises can also benefit from the standard, as the recommendations are scalable and can be applied to varying degrees depending on the size of the organisation.
The Compliance Management System (CMS) set out in ISO 19600 is based on five pillars, which can also serve as a „roadmap“ for implementing a CMS:
1. Compliance and Risk Audit
The compliance audit serves to determine the company’s current status with regard to its compliance activities. The risk audit serves to identify compliance obligations (risks). The result is a „compliance risk map“ for the company. This analysis forms the basis for all further measures aimed at establishing the CMS.
2. Guided tour
The focus is on the various roles, responsibilities and areas of authority within the organisation, particularly at management level. It is management’s responsibility to take the decision to implement a CMS, to define the objectives and framework of the CMS, and to allocate the necessary resources. A key factor here is the example set by management: if management is committed to ethical, legally compliant behaviour – and thus to preventing and penalising unlawful practices – and actually lives up to this commitment, then an important prerequisite for a CMS to function effectively is in place.
3. Management and control measures
The control measures that a company must put in place include policy documents such as a code of conduct, process descriptions and operational guidelines. These must be drawn up in accordance with the findings of the compliance and risk audit and should be specifically tailored to address identified compliance risks – always closely aligned with business processes. Appropriate monitoring and control measures must be integrated into these processes.
4. Communication and training
Most breaches of the rules stem from a lack of knowledge. Knowledge of the existence of a requirement and of the consequences of one’s own actions is therefore crucial if compliance is to be achieved. The standard requires ongoing training designed to enable employees to understand compliance requirements and act accordingly. Intensive communication and awareness-raising help to create a sustainable corporate culture.
5. Continuous improvement
As with quality management, the continuous improvement of the CMS in place is one of the key tasks. This involves carrying out random and ad hoc checks to ensure compliance with regulatory requirements (e.g. through internal audits). Ongoing monitoring of the legal environment and continuous updating of the risk analysis are necessary in order to constantly adapt the system to new circumstances.
Any identified breaches of compliance must result in a response from the company. This includes investigating the incident and determining the consequences of the identified misconduct (sanction). Corrective and preventative measures are designed to prevent a recurrence.
Certification of a management system is not always appropriate or necessary. Therefore, when setting up a CMS, this aspect should be carefully assessed in advance: what are the benefits of certification? Is it required (by the market or by customers)?
Certification should only be considered if these and similar questions can be answered unequivocally with „yes“. In addition to certification, the company has numerous alternative options available to it for effectively communicating the existence of the CMS.
About the author

Eckart Achauer studied law and business administration, followed by postgraduate studies leading to a Master of Business Administration (MBA). He undertook further professional development alongside his work to qualify as a European Quality Manager (DGQ), a mediator specialising in commercial mediation, and a Certified Compliance Manager (TÜV).
He spent around 10 years in the international insurance industry, holding various management positions within a Swiss insurance group (claims department, sales, assistance), before moving into management and business consultancy in 1997.
As a consultant and managing director of various consultancy firms, Mr Achauer has specialised in organisational and process optimisation, as well as in the development and implementation of management systems – quality management, risk management and compliance management.
At Senator Executive Search Partners, Mr Achauer is responsible for the Compliance Management division. As part of compliance audits, he analyses organisations„ “compliance fitness’, raises awareness and provides training for management, executives and staff, and supports companies in developing and implementing bespoke compliance management systems. In doing so, he always takes into account the specific risk profile of each company. Thanks to his many years’ experience as a manager and consultant, he is thoroughly familiar with the practical challenges faced by businesses.


