Home / Europe / Germany / Compliance & Forensic Services / Compliance-Management-Systeme

Compliance Management Systems

Back to Compliance & Forensic Services

A trip to Bangkok, a business deal between brothers, and a bottle of wine – about life with and without compliance  

Case study on implementing a compliance management system 

It’s not uncommon for multiple compliance risks to be identified during due diligence when acquiring a company. An institutionalised compliance costs money, an institutionalised compliance does not evolve by itself, the company has grown quickly, and “has always managed fine without it” – those are just four of the many reasons why German SMEs in particular struggle in this area.

Like in the case we are describing here. We identified policies that were not state-of-the-art for a compliance management system. We found out that employees were not sensitised to compliance-related issues. We saw organisational and governance structures that lacked clarity around how, and by whom, compliance measures should be developed, implemented and applied. 

The acquiring company considered this a problem, having itself a rather different compliance culture. They consider a professional compliance management system as the market standard and part of proper corporate governance. The lack of this type of system at the target company worked in its favour during the price negotiations, however, the company would now like to implement appropriate compliance structures in the acquired company. The purchaser considered it essential to urgently reduce liability risks that could arise for both the company and its management as a result of inadequate structures (in a worst-case scenario, fines of up to EUR 10 million could be imposed). Another aim is to ensure compliant conduct on the part of all company employees. 

The directors of the acquired company and its employees are not exactly enthusiastic about this approach. They voice various concerns, citing unnecessary costs, unnecessary work and unnecessary expenditure on external consultants. Managers fear that compliance would hinder their day-to-day work. “Compliance requirements take up too much time, you don’t get anything else done.” There were mutterings among employees about a “surveillance state” in which you are no longer allowed to do anything. And the knock-down argument raised by the directors, managers, employees and works council is that there was nothing wrong in the first place, so why not just carry on as usual? 

In situations such as this, where two wholly different viewpoints collide, the key is to engage in dialogue. A functioning compliance system must not just be aligned with a company’s size, international scope, industry specifics and risk areas, but also with its corporate culture. In addition to managers, it is particularly important to address the concerns of the employees, who ultimately have to put the compliance culture into practice. You need to explain the benefits of compliance to them and involve them in designing the compliance management system. It’s also necessary to find practical solutions that are genuinely tailored to the needs of the specific company. Compliance should not be a burden, but should protect the company, its management and the employees, and ideally simplify their everyday work by providing clear rules on dos and don’ts. 

Grudgingly, the company began to tackle the project. We came in as external advisors, starting with workshops in which we talked to the company about key aspects and concerns. This was followed by quick compliance checks on specific areas to get an idea of where loopholes might be found. We conducted interviews with key stakeholders from the core areas and used our dedicated tool to analyse documents efficiently. 

Not so surprising to us, but certainly to the company management, that alongside identifying weaknesses we uncovered embarrassing compliance-related incidents, some of which were financially detrimental to the company. Employees from the Business Development department regularly received invitations from business partners, including a week-long stay in Bangkok for a trade association meeting. Christmas presents in Sales exceeded the appropriate value. In the Purchasing department, contracts were regularly awarded to a construction company whose managing director just happened to be the brother of our client’s purchasing manager. In the Finance department, reminders were simply thrown away and duplicate payments made, possibly due to the lack of an appropriate IT system. The HR department told us about people being off sick due to workplace bullying. These incidents went unreported because there was too little awareness of whistleblower protection or the Whistleblower Protection Act (Hinweisgeberschutzgesetz). A Legal department that had never heard of the Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG) insisted that sustainability was leftist nonsense, and that you could not be held liable for things in the supply chain anyway. 

The picture that gradually emerged was very different from the view of compliance held by company management and many employees. There was a clear need for action on several fronts. Accordingly, with the evidence in our favour, we set about establishing a compliance organisation (and in particular appointing a Compliance Officer). A code of conduct was drawn up together with policies on corruption and on conflicts of interest. A system for screening business partners was also introduced, along with a signature policy including a documentation/filing system and a reporting system. We took various steps to ensure compliance with the Supply Chain Due Diligence Act and developed a modern training programme. This was designed to make employees more aware of compliance issues going forward, with attendance being documented.

Shortly before Christmas, we received something in the mail. It was from the company’s senior management team, with whom we had worked closely over the course of a year to help introduce a compliance management system. It turned out to be a nice bottle of wine – which is deemed completely appropriate from a compliance perspective in such a context. But we remember the card much more, which thanked us for our work and said they were looking forward to more projects in the coming year. No trace of a grudging attitude now. More a sense of gratitude, in fact, since our project had eliminated several personal liability risks compared to the original situation.

OUR ADVISORY PORTFOLIO

We provide a full range of advisory services around compliance management systems, including

  • Development, implementation and optimisation of compliance programmes
  • Advising executive bodies on legal compliance and organisational obligations, and on corporate governance structures
  • Structuring a compliance organisation (responsibilities, etc.)
  • Risikoanalyse und -management (Compliance Due Diligence, Business Partner Screenings, Compliance-Klauseln) 
  • Setting up and managing whistleblower systems (whistleblower hotline, ombudsman) 
  • Preparation of compliance policies as well as instructions and trainings

Structured approaches – example: review of Compliance processes
 

 

What others say about us:

„Kompetent, kunden- und lösungsorientiert.“

The Legal 500, 2023

Contact us!

Write us a message and we will get in contact.

Your message was sent.

Thank you for contacting us. We will get back to you soon.

Please check these fields.

By including your personal data on this form you agree to it being used in accordance with our Privacy Policy

sending...

Feed

15/04/2024
Co-determination in the setup and organisation of whistleblower reporting...
This article deals with the co-determination rights of the works council as regards whistleblower reporting offices in accordance with the German Whistleblower Protection Act (HinSchG).The legislator...
18/03/2024
E-learning | Protection of reporting persons using a whistleblower system
The EU’s Whistleblower Directive (2019/1937) was transposed into national law in Germany by the Whistleblower Protection Act (Hin­weis­ge­ber­s­chutzge­setz, HinSchG). The Whistleblower Protection Act came into effect on 2 July 2023. We have developed an e-learning course for your employees that answers the essential legal and organisational questions relating to the whistleblower protection provided by having a reporting system in place. The course also explains how a whistleblowing system works and encourages staff to report potential issues internally rather than contacting the relevant external reporting office.
18/03/2024
E-learning | Contact with competitors – basic competition law rules
Our e-learning course on dealing with competitors provides our clients with a sound basis for training their employees. This e-learning course guides through the correct conduct under competition law when in contact with competitors.
18/03/2024
E-learning | Open source compliance – basics
This e-learning course teaches the basics of open source compliance. The aim of the course is to raise awareness of the advantages as well as the risks and pitfalls of open source software in all these levels of the company. At the end of the course, solutions to identify risks and avoid them as best as possible through appropriate processes are shown. The e-learning course is aimed at everyone in companies who comes into contact with open source software. This includes not only management but also the IT and development department, purchasing, sales and product management.
18/03/2024
E-learning | Money laundering prevention in industry and trade
This e-learning course was developed specifically for employees and suppliers. It is intended to raise awareness of what must be observed legally to successfully prevent money laundering. As the addressees of the Anti-Money Laundering Act (Geld­wäschege­setz, GwG), companies are obliged to take precautions against their own abuse for money laundering purposes or financing terrorists. The e-learning course takes into account the special position of goods traders in money laundering prevention and can be individually supplemented and modified with regard to the specific risk exposure (especially business activities with high-risk countries, dealing with deviating payers or conspicuous drop shipments).
18/03/2024
E-learning | Open source compliance for software developers
This e-learning course has been specially designed for software developers. Its purpose is to raise awareness of what needs to be considered from a legal viewpoint when software developers use open source software.
18/03/2024
E-Learning | Preventing corruption – basics and practical tips
In a business context, benefits such as gifts and invitations are mainly intended to promote and maintain business relationships. However, using excessive benefits to influence business decisions is not allowed. There is often uncertainty about what is "allowed" and what is "banned" in the business world. Our basic training on corruption prevention educates your employees and provides practical guidance for everyday business that complies with legal requirements.
06/03/2024
ARD Conference of Committee Chairs draws up framework compliance policy...
Munich – The committee chairs of German broadcaster ARD have agreed on a framework policy for members of supervisory bodies. This specifies in more detail the requirements under the relevant interstate treaties and establishes the basis for a common compliance culture across the individual broadcasting councils and administration councils. The policy includes standards of conduct for committee members and rules on dealing with possible conflicts of interest. For greater transparency, members of ARD supervisory bodies are also urged to share information on the Internet about their other roles before and during membership of broadcasting councils and administration councils. The onus is now on the broadcasting councils and administration councils of the ARD stations to implement the recommendations of the ARD Conference of Committee Chairs. They also need to check on a case-by-case basis whether additions need to be made as a result of existing statutory regulations or aspects specific to the particular committee.A CMS team including Dr Harald Potinecke and Laura Posch advised the Conference of Committee Chairs and a working party comprising committee members of all stations on all legal aspects of developing the framework compliance policy. Contacts at CMS Germany Dr Harald Potinecke, Partner Laura Posch, Senior Associate, both CompliancePress Con­tact presse@cms-hs. com
19/01/2024
Greenwashing: Stricter EU rules on environmental marketing ban misleading...
On 17 January 2024, the European Parliament voted to adopt the Directive on Empowering Consumers for the Green Transition (the ECGT Directive), which seeks to protect consumers from various misleading...
19/01/2024
CBAM: Just over a week to comply
As the deadline for the first Carbon Border Adjustment Mechanism (CBAM) report approaches on January 31st, it is crucial for undertakings engaged in importing relevant goods into the European Union to...
19/01/2024
EU Proposals for a Regulation and a Directive on Anti-Money Laundering...
On 18 January 2024, the Council of the European Union and the European Parliament reached a provisional agreement on a part of the new anti-money laundering and counter terrorism financing (“AML/CTF”)...
29/12/2023
Tackling the misuse of crypto-assets for ML-TF purposes
As a constantly evolving sector, the crypto-assets ecosystem presents continuous challenges, particularly in terms of money laundering and terrorist financing (ML-TF) risks.To tackle the misuse of crypto-assets...