Compliance
9 Dec 2025 · updated 13 Jul 2026

What is compliance? Definition and meaning

Bridgly Editorial Team
Reading time:
3
minutes
Diverse team discussing company compliance rules at a meeting table using a printed guide
Table of contents

What is compliance? Definition and meaning

What is compliance? The term refers to adherence to all laws, regulations, contracts and self-imposed rules that apply to a company and its employees. In German the term is rendered as Regelkonformität (conformity to rules) or Regeltreue. Compliance thus covers both observance of external requirements – for instance from data protection, employment or competition law – and adherence to internal policies such as a code of conduct.

The term describes not only a state but also the entirety of the organisational measures with which a company ensures that rules are known and followed. These include policies, training, controls and reporting channels.

Conformity to rules, the duty of legality and GRC

A number of fixed terms have become established around compliance. Regelkonformität and Regeltreue are the customary German renderings and are mostly used synonymously.

The duty of legality (Legalitätspflicht) describes the responsibility of the management to ensure that the company behaves lawfully. It derives from the general management and due-diligence responsibility of the corporate bodies – for instance from the diligence of a prudent and conscientious manager under the Stock Corporation Act (AktG) (in German) or the duty of care of the managing director under the Limited Liability Companies Act (GmbHG) (in German). For the management, compliance is therefore not an optional extra task but part of its organisational responsibility. In addition, § 130 OWiG (in German) governs the supervisory duty of business owners and management within the company – the provision is one of the central legal reasons why companies build up systematic compliance management.

GRC stands for governance, risk and compliance. The term brings together corporate governance, risk management and adherence to rules as three closely interlinked management disciplines that many organisations think of as one.

Why compliance matters for companies

Compliance brings order to a broad field of mandatory topics that would otherwise stand side by side. Data protection, information security, anti-money laundering, occupational safety and health, the protection of whistleblowers under the Act for the Better Protection of Whistleblowers (HinSchG) (in German) and the prohibition of discrimination on the grounds listed in § 1 AGG (in German) are typical sub-areas – each with its own rules and often its own training obligations. A systematic compliance approach bundles these topics, allocates responsibilities and makes rules traceable in everyday work.

For small and medium-sized enterprises (SMEs) and public administration, this is less about a large body of rules than about knowing the relevant obligations, raising employees’ awareness regularly and being able to document adherence.

Compliance management system: ISO 37301 and IDW PS 980

Larger organisations structure their compliance through a compliance management system, or CMS for short. This is the organisational framework of principles, objectives, responsibilities and measures for adherence to rules.

Two standards shape the German-speaking region. The international standard ISO 37301:2021 describes requirements for a compliance management system and is certifiable. The auditing standard IDW PS 980 (in German) of the Institute of Public Auditors in Germany (IDW) sets out principles for auditing such systems and names compliance culture as a fundamental element. Both standards are frameworks for orientation – their application is not mandatory. An overview of further compliance topics is provided by the Compliance section of the Bridgly knowledge hub.

FAQ

What does compliance mean in simple terms?

Compliance means that a company adheres to all laws, regulations and internal rules that apply to it. In German the term is rendered as Regelkonformität (conformity to rules). It covers both the state of adherence to rules and the organisational measures – such as policies, training and controls – with which a company ensures that rules are known and followed.

What is the difference between compliance and GRC?

Compliance is adherence to laws and internal rules. GRC stands for governance, risk and compliance and describes the overarching interplay of corporate governance, risk management and adherence to rules as three closely interlinked management disciplines that many organisations think of and manage together. Compliance is thus an important building block of GRC, not its replacement or synonym.

Who in the company is responsible for compliance?

Responsibility lies first with the management: from its duty of legality (Legalitätspflicht) – for instance under § 93 of the Stock Corporation Act (AktG) or § 43 of the Limited Liability Companies Act (GmbHG) – follows the duty to ensure lawful conduct throughout the company. In larger organisations this task is additionally organised and documented through a compliance management system, designated compliance functions and regular training for all employees.

Which topics typically belong to compliance?

Compliance includes, among other things, data protection, information security, anti-money laundering, occupational safety and health, the protection of whistleblowers under the Act for the Better Protection of Whistleblowers (HinSchG) and the prohibition of discrimination under the General Act on Equal Treatment (AGG). Each of these areas brings its own rules, often also its own training and documentation obligations for employees, which a company-wide compliance management system bundles and makes traceable in everyday work.

Sources

  • Primary – Stock Corporation Act, §§ 76, 91 and 93 AktG (management and duty of care of the management board) – gesetze-im-internet.de (as of 7 Jul 2026)
  • Primary – Limited Liability Companies Act, § 43 GmbHG (duty of care of the managing director) – gesetze-im-internet.de (as of 7 Jul 2026)
  • Primary – Act on Regulatory Offences, § 130 OWiG (breach of the supervisory duty in establishments and companies) – gesetze-im-internet.de (as of 7 Jul 2026)
  • Primary – Act for the Better Protection of Whistleblowers (HinSchG), in force since 2 July 2023 – gesetze-im-internet.de (as of 7 Jul 2026)
  • Primary – General Act on Equal Treatment, § 1 AGG (protected grounds) – gesetze-im-internet.de (as of 7 Jul 2026)
  • Primary – ISO 37301:2021, „Compliance management systems – Requirements with guidance for use“, International Organization for Standardization – iso.org (as of 7 Jul 2026)
  • Primary – IDW PS 980 (revised version 09.2022), „Grundsätze ordnungsmäßiger Prüfung von Compliance-Management-Systemen“ (principles of proper auditing of compliance management systems), Institute of Public Auditors in Germany (IDW) – idw.de (as of 7 Jul 2026)
  • Image licence: AI-generated image (prompt see field „Bild-Prompt (KI-Bild)“), full usage rights held by Bridgly; labelled „Created with AI“ as an image overlay in line with Art. 50 EU AI Act after image production.

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.