
What is compliance? The term refers to adherence to all laws, regulations, contracts and self-imposed rules that apply to a company and its employees. In German the term is rendered as Regelkonformität (conformity to rules) or Regeltreue. Compliance thus covers both observance of external requirements – for instance from data protection, employment or competition law – and adherence to internal policies such as a code of conduct.
The term describes not only a state but also the entirety of the organisational measures with which a company ensures that rules are known and followed. These include policies, training, controls and reporting channels.
A number of fixed terms have become established around compliance. Regelkonformität and Regeltreue are the customary German renderings and are mostly used synonymously.
The duty of legality (Legalitätspflicht) describes the responsibility of the management to ensure that the company behaves lawfully. It derives from the general management and due-diligence responsibility of the corporate bodies – for instance from the diligence of a prudent and conscientious manager under the Stock Corporation Act (AktG) (in German) or the duty of care of the managing director under the Limited Liability Companies Act (GmbHG) (in German). For the management, compliance is therefore not an optional extra task but part of its organisational responsibility. In addition, § 130 OWiG (in German) governs the supervisory duty of business owners and management within the company – the provision is one of the central legal reasons why companies build up systematic compliance management.
GRC stands for governance, risk and compliance. The term brings together corporate governance, risk management and adherence to rules as three closely interlinked management disciplines that many organisations think of as one.
Compliance brings order to a broad field of mandatory topics that would otherwise stand side by side. Data protection, information security, anti-money laundering, occupational safety and health, the protection of whistleblowers under the Act for the Better Protection of Whistleblowers (HinSchG) (in German) and the prohibition of discrimination on the grounds listed in § 1 AGG (in German) are typical sub-areas – each with its own rules and often its own training obligations. A systematic compliance approach bundles these topics, allocates responsibilities and makes rules traceable in everyday work.
For small and medium-sized enterprises (SMEs) and public administration, this is less about a large body of rules than about knowing the relevant obligations, raising employees’ awareness regularly and being able to document adherence.
Larger organisations structure their compliance through a compliance management system, or CMS for short. This is the organisational framework of principles, objectives, responsibilities and measures for adherence to rules.
Two standards shape the German-speaking region. The international standard ISO 37301:2021 describes requirements for a compliance management system and is certifiable. The auditing standard IDW PS 980 (in German) of the Institute of Public Auditors in Germany (IDW) sets out principles for auditing such systems and names compliance culture as a fundamental element. Both standards are frameworks for orientation – their application is not mandatory. An overview of further compliance topics is provided by the Compliance section of the Bridgly knowledge hub.
Compliance means that a company adheres to all laws, regulations and internal rules that apply to it. In German the term is rendered as Regelkonformität (conformity to rules). It covers both the state of adherence to rules and the organisational measures – such as policies, training and controls – with which a company ensures that rules are known and followed.
Compliance is adherence to laws and internal rules. GRC stands for governance, risk and compliance and describes the overarching interplay of corporate governance, risk management and adherence to rules as three closely interlinked management disciplines that many organisations think of and manage together. Compliance is thus an important building block of GRC, not its replacement or synonym.
Responsibility lies first with the management: from its duty of legality (Legalitätspflicht) – for instance under § 93 of the Stock Corporation Act (AktG) or § 43 of the Limited Liability Companies Act (GmbHG) – follows the duty to ensure lawful conduct throughout the company. In larger organisations this task is additionally organised and documented through a compliance management system, designated compliance functions and regular training for all employees.
Compliance includes, among other things, data protection, information security, anti-money laundering, occupational safety and health, the protection of whistleblowers under the Act for the Better Protection of Whistleblowers (HinSchG) and the prohibition of discrimination under the General Act on Equal Treatment (AGG). Each of these areas brings its own rules, often also its own training and documentation obligations for employees, which a company-wide compliance management system bundles and makes traceable in everyday work.
Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.
Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.