Compliance – Regulatory Compliance and Responsible Corporate Governance
Compliance means that a company knows, assesses and appropriately implements the legal, regulatory and internal requirements applicable to its activities.
An effective compliance organisation supports management in identifying risks at an early stage, defining responsibilities and avoiding violations of rules wherever possible. It is therefore an integral part of good corporate governance and not merely a reaction to damage that has already occurred.
Your Compliance Management System
We support companies in establishing, developing and reviewing an appropriate Compliance Management System (CMS).
In doing so, we particularly consider:
- compliance obligations relevant to your company,
- the identification and assessment of compliance risks,
- roles, responsibilities and reporting lines,
- policies, processes and controls,
- training and awareness measures,
- whistleblowing systems and investigation processes,
- documentation, monitoring and continuous improvement.
ISO 37301:2021 may serve as an international reference framework. However, the specific design of the system must be appropriate to the size, structure, industry and risk situation of the individual company.
Would you like to establish a CMS?
Do you lack sufficient internal expertise or the necessary resources?
We support you with:
- assessing your existing compliance structures,
- identifying relevant compliance obligations,
- conducting a risk-based gap analysis,
- developing policies and processes,
- defining roles and responsibilities,
- training your compliance and IT compliance officers,
- preparing for a possible certification.
We can enable your employees to further develop the CMS independently. Alternatively, we can provide your company with ongoing or project-based support as external consultants.
Are you already preparing for certification?
Together with you, we assess whether the required structures, documentation and processes have been fully and effectively implemented.
Our support may include:
- reviewing existing documentation,
- assessing compliance risks and controls,
- conducting internal assessments,
- identifying and prioritising gaps,
- supporting the implementation of measures,
- preparing for discussions and evidence requests,
- providing support during the certification process.
Certification may be performed by a suitable independent certification body. We can support the preparation and provide professional guidance, but we do not replace the independent certification decision.
IT-Compliance
IT operations are subject to numerous legal, regulatory and contractual requirements. These may include requirements relating to:
- data protection and the protection of personal data,
- retention and archiving,
- deletion and disposal of data carriers,
- licence management,
- access and authorisation concepts,
- information security,
- outsourcing and service-provider management,
- emergency preparedness and recovery,
- documentation and the provision of evidence.
We support you in translating these requirements into suitable IT processes and controls.
Depending on your organisation, the GDPR, DORA, NIS2/BSIG, ISO/IEC 27001 and industry-specific requirements may be relevant. The requirements that actually apply depend on your organisation, industry, size, role and business activities.
Artificial Intelligence and the AI Act
The use of AI systems creates new opportunities, but also additional requirements and risks. Companies should particularly clarify:
- Which AI systems are being used?
- For which business processes are they used?
- Which data is processed?
- What dependencies exist on external providers?
- Who is responsible for the selection, operation and monitoring of the systems?
- Which requirements apply to transparency, documentation, security and human oversight?
Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence — the so-called AI Act — applies in stages. General application began on 2 August 2026; individual regulatory areas have already applied since 2 February 2025 and 2 August 2025, while further provisions will apply from 2 August 2027. EUR-Lex: Regulation (EU) 2024/1689
We support companies, for example, with:
- recording and classifying the AI systems in use,
- assessing AI-related risks,
- developing AI policies,
- defining responsibilities,
- preparing procedural and evidentiary documentation,
- raising employee awareness and providing training,
- integrating AI governance into existing compliance and information security structures.
Training can be provided by suitable external providers or, upon request, as an in-house event.
Contact
Would you like to establish, develop or review a Compliance Management System?
Please contact us. Together, we will clarify which requirements, risks and measures are relevant to your organisation.
office@collegium-auditores.de

