Skip to main content
Should Your Compliance System Survive a Courtroom Test?Ethics and Conduct
5 min readFor Compliance Officers

Should Your Compliance System Survive a Courtroom Test?

Scope - What This Guide Covers

This guide addresses Germany's Law to Strengthen Business Integrity (Gesetz zur Stärkung der Integrität in der Wirtschaft), expected to take effect later this year. It's designed for compliance officers, legal teams, and risk managers at companies with German operations or subsidiaries.

You'll find requirement breakdowns, implementation steps, and cross-references to international frameworks that can strengthen your compliance posture. This guide focuses on what the draft bill requires and how you can prepare your organization before enforcement begins.

What's in scope:

  • Companies defined as "Verband" under the draft bill (legal entities under public or private law, partnerships with legal capacity, associations without legal capacity)
  • Criminal liability provisions for corporate entities
  • Compliance management system requirements and penalty mitigation factors
  • Cross-border application scenarios

What's out of scope:

  • Individual employee criminal liability (covered under existing German criminal law)
  • Administrative fines under the current Administrative Offences Act
  • Sector-specific compliance obligations beyond this law's framework

Key Concepts and Definitions

Company (Verband): The draft bill uses an expansive definition covering legal entities under public or private law, associations without legal capacity, and partnerships with legal capacity. Excluded: associations whose purpose isn't directed at commercial business operations.

Company-Level Criminal Liability: A fundamental shift in German law. Sanctions apply when offenses:

  • Violate obligations affecting the company, and
  • Enrich the company or are intended to enrich it

Compliance Management System: The draft bill doesn't specify required components, but references these systems at multiple enforcement stages: as a potential criminal offense if absent, as a sanction assessment factor, and as a court-ordered rehabilitation measure.

Internal Investigation: Formal inquiry conducted by the company into suspected criminal offenses. The draft bill creates incentive structures around cooperation with law enforcement authorities during preliminary investigations.

Requirements Breakdown

Monetary Sanctions Framework

The draft bill establishes two penalty calculation methods:

Revenue-based sanctions:

  • Up to 10% of average worldwide annual revenue
  • Applies when company turnover exceeds EUR 100 million
  • Calculated on worldwide operations, not German revenue alone

Profit-based sanctions:

  • Up to 100% of profit earned through the offense
  • Applied independently or in combination with revenue-based penalties

Non-Monetary Sanctions

Publication requirement: Final convictions appear in a register of company sanctions, creating reputational consequences beyond financial penalties.

Court-ordered rehabilitation: Courts may mandate establishment of a compliance management system as a remedial measure.

Penalty Mitigation Provisions

Cooperation credit: Penalties may be discounted by up to 50% if companies cooperate with law enforcement authorities in a preliminary investigation. The draft sets strict conditions for this reduction.

Compliance system credit: Presence or absence of a compliance management system factors into:

  • Overall sanction assessment
  • Prosecution versus warning decisions
  • Penalty calculation methodology

Cross-Border Application

Foreign-owned entities in Germany: Companies seated outside Germany may face sanctions if an offense to which German criminal law applies has been committed.

German companies with foreign operations: Sanctions apply to offenses committed abroad when:

  • The conduct would constitute a criminal offense under German law if committed in Germany, and
  • The conduct is punishable at the place of the offense

This dual-criminality standard prevents German companies from avoiding liability through offshore operations.

Implementation Guidance

Phase 1: Compliance Risk Analysis

Conduct a formal risk assessment that maps your organization's criminal liability exposure under German law. This isn't a generic enterprise risk review; focus specifically on offenses that could trigger company-level sanctions.

Document which business units, geographies, and processes carry the highest risk of violations that would both affect the company and enrich it (or be intended to enrich it). Your analysis should address the dual-element test the draft bill establishes.

Phase 2: System Architecture Review

Evaluate your existing compliance structures against what enforcement authorities will examine during sanction assessment. The draft bill doesn't prescribe specific system components, but you can reference ISO 37301 (Compliance Management Systems) and ISO 37001 (Anti-Bribery Management Systems) as internationally recognized frameworks.

Your review should cover:

  • Governance structures and accountability chains
  • Risk assessment methodologies and update frequencies
  • Control design and operating effectiveness
  • Training programs and competency requirements
  • Monitoring, testing, and assurance activities
  • Incident response and investigation protocols

Phase 3: Investigation Readiness

Prepare your organization to conduct internal investigations that meet the cooperation standards necessary for penalty mitigation. This preparation should happen before an incident occurs.

Establish investigation protocols that address:

  • Immediate response procedures when potential violations surface
  • Evidence preservation and chain-of-custody requirements
  • Attorney-client privilege considerations under German law
  • Coordination protocols with law enforcement authorities
  • Documentation standards that demonstrate cooperation

Since penalties may be discounted by up to 50% for cooperation during preliminary investigations, your protocols must enable rapid, thorough responses when authorities initiate inquiries.

Phase 4: Documentation Standards

Create records that demonstrate your compliance management system's existence and operation. During sanction assessment, authorities will evaluate whether you had functioning controls in place, not just policies on paper.

Document:

  • Board-level compliance oversight activities and decisions
  • Risk assessment outputs and remediation plans
  • Control testing results and corrective actions
  • Training completion rates and effectiveness measures
  • Investigation findings and disciplinary actions

Common Pitfalls

Assuming current administrative fine exposure reflects future risk: The shift from EUR 10 million maximum fines to 10% of worldwide annual revenue represents a magnitude change for large organizations. Don't calibrate your compliance investment to the old penalty framework.

Treating compliance systems as optional for SMEs: Small and medium-sized enterprises face particular challenges; resource constraints make robust compliance structures difficult to justify under cost-benefit analysis. However, the absence of a compliance management system will negatively impact penalty assessments. SMEs should prioritize risk-based controls in high-exposure areas rather than attempting comprehensive programs they can't sustain.

Delaying implementation until the law takes effect: Companies that wait for final enactment will face compressed timelines to establish systems that can credibly demonstrate maturity and effectiveness. Authorities will likely scrutinize whether your compliance management system predates the violation or was hastily assembled afterward.

Ignoring cross-border implications: If you operate German subsidiaries from a non-German parent company, or if German entities employ staff abroad, map how the dual-criminality provisions apply to your structure. The draft bill's extraterritorial reach means compliance gaps in foreign operations create German liability.

Failing to connect compliance to business operations: Compliance management systems that exist separately from operational processes won't satisfy enforcement scrutiny. Your controls must be embedded in transaction workflows, approval chains, and performance management systems.

Quick Reference Table

Element Requirement Implementation Priority
Revenue-based sanctions Up to 10% worldwide annual revenue (companies >EUR 100M turnover) Immediate risk quantification
Profit-based sanctions Up to 100% of offense-derived profit Transaction monitoring controls
Compliance system assessment Presence/absence factors into prosecution decisions and penalty calculation System architecture review
Cooperation credit Up to 50% penalty discount for preliminary investigation cooperation Investigation protocol development
Cross-border liability Dual-criminality standard for foreign offenses Global operations risk mapping
Publication requirement Final convictions in public sanctions register Reputational risk assessment
Court-ordered rehabilitation Mandated compliance system establishment Proactive system implementation

Your compliance management system should be operational and demonstrably effective before violations occur. The draft bill creates no safe harbor for organizations that implement controls only after enforcement actions begin.

You Might Also Like