Regulatory requirements, international standards and social expectations are constantly changing. Effective compliance management protects your company from legal and financial risks, strengthens the trust of your stakeholders and creates certainty of action - even in complex situations.
Relevant challenges and requirements
Companies are under great pressure to act in a legally compliant and responsible manner. Compliance systems must be transparent, flexible and effective in order to meet the growing regulatory requirements and at the same time create real added value for the organisation.
Your advantages at a glance
Our services are tailored to your individual requirements and offer you
Our services - compliance that works
Our four fields of action offer you targeted support - structured, effective and with clear added value for your organisation:
Compliance Assurance
An effective compliance management system (CMS) creates trust - both internally and externally. Our independent audit in accordance with IDW PS 980 provides you with reliable information on the appropriateness and effectiveness of your CMS. This provides you with certainty vis-à-vis authorities, stakeholders and internal committees - and gives you clear indications of possible optimisation potential.
Compliance & Integrity Advisory
Your compliance system becomes an integral part of your corporate culture - transparent, effective and customisable. We support you in the development, implementation and optimisation of your system - in line with relevant standards, legal requirements and your individual organisation.
Compliance Monitorship
US monitor proceedings present companies with complex challenges. We are at your side with experienced compliance and forensic specialists to professionally represent your interests, create transparency and efficiently fulfil the requirements of the authorities - throughout the entire duration of the proceedings.
Compliance Strategy & Transformation
Efficient and digitalised compliance processes strengthen your organisation in the long term. We support you in integrating governance, risk and compliance systems, utilising automation potential and implementing lean compliance - so that your compliance not only protects, but also creates added value.
Contract Compliance
Through data-driven analysis, independent audits and in-depth industry expertise, we provide transparency regarding actual compliance with contractual agreements and identify financial opportunities and risks across your business relationships. In this way, we help you to realise revenue and cost-saving opportunities, reduce compliance and reputational risks, and strengthen processes, controls and partner relationships in the long term.
Compliance Assurance
Safety through independent testingAn effective compliance management system (CMS) creates trust - both internally and externally. Our independent audit in accordance with IDW PS 980 provides you with reliable information on the appropriateness and effectiveness of your CMS. This provides you with certainty vis-à-vis authorities, stakeholders and internal committees - and gives you clear indications of possible optimisation potential.
Compliance & Integrity Advisory
Systems that workYour compliance system becomes an integral part of your corporate culture - transparent, effective and customisable. We support you in the development, implementation and optimisation of your system - in line with relevant standards, legal requirements and your individual organisation.
Compliance Monitorship
Support in sensitive proceedingsUS monitor proceedings present companies with complex challenges. We are at your side with experienced compliance and forensic specialists to professionally represent your interests, create transparency and efficiently fulfil the requirements of the authorities - throughout the entire duration of the proceedings.
Compliance Strategy & Transformation
Shaping the futureEfficient and digitalised compliance processes strengthen your organisation in the long term. We support you in integrating governance, risk and compliance systems, utilising automation potential and implementing lean compliance - so that your compliance not only protects, but also creates added value.
Contract Compliance
Transparency regarding your business relationshipThrough data-driven analysis, independent audits and in-depth industry expertise, we provide transparency regarding actual compliance with contractual agreements and identify financial opportunities and risks across your business relationships. In this way, we help you to realise revenue and cost-saving opportunities, reduce compliance and reputational risks, and strengthen processes, controls and partner relationships in the long term.
Your contacts
Dr. Jan-Hendrik Gnändiger
Partner, Audit, Global & EMA ESG Reporting Advisory Lead, Head of ESG Germany, Head of Sustainability Reporting & Governance Germany
KPMG AG Wirtschaftsprüfungsgesellschaft
Marc Stauder
Partner, Audit, Regulatory Advisory, Sustainability Reporting & Governance
KPMG AG Wirtschaftsprüfungsgesellschaft
Developing and managing compliance in a targeted manner
A robust compliance management system translates a company’s individual risk profile into clear responsibilities, transparent processes and reliable decision-making procedures. A Compliance Management System (CMS) encompasses the principles and measures by which a company ensures compliance with legal requirements and internal policies, prevents breaches, detects them and responds appropriately. The impetus for establishing or further developing such a system often stems from new regulatory requirements, international growth, corporate transactions, changes to supply chains or identified weaknesses in the existing system. Anyone wishing to establish or further develop a compliance management system should prioritise relevant risk areas and create suitable structures for compliance with both internal and external requirements.
The design of the individual elements depends on the company’s size, sector, international reach and risk exposure. A CMS should be appropriately scaled: it should effectively address the key risks without burdening the organisation with unnecessary complexity.
From risk assessment to reliable routine operations
The starting point is a structured compliance risk analysis. This takes into account the business model, markets, supply chains, business partners, regulatory requirements and potential operational risks. Typical risk areas include corruption and bribery, antitrust and competition law, sanctions and export control legislation, anti-money laundering, data protection and information security, labour and human rights throughout the supply chain, as well as tax and product-related obligations. Added to these are requirements under the Supply Chain Due Diligence Act, the Corporate Sustainability Due Diligence Directive and the Whistleblower Protection Act, as well as the organisational and supervisory obligations under Sections 30 and 130 of the German Administrative Offences Act (OWiG). On this basis, responsibilities, control activities, escalation procedures and reporting processes can be structured in such a way that they are tailored to the organisation and function reliably in day-to-day operations.
A proven approach is to allocate tasks across the three lines of defence: the operational units are responsible for risks and controls within their processes. Compliance and other monitoring functions define methods, collate information and scrutinise their adequacy. Internal Audit assesses, independently and in a risk-based manner, whether the intended mechanisms are operating as planned.
This provides management with a sound basis for deploying resources in a targeted manner, identifying operational risks at an early stage and managing compliance with relevant requirements in a transparent way. Clearly defined interfaces with risk management, the internal control system and the Internal Audit function reduce overlapping structures and facilitate the long-term integration of these processes into day-to-day operations.
Measuring effectiveness and further developing structures
The assessment of a CMS distinguishes between two levels: Adequacy examines whether the principles and measures are suitable for mitigating the identified risks with reasonable assurance. Effectiveness examines whether they were actually applied as intended within a defined period. Both assessments can be independently verified as part of an audit in accordance with IDW PS 980.
Measures that provide meaningful insights may include, amongst others: the scope and timeliness of the compliance risk analysis; training rates and participation deadlines for high-risk target groups; the number and processing time of reports received; the results and exception rates of control tests; the number of outstanding and overdue measures; and the findings of the Internal Audit. Regular evaluation highlights where adjustments are required and in which areas operational risks persist.
Reporting tailored to the relevant audience helps senior management and supervisory bodies to assess developments, monitor compliance with defined requirements and document decisions in a transparent manner. If defined thresholds are exceeded, clearly defined escalation and decision-making procedures are required.
KPMG supports companies with compliance management consultancy in the design of target frameworks, role models, processes and management information. This includes an assessment of the current situation using a maturity model, a prioritised implementation roadmap, the integration of new requirements into day-to-day operations, and the incorporation of digital data flows and GRC solutions. In addition, independent audits in accordance with IDW PS 980 can provide reliable insights into the adequacy and effectiveness of the CMS. This results in a scalable approach that enables companies to adapt to regulatory changes and address operational risks in a targeted manner.
Frequently Asked Questions
Effective compliance management combines the analysis of relevant compliance and operational risks with clear lines of responsibility, appropriate controls, training, reporting channels and a structured reporting framework. The individual elements should be tailored to the business model and the organisation, and should be firmly embedded in day-to-day operations on a permanent basis.
A compliance management system is usually based on seven fundamental elements: compliance culture, compliance objectives, compliance risks, compliance programme, compliance organisation, compliance communication, and compliance monitoring and improvement. This structure also forms the basis of IDW PS 980. The specific design depends on the company’s size, sector, international reach and risk exposure.
To begin with, organisations should assess the current situation, regulatory requirements and key operational risks. Building on this, the target state, roles, processes, controls and reporting lines are defined. A prioritised implementation roadmap facilitates the phased roll-out and the subsequent transition to stable, routine operations.
Compliance management consultancy can be particularly useful in the context of international growth, organisational changes, corporate transactions or new regulatory requirements. Identified weaknesses, increased operational risks or uncertainties regarding compliance with internal and external requirements may also prompt the need to further develop the system.
Suitable key performance indicators may include, amongst other things, audit results, reported incidents, processing times, training rates and the status of implementation of agreed measures. Regular analysis shows whether compliance with defined requirements is being maintained during normal operations and in which areas operational risks still exist.
Adequacy relates to the design: Are the principles and measures suitable for identifying and preventing the identified risks with reasonable assurance? Effectiveness relates to implementation: Were these principles and measures actually implemented as intended over a defined period? A CMS may be appropriately designed but not effective in practice. Both aspects can be assessed separately and independently verified as part of an audit in accordance with IDW PS 980.