Skip to main content

      Until now, the fulfilment of regulatory requirements has been at the forefront of compliance activities. The constantly growing regulatory requirements and increased expectations of supervisory bodies have steadily expanded the remit of compliance in recent years. At the same time, business models are becoming more digital, risk profiles are changing and the collection of big data is changing the information base - in other words, the digital transformation is in full swing.

      Focusing on the value contribution of individual compliance services

      And this has now also arrived in compliance. The self-image of the compliance organisation is changing towards a value-oriented approach that efficiently focuses on the value contribution of individual compliance services. The prerequisite for this transformation is a value and results-oriented analysis of services in conjunction with the digitalisation of key compliance services and a clear idea of their strategic direction.

      In order to drive this transformation forward, a deep understanding of the organisation, business models and processes is required, along with expert knowledge of complex compliance issues and processes. A modern compliance management system must be able to react agilely and flexibly to permanent changes, is constantly in the process of further development and confidently addresses the issue of value contribution within an organisation.

      Our range of services

      First of all, we evaluate your compliance function using a maturity model and analyse the value contribution of individual compliance services in terms of risk mitigation, the time they take, their agility and flexibility with regard to new compliance-relevant issues and, last but not least, the extent to which they are in line with your overall strategy and culture. As part of this analysis, we look at your entire compliance organisation and identify potential for optimisation through, for example, digitalisation or the bundling of compliance activities.

      With innovative solutions, technology and an interdisciplinary team, we implement your compliance strategy and equip you for the challenges of tomorrow.

      Your contacts 

      Dr. Jan-Hendrik Gnändiger

      Partner, Audit, Global & EMA ESG Reporting Advisory Lead, Head of ESG Germany, Head of Sustainability Reporting & Governance Germany

      KPMG AG Wirtschaftsprüfungsgesellschaft

      Eun-Hye Cho

      Partner, Audit, Regulatory Advisory, Sustainability Reporting & Governance

      KPMG AG Wirtschaftsprüfungsgesellschaft

      A compliance strategy with clear priorities

      A robust compliance strategy links a company’s individual risk profile with its business objectives and the expectations of relevant stakeholders. The starting point is a structured risk assessment: What regulatory, organisational and business-specific risks exist? What are the likelihood of occurrence and potential impacts? And what measures are required to manage these risks appropriately?

      On this basis, the compliance strategy defines the services provided by the compliance function, how resources are allocated and what responsibilities apply. KPMG supports companies in formulating strategic guidelines and translating them into an actionable portfolio of services. In doing so, KPMG considers regulatory obligations, the results of risk assessments and requirements arising from the organisation, business model and corporate culture as a whole.

      Embedding compliance transformation in the operating model

      A compliance transformation is effective when it is reflected in the organisation’s roles, processes and interfaces. This requires a Target Operating Model that defines responsibilities between Compliance, Legal, Risk Management, Internal Audit, IT, Human Resources and operational units.

      KPMG supports companies in structuring this governance framework and develops decision-making powers, escalation procedures and cooperation models. The allocation of responsibilities to central, decentralised or international units is also taken into account. An open culture of communication helps to convey compliance requirements clearly, address concerns at an early stage and strengthen a sense of responsibility within the organisation.

      Steering through data and meaningful key performance indicators

      A modern compliance strategy requires a robust information base. Key performance indicators relating to risk assessment, controls, reports, investigations, training and policies highlight trends and support well-informed management decisions. This requires standardised definitions, clear accountability for data and transparent reporting channels.

      KPMG provides support in selecting appropriate performance and risk indicators, as well as in developing dashboards tailored to specific audiences. This enables organisations to continuously assess the effectiveness of their compliance function, identify deviations at an early stage and prioritise measures in a targeted manner.

      From strategy to successful implementation

      For the implementation, KPMG develops a prioritised roadmap setting out specific measures, dependencies, responsibilities and milestones. Pilot schemes and phased implementation stages make it possible to test new roles and processes initially in selected areas and subsequently roll them out across the entire organisation.

      Active change management supports the compliance transformation. Communication, training and the involvement of relevant stakeholder groups promote acceptance of new ways of working. At the same time, a consistent communication culture helps to embed the vision within the organisation on a long-term basis.

      Frequently asked questions

      A compliance strategy defines the target state, priorities and service portfolio of the compliance function. It links the results of the risk assessment to the company’s business objectives, responsibilities and resources.

      Risk assessment provides transparency regarding relevant compliance risks and their potential impacts. This enables organisations to prioritise measures, allocate resources in a risk-based manner and align their compliance strategy with their actual risk profile.

      To begin with, the current situation, the risk assessment and the strategic objectives are analysed. This is followed by the design of the future operating model, the development of a roadmap and the phased implementation of new roles, processes and control mechanisms.

      An open communication culture makes it easier for staff to raise questions, address uncertainties and report potential breaches at an early stage. It helps organisations to embed compliance as a shared responsibility and to communicate changes in a transparent manner.

      A compliance target operating model describes how a company’s compliance function is organised and managed. It encompasses tasks, responsibilities, decision-making authority, interfaces, competencies, technology and the allocation of resources.

      Successful implementation requires clear responsibilities, realistic implementation steps and measurable milestones. Pilot schemes, training, communication and the early involvement of affected departments support the long-term transition to routine operations.