Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
German Companies Keep Making These Compliance MistakesRegulatory Obligations Management
5 min readFor Third-Party Risk Managers

German Companies Keep Making These Compliance Mistakes

Germany's Law to Strengthen Business Integrity introduces criminal liability for companies and allows sanctions up to 10% of worldwide annual revenue for organizations exceeding EUR 100 million in turnover. Yet, many compliance teams are preparing for it the wrong way.

The law marks Germany's first independent criminal statute for corporate sanctions. Until now, you faced administrative fines capped at EUR 10 million. Starting later this year, you're operating in a regime where billion-dollar penalties become possible, and the presence or absence of a compliance management system directly affects your sanction assessment.

Here's what we're seeing teams get wrong as they scramble to prepare.

Why These Mistakes Keep Happening

The draft bill offers almost no guidance on structuring a compliance management system to limit penalties. This silence creates two problems: teams either copy structures from other jurisdictions without adapting them to German requirements, or they freeze, waiting for regulatory clarity that won't arrive before the law takes effect.

The second issue is historical. Many German companies, particularly mid-sized firms, haven't built robust compliance structures because no law previously referenced their value in penalty mitigation. You're now retrofitting programs under time pressure rather than evolving mature systems.

Mistake 1: Treating This as a Documentation Exercise

Your team drafts policies, creates an org chart showing a compliance function, and calls it done. This happens because you're thinking about compliance as a checkbox for regulators rather than as operational infrastructure.

The consequence: When an offense occurs, prosecutors will evaluate whether your compliance management system actually prevented violations or merely existed on paper. A policy library with no evidence of monitoring, training, or enforcement won't reduce your penalty by 50% during cooperation with authorities. It might increase scrutiny.

The fix: Build your system around detection and response, not documentation. Implement transaction monitoring for high-risk processes. Establish a whistleblower hotline with documented intake and investigation procedures. Create training completion records tied to role-based risk profiles. Your compliance management system should generate evidence of activity, not just statements of intent.

Mistake 2: Ignoring Foreign Subsidiaries in Your Risk Analysis

You focus compliance resources on German operations while treating foreign subsidiaries as separate risk domains. This happens because you're reading the law as a domestic statute rather than as extraterritorial enforcement.

The consequence: The draft bill allows sanctions against German-based companies for offenses committed abroad if the act would be criminal under German law and is punishable where it occurred. Your subsidiary's bribery of officials in a market with weak enforcement still exposes your German parent to sanctions up to 10% of consolidated worldwide revenue.

The fix: Conduct a compliance risk analysis that maps criminal exposure across all jurisdictions where you operate. Identify where local law criminalizes conduct that German law also prohibits. Extend your compliance management system to those subsidiaries with controls proportionate to the German exposure they create. For high-risk markets, implement enhanced due diligence on third-party intermediaries and dual approval requirements for sensitive transactions.

Mistake 3: Underestimating the "Absence of Compliance" as a Criminal Offense

You view compliance systems as penalty mitigation tools, not as legal obligations. This happens because you're thinking about the law's sanctions framework without reading its criminal provisions.

The consequence: The draft bill makes the absence of a compliance management system a punishable criminal offense when committed by persons with management authority. You're not just risking higher fines for underlying violations. You're creating direct criminal liability for executives who fail to establish compliance structures.

The fix: Document a board-level decision establishing your compliance management system, including scope, resources, and reporting lines. Ensure your system addresses the company's specific risk profile rather than generic templates. Create evidence that management exercised reasonable judgment in designing the system, even if that system later proves inadequate. This shifts the question from "Did you have compliance?" to "Was your compliance reasonable given known risks?"

Mistake 4: Preparing for Penalties Without Preparing for Investigations

You build controls to prevent offenses but don't establish protocols for internal investigations. This happens because you're focused on the law's sanctions framework rather than its cooperation provisions.

The consequence: The draft bill allows penalty reductions up to 50% for companies that cooperate with law enforcement during preliminary investigations, but the conditions are strict. If an offense occurs and you can't quickly marshal evidence, interview witnesses, and assess scope, you'll forfeit the cooperation discount. Worse, a chaotic investigation creates liability for obstruction or evidence tampering.

The fix: Establish an internal investigation protocol now. Identify external counsel who can lead investigations involving potential criminal exposure. Create document preservation procedures that trigger automatically when you detect potential violations. Train your legal and compliance teams on interview techniques and evidence handling. Designate a single point of contact for law enforcement inquiries. You won't have time to build this infrastructure after discovering an offense.

Mistake 5: Treating Small and Medium-Sized Companies Differently

Your compliance program scales resources based on company size, giving smaller entities minimal systems. This happens because you're applying a risk-based approach without understanding how the law calculates sanctions.

The consequence: While the 10% revenue sanction applies only to companies exceeding EUR 100 million in turnover, the law's other provisions, criminal liability for compliance absence, profit disgorgement up to 100%, and publication of convictions, apply regardless of size. A EUR 50 million company faces reputational destruction from public sanctions and complete profit forfeiture even if it avoids the percentage-based fine.

The fix: Establish minimum compliance standards that apply across your organization regardless of size. Every entity needs a risk analysis, a whistleblower channel, and documented training. Scale the sophistication of controls to risk, not to revenue. A small subsidiary handling government contracts needs stronger anti-corruption controls than a large subsidiary selling commodity products to private buyers.

Prevention Checklist

Before the law takes effect, complete these actions:

  • Conduct a compliance risk analysis covering all jurisdictions where you operate, identifying criminal exposure under both local and German law
  • Document a board resolution establishing your compliance management system, including scope, budget, and reporting structure
  • Implement role-based compliance training with completion tracking and periodic refreshers
  • Establish a whistleblower hotline with documented intake, investigation, and resolution procedures
  • Create an internal investigation protocol identifying external counsel, preservation procedures, and law enforcement contact procedures
  • Extend compliance controls to foreign subsidiaries based on the German criminal exposure they create, not their local regulatory environment
  • Implement transaction monitoring for high-risk processes with documented escalation procedures
  • Establish a policy exception registry to track and remediate control gaps
  • Create evidence that your compliance management system reflects your specific risk profile, not a generic template
  • Designate executive ownership for compliance system effectiveness, not just compliance function management

The law eliminates the distinction between having compliance and having effective compliance. Your system either generates evidence of prevention, detection, and response, or it becomes evidence of negligence.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like