Home / Europe / Germany / Compliance & Forensic Services / Corporate Governance

Corporate Governance

Back to Compliance & Forensic Services

Case Study | Terra incognita?

Companies are entering new compliance territory with the LkSG and HinSchG

The Supply Chain Due Diligence Act (Lieferkettensorgfaltspflichtengesetz – LkSG) and the Whistleblower Protection Act (Hinweisgeberschutzgesetz – HinSchG) are now in force, after a lengthy legislative process. They aim to prevent breaches of human rights and environmental protection legislation in supply chains, and to protect whistleblowers who report abuses. Both laws seek to achieve a more sustainable world by imposing a wide range of demands on compliance departments, management teams and companies as a whole. When the new regulations come to the attention of our clients for the first time, the practical question as to how to implement them is a typical response. The legislation stipulates objectives and (minimum) requirements, but how can they best be incorporated into existing structures? What changes are needed in order to comply with the rules? 

Against this backdrop, our client initially wanted us to explain the exact implications of these laws. The goal was to be in a position to integrate tailored solutions into the company’s day-to-day operations either alone, or with our aid where necessary.

Legal master plan vs reality

The aim of our advice was not to draw up a theoretical master plan that defines the “how” in categorical terms, but rather to be guided by the reality of the company’s situation, to respond to the client’s most urgent needs and to arrange the timeline of measures accordingly. 

One of the first questions facing our client was: Does the LkSG actually apply to us? Answering this question is more difficult than it seems when you look at the details. The LkSG applies to companies above a certain number of employees, but how are they counted in practice? What does the LkSG mean by a “parent company with determinative influence”? Employees of the subsidiaries must be added to the headcount of such companies. Our case did not involve such a parent company, so subsidiaries were not regarded as falling within the sphere of responsibility of the company’s own business activities but are treated instead as suppliers. 

Welcome to the classroom!

The initial assessment was followed by an internal training course, which we conducted as an in-person event for around 15 employees. This was based on the belief that the more informed employees are about the content and requirements of the law, the easier it will be for the company to implement it. The course was also able to serve as a prototype for further training to be offered to the company’s suppliers. A second training session is planned at a later date to deal with the various questions that arise in the meantime.

Appointing a Human Rights Officer

The LkSG provides for a clear allocation of responsibilities and suggests that a Human Rights Officer be appointed. The client’s Compliance team and our lawyers put their heads together to formulate the duties of this position with the necessary clarity and precision and to structure them appropriately. The role is now filled by an internal employee who acts independently and benefits from useful previous experience. Drawing on existing expertise is generally preferable as a compliance method, and in a best-case scenario also leads to synergies by connecting different areas of the company.

At the core: risk analysis

An integral component of LkSG compliance is carrying out an (annual) risk analysis. Risks and any need for action can only be revealed by carefully observing the status quo. A thorough risk analysis requires time and human resources, but is the starting point for many company-internal measures required under the LkSG. With our support, the client developed a process description that sets out the “roadmap” for the LkSG analysis and will be implemented shortly. Here again, it was possible to draw on existing experience within the organisation. It would be difficult for company management to develop the policy statement required by the LkSG without first carrying out this risk analysis. Model statements that make a vague and general commitment to human rights and environmental protection are not fit for purpose and do little to really embed these values in the corporate culture. Accordingly, we assisted our client with drafting the policy statement based on the identified risks that the company and its industry face.

Now is the time…

With a good grounding in the LkSG and a focus on potential risks, the client felt well equipped to ensure compliance with the LkSG by adapting and improving existing compliance tools, such as a business partner checklist. This questionnaire is sent to customers and suppliers, and is part of a balanced LkSG risk management system. A complaints system is also under development to handle reports of LkSG violations. The Compliance and HR departments are now working on raising awareness of LkSG compliance among new employees during the onboarding process. The Code of Conduct for Suppliers is also being adapted with our assistance. CMS acted as advisor in the context of this instruction, responding flexibly to the company’s specific circumstances and needs. We were also able to make several suggestions concerning organisational aspects and wording, as well as reviewing the company’s ideas to ensure they were legally sound. This resulted in a rewarding long-term collaboration that combines legal expertise with practical business aspects. 

A law rarely comes alone

Alongside gearing up for LkSG compliance, our client was faced with the HinSchG, which guarantees whistleblower protection and requires an internal reporting office to be set up. In this case, CMS took on the role of ombudsman/reporting office. As an independent organisation external to the company and with a professional obligation to maintain confidentiality, it is ideally suited to this role. In addition, our client is deploying a digital reporting tool that makes it easier to receive and structure tip-offs. We used a flow chart to summarise the processes in a clear and easy-to-understand way. 

There are an increasing number of (EU) regulations covering the wide field of sustainability compliance. The associated legal environment is also subject to dynamic change (an amendment to the current LkSG, for example, will be triggered at the latest by the EU’s proposed supply chain legislation – the Corporate Sustainability Due Diligence Directive), which will make it necessary to translate (new) legal text into corporate reality on an ongoing basis. This calls for creative solutions from businesses and the law firms that advise them. 


Robust compliance structures are impossible without proper corporate governance.

Are you asking yourself the following questions?

  • Where are the main compliance risks and am I prioritising them correctly?
  • What are the minimum structures I need to create, what (minimum) resources do I have to commit here? And what is best practice in this regard?
  • Are responsibilities (and interfaces) clearly defined and documented?
  • Are internal regulations adequate and clearly understandable?
  • Are my managers committed and well enough trained? 
  • Do my employees apply compliance standards in their daily work and are they aware of the relevant regulations?
  • How do I ensure that regulatory changes at national and international level are adequately monitored, and have I properly implemented the relevant special legislation (LkSG, Whistleblower Protection Act, in future CSRD, CS3D)?
  • How do I implement ESG compliance within the organisation and what options do I have for structuring the compliance management system?

Then you’ve come to the right place!

CMS Germany is your expert for all corporate compliance issues. We provide support both as an outsourced legal department and to complement your own in-house lawyers.

We advise companies across all industries, sectors and legal forms, developing customised solutions. Our service portfolio:

  • Planning, advising on and/or conducting risk analysis 
  • Advice on setting up and improving compliance structures, and on assigning resources appropriately and reasonably
  • Establishing and enhancing the compliance management system, along with developing and implementing the required implementation measures 
  • Preparing responsibility matrices and the associated documentation
  • Developing and revising internal regulations
  • Developing and implementing training programmes for managers and staff
  • Monitoring regulatory changes at national and international level, and advice on implementing the relevant special legislation (LkSG, Whistleblower Protection Act, in future CSRD, CS3D)
  • Advice on all aspects of ESG compliance and on the relevant structuring options, especially with regard to the compliance management system

Contact us!

Write us a message and we will get in contact.

Your message was sent.

Thank you for contacting us. We will get back to you soon.

Please check these fields.

By including your personal data on this form you agree to it being used in accordance with our Privacy Policy

sending...

Feed

15/04/2024
Co-determination in the setup and organisation of whistleblower reporting...
This article deals with the co-determination rights of the works council as regards whistleblower reporting offices in accordance with the German Whistleblower Protection Act (HinSchG).The legislator...
18/03/2024
E-learning | Protection of reporting persons using a whistleblower system
The EU’s Whistleblower Directive (2019/1937) was transposed into national law in Germany by the Whistleblower Protection Act (Hin­weis­ge­ber­s­chutzge­setz, HinSchG). The Whistleblower Protection Act came into effect on 2 July 2023. We have developed an e-learning course for your employees that answers the essential legal and organisational questions relating to the whistleblower protection provided by having a reporting system in place. The course also explains how a whistleblowing system works and encourages staff to report potential issues internally rather than contacting the relevant external reporting office.
18/03/2024
E-learning | Contact with competitors – basic competition law rules
Our e-learning course on dealing with competitors provides our clients with a sound basis for training their employees. This e-learning course guides through the correct conduct under competition law when in contact with competitors.
18/03/2024
E-learning | Open source compliance – basics
This e-learning course teaches the basics of open source compliance. The aim of the course is to raise awareness of the advantages as well as the risks and pitfalls of open source software in all these levels of the company. At the end of the course, solutions to identify risks and avoid them as best as possible through appropriate processes are shown. The e-learning course is aimed at everyone in companies who comes into contact with open source software. This includes not only management but also the IT and development department, purchasing, sales and product management.
18/03/2024
E-learning | Money laundering prevention in industry and trade
This e-learning course was developed specifically for employees and suppliers. It is intended to raise awareness of what must be observed legally to successfully prevent money laundering. As the addressees of the Anti-Money Laundering Act (Geld­wäschege­setz, GwG), companies are obliged to take precautions against their own abuse for money laundering purposes or financing terrorists. The e-learning course takes into account the special position of goods traders in money laundering prevention and can be individually supplemented and modified with regard to the specific risk exposure (especially business activities with high-risk countries, dealing with deviating payers or conspicuous drop shipments).
18/03/2024
E-learning | Open source compliance for software developers
This e-learning course has been specially designed for software developers. Its purpose is to raise awareness of what needs to be considered from a legal viewpoint when software developers use open source software.
18/03/2024
E-Learning | Preventing corruption – basics and practical tips
In a business context, benefits such as gifts and invitations are mainly intended to promote and maintain business relationships. However, using excessive benefits to influence business decisions is not allowed. There is often uncertainty about what is "allowed" and what is "banned" in the business world. Our basic training on corruption prevention educates your employees and provides practical guidance for everyday business that complies with legal requirements.
06/03/2024
ARD Conference of Committee Chairs draws up framework compliance policy...
Munich – The committee chairs of German broadcaster ARD have agreed on a framework policy for members of supervisory bodies. This specifies in more detail the requirements under the relevant interstate treaties and establishes the basis for a common compliance culture across the individual broadcasting councils and administration councils. The policy includes standards of conduct for committee members and rules on dealing with possible conflicts of interest. For greater transparency, members of ARD supervisory bodies are also urged to share information on the Internet about their other roles before and during membership of broadcasting councils and administration councils. The onus is now on the broadcasting councils and administration councils of the ARD stations to implement the recommendations of the ARD Conference of Committee Chairs. They also need to check on a case-by-case basis whether additions need to be made as a result of existing statutory regulations or aspects specific to the particular committee.A CMS team including Dr Harald Potinecke and Laura Posch advised the Conference of Committee Chairs and a working party comprising committee members of all stations on all legal aspects of developing the framework compliance policy. Contacts at CMS Germany Dr Harald Potinecke, Partner Laura Posch, Senior Associate, both CompliancePress Con­tact presse@cms-hs. com
19/01/2024
Greenwashing: Stricter EU rules on environmental marketing ban misleading...
On 17 January 2024, the European Parliament voted to adopt the Directive on Empowering Consumers for the Green Transition (the ECGT Directive), which seeks to protect consumers from various misleading...
19/01/2024
CBAM: Just over a week to comply
As the deadline for the first Carbon Border Adjustment Mechanism (CBAM) report approaches on January 31st, it is crucial for undertakings engaged in importing relevant goods into the European Union to...
19/01/2024
EU Proposals for a Regulation and a Directive on Anti-Money Laundering...
On 18 January 2024, the Council of the European Union and the European Parliament reached a provisional agreement on a part of the new anti-money laundering and counter terrorism financing (“AML/CTF”)...
29/12/2023
Tackling the misuse of crypto-assets for ML-TF purposes
As a constantly evolving sector, the crypto-assets ecosystem presents continuous challenges, particularly in terms of money laundering and terrorist financing (ML-TF) risks.To tackle the misuse of crypto-assets...