
Compliance and Preventive Advisory for Companies and Executives
An effective compliance system is no longer optional — it is an essential component of responsible corporate governance. GLADICA Lawyers develops compliance programmes pursuant to ISO 37301 and IDW PS 980, seamlessly tailored to the legal framework of German and European white-collar criminal law.
Book an AppointmentCompliance Advisory You Can Trust

Compliance Expertise Grounded in Criminal Law
Our compliance work is led by lawyers experienced in white-collar criminal law who know precisely what public prosecutor's offices, regulatory authorities and courts focus on when it counts. The result is systems that are not merely formally correct but also hold up under criminal law scrutiny.
Risk Analysis and Systematic Implementation
Every reliable compliance system begins with a systematic risk analysis. We identify criminal offences and regulatory violations that can realistically become relevant in the context of your business operations and develop targeted control and governance measures according to a clear step model.
Compliance Culture, Training and Management Responsibility
Every system is only as effective as the people who carry it. We develop training concepts for different levels of responsibility and address the tone at the top directly in leadership formats, so that compliance operates not as formalism but as a lived corporate culture.
Prevention Instrument and Strategic Protection at All Levels
At the same time, an effective compliance system represents a central instrument for reducing criminal law risks, administrative fines and personal liability of company officers. Our preventive advisory combines legal precision, operational implementability and strategic foresight. The objective is a system that captures risks in a structured manner, defines responsibilities clearly and can serve as a reliable foundation before authorities and courts when required.
Compliance Advisory in Detail
Our Services at a Glance
We accompany companies from the initial risk analysis through to the ongoing operation of a high-performance compliance management system:
Systematic risk analysis for all business areas and corporate structures
Design and implementation of compliance management systems pursuant to ISO 37301 and IDW PS 980
Development of sector-specific policies, control mechanisms and process documentation
Establishment and implementation of internal reporting systems under the Whistleblower Protection Act (HinSchG)
Anti-corruption programmes taking into account national and international requirements
Competition law compliance and training for key sales functions
Anti-money laundering compliance with identification, monitoring and reporting processes under the GwG
Data protection compliance and implementation of the GDPR in robust processes
Training for executives, compliance officers and employees
Support during compliance audits, certifications and evidentiary documentation
Assistance with business partner reviews (third-party compliance)
Ongoing support as an external compliance function
Legal Framework and Liability Risks Without Compliance
Missing or inadequate compliance structures can give rise to significant legal and economic risks on multiple levels. § 130 OWiG sanctions supervisory duty violations with fines of up to one million euros. In addition, corporate fines can be imposed on companies under § 30 OWiG. Profit recovery under § 17 (4) OWiG substantially increases the economic risk.
Civil law liability risks for managing directors also exist, in particular under § 43 GmbHG and § 93 AktG. A structured compliance organisation can help reduce these risks and document responsibilities in a traceable manner.
Implementation, Culture and Lasting Effectiveness
Every reliable compliance system begins with a systematic risk analysis. We identify criminal offences and regulatory violations that can realistically become relevant in the context of your business operations, assess the likelihood of occurrence and develop targeted control and governance measures on this basis. Implementation follows a clear step model: risk analysis, rulebook, training, controls, monitoring and continuous improvement. Throughout, we ensure operational implementability so that compliance supports business processes rather than impeding them.
Every system is only as effective as the people who carry it. We develop training concepts for different levels of responsibility, precisely tailored to the relevant areas. Compliance messages must be credibly embodied by senior leadership, which is why we address the tone at the top directly in leadership formats. In parallel, we design incentive and sanction systems so that compliant behaviour is rewarded and violations are consistently pursued.
Development of programmes to prevent bribery and the granting of advantages under §§ 299 ff. StGB and §§ 331 ff. StGB, including rules on gifts, invitations and sponsorship.
Prevention of anti-competitive agreements under § 298 StGB and avoidance of cartel fines, which under § 81c (2) GWB can reach up to ten percent of global group turnover.
Implementation of the requirements of the GwG, including risk analyses, due diligence obligations and suspicious activity reports under § 43 GwG as well as enhanced due diligence under § 15 GwG for politically exposed persons.
Implementation of the GDPR, privacy by design under Art. 25 GDPR and structured breach notification processes under Art. 33 and 34 GDPR to avoid fines under Art. 83 GDPR of up to twenty million euros or four percent of global annual turnover.
Implementation and operation of internal reporting offices under the HinSchG, which applies to companies with fifty or more employees. We implement legally compliant reporting channels, train responsible persons and structure case handling to be audit-proof.
Structures to prevent tax law violations under § 370 AO, frequently combined with a tax compliance management system pursuant to IDW Practice Note 1/2016.
Why Clients Trust GLADICA Lawyers
Our compliance work is led by lawyers experienced in white-collar criminal law who know precisely what public prosecutor's offices, regulatory authorities and courts focus on when it counts. We work with discretion, sector-specific expertise and a focus on results, connecting compliance with criminal defence practice and delivering systems that function operationally and hold up under criminal law scrutiny. No mandate is delegated to junior associates.
Highly Specialised Criminal Defence Lawyers
Specialists in white-collar criminal law with extensive experience in complex corporate proceedings.
500+ Five-Star Reviews
Your personal and case information remains strictly protected at all times.
30+ Years of Experience
Urgent legal help whenever you need it, including nights and weekends.
Multilingual Team
Legal representation available in German, English, and additional languages.
Nationwide Representation
Legal representation before all German courts, from local courts to the Federal Court of Justice.
Frequently Asked Questions about Compliance and Preventive Advisory

As soon as a company has multiple employees, customer relationships or public contracts, criminal liability and liability risks arise that cannot be managed without structured compliance. From fifty employees onwards, an internal reporting system under the HinSchG is also mandatory. A well-designed system pays off through reduced sanctions risks, lower recourse exposure and advantages in procurement processes.
§ 130 OWiG sanctions breach of supervisory duties where criminal offences or regulatory violations within the company are facilitated by a lack of oversight. The fine ceiling reaches one million euros and can be higher where the underlying offence was intentional. Demonstrable compliance structures are in practice the most important exculpatory factor against allegations under § 130 OWiG.
ISO 37301 is an internationally recognised, certifiable standard for compliance management systems, while IDW PS 980 is an established German auditing standard for assessing such systems. ISO 37301 defines requirements for design and operation, while IDW PS 980 serves as a benchmark for reviewing adequacy and effectiveness. Both approaches are frequently combined in practice.
Yes. The Federal Court of Justice expressly confirmed in its judgment of 9 May 2017 (ref. 1 StR 265/16) that effective compliance management must be taken into account as a mitigating factor in the imposition of fines. In individual cases, a documented system can be the difference between a substantial fine and a moderate resolution.
The HinSchG requires companies with fifty or more employees to operate an internal reporting office that receives confidential reports, processes them and protects whistleblowers from retaliation. Certain sectors such as financial services providers are subject to this requirement regardless of headcount. We implement legally compliant reporting channels and structure case handling to be audit-proof.
Under § 81c (2) GWB, fines for serious violations can reach up to ten percent of the worldwide total turnover of the group in the preceding financial year. Preventive cartel compliance is therefore one of the most economically effective instruments of risk management.
The leniency programme under §§ 81h to 81n GWB allows, under certain conditions, a full waiver or reduction of cartel fines. The sequence, completeness and quality of information provided are decisive. We assess the conditions confidentially and file the application with the competent cartel authority.
Obligated companies must conduct a risk analysis, implement internal security measures, identify business partners and immediately report suspicious cases to the FIU under § 43 GwG. Enhanced due diligence obligations under § 15 GwG apply in particular to politically exposed persons and high-risk countries. We develop processes that integrate these requirements efficiently and in an audit-proof manner into business operations.
Effective GDPR compliance requires privacy by design under Art. 25 GDPR, clearly documented legal bases for data processing and a record of processing activities. In addition, structured breach notification processes under Art. 33 and 34 GDPR are required. Violations can be sanctioned under Art. 83 GDPR with fines up to twenty million euros or four percent of global annual turnover.
Companies with international exposure are frequently subject to additional regulatory requirements, such as the US Foreign Corrupt Practices Act, the UK Bribery Act or the French Sapin II legislation. These frameworks can, under certain conditions, also apply to German companies. We take these requirements into account when designing a unified compliance system.


