Compliance & Investigations.
Compliance management, internal investigations and crisis advisory — pragmatic, audit-proof and partner-led.
Context
Prevention is less expensive.
Compliance is not a bureaucratic issue — in a crisis, it determines fines, reputation, and personal liability. Good compliance is invisible in day-to-day business and resilient in a crisis.
We design, review and defend compliance systems for mid-sized companies, groups and private equity portfolio companies — and investigate incidents confidentially.
Scope of services
What we take care of for you.
01
Compliance management systems
Set-up, assessment and optimisation in accordance with IDW PS 980 and ISO 37301.
02
Internal investigations
Discreet fact-finding in suspected cases — documented in a manner admissible in court.
03
Sanctions & export controls
EU sanctions, embargoes, BAFA proceedings, screening processes.
04
Anti-money laundering
GwG obligations, KYC, training, MaRisk and MaComp.
05
Supply chain due diligence
LkSG risk analysis, complaints mechanisms, reporting.
06
Whistleblowing system
HinSchG-compliant set-up and case handling.
Who we work for
Clients seeking clarity.
- Mid-sized companies
- subsidiaries of corporate groups
- PE portfolio companies
- Board members and managing directors
- Compliance officers
- Supervisory and advisory boards
Our approach
How we work.
Practical
Compliance must work in day-to-day business. We develop solutions that are accepted, understood and put into practice.
Preventive
We establish early-warning systems that identify risks at an early stage and prevent escalation before it arises.
Liability-focused
We create structures that effectively relieve management, the executive board and supervisory bodies and minimise personal liability risks.
Robust
We design processes, policies and documentation so that they stand up to regulators, public prosecutors and courts.
Process
From the initial conversation to completion.
I
Risk Assessment
Risk map, gap analysis, prioritisation.
II
Design
Policies, processes, controls.
III
Implementation
Training, tools, communication.
IV
Monitoring
Audits, reporting, improvement.
V
Response
Investigation, sanction, remediation.
Insights
Clarity in just a few minutes.
Compliance management, internal investigations and crisis advisory, partner-led.



FAQ
Frequently asked questions.
Do you have a specific question? We will respond within 24 hours.
What is meant by compliance in a corporate context?
Compliance refers to a company and its employees adhering to legal requirements, internal policies and ethical standards in order to avoid risks such as fines, liability or reputational damage.
Which areas of law does compliance typically cover?
Relevant areas include, among others, anti-corruption and anti-bribery, competition, data protection, antitrust law, employment law, export controls, anti-money laundering and IT/data security.
Why is compliance not only a legal issue, but also a management responsibility?
Compliance affects internal structures, decision-making processes and corporate culture; it requires operational implementation, training, controls and regular adjustments to new risks or regulations.
When should a company introduce a compliance management system (CMS)?
A CMS should be introduced as soon as legal risks, headcount, business processes or international activities create an increased risk exposure — i.e., early on, to minimise liability risks.
What are typical components of an effective compliance management system?
Key components include: risk assessment, policies & codes, training, reporting channels (speak-up), monitoring and audit, sanction mechanisms, incident investigations, and continuous improvement.
What is a compliance risk assessment and why is it important?
A compliance risk analysis identifies and assesses risks in business processes, products or markets in order to prioritise preventive measures in a targeted manner and use resources efficiently.
Who should be responsible for compliance in a company?
Typically, compliance is led by a Chief Compliance Officer (CCO) or a compliance function within the executive board/management, supported by functional owners in the specialist departments.
What is the difference between compliance and an internal control system (ICS)?
Compliance relates to law and integrity, while an ICS ensures the reliability of financial reporting and proper business processes. Both systems are complementary, but differ in purpose and focus.
Why does compliance need to be embedded organisationally within the company?
Only if responsibilities, resources and escalation paths are formally defined can compliance function sustainably and not remain a “brand” without impact.
What is a compliance code (code of conduct)?
A compliance code is a binding set of ethical principles and rules of conduct that apply to all employees, e.g., on conflicts of interest, gifts, benefits or data processing.
How are compliance policies communicated and implemented effectively?
Compliance policies must be clear, accessible and trained on regularly; in addition, evidence of participation and understanding is required (training certificates, e-learning).
Why are whistleblowing and reporting systems central to compliance?
Reporting systems enable employees to report unlawful conduct or risks anonymously or in a protected manner before they escalate into significant harm. They are an early-warning and protection mechanism.
What legal requirements apply to whistleblowing systems?
Whistleblowing systems must ensure confidentiality, protection against retaliation and traceable case handling; in the EU, there are minimum standards for this (Whistleblower Directive).
What consequences can arise from compliance violations?
Consequences may include: fines, criminal and civil liability risks for the company and responsible individuals, reputational damage, contractual penalties or competitive disadvantages.
What does “compliance enforcement” mean and how is it ensured?
Compliance enforcement means identifying violations, investigating them and sanctioning them consistently, as well as implementing lessons learned. This is done through monitoring, internal audits, case analyses and disciplinary measures.
What are internal investigations and when are they conducted?
Internal investigations are structured fact-finding exercises within a company, conducted when there are indications of possible compliance violations, breaches of duty, potentially criminal conduct or other irregularities. They serve internal clarification and risk management.
What objectives do internal investigations typically pursue?
Objectives include, in particular, establishing the actual facts, legally assessing potential violations, preparing remedial measures, and reducing liability, sanctions and reputational risks vis-à-vis authorities, business partners and shareholders.
What role does data preservation play in internal investigations?
Early and structured preservation of relevant data is essential to secure evidence and prevent manipulation or data loss. This includes, in particular, emails, files, chats, server and cloud data, as well as mobile devices.
How is information collected and analysed in a legally compliant manner?
The collection and analysis of information in the context of internal investigations must always comply with employment law, data protection law, personal rights and other third-party rights. It must be reviewed on a regular basis which data may be collected, analysed and disclosed, and in what form. Whether and to what extent findings can be used procedurally is always assessed on a case-by-case basis. The question of admissibility of evidence is therefore not a downstream step; it is anticipated already when designing and conducting the investigation, in order to minimise later risks of inadmissibility and to comply with legal limits. In practice, it may be necessary to redact documents or communication content to exclude irrelevant or particularly sensitive information (e.g., private content, third-party references or personal data of uninvolved persons). The handling of audio or sound recordings is also particularly sensitive, as their collection and use may be legally problematic.
When is it advisable to involve external forensic and investigation partners — in particular for “asset location / asset tracing” and enforcement?
In complex commercial disputes and internal investigations, the file record alone is often insufficient because key information lies outside the company’s own systems or assets are deliberately “moved.” In such cases, involving specialised forensic and investigation partners is particularly advisable — for example, for data preservation and analysis (e.g., forensic imaging, analysis of large volumes of communications and documents) and for asset location / asset tracing (locating assets, reconstructing ownership and control structures, identifying beneficial persons or target jurisdictions). Especially in cross-border constellations, asset tracing can also clarify strategically whether proceedings are economically worthwhile, where claims can be enforced most effectively, and how subsequent enforcement of a judgment or arbitral award can actually be achieved (e.g., through asset discovery, ownership evidence, preparation of interim measures). For this reason, in relevant cases we work with a network of proven forensic and investigation specialists and closely integrate this work into the legal strategy — from early risk and enforceability analysis through to contentious enforcement and execution.
How are large volumes of data analysed in the context of internal investigations?
For extensive datasets, technical analysis tools and AI-supported software solutions are increasingly used to help identify relevant content efficiently, detect patterns and set priorities.
What advantages does the use of AI software offer in internal investigations?
AI-supported systems enable faster, structured and traceable analysis of large volumes of data, reduce manual review and support focusing on relevant documents and communication threads.
How are the results of internal investigations used?
The results serve as a basis for internal measures, such as organisational adjustments, employment-law steps or compliance improvements, and may also be relevant for communication with supervisory or law enforcement authorities.
Compliance that holds up.
Contact us — we will analyse your situation and develop pragmatic solutions that stand up when it matters.
