Back to Germany Rankings

Germany: A Compliance Overview

Introduction

The German compliance landscape in 2026 and beyond is defined by one clear theme: simplification on paper, greater scrutiny in practice.

There is a genuine political push to reduce regulatory burden. At EU level, the Omnibus simplification packages are intended to streamline parts of the sustainability and technology-related reporting framework. In Germany, the creation of the Federal Ministry for Digital Transformation and Government Modernisation signals a broader commitment to cutting bureaucracy and modernising administration.

For companies, however, this does not mean a lighter compliance environment. In our work with boards, audit committees and global compliance functions, we see a different reality emerging. The focus is shifting from formal reporting obligations to the effectiveness of compliance in practice. Regulators, prosecutors, auditors and other stakeholders increasingly ask a simple question: not only “Do you have the right policies?” but, more importantly, “Do they work?”.

That shift is critical. It means that companies must be able to demonstrate that their compliance systems are embedded in the business, tested, documented and capable of withstanding scrutiny. Paper programmes are no longer enough. What matters is governance, accountability, escalation, evidence and the ability to show that controls operate effectively when pressure is applied.

In practice, this means a two-speed compliance environment: formal reporting obligations may be streamlined in some areas, but expectations around governance, controls, documentation and demonstrable effectiveness continue to rise. Across the market, the direction is clear: compliance is becoming less about form and more about proof.

That is the lens through which we assess the German compliance outlook – and the following sections identify the areas we consider most important for companies operating in Germany.

ESG

The simplification agenda is most visible in sustainability regulation. At EU level, the Omnibus I package adopted in early 2026 narrowed the scope of the Corporate Sustainability Reporting Directive (CSRD), including by raising the employee threshold from 250 to 1,000 and reducing the data requests that had been cascading down to smaller companies. The Corporate Sustainability Due Diligence Directive (CSDDD) has also been scaled back compared with its original design.

Germany has moved in the same direction. In September 2025, standalone reporting obligations under the Supply Chain Due Diligence Act were removed, while the core due diligence obligations remained in place.

From our perspective, this is recalibration, not retreat. ESG compliance is not disappearing; it is becoming more focused. Companies that remain in scope of the CSRD will still need to report, while companies subject to supply chain and human rights due diligence obligations under the CSDDD will still need functioning risk assessment, prevention, remediation and documentation processes. At the same time, enforcement of existing obligations continues. The message is clear: ESG compliance may become less burdensome for some companies at the reporting level, but expectations around substance, controls and evidence remain high. Companies should not treat simplification as permission to slow down.

Sanctions and Export Control

Sanctions and export control show the opposite trend – markedly more complex with each successive round of EU measures, particularly in relation to Russia. The most important shift, however, is not only the volume of new rules. It is the change in enforcement focus. Authorities are no longer satisfied with the formal existence of sanctions and export control policies. They are looking at whether those policies work in practice. In Germany, customs authorities and prosecutors have intensified their focus on:

  • circumvention through third-country structures;
  • re-export risks;
  • end-use and end-user verification;
  • intermediary and distributor arrangements; and
  • the actual transaction flows behind the contractual documentation.

From our perspective, this is one of the clearest examples of the broader compliance trend: paper controls are not enough. A sanctions policy that has not been tested against real transaction flows, third-party structures and high-risk jurisdictions provides limited protection when challenged by authorities.

The message is straightforward: sanctions and export control compliance must be operational, risk-based and evidence-led. Companies need to know not only who they are contracting with, but where products go, who ultimately uses them and whether the commercial structure creates circumvention risk. That requires strong screening, robust contractual safeguards, clear escalation channels and documented end-use controls.

Data and AI

Data protection and artificial intelligence follow the same pattern: limited simplification at the margins but increasing complexity in substance.

The EU AI Act is now entering phased implementation. Certain prohibited AI practices have already taken effect, with further obligations for high-risk AI systems to follow. The challenge for companies is not only the content of the new rules. It is also the uncertainty around enforcement. The supervisory architecture remains unsettled, with potentially overlapping responsibilities at EU and national level and the final allocation of competences still developing.

At the same time, German data protection authorities continue to apply the GDPR strictly. Enforcement activity remains high, and data protection issues increasingly arise in parallel with AI governance, cybersecurity, employment, investigations and customer-facing digital products.

From our perspective, the key issue is the accumulation of obligations. The proposed EU Digital Omnibus package may simplify certain aspects of European technology regulation, including parts of the AI Act. But it does not change the direction of travel. Companies deploying AI systems will still need to:

  • classify AI use cases by risk;
  • implement clear governance and accountability structures;
  • maintain technical and compliance documentation;
  • ensure appropriate human oversight;
  • manage data protection and cybersecurity risks; and
  • evidence that AI systems are monitored and controlled in practice.

The message is clear: AI governance cannot be left to technology teams alone. It requires ownership at management level, clear risk classification, legal and compliance input at the design stage, and documented controls throughout the lifecycle of the system. As with other areas of compliance, the question will not be whether a policy exists, but whether the company can show that AI and data risks are understood, governed and controlled.

AML

AML is another area where the compliance burden is increasing, not decreasing.

At EU level, the new Anti-Money Laundering Authority (AMLA) began operations in Frankfurt in mid-2025 and is preparing to directly supervise 40 high-risk financial institutions, to be selected by 2027. Direct supervision is expected to begin in 2028, once AMLA is fully operational. AMLA may also assume supervision of other obliged entities at the request of a national regulator or where this is necessary to safeguard EU interests. In addition, it will strengthen co-operation between national Financial Intelligence Units (FIUs).

For German banks and financial institutions, this adds another supervisory layer alongside the ECB, Bafin and the Bundesbank. The practical consequence is clear: AML compliance will be subject to more co-ordinated, more data-driven and more intrusive scrutiny.

The domestic enforcement environment points in the same direction. Bafin has continued to use its sanctioning powers actively, including a record EUR45 million fine imposed on a major bank in late 2025 for persistent AML deficiencies. At the legislative level, Germany’s new Money Laundering Reporting Ordinance (GwGMeldV), effective from March 2026, codifies strict requirements for submitting suspicious activity reports through the official electronic platform. Failure to comply may result in administrative fines.

From our perspective, AML is becoming a board-level control issue. The focus is no longer only on whether an institution has AML policies and procedures. Supervisors now expect evidence that transaction monitoring, customer due diligence, escalation, SAR filing and remediation processes operate effectively in practice.

The message is straightforward: AML frameworks must be demonstrably effective, properly resourced and capable of withstanding supervisory review. Institutions should expect greater scrutiny of governance, data quality, alert handling, escalation discipline and remediation follow-through. This will become even more important in light of the expected corporate liability reforms, which would materially increase potential penalties.

Corporate Liability

Corporate liability is the area where the German debate may change most visibly.

Germany still does not recognise corporate criminal liability in the strict sense. Companies can, however, face administrative fines for misconduct committed by managers or employees. Historically, the maximum corporate fine has generally been EUR10 million, subject to disgorgement of economic benefits. This framework is now under renewed political and legislative pressure.

In April 2026, the federal government introduced draft legislation to transpose the EU Environmental Crimes Directive. Although the draft primarily concerns environmental offences, it would amend Germany’s broader corporate liability regime. Most importantly, it would raise the maximum administrative fine for corporate entities from EUR10 million to EUR40 million for intentional offences. If enacted, that higher threshold would not be limited to environmental cases. It would apply across the corporate liability framework.

Equally important is the proposed codification of corporate sentencing criteria. Authorities would be required to consider, expressly and systematically, a company’s compliance efforts and cooperation. This would include the existence and effectiveness of compliance management systems as well as voluntary internal investigations.

From our perspective, this would be a material development. For the first time, German law would formally recognise that robust compliance structures and credible internal investigations can mitigate corporate penalties. The value of a well-conducted investigation would no longer depend primarily on prosecutorial discretion. It would become part of the statutory framework for assessing penalties.

This reflects a broader European trend. New EU instruments, including the planned Anti-Corruption Directive, increasingly require member states to take account of preventive compliance programmes, self-disclosure and co-operation when determining corporate sanctions.

The message is clear: compliance systems and internal investigations are becoming even more consequential. If the reform is enacted, companies operating in Germany will face higher potential penalties, but also clearer legal credit for strong prevention, early detection, co-operation and remediation. The quality of the compliance framework – and the quality of the response when issues arise – will matter more than ever.

Conclusion

Germany’s regulatory environment is being reorganised, not deregulated.

Some reporting obligations are being streamlined, but the underlying compliance architecture remains firmly in place. The number of relevant frameworks, the complexity of their interaction and the breadth of substantive obligations remain significant.

For compliance and legal functions, as well as boards, this means recalibration, not retreat. The focus is shifting from the formal existence of policies and reports to demonstrable effectiveness: governance, controls, documentation, escalation and evidence that systems work in practice.

At the same time, the direction of corporate liability reform is clear. Strong compliance systems, credible internal investigations, co-operation and remediation are increasingly likely to receive formal recognition when sanctions are assessed.

The advantage will therefore lie with companies that adapt early – not by doing less, but by making compliance more focused, more operational and more capable of withstanding scrutiny.