IT Governance and Compliance

    IT obligations at a glance

    By Redaktion techport.ai, IT-Beratung · Last updated on

    The IT related obligations of a mid-sized company today spread across several areas of law and several authorities. Data protection, cyber security, artificial intelligence, retention, electronic invoicing, accessibility, product safety for digital products, plus industry specific requirements. They arose at different times, they have their own deadlines, and in most companies there is no place that keeps the overview.

    The first step is therefore not a project but a list: what applies to us, who owns it, what evidence do we hold, and when is it reviewed again.

    How you notice it

    • A customer question about compliance topics gets answered from scratch every time.
    • It is unclear whether an obligation already applies or has only been announced.
    • Responsibility sits implicitly with IT although the obligation binds the company.
    • Measures are implemented but not documented, and therefore cannot be demonstrated.

    Why this happens

    Obligations arrive one at a time and from different directions. Each is noted individually, usually by whoever reads about it first. There is rarely a place where they are brought together, and even more rarely a date on which someone checks whether anything has changed. On top of that, most obligations have no immediate effect: their absence only shows when a customer asks, an auditor arrives or something happens.

    How we go about it

    1. Collect and assign the obligations. We build a register of the IT related obligations relevant to your company, with legal basis, applicability, deadline and a short description of what has to be done.
    2. Name the owners. We assign every obligation a responsible person, usually outside IT, because the obligation binds the company and not the department. IT delivers the technical implementation.
    3. Close gaps and produce evidence. We check the state of implementation, close gaps in the order of risk and deadline, and make sure every measure leaves evidence behind: a policy, a log, a report or a training record.
    4. Keep it current. We set up a cycle in which the register is reviewed, at least twice a year, and name the sources for changes. A register of obligations without maintenance is misleading rather than helpful after a year.

    What you gain

    • An answer to customer and auditor questions that already exists.
    • Clear ownership instead of an assumption that IT will handle it.
    • An order of measures driven by risk and deadline.

    From our projects

    While building the register it regularly turns out that part of the obligations are already met but without evidence. That applies particularly to technical measures that have been running for years and were never described. The effort to document that state is small compared with the effort of demonstrating it retrospectively during an audit. The second recurring finding concerns ownership: as soon as obligations carry names, priorities shift noticeably, because an abstract topic becomes a personal task.

    Good to know

    Responsibility for compliance sits with management. For a GmbH that follows from Section 43 GmbHG, for a stock corporation from Section 91 AktG. What can be delegated is the execution, not the responsibility for selection, instruction and supervision. Individual regimes sharpen this further: the German BSI Act explicitly obliges management to approve and supervise the risk management measures and provides for personal liability. For companies in the financial sector, DORA sets its own requirements for managing information and communication technology risk that go beyond the general duties.

    Häufige Fragen

    Do we need a dedicated compliance function?

    In most mid-sized companies no. A named person who keeps the register and sets the dates is enough, with input from IT, legal, data protection and tax advisers. More important than the organisational form is that someone holds the task bindingly and that it is allowed for in their working time.

    How do we keep up with new obligations?

    Through a few reliable sources rather than many: publications from the competent authorities, guidance from your industry association or chamber, and the circulars of your legal and tax advisers. In addition, a fixed date twice a year on which the register is reviewed. Without that date, every source is wasted.

    Let us talk about IT obligations at a glance

    In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

    Further reading

    Back to the field IT Governance and Compliance

    Sources