# IT compliance in the mid-market: know the obligations, assign them, evidence them

> Which IT related obligations affect your company, who owns them, which evidence is needed and how a register of obligations gets you prepared for every audit.

URL: https://techport.ai/en/it-beratung/it-governance-und-recht/it-compliance

---

1.  [IT Consulting](/en/it-beratung)/
2.  [IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)/
3.  IT obligations at a glance

[IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)

# IT obligations at a glance

By Redaktion techport.ai, IT-Beratung · Last updated on 21 August 2026

The IT related obligations of a mid-sized company today spread across several areas of law and several authorities. Data protection, cyber security, artificial intelligence, retention, electronic invoicing, accessibility, product safety for digital products, plus industry specific requirements. They arose at different times, they have their own deadlines, and in most companies there is no place that keeps the overview.

The first step is therefore not a project but a list: what applies to us, who owns it, what evidence do we hold, and when is it reviewed again.

## How you notice it

*   A customer question about compliance topics gets answered from scratch every time.
*   It is unclear whether an obligation already applies or has only been announced.
*   Responsibility sits implicitly with IT although the obligation binds the company.
*   Measures are implemented but not documented, and therefore cannot be demonstrated.

## Why this happens

Obligations arrive one at a time and from different directions. Each is noted individually, usually by whoever reads about it first. There is rarely a place where they are brought together, and even more rarely a date on which someone checks whether anything has changed. On top of that, most obligations have no immediate effect: their absence only shows when a customer asks, an auditor arrives or something happens.

## How we go about it

1.  **Collect and assign the obligations.** We build a register of the IT related obligations relevant to your company, with legal basis, applicability, deadline and a short description of what has to be done.
2.  **Name the owners.** We assign every obligation a responsible person, usually outside IT, because the obligation binds the company and not the department. IT delivers the technical implementation.
3.  **Close gaps and produce evidence.** We check the state of implementation, close gaps in the order of risk and deadline, and make sure every measure leaves evidence behind: a policy, a log, a report or a training record.
4.  **Keep it current.** We set up a cycle in which the register is reviewed, at least twice a year, and name the sources for changes. A register of obligations without maintenance is misleading rather than helpful after a year.

## What you gain

*   An answer to customer and auditor questions that already exists.
*   Clear ownership instead of an assumption that IT will handle it.
*   An order of measures driven by risk and deadline.

## From our projects

While building the register it regularly turns out that part of the obligations are already met but without evidence. That applies particularly to technical measures that have been running for years and were never described. The effort to document that state is small compared with the effort of demonstrating it retrospectively during an audit. The second recurring finding concerns ownership: as soon as obligations carry names, priorities shift noticeably, because an abstract topic becomes a personal task.

## Good to know

Responsibility for compliance sits with management. For a GmbH that follows from Section 43 GmbHG, for a stock corporation from Section 91 AktG. What can be delegated is the execution, not the responsibility for selection, instruction and supervision. Individual regimes sharpen this further: the German BSI Act explicitly obliges management to approve and supervise the risk management measures and provides for personal liability. For companies in the financial sector, DORA sets its own requirements for managing information and communication technology risk that go beyond the general duties.

## Häufige Fragen

Do we need a dedicated compliance function?

In most mid-sized companies no. A named person who keeps the register and sets the dates is enough, with input from IT, legal, data protection and tax advisers. More important than the organisational form is that someone holds the task bindingly and that it is allowed for in their working time.

How do we keep up with new obligations?

Through a few reliable sources rather than many: publications from the competent authorities, guidance from your industry association or chamber, and the circulars of your legal and tax advisers. In addition, a fixed date twice a year on which the register is reviewed. Without that date, every source is wasted.

## Let us talk about IT obligations at a glance

In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.

[Arrange an initial call](/en/kontakt)[Our consulting](/en/so-funktionierts)

## Further reading

[Security and ResilienceNIS2 and cyber securityWhether your company falls under the new German BSI Act, which duties follow, how risk management, reporting and supply chain are implemented, and what applies personally to management.](/en/it-beratung/sicherheit-und-resilienz/nis2-und-cybersicherheit)[IT Governance and ComplianceImplementing data protection technicallyGDPR put into practice: technical and organisational measures, processor agreements, records, deletion concept, log data, third country transfers and handling data breaches.](/en/it-beratung/it-governance-und-recht/datenschutz-in-der-it)[Security and ResilienceBuilding information securityAn information security management system that fits your size: scope, risks, policies, evidence and the route to certification when customers require it.](/en/it-beratung/sicherheit-und-resilienz/isms-und-zertifizierung)[KnowledgeIT regulatory radarWhat applies, what is coming, what to do now.](/en/it-beratung/regulatorik-radar)[KnowledgeIT maturity checkKnow where your IT stands in ten minutes.](/en/it-beratung/reifegrad-check)

Back to the field [IT Governance and Compliance](/en/it-beratung/it-governance-und-recht)

## Sources

*   [Section 43 GmbHG, liability of managing directors (in German)](https://www.gesetze-im-internet.de/gmbhg/__43.html)
*   [Section 91 AktG, organisation and accounting (in German)](https://www.gesetze-im-internet.de/aktg/__91.html)
*   [Section 38 BSIG, information and approval by management (in German)](https://www.gesetze-im-internet.de/bsig_2025/__38.html)

Rt

Written by

[Redaktion techport.ai](/ueber-uns), IT-Beratung

Mehr als 15 Jahre Erfahrung in IT-Projekten des Mittelstands, Auswahl und Einführung von Unternehmenssoftware, Aufbau von IT-Betrieb und Informationssicherheit in wachsenden Organisationen.

This page reflects the position at the date given and does not replace legal advice. For specific questions we work together with your legal advisers.

[More about us](/en/ueber-uns)

More from techport.ai

[

Software

Custom process software for mid-sized companies.

](/en/loesungen)[

HR consulting

People processes and the systems behind them.

](/en/hr-beratung)[

IT maturity check

Ten minutes to a clear position.

](/en/it-beratung/reifegrad-check)[

HR maturity check

24 statements, a result per field.

](/en/hr-beratung/reifegrad-check)[

Funding

BAFA grant plus more than 50 programmes for delivery.

](/en/foerderung)[

Process in practice

How workflows become reliable software.

](/en/sop-praxis)[

Data and AI

Analysis, forecasts and assistance systems.

](/en/daten-ki)[

About us

The people behind techport.ai.

](/en/ueber-uns)
