Effectiveness becomes law: The planned reform of Sec. 30 und 130 OWiG

Why legislators are re-evaluating preventive compliance – and why companies should no longer put off addressing the question ‘Is our compliance management system effective?’

Some reforms announce themselves loudly – and leave again. The German “Verbandssanktionengesetz“, which intended to establish a fundamental restructuring of corporate sanctions, is the most prominent example for it: discussed over two legislative terms but failed in the end. Other reforms come quiet. They hide themselves in draft bills, whose titles suggest something completely different – and change the rules for almost every company located in Germany.

That’s exactly what is currently happening. The previously in May 2026 submitted government bill for the implementation of EU environmental criminal law guidelines[1], holds environmental criminal law as a title – but contains a fundamental revision of Sec. 30 of the Act on Regulatory Offences (Gesetz über Ordnungswidrigkeiten – “OWiG”), the core principle of German corporate sanctions. The maximum amounts of the association fines are supposed to quadruple themselves. Firstly, calculation of the amount of an administrative fine is supposed to be regulated by law – and the quality of the Compliance-organization is explicitly a part of it. The federal council wants to go further and establish the basic elements of a suitable Compliance Management System in law.[2]

At first, it seems like a technical adjustment, taking a closer look, it is a change of paradigm. The effectiveness of Compliance changes from a weak argument put forward by the defense, to a strict legal term. For companies this raises a question newly and with legal emphasis: not „do we have a Compliance Management System? “, but „Does it work? “

The most important points briefly:

  • What happened: The government draft on the realization of the EU environmental criminal law guideline (BT-Drs. 21/6133) raises the maximum amount of the association fine under Sec. 30 OWiG from 10 to 40 million euros and for the first time implements legal criteria for its calculations – explicitly including Compliance precautions by the companies.
  • Who is affected: All companies – the new regulations do not apply to environmental crimes, but for all actions that can be attributed to the companies under Sec. 30 OWiG.
  • What matters: Not the existence, but the effectiveness of the Compliance Management Systems becomes legally relevant. The most important thing to consider is under Sec. 130 OWiG: Effective supervisory measures prevent liability before it arises.
  • What to do now: Assessment with a focus on effectiveness, create verifiability and integrate the management – as long as the legislative process still contains a scope for configuration.

A reform through the side entrance: From environmental law to general corporate sanctions law

The impulse for the reform is European: The Directive (EU) 2024/1203 requires the EU member countries, to significantly expand the criminal law protection of the environment – with expanded offenses and substantial penalties also against companies.[3] The German legislature is using the implementation as an opportunity to take a step that goes far beyond environmental criminal law: The increase in maximum fines and the new rules for calculating fines under Sec. 30 OWiG-E not only apply for environmental offenses, but to all related offenses – including all crimes and administrative offenses, that can be attributed to a company under Sec. 30 OWiG. This includes classics of White-Collar Crime law like corruption, infidelity, tax evasion, money laundering or prohibitions on sanctions.[4]

This regulatory approach has significant consequences: While a public debate about environmental criminal law is taking place, general corporate sanctions are getting tightened and structured by law. Anyone who categorizes the reform solely under the heading “Environment” underestimates its scope. Ultimately, this affects any company in which a member of management could commit a business-related crime or administrative offence – and, viewed objectively, that applies to every company.

On June 11, 2026, the Bundestag debated the bill in its first reading and referred it to the committees for further deliberation.[5] The federal council issued a statement on June 12. 2026; the federal government has already responded to this.[6] The process is therefore actively ongoing– and the exact wording of the new regulations has yet to be determined. But the direction it takes is clear.

Maximum amounts quadrupled: the visible side of the reform

The headline of the reform is quickly told: The administrative fine under Sec. 30 Para. 2 OWiG is to rise from the current 10 to 40 million euros in the case of intentional offences committed by a senior manager, and from 5 to 20 million euros in the case of negligent offences.[7] Adding to that – just like today  – the confiscation of the economic benefit, which may far exceed the scope of the penalty.

These figures can be put into perspective: For large corporations, even 40 million euros does not necessarily pose a threat to their survival, and in many cases the confiscation of the proceeds carries greater economic weight anyway. However, such an approach does not go far enough. The corporate fine is the state’s expression of disapproval of a company’s organisational responsibility – and if the scale quadruples, the entire scope of negotiation and expectations in fine proceedings shifts. For small and medium-sized companies, sums of this magnitude can have a substantial immediate impact. And the immediate consequences – registration entries, contract award restrictions, reputational damage, civil liability risks – scale with it.

Nevertheless, anyone who focuses solely on the numbers misses the real essence of the reform.

The actual paradigm shift: Compliance-Effectiveness becomes a legal concept

To date, general administrative offense law does not provide any specific statutory criteria for determining the amount of an association fine. The practice is guided by the general standard set forth in Sec. 17 OWiG, by case law and by special regulations in individual areas of law. Although the federal court of justice recognized far back in 2017, that an effective compliance management system should be considered in reducing fines[8] – it remained a matter of judicial precedent, the application of which was difficult to predict in individual cases.

Thats supposed to change. The proposed Sec. 30 Para. 2a OWiG-E establishes general legal principles and criteria for determining the amount of an association fine for the first time: the significance of the act, the allegations against the association and its financial circumstances – specified by a non-exhaustive list of individual criteria, which expressly includes the measures taken before and after the offense to prevent and detect violations.[9]

That sounds technical, but it has far-reaching consequences. This is because law enforcement agencies will have to examine whatever the legislature codifies as an assessment criterion in the future – in every proceeding, not just when the defense skillfully argues the point. The quality of compliance organization thus shifts from an optional defense argument to a mandatory review requirement. For the first time, companies that can demonstrate their preventive measures will have a clear legal basis. Companies that can’t, lose an argument they’ve been able to rely on silently until now: that, when in doubt, no one will look that closely.

„The reform answers a question that many companies have not yet asked themselves: How effective is our compliance management system in a real emergency? In the future, the answer will be found in the law – and it doesn’t depend on what’s on paper, but on what actually works within the organization.“

Daniel Pfaff, Counsel

Sec. 130 of the Act on Regulatory Offences: Where prevention does not alleviate, but prevent liability

As significant as Sec. 30 OWiG is – from a preventive standpoint, the strategically more important lever is still found in Sec. 130 OWiG.

The difference is fundamental. Sec. 30 OWiG applies, once the damage already been done: A manager has committed a work-related offense, and the association may impose a fine – and an effective compliance management system can mitigate the penalty. Sec. 130 OWiG on the other hand, is based on the duty of supervision itself: The omission to implement the necessary supervisory measures that would have prevented or significantly hindered a violation is subject to a fine. Anyone who has taken the necessary measures is not violating their duty of supervision – and when there is no breach of the duty of supervision, the associated liability does not arise in the first place.

Put another way: Under Sec. 30 OWiG, a company is negotiating the amount of the invoice. Sec. 130 OWiG determines whether an invoice is issued at all. An effective compliance management system constitutes a mitigating factor under Sec. 30 OWiG – under Sec. 130 OWiG, it is the exclusion of liability itself.

This distinction is not a legal technicality, but the very essence of a preventive compliance strategy. It explains why investments in the effectiveness of a compliance management system should be assessed differently from an economic perspective than investments in its documentation: The former can prevent proceedings from starting; the latter at best, help to bring them to a more lenient conclusion. And it explains why the reform is particularly relevant to board members, managing directors and supervisory board members – because Sec. 130 OWiG is directed specifically at management level.

The federal council is moving forward: a statutory list of requirements for the compliance management system

The course of the proceedings going forward demonstrates just how seriously the lawmaker takes the issue. The federal council believes the provisions of the government’s draft bill do not go far enough. In his statement dated June 12, 2026, he makes two demands: First, appropriate measures to prevent or detect violations should not merely be one criterion among many in the list of factors used to determine the amount of the fine, but should mandatorily serve as an independent mitigating factor that reduces the fine – expressly clarifying that structures that are merely formal or introduced for appearances’ sake („Window Dressing“) do not justify preferential treatment. Second, the basic elements of appropriate compliance measures – ranging from risk analysis to guidelines, training, and whistleblower systems, and including processes for investigating and sanctioning violations – are to be codified directly in Sec. 130 OWiG for the first time.[10]

The federal government initially rejected both proposals in its response.[11] It therefore remains to be seen what the final wording of the law will be. At the same time, practitioners and academics at the „Compliance und Internal Investigations” roundtable hosted by the Bayerischen Staatsministeriums of justice presented their own key points, which indicated the same direction: clearer legal guidelines for compliance in Sec. 130 OWiG, more clearly defined grounds for mitigation in Sec. 30 OWiG, and reliable incentives for cooperations.[12]

For companies, the debate is insightful in both directions. If the statutory list is introduced, companies will benefit from greater predictability – but they pay a price for it: A codified list of criteria also serves as an official assessment framework, against which any element, that is missing or only formally presented, can be identified as an organizational deficiency. If it will not be introduced, the more open-ended wording of the government’s draft will stand – the regulatory authorities’ expectations that companies should have verifiable, effective compliance structures remain in all cases. The question, therefore, is not whether companies must be assessed on the effectiveness of their compliance management systems, but simply how detailed the legal criteria will be.

Paper does not provide protection: What „effectiveness“ means in an emergency

This brings a term into focus, that is easier to write than to prove: effectiveness. Experience gained from administrative fine proceedings, internal investigations and regulatory audits reveals a recurring pattern: most companies have the standard compliance components in place – a code of conduct, policies, training programs and a whistleblower scheme. On paper, the compliance management system is complete. The crucial questions lie beyond that:

  • Is the system based on a recent, company-specific risk analysis – or on a template that has been updated over the years?
  • Do training courses actually reach the roles that are genuinely exposed to risk – or do they mainly reach those who are already aware of the risk?
  • Do controls work even in situations where they become inconvenient – in sales, in procurement, in overseas subsidiaries, or under time pressure?
  • Do reports lead to verifiable consequences – and are the findings fed back into the further development of the system?
  • Can the management demonstrate that it is fulfilling its supervisory responsibilities – through reporting lines, decision and resources, not just through organizational charts?

This is precisely the area the reform is aimed at. The proposed assessment criteria do not focus on whether measures exist, but on their suitability – and the Federal Council’s initiative, with its explicit rejection of “window dressing”, makes it clear that the legislator is well aware of the difference between documented compliance and compliance in practice. This is in line with an international development: For years, the US Department of Justice has also been asking the simple yet uncomfortable question when assessing compliance programmes: „Does it work in practice?“.[13]

This leads to a clear set of priorities for prevention: It is not the most comprehensive set of rules that provides protection, but the most effective one. A compact system, that has been proven to work, is worth more in an emergency than a comprehensive one that only exists.

What companies should be doing now

The final wording of the bill has yet to be finalised – but its general direction is clear. Companies that take action now are not doing so against a tight deadline, but with room for scope of flexibility. There are three key steps involved:

  • Review of the current situation with a focus on effectiveness: The starting point is an honest assessment of one’s own compliance management system – not based on the question “What do we have?”, but on the question “Which parts of it are effective – and how do we measure that?”. Such an analysis regularly uncovers gaps that remain hidden in day-to-day operations: risk assessments that are not aligned with the current business model, controls for which there is no evidence of implementation, and responsibilities without established reporting lines.
  • Establishing the ability to provide evidence: Whatever becomes the statutory basis for assessment in future must be capable of being substantiated in the event of a dispute – not only to public prosecutors and fine-imposing authorities, but also to supervisory boards, auditors and business partners. Effective prevention and its documentation are two sides of the same coin: it is not about producing paperwork, but about demonstrating actual effectiveness.
  • Involving management: As Sec. 130 OWiG addresses the supervisory responsibilities of the management, the reform is not purely a matter for the compliance function. Board members and senior management should seek a report on the current status of their compliance management system, the gaps that exist, and the priority with which these gaps are to be addressed. Supervisory boards should actively demand such reporting. Where individual areas show a need for improvement, this can now be addressed in a planned and systematic manner – rather than only under the pressure of ongoing proceedings.

Fazit: Prevention is the best defence

What’s on paper will matter less in future. What makes a difference within the organisation counts for more – and for the first time, this is stated in law.

The reform of Sec. 30 and 130 OWiG does not represent a revolution in corporate sanctions law, but rather a significant shift within the existing system: higher penalty ranges, a structured approach to determining penalties, and the statutory recognition of the relevance of the compliance organisation. The real message to businesses here is a preventative one: in future, the legislator will explicitly recognize what works – and for those who have effectively implemented the necessary supervisory measures, Sec. 130 OWiG will not only assist in determining the level of the fine, but will do so even before that: when it comes to the question of whether liability arises at all.

We at Pohlmann & Company have been supporting companies not only in setting up compliance management systems, but also in ensuring they are effective – from risk-based assessments, through structured gap analyses and health checks, to evaluating the actual effectiveness of compliance measures within the organization. Drawing on our experience in consultancy, business and investigations, we know how compliance management systems are assessed in a crisis – and what they must deliver to ensure that a crisis does not arise in the first place. After all, many people know what the rules are. We know what works.

Please find here our free of charge online selfcheck.

Would you like to know where your compliance management system stands today – and how it would be assessed in the event of an incident? Please feel free to get in touch.


[1]      Entwurf eines Gesetzes zur Änderung des Strafrechts – Umsetzung der Richtlinie (EU) 2024/1203 über den strafrechtlichen Schutz der Umwelt, BT-Drs. 21/6133.

[2]      Stellungnahme des Bundesrates vom 12. Juni 2026 nebst Gegenäußerung der Bundesregierung, BT-Drs. 21/6668 (zu BT-Drs. 21/6133).

[3]      Richtlinie (EU) 2024/1203 des Europäischen Parlaments und des Rates vom 11. April 2024 über den strafrechtlichen Schutz der Umwelt und zur Ersetzung der Richtlinien 2008/99/EG und 2009/123/EG.

[4]       Vgl. die Entwurfsbegründung zu Art. 3 des Entwurfs (§ 30 OWiG-E), BT-Drs. 21/6133; die neuen Höchstbeträge und Bemessungskriterien gelten für alle Anknüpfungstaten im Sinne des § 30 Abs. 1 OWiG.

[5]       BT-Plenarprotokoll der Sitzung vom 11. Juni 2026; der Entwurf wurde zur weiteren Beratung an die Ausschüsse überwiesen.

[6]       BT-Drs. 21/6668 (Fn. 2).

[7]       § 30 Abs. 2 S. 1 OWiG-E; bislang 10 Mio. Euro (Vorsatz) bzw. 5 Mio. Euro (Fahrlässigkeit).

[8]       BGH, Urteil vom 9. Mai 2017 – 1 StR 265/16

[9]       § 30 Abs. 2a OWiG-E, BT-Drs. 21/6133.

[10]     BT-Drs. 21/6668, insbesondere Nr. 15 (§ 130 Abs. 1 S. 2, 3 – neu – OWiG) und Nr. 16 (§ 30 Abs. 2a S. 3 Nr. 5, S. 4/5 – neu – OWiG).

[11]     Gegenäußerung der Bundesregierung, BT-Drs. 21/6668.

[12]     Eckpunkte des Runden Tisches „Compliance und Internal Investigations“ beim Bayerischen Staatsministerium der Justiz vom 27. Mai 2026.

[13]     U.S. Department of Justice, Criminal Division, Evaluation of Corporate Compliance Programs.