Legally compliant. Audit-proof. Effective. – Professional setup and implementation for companies and public authorities.
An effective compliance management system (CMS) is essential for organizations of all sizes today. The international standard ISO 37301 sets out precise requirements and guidelines on how organizations can systematically fulfill their legal, regulatory, and internal obligations—and how they can establish a robust and active culture of integrity.
We support companies and public institutions in the complete setup, further development, and audit-proof implementation of a CMS that meets the requirements of ISO 37301—and works in practice.
ISO 37301 is the globally applicable standard for compliance management systems. Unlike the previous ISO 19600, it is a genuine requirements standard that defines not only recommendations but also concrete, verifiable specifications for a CMS.
Among other things, it demands:
ISO 37301 thus forms the foundation of organized legal compliance—and demonstrably protects management and the organization from liability and reputational risks.
The standard follows the so-called Harmonized Structure of all modern ISO management systems (including ISO 9001, ISO 27001, and ISO 45001)
A complete CMS comprises:
This point is the central requirement for ISO 37301 certification.
The standard requires an up-to-date legal register in order to continuously review all applicable regulations and reflect any changes.
We review the status quo based on ISO 37301 requirements and identify gaps.
We conduct a structured risk analysis (strategic, operational, legal).
Introduction or optimization of a legally compliant register of rights and obligations.
Compliance only works when it is understood—not when it is merely documented. We develop efficient and legally compliant training concepts for managers and employees.
We accompany you all the way to successful certification—or to audit-proof internal verification.
We provide comprehensive support in setting up a CMS in accordance with ISO 37301:
✔ Setting up a complete CMS in accordance with ISO 37301
✔ Further development of existing systems
✔ Performing ISO 37301 readiness analyses
✔ Setting up export control ICP systems
✔ Compliance and enterprise risk assessments
✔ Creation of all guidelines, processes, and evidence
✔ Training and management briefings
✔ Preparation for certifications
✔ Support in dealing with supervisory and penalty authorities
We combine legal precision, practical implementation, and experience from companies and public authorities.
Your advantages:
A CMS in accordance with ISO 37301 not only protects the organization, but also demonstrably protects those responsible (Section 43 GmbHG, Section 93 AktG).
An effective compliance management system offers tangible added value for companies and public authorities. It has been proven to reduce key risks – from liability risks and the threat of fines under Section 130 of the German Administrative Offenses Act (OWiG) to reputational damage, governance deficits, and risks arising from supervisory failures. At the same time, a professionally structured CMS creates the basis for demonstrating compliance with organizational and monitoring obligations to authorities and supervisory bodies at any time.

Do you have questions on this topic or need support? Please contact us directly.
T:
0221 29265841
E:
rostalski@rostalski.legal
Save contact

Would you like to make a report or find out more about the work of the ombudsman's office?
T:
0221 29265841
E:
rostalski@rostalski.legal
We accompany you from the initial analysis to the audit-proof implementation of ISO 37301.
Dr. Tony Rostalski
Attorney at Law | Specialist in Criminal Law
ROSTALSKI Commercial Criminal Law & Compliance – Cologne
Lindenallee 43
50968 Cologne
Email: kanzlei@rostalski.legal
Phone: +49 (0)221 2926 5840
ROSTALSKI is an independent law firm based in Cologne. We specialize in commercial criminal law, compliance consulting, and the development of effective organizational structures. Our clients include private individuals, executives, companies, and public sector clients. The firm is regularly recognized as a top address in rankings by WirtschaftsWoche, Handelsblatt, and FOCUS Business.