Current language: English
Our services
Support for growth strategies, transformations or M&A processes.
Our freelance experts have in-depth specialist knowledge in their field.
We provide you with experienced interim managers who take on responsibility.
Customized expert teams for complex projects
We find the best experts for these companies
Private equity
Efficient support throughout the deal cycle
Management consultancies
Flexible resources for demanding projects
Medium sized business
Consulting expertise for SMEs
Corporates
Technical and management experts for operational excellence
Scale-ups
Strategic & operational support for growth
Rule and Evidence

What Compliance Consulting Delivers — and What It Does Not

Consulting team following the path of a rule from policy to evidence on screen

Compliance consulting — bundled with risk management under the heading governance risk compliance in most organisations — works on one question: do the rules that apply to a company actually take effect in day-to-day work? A rule passes through four states. It is decided, it is known, it is built into a work step, and it is verifiable. Projects almost never fail at the first state, because policies are plentiful. They fail at the move from the second state to the third, and that is where the work sits.

It separates the rulebook from the control. A policy document is not a control. A control has a named owner, a cycle, a threshold at which someone steps in, and a trail showing that it took place. Twenty maintained controls at the points where something can genuinely go wrong carry further than two hundred pages of policy.

It sorts risks by how far they can be steered, not by how alarming they sound. A register ordered by loss amount creates attention for rare catastrophes and blindness towards the transaction that goes wrong every week. The list becomes usable only once every entry says who can influence it, with which measure — and how you would recognise that the measure is working.

It builds the rule into the work step rather than beside it. A check that lives in a separate file gets skipped under deadline pressure; one that sits in the approval step of the system does not. That includes the willingness to delete rules that block a process without lowering a risk.

What it does not do. It is not legal advice: whether a norm applies in a particular case, and which duties follow from it, belongs in the hands of a lawyer. It is not an audit and not a certification either, and it cannot guarantee compliant behaviour — anyone promising legal certainty is selling a feeling. And without the business functions, IT and procurement on board, every control stays a document.

Adjacent topics deliberately sit elsewhere: the reporting side of environmental and social duties in sustainability consulting, the governance of machine learning applications in AI consulting, permissions and service provider steering in IT consulting, supplier diligence along the chain in supply chain consulting, and the plain mapping of workflows in operations and process improvement.

Pressure to Act

When External Support on Compliance and Risk Topics Pays Off

Not every situation calls for help from outside. Where the question of what applies is already settled, where a named owner with a time budget exists in-house, and where a comparable body of rules has been introduced before, the internal route is the faster one. In the situations below the calculation comes out differently — not because knowledge of the business is missing, but because routine with this kind of evidence work is.

1. A Client Asks You for Evidence

  • The supplier questionnaire asks about policies, controls and reporting channels — and the answers would have to be worked out first.
  • The evidence is a condition of the contract, and improvised answers get noticed at the next review.

2. A Body of Rules Reaches You for the First Time

  • A threshold has been crossed, a new market was added, or a product category newly falls under a requirement.
  • The real question is rarely the legal text, but what it means for the way the work is organised.

3. An Incident Has Made a Gap Visible

  • A mishap, a complaint or an audit finding has shown that a control was missing or did not bite.
  • Whoever owned the transaction is badly placed to review it, so an outside view is also a relief.

4. The Risk Register Is a Spreadsheet Nobody Uses

  • The list exists, gets updated once a year and changes no decision.
  • What is missing is usually not the entry but the assignment: who steers it, with what, and how the effect is measured.

5. Compliance Is a Side Role Without a Time Budget

  • The task hangs on one person who carries it next to a main job, and it grows faster than that person's capacity.
  • Until a permanent appointment is decided, temporary reinforcement keeps the operation upright.

6. A Growth or Investment Step Is Coming Up

  • An investor, a bank or a buyer looks at governance — and finds gaps that never got in the way of day-to-day business.
  • What is put in order before a review costs a fraction of what has to be supplied afterwards.

Does one of these points describe the place you are standing in right now? A short conversation is usually enough to sort it out: which bodies of rules could reach you at all, which control is missing first — and whether an outside pair of hands is needed for it.

Control Areas

The Control Areas Compliance Consulting Works On

The areas are staffed one at a time or together, depending on where a company stands. It usually begins with the risk register and the controls; data protection, reporting channels and supplier screening follow wherever exposure calls for them. This is a selection — the category pages add a large number of further specialisations.

Compliance Management System

The frame that holds the single rules together: principles, responsibilities, training, monitoring and improvement. We build it along the actual risk picture instead of along a model handbook, and keep it small enough to stay maintainable. Frameworks such as ISO 37301 serve as an ordering grid, not as a target state.

Risk Register and Risk Steering

Collecting, scoring and updating the risks that can endanger the business, its assets or its reputation — with impact, frequency and, above all, a named owner for steering. Part of it are a reporting line that reaches the management in time and an escalation threshold. What decides the value of the register is whether it changes decisions.

Internal Control System (ICS)

Controls where value moves and mistakes get expensive: approval limits, segregation of duties, four-eyes checks, reconciliations in accounting, permissions in the leading systems. We first record what is already being controlled in practice, remove the duplication and close what is left open — until a control plan stands that the line organisation carries on without accompaniment.

Data Protection Organisation

The organisational side of data protection: records of processing, deletion concept, processor management, data subject rights, the notification route for incidents, and the question of who in the house decides what. We bring the paperwork together with lived practice and make it fit for review. The legal assessment of a single processing activity stays untouched by this.

Whistleblowing and Internal Investigation

A reporting office is quick to set up and hard to run. It needs confidentiality, deadlines, a traceable way of handling a case, protection against retaliation, and somebody who assesses a report independently. We set the route up and define when an internal investigation begins. Judging a concrete case belongs into a lawyer's hands.

Supplier and Third-Party Screening

Whoever works for you works in your name. This covers risk classification of the supplier base, self-disclosures, contract clauses, audits on site and a way of handling findings that goes beyond filing them. The area connects compliance with procurement and logistics — from sanctions screening through to diligence duties along the chain.

Which of these areas has to carry first in your case can be sorted out in a short conversation. Describe the situation to us; what comes back is an assessment, not a deck of offer slides.

Engagement Formats

In Which Forms Compliance Experience Is Brought In

The outcome is often decided less by technical depth than by the way experience is brought in: how much external capacity, with what mandate, over what period. The same frame holds for every form — a named internal owner, goals agreed in writing before the start, and a handover point that is fixed from day one.

Assessment
An Outside Review

An experienced professional goes through the applicable rules, the exposure, the existing controls and the state of evidence, and names the gaps that count first. Deliberately short and open-ended — it often ends with the finding that the organisation manages the rest on its own.

Build Phase
Building in a Mixed Team

External specialists work on the control framework together with your own people, under internal professional leadership. This is the most common model for a first build: the knowledge stays in the house, and later maintenance does not hang on a contract.

Vacancy
Responsibility for a Period

An external person takes over a compliance or risk responsibility with decision-making authority — for an unfilled position, in a special situation, or when an authority is needed that does not sit inside the internal interests.

Ongoing Operation
Support in Regular Operation

Recurring support on a fixed cycle: following up controls, preparing reports, refreshing training, accompanying audits. Sensible once the framework stands and the routine exists in the house but the capacity does not.

Regulatory Density

Compliance by Sector: Which Rulebook Sets the Pace

The pressure to regulate is felt everywhere; its source is not the same everywhere. In banking and insurance the supervisor sets the pace and the audit rhythm, in industry it is product safety, export control and the standards demanded by customers, in pharma and healthcare it is market authorisation together with its documentation duties, in retail the supply chain requirements of the sales markets, in logistics and foreign trade the customs and sanctions rules, in administration and utilities procurement law.

That is why we staff by sector experience and not by availability: with professionals who know the relevant bodies of rules, the usual system landscapes and the points at which comparable projects have run aground before. This is what separates regulatory compliance consulting from a generic policy exercise — the requirement is read in the language of the sector that has to meet it. The basis is a network spanning 25 specialist areas with more than 300 role profiles. The six sectors below ask for compliance and risk work most often; none is excluded by that.

Compliance in banking - digital review of transaction data

Banking & Financial Services

Industrial plant representing product and export control duties in mechanical engineering

Industry & Mechanical Engineering

Healthcare setting representing documentation and diligence duties in pharma and care

Pharma & Healthcare

Global goods flows representing customs, sanctions and dangerous goods duties

Logistics & Foreign Trade

Product labelling in retail representing diligence duties along the supply chain

Retail & Consumer Goods

Specialists in front of an administrative building representing procurement and sector law

Public Administration & Utilities

Compliance in banking - digital review of transaction data

Banking & Financial Services

Industrial plant representing product and export control duties in mechanical engineering

Industry & Mechanical Engineering

Healthcare setting representing documentation and diligence duties in pharma and care

Pharma & Healthcare

Global goods flows representing customs, sanctions and dangerous goods duties

Logistics & Foreign Trade

Product labelling in retail representing diligence duties along the supply chain

Retail & Consumer Goods

Specialists in front of an administrative building representing procurement and sector law

Public Administration & Utilities

Evidence Goals

Projects From Compliance Practice and Their Evidence Goals

What actually gets commissioned falls for the most part into four types. Each has a typical starting point, an order of work that has proven itself, and an evidence goal that is agreed before the start and demonstrated at the end rather than estimated. The examples are a selection, not a boundary.

Building a Compliance Management System

Starting point: scattered policies, committed individuals, but no frame that shows what belongs together. The order that holds: first clarify exposure and risks, then collect the controls that already exist, then close the gaps, and write last. The evidence goal is a control plan with owners and cycles that is still being maintained in the second year.

Setting Up a Risk Register and Reporting Line

Starting point: a risk list exists, changes no decision and reaches the management once a year. The work consists of interviews in the business functions, one consistent scoring logic and the nerve to produce a shorter list. The evidence goal is a report on a fixed cadence that triggers at least one decision per cycle.

Putting a Whistleblowing System Into Operation

Starting point: a reporting channel has been bought or is about to be, and the operation behind it is missing. To be settled are ownership, confidentiality, deadlines, documentation and the question of when legal support is brought in. The evidence goal is a documented handling route that also holds on the first serious case.

Anchoring Diligence Duties in the Supply Chain

Starting point: questionnaires went out, the answers came back, and nobody knows what should follow from them. The order: classify the supplier base by risk, align the depth of checking to it, add contract clauses and escalation routes, use audits selectively. The evidence goal is a demonstrable chain from the classification through the check to the consequence.

Staffing

Which Profiles Staff Compliance and Risk Projects

The cut of the assignment decides the staffing: a risk register calls for a different profile than an export control check inside the order process. The profiles below are the ones most often asked for in compliance and risk work; they are a selection, and the category pages add many more. The task profile, the typical assignments and the daily rate range sit on each role's own page.

How a Compliance Project Takes Shape Step by Step

The scope and the duration of the steps depend on size and regulatory density; the sequence does not: first clarify what applies, then score, then build, then embed, then evidence. The scoring is never skipped — otherwise everything ends up controlled to the same depth.

Step 1: reviewing the rulebooks that apply to a company and its exposure

1. Review the Rulebooks and Your Exposure

What gets collected is which requirements could come into play for the business activity, the sites, the products and the customer base — including contractual requirements that no law prescribes.
Whether a norm applies in a particular case is something we obtain legally instead of asserting it.
The result is an ordered overview of the applicable rules, including the points where exposure stays open.
Step 2: risks are scored and ordered by how far they can be steered

2. Score the Risks and Put Them in Order

Conversations in the business functions show where transactions actually go wrong — not only where it would be dangerous in theory.
Scoring runs on impact, frequency and steerability, so that a ranking emerges instead of a flat list.
The result is a risk register whose first ten entries deserve a decision.
Step 3: controls are designed with an owner and a cycle

3. Design the Controls

Every material risk gets a control with a responsible person, a cycle, an intervention threshold and a form of evidence.
Controls that already exist are consolidated first; only what is missing is newly built.
Duplication and rules without effect are deleted — acceptance in the line organisation is decided right here.
Step 4: controls are embedded into workflows and systems

4. Embed Them Into Workflows and Systems

Controls move to where the work happens: into approval steps, permissions, forms and checklists.
Training belongs inside this step and not behind it — what nobody understands gets bypassed instead of carried out.
The result is a workflow in which the compliant route is also the most convenient one.
Step 5: evidence that controls were carried out is produced

5. Produce the Evidence

Every control leaves a findable trail: date, reviewer, result, consequence.
The documentation is reduced to what somebody actually reads.
The result is a state of evidence from which a questionnaire or an audit can be answered out of stock.
Step 6: the effect of the controls is tested and kept current

6. Test the Effect and Keep It Current

At fixed intervals it is measured whether controls were carried out and whether they lower the risk.
What has no effect is changed or abolished — a framework that only grows loses its grip.
At the end stands the handover to the line organisation, with a cycle that holds without external accompaniment.
Daily Rates

What Compliance Consulting Costs: Daily Rates and Budgeting

Two figures determine the budget: the daily rate and the number of days. The second one is the larger and the one planned less often. Work through our network is billed by daily rate, with no project lump sum and no success-based components.

What moves the rate. In first place the seniority and the decision proximity of the role: whoever represents a control framework towards management, a supervisor or auditors sits above a role that supplies input. Next the regulatory density of the sector — in supervised or authorisation-bound environments the additional experience required is scarce, and scarcity works more strongly than any other factor. The share of on-site presence pushes in both directions: site and supplier audits need attendance, while work on policies and control plans runs largely remote and opens the pool of eligible profiles beyond your own region. Last the duration: an assignment over twelve months sits below a four-week engagement per day at the same onboarding effort.

The ranges from our own network — as published on each role page. For governance, control and framework work €750 to €1,300 per day (Freelance GRC Consultant, Freelance IT Governance Consultant). For regulatory specialist roles in foreign trade €800 to €1,300 (Freelance Trade Compliance Specialist, Freelance Export Control Specialist, Freelance Customs Expert). For controls in accounting €700 to €1,300 (Freelance Financial Controller, Freelance Group Controller). For supplier, contract and evidence work €800 to €1,400 (Freelance Supplier Auditor, Freelance Contract Manager (Procurement), Freelance ESG Reporting Consultant). Leadership responsibility sits above that: a finance responsibility for a period moves between €1,300 and €2,500 (Interim CFO). These are ranges and not a price tag — what applies to a specific assignment is set down in writing before the engagement.

Release in stages rather than as one sum. A project can be cut into four sections, each ending with a decision that is allowed to read „not further“: the assessment, the concept with risk register and control plan, the implementation with the embedding into workflows and systems, and the operation with its cycle and effect testing. Whoever releases everything in one amount loses the points at which the cut could still be corrected cheaply.

The difference from a law firm or an audit mandate lies less in the price than in what you are buying. A law firm assesses the legal position and represents you; an audit firm audits and certifies and, for independence reasons alone, must not build what it later audits. Here you staff a role inside your own line organisation that builds the framework and runs it — the experience stays where the transaction is handled. Costs for certification, external audits, legal review or software licences are not part of the daily rate.

Staffing follows the cut of the assignment: a control framework calls for a different profile than an export control check. The full overview sits under Compliance & Legal — among them GRC consultants and trade compliance specialists. Adjacent profiles are listed by Finance & Controlling for controls in accounting, Purchasing & Procurement for supplier and contract screening, Supply Chain Management for customs and export control, IT Service Management for IT governance and AI & Machine Learning for the governance of AI applications. The complete overview sits under Experts by Area.

Why Now

The Number of Rulebooks Grows Faster Than the Capacity to Serve Them

1,000

employees is where the EU due diligence directive reaches a company of its own accord, alongside a turnover threshold. Smaller suppliers meet the requirements indirectly, through the questionnaires of their customers. Whether and how it applies in a given case belongs in a legal review.
European Commission, Corporate Sustainability Due Diligence

Four States

are what a rule passes through before it counts: decided, known, built into a work step, verifiable. Most organisations stop after the second one — which is why an audit finding arrives long after the policy was signed.

Two Registers

usually sit side by side wherever compliance and risk management were never connected: one lists the rules, the other the threats. Merging them costs a fortnight and settles the argument about which list a decision follows.
Common Questions

Frequently Asked Questions About Compliance Consulting

Compliance means the organisational arrangements a company uses to make sure that applicable laws, contractual promises and its own policies are observed in day-to-day work: an assessment of its own risks, controls at the points where something can happen, clear responsibilities, training, and a reporting channel for concerns. Compliance consulting supports the building and the running of those arrangements; it is not legal advice. Whether a provision applies in a particular case, and which duties follow from it, has to be reviewed by a lawyer.
A compliance management system, CMS for short, is the frame that ties single rules, controls and responsibilities into one whole. It describes which topics are material, who owns them, how checking happens and how concerns are handled. What decides its quality is not the volume of documentation but whether the controls take place in everyday work and leave a trail behind them.
Seven components recur in practice: a stated position from the leadership, an analysis of the material risks, a programme of rules and controls derived from it, an organisation with named responsibilities, communication and training, a reporting channel including the handling of concerns, and monitoring with improvement. How strongly each element has to be developed depends on size, sector and risk exposure.
Compliance risks are events that can arise from failing to meet requirements — from contractual penalties and the loss of an authorisation through exclusion from tenders to reputational damage and measures by an authority. Typical fields are corruption, competition law, data protection, employment law, product conformity, anti-money-laundering, and customs and export control. The list only becomes useful once every entry states who influences it with which control.
Both work with the same instruments but ask different questions. Compliance asks which requirements apply and how adherence is secured and evidenced. Risk management asks more broadly which events endanger the continuation or the success of the business — including market, default or operational risks with no link to a rule. Because they overlap heavily, one shared register is usually worth more than two separate lists.
IT compliance is the part of the task that relates to information technology: permissions and segregation of duties, traceability of changes, retention and deletion of data, the steering of IT service providers, and licence and contract duties. It is not the same as information security: security asks about protection against attacks, IT compliance about demonstrability against requirements.
Work through our network is billed by daily rate. According to the individual role pages the ranges for the relevant profiles run from 750 to 1,300 euros for governance and control work, 800 to 1,300 euros for regulatory specialist roles in foreign trade, 700 to 1,300 euros for controls in accounting, and 800 to 1,400 euros for supplier and evidence work. What tips the figure is seniority, the regulatory density of the sector, the share of on-site presence and the duration; for the total sum the number of days matters more than the rate. Costs for certification, external audits, legal review or software are not included.
Governance risk compliance, usually shortened to GRC, describes the joint steering of three tasks that were long handled separately: governance as the question of who decides what and how it is documented, risk as the question of which events are steered by whom, and compliance as the question of which requirements are met and evidenced. The practical benefit lies in one register, one set of controls and one reporting line instead of three parallel ones.
You can rely on us

Excellent. We are not the only ones who think so.

consultingheads has received several awards from leading trade magazines and independent third parties.

Siegel_TOP-Berater
consultingheads-award-top-company-2025-kununu
consultingheads-brand-eins-beste-berater-2025-1
consultingheads-kununu-top-company-2024
consultingheads-brand-eins-beste-berater-2024-3
consultingheads-kununu-top-company-2023 (1)
consultingheads-kununu-top-company-2023 (1)
consultingheads-brand-eins-beste-berater-2019-1
consultingheads-brand-eins-beste-berater-2021
consultingheads-brand-eins-beste-berater-2020
BrandEins_Berater2026_Logo_DE_basic
Siegel_TOP-Berater
consultingheads-award-top-company-2025-kununu
consultingheads-brand-eins-beste-berater-2025-1
consultingheads-kununu-top-company-2024
consultingheads-brand-eins-beste-berater-2024-3
consultingheads-kununu-top-company-2023 (1)
consultingheads-kununu-top-company-2023 (1)
consultingheads-brand-eins-beste-berater-2019-1
consultingheads-brand-eins-beste-berater-2021
consultingheads-brand-eins-beste-berater-2020
BrandEins_Berater2026_Logo_DE_basic
bildmarke
brand eins Best Management Consultants 2026 - consultingheads
Next Step

Let's talk about your control framework.

Twenty minutes to place your exposure
One concrete next measure, not a slide deck
No charge, no obligation and no pitch at the end
Twenty minutes in which we place your situation and name the control that is missing first — and whether our network is the right place to look for the person who fills it.