Skip to content

16 December 2024 | 4 min

Gifts for business partners at Christmas time: regulations and laws in Germany, Austria and Switzerland

The Christmas season is not only an opportunity to show gratitude and appreciation, but also a time when gifts for business partners are often exchanged. But especially in a professional context, such gestures can raise complex legal and tax issues. In Germany, Austria and Switzerland, there are specific regulations that companies and business partners must observe. A look at the regulations in the DACH region shows how to act legally safely.

Germany: Strict rules, clear boundaries

In Germany, the handling of gifts is regulated by the Criminal Code (StGB), tax law and internal company guidelines.

1. Corruption legislation
– According to Section 299 of the StGB, bribery in commercial transactions is prohibited. A gift could be considered an impermissible granting of an advantage if it is used to influence the recipient.
– Public officials are subject to particularly strict regulations (Section 331 ff. of the StGB). The following applies here: Even small gifts can be problematic.

2. Tax aspects
– Deductibility: Gifts to business partners are tax deductible up to an amount of 35 euros per person per year (Section 4 Paragraph 5 No. 1 EStG).
– Flat rate tax: The donor can pay the flat rate tax so that the recipient is not taxed (Section 37b EStG).

3. Compliance guidelines
Many companies set their own value limits, often between 20 and 50 euros. Larger gifts must be documented or approved.

Austria: Generosity in moderation

In Austria, too, corruption laws, tax law and company guidelines regulate the handling of gifts.

1. Corruption legislation
– According to Section 304 of the Criminal Code, it is not permitted to grant public officials advantages that could influence their impartiality.
– Strict requirements also apply in the business sector (UWG, Section 10): Gifts must not be aimed at influencing decisions.

2. Tax aspects
– Gifts to business partners can be claimed for tax purposes as long as they are clearly business-related.
– As in Germany, there are value limits, but these are not set by law but by the tax authorities.

3. Company guidelines
Internal guidelines often determine whether and to what extent gifts are permitted. Strict compliance rules apply particularly in regulated industries such as the pharmaceutical industry.

Switzerland: Restrained practices

In Switzerland, corruption legislation plays just as important a role as tax law and industry standards.

1. Corruption legislation
– According to Art. 322 of the Criminal Code, both bribing public officials and granting benefits in the private sector are punishable. The rules apply here in a similar way to those in Germany.
– The Unfair Competition Act (Art. 4) prohibits unfair competition, which can also include gifts that lead to improper influence.

2. Tax aspects
– Gifts to business partners are deductible as business expenses if they are appropriate and business-related.
– Unlike in Germany, there are no fixed value limits, but luxury gifts should be avoided.

3. Cultural peculiarities
In Switzerland, a cautious approach to gifts is expected. Small gestures of appreciation are accepted, but large gifts are rare.

Practical tips for legally compliant Christmas gifts

1. Observe value limits: In all three countries, gifts worth 20 to 50 euros are generally not critical.

2. Observe compliance: Find out about your business partner’s internal company guidelines.

3. Documentation: Record which gifts you have given, especially if they are more valuable gifts.

4. Purpose and occasion: Gifts should not be directly linked to a business decision, but should be seen as a general sign of appreciation.

5. Individuality instead of luxury: Personal, symbolic gifts such as a high-quality calendar or regional specialties are unproblematic and often more effective than expensive presents.

Conclusion


Christmas gifts for business partners can be a valuable gesture to strengthen relationships and express gratitude. However, it is important to observe the legal framework in Germany, Austria and Switzerland. Transparency, moderation and an awareness of compliance rules ensure that your gifts are perceived positively – and remain legally sound. This is how you can end the year successfully in the spirit of cooperation.

Related posts

9 December 2024 | 3 min

The Evolution of Compliance Management: A Look at Recent Transformations

Compliance management has undergone significant transformations in recent years. Driven by new regulatory requirements, technological advancements, and shifting societal expectations, the role and functionality of compliance within organizations have evolved dramatically. The recent PwC study “Compliance Transformation 2025+” provides insightful perspectives on these changes and highlights how companies in the DACH region are adapting to new challenges.

From Control to Value Creation

Traditionally, compliance was seen as a reactive function focused on adherence to legal regulations. Today, it stands at the core of the value chain. According to the study, 94% of companies have significantly expanded their compliance scope over the past five years. Compliance now encompasses not only traditional areas like anti-corruption and antitrust laws but also new domains such as:

  • Data Protection (e.g., GDPR)
  • Human Rights (e.g., supply chain due diligence laws)
  • ESG Criteria (Environmental, Social, and Governance)
  • Product Compliance (e.g., EU Deforestation Regulation).

Drivers of Change: Risk Orientation and ESG

A key driver of this transformation is the focus on risk-oriented approaches. Companies are increasingly aligning their compliance management systems (CMS) with specific risks arising from new business models, technological developments, or regulatory requirements. For instance, 93% of respondents assess the risk potential of ESG topics as high or very high. As a result, compliance has evolved from being a control function to becoming an integral part of strategic risk management.

Digitization as a Key Enabler

Digitization has fundamentally changed compliance. Digital solutions and AI-driven tools enable:

  • Real-Time Risk Monitoring: Automatic identification of regulatory changes and their implementation.
  • Efficiency Gains: Streamlined processes through automation.
  • Data-Driven Analysis: Enhanced decision-making through predictive analytics and pattern recognition.

According to the study, 72% of companies report positive effects from the use of digital technologies in compliance management.

Compliance Culture and the Role of Employees

A robust compliance culture is indispensable. Companies with high compliance standards systematically measure how effectively employees raise concerns, understand training, and align with corporate values. Promoting a “speak-up” culture and establishing a reliable whistleblowing system are critical. Best-in-class companies implement comprehensive measures to build trust and foster integrity.

Challenges and Opportunities

 Challenges

  • Regulatory Complexity: New laws, such as the EU AI Act or supply chain due diligence laws, require rapid adaptation.
  • Resource Constraints: Growing demands on specialized compliance teams often outpace the availability of interdisciplinary talent.
  • System Integration: Connecting CMS with other management systems like risk or quality management remains a challenge.

 Opportunities

  • Business Enablement: Compliance is increasingly seen as a business enabler. 84% of respondents view compliance as a facilitator of new business models.
  • Sustainability and ESG: Strong ESG compliance can provide a competitive advantage.
  • Technology Adoption: Expanding digital solutions promises long-term efficiency gains and cost savings.

 Conclusion: A New Era of Compliance

Compliance management has evolved from a control-focused function to a strategic element that helps organizations manage risks, create value, and support innovative business models. The integration of technology, emphasis on risk orientation, and involvement in ESG topics are central to this transformation.

Companies that adapt to these new requirements early will not only enhance their resilience but also leverage compliance as a strategic competitive advantage. The coming years will reveal how well organizations embrace this change.

2 December 2024 | 3 min

The use of artificial intelligence in Europe

The introduction of artificial intelligence (AI) is transforming companies worldwide. In Europe, especially in the DACH region (Germany, Austria, Switzerland), an ambivalent picture emerges: While companies appreciate the benefits of AI, they face considerable challenges in implementing and using it. This article highlights the most important trends, problems and solutions – with a particular focus on how governance, risk and compliance (GRC) software can support companies in this.

AI use in Europe: status quo and potential

According to studies, 93% of companies in Europe use AI solutions in various phases – from exploration to optimization. AI is proving to be a valuable tool, particularly in the areas of IT security, human resources management and marketing. Companies in the DACH region particularly emphasize the relevance of AI for process automation, data analysis and personalization.

The advantages of AI:

  1. Increased efficiency: Automated processes save time and reduce errors.
  2. Better decision making: Data-driven analytics provide deep insights and forecast trends.
  3. Improved customer experiences: Personalization increases customer satisfaction and loyalty.

Challenges of AI integration

Despite the optimism, companies face several obstacles:

  1. Black box problem and traceability: AI decisions are often difficult to understand, which makes it difficult to accept and trust the technology.
  2. Data management: Data fragmentation and silos make efficient use difficult. 82% of companies in the DACH region report difficulties in integrating data sources.
  3. Skilled labor shortage: The lack of AI experts hinders the scaling of projects. Around 48% of companies are only moderately equipped with the right talent.
  4. Regulatory requirements: The EU AI Act and other compliance requirements make the use of AI difficult, especially in sensitive areas.
  5. Cultural barriers: Resistance among the workforce and a lack of acceptance are a significant problem.

Key areas with challenges

Some areas show particularly clear problems with AI integration:

  • Marketing: Personalization and segmentation of target groups require in-depth data analysis, which is often hampered by inadequate data quality.
  • IT and infrastructure: 68% of companies do not feel ready to adapt their infrastructure to the increasing demands of AI.
  • Governance and compliance: Only 35% of companies have a high level of understanding of global data protection standards, which makes compliance with regulatory requirements difficult.

How GRC software can help

Governance, risk and compliance (GRC) software can play a crucial role in overcoming these challenges:

1. Data integration and management:

o Centralization and organization of data in compliant platforms.

o Improvement of data quality and traceability through automated processes.

2. Regulatory compliance:

o Support in compliance with EU AI laws through predefined frameworks.

o Automated monitoring and reporting on regulatory requirements.

3. Risk management:

o Early detection of security and operational risks through AI-supported analysis.

o Development of scenarios to minimize potential risks.

4. Employee training:

o Integration of learning modules and training programs to promote workforce acceptance and competence.

5. Cultural transformation:

o Promoting a proactive and open approach to new technologies through transparent communication and measurable success criteria.

Conclusion

The DACH region is facing a critical phase in the use of AI. Companies recognize the opportunities, but also the challenges, that come with integrating this technology. GRC software offers a strategic advantage here by helping companies minimize risks, meet regulatory requirements and increase efficiency. Those who consistently rely on these solutions can not only position themselves better, but also secure long-term competitive advantages.

The message is clear: the future of AI in Europe lies in targeted and responsible use – and GRC software could be the key to this.

25 November 2024 | 3 min

AI in the Context of GRC: A Comprehensive Overview

The use of Artificial Intelligence (AI) has advanced rapidly in recent years and has become an integral part of modern businesses. In the field of Governance, Risk & Compliance (GRC), AI plays a transformative role. This blog post explores the advantages and challenges of using AI in the GRC context and highlights how specialized software solutions can optimize these processes.

1. Benefits of AI in GRC Management

Automation and Efficiency

AI can automate repetitive and time-consuming tasks such as analyzing risk reports, reviewing compliance documents, or identifying anomalies in data. This frees up resources, allowing employees to focus on more strategic activities.

Improved Risk Detection

Leveraging machine learning and data analytics, AI can identify complex patterns and correlations in large datasets. This enables the early detection of potential risks before they escalate.

Regulatory Compliance

AI-driven GRC systems help ensure compliance with regulations by monitoring regulatory changes and automatically flagging potential gaps in compliance.

Transparency and Traceability

AI allows businesses to monitor, document, and analyze processes, ensuring a high degree of transparency. This is particularly beneficial during audits and reporting.

Scalability

International companies benefit from the scalability of AI, as it allows for monitoring compliance requirements across multiple countries and regions simultaneously.

2. Challenges and Risks

Data Privacy and Ethical Concerns

Processing sensitive data with AI raises questions about data protection and security. Businesses must ensure their AI systems comply with applicable data privacy regulations.

Bias in Algorithms

Algorithms can harbor biases that lead to unfair or incorrect decisions, potentially resulting in significant legal and reputational consequences.

Complexity of Implementation

Introducing AI systems into GRC processes can be costly and technically demanding. Companies need to invest in the right infrastructure and employee training.

Lack of Standardization

The rapid development of AI technologies means there are few standardized approaches, which can complicate integration into existing GRC systems.

3. How GRC Software Can Help

Specialized GRC software can harness the advantages of AI while addressing the challenges. Here are some key functionalities such software solutions offer:

AI Governance Framework

GRC software can provide a structured framework to ensure AI systems are used ethically and compliantly. This includes policies, standards, and metrics for monitoring AI performance.

Risk Assessments

The software facilitates detailed risk assessments, identifying potential risks, stakeholders, and harm scenarios. This enables businesses to develop mitigation strategies.

Real-Time Monitoring

Modern GRC systems integrate AI to monitor risks and compliance issues in real time, issuing alerts to improve response times and minimize potential damage.

Integration and Scalability

Through integration into existing IT systems and scalability, GRC software ensures seamless application of AI across different business areas.

Training and Capacity Building

Another critical feature is the provision of training materials and tools to help employees use AI technologies safely and effectively.

Conclusion

The use of AI in GRC offers immense opportunities but also presents challenges. Companies should adopt a strategic approach that ensures ethical AI usage while meeting compliance requirements. Specialized GRC software solutions can serve as effective tools to maximize AI’s benefits and address its challenges. With a well-defined governance framework and the right technological support, companies can ensure AI remains a transformative force – driving efficiency, transparency, and security.

18 November 2024 | 4 min

The Bayer stock: causes, impact and lessons for GRC

Bayer AG, once a flagship of German industry, has experienced an unprecedented share price decline in recent years. This article looks at how far the share is from its peak, what factors led to this crash, whether it is justified and how improved governance, risk and compliance (GRC) management could have prevented such developments.

Distance from the peak

In 2015, Bayer shares reached their historic high of around 140 euros. Currently, in November 2024, the share is trading at around 20 euros, which represents a decline of over 85%. On November 12, 2024 alone, the share price fell by 14.5%, approaching the 20 euro mark, the lowest level in 20 years.

Causes of the crash

Acquisition of Monsanto

The acquisition of the US agrochemical company Monsanto for 63 billion US dollars, completed in 2018, is considered the main cause of Bayer’s problems. Monsanto was already involved in numerous legal disputes before the acquisition, in particular over the weed killer glyphosate, which is suspected of being carcinogenic.

Legal disputes and financial burdens

After the acquisition, Bayer was faced with a flood of lawsuits. In the third quarter of 2024, the company recorded a net loss of 4.2 billion euros, mainly due to write-downs in the agricultural division.

Weakness in the agricultural business

Bayer had to lower its profit forecasts for 2024 and now expects EBITDA between 10.4 and 10.7 billion euros, compared to previous estimates of 10.7 to 11.3 billion euros. This adjustment is due to weaker developments in the agricultural market, especially in Latin America.

The role of GRC

The dramatic challenges Bayer AG is facing following the acquisition of Monsanto underscore the critical importance of effective GRC. More careful implementation and application of GRC processes could have helped Bayer avoid or at least mitigate the current problems. The following explains the specific areas where improved GRC processes would have been beneficial:

1. Thorough due diligence prior to the acquisition

Before the acquisition of Monsanto, a comprehensive due diligence should have been conducted, taking into account not only financial aspects but also legal and regulatory risks in particular. An in-depth analysis of existing and potential litigation related to glyphosate and other Monsanto products would have enabled Bayer to better assess the scope of the risks and make informed decisions.

2. Comprehensive risk management

A robust risk management system would have helped Bayer to identify, assess and take appropriate action on potential risks at an early stage. This includes developing scenario analyses for potential litigation and its financial impact, as well as implementing risk mitigation strategies.

3. Strengthening the compliance culture

A strong compliance culture within the company could have ensured that all business activities were in line with legal requirements and ethical standards. This would not only have strengthened stakeholder trust, but also reduced the risk of litigation and reputational damage.

4. Effective corporate governance

Transparent and responsible corporate governance would have helped ensure that strategic decisions, such as the acquisition of Monsanto, were made taking into account all relevant risks and stakeholder interests. This might have led to a more critical assessment of the acquisition.

5. Continuous monitoring and adjustment

After the acquisition, continuous monitoring of the integration and the associated risks would have been essential. Through regular reviews and adjustments of strategies, Bayer would have been able to respond flexibly to challenges that arose.

Conclusion

The dramatic fall in Bayer’s share price is the result of a combination of strategic mistakes, inadequate risk management and a lack of compliance. A robust GRC system could have helped to identify these risks early on and take appropriate countermeasures. For Bayer and other companies, this is an important lesson about the importance of governance, risk and compliance management for long-term success. The implementation and consistent application of improved GRC processes would have helped Bayer to better manage the risks associated with the Monsanto takeover and avoid or at least mitigate the current challenges.

12 November 2024 | 6 min

Business Continuity and ISO 22301

In a world where companies face increasing risks such as natural disasters, cyberattacks and pandemic-related disruptions, effective business continuity management (BCM) is becoming increasingly important. The ISO 22301 standard was specifically developed to help organizations develop, implement and maintain a comprehensive BCM system. This article provides an overview of the standard, why it is central to companies and how governance, risk & compliance (GRC) software can help effectively meet the requirements of the standard.

What is ISO 22301?

ISO 22301:2019 is an international standard for business continuity management systems (BCMS). It provides organizations with a structured framework to prepare for unforeseen disruptions and ensure that they can maintain their most important business processes even in times of crisis. The standard covers all essential aspects of BCM, including:

  • Risk assessment and identification of threats
  • Continuity planning and measures to minimize disruptions
  • Response and recovery plans
  • Training and awareness of employees
  • Regular review and improvement of the BCM system

The main purpose of ISO 22301 is to help organizations mitigate the risks associated with business interruptions. This means that companies are able to respond quickly and efficiently to unforeseen events to minimize the damage to their operations and reputation.

Why is ISO 22301 important?

The importance of ISO 22301 lies in its ability to protect and provide resilience to companies. Here are some of the main benefits of effective business continuity management according to ISO 22301:

1. Protecting business processes and reputation

When companies are able to continue their critical business processes even in times of crisis, they minimize the risk of revenue loss and customer churn. At the same time, they protect their reputation and gain the trust of customers and partners who rely on high availability and reliability.

2. Meeting regulatory requirements

Many industries, especially financial and healthcare, have strict requirements for BCM. ISO 22301 provides organizations with a basis to meet these requirements and prevent potential fines or legal consequences.

3. Minimizing financial losses

Disruptions in operations can lead to significant financial losses. By taking preventive measures and having a well-prepared crisis management strategy, companies can reduce their losses in the event of a crisis.

4. Preventing and managing risks

Through structured risk analysis and continuous monitoring of threats, companies can identify potential risks early and develop appropriate measures to protect business operations.

5. Improving organizational resilience

An effective BCM system strengthens an organization’s resilience by ensuring that it can adapt quickly to changes and unexpected events. This not only helps to secure the company, but also to ensure long-term competitiveness.

Requirements of the ISO 22301 standard

ISO 22301 includes a number of specific requirements that companies must meet in order to design their BCM strategies in accordance with the standard. These include:

  • Context analysis: Companies must analyze the internal and external context to understand potential risks and impacts that could affect their operational processes.
  • Leadership and commitment: Company management must actively engage in BCM and provide the necessary resources.
  • Planning and support: Organizations must provide clear plans, objectives and resources for the implementation of BCM.
  • Risk assessment and needs analysis: Threats to business operations must be identified and assessed in terms of their impact.
  • Response and recovery plans: Companies must develop plans for rapid response and recovery of critical business processes.
  • Training and skills development: Employees must be trained and prepared for potential crises.
  • Review and improvement: BCM must be regularly reviewed and adjusted if necessary to ensure its effectiveness.

How can GRC software help with the implementation of ISO 22301?

Governance, Risk & Compliance (GRC) software can significantly help companies meet the requirements of ISO 22301. A GRC platform integrates various e processes and provides a central point of contact for managing risks, meeting compliance requirements and implementing business continuity programs. Here are some ways GRC software can help implement ISO 22301:

1. Risk assessment and monitoring

GRC software enables risks to be assessed in a structured manner and monitored continuously. It can detect and assess threats such as natural disasters, cyber attacks and system failures at an early stage. By integrating risk data and threat intelligence in a central platform, companies have a better overview of potential vulnerabilities.

2. Automation and standardization of business continuity plans

GRC software helps to systematically create and maintain business continuity plans. These plans can be automated and standardized so that all critical processes are documented and responsibilities are clearly defined. In the event of a crisis, the software can also ensure that all necessary steps and notifications are carried out.

3. Compliance tracking and documentation

Compliance with ISO 22301 requirements requires comprehensive documentation and regular audits. GRC software provides companies with a central platform for managing and documenting all compliance activities, making it easier to prepare for audits and report. Documentation on BCM implementation and regular reviews of emergency plans can also be recorded centrally.

4. Training and awareness

An essential part of ISO 22301 is employee training. GRC software can organize and track training and awareness programs. This makes it possible to understand which employees have been trained and whether they have the appropriate skills to deal with emergencies.

5. Monitoring and continuous improvement

GRC software also helps companies to continuously monitor and improve their BCM system. Regular reviews, audits and performance analyses can identify and optimize weak points in BCM. The system can be set up to automatically generate notifications and initiate improvement measures if there are deviations from the requirements.

6. Crisis management and communication

In the event of a crisis, clear and effective communication is crucial. GRC software offers integrated communication tools to quickly and specifically communicate relevant information to the employees affected. By using predefined escalation plans and communication strategies, companies can ensure that everyone involved is informed and the right measures are taken in the event of a crisis.

Conclusion

ISO 22301 is an essential standard for companies that want to ensure that their critical business processes continue to run smoothly even in times of crisis. In an increasingly uncertain and risky world, strong business continuity management is crucial for the long-term success and resilience of a company. GRC software can provide valuable support here by structuring, automating and continuously monitoring the implementation of BCM.

With the help of GRC software, companies can implement the requirements of the ISO 22301 standard efficiently and effectively. This not only strengthens business continuity, but also promotes the trust of customers, partners and investors and ensures company success – even in difficult times.

5 November 2024 | 4 min

LkSG and CSDDD: A comparison and what companies need to consider

In recent years, the topic of sustainability and responsibility in the supply chain has become increasingly important. Two key legal frameworks that affect companies in Europe are the German Supply Chain Due Diligence Act (LkSG) and the European Corporate Sustainability Due Diligence Directive (CSDDD). Both aim to strengthen human rights and environmental standards in global supply chains. But there are important differences that companies need to know and consider.

The Supply Chain Due Diligence Act (LkSG)

The LkSG came into force in Germany on January 1, 2023 and is aimed at companies with more than 3,000 employees (from 2024 also for companies with 1,000 or more employees). It obliges companies to exercise human rights and environmental due diligence throughout their supply chain. The key requirements include:

  1. Risk management: Companies must identify and assess risks in their supply chain and take measures to minimize these risks.
  2. Complaint mechanisms: Mechanisms must be put in place that enable those affected to report violations of human rights or environmental standards.
  3. Reporting obligation: Companies are obliged to regularly report on their due diligence obligations and their implementation.
  4. The LkSG has a strong national focus and focuses on preventing human rights violations and environmental degradation throughout the supply chain.

The Corporate Sustainability Due Diligence Directive (CSDDD)

The CSDDD is a planned EU-wide directive that takes a more comprehensive approach. It is due to come into force in the coming years and will be applicable to all large companies in the EU, regardless of their industry. The CSDDD goes beyond the LkSG and requires companies to:

  1. More comprehensive risk assessment: In addition to analyzing human rights and environmental threats, climate-related risks and their impact on business must also be taken into account.
  2. Mandatory measures: Companies must take concrete measures to minimize risks, while also ensuring compliance with the Paris climate goals.
  3. Integration into corporate policy: Sustainability considerations must be more integrated into the overall corporate strategy, including executive compensation policies.
  4. Transparency and reporting: In line with the Corporate Sustainability Reporting Directive (CSRD), companies must prepare detailed reports on their sustainability practices.

Differences between LkSG and CSDDD

The main difference lies in the scope and requirements:

– Scope: The LkSG is a national law that focuses on German companies, while the CSDDD is an EU-wide directive that will affect all large companies in the EU.

– Requirements: While the LkSG focuses on compliance with human rights and environmental standards, the CSDDD additionally requires measures to combat climate change and a more comprehensive integration of sustainability into corporate strategy.

– Reporting: Reporting obligations under the CSDDD are stricter and must be in line with the new EU sustainability standards.

What companies need to consider

Companies should proactively prepare for both sets of rules. Here are some recommendations for action:

  1. Expand risk analysis: Companies should update their risk analyses to cover not only human rights and environmental risks, but also climate-related risks.
  2. Adapt compliance programs: It is important to review and adapt existing compliance programs to meet the stricter requirements of the CSDDD.
  3. Improve reporting: Reporting requirements are becoming more complex. Companies should invest in appropriate systems and processes to efficiently collect and report the necessary data.
  4. Make early adjustments: Since the CSDDD is still in the legislative phase, companies should closely monitor developments and make adjustments early on to avoid later compliance pressure.

Conclusion

The LkSG and the CSDDD mark an important step towards greater sustainability and responsibility in business. Companies must not only prepare to comply with current laws, but also be able to respond flexibly to upcoming regulations. A proactive and comprehensive strategy will be crucial to meet future requirements and achieve long-term sustainability success.

5 November 2024 | 5 min

Volkswagen and how better GRC could have helped

Volkswagen (VW) is currently facing several major challenges that have put the company in a difficult position. From falling sales and poor electric vehicle (EV) performance to operational inefficiencies, the automaker’s problems are multifaceted. These issues have led to significant restructuring efforts, including potential plant closures and job cuts unprecedented in VW’s history. While the company is now taking drastic measures to stabilize its finances, stronger governance, risk management, and compliance (GRC) practices could have helped prevent these issues or mitigate their severity.

The Core of VW’s Current Issues

  1. Declining Sales and Over-Reliance on China

VW has experienced a sharp decline in sales, particularly in Europe and China. The company’s dependence on China – where up to 40% of its sales came from in the past – has become a serious liability. Increasing competition from domestic automakers in China has reduced VW’s profits by 20% in 2023 and a further estimated 40% in 2024. This heavy dependence on one market, combined with lower demand in Europe, has left the company vulnerable to external shocks.

  1. Difficulties in electric vehicles

VW has invested heavily in electric vehicles in response to global sustainability trends, but its electric vehicle range has underperformed. The end of government subsidies in Germany has significantly slowed the adoption of electric vehicles, leading to a 16.4% decline in sales. This has put additional financial pressure on VW, especially as its competitors have overtaken the company in the electric mobility market.

  1. High production costs and low capacity utilization

In Germany, VW is struggling with high labor and energy costs, which have hurt its profitability. The company has a large workforce and numerous production facilities, yet many of these plants are operating well below capacity – some as low as 20-30%. This inefficiency contributed to VW’s profit margin falling to just 2.3% in the first half of 2024, compared to much higher margins at competitors like BMW and Mercedes

How better GRC could have helped

Improved governance: strategic oversight and alignment

Volkswagen’s governance structure is complex and involves multiple stakeholders, including the state of Lower Saxony, which has significant influence over key decisions. While this governance model has enabled stability in some areas, it has also made the company slow to adapt to market changes. Stronger governance practices that foster strategic agility could have helped VW better align its leadership and operations with the evolving needs of the EV market and the risks associated with over-reliance on China. A more dynamic governance framework would have enabled faster responses to external challenges such as changing consumer preferences and regulatory changes in key markets. For example, VW could have diversified its market focus earlier, reduced its dependence on China and better prepared for the decline in demand for internal combustion engine vehicles in Europe.

Risk management: Proactive identification and mitigation

A robust risk management system would have identified key risks earlier, particularly the company’s over-reliance on a single market and the challenges in the electric vehicle sector. Better risk assessment would have enabled VW to anticipate increasing competition in China and diversify its revenue streams, thus mitigating the financial impact of declining sales there. In addition, VW’s heavy investments in electric vehicles without a full understanding of market risks – such as the possibility of reduced government subsidies – reflect a deficit in risk management. With more proactive risk strategies, VW could have prepared by adjusting its product portfolio and scaling its investments in electric vehicles to align with more predictable market growth.

Compliance: Staying ahead of regulatory changes

Compliance violations have contributed to some of VW’s problems, particularly in the electric vehicle market. The abrupt end of subsidies for electric vehicles in Germany has surprised VW and has slowed sales of electric vehicles A well-implemented compliance framework would have anticipated such regulatory changes and allowed the company to advocate for more incremental changes or adjust its product pricing and marketing strategies in advance. In addition, compliance mechanisms could have helped VW adapt to the broader regulatory environment in Europe, particularly with regard to sustainability and emissions standards. Early adaptation to these regulations could have facilitated the company’s transition to electric vehicles and better positioned it against competitors who have made this transition more successfully.

Cultural and operational risk: Foster flexibility

VW’s rigid organization, corporate culture heavily influenced by unions and political stakeholders, has made it difficult to implement necessary operational changes. Failure to address long-standing issues related to workforce size and productivity has left the company with bloated costs. Strong GRC practices that foster cultural flexibility would have facilitated a smoother transition to a leaner, more efficient operating model and allowed VW to make adjustments before the crisis reached its current magnitude. Better governance structures could have fostered an environment where operational risks were addressed through earlier cost-cutting measures rather than drastic restructuring efforts that have led to internal resistance and public outcry.

Conclusion

Volkswagen’s current problems, from falling sales and poor electric vehicle performance to operational inefficiencies, underscore the need for stronger GRC practices. While the company is now taking significant steps to restructure and stabilize, better governance, risk management and compliance could have helped VW avoid or at least mitigate these problems. A more agile and proactive GRC framework would have enabled VW to anticipate market changes, diversify its risks and respond more effectively to regulatory changes. This may have prevented the company from experiencing the severe financial and operational difficulties it faces today.

For VW, a renewed focus on GRC could be critical to ensuring the company remains competitive in an increasingly complex and rapidly changing automotive landscape.

5 November 2024 | 4 min

What are Key Risk Indicators (KRIs) and why are they important?

Key Risk Indicators (KRIs) are key metrics that organizations use to alert to potential risks before they become real problems. KRIs serve as an early warning system that highlights risks in areas such as finance, compliance, operations and IT. They help companies identify, monitor and manage risks early. Below we explain why KRIs are so crucial and how they can be defined.

1. What are Key Risk Indicators (KRIs)?

KRIs are metrics that indicate potential threats to a company. They allow risks to be proactively monitored and assessed. A well-defined KRI gives companies an advance warning that a specific risk is increasing or changing, thus providing the basis for informed management decisions.

Example: In a financial company, the increase in loan defaults could be a KRI that indicates an increasing risk related to the loan portfolio.

KRIs differ from Key Performance Indicators (KPIs) because KPIs measure the success of business activities, while KRIs target risks that could impact that success.

2. Why are KRIs so important?

Early warning system for risks

KRIs give organizations the ability to identify potential problems before they happen, allowing action to be taken before a risk has a significant negative impact.

For example, a KRI for a company might be an increased spike in customer complaints, indicating potential operational problems. By intervening early, the company can prevent escalations.

Improving risk management

KRIs are an essential part of effective risk management. They help leaders monitor risks in real time and take appropriate action to minimize them. This increases responsiveness and reduces the risk of unexpected losses.

Focused resource allocation

Monitoring KRIs allows a company to use its resources more effectively. When a KRI indicates a specific risk, management can direct personnel, capital, or other resources to the affected areas to address the problem.

Meeting regulatory requirements

In many industries, such as finance, regulators require companies to monitor certain risks. KRIs help meet these requirements by continuously monitoring key risk areas.

3. How to define effective KRIs?

Defining and implementing effective KRIs is critical to getting the maximum benefit from these indicators. There are several steps to consider when setting KRIs:

  • Identify relevant risks

The first step in defining KRIs is to identify the relevant risks to the company. These risks depend on the industry, business environment, and specific business objectives. It is important to focus on risks that have the potential to significantly impact the company.

Example: In a technology company, risks related to data loss and cybersecurity might be at the forefront.

  • Establish measurable and specific indicators

An effective KRI must be measurable and based on clearly defined data. The data must be able to be collected and analyzed regularly to ensure continuous monitoring.

Example: One indicator could be the number of IT security incidents in a certain period of time. This gives the company a clear idea of ​​whether the security risk is increasing or decreasing.

  • Establish thresholds

Clear thresholds should be established for each KRI that signal when a certain risk level has been reached. These thresholds should be in line with the company’s risk tolerance.

Example: If more than 5% of customers have payment defaults in a given month, this could be an indication that the company’s credit risk is increasing.

  • Regular review and adjustment

KRIs must be regularly reviewed and adjusted if necessary to ensure they remain relevant and effective. The business environment is constantly changing and new risks may also emerge that need to be monitored.

4. Examples of common KRIs

Financial KRIs: liquidity ratios, debt ratio, net profit margin

Operational KRIs: production downtime, delivery delays

IT and security KRIs: number of cyber attacks, system availability rate

Reputation KRIs: increase in negative online reviews or media reports

Conclusion

KRIs are essential for risk management in modern companies. They provide valuable information about potential risks and help organizations take timely action to minimize negative impacts. By identifying relevant risks, setting measurable indicators and regularly monitoring and adjusting KRIs, companies can be better prepared for potential threats. In an increasingly complex and dynamic business world, KRIs help anticipate risks and strengthen the company’s resilience.

Integrating KRIs into corporate management creates the basis for proactive, informed decisions – an essential component of a successful risk management system.

5 November 2024 | 4 min

The ROI of Sustainability

In a rapidly changing global landscape, companies can no longer afford to dismiss sustainability as a mere trend. The growing focus on ESG (environmental, social, governance), which covers all aspects of sustainability, means companies need to recognize the tangible impact on their bottom line. But how do sustainability and profits relate? And why is it so important for companies to invest in environmentally and socially responsible practices, especially in their value chains?

Redefining ROI in a Sustainability Context

The return on investment (ROI) of sustainability is more complex than its traditional calculations. Standard ROI metrics often miss critical sources of value that can influence a company’s future growth trajectory. This deficiency can make them unsuitable for assessing the true benefits of sustainability investments, which are often long-term and extend beyond net profit.

Quantifying the ROI of Sustainability

For some, the term “sustainability” still conjures up images of added costs and regulatory burdens. But numerous studies paint a different picture:

  • The WEF found that companies that implement ethical supply chain practices can increase sales for responsible products by up to 20%, reduce supply chain costs by up to 16%, and increase brand value by up to 30%.
  • McKinsey reports that a solid ESG score can reduce the cost of capital by about 10%.
  • Research from Harvard Business School found that companies with strong sustainability practices outperform their competitors in terms of stock performance.

The question is: do successful companies simply have the means to invest in sustainability, or are investments in sustainability the engine of their success? Research increasingly shows that the latter is the case. Recent studies show that ESG practices predict financial performance and shareholder value.

These findings underscore a clear message: promoting sustainability does not mean sacrificing profitability.

Beyond financial returns, sustainability ROI also includes reputational value, brand loyalty, improved productivity, increased resilience, and improved employee satisfaction and morale. These intangible returns can add significantly to a company’s overall value and demonstrate the far-reaching benefits of sustainability investments.

How does sustainability increase ROI?

1. Cost savings: Sustainable companies often have a lower unit cost structure. Adopting sustainable practices can directly lead to significant cost reductions in various departments, including:

  • Waste reduction through recyclable materials and waste management.
  • Facilities through energy-efficient buildings and green maintenance practices. Manufacturing through optimized production and logistics processes.
  • Adoption of green technologies and suppliers.
  • Reduced business travel by prioritizing virtual meetings and reducing physical real estate requirements.

2. Revenue growth: Sustainability is not just about saving money, it’s also about making money. Sustainable brands tend to grow faster because they address increasing consumer demand for responsible products, leading to stronger customer loyalty and the attraction of new segments. Promoting green initiatives increases brand reputation, helps win tenders and enables the company to differentiate itself in crowded markets. Large companies now often look for suppliers with solid sustainability credentials and emphasize the importance of a strong ESG offering.

3. Risk mitigation: Proactively addressing ESG concerns can reduce the risk of punitive regulatory consequences and reputational damage from related incidents. Sustainability serves as a form of risk mitigation, reducing the likelihood of litigation and providing proactive solutions to future regulatory challenges.

4. Talent attraction and retention: Sustainability initiatives can have a profound impact on employees. Younger generations crave meaning in their work and emphasize the importance of a strong ESG offering. Companies that offer meaningful roles anchored in sustainability are more attractive to this talent pool, leading to higher productivity, engagement and morale.

5. Investment optimization: While investments in more traditional economic sectors such as fossil fuels are not going to disappear, there is increasing potential for ESG-related investments. According to various forecasts, sustainability metrics will play a crucial role in investment plans and become standard. This presents great opportunities for companies that focus on sustainability early and consistently.

How to determine the ROI of your ESG strategy

Given the comprehensive benefits of sustainability, companies must develop effective strategies to maximize their return. Here are the key considerations when creating your ESG strategy:

  • Focus on risk management. Expect external events that could negatively impact finances.
  • Think long-term. Sustainability is an investment in the future; immediate returns may not always be apparent.
  • Measure the impact of specific projects to understand cost savings and efficiency gains.
  • Accept immeasurability. Some benefits, such as improved working conditions that lead to higher employee satisfaction, may not have a direct numerical value, but are still important.
  • Respond proactively to external pressures from consumers and investors by incorporating these factors into your priorities.

Conclusion

Promoting sustainability is no longer just the moral right thing to do – it is a strategic business imperative. From driving revenue growth to optimizing investments, sustainability is changing our perception of ROI. As metrics become more transparent and integrated into overall investment assessments, the business world is undoubtedly becoming greener, both environmentally and financially.