Tpirot sza arch aust hires 053 TP 7645

Reform of Corporate Fines: Higher Fines and Greater Emphasis on Compliance

The planned reform of Section 30 of the German Act on Regulatory Offences (OWiG) significantly increases the range of corporate fines and, for the first time, introduces general criteria for determining the amount of fines. Of particular relevance: An effective and documented compliance management system may explicitly reduce fines in the future.

Key Takeaways:

  • The government’s draft bill proposes quadrupling the current maximum fines: to EUR 40 million for intentional predicate offenses and EUR 20 million for negligent predicate offenses, in each case committed by a person with management responsibility. The maximum amounts apply across all types of offenses; the disgorgement of economic benefits remains possible.
  • For the first time, general statutory criteria for determining fines are to be introduced. An effective compliance management system and convincing post-offense conduct can reduce the fine.
  • High corporate fines also place even greater emphasis on holding managing directors and supervisory board members personally liable.
  • The draft has not yet become law. However, companies should already begin reviewing their compliance management system, the documentation demonstrating its effectiveness, and the procedures for handling suspected violations.

What are corporate fines?

Under German law, only natural persons can be held criminally liable. Companies, on the other hand, cannot be convicted under criminal law. The so-called corporate fine under Section 30 OWiG closes this gap: It allows corporate fines to be imposed on the company if a person with management responsibility – such as a de facto managing director or an authorized signatory – commits a criminal or regulatory offence through which duties incumbent on the company are violated, or if the company is thereby enriched.

Furthermore, Section 130 OWiG can be used to address supervisory failures at the management level. If an employee commits a legal violation that would have been significantly impeded or prevented by proper supervision, the failure to supervise can be penalized as a regulatory offense committed by the responsible person with management responsibility and, pursuant to Section 30 OWiG, also result in a corporate fine.

Why are corporate fines being reformed?

It has long been undisputed that the law governing corporate fines is in need of reform. In Germany, however, no consensus has yet been reached on the correct approach: whether to create a new Corporate Sanctions Act (Verbandssanktionengesetz) or to amend the two provisions of the law on regulatory offenses.

The legislature has now opted for the more modest approach of amending Sections 30 and 130 OWiG. However, the impetus for the planned reform is not a domestic political initiative, but rather the obligation to implement the Directive on the protection of the environment through criminal law (Environmental Crime Directive) (EU) 2024/1203 on the criminal-law protection of the environment. The EU directive requires member states to provide for effective, proportionate, and dissuasive sanctions against companies for serious environmental crimes.

However, the government’s draft does not limit the amendments to Section 30 OWiG to environmental offenses. Rather, the expanded range of fines is intended to apply to all intentional and negligent predicate offenses committed by a person with management responsibility that could result in a corporate fine – including, for example, corruption, breach of trust (Untreue), or tax offences. At the same time, general statutory criteria for determining corporate fines are to be introduced for the first time.

Ultimately, the reform represents a significant tightening of the law but does not constitute a systemic change: it introduces neither a separate corporate criminal law nor a general turnover-based fine model. Section 30 OWiG remains anchored in regulatory offense law.

How high could fines be in the future?

Section 30(2) OWiG-E (draft) provides for the following maximum amounts for corporate fines, depending on the degree of fault on the part of the person with management responsibility:

Predicate OffenseCurrent LawGovernment Draft
Intentional criminal offenseup to EUR 10 millionup to EUR 40 million
Negligent criminal offenseup to EUR 5 millionup to EUR 20 million

The maximum amounts specified apply exclusively to the punitive component of the corporate fine. Unlawfully obtained profits may also be disgorged through asset recovery, meaning that the overall financial exposure may therefore significantly exceed EUR 40 million.

In cases where an regulatory offense serves as the predicate offense, the maximum amount specified for that particular offense remains applicable.

How will the amount of the fine be determined in the future?

The new Section 30(2a) of the draft OWiG (OWiG-E) is intended to establish a general statutory framework for determining fines for the first time. The following factors are particularly relevant:

  • The offence and corporate responsibility: the severity, duration, and impact of the violation, as well as any factors that may have facilitated the offense, such as organizational shortcomings or corporate culture.
  • Pre- and post-offense conduct: Previous violations, efforts to investigate the facts, cooperation, and remediation or compensation for harm caused.
  • Compliance: Preventive compliance measures prior to the offense, and reactive measures taken after the offense to address deficiencies.
  • Economic circumstances: The company’s size, profitability, and financial capacity.

This list is not exhaustive. For companies, codification provides greater predictability and legal certainty, but at the same time requires a robust factual and documentary basis for mitigating factors.

What role does a compliance management system play?

Effective compliance management systems (“CMS”) can reduce the fine. However, the government’s draft does not provide for an automatic reduction. Rather, the key factors are the appropriateness, actual implementation, and demonstrable effectiveness of the measures.

Both preventive measures and actions taken after an incident – such as those conducted as part of an internal investigation, mitigation of damage, and the remediation of identified vulnerabilities – may be taken into account.

According to the explanatory memorandum to the draft bill, however, mere “paper compliance” is expressly insufficient. If compliance structures serve merely to conceal violations, or if company management clearly does not stand behind its own rules, a reduction in the fine may be ruled out, or the structure may even result in a higher fine.

Companies should therefore, in particular:

  • Conduct a risk-based review of their CMS and align it with their business model, size, and risk profile.
  • Document implementation, training, controls, and responses to reports in a traceable manner.
  • Define responsibilities and escalation procedures for suspected violations and internal investigations in advance.

Preventive measures are not the only measures that may have a mitigating effect. The proposed Section 30(2a) OWiG-E would also expressly take post-offence remedial conduct into account. Companies that, following an incident, proactively investigate the matter internally and cooperate openly with the investigating authorities may benefit from a significant reduction in the fine. The draft law now creates a clear and reliable incentive for this.

What are the implications for members of management and M&A transactions?

Liability of Management and Supervisory Board Members

Substantial corporate fines regularly lead to closer scrutiny of potential breaches of organizational or supervisory duties by managing directors and supervisory board members. For members of management, therefore, appropriate organization, effective supervision, and robust documentation of compliance measures are becoming increasingly important.

M&A Transactions

Historical compliance violations and deficiencies at the target company can increase the risk of sanctions and negatively impact valuation. Due diligence should therefore include an in-depth review of the target’s compliance history and the actual effectiveness of its compliance management system (CMS). Identified risks must be quantified and addressed in the share or asset purchase agreement through warranties, indemnities, or other risk allocations.

What is the current status of the legislative process?

The government bill (BT-Drs. 21/6133) dated May 26, 2026, was debated for the first time in the Bundestag on June 11, 2026; a public hearing was held on July 6, 2026, in the Committee on Legal Affairs and Consumer Protection. The final content and the effective date remain to be determined. Until the law is promulgated, the current law remains in effect.

In its statement of June 12, 2026, the Bundesrat proposed that appropriate compliance measures be established as an independent factor that must be taken into account in favor of the company, and that five fundamental elements of appropriate compliance measures be included in Section 130 OWiG. The Federal Government has so far rejected both proposals in its response dated June 24, 2026. Details can be found in the Bundesrat’s statement and the Federal Government’s response (BT-Drs. 21/6668).

FAQ

This client information contains only a non-binding overview of the subject area addressed in it. It does not replace legal advice. We would be happy to assist you with a CMS Health Check to conduct a risk-based review and assist with the legally robust documentation of your existing compliance structures. Further information on our advisory services can be found in the Compliance section.

Please do not hesitate to contact us for this client information: