Toll-free hotline: 0800 123 2 321 (free of charge from German landline and mobile networks)
Quality & Compliance

Compliance, Standards Conformity and Legal Framework

Professional investigative work for companies, law firms and institutional clients today regularly takes place in the context of existing compliance management systems. Interdetekt orients the organisation and documentation of its investigative processes towards the relevant international and European standards.

Classification

In Germany, there is currently no statutory obligation to be certified under the standards named above; their application is driven predominantly by clients' contractual requirements, industry standards, or as a voluntary demonstration of professional organisational and quality structures. Interdetekt aligns its understanding of quality and work practice with these core standards, without this implying a formal certification claim unless such certification is separately evidenced.

International Standards as a Frame of Reference

ISO 37301 — Compliance management systems. The globally authoritative standard for compliance management addresses compliance culture, responsibilities, risk assessment, whistleblowing systems, internal investigations, documentation and continual improvement. For investigative work, orientation towards this standard means: neutral fact-finding, documented procedure, traceability of every measure, observance of legal limits, and an unbroken chain of evidence.

ISO 37001 — Anti-bribery management systems. This standard's focus is combating bribery, undue advantage, corruption and kickback schemes. External investigators are regularly engaged for corruption investigations, supplier vetting, due diligence, background checks and interviewing.

ISO 37002 — Whistleblowing management systems. This standard governs how whistleblowers are handled — identity protection, documentation, objectivity, investigation of incoming reports, and procedural protection.

ISO 31000 — Risk management. Investigations frequently serve directly to clarify risk — for example in cases of economic crime, insider trading, fraud, breach of fiduciary duty, sabotage or conflicts of interest.

ISO 27001 — Information security. By now nearly indispensable for investigative work: data security, encryption, access concepts, retention, handling of data carriers, and evidence securing — particularly relevant for surveillance, video recordings, cloud storage, mobile phone analysis and forensic data carriers.

ISO 22301 — Business continuity. Relevant to crisis investigations, cyber incidents, sabotage, and emergency management.

ISO 9001 — Quality management. Increasingly the foundation of professional investigative work: standardised investigation processes, review mechanisms, documentation, error prevention, and continual improvement.

European Standards

EN 17483 was developed specifically for private security services and covers qualification, integrity, management structure, deployment planning, risk analysis, data protection and documentation.

ISO 18788 is a management system for security operations, particularly relevant for international investigations, facility protection, security consulting and overseas investigations, placing great emphasis on human rights, the rule of law, proportionality and transparency.

Corporate Compliance Frameworks

Beyond the standards named above, many clients additionally work to their own internal frameworks, such as the COSO Internal Control Framework, COSO ERM, the Three Lines Model of the Institute of Internal Auditors, or company-specific corporate investigation guidelines. Interdetekt is set up to integrate into clients' existing compliance structures.

Legal Framework

Independent of voluntary standards, mandatory statutory requirements apply to any investigative activity:

  • Data protection: GDPR and BDSG, in particular Articles 5, 6, 9, 32 and 35 GDPR
  • Criminal law: Sections 201 et seq., 202a–202d, 238, 263, 266 and 303a of the German Criminal Code (StGB)
  • Civil law: Sections 823 et seq. BGB, the general right of personality, the right to one's own image
  • Employment law: proportionality, works council rights, Section 26 BDSG
  • Whistleblower protection: German Whistleblower Protection Act (HinSchG)

Integration into a Client's Compliance System

  • confidentiality agreements (NDA)
  • compliance with the client's code of conduct
  • data protection agreements
  • seamless documentation of every investigative step
  • ensuring the integrity of evidence (chain of custody)
  • traceable, reproducible methodology
  • proof of professional qualification
  • transparent rules on conflicts of interest
  • clear escalation channels for compliance breaches
  • audit-proof archiving

Industry-Specific Requirements

IndustryTypical requirements
BankingMaRisk, BAIT, anti-money-laundering
InsuranceIDD compliance, fraud prevention
PharmaceuticalsGxP, anti-corruption, supply chain controls
AutomotiveTISAX, information security
EnergyCritical infrastructure (KRITIS), NIS2 implementation
Public sectorPublic procurement law, corruption prevention
International groupsUK Bribery Act, FCPA, OECD guidelines

Our Commitment to the Professional Code of Conduct

We expressly commit to the Professional Code of Conduct for Private Investigators in Germany (Berufsordnung für Detektive). This commitment is not based solely on our membership in professional associations, but on the conviction that serious investigative work requires clear legal, professional and ethical standards.

Every engagement is reviewed for a legal or legitimate interest and is handled exclusively to the extent that is permissible, necessary and proportionate. Confidentiality, data protection, objectivity, truthful reporting and continuous further training are, for us, binding foundations of professional practice.

These requirements apply equally to all employees, external investigators and subcontractors engaged by us.

Professional Code of Conduct (PDF)