IT compliance for small and medium-sized enterprises – audit-proof and future-proof

Protect your business from liability risks and cyber attacks. We combine IT expertise with tax consultancy and auditing expertise – to ensure your IT processes are legally compliant and efficient.

Why IT compliance is a top priority

Managing directors are under increasing pressure today due to rising regulatory requirements: GoBD, NIS-2, DORA, VDA ISA, ISO 27001 and other standards are raising the bar for what constitutes a properly organised IT department.

GKK PARTNERS supports you in meeting these legal requirements in an audit-proof and future-proof manner – efficiently, practically and with an understanding of your business processes that only a long-standing tax and audit consultant can provide.

Start the compliance check

Procedural documentation (GoBD)

More than just a requirement – your calling card for a smooth start to a tax audit.

The tax authorities require GoBD-compliant procedural documentation – and tax auditors now routinely request it at the start of every audit. Nevertheless, it is often missing or out of date. The problem is that without traceable and documented processes, you risk being denied input tax deduction, facing tax assessments or even having your accounts rejected.

With professional procedural documentation, you create transparency, protect yourself against financial risks and ensure that the tax audit does not become a stressful situation.

We often identify further opportunities for digitalisation within your financial processes whilst preparing the procedural documentation. For example, GoBD-compliant procedural documentation allows you to destroy paper documents once they have been successfully digitised – saving you space and the effort involved in physical archiving. This lays the foundation for the complete digitisation of your incoming invoice process and significantly reduces your processing times.

Request procedural documentation now

Find out more about process documentation ...

Find out here how we guide you step by step, from the initial analysis to the final GoBD-compliant documentation.

Everything you need to know about procedural documentation

Cyber-Security Check

Your early-warning system against cyber risks – clear, easy to understand and practical.

Many small and medium-sized enterprises rely on their IT systems functioning properly – without knowing whether they are truly protected against cyber attacks. Without key security measures in place, there is a risk of business disruption, data loss, reputational damage and, increasingly, personal liability risks for the management. In the worst-case scenario, this can lead to insolvency.

Our Cyber Security Check provides you with a precise assessment of your current level of cyber security, identifies critical vulnerabilities and outlines practical immediate measures.

Request a cyber security check now

Find out more about the Cyber Security Check...

Our Cyber Security Check includes:

  • Kick-off and structured planning
  • Joint risk assessment
  • Analysis and evaluation of your current measures
    – based on the guidelines of the Alliance for Cyber Security and the BSI CyberRiskCheck in accordance with DIN SPEC 27076. (BSI – Federal Office for Information Security)
  • On-site or virtual assessment of risks and security measures
  • Management letter containing:
    • clear findings
    • prioritised recommendations for action
    • a clear presentation of the findings for senior management and IT
[Translate to English:] Beratung

Consultancy support throughout the project for the implementation of an ISMS

Guidance throughout the entire implementation process – technically, regulatory and audit-proof.

For many organisations, the introduction of an Information Security Management System (ISMS), for example in accordance with ISO 27001, is a complex project involving high regulatory, technical and organisational requirements. Often, organisations lack the in-house expertise to determine which measures are truly necessary, how roles and processes should be properly documented – and how, ultimately, certification readiness can be demonstrated.

Our consultancy support throughout the project ensures that your ISMS is implemented in a structured, efficient and compliant manner right from the start. We highlight what auditors actually look for, provide clear recommendations for action at every stage of the project, and ensure that your organisation becomes eligible for certification without any detours.

Request a consultation now

Find out more about ISMS consultancy...
  • Scope Definition: Defining the scope, identifying relevant stakeholders and regulatory requirements
  • Risk-based approach: Conducting risk analyses and developing appropriate risk treatment measures
  • Management system structure: Defining roles, responsibilities, policies and processes
  • Implementation of practical measures
  • Audit preparation: Support for internal audits and management reviews to ensure readiness for certification
[Translate to English:] VDA

Consultancy throughout the project to support the implementation of the VDA-ISA requirements (TISAX)

Ensure compliance through customer audits – and achieve TISAX certification readiness without any detours.

Many companies in the automotive industry face the challenge of correctly and fully implementing the VDA-ISA requirements in preparation for TISAX certification. Manufacturers’ expectations are high: they demand a verifiable, appropriate and comparable level of information security throughout the entire supply chain. Failure to meet these requirements poses significant business risks – ranging from delays during customer audits to the loss of business relationships.

Our project-based consultancy ensures that you implement the VDA-ISA requirements in a structured, efficient and audit-proof manner. We support you at every stage of the project, explain in practical terms what auditors actually look for, and ensure that you achieve certification readiness at an early stage – without unnecessary delays or extra effort.

Implement VDA-ISA confidently now

Find out more about VDA-ISA consultancy...
  • Scope Definition: Defining the scope of the project and identifying relevant stakeholders and regulatory requirements.
  • Status Review: Conducting a risk analysis and deriving appropriate risk mitigation measures.
  • Support during implementation: Assistance with defining roles, responsibilities, policies and processes.
  • Practical measures: Specific recommendations on what needs to be improved.
  • Assessment & improvement: Preparation for and support with internal audits and management reviews to ensure readiness for certification.
[Translate to English:] Analyse

NIS-2 Impact Analysis

Are you affected by the NIS 2 Directive?

With the entry into force of the NIS 2 Implementation Act, around 30,000 further organisations in Germany are now obliged to protect their IT systems and networks effectively. Failure to comply may result in substantial fines as well as personal liability risks for the management.

Among others, companies in the following sectors are affected (excerpt):

  • Healthcare
  • Production, processing and distribution of foodstuffs
  • Manufacturing / production of goods, e.g. mechanical engineering, motor vehicle parts, electronics
  • Production, manufacture and trade in chemical substances
  • Digital service providers

With our NIS 2 impact assessment, we identify the relevant business areas and IT systems and help you determine the extent to which your organisation is affected by NIS 2.
 

Carry out a NIS 2 impact assessment now

Find out more about NIS-2 and your next steps:

Here you can find comprehensive information on the NIS 2 Directive – and discover how we can support you in meeting the legal requirements for cyber and information security through measures such as GAP analyses, training and targeted implementation support.

Everything you need to know about the NIS 2 Directive

CISO-as-a-Service

Manage information security professionally – flexibly and without the need for a dedicated CISO role.

Cyber risks, increasing regulatory requirements and a lack of internal resources mean that information security has become a management priority for medium-sized businesses. At the same time, there is often a lack of a clear overview: What risks exist? Which measures are truly important? And who is responsible for strategic management?

With our CISO-as-a-Service, you gain an experienced external sparring partner for senior management and IT. We provide clarity on your current security situation, develop a practical roadmap and support you in establishing IT security in a structured, comprehensible and manageable way – from governance and risk management to reporting, compliance and contingency planning.

Structure your IT security now

CAREER
Scroll down Scroll down