Consileon Compliance Manager logo
Gov Legal · Legal Assistants

Consileon Compliance Manager

An AI-powered compliance platform from German consultancy Consileon that reviews contracts, documents and internal processes against regulatory frameworks such as DORA, MaRisk, NIS-2, GDP and GMP, flagging compliance gaps and proposing concrete corrective measures for regulated organisations.

Active GDPR compliant Usage Based No public API Verified by Guidaio
Overview

What is Consileon Compliance Manager?

The Consileon Compliance Manager is enterprise software that automates regulatory document and contract review using artificial intelligence. It is published by Consileon Business Consultancy GmbH, a management and IT consultancy based in Karlsruhe that has been trading since 2001 and employs around 550 people across fifteen European locations. Within the firm's portfolio of AI solutions, the Compliance Manager is the flagship product, with its own German and English product pages, a downloadable one-pager and a registered trademark filed in August 2026.

The problem it addresses is straightforward. The volume of new regulation has made manual review of contracts and internal documentation unsustainable in terms of time, headcount and quality. The Compliance Manager attacks that workload with six functions. Regulatory Watch is an AI web crawler that spots new or amended requirements, pre-sorts them and rates their relevance. RegProfile Builder derives the obligations that actually apply to a given organisation and defines the regulatory target state. The gap analysis compares the documented internal regulations — the German Schriftlich fixierte Ordnung — together with internal structures, processes and IT systems against that requirement list, and turns the deviations into an action plan. AI contract review scans the contract portfolio for missing clauses, critical wording and insufficient passages, with concrete suggestions. Reporting produces management and status reports for authorities such as BaFin. A regulatory assistant chatbot answers detailed questions and references the exact passages of the underlying text.

Six regulatory modules ship with the product: DORA, MaRisk, NIS-2, GDP, GMP and German public procurement law. Further frameworks are handled on request. The engine runs on large language models whose outputs are additionally verified by the Lighthouz AI quality assurance framework, which Consileon presents as satisfying the quality obligations of the EU AI Act. A traffic-light system highlights problem areas, all text-based formats are accepted, and human validation of every finding is built in by design. The product was co-developed with Prof. Jan Pieter Krahnen and carries the German BSFZ seal as a recognised research and development project.

What it does

  • Screen a contract portfolio against a chosen regulation and flag missing clauses, critical wording and insufficient passages, with concrete rewording suggestions
  • Run a gap analysis between the documented internal regulations, processes and IT systems and the applicable regulatory requirement list
  • Build a tailored list of the regulatory obligations that genuinely apply to the organisation
  • Detect new and amended regulatory requirements automatically and rank them by relevance
  • Generate management and status reports for supervisory authorities such as BaFin in a few clicks
  • Question a regulatory chatbot that answers highly specific questions and points back to the relevant passages of the legal text
  • Produce audit-proof documentation of each review for internal audit, external auditors and regulators
Audience

When to use Consileon Compliance Manager / When not to

A quick filter to help you decide if Consileon Compliance Manager is the right fit.

When to use Consileon Compliance Manager

  • Compliance officers at banks and financial service providers who have to evidence DORA and MaRisk conformity contract by contract
  • Third-party and vendor risk teams working through large supplier contract portfolios against a single regulatory standard
  • Regulatory affairs and quality managers in pharmaceuticals running GDP and GMP audits along the supply chain
  • IT security and GRC teams mapping IT contracts and security agreements onto NIS-2 obligations
  • Public sector contracting authorities checking incoming tenders for completeness and procurement-law conformity

When not to use Consileon Compliance Manager

  • Individuals and small teams looking for a self-service tool, since there is no free plan, no free trial and no published price
  • Buyers who need to compare costs before speaking to a vendor, because conditions are agreed case by case in a sales conversation
  • Developers looking for a documented public API, as none is published for this product
  • Organisations outside the European regulatory perimeter, the shipped library being built around EU and German frameworks
  • Teams expecting an autonomous legal verdict, since expert validation of every AI finding is a deliberate part of the process
Get started

How to use Consileon Compliance Manager

A typical end-to-end flow, from setup to results.

  1. Request a live demo through the form on the product page, or contact one of the named consultants listed there
  2. Select the regulatory frameworks that matter to you from the shipped library — DORA, MaRisk, NIS-2, GDP, GMP or public procurement law
  3. Let Consileon pre-configure the software around the selected modules and your own list of requirements
  4. Go through a short setup phase in which the solution is deployed in your environment, as SaaS or on-premises in a data centre of your choice
  5. Feed in your company-specific policies, supplementary rules and individual assessment parameters to build a tailored review profile
  6. Upload contracts, quality documents or process descriptions through the user interface or through technical interfaces
  7. Let the AI check the content against the selected frameworks; a traffic-light system marks the problem areas within minutes
  8. Work through the grouped findings, which arrive as a structured checklist of recommended actions with a rationale attached to each one
  9. Have your own experts validate the suggestions, accepting them as they stand or adjusting them, so that final control stays with a human
  10. Export the detailed report as evidence for internal audit, external auditors or the supervisory authority, and add further modules whenever you need them
Quick read

Pros & Cons

Pros

  • A named, concrete regulatory scope rather than a generic promise: six frameworks ship documented, from DORA to German procurement law
  • The whole chain is covered, from monitoring new rules to producing a report that stands up to an audit
  • Traceability is built in: every AI suggestion comes with a rationale and points back to the relevant passage of the legal text
  • Human-in-the-loop is assumed rather than apologised for, and final control remains with the customer's experts
  • Security is described publicly and in unusual detail: encryption, logical and physical tenant separation, zero trust, penetration testing, OWASP, DDoS protection and identity management
  • European data residency in certified data centres, with an explicit statement that customer data is not used to train AI models
  • An on-premises alternative exists for organisations that cannot let their documents leave the building, and the publisher has been trading since 2001

Cons

  • No price is published at all: both the setup fee and the usage tariff are negotiated individually, so budgeting requires a sales conversation
  • Neither a free plan nor a free trial is advertised, and access is gated behind a demo request and a setup phase
  • No terms and conditions are published anywhere on the site, so the contractual framework cannot be assessed in advance
  • No Article 28 data processing agreement is published or announced as available, and the subprocessor list is supplied only on request
  • ISO 27001 and OWASP are cited as standards the solution follows, without any product certification being displayed
  • The shipped library stops at six frameworks, and the site and documentation are predominantly German, the English version being noticeably shorter
  • There is no public API documentation and no mobile application, and the non-training commitment appears in a blog post rather than a contractual document
Pricing

Pricing & Plans

No free plan and no free trial are advertised. The Consileon Compliance Manager is offered as a SaaS solution on a pay-per-use basis: use begins with a one-time setup fee covering configuration of the relevant regulatory modules and their integration into the customer's system landscape, after which billing switches to actual consumption with no long-term licensing commitment. No amount, currency or tier is published anywhere on the site, and the publisher states that individual pricing conditions are agreed in a personal consultation. An on-premises deployment in a data centre of the customer's choice is offered as an alternative to the hosted service.

Plan 1
  • One-time setup fee — configuration of the selected regulatory modules and integration into the customer's system landscape
  • amount not published
Plan 3
  • Additional regulatory modules — bookable at any point during the usage period
  • with shipped modules kept up to date throughout
  • price not published
Plan 4
  • On-premises deployment — installation in a data centre chosen by the customer as an alternative to the hosted SaaS service
  • price not published
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Consileon Compliance Manager handles your data.

GDPR overview

GDPR implementation is stated concretely rather than merely asserted. The publisher is established in Germany, so no Article 27 representative is required. Consileon states that all data remains within GDPR-compliant, certified European data centres and that processing takes place always in compliance with GDPR regulations in the EU. The privacy statement sets out the rights under Articles 7(3), 15, 16, 17, 18, 20 and 21, names a data protection officer, and identifies the Baden-Württemberg commissioner as the supervisory authority. Security is described in detail: encryption in transit and at rest, strict tenant separation, a zero-trust architecture, regular penetration testing, OWASP principles and a reference to ISO 27001. Two documentary gaps remain: no Article 28 processing agreement is published or announced as available, and the subprocessor list is supplied only on request.

Who owns the data?

The controller named consistently across the site is Consileon Business Consultancy GmbH in Karlsruhe, represented by Dr Joachim Schü, with a named data protection officer reachable at natalie.dittrich@consileon.de and a general rights address at datenschutz@consileon.de. Uploaded contracts and documents remain the customer's own: Consileon states they are never stored permanently and that each client's data is kept logically and physically separate from every other client's. No terms and conditions are published on the site, so no contractual clause covering rights over uploaded content could be examined. The competent supervisory authority is the data protection commissioner of Baden-Württemberg.

Reuse rights

Consileon states that uploaded material serves one purpose only: analysing documents against the regulatory frameworks the customer has selected. The company declares explicitly that customer data is not used to train AI models and is never stored permanently. The system draws its regulatory knowledge from the wording of the regulations themselves, from official explanatory sources and from quality-assured interpretations, not from customer files. Because no terms of use are published, the customer's freedom to reuse the outputs is not documented contractually; the site states only that the AI always supplies a rationale for each recommendation and that final control stays with the customer's own experts. On the website itself, contact-form data is deleted once the enquiry has been settled, and server log files after three months.

Data retention & training

Retention summary
Documents submitted to the tool are not kept: Consileon states that customer data is never stored permanently, although no specific retention period for uploaded files is published and no product-level retention policy appears in any contractual document. On the publisher's website the picture is more precise. Data entered into a contact form is deleted automatically once the enquiry has been dealt with, server log files are erased after three months, and the Cookiebot consent cookie lasts twelve months. Business correspondence such as emails and telephone notes is normally kept for six years to the year end under German commercial and tax retention duties, with shorter deletion periods for connection records and Microsoft Teams communication.
Trains on customer data
No

Hosting summary

All processing takes place exclusively in certified European data centres, which Consileon describes as GDPR-compliant; no individual country is named beyond that European scope, and the product one-pager states plainly that customer data sits on European servers only. Data is encrypted both in transit and while stored. Each customer's data is separated from every other customer's both logically and physically, and a zero-trust architecture adds further layers so that access remains blocked even if an attacker reaches the system. Automated penetration tests run continuously, security mechanisms detect and block DDoS attacks, and strict identity and access management governs entry to confidential material. The solution follows OWASP principles and references ISO 27001, although neither is presented as a certification held by the product. Organisations that cannot let documents leave their own environment can instead deploy the software on-premises in a data centre of their choice. The publisher's own website is hosted in Germany.

Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Consileon Compliance Manager.

  • No terms and conditions are published anywhere on the site, so the contractual framework cannot be checked before entering a sales conversation
  • No Article 28 data processing agreement is published or announced as available, even though the product ingests corporate contracts and internal documentation
  • The subprocessor list is supplied only on request, so the processing chain cannot be assessed in advance
  • The commitment not to train on customer data appears in an October 2025 article about pharma audits, phrased for the publisher's AI solutions in general, rather than on the product page or in a contractual document
  • ISO 27001 and OWASP are described as standards the solution follows, not as certifications held by the product, and should not be read as an audited attestation
  • Automating compliance review invites over-reliance: the vendor builds in expert validation for a reason, and a traffic-light result is the start of a judgement, not a legal opinion
  • The publisher is a consultancy, so the line between licensed software and a billable engagement is not always explicit, and the English forms still point at the product's former name, Regulatory Radar, suggesting a rebranding that has not fully propagated
Setup

Setup & Integrations

Technical difficulty

Low for the end user, because the effort sits with the vendor. Consileon pre-configures the software around the selected regulatory frameworks and runs a short setup phase in which the solution is deployed in the customer's environment, with internal policies and individual assessment parameters integrated to build a tailored review profile. Day-to-day use then amounts to uploading documents through the interface and reading structured reports, with no technical skill required. An on-premises installation is available for organisations that need it. No duration is quoted for the setup phase.

Deployment

Web app

Integrations

Lighthouz AI
Company

Behind Consileon Compliance Manager

Company name
Consileon Business Consultancy GmbH
Founded
01/05/2001
Country of origin
🇩🇩 Germany
Headquarters
Maximilianstraße 5, 76133 Karlsruhe
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
INFORMATION_NOT_FOUND
Legal contact

Fundraising

No venture funding is reported: Consileon describes itself as an owner-managed consultancy and no fundraising round appears anywhere on the site
Growth has come through acquisitions and stakes rather than capital rounds: Consileon Schweiz in 2002, Consileon Polska in 2005, syracom in 2012, ajco in 2013, FiANTEC in 2016, Lüdke + Döbele in 2017, aye4fin and Consileon Applied Business in 2019, Consileon DX in 2022, Opereon Consulting in 2023 and Q-Soft in 2025
ajco solutions GmbH was merged into the company on 17 April 2025
Public research support rather than equity: a grant of EUR 93,570 is recorded for 1 April 2018, and the Compliance Manager itself carries the BSFZ seal as a recognised research and development project under §6 of the German Research Allowance Act

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What does the Consileon Compliance Manager actually do?
It automates the review of contracts, documents and process descriptions against regulatory frameworks, identifies compliance gaps and proposes targeted corrective measures. The findings are grouped into a structured checklist and can be exported as a report for internal audit, external auditors or a supervisory authority.
Which regulations does it cover?
Six frameworks ship with the product: DORA, MaRisk, NIS-2, GDP, GMP and German public procurement law. Consileon states that further EU directives, regulations and industry standards can be added on request, and that the modules already installed are kept up to date during the usage period.
What technology is it built on?
It runs on large language models. Their outputs are additionally verified by the Lighthouz AI quality assurance framework, which Consileon presents as covering the quality assurance obligations of the EU AI Act. The regulatory knowledge comes from the wording of the regulations, official explanations and quality-assured interpretations.
Are my documents used to train the AI?
No. Consileon states that customer data is never stored permanently and is not used for AI model training. This statement appears in the publisher's article on data security in AI pharma audits, phrased for its AI solutions generally rather than in a contractual document.
Where is the data hosted?
Exclusively in certified European data centres. Data is encrypted in transit and at rest, tenants are separated both logically and physically, a zero-trust architecture is in place, and penetration tests run regularly. No individual country is named beyond the European scope.
How much does it cost?
No price is published. The model is a one-time setup fee followed by usage-based billing, with no long-term licensing commitment. Consileon states that individual pricing conditions are agreed in a personal consultation, so a budget figure requires contacting the vendor.
Is there a free trial or a free plan?
Neither is advertised on the site. The entry point is a live demo request through the form on the product page, or contact with one of the named consultants. The downloadable product one-pager is freely available.
Can it be installed on our own infrastructure?
Yes. Alongside the hosted SaaS service, Consileon offers an on-premises deployment in a data centre chosen by the customer, which is relevant for organisations that cannot let sensitive documents leave their own environment.
Does the AI decide on its own?
No. A professional validation step by the customer's own experts is built into the process: they review the suggestions, adopt them directly or adjust them. The AI always supplies a rationale for each recommendation, so final control stays with a human.
Who publishes the tool?
Consileon Business Consultancy GmbH, a management and IT consultancy in Karlsruhe active since 2001, with around 550 staff across fifteen European locations. The product was co-developed with Prof. Jan Pieter Krahnen and carries the German BSFZ seal as a recognised research and development project.
Conclusion

Should you pick Consileon Compliance Manager?

The Consileon Compliance Manager is a narrow, serious product rather than a general-purpose assistant, and it is better for it. Where most compliance tooling promises to handle regulation in the abstract, this one names six frameworks it ships with — DORA, MaRisk, NIS-2, GDP, GMP and German public procurement law — and describes what it does with each: build the applicable requirement list, compare it against the documented internal regulations, scan the contract portfolio, and produce a report that survives an audit. Traceability is the strongest part of the design: every finding carries a rationale and points back to the passage it came from, and human validation is designed in rather than disclaimed. The security disclosure is unusually detailed, and the statements on European data residency and on not training models with customer data are welcome.

The weaknesses are documentary rather than functional. Nothing about the price is public: a one-time setup fee and usage-based billing are described, but no figure, currency or tier appears anywhere, so evaluation cannot begin without a sales conversation. More significantly for a tool that ingests corporate contracts, no terms and conditions are published, no Article 28 processing agreement is offered, and the subprocessor list is available only on request. ISO 27001 and OWASP are named as standards the solution follows, not as certifications it holds.

The realistic audience is a regulated organisation in the EU — a bank under DORA and MaRisk, a pharmaceutical manufacturer facing GDP and GMP audits, an entity in scope for NIS-2, or a public contracting authority — that already has a compliance budget and is prepared to buy through a consultancy. For that reader it is worth a demo. For anyone hoping to try software before talking to someone, it is not.