
Consileon Compliance Manager
An AI-powered compliance platform from German consultancy Consileon that reviews contracts, documents and internal processes against regulatory frameworks such as DORA, MaRisk, NIS-2, GDP and GMP, flagging compliance gaps and proposing concrete corrective measures for regulated organisations.
What is Consileon Compliance Manager?
The Consileon Compliance Manager is enterprise software that automates regulatory document and contract review using artificial intelligence. It is published by Consileon Business Consultancy GmbH, a management and IT consultancy based in Karlsruhe that has been trading since 2001 and employs around 550 people across fifteen European locations. Within the firm's portfolio of AI solutions, the Compliance Manager is the flagship product, with its own German and English product pages, a downloadable one-pager and a registered trademark filed in August 2026.
The problem it addresses is straightforward. The volume of new regulation has made manual review of contracts and internal documentation unsustainable in terms of time, headcount and quality. The Compliance Manager attacks that workload with six functions. Regulatory Watch is an AI web crawler that spots new or amended requirements, pre-sorts them and rates their relevance. RegProfile Builder derives the obligations that actually apply to a given organisation and defines the regulatory target state. The gap analysis compares the documented internal regulations — the German Schriftlich fixierte Ordnung — together with internal structures, processes and IT systems against that requirement list, and turns the deviations into an action plan. AI contract review scans the contract portfolio for missing clauses, critical wording and insufficient passages, with concrete suggestions. Reporting produces management and status reports for authorities such as BaFin. A regulatory assistant chatbot answers detailed questions and references the exact passages of the underlying text.
Six regulatory modules ship with the product: DORA, MaRisk, NIS-2, GDP, GMP and German public procurement law. Further frameworks are handled on request. The engine runs on large language models whose outputs are additionally verified by the Lighthouz AI quality assurance framework, which Consileon presents as satisfying the quality obligations of the EU AI Act. A traffic-light system highlights problem areas, all text-based formats are accepted, and human validation of every finding is built in by design. The product was co-developed with Prof. Jan Pieter Krahnen and carries the German BSFZ seal as a recognised research and development project.
What it does
- Screen a contract portfolio against a chosen regulation and flag missing clauses, critical wording and insufficient passages, with concrete rewording suggestions
- Run a gap analysis between the documented internal regulations, processes and IT systems and the applicable regulatory requirement list
- Build a tailored list of the regulatory obligations that genuinely apply to the organisation
- Detect new and amended regulatory requirements automatically and rank them by relevance
- Generate management and status reports for supervisory authorities such as BaFin in a few clicks
- Question a regulatory chatbot that answers highly specific questions and points back to the relevant passages of the legal text
- Produce audit-proof documentation of each review for internal audit, external auditors and regulators
When to use Consileon Compliance Manager / When not to
A quick filter to help you decide if Consileon Compliance Manager is the right fit.
When to use Consileon Compliance Manager
- Compliance officers at banks and financial service providers who have to evidence DORA and MaRisk conformity contract by contract
- Third-party and vendor risk teams working through large supplier contract portfolios against a single regulatory standard
- Regulatory affairs and quality managers in pharmaceuticals running GDP and GMP audits along the supply chain
- IT security and GRC teams mapping IT contracts and security agreements onto NIS-2 obligations
- Public sector contracting authorities checking incoming tenders for completeness and procurement-law conformity
When not to use Consileon Compliance Manager
- Individuals and small teams looking for a self-service tool, since there is no free plan, no free trial and no published price
- Buyers who need to compare costs before speaking to a vendor, because conditions are agreed case by case in a sales conversation
- Developers looking for a documented public API, as none is published for this product
- Organisations outside the European regulatory perimeter, the shipped library being built around EU and German frameworks
- Teams expecting an autonomous legal verdict, since expert validation of every AI finding is a deliberate part of the process
How to use Consileon Compliance Manager
A typical end-to-end flow, from setup to results.
- Request a live demo through the form on the product page, or contact one of the named consultants listed there
- Select the regulatory frameworks that matter to you from the shipped library — DORA, MaRisk, NIS-2, GDP, GMP or public procurement law
- Let Consileon pre-configure the software around the selected modules and your own list of requirements
- Go through a short setup phase in which the solution is deployed in your environment, as SaaS or on-premises in a data centre of your choice
- Feed in your company-specific policies, supplementary rules and individual assessment parameters to build a tailored review profile
- Upload contracts, quality documents or process descriptions through the user interface or through technical interfaces
- Let the AI check the content against the selected frameworks; a traffic-light system marks the problem areas within minutes
- Work through the grouped findings, which arrive as a structured checklist of recommended actions with a rationale attached to each one
- Have your own experts validate the suggestions, accepting them as they stand or adjusting them, so that final control stays with a human
- Export the detailed report as evidence for internal audit, external auditors or the supervisory authority, and add further modules whenever you need them
Pros & Cons
Pros
- A named, concrete regulatory scope rather than a generic promise: six frameworks ship documented, from DORA to German procurement law
- The whole chain is covered, from monitoring new rules to producing a report that stands up to an audit
- Traceability is built in: every AI suggestion comes with a rationale and points back to the relevant passage of the legal text
- Human-in-the-loop is assumed rather than apologised for, and final control remains with the customer's experts
- Security is described publicly and in unusual detail: encryption, logical and physical tenant separation, zero trust, penetration testing, OWASP, DDoS protection and identity management
- European data residency in certified data centres, with an explicit statement that customer data is not used to train AI models
- An on-premises alternative exists for organisations that cannot let their documents leave the building, and the publisher has been trading since 2001
Cons
- No price is published at all: both the setup fee and the usage tariff are negotiated individually, so budgeting requires a sales conversation
- Neither a free plan nor a free trial is advertised, and access is gated behind a demo request and a setup phase
- No terms and conditions are published anywhere on the site, so the contractual framework cannot be assessed in advance
- No Article 28 data processing agreement is published or announced as available, and the subprocessor list is supplied only on request
- ISO 27001 and OWASP are cited as standards the solution follows, without any product certification being displayed
- The shipped library stops at six frameworks, and the site and documentation are predominantly German, the English version being noticeably shorter
- There is no public API documentation and no mobile application, and the non-training commitment appears in a blog post rather than a contractual document
Pricing & Plans
No free plan and no free trial are advertised. The Consileon Compliance Manager is offered as a SaaS solution on a pay-per-use basis: use begins with a one-time setup fee covering configuration of the relevant regulatory modules and their integration into the customer's system landscape, after which billing switches to actual consumption with no long-term licensing commitment. No amount, currency or tier is published anywhere on the site, and the publisher states that individual pricing conditions are agreed in a personal consultation. An on-premises deployment in a data centre of the customer's choice is offered as an alternative to the hosted service.
- One-time setup fee — configuration of the selected regulatory modules and integration into the customer's system landscape
- amount not published
- Usage-based billing — pay only for what is actually used once implementation is complete
- with no long-term licensing commitment
- tariff not published
- Additional regulatory modules — bookable at any point during the usage period
- with shipped modules kept up to date throughout
- price not published
- On-premises deployment — installation in a data centre chosen by the customer as an alternative to the hosted SaaS service
- price not published
Data, GDPR & hosting
A consolidated view of how Consileon Compliance Manager handles your data.
GDPR overview
GDPR implementation is stated concretely rather than merely asserted. The publisher is established in Germany, so no Article 27 representative is required. Consileon states that all data remains within GDPR-compliant, certified European data centres and that processing takes place always in compliance with GDPR regulations in the EU. The privacy statement sets out the rights under Articles 7(3), 15, 16, 17, 18, 20 and 21, names a data protection officer, and identifies the Baden-Württemberg commissioner as the supervisory authority. Security is described in detail: encryption in transit and at rest, strict tenant separation, a zero-trust architecture, regular penetration testing, OWASP principles and a reference to ISO 27001. Two documentary gaps remain: no Article 28 processing agreement is published or announced as available, and the subprocessor list is supplied only on request.
Who owns the data?
The controller named consistently across the site is Consileon Business Consultancy GmbH in Karlsruhe, represented by Dr Joachim Schü, with a named data protection officer reachable at natalie.dittrich@consileon.de and a general rights address at datenschutz@consileon.de. Uploaded contracts and documents remain the customer's own: Consileon states they are never stored permanently and that each client's data is kept logically and physically separate from every other client's. No terms and conditions are published on the site, so no contractual clause covering rights over uploaded content could be examined. The competent supervisory authority is the data protection commissioner of Baden-Württemberg.
Reuse rights
Consileon states that uploaded material serves one purpose only: analysing documents against the regulatory frameworks the customer has selected. The company declares explicitly that customer data is not used to train AI models and is never stored permanently. The system draws its regulatory knowledge from the wording of the regulations themselves, from official explanatory sources and from quality-assured interpretations, not from customer files. Because no terms of use are published, the customer's freedom to reuse the outputs is not documented contractually; the site states only that the AI always supplies a rationale for each recommendation and that final control stays with the customer's own experts. On the website itself, contact-form data is deleted once the enquiry has been settled, and server log files after three months.
Data retention & training
Hosting summary
All processing takes place exclusively in certified European data centres, which Consileon describes as GDPR-compliant; no individual country is named beyond that European scope, and the product one-pager states plainly that customer data sits on European servers only. Data is encrypted both in transit and while stored. Each customer's data is separated from every other customer's both logically and physically, and a zero-trust architecture adds further layers so that access remains blocked even if an attacker reaches the system. Automated penetration tests run continuously, security mechanisms detect and block DDoS attacks, and strict identity and access management governs entry to confidential material. The solution follows OWASP principles and references ISO 27001, although neither is presented as a certification held by the product. Organisations that cannot let documents leave their own environment can instead deploy the software on-premises in a data centre of their choice. The publisher's own website is hosted in Germany.
Things to keep in mind
Risks and trade-offs to weigh before adopting Consileon Compliance Manager.
- No terms and conditions are published anywhere on the site, so the contractual framework cannot be checked before entering a sales conversation
- No Article 28 data processing agreement is published or announced as available, even though the product ingests corporate contracts and internal documentation
- The subprocessor list is supplied only on request, so the processing chain cannot be assessed in advance
- The commitment not to train on customer data appears in an October 2025 article about pharma audits, phrased for the publisher's AI solutions in general, rather than on the product page or in a contractual document
- ISO 27001 and OWASP are described as standards the solution follows, not as certifications held by the product, and should not be read as an audited attestation
- Automating compliance review invites over-reliance: the vendor builds in expert validation for a reason, and a traffic-light result is the start of a judgement, not a legal opinion
- The publisher is a consultancy, so the line between licensed software and a billable engagement is not always explicit, and the English forms still point at the product's former name, Regulatory Radar, suggesting a rebranding that has not fully propagated
Setup & Integrations
Technical difficulty
Low for the end user, because the effort sits with the vendor. Consileon pre-configures the software around the selected regulatory frameworks and runs a short setup phase in which the solution is deployed in the customer's environment, with internal policies and individual assessment parameters integrated to build a tailored review profile. Day-to-day use then amounts to uploading documents through the interface and reading structured reports, with no technical skill required. An on-premises installation is available for organisations that need it. No duration is quoted for the setup phase.
Deployment
Integrations
Behind Consileon Compliance Manager
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does the Consileon Compliance Manager actually do?
Which regulations does it cover?
What technology is it built on?
Are my documents used to train the AI?
Where is the data hosted?
How much does it cost?
Is there a free trial or a free plan?
Can it be installed on our own infrastructure?
Does the AI decide on its own?
Who publishes the tool?
Should you pick Consileon Compliance Manager?
The Consileon Compliance Manager is a narrow, serious product rather than a general-purpose assistant, and it is better for it. Where most compliance tooling promises to handle regulation in the abstract, this one names six frameworks it ships with — DORA, MaRisk, NIS-2, GDP, GMP and German public procurement law — and describes what it does with each: build the applicable requirement list, compare it against the documented internal regulations, scan the contract portfolio, and produce a report that survives an audit. Traceability is the strongest part of the design: every finding carries a rationale and points back to the passage it came from, and human validation is designed in rather than disclaimed. The security disclosure is unusually detailed, and the statements on European data residency and on not training models with customer data are welcome.
The weaknesses are documentary rather than functional. Nothing about the price is public: a one-time setup fee and usage-based billing are described, but no figure, currency or tier appears anywhere, so evaluation cannot begin without a sales conversation. More significantly for a tool that ingests corporate contracts, no terms and conditions are published, no Article 28 processing agreement is offered, and the subprocessor list is available only on request. ISO 27001 and OWASP are named as standards the solution follows, not as certifications it holds.
The realistic audience is a regulated organisation in the EU — a bank under DORA and MaRisk, a pharmaceutical manufacturer facing GDP and GMP audits, an entity in scope for NIS-2, or a public contracting authority — that already has a compliance budget and is prepared to buy through a consultancy. For that reader it is worth a demo. For anyone hoping to try software before talking to someone, it is not.
- Choosing a selection results in a full page refresh.
- Opens in a new window.