Planning internal projects without a dedicated PMO
Software rollout, office move, certification, time recording or a new product line: internal initiatives often run alongside day-to-day business. Here is how to plan them so nothing important is missed.
What are internal projects?
An internal project has no external client: the sponsor is your own company, usually management or a business unit. Typical examples change processes, systems or locations.
Especially in mid-sized companies there is rarely a dedicated project manager. Planning is done by someone who has another job, and the initiative competes with daily business for time and attention.
| Aspect | Internal project | Client project |
|---|---|---|
| Sponsor | your own company | external client |
| Project lead | often on the side, changing | usually named |
| Budget | estimated internally, rarely tracked | fixed by quote and contract |
| Priority | competes with daily business | set by the delivery date |
| Typical risk | obligations and stakeholders are forgotten | change requests and delays |
Typical internal initiatives
Each initiative comes with a complete sample plan created with PathHub AI, including obligations with lead times.
ERP rollout
Materials management, production, warehouse and data migration in one plan.
See the sample planSAP S/4HANA
Move from SAP ECC with test cycles, training and hypercare.
See the sample planCRM rollout
Sales at several sites, data migration and training.
See the sample planTime recording
Recording rules, works agreement and data protection.
See the sample planOffice move
New workplaces, IT, safety instruction and moving while operating.
See the sample planISO 27001 certification
Gap analysis, measures, internal audit and certification audit.
See the sample planNIS2 implementation
Registration, risk management and reporting processes.
See the sample planWebsite relaunch
CMS, accessibility, SEO migration and hosting.
See the sample planCloud migration
Inventory, migration in waves, disaster recovery.
See the sample planE-invoicing
XRechnung and ZUGFeRD, ERP integration and audit-proof archive.
See the sample planWhistleblowing system
Internal reporting office with deadlines and data protection.
See the sample planRecruiting
Job ads, selection, works council and onboarding.
See the sample planAccess control
Access and video surveillance with DPIA and works agreement.
See the sample planNew product line
Recipe, label, production and retail listing.
See the sample planOnline shop relaunch
Shop system, payment provider and accessibility.
See the sample planWhy internal projects fail
Rarely for lack of skill. Almost always because of things that get lost in daily business before the project really starts.
- Planning on the sideWhoever leads the initiative has a full day job. The plan comes late or not at all.
- Unclear responsibilitiesNobody is explicitly accountable, so decisions stall.
- Forgotten stakeholdersWorks council, data protection or purchasing are involved only when it is urgent.
- Obligations with lead timeA works agreement, a data processing agreement or an audit date takes weeks. Starting late pushes the go-live.
- No eye on the budgetInternal hours and external services are not tracked; deviations show up too late.
Planning internal projects in 6 steps
- Set goal and scopeWhat should be different at the end, by when, with what budget? A SMART goal helps.SMART check
- Clarify stakeholders and rolesWho decides, who does the work, who is consulted, who is informed?RACI generator
- Check obligations and lead timesWhich laws, agreements and approvals does the initiative trigger, and how much lead time do they need?Obligations table
- Plan phases, tasks and milestonesFrom kick-off to close, with realistic buffers and dependencies.Templates
- Estimate budget and risksLine items instead of a lump sum, risks with mitigation and an owner.Risk matrix
- Execute, track, learnCompare progress and costs regularly and capture lessons for the next initiative.Kanban board
Which obligations typical internal initiatives trigger
This is how PathHub AI shows obligations in the plan (example: Germany): marked required or important, with lead time and, under “Rule & evidence”, the rule from the compliance library, its criteria and the consequences of a breach. “Statutory” means the obligation follows directly from the law. “Guide value” is a typical duration from practice. Not legal advice.
Rule & evidence
Why: The new system processes personal data of customers or employees.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: The provider processes personal data on your behalf (cloud, maintenance, support).
Legal basis: GDPR Art. 28: the contract must be in place before processing starts, including tests with real data or data migration.
- Data Processing Agreement (DPA) with cloud provider
- SLA with availability, RPO, RTO
- Exit and portability clause
- Data localisation and transfer mechanism (SCC / adequacy)
If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.
Rule & evidence
Why: Almost any software logs user actions and is therefore suitable for monitoring performance or behaviour.
Applies: only if a works council exists
Legal basis: Sec. 87(1) No. 6 Works Constitution Act: co-determination for technical systems suitable for monitoring behaviour or performance; suitability is enough. Without agreement the system must not be introduced.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: Tax-relevant data must be retained completely, unalterably and auditably, also after the system change.
Applies: if the system processes accounting or tax-relevant data (ERP, invoices, POS)
- Process documentation for all tax-relevant systems and procedures
- Complete and unalterable records, changes are logged
- Retention of tax-relevant documents for the statutory period (generally 8 or 10 years)
- Data access for tax audits possible (Sec. 147(6) German Fiscal Code)
- Receipt of structured e-invoices (XRechnung, ZUGFeRD) since 1 Jan 2025
- Issuing e-invoices to domestic businesses: from 2027 for prior-year turnover above EUR 800,000, from 2028 generally for all (exceptions incl. small-amount invoices, small businesses)
If breached: Formal defects can lead to the bookkeeping being rejected and the tax base being estimated (Sec. 162 German Fiscal Code); refusing data access can trigger a delay penalty (Sec. 146(2c)).
Rule & evidence
Why: The system must reflect statutory maximum hours, breaks and rest periods.
Legal basis: Since the Federal Labour Court decision of 13 Sept 2022 (1 ABR 22/21) employers must record working time systematically; time beyond 8 hours must be recorded and kept for two years (Sec. 16(2) ArbZG).
- Maximum 8 hours per working day, up to 10 hours with compensation within 6 months or 24 weeks (Sec. 3 ArbZG)
- Breaks: 30 minutes after 6 hours, 45 minutes after 9 hours (Sec. 4)
- Rest period of at least 11 hours after work ends (Sec. 5)
- Systematic recording of start, end and duration of working time (Federal Labour Court, 1 ABR 22/21)
- Record time beyond 8 hours and keep records for at least two years (Sec. 16(2))
If breached: Administrative offences under Sec. 22 ArbZG with fines up to EUR 30,000; intentional violations endangering health are criminal offences under Sec. 23.
Rule & evidence
Why: Time recording is a technical system that can reflect performance and behaviour.
Applies: only if a works council exists
Legal basis: Sec. 87(1) No. 2 and 6 BetrVG: co-determination on working time arrangements and technical monitoring systems.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: Time recording continuously processes personal data of all employees.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: New premises mean new escape routes, lighting, ventilation and workstations.
Legal basis: Sec. 3 ArbStättV: the risk assessment must be documented before work begins.
- Workplace risk assessment documented before work begins (Sec. 3)
- Escape and rescue routes, emergency exits and signage (ASR A2.3)
- Lighting, ventilation and room temperature according to the ASR
- Ergonomic display screen workstations
- Sanitary, break and first-aid rooms according to headcount
If breached: Administrative offence with fines up to EUR 5,000 per violation (Sec. 9 ArbStättV with Sec. 25 ArbSchG); intentionally endangering life or health is a criminal offence.
Rule & evidence
Why: Instruction is mandatory when working conditions change.
Legal basis: Sec. 12 ArbSchG: instruction on changes before work begins.
- Risk assessment for every workstation (incl. psychological stress)
- Instruction on hiring, after changes, after accidents — at least annually
- Safety officer and company doctor appointed (DGUV V2)
- First-aid responders (min. 5% of staff) trained
If breached: Fines up to EUR 30,000 per violation (Sec. 25 ArbSchG); persistent repetition or intentional endangerment: imprisonment up to one year or a fine (Sec. 26). Personal injury can additionally lead to criminal liability under the Criminal Code.
Rule & evidence
Why: A relocation changes commutes, workstations and procedures.
Applies: if a works council exists; reconciliation of interests for relocating the establishment in companies with more than 20 eligible employees
Legal basis: Sec. 111 sentence 3 No. 2 BetrVG: relocating the establishment is an operational change; a reconciliation of interests must be attempted beforehand.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: During a move, documents with personal data pass through many hands.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: With the migration, the provider processes your personal data.
Legal basis: GDPR Art. 28: contract before processing starts, including before migrating real data; for providers outside the EU also secure third-country transfers (Art. 44 ff.).
- Data Processing Agreement (DPA) with cloud provider
- SLA with availability, RPO, RTO
- Exit and portability clause
- Data localisation and transfer mechanism (SCC / adequacy)
If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.
Rule & evidence
Why: Storage locations, sub-processors and access paths change.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: NIS2 requires risks from service providers to be assessed and contractually covered.
Applies: if the company falls under NIS2 (e.g. from 50 employees or EUR 10m turnover in covered sectors)
- Documented IT risk management reviewed annually
- Business continuity plan and disaster recovery tested
- Multi-factor authentication (MFA) for critical systems
- Encryption of all sensitive data (at rest + in transit)
- Supplier security reviews (supply chain security)
- Annual cybersecurity training for all employees
If breached: Fines up to €10 million or 2% of global annual revenue. Personal liability of management for gross negligence.
Rule & evidence
Why: Services such as Microsoft 365 record employees' usage data.
Applies: only if a works council exists
Legal basis: Sec. 87(1) No. 6 BetrVG: cloud services with logs and analytics are suitable for monitoring performance or behaviour.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: Phrases like "young team" are frequent triggers of compensation claims.
Legal basis: Secs. 1, 7, 11 AGG: job ads must be free of discrimination; compensation claims must be raised within two months (Sec. 15(4)).
- Non-discriminatory job ads (m/f/d)
- Structured, anonymisable selection process
- Complaints office for discrimination set up (§13 AGG)
- Training of all managers on AGG obligations
If breached: Damages up to 3 months' salary for non-hiring due to discrimination. Additional compensation for severe personality rights violations.
Rule & evidence
Why: Applications may only be kept as long as AGG deadlines justify.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: Without consent or court replacement the person must not be employed.
Applies: if a works council exists and the company has more than 20 eligible employees
Legal basis: Sec. 99 BetrVG: works council consent to every hiring; it can object within one week.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: Missing or late documentation is subject to fines.
Legal basis: Sec. 2 NachwG: pay, working time and parties on the first working day, further information by the seventh calendar day, the rest within one month; text form possible since 2025.
- Names and addresses of the parties, pay and working time on the first working day at the latest
- Start, fixed term, place of work, duties, probation and rules on on-call work and overtime by the seventh calendar day
- Other information (e.g. leave, dismissal procedure, references to collective agreements) within one month
- Text form possible since 2025 if the document can be stored and printed and receipt is confirmed; written form on request
- Written form still required in sectors under Sec. 2a of the Act to Combat Undeclared Work (e.g. construction, hospitality)
If breached: Administrative offence with fines up to EUR 2,000 per violation (Sec. 4 NachwG).
Rule & evidence
Why: The channel must work independently, confidentially and with fixed deadlines.
Legal basis: HinSchG: internal reporting channel from 50 employees; acknowledgement within 7 days, feedback within 3 months (Sec. 17); a missing channel is subject to fines.
- Internal reporting office set up — written, phone, in-person on request
- Acknowledgement within 7 days, feedback within 3 months
- Confidentiality of whistleblower identity guaranteed
- Case files retained for 3 years
If breached: Fines up to €50,000 for missing reporting office. Obstructing a report or retaliation up to €500,000. Plus damages liability.
Rule & evidence
Why: Reports contain highly sensitive data about whistleblowers and accused persons.
- Legal basis for every processing of personal data (consent, contract, legal obligation, legitimate interest)
- Complete record of processing activities (Art. 30) for all processes
- Data Processing Agreements (DPA) with all sub-processors
- Data Protection Impact Assessment (DPIA) for high-risk processing
- Technical and organisational measures (TOM) documented
If breached: Fines up to €20 million or 4% of global annual revenue — whichever is higher. Plus civil damages claims by affected individuals.
Rule & evidence
Why: External channels process the reports on your behalf.
Applies: if an external platform or ombudsperson is used
Legal basis: GDPR Art. 28: contract before processing starts.
- Data Processing Agreement (DPA) with cloud provider
- SLA with availability, RPO, RTO
- Exit and portability clause
- Data localisation and transfer mechanism (SCC / adequacy)
If breached: Civil claims for data loss; recourse depends on contract. GDPR fines for non-compliance.
Rule & evidence
Why: Procedural rules affect workplace conduct.
Applies: only if a works council exists
Legal basis: Depending on the design (conduct rules, technical platform), co-determination rights under Sec. 87(1) No. 1 and 6 BetrVG may apply.
- Enable works council election from 5 eligible employees upward
- Co-determination on working time, monitoring systems, IT rollouts (§87)
- Hearing before every dismissal (§102) — written with reasons
- Balance-of-interests and social plan on operational changes (§111)
If breached: Dismissals without works council hearing are void. Administrative fines up to €10,000 per violation. Criminal liability (§119) for obstructing the works council up to 1 year imprisonment.
Rule & evidence
Why: Certification bodies and auditors are often booked months ahead; without a fixed date the whole initiative slips.
Rule & evidence
Why: Common certification standards require internal audits; open nonconformities put the certificate at risk or lead to follow-up audits.
Rule & evidence
Why: Faulty labels lead to recalls, and print lead times take weeks.
Legal basis: Reg. (EU) 1169/2011: mandatory particulars, emphasised allergens and nutrition declaration must be in place when placed on the market, online before purchase.
- Mandatory particulars under Art. 9 complete
- The 14 major allergens emphasised in the ingredients list (Annex II)
- Nutrition declaration (Art. 30)
- Minimum font size and legibility (Art. 13)
- Mandatory information available before purchase in distance selling (Art. 14)
If breached: Fines under the LFGB and the national implementing ordinance, warning letters from competitors, withdrawal or recall of mislabelled goods.
Rule & evidence
Why: New ingredients and steps bring new hazards and critical control points.
Legal basis: Art. 5 Reg. (EC) 852/2004: HACCP must be updated for new products, recipes or processes before production.
- Establishment registered with the competent authority, significant changes notified (Art. 6 Reg. 852/2004)
- HACCP: hazard analysis, critical control points, limits, monitoring, corrective actions, verification and records (Art. 5)
- Hygiene training documented, instruction under Sec. 43 Infection Protection Act before first work
- Traceability one step back and one step forward (Art. 18 Reg. 178/2002)
- Cleaning and pest control plan
If breached: Fines and penalties under the German Food and Feed Code (LFGB), official orders up to closure, recalls.
Rule & evidence
Why: The authority must always know what is produced where.
Applies: if a new site is used or the activity changes significantly
Legal basis: Art. 6 Reg. (EC) 852/2004: establishments and significant changes in activity must be notified to the food control authority.
- Establishment registered with the competent authority, significant changes notified (Art. 6 Reg. 852/2004)
- HACCP: hazard analysis, critical control points, limits, monitoring, corrective actions, verification and records (Art. 5)
- Hygiene training documented, instruction under Sec. 43 Infection Protection Act before first work
- Traceability one step back and one step forward (Art. 18 Reg. 178/2002)
- Cleaning and pest control plan
If breached: Fines and penalties under the German Food and Feed Code (LFGB), official orders up to closure, recalls.
Rule & evidence
Why: Without registration, selling is prohibited.
Applies: if the product reaches private end consumers in packaging
Legal basis: Packaging Act: LUCID registration and system participation before first placing on the market.
- Registration in the LUCID packaging register before placing on the market
- System participation (licensing) of sales packaging subject to participation with a dual system
- Identical volume reporting to LUCID and the dual system
- Declaration of completeness when statutory volume thresholds are exceeded
- Observance of take-back and deposit obligations (e.g. one-way deposit)
If breached: Sales and distribution ban for non-registration. Fines up to €200,000.
Tools for internal projects
Frequently asked questions
What is an internal project?
An initiative a company carries out for itself, without an external client. Examples are introducing new software, an office move, a certification or a new product line.
Who should lead an internal project?
A named person with enough time and backing from management. Without a clear lead, decisions stall and the project only runs on the side.
Do internal projects need their own budget?
Yes. Even if most effort is internal hours, plan external services, licences and a buffer and track actual costs, otherwise deviations show up too late.
When does the works council need to be involved?
In Germany, if a works council exists: among others for technical systems that can monitor behaviour or performance (Sec. 87(1) No. 6 BetrVG), for operational changes such as relocations (Sec. 111 BetrVG) and for hiring (Sec. 99 BetrVG). In good time means before decisions are final.
How do I plan an internal project with AI?
Describe the initiative in one sentence. PathHub AI creates phases, tasks with owners, schedule, budget frame, risks, stakeholders and obligations with lead times. You can try it without sign-up.
What is your next initiative?
Describe it in one sentence. In a few minutes you have a complete plan, free and without sign-up.
Create a free plan →