Skip to content

20 August 2026 | 10 min

BaFin Takes Over AI Market Surveillance: Why AI Governance in the Financial Sector Must Become Audit-Ready

BaFin has received new responsibilities for the supervision of artificial intelligence in the German financial sector. Since 29 July 2026, it has acted as market surveillance authority for AI systems that are directly connected to regulated financial activities. This includes, among others, banks, insurers and other financial institutions under BaFin supervision.

For financial institutions, this is an important turning point. AI governance is becoming part of ongoing supervision. AI systems are no longer merely an innovation, efficiency or IT topic. They are becoming a governance, risk and compliance topic that must be documented, controlled and auditable.

The key question is therefore no longer only: Where can AI create value? The more important question is: Can we prove where AI is used, which risks exist, which obligations apply, who is responsible and which controls are in place?

BaFin has been the market surveillance authority for certain AI systems in the financial sector since 29 July 2026. Its responsibility applies to AI systems that are directly linked to regulated financial activities.

This affects financial institutions under BaFin supervision, including banks, insurers and other regulated financial companies. In practice, this means that AI governance is moving closer to established supervisory expectations around risk management, compliance, internal control systems and auditability.

Initially, the focus is likely to include transparency obligations, prohibited AI practices and measures to ensure sufficient AI literacy among employees. From December 2027, BaFin is also expected to supervise high-risk AI systems in the financial sector, such as AI used in creditworthiness assessments or certain insurance pricing models.

For GRC teams, the message is clear: AI inventories, risk assessments, roles, controls, vendor governance and audit trails need to become robust and defensible.

Why BaFin’s New Role Matters

The EU AI Act is a horizontal regulation. It applies across sectors. At the same time, regulated industries are not starting from scratch. Existing supervisory structures are being connected with AI regulation, and this is exactly what is now happening in the German financial sector.

BaFin will supervise AI systems that are directly connected to regulated financial activities. As a result, AI Act compliance in banks, insurers, fintechs and other financial companies will become more closely linked to familiar supervisory practices: risk governance, documentation, management responsibility and internal controls.

This matters because AI in finance can affect sensitive decisions. AI can be used in customer communication, credit scoring, fraud detection, insurance risk assessment, pricing, customer classification, compliance monitoring, anti-money laundering or portfolio risk models. Many of these use cases touch consumer protection, data protection, discrimination risks, model risk, cybersecurity and operational resilience.

For GRC leaders, this creates a clear mandate. AI must become visible, manageable and auditable.

AI Governance Needs More Than a Policy

Many organisations already have AI policies or general guidelines for the use of generative AI. That is a useful starting point, but it is not enough for supervised financial institutions.

Supervisors do not only look for principles. They look for implementation. Financial institutions need to be able to show which AI systems are used, in which business process they operate, which regulatory role the company has, whether the use case is connected to a regulated financial activity and which risks arise for customers, market integrity, data protection or fundamental rights.

The same applies to transparency obligations, prohibited AI practices, human oversight, provider dependencies and training measures. It is not enough to state that AI is used responsibly. Companies need evidence that the relevant risks were assessed, that controls were defined and that responsibilities are clear.

AI governance therefore becomes a classic GRC process: identify, classify, assess, control, document, monitor and improve.

The First Step: A Reliable AI Inventory

Without an AI inventory, no financial institution can reliably determine which systems fall under BaFin’s market surveillance or other AI Act obligations. The inventory is the foundation of every serious AI governance structure.

A useful AI inventory should go beyond large models or central IT projects. It should also capture business-unit tools, external SaaS solutions, chatbots, analytics tools, agency services and AI functions embedded in existing applications.

The inventory should document the purpose of the AI system, the business process it supports, the responsible owner, the provider or internal development team, the user groups, the data involved, the connection to regulated financial activities and the initial classification under the AI Act. It should also capture data protection relevance, third-party dependencies, transparency obligations, controls, review cycles and available evidence.

In the financial sector, an AI inventory is not just a list. It is the basis for supervisory readiness.

Transparency Obligations as a Control Process

Since 2 August 2026, transparency obligations under Article 50 of the AI Act apply to certain AI systems. This includes, for example, interactive AI systems such as chatbots and certain AI-generated or AI-manipulated content.

For financial institutions, this is highly relevant. A chatbot on a bank website, an AI assistant in customer service or AI-generated customer communication can trigger transparency obligations. At the same time, the information provided to customers must be legally sound, understandable, consistent with privacy notices and operationally feasible.

This makes transparency more than a wording exercise. It is a control process. Companies need to know where customer-facing AI is used, who approved it, what information is provided to users, how changes are reviewed and which evidence is available.

A short disclaimer may be part of the solution. But the real GRC question is whether the company can prove that the obligation was identified, assessed and implemented correctly.

Prohibited AI Practices Require Early Scope Checks

BaFin’s supervisory role also makes the assessment of prohibited AI practices more important. Financial institutions should review AI use cases before they go live, especially where systems classify, influence, score or support decisions about individuals.

The risk is not limited to obviously problematic systems. Even well-intended applications can create compliance issues if they affect vulnerable customer groups, produce opaque scoring outcomes or shift decision-making in practice from humans to automated systems.

This is why AI use cases need an early scope and risk review. Companies should document whether a use case could fall into a prohibited category, whether fundamental rights or discrimination risks are involved and whether additional controls or restrictions are necessary. This review should not happen only once. AI systems change, data changes and providers update their models. Governance needs to account for that.

AI Literacy Becomes a Compliance Topic

The AI Act requires providers and deployers of AI systems to take measures ensuring an appropriate level of AI literacy among employees and other persons involved in the operation or use of AI systems on their behalf.

For financial institutions, this is especially important. Employees in compliance, risk, IT, customer service, product management, HR, sales and management need to understand what AI can do, where its limits are and which risks arise in their specific context.

AI literacy should therefore not be treated as a generic awareness module. It should be role-based. Customer service teams need to understand chatbot escalation and AI-generated responses. Risk teams need knowledge about model risk, data quality and validation. Compliance teams need to understand AI Act obligations, data protection and internal approvals. IT and security teams need to address monitoring, access controls and incident response. Management needs a clear view of risk acceptance and governance responsibilities.

For GRC teams, this creates a new evidence requirement. Companies need to show who was trained, when, on what topic and with which relevance to the AI systems they use.

High-Risk AI: More Time, but No Reason to Wait

BaFin is expected to supervise high-risk AI systems in the financial sector from December 2027. Examples may include AI systems used by banks for creditworthiness assessments or by insurers for certain individual risk assessments and pricing models.

That may sound like a distant deadline, but financial institutions should not wait. High-risk AI typically requires significantly more robust governance. This includes risk management, data quality, technical documentation, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

Trying to retrofit these requirements shortly before the deadline will be difficult. Existing AI systems need to be identified, classified, documented and controlled early. This is particularly important for systems that already support important customer, risk or pricing decisions.

The practical challenge is that many AI systems will not sit neatly in one department. They may involve business owners, IT, external providers, data teams, risk management and compliance. Without a central governance structure, readiness will be fragmented.

The Link to Data Protection, DORA and Vendor Risk

AI governance in the financial sector does not stand alone. It overlaps with several existing GRC areas.

Data protection is one of the most important interfaces. Many AI systems process personal data. This means that legal bases, transparency obligations, data protection impact assessments, retention rules and data subject rights need to be considered.

Operational resilience is another key area. AI systems may support critical or important functions. In such cases, availability, integrity, incident response, testing, business continuity and third-party risk management become relevant. This creates a clear link to DORA.

Vendor risk management is equally important. Many AI systems are provided by external vendors, cloud platforms or specialised technology providers. Financial institutions need to understand dependencies, data flows, subcontractors, access rights, monitoring obligations and exit options.

Finally, model risk and internal controls need to be addressed. AI systems can support or influence decisions. Companies need to ensure that model changes, performance, bias, drift and error rates are monitored and that decisions remain explainable and controlled.

This shows why AI governance should not run next to the GRC system. It needs to become part of it.

Conclusion: BaFin Makes AI Governance in Finance Auditable

With BaFin’s new responsibility, AI Act compliance in the German financial sector becomes more concrete. AI systems that are directly connected to regulated financial activities are moving into the market surveillance remit of the financial supervisory authority.

For GRC leaders, this is a clear signal: AI governance must now move from general principles into auditable processes. The key elements are a reliable AI inventory, clear roles, risk assessments, transparency controls, AI literacy, vendor risk management and audit-ready evidence.

Companies that start early will not only reduce regulatory risk. They will also strengthen trust with customers, supervisors, management and business partners.

Zazoon helps financial institutions build BaFin-ready AI governance: from AI use case inventories and risk assessments to controls, evidence, audits and management reporting.

FAQ

What has changed at BaFin?

BaFin has become the market surveillance authority for certain AI systems in the German financial sector where those systems are directly connected to regulated financial activities.

Which companies are affected?

Affected companies include banks, insurers and other financial institutions under BaFin supervision.

Which AI systems are in scope?

Relevant AI systems may include chatbots, creditworthiness assessments, insurance risk models, fraud detection, compliance monitoring or AI-supported customer classification, provided they are connected to regulated financial activities.

Which obligations are particularly relevant now?

Short-term priorities include transparency obligations, prohibited AI practices and AI literacy measures. High-risk AI requirements will become especially important for many financial use cases at later stages.

Why is this a GRC topic?

Because AI supervision connects risks, controls, roles, data protection, DORA, vendor risk, documentation and audit trails. A standalone AI policy is not enough.

What should financial institutions do now?

They should build an AI inventory, classify use cases, assess BaFin and AI Act relevance, evaluate risks, define controls and document evidence centrally.

How does Zazoon support BaFin-ready AI governance?

Zazoon connects AI use cases, regulatory requirements, risks, controls, responsibilities, vendor reviews and evidence in one central GRC system. This makes AI governance traceable, efficient and audit-ready.

Related posts

19 May 2026 | 10 min

AI Risk Becomes a Supervisory Topic: What the BaFin Warning Means for DORA, BCM and Vendor Risk

In mid-May, BaFin made it clear that cyber risks for financial institutions continue to increase. One point is particularly relevant: attackers are using artificial intelligence more often to identify vulnerabilities faster, prepare attacks more effectively and target IT systems with greater precision.

For banks, insurers and other regulated companies, this is more than a technical warning. If AI makes attacks faster and more scalable, the requirements for risk management, business continuity, third-party oversight and evidence documentation also increase. In short: AI risk is becoming a supervisory topic.

This does not only affect companies that use AI themselves. It also affects companies whose IT, suppliers, cloud services or software products may become more vulnerable to AI-driven attacks. This is exactly where DORA, BCM and vendor risk management come into play.

AI is changing the cyber threat landscape. Attackers can identify vulnerabilities faster, create more realistic phishing messages and automate attacks more effectively. This increases the pressure on companies to detect and close security gaps more quickly.

For financial institutions, this is especially relevant because DORA makes digital operational resilience a binding requirement. Companies need to manage and document risks, ICT systems, service providers, incidents and recovery processes more effectively.

Business continuity management and vendor risk management are also becoming more important. An AI-driven cyberattack rarely affects only one system. It can impact service providers, critical processes, data, customer communication and ongoing operations at the same time.

Why AI increases cyber risks

Cyberattacks are not new. What is new is the speed and quality with which attackers can use AI.

In the past, many steps had to be performed manually: analysing systems, searching for vulnerabilities, preparing attacks, writing phishing messages or adapting technical attack patterns. With AI, many of these steps can be accelerated or partly automated.

This does not mean that every attack will automatically be successful. But it does mean that companies must expect more attempts, better prepared attacks and shorter response windows.

Typical risks include:

  • faster identification of vulnerabilities in IT systems
  • more realistic phishing and social engineering attacks
  • automated analysis of publicly available information
  • more targeted attacks on employees, service providers or executives
  • faster adaptation of attack methods
  • higher pressure on security, IT and incident teams

For GRC teams, the key point is this: AI-driven cyberattacks are not just an IT security issue. They affect governance, risk, compliance, suppliers, emergency planning and management reporting.

What this has to do with DORA

DORA requires financial institutions to manage their digital operational resilience systematically. At its core, DORA is about ensuring that companies remain operational even during IT disruptions, cyberattacks or problems with external service providers.

AI-driven attacks increase pressure in exactly this area.

Companies need to know which ICT systems are critical, which risks exist, which controls are in place, which service providers are involved and which measures are triggered in the event of an incident. At the same time, they need to prove that this information is up to date and manageable.

DORA is therefore not only about technical security. It requires a reliable management system for digital risks.

In practice, this means:

  • ICT risks must be assessed regularly
  • critical systems and processes must be known
  • security measures must be documented and reviewed
  • incidents must be detected, assessed and reported
  • service providers must be managed according to risk and criticality
  • recovery and emergency processes must work in practice

If AI makes attacks faster, the quality of these processes becomes more important. Companies cannot afford to start searching for information only once an incident has already happened.

Why BCM is becoming more important

Business continuity management often only becomes visible when something fails. That is exactly the problem.

An AI-driven cyberattack may not only affect individual IT systems. It can also disrupt critical business processes, customer communication, data access or external service providers.

In that situation, having an emergency plan in a folder is not enough. Companies need to know:

  • Which processes are truly critical?
  • Which systems support these processes?
  • Which service providers are involved?
  • What alternatives exist if a system or provider fails?
  • Who makes decisions during a crisis?
  • How quickly do systems need to be restored?
  • What internal and external communication is required?

BCM therefore needs to be more closely connected with cyber risk, incident management and vendor risk management. Only then can companies gain a realistic view of their actual resilience.

Why vendor risk management is critical

Many companies no longer operate their most important systems entirely by themselves. They rely on cloud providers, software solutions, outsourcing partners, managed services and specialised IT providers.

This is normal and often efficient. But it changes the risk profile.

If a critical service provider is attacked, the company itself may still be affected. If a software provider has a vulnerability, it can create risk for many customers. If a cloud service fails, core business processes may come to a halt.

AI-driven attacks make this problem more serious because attackers can analyse supply chains more precisely and identify weak points faster.

That is why a simple supplier list is no longer enough. Companies need structured vendor risk management. They need to know which providers are critical, what services they deliver, which data is affected, which security requirements apply and which evidence is available.

Particularly important are:

  • criticality assessments of service providers
  • documentation of ICT dependencies
  • security requirements in contracts
  • regular supplier assessments
  • evidence of controls and certifications
  • exit strategies for critical providers
  • connection with BCM and incident management

Vendor risk is therefore not just a procurement topic. It is a central part of cyber resilience.

The real problem: information is often scattered

Many companies already have much of the information they need. It is simply not available where it is needed in an emergency.

Risks are documented in spreadsheets. Supplier information sits with procurement. Emergency plans are maintained separately. Incidents are handled in a ticketing system. Controls are documented in audit files. Evidence is stored in folders. Management reports are created manually.

As long as nothing happens, this may seem manageable. During a cyber incident, it becomes a problem.

At that point, companies need to know quickly which systems are affected, which processes are critical, which service providers are involved, which reporting obligations apply and which measures have already been planned or implemented.

If this information is scattered, companies lose time. And in a cyberattack, time is one of the most important factors.

What companies should do now

Companies do not need to launch a massive new programme immediately. But they should review their existing processes in a targeted way.

The first step is transparency. Which critical systems, processes and service providers exist? Which risks are known? Which measures are already in progress? Where is evidence missing?

The second step is connection. Risks, controls, suppliers, incidents and BCM plans should not be managed in isolation. They need to be linked.

The third step is auditability. Supervisors, auditors and management need clear answers. Not at some point in the future, but quickly and reliably.

For many companies, these questions are especially important:

  • Are AI-related cyber risks included in risk management?
  • Are critical ICT systems and service providers fully documented?
  • Are BCM plans connected to real system and supplier dependencies?
  • Are there clear processes for cyber incidents and reporting obligations?
  • Can controls, measures and evidence be found quickly?
  • Is there up-to-date reporting for management and supervisors?

These questions are simple. But they quickly show whether a company is truly in control.

The role of Zazoon GRC

Zazoon GRC helps companies manage cyber risks, DORA requirements, BCM, vendor risk and evidence centrally.

Instead of maintaining risks, controls, service providers, incidents and measures in different tools, companies can connect this information in one shared GRC structure. This creates a clearer picture: Which risks affect which systems? Which providers are critical? Which measures are still open? Which evidence is available? Which requirements are being fulfilled?

This transparency is especially important for AI-driven cyber risks. The faster the threat landscape changes, the more important up-to-date data, clear responsibilities and traceable processes become.

Zazoon helps companies view compliance not as an isolated obligation, but as a foundation for better resilience and better decision-making.

Conclusion: AI makes cyber risk faster, GRC needs to become more structured

The BaFin warning makes one thing clear: AI is changing the cyber threat landscape. Attacks can become faster, more targeted and more scalable. For regulated companies, this increases pressure on DORA, BCM, vendor risk and incident management.

The answer is not more manual documentation. The answer is better structure.

Companies need to know which risks exist, which systems are critical, which service providers are involved, which measures are effective and which evidence is available. This is the core of modern GRC processes.

AI risk is therefore no longer a future topic. It is a current supervisory topic and a clear reason to connect digital resilience, third-party oversight and business continuity more closely.

FAQ

What does AI risk mean in cybersecurity?

AI risk describes risks that arise from or are amplified by the use of artificial intelligence. In cybersecurity, this mainly means that attackers can use AI to identify vulnerabilities faster, create more realistic phishing attacks or automate attack processes more effectively.

Why is the BaFin warning important for companies?

BaFin makes it clear that AI-driven cyberattacks are not only a technical problem. They can threaten the stability of companies, the availability of services and digital resilience. For regulated companies, this increases the pressure to manage and document cyber risks more effectively.

What does AI risk have to do with DORA?

DORA requires financial institutions to manage digital risks in a structured way. If AI makes cyberattacks faster and more complex, companies need better control over their ICT risks, controls, incidents, service providers and recovery processes.

Why is BCM important for AI-driven cyberattacks?

Business continuity management ensures that critical business processes can continue or be restored quickly during disruptions. In an AI-driven cyberattack, one incident can affect several systems, providers and processes at the same time. That is why BCM must be closely connected with cyber risk and incident management.

What role does vendor risk management play?

Many cyber risks do not arise only inside the company. They can also come from service providers, cloud providers or software suppliers. Vendor risk management helps companies identify critical providers, assess risks and document security requirements in a traceable way.

Do companies now need separate AI risk programmes?

Not necessarily. The first step should be to integrate AI-related cyber risks into existing GRC, DORA, BCM and vendor risk processes. What matters most is that risks, controls, measures and evidence can be managed centrally.

Is a technical security solution enough?

No. Technical security solutions are important, but they are not enough on their own. Companies also need clear responsibilities, documented processes, supplier oversight, emergency plans, incident management and reliable evidence.

How does Zazoon GRC support AI risk management?

Zazoon GRC helps companies manage risks, controls, measures, suppliers, incidents and evidence centrally and connect them with each other. This makes it easier to understand where risks arise, which measures are effective and which regulatory requirements are being fulfilled.

11 December 2025 | 6 min

Holiday gifts for business partners in the DACH region

During the Christmas season, many companies take the opportunity to thank their business partners with small gifts. These gestures strengthen relationships, show appreciation and are often part of a company’s culture. At the same time, tax rules, compliance requirements and internal guidelines must be respected – and these differ between Germany, Austria and Switzerland.

This article provides a current and balanced overview of the legal and practical framework for holiday gifts in all three DACH countries. It explains what companies should consider in order to give appropriately, avoid risks and maintain trust.

  • In all three countries, the same core principles apply: gifts must be business related, appropriate and transparent.
  • Germany has a tax threshold of 50 euros per recipient and calendar year for business gifts.
  • Austria and Switzerland do not use a single statutory value limit, but focus on appropriateness, business purpose and documentation.
  • Clear internal guidelines and consistent documentation are recommended throughout the DACH region.
  • Gifts to people in the public sector or highly regulated industries require particular caution.

Why clear rules are important in all three countries

Regardless of whether a company is based in Austria, Switzerland or Germany, gifts must never give the impression that they are intended to influence business decisions improperly. Compliance standards, anti-corruption rules and tax legislation are designed to ensure clean business relationships.

Companies should therefore apply clear and comprehensible principles in every country in which they operate. This prevents misunderstandings, reduces legal and tax risks and creates a uniform standard for all employees.

Current regulations at a glance

Germany

Germany is the only DACH country with a clearly defined tax limit for gifts to business partners. Business gifts are tax deductible up to 50 euros per recipient and calendar year if they are business related and properly documented.

For gifts that exceed this amount, the tax deduction may be denied unless the gift is clearly and exclusively usable for business purposes.

Austria

Austria does not work with a uniform fixed value limit. Instead, the following aspects are crucial:

  • the gift must serve a clear business purpose
  • the value must be reasonable in relation to the relationship and the occasion
  • the gift must be documented in a comprehensible way

As in the other DACH countries, gifts must not be used to gain improper advantages. Particular care is required in the public sector and in strongly regulated industries.

Switzerland

Switzerland also has no statutory standard limit for gifts to business partners. The focus is on:

  • usual appropriateness according to Swiss business practice
  • transparency and traceability
  • compliance with internal rules and industry-specific regulations

Swiss business culture tends to favour modest, high-quality but unobtrusive gifts rather than expensive luxury items.

Common basic principles for the entire DACH region

Despite the legal differences, companies in Germany, Austria and Switzerland can follow a common set of basic rules.

Appropriateness

The gift should match the business relationship, the role of the recipient and the occasion. Very expensive or flashy gifts can quickly appear inappropriate.

Business purpose

Holiday gifts should always serve a legitimate business purpose, such as maintaining a good relationship or thanking partners for successful cooperation. They must not be used to steer decisions or promises of business.

Documentation

For every gift, companies should record at least the following:

  • name of the recipient and company
  • occasion
  • date
  • value
  • business purpose

This documentation helps during tax audits and internal or external compliance checks.

Caution with public sector recipients

For employees of authorities, public hospitals, universities, municipalities and similar organisations, stricter requirements usually apply in all three countries. Often only very small tokens are permitted, and in some cases gifts are completely prohibited. When in doubt, it is better to ask in advance or avoid gifts altogether.

Recommendations for companies in the DACH region

  1. Create a clear, written gifting policy that applies in all locations.
  2. Define maximum values for gifts per person and per year.
  3. Ensure consistent documentation of all gifts to business partners.
  4. Pay special attention to sensitive sectors such as the public sector, healthcare or regulated industries.
  5. Plan gifts early and avoid borderline cases in terms of value or type of gift.
  6. Consider alternatives such as charitable donations in the name of a business partner instead of material gifts.

Why restraint is often the best strategy

No matter in which of the three countries a company operates, gifts that are too expensive or too personal can send the wrong signal. They may be perceived as an attempt to influence decisions and can trigger tax or compliance issues.

Modest, tasteful gifts or a personal handwritten card are often more effective and credible than high-value items. What counts in the long term is trust and partnership – not the material value of a present.

FAQ – Frequently asked questions in the DACH region

Is there a single value limit that applies to the whole DACH region?

No. Germany has a defined tax threshold of 50 euros per recipient and calendar year for business gifts. Austria and Switzerland use the principles of appropriateness, business purpose and documentation instead of fixed legal limits.

May I give expensive gifts in Austria or Switzerland if they seem appropriate?

In principle this is possible, but it is usually not advisable. High-value gifts increase the risk of compliance concerns, negative perceptions and disputes during audits. In practice, modest gifts are safer and more in line with expectations.

How should a business gift be documented correctly?

For each gift you should record who received it, for which company the person works, the date, the occasion, the value and the business reason. This information should be stored centrally, for example in a simple gifts register.

Are gifts to employees treated in the same way as gifts to business partners?

No. Gifts to employees are subject to different tax and payroll regulations in all three countries. Companies should therefore treat gifts to staff separately from gifts to external business partners and observe the respective rules.

How should I handle gifts to governmental bodies or public organisations?

With particular caution. In all DACH countries there are strict rules for the public sector, and many organisations either prohibit gifts completely or limit them to very small amounts. If you are unsure, ask for written guidance or refrain from giving a gift.

21 November 2025 | 5 min

NIS-2 Implemented: Why German Companies Must Act Now

In November 2025, the German Bundestag passed the law implementing the NIS-2 Directive. This introduced new national rules for cybersecurity and information security that go far beyond previous requirements. Companies that have so far operated under the radar must now assess whether they are affected – and if so, urgently adapt their security measures, processes and governance structures.

The delay in implementation gave many organisations a bit of breathing room, but now the pressure to act begins. Those who prepare early can gain a competitive advantage – those who react too late risk penalties, reputational damage or even business disruption.

Key Points at a Glance

The Bundestag adopted the NIS-2 Implementation Act on 13 November 2025.

The law expands its scope to significantly more companies and public authorities – an estimated 29,500 entities in Germany.

New obligations include risk management, technical and organisational measures, incident reporting with defined deadlines (e.g., first report within 24 hours), as well as expanded oversight and sanctions by the Federal Office for Information Security (BSI).

Companies should now carry out an impact assessment, revise regulatory and compliance processes and align governance and IT security architecture with the tightened requirements.

Why This Topic Matters

Digital connectivity and dependency on IT systems and services have increased significantly in recent years. At the same time, the threat posed by cyber attacks, targeted sabotage, espionage and hybrid attacks on critical infrastructure continues to grow. In this environment, the previous legal framework in Germany was no longer considered sufficient by many experts.

The EU NIS-2 Directive aims to ensure a high and consistent level of security for network and information systems across the Union.

Since Germany missed the deadline for implementing the directive, action was required – the newly adopted law represents the next crucial step.

For companies, this means the following: not only traditional operators of critical infrastructures (KRITIS) are affected, but also many organisations that were previously not within this category. This significantly increases the number of regulated entities – creating a competitive advantage for those who prepare early.

What Requirements and Obligations Must Be Met?

Companies that fall under the new rules face several new elements. The most important obligations at a glance:

Scope and Categories

The law distinguishes between “essential entities” and “important entities”. Both categories are subject to the requirements, with different intensities depending on criticality.

Companies from sectors such as energy, healthcare, transport, digital services or public administration typically fall under these rules. However, other organisations may also be affected if their services are relevant for the functioning of society.

Technical and Organisational Measures (TOM)

Affected entities must implement IT security measures that reflect the state of the art. These include risk analyses, business continuity plans, backup concepts, encryption, access controls and monitoring and detection of attacks.

The integration of supply chain and third-party risks is now much more strongly required – companies must understand and manage their dependencies.

Incident Reporting and Notification Obligations

A central element is the reporting obligation for security incidents. A new three-stage regime applies:

  • First notification within 24 hours after detection
  • Interim report after 72 hours
  • Final report no later than one month later

These deadlines turn incident reporting into a time-critical compliance and management task.

Expanded Oversight and Sanctions

The BSI assumes expanded supervisory and audit functions. It can issue sanctions, publish guidance and maintain the required registers.

Companies must also register and designate responsibilities – such as a person responsible for information security.

Role of Public Administration

New: Public authorities and federal administration are now also subject to minimum requirements. This brings governmental IT security to the same level as the private sector – an important step for overall resilience.

What Companies Should Do Now

  • Conduct an impact assessment to determine whether the organisation falls under the categories “essential” or “important”.
  • Perform a gap analysis of existing IT security, governance and reporting processes and align them with NIS-2 requirements.
  • Revise governance and risk management processes: Who is responsible? How is risk measured? How quickly do we report incidents?
  • Implement and document technical measures: risk analysis, access controls, incident response plan, backup and recovery strategy.
  • Establish reporting and notification processes: define responsibilities and ensure deadlines can be met.
  • Provide training and awareness programmes for employees: cyber risks, reporting obligations, responsibilities.
  • Set up monitoring and reporting structures: dashboards for incidents, risks and measures, including third-party risk management.

Those who start early can not only ensure compliance but also gain competitive advantages – for example, by strengthening trust in partner relationships or reducing insurance premiums.

Conclusion

With the law implementing the NIS-2 Directive, Germany marks a decisive step towards digital resilience. For companies, this means cybersecurity is no longer voluntary but becomes a regulated and strategically essential task.

The requirements are demanding – but those who act early secure legal certainty and build trust with customers, partners and investors.

FAQ

Who is affected by NIS-2 implementation?
Affected are companies classified as “essential entities” or “important entities”, particularly in sectors such as energy, healthcare, transport, digital services, as well as public authorities and administration.

When do the new regulations apply?
The Bundestag adopted the law on 13 November 2025. It still needs approval by the Bundesrat and publication in the Federal Law Gazette before it enters into force.

What deadlines apply for reporting security incidents?
Initial report within 24 hours of detection, interim report after 72 hours, final report after one month at the latest.

What happens if the requirements are not met?
The BSI receives extended supervisory and sanctioning powers. Violations may lead to fines and further legal consequences.

How should companies proceed now?
Conduct an impact and gap analysis, adjust governance and risk processes, document technical measures, establish reporting processes and train employees.

14 October 2025 | 6 min

Resilience at Sea – How Good GRC Makes the Shipping Industry Crisis-Proof

The global shipping industry is defying the slowdown. Despite geopolitical tensions, tariffs, and weak industrial production in Europe, many shipping companies report stable or even growing business. This is surprising, given that most economic indicators point in the opposite direction: trade barriers are increasing, transport costs are rising, and global demand is softening.

Yet, according to the latest shipping survey by PwC Germany, the industry remains remarkably resilient. Ninety-three percent of the companies surveyed said their ships are fully utilized, and 58 percent expect further growth in the next twelve months. Only four percent anticipate a downturn. This confidence stands in sharp contrast to the broader economic situation and highlights how effective governance, risk, and compliance (GRC) practices contribute directly to stability.

  • According to PwC Germany’s 2025 shipping survey, 93 percent of German shipping companies report full utilization, and 58 percent expect continued growth.
  • Despite tariffs, trade conflicts, and weak industrial output, the sector remains robust.
  • The main reason is strategic decoupling from the German economy and diversification across global markets.
  • Strong GRC – meaning sound governance, effective risk management, and reliable compliance – is the key driver of resilience.

Economic Situation: Between Slowdown and Strength

Traditionally, the maritime sector serves as a barometer of global trade. But while many industrial sectors are struggling, the shipping industry shows impressive stability.

PwC’s 2025 shipping study, now in its 17th edition, paints a surprisingly positive picture. Despite political unrest, volatile energy prices, and new trade barriers, most fleets remain busy. The Baltic Exchange’s 2025 outlook also predicts moderate growth in container and LNG segments, while Fitch Ratings describes the global shipping outlook for 2025 as “stable,” despite ongoing market uncertainty.

This strength is no coincidence. Over the past years, shipping companies have systematically adapted their business models. Only about 30 percent now depend directly on Germany’s industrial output. Instead, they focus on global markets, long-term charter contracts, and specialized niches.

Why the Shipping Sector is Thriving Despite the Crisis

Several factors explain the shipping industry’s resilience:

  1. Global Diversification
    Shipping companies have reduced their dependence on domestic markets. Operating in multiple regions allows them to offset weaknesses in individual economies.
  2. Long-Term Charter Contracts
    Many carriers rely on multi-year agreements that guarantee stable income even when spot market rates fall.
  3. Efficient Cost and Route Management
    Flexible rerouting, such as avoiding the Red Sea by sailing around the Cape of Good Hope, allows operators to manage geopolitical disruptions effectively.
  4. Investment in Technology and Sustainability
    The use of digital systems and cleaner fuels (like LNG and methanol) not only ensures regulatory compliance but also provides long-term competitive advantages.
  5. Solid Governance Structures
    Many shipping companies have strengthened their corporate governance with professional boards, risk committees, and compliance units – structures that were far less common a decade ago.

These factors form part of an integrated GRC approach – the foundation of today’s maritime resilience.

Governance: Stability Through Clear Leadership

Strong governance is the backbone of any resilient organization. Shipping companies that navigate uncertainty successfully have clear decision-making processes and transparent accountability structures.

In practice, this means that strategic decisions – regarding fleet expansion, financing, sustainability, or insurance – are made in close coordination with risk and compliance functions. Supervisory boards are not mere oversight bodies but active strategic partners.

Such governance models allow companies to react swiftly to market changes without losing control or consistency.

Risk Management: Early Warning for Geopolitical and Operational Threats

The shipping sector faces constant uncertainty: geopolitical conflicts, piracy, environmental regulations, fluctuating fuel prices, and cyberattacks. Effective risk management is therefore crucial.

Successful shipping companies use scenario planning to assess how trade wars, port strikes, or route blockages could impact operations. They continuously monitor key variables like fuel prices, insurance costs, and new regulations.

Cyber risk is now one of the top concerns. Digital systems on ships and in ports are increasingly vulnerable to attacks. According to PwC’s study, 78 percent of respondents now manage cybersecurity risks at the executive level – a major step toward operational resilience.

Compliance: Building Trust Through Integrity

Compliance is the third pillar of resilience, alongside governance and risk management. Regulatory pressure on shipping companies continues to grow – from emissions rules and ESG reporting to international trade and sanctions regulations.

Companies that take a proactive stance gain a clear advantage: they avoid fines, improve credit ratings, and strengthen stakeholder trust. ESG compliance is especially critical, as sustainability performance increasingly influences access to financing and new business.

A well-structured compliance management system, based on ISO 37301, provides the necessary framework. It standardizes procedures, simplifies audits, and ensures documentation of all key processes.

How Strong GRC Drives Resilience

Governance, Risk, and Compliance are no longer checkboxes for shipping companies – they are strategic enablers. GRC creates transparency, defines responsibilities, and ensures alignment with international standards.

By identifying and managing risks early, companies can maintain stability in volatile markets. The result is an industry that continues to grow – not because it is immune to crises, but because it is prepared for them.

Conclusion

Shipping remains a cornerstone of the global economy – and its resilience is no coincidence. Studies such as PwC’s 2025 survey make it clear: effective governance, solid risk management, and strong compliance practices distinguish resilient companies from vulnerable ones.

Organizations that view GRC as a strategic tool, not a regulatory burden, are better positioned to weather uncertainty. Governance provides navigation, risk management forecasts the storms, and compliance ensures the voyage stays on course. In short: good GRC is the compass that keeps the shipping industry steady, even in rough seas.


FAQ

Why is the shipping industry performing well despite the global slowdown?
Because many carriers have diversified internationally, secured long-term contracts, and strengthened their risk management systems.

What does the PwC Shipping Study 2025 reveal?
Ninety-three percent of shipping companies report full capacity utilization, and 58 percent expect growth – only four percent predict a decline.

What role does GRC play in the shipping industry?
GRC creates transparency, improves control, and ensures compliance with international regulations. It is the backbone of maritime resilience.

What are the main risks for shipping companies today?
Geopolitical tensions, trade barriers, cyberattacks, environmental regulations, and ESG reporting requirements are among the top challenges.

How can shipping companies improve their GRC practices?
By establishing clear governance structures, conducting regular risk assessments, implementing certified compliance systems (like ISO 37301), and using integrated digital GRC platforms for real-time oversight.

3 June 2025 | 3 min

How BaFin Uses Artificial Intelligence: Digitizing Financial Supervision

Germany’s Federal Financial Supervisory Authority (BaFin) is modernizing its tools for monitoring financial markets. To do this, it is increasingly relying on Artificial Intelligence (AI) to detect risks faster, uncover market manipulation, and automate compliance processes. In this blog post, we explore how BaFin uses AI, what benefits it brings, and what it means for companies and consumers.

AI in Market Surveillance: Algorithms Against Insider Trading

A key application of AI at BaFin is the detection of suspicious trading patterns. Using machine learning, BaFin analyzes vast amounts of trading data to uncover market manipulation and insider trading. These patterns are often hard for human analysts to detect but can be statistically significant indicators of abuse.

Automated Analysis of Company Data

Another field of application is the analysis of annual reports, ad-hoc disclosures, and financial statements. BaFin employs Natural Language Processing (NLP) to automatically identify risks, irregularities, or anomalies in corporate data. This accelerates the auditing of financial reports and helps detect adverse trends early.

AI in Banking Supervision: Risk Assessment and Early Warning Systems

AI is also used in regulatory assessments of banks and insurers. AI-powered early warning systems analyze metrics, capital structures, and market movements to identify risks early. This enables BaFin to intervene more quickly in times of crisis and prevent potential failures.

Anti-Money Laundering with AI

BaFin also uses AI to combat money laundering. By analyzing transaction patterns, suspicious activities can be automatically detected and reported. In collaboration with financial institutions, this improves both efficiency and the accuracy of prevention systems.

SupTech: Technological Shift in Supervision

Under the term SupTech (Supervisory Technology), BaFin is driving the digital transformation of its supervisory functions. AI plays a key role in processing large volumes of data, automating procedures, and making data-driven decisions.

Conclusion: Smarter Supervision Through Intelligent Systems

BaFin’s use of AI represents a decisive step toward modern, data-driven financial supervision. For companies, this means more transparency and faster processes. For consumers, it means greater protection from market abuse and financial crime. It also makes clear: supervisory authorities must evolve in the digital age to remain effective.


FAQ: Frequently Asked Questions About AI at BaFin

What is BaFin’s goal in using AI?

BaFin aims to detect risks earlier, uncover market abuse faster, and make supervision more efficient.

What technologies are being used?

Primarily machine learning, natural language processing (NLP), and data analytics.

Is the use of AI legally regulated?

Yes, BaFin must adhere to all applicable laws, including data protection and administrative law.

How do financial firms benefit?

Through clearer risk indicators, faster communication with regulators, and early warnings of potential problems.

What is SupTech?

SupTech refers to the technological advancement of supervisory work. AI is a central component of this development.