Skip to content

21 August 2026 | 8 min

CO2 Certificates Under Pressure: Why Climate Projects Are Now a GRC Topic

Handelsblatt is currently reporting that the German Environment Agency has declared CO2 certificates from 30 Chinese projects invalid. According to the report, the projects either overstated their climate impact or did not exist at all. One of the affected projects was reportedly financed by a Belgian subsidiary of ExxonMobil and promised savings of almost 96,000 tonnes of CO2. In total, the cancelled projects are said to have claimed CO2 savings of 2.1 million tonnes.

The case highlights a problem that reaches far beyond the oil and gas sector: climate claims are only as reliable as the governance behind them. Companies that use CO2 certificates, communicate climate neutrality or support ESG targets with external projects carry significant risk. If certificates are later deemed invalid, overstated or insufficiently evidenced, this is not only a sustainability problem. It becomes a compliance, reputation and control issue.

For GRC leaders, the message is clear: ESG claims need more than good intentions and external certificates. They need auditable processes, clear responsibilities, reliable data and robust evidence.

CO2 certificates and climate projects are coming under increasing scrutiny. The current Handelsblatt report shows that even large companies and formally reviewed projects are not automatically protected from later invalidation or doubt.

For companies, this means that anyone using climate projects must understand, review and document the underlying evidence. It is not enough to buy certificates and include their claimed impact in ESG communication, sustainability reporting or regulatory fulfilment without further scrutiny.

The topic is especially relevant for companies with net-zero targets, climate neutrality claims, CSRD or ESRS reporting, supplier assessments or carbon offsetting strategies. External ESG evidence must be treated like any other third-party risk: with due diligence, controls, monitoring and clear evidence.

Why CO2 Certificates Become a GRC Risk

CO2 certificates are intended to help companies offset emissions or meet regulatory requirements. In practice, however, the chain behind a certificate is complex. A single certificate may involve project developers, local operators, validators, verifiers, registries, brokers, buyers and several intermediaries.

This complexity creates risk. Companies often rely on the assumption that a certificate has already been sufficiently reviewed. But if doubts later arise about the existence, impact, additionality, calculation or documentation of a project, the risk remains with the company that relied on the certificate.

This is not only a legal issue. It is also a trust issue. Customers, investors, regulators, media and business partners increasingly expect climate-related claims to be reliable. Any company that advertises CO2 reductions or includes certificates in sustainability reporting must be able to explain why these claims are credible.

Carbon accounting therefore becomes a GRC topic. The decisive question is not only how much CO2 is claimed, but how that figure was calculated, reviewed, accepted and monitored.

The UER Case: When External Evidence Is Not Enough

In Germany, so-called Upstream Emission Reductions, or UERs, play a specific role. UER projects are measures designed to reduce CO2 emissions in the upstream part of oil and gas production, before crude oil is processed in a refinery. For the mineral oil industry, such projects were a way to meet greenhouse gas reduction quota requirements.

The current Handelsblatt report makes the issue tangible. If projects are later classified as suspicious or invalid, gaps emerge. Companies that used such certificates may need to close those gaps in other ways. But the more fundamental issue is governance: How did the company ensure that the project was reliable? Which checks were performed? Which warning signals existed? What role did external auditors or validators play? And how was the decision documented internally?

These are classic GRC questions. They show that ESG compliance is not just about reporting obligations. It requires robust decision-making processes.

ESG Claims Need the Same Discipline as Financial Controls

Many companies have published ESG targets, climate strategies and compensation measures in recent years. CO2 certificates were often seen as a pragmatic way to address emissions that are hard to avoid.

But the market is changing. Climate-related statements are being examined more critically. Greenwashing risks are increasing. CSRD and ESRS raise expectations for data quality, traceability and controls. Voluntary climate neutrality claims are also under greater public and regulatory scrutiny.

The consequence is clear: ESG claims need the same process discipline as financial figures or regulatory risk data. Companies must know where data comes from, who reviewed it, which assumptions were used, which controls exist and which evidence supports the claim.

A CO2 certificate is therefore not just a document. It is a data point, a third-party statement and a potential risk object.

Third-Party Risk in the ESG Context

The case shows why ESG and vendor risk are moving closer together. Climate projects are rarely managed fully in-house. Companies rely on project developers, intermediaries, certifiers, auditors, registries and local operators.

Each of these parties can introduce risk. Project documentation may be incomplete. Climate impact may be calculated incorrectly. Verification reports may have methodological weaknesses. Local controls may be insufficient. Conflicts of interest may remain unnoticed. Or a project may formally exist but fail to deliver the promised impact.

For GRC teams, this means that external ESG evidence belongs in third-party risk management. Companies need clear criteria for when a certificate can be accepted, what minimum information must be available, which providers and standards are approved and when additional review is required.

Companies that rely heavily on climate projects should not only purchase ESG evidence. They should monitor it.

What Companies Should Review Now

The Handelsblatt case is a useful trigger to review internal carbon credit governance. Companies should first understand whether and where CO2 certificates, offsets or external climate projects are used in their ESG strategy.

The next question is how robust the evidence behind these instruments is. Is there project-specific documentation? Are the project developer, certifier and registry known? Has the plausibility of the climate impact been assessed? Are there risks related to the project country, methodology, verification body or potential conflicts of interest? Were certificates simply purchased, or were they internally assessed and approved?

It is equally important to understand where certificates are used. Evidence that remains internal carries a different risk profile from evidence used in public sustainability claims, CSRD reporting, customer proposals or regulatory fulfilment mechanisms.

The more visible and material a climate claim is, the more mature the governance behind it must be.

Why Excel and Certificate Folders Are Not Enough

Many companies still manage ESG evidence in Excel files, SharePoint folders, email approvals or isolated sustainability tools. This may work for simple data points. But for CO2 certificates and climate projects, it is often not sufficient.

The challenge lies in the connections. A certificate belongs to a project. The project has a methodology, an operator, a country, a verification body, a lifecycle and specific assumptions about emission reductions. The certificate may be linked to an ESG target, a report, a claim or a regulatory obligation. At the same time, later findings, media reports, authority decisions or registry changes may alter the risk assessment.

If this information is stored separately, the audit trail is missing. In a critical situation, it becomes unclear who approved the certificate, on what basis the decision was made and whether new risks were considered in time.

Conclusion: Climate Claims Need Auditable Governance

The current Handelsblatt report on invalid CO2 certificates shows how quickly climate projects can move from a sustainability topic to a GRC risk. When certificates are later cancelled or projects are classified as questionable, the impact goes beyond the climate balance. It affects compliance, reputation, supplier governance, reporting and management responsibility.

For GRC leaders, the message is clear: ESG claims must be auditable. External certificates do not replace internal governance. Companies need clear processes, risk-based due diligence, documented approvals, ongoing monitoring and reliable evidence.

Zazoon supports companies in structuring carbon credit governance. This ensures that climate projects are not only purchased, but controlled, documented and managed in an audit-ready way.

FAQ

What is the current trigger?

Handelsblatt reports that the German Environment Agency has declared CO2 certificates from 30 Chinese projects invalid. According to the report, one of the affected projects was financed by a Belgian subsidiary of ExxonMobil.

Why is this a GRC topic?

Because CO2 certificates are not only sustainability instruments. If their impact cannot be reliably proven, they can trigger compliance, reputation, financial and regulatory risks.

What are UER projects?

UER stands for Upstream Emission Reductions. These are projects designed to reduce emissions in the upstream part of oil and gas production. In Germany, such evidence could be used to meet greenhouse gas reduction quota requirements.

Which companies are affected?

Companies that use CO2 certificates or external climate projects are directly affected. The topic is also relevant for any company communicating climate neutrality, net zero, ESG targets or CO2 reductions.

Is an external certificate sufficient evidence?

A certificate is an important document, but it does not replace internal governance. Companies should review the project information, verification reports, provider information and controls behind the certificate.

What should companies do now?

They should inventory their use of CO2 certificates, assess risks, review third parties, document approvals and establish ongoing monitoring.

How does Zazoon support this?

Zazoon helps companies centrally manage ESG requirements, climate projects, third parties, risks, controls, actions and evidence. This makes carbon credits and ESG claims traceable, controllable and audit-ready.

Related posts

20 August 2026 | 10 min

BaFin Takes Over AI Market Surveillance: Why AI Governance in the Financial Sector Must Become Audit-Ready

BaFin has received new responsibilities for the supervision of artificial intelligence in the German financial sector. Since 29 July 2026, it has acted as market surveillance authority for AI systems that are directly connected to regulated financial activities. This includes, among others, banks, insurers and other financial institutions under BaFin supervision.

For financial institutions, this is an important turning point. AI governance is becoming part of ongoing supervision. AI systems are no longer merely an innovation, efficiency or IT topic. They are becoming a governance, risk and compliance topic that must be documented, controlled and auditable.

The key question is therefore no longer only: Where can AI create value? The more important question is: Can we prove where AI is used, which risks exist, which obligations apply, who is responsible and which controls are in place?

BaFin has been the market surveillance authority for certain AI systems in the financial sector since 29 July 2026. Its responsibility applies to AI systems that are directly linked to regulated financial activities.

This affects financial institutions under BaFin supervision, including banks, insurers and other regulated financial companies. In practice, this means that AI governance is moving closer to established supervisory expectations around risk management, compliance, internal control systems and auditability.

Initially, the focus is likely to include transparency obligations, prohibited AI practices and measures to ensure sufficient AI literacy among employees. From December 2027, BaFin is also expected to supervise high-risk AI systems in the financial sector, such as AI used in creditworthiness assessments or certain insurance pricing models.

For GRC teams, the message is clear: AI inventories, risk assessments, roles, controls, vendor governance and audit trails need to become robust and defensible.

Why BaFin’s New Role Matters

The EU AI Act is a horizontal regulation. It applies across sectors. At the same time, regulated industries are not starting from scratch. Existing supervisory structures are being connected with AI regulation, and this is exactly what is now happening in the German financial sector.

BaFin will supervise AI systems that are directly connected to regulated financial activities. As a result, AI Act compliance in banks, insurers, fintechs and other financial companies will become more closely linked to familiar supervisory practices: risk governance, documentation, management responsibility and internal controls.

This matters because AI in finance can affect sensitive decisions. AI can be used in customer communication, credit scoring, fraud detection, insurance risk assessment, pricing, customer classification, compliance monitoring, anti-money laundering or portfolio risk models. Many of these use cases touch consumer protection, data protection, discrimination risks, model risk, cybersecurity and operational resilience.

For GRC leaders, this creates a clear mandate. AI must become visible, manageable and auditable.

AI Governance Needs More Than a Policy

Many organisations already have AI policies or general guidelines for the use of generative AI. That is a useful starting point, but it is not enough for supervised financial institutions.

Supervisors do not only look for principles. They look for implementation. Financial institutions need to be able to show which AI systems are used, in which business process they operate, which regulatory role the company has, whether the use case is connected to a regulated financial activity and which risks arise for customers, market integrity, data protection or fundamental rights.

The same applies to transparency obligations, prohibited AI practices, human oversight, provider dependencies and training measures. It is not enough to state that AI is used responsibly. Companies need evidence that the relevant risks were assessed, that controls were defined and that responsibilities are clear.

AI governance therefore becomes a classic GRC process: identify, classify, assess, control, document, monitor and improve.

The First Step: A Reliable AI Inventory

Without an AI inventory, no financial institution can reliably determine which systems fall under BaFin’s market surveillance or other AI Act obligations. The inventory is the foundation of every serious AI governance structure.

A useful AI inventory should go beyond large models or central IT projects. It should also capture business-unit tools, external SaaS solutions, chatbots, analytics tools, agency services and AI functions embedded in existing applications.

The inventory should document the purpose of the AI system, the business process it supports, the responsible owner, the provider or internal development team, the user groups, the data involved, the connection to regulated financial activities and the initial classification under the AI Act. It should also capture data protection relevance, third-party dependencies, transparency obligations, controls, review cycles and available evidence.

In the financial sector, an AI inventory is not just a list. It is the basis for supervisory readiness.

Transparency Obligations as a Control Process

Since 2 August 2026, transparency obligations under Article 50 of the AI Act apply to certain AI systems. This includes, for example, interactive AI systems such as chatbots and certain AI-generated or AI-manipulated content.

For financial institutions, this is highly relevant. A chatbot on a bank website, an AI assistant in customer service or AI-generated customer communication can trigger transparency obligations. At the same time, the information provided to customers must be legally sound, understandable, consistent with privacy notices and operationally feasible.

This makes transparency more than a wording exercise. It is a control process. Companies need to know where customer-facing AI is used, who approved it, what information is provided to users, how changes are reviewed and which evidence is available.

A short disclaimer may be part of the solution. But the real GRC question is whether the company can prove that the obligation was identified, assessed and implemented correctly.

Prohibited AI Practices Require Early Scope Checks

BaFin’s supervisory role also makes the assessment of prohibited AI practices more important. Financial institutions should review AI use cases before they go live, especially where systems classify, influence, score or support decisions about individuals.

The risk is not limited to obviously problematic systems. Even well-intended applications can create compliance issues if they affect vulnerable customer groups, produce opaque scoring outcomes or shift decision-making in practice from humans to automated systems.

This is why AI use cases need an early scope and risk review. Companies should document whether a use case could fall into a prohibited category, whether fundamental rights or discrimination risks are involved and whether additional controls or restrictions are necessary. This review should not happen only once. AI systems change, data changes and providers update their models. Governance needs to account for that.

AI Literacy Becomes a Compliance Topic

The AI Act requires providers and deployers of AI systems to take measures ensuring an appropriate level of AI literacy among employees and other persons involved in the operation or use of AI systems on their behalf.

For financial institutions, this is especially important. Employees in compliance, risk, IT, customer service, product management, HR, sales and management need to understand what AI can do, where its limits are and which risks arise in their specific context.

AI literacy should therefore not be treated as a generic awareness module. It should be role-based. Customer service teams need to understand chatbot escalation and AI-generated responses. Risk teams need knowledge about model risk, data quality and validation. Compliance teams need to understand AI Act obligations, data protection and internal approvals. IT and security teams need to address monitoring, access controls and incident response. Management needs a clear view of risk acceptance and governance responsibilities.

For GRC teams, this creates a new evidence requirement. Companies need to show who was trained, when, on what topic and with which relevance to the AI systems they use.

High-Risk AI: More Time, but No Reason to Wait

BaFin is expected to supervise high-risk AI systems in the financial sector from December 2027. Examples may include AI systems used by banks for creditworthiness assessments or by insurers for certain individual risk assessments and pricing models.

That may sound like a distant deadline, but financial institutions should not wait. High-risk AI typically requires significantly more robust governance. This includes risk management, data quality, technical documentation, human oversight, accuracy, robustness, cybersecurity and post-market monitoring.

Trying to retrofit these requirements shortly before the deadline will be difficult. Existing AI systems need to be identified, classified, documented and controlled early. This is particularly important for systems that already support important customer, risk or pricing decisions.

The practical challenge is that many AI systems will not sit neatly in one department. They may involve business owners, IT, external providers, data teams, risk management and compliance. Without a central governance structure, readiness will be fragmented.

The Link to Data Protection, DORA and Vendor Risk

AI governance in the financial sector does not stand alone. It overlaps with several existing GRC areas.

Data protection is one of the most important interfaces. Many AI systems process personal data. This means that legal bases, transparency obligations, data protection impact assessments, retention rules and data subject rights need to be considered.

Operational resilience is another key area. AI systems may support critical or important functions. In such cases, availability, integrity, incident response, testing, business continuity and third-party risk management become relevant. This creates a clear link to DORA.

Vendor risk management is equally important. Many AI systems are provided by external vendors, cloud platforms or specialised technology providers. Financial institutions need to understand dependencies, data flows, subcontractors, access rights, monitoring obligations and exit options.

Finally, model risk and internal controls need to be addressed. AI systems can support or influence decisions. Companies need to ensure that model changes, performance, bias, drift and error rates are monitored and that decisions remain explainable and controlled.

This shows why AI governance should not run next to the GRC system. It needs to become part of it.

Conclusion: BaFin Makes AI Governance in Finance Auditable

With BaFin’s new responsibility, AI Act compliance in the German financial sector becomes more concrete. AI systems that are directly connected to regulated financial activities are moving into the market surveillance remit of the financial supervisory authority.

For GRC leaders, this is a clear signal: AI governance must now move from general principles into auditable processes. The key elements are a reliable AI inventory, clear roles, risk assessments, transparency controls, AI literacy, vendor risk management and audit-ready evidence.

Companies that start early will not only reduce regulatory risk. They will also strengthen trust with customers, supervisors, management and business partners.

Zazoon helps financial institutions build BaFin-ready AI governance: from AI use case inventories and risk assessments to controls, evidence, audits and management reporting.

FAQ

What has changed at BaFin?

BaFin has become the market surveillance authority for certain AI systems in the German financial sector where those systems are directly connected to regulated financial activities.

Which companies are affected?

Affected companies include banks, insurers and other financial institutions under BaFin supervision.

Which AI systems are in scope?

Relevant AI systems may include chatbots, creditworthiness assessments, insurance risk models, fraud detection, compliance monitoring or AI-supported customer classification, provided they are connected to regulated financial activities.

Which obligations are particularly relevant now?

Short-term priorities include transparency obligations, prohibited AI practices and AI literacy measures. High-risk AI requirements will become especially important for many financial use cases at later stages.

Why is this a GRC topic?

Because AI supervision connects risks, controls, roles, data protection, DORA, vendor risk, documentation and audit trails. A standalone AI policy is not enough.

What should financial institutions do now?

They should build an AI inventory, classify use cases, assess BaFin and AI Act relevance, evaluate risks, define controls and document evidence centrally.

How does Zazoon support BaFin-ready AI governance?

Zazoon connects AI use cases, regulatory requirements, risks, controls, responsibilities, vendor reviews and evidence in one central GRC system. This makes AI governance traceable, efficient and audit-ready.

16 June 2026 | 12 min

Cyber Europe 2026: Why Cyber Resilience Is Becoming a Management Priority

Cyber Europe 2026 was the eighth major European cyber crisis exercise organised by the European Union Agency for Cybersecurity, ENISA. The exercise took place on 10 and 11 June 2026 and tested how well Europe can respond in a coordinated way to large-scale cyber incidents.

The focus was on the railway and maritime sectors. The exercise simulated the handling of parallel cyber incidents affecting critical transport and logistics infrastructure. It was not only about technical defence, but also about crisis coordination, business continuity, communication with authorities, situational awareness, decision-making processes and the continuity of essential services.

Participants included European authorities, national cybersecurity bodies, operators of critical infrastructure and other organisations from the European cyber ecosystem. Switzerland also took part. Under the lead of the Federal Office for Cybersecurity, BACS, various national and cantonal authorities as well as operators of critical infrastructure participated in the exercise.

For companies, Cyber Europe 2026 sends an important signal: cyber resilience is no longer measured only by the existence of security policies. What matters is whether organisations can remain operational during an incident, make clear decisions, coordinate their response and document their actions in a reliable way.

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA, with a focus on railway and maritime transport.

The exercise tested responses to parallel cyber incidents, coordination between authorities and operators, and the ability to maintain essential services.

Switzerland participated under the lead of BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

For companies, the exercise shows that cyber resilience goes far beyond IT security. Incident response, business continuity management, crisis communication, vendor management and management responsibility must work together.

In the context of NIS2, critical infrastructure and rising cyber risks, operational evidence is becoming increasingly important. Companies must not only plan, but also exercise, document and improve.

What Is Cyber Europe 2026?

Cyber Europe is a regular European cyber crisis exercise organised by ENISA. It brings together authorities, critical sectors and cybersecurity organisations. The goal is to simulate realistic cyber crises and test how well collaboration, escalation and crisis response work in practice.

Cyber Europe 2026 focused on transport networks, especially rail and maritime infrastructure. Both sectors are highly connected, internationally dependent and essential for the economy, supply chains and mobility. A cyberattack on such infrastructure can have consequences far beyond a single company.

For this reason, the exercise was not designed as an isolated technical test. It aimed to show how organisations work together under pressure, exchange information, make decisions and keep operations as stable as possible.

What Was Tested During Cyber Europe 2026?

The exercise centred on several parallel cyber incidents. Such scenarios are particularly demanding because they put organisations under pressure at the technical, operational and strategic levels at the same time.

The exercise tested, among other things, how quickly incidents are detected and assessed, how information flows between the parties involved, how crisis teams make decisions and how essential services can be maintained despite cyberattacks.

Business continuity was also a key element. A cyber incident is not just an IT problem when timetables, logistics processes, port operations, communication systems or safety-related operational processes are affected. Companies need to know which processes are critical, which dependencies exist and which alternatives are available in an emergency.

Another focus was coordination. Cyber crises can quickly cross organisational and national boundaries. Operators, service providers, authorities, regulators, crisis teams and communication teams must work together under time pressure. In real crises, these interfaces are often the biggest weakness.

Why the Railway and Maritime Sectors Were in Focus

Railway and maritime transport are central components of European mobility and supply chains. They connect passenger transport, goods flows, ports, industry, energy supply and international trade routes.

At the same time, these sectors are becoming increasingly digital. Operational control systems, communication networks, booking platforms, port management, logistics data, sensors and automated processes increase efficiency, but also create new attack surfaces.

A successful cyberattack can therefore have far-reaching consequences. It can delay supply chains, disrupt passenger transport, increase safety risks and damage public trust.

Cyber Europe 2026 therefore illustrates a challenge that applies to many critical sectors: the more connected organisations become, the more important robust cyber resilience, clear responsibilities and tested crisis processes become.

Why Switzerland’s Participation Matters

Switzerland participated in Cyber Europe 2026 and tested its cyber resilience in the railway and maritime sectors. The exercise was led in Switzerland by the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

This is relevant for two reasons. First, cyber risks are cross-border by nature. Even though Switzerland is not a member of the EU, it is closely connected to European transport, energy, financial and supply chains. An incident in a neighbouring country can affect Swiss organisations, and vice versa.

Second, Switzerland’s participation shows that cyber resilience is not only a matter for national authorities. It is created through cooperation between the state, the private sector, critical operators and specialised service providers. In major incidents, it matters whether this cooperation has already been tested.

For Swiss companies, the message is clear: cyber crises must not only be prepared for technically. They require crisis leadership, reporting channels, roles, supplier contacts, recovery plans and documented decision-making processes.

Cyber Europe 2026 and NIS2: What Companies Should Take Away

Cyber Europe 2026 fits directly into current developments around NIS2. The directive strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility in important and essential entities.

The exercise shows what matters in practice. Companies must not only meet requirements, but also demonstrate that their processes work during an actual incident. This is especially relevant for incident response, business continuity management, crisis communication and the management of external dependencies.

NIS2 is becoming increasingly operational. A policy alone is not enough. A company must know who makes decisions during an incident, which systems are critical, which service providers need to be involved, which reporting deadlines apply and which evidence must be available afterwards.

Cyber Europe 2026 makes one thing clear: cybersecurity readiness must be exercised. Only then can companies see whether roles are clear, escalation paths work and measures are effective in practice.

Why Cyber Resilience Is More Than IT Security

Cyber resilience describes an organisation’s ability to prevent, detect, manage and recover from cyber incidents. This goes far beyond traditional IT security.

Technical protection measures remain important. But during a crisis, organisational factors are just as decisive. These include clear responsibilities, fast decision-making, crisis communication, emergency processes, supplier coordination and the ability to continue critical business processes.

A company can be technically well positioned and still fail during a crisis if it is unclear who decides, who communicates or which systems need to be restored first.

Conversely, an organisation with strong governance can respond faster, limit damage and learn from incidents. Cyber resilience is therefore a management topic and a central part of modern GRC structures.

The Role of Business Continuity Management

Business continuity management, or BCM, plays a central role in cyber crises. It answers the question of how critical processes can continue when systems, service providers or locations fail.

Cyber Europe 2026 shows that BCM should not be viewed separately from cybersecurity. A cyber incident can disrupt business processes just as severely as a natural disaster, power outage or supply chain disruption.

Companies should therefore review whether their BCM plans are realistic from a cyber perspective. Are recovery priorities defined? Are critical processes known? Are dependencies on service providers documented? Are alternative communication channels available? Have crisis roles been tested?

BCM proves its value not on paper, but in exercises. Companies that regularly simulate cyber crises identify weaknesses before a real incident exposes them.

Incident Response: From Plan to Tested Reaction

Many companies have incident response plans. The decisive question is whether these plans work under pressure.

Cyber Europe 2026 shows that incident response is dynamic. Information is incomplete, decisions must be made quickly and multiple stakeholders are involved at the same time. This is why a static process document is not enough.

Effective incident response requires clear roles, defined escalation levels, communication rules, technical analysis capabilities and links to management, legal, data protection, communications and business departments.

Post-incident review is just as important. Every incident and every exercise should be documented and evaluated. Which decisions were made? Which measures worked? Where were there delays? Which controls need to be improved?

This turns incident response into a continuous improvement process.

Suppliers and External Dependencies as a Risk Factor

Cyber crises rarely affect only one organisation. Many critical processes depend on IT service providers, cloud providers, software vendors, network operators, logistics partners or specialised platforms.

Such dependencies are particularly important in the railway and maritime sectors. But the same principle applies in other industries: companies that do not know their critical third parties will struggle to respond quickly and effectively during an incident.

Companies should therefore know which service providers are relevant for critical processes, which contact and escalation channels exist, which contractual obligations apply and which evidence is available.

Vendor risk management is becoming a permanent part of cyber resilience. It is not enough to assess suppliers once. Dependencies must be monitored continuously and included in crisis exercises.

Why Evidence and Documentation Are Critical

After a cyber crisis, it is not only important what was done. It is also important whether the company can show what was done in a reliable and traceable way.

Documentation is therefore not an administrative side issue. It is central for audits, regulatory inquiries, internal lessons learned, insurance claims, customer communication and possible legal assessments.

In an emergency, companies must be able to trace when an incident was detected, who was informed, which decisions were made, which measures were implemented and which systems were affected.

Cyber Europe 2026 shows that evidence is part of resilience. Companies that cannot document their response will later struggle to demonstrate effectiveness, due care and improvement.

What Companies Should Do Now

Companies should use Cyber Europe 2026 as an opportunity to review their own crisis readiness. The most important step is an honest assessment of the current state.

Are critical processes known? Are incident response plans up to date? Are roles and escalation paths clear? Have crisis exercises been conducted? Are suppliers integrated into emergency processes? Is there a connection between cybersecurity, BCM, risk management and management reporting?

Tabletop exercises are particularly useful. They allow organisations to run through a realistic crisis scenario without affecting production systems. Such exercises quickly show whether responsibilities are clear and whether decision-making paths work.

Companies should also review their evidence management. Risks, controls, measures, incidents, exercises and lessons learned should not be scattered across individual files, but managed in a structured way.

Common Weaknesses in Cyber Crises

Many organisations underestimate organisational weaknesses. In practice, crisis response rarely fails only because of missing technology. More often, the problem lies in unclear responsibilities, outdated contact lists, slow escalation, incomplete situational awareness or inconsistent communication.

Another weakness is the separation of IT and business processes. If technical teams do not know which processes are business-critical, recovery priorities may be set incorrectly.

External dependencies are also often considered too late. If a critical service provider cannot be reached or contractual reporting channels are unclear, the company loses valuable time.

Cyber Europe 2026 therefore shows that resilience is not created by individual measures. It is created through the interaction of people, processes, technology, governance and practice.

Conclusion

Cyber Europe 2026 was an important practical test of Europe’s cyber resilience. The focus was on railway and maritime transport, two sectors whose disruption can have far-reaching consequences for mobility, supply chains and public safety.

The exercise clearly shows that cybersecurity is no longer a purely technical task. Companies must be able to manage cyber incidents organisationally, operationally and strategically. This includes incident response, business continuity management, crisis communication, vendor management, management responsibility and reliable evidence.

For companies in Europe and Switzerland, the most important lesson is this: cyber resilience must be exercised. Plans, policies and controls are necessary, but only realistic exercises show whether they work in practice.

Cyber Europe 2026 is not just an isolated public-sector event. It is a clear signal to all organisations: the next stage of cybersecurity is operational resilience.

FAQ on Cyber Europe 2026

What is Cyber Europe 2026?

Cyber Europe 2026 was a Europe-wide cyber crisis exercise organised by ENISA. Its goal was to test Europe’s collective response capability during major cyber incidents and strengthen the cyber resilience of essential services.

When did Cyber Europe 2026 take place?

Cyber Europe 2026 took place on 10 and 11 June 2026.

Which sectors were in focus?

The exercise focused on the railway and maritime sectors. It tested the handling of cyber incidents that could affect transport and logistics infrastructure.

Did Switzerland participate in Cyber Europe 2026?

Yes. Switzerland participated under the lead of the Federal Office for Cybersecurity, BACS. National and cantonal authorities as well as operators of critical infrastructure were involved.

What was tested during Cyber Europe 2026?

The exercise tested incident response, crisis coordination, business continuity, information exchange, communication with authorities and the ability to maintain essential services despite cyber incidents.

Why is Cyber Europe 2026 relevant for companies?

The exercise shows that cyber resilience does not depend only on technical security measures. Companies must also be organisationally prepared, have clear roles, coordinate incidents and document their response.

What does Cyber Europe 2026 have to do with NIS2?

NIS2 strengthens requirements for cybersecurity, risk management, incident reporting and management responsibility. Cyber Europe 2026 shows in practical terms why these capabilities are essential in realistic crisis scenarios.

Why does business continuity management play such an important role?

Cyber incidents can interrupt critical business processes. Business continuity management helps companies maintain essential processes even during system outages, attacks or supplier disruptions.

What should companies do after Cyber Europe 2026?

Companies should review their incident response plans, BCM processes, crisis roles, supplier dependencies and evidence management. Regular tabletop exercises and realistic crisis simulations are especially valuable.

What is the main lesson from Cyber Europe 2026?

The main lesson is that cyber resilience is not created by policies alone. Companies must exercise their crisis capabilities, clarify responsibilities, understand dependencies and act in a traceable way during an incident.

21 April 2026 | 13 min

NIS 2: Why Germany Is Falling Behind

NIS-2 has been enforceable law in Germany since December 2025. No transition period, no grace period, no exceptions. Around 29,500 companies across 18 sectors are required to implement risk management, report security incidents, and register with the BSI. And yet: at the 21st German IT Security Congress of the Federal Office for Information Security, the BSI was forced to admit that implementation is falling far short of expectations. Registration numbers are disappointing, awareness of the directive is alarmingly low, and a significant number of affected companies have made a deliberate choice not to register at all.

What is driving this? And more importantly: how can companies finally clear the compliance hurdle without overstretching their operational resources? The answer lies, to a large degree, in modern GRC software solutions.

  • According to the BSI, nearly half of all German companies had never heard of NIS-2 by the end of 2024.
  • The NIS-2 Implementation Act has been in force since December 6, 2025, with no transition period. The BSI registration deadline expired on March 6, 2026.
  • The main reasons for non-compliance: lack of awareness, perceived complexity, resource constraints, and a deliberate wait-and-see approach.
  • Non-compliance can result in fines of up to 10 million euros or 2% of global annual turnover.
  • Managing directors and executives face personal liability for meeting cybersecurity obligations.
  • GRC software demonstrably reduces implementation effort by up to 40–50% and delivers structure, automation, and audit-readiness in a single tool.

The Wake-Up Call from the BSI Congress: Germany Is Asleep at the Wheel

At the 21st BSI Security Congress, Manuel Bach of the BSI’s Cybersecurity in Business division spoke plainly: registration numbers in the BSI’s reporting portal remain well below expectations. Worse still, the BSI is aware of companies that — after consulting their legal counsel — have made a conscious decision not to register, hoping to stay below the radar.

And then came perhaps the most alarming statistic: nearly half of all German companies had never heard the term “NIS-2” at the time of a BSI study conducted at the end of 2024. Not unfamiliar as an obligation — simply unknown as a concept.

Younes Ahmadzei, who examined NIS-2 implementation in German SMEs as part of his bachelor’s thesis at the Technical University of Munich, painted a similar picture: many of the companies he surveyed had only begun engaging seriously with the topic at the start of 2026 — after the law had already come into force without a transition period. And even those who are aware of the directive often doubt whether implementing it would actually improve their company’s IT security. NIS-2 is being perceived as a bureaucratic checkbox exercise, not as a strategic opportunity.

This finding is alarming — and, at the same time, entirely explainable.

Why So Many Companies Are Ignoring NIS-2: The Five Biggest Barriers

1. Lack of Awareness and Uncertainty About Being Affected

The first and most fundamental reason is simply a lack of awareness. Many companies do not know that NIS-2 applies to them. The directive has dramatically expanded the circle of organizations under obligation: from around 4,500 companies under the old NIS directive to more than 29,500 in Germany alone. Now covered are mid-sized companies across 18 sectors — including energy, transport, healthcare, manufacturing, digital services, financial services, and public administration.

As a general rule: companies with at least 50 employees or more than 10 million euros in annual revenue may fall within scope. Those who do not actively ask whether this applies to their organization risk overlooking their own legal obligations.

2. The Perceived Complexity of the Regulatory Framework

NIS-2 is complex. Germany attempted to address multiple regulatory challenges simultaneously within a single piece of legislation — the result is a layered rulebook that even experts find challenging. For many mid-sized businesses, the legal text feels abstract and difficult to translate into concrete operational measures.

According to the study “Cybersecurity & Digital Resilience 2026,” 47 percent of surveyed companies rate the implementation of NIS-2 as difficult or very difficult. The most commonly cited barriers — each named by around 39 percent of respondents — are the high effort required to adapt processes and policies, and the sheer complexity of the requirements themselves. A further third cite unclear regulatory guidance and integration challenges with existing IT systems.

Governance obligations, risk management, incident response, supplier assessments — many of these requirements feel as though they were written for large corporations with dedicated compliance teams. For a mechanical engineering firm with 80 employees in southern Germany, the reality looks very different.

3. Resource Constraints in SMEs

Large companies have dedicated IT departments, security teams, and in-house compliance expertise. Small and medium-sized enterprises — precisely the group that NIS-2 brings into scope for the first time — simply do not. In interviews with affected business representatives, the workload was estimated at a minimum of one person spending two to three days per week on this topic alone — a realistic assessment that many SMEs cannot absorb without significant additional cost.

There is another layer to this: many companies are technically reasonably well set up, but fall short when it comes to organizational structures and documentation. Missing process frameworks, no embedded security culture, barely any reporting structures in place — all of this makes compliance work laborious and draining.

4. The Wait-and-See Strategy

For as long as the national implementation law was not finalized, many companies chose to wait. This hesitation was a deliberate strategic calculation: investing too early might mean heading in a direction that the final legislation would correct. This posture led to a dangerous standstill — and when the law came into force in December 2025 without a transition period, many companies were completely unprepared.

That argument is now obsolete. The law is in effect. The registration deadline passed on March 6, 2026. Any company that has not yet registered is already risking a fine.

5. Underestimating Personal Liability

NIS-2 is the first German cybersecurity law to hold managing directors personally accountable. Section 38 of the new BSIG requires company management to, among other things, regularly undergo training in four core areas — at least every three years. And any executive who ignores their organization’s reporting obligations faces personal liability.

Manuel Bach of the BSI drew a sharp analogy at the congress: you cannot simply decide for yourself that you are not subject to tax obligations. The same logic applies here. Just because a company believes it falls outside the scope of NIS-2 does not make that belief legally valid.

The Cost of Inaction: What Companies Are Risking

The fine frameworks under NIS-2 are substantial. For particularly important entities, sanctions can reach up to 10 million euros or 2 percent of global annual turnover — whichever is higher. For important entities, the framework is up to 7 million euros or 1.4 percent of global revenue.

On top of that comes the personal liability of senior management, the full weight of which many executive teams have yet to appreciate. Companies with inadequate security measures also face significant reputational damage if a security incident becomes public and it is clear that no appropriate steps had been taken.

And finally: companies that are part of a supply chain are increasingly being scrutinized by larger customers and partners for compliance status. NIS-2 compliance is becoming a competitive differentiator.

Why Manual Implementation Hits a Wall

The traditional approach — bringing in consultants, maintaining Excel spreadsheets, assembling documentation in Word files — works for large corporations with the necessary resources. For mid-sized businesses, it is simply too time-consuming, too error-prone, and too difficult to scale.

NIS-2 is not a one-time project you can tick off and forget. It demands continuous risk management, regular review of security measures, structured incident response within strict reporting deadlines — significant security incidents must be reported to the BSI within 24 hours — and ongoing documentation of supply chain security.

That is not a workload you can manage with a checklist in a drawer.

How GRC Software Closes the Compliance Gap

Governance, Risk & Compliance — or GRC — software was built precisely for this problem: translating complex regulatory requirements into structured, scalable, and traceable action. For NIS-2, GRC software is not a nice-to-have. It is a strategic tool.

A Structured Starting Point Instead of Disorientation

Modern GRC platforms deliver pre-configured NIS-2 frameworks that include all relevant control areas, compliance objectives, and documentation templates. Instead of starting from scratch, a company begins with a structured gap assessment: where does the organization stand today? Which requirements are already met? Where do gaps remain?

This gap analysis is the foundation for a prioritized action plan — and exactly what many companies have been missing: a clear picture of where to start.

Automated Risk Management

NIS-2 demands the continuous identification, assessment, and mitigation of risks. Handled manually, that means recurring workshops, spreadsheet maintenance, and internal coordination rounds. A GRC platform automates these processes: risks are captured, assessed, linked to specific measures, and documented in a living risk register — one that updates automatically as the threat landscape or organizational structure evolves.

Incident Management with Integrated Reporting Workflows

The 24-hour reporting deadline for significant security incidents is one of the toughest operational requirements in NIS-2. Without structured processes, it is nearly impossible to meet. GRC software provides integrated incident management modules: incidents are recorded in a structured way, automatically classified, relevant stakeholders are notified, and reporting pathways to the BSI can be prepared in advance. Comprehensive documentation also protects management in the event of a liability claim.

Supply Chain Security and Third-Party Management

NIS-2 also requires companies to secure their supply chains. That means: suppliers and service providers must be assessed for their security practices. A GRC platform allows this third-party management to be mapped systematically — with automated questionnaires, structured assessment workflows, and a central overview of all relevant partners.

Audit-Readiness at the Push of a Button

Particularly important entities must demonstrate their measures to the BSI within three years. Organizations that map their NIS-2 compliance in a GRC platform are audit-ready at any time: all evidence, documents, risk assessments, and action logs are stored in one central location, versioned, and retrievable on demand.

Relieving the Burden on Management and IT

An often-underestimated benefit: GRC software takes pressure off executive leadership. Instead of being overwhelmed by compliance details, decision-makers get clear dashboards that show at a glance where the organization stands on NIS-2 conformity. IT teams are relieved because routine tasks are automated — by up to 40 percent, according to research data.

Multi-Framework Coverage: NIS-2 Does Not Stand Alone

Companies required to implement NIS-2 often carry other regulatory obligations as well: GDPR, ISO 27001, DORA (for financial entities), TISAX (for the automotive industry), or the forthcoming KRITIS Umbrella Act. Well-integrated GRC platforms can map these frameworks in parallel and leverage synergies — organizations that are already ISO 27001 certified have a significant head start on NIS-2 compliance.

Zazoon: GRC Software That Does Not Overwhelm

At Zazoon, we have observed the realities of the mid-market up close. Companies do not need another checklist or another consultant’s slide deck. They need a software solution that breaks NIS-2 down into manageable steps, guides the implementation, and does not demand more IT expertise than realistically exists within the organization.

Our GRC platform delivers exactly that: a structured NIS-2 onboarding experience, integrated risk management, automated documentation, and a central dashboard for both management and IT — without requiring a dedicated compliance team to be built from scratch.

Conclusion: The Cost of Waiting Is Too High

NIS-2 is not a bureaucratic construct you can wait out. It is enforceable law with substantial penalties and personal liability for management. The sobering figures from the BSI Congress show that a significant portion of German business has yet to grasp this reality — or is deliberately choosing to ignore it.

The good news: it is not too late to get started in a structured way. And GRC software makes it realistic for the first time to achieve NIS-2 compliance without a large compliance team and without six-figure consulting budgets. Companies that act now are not just protecting themselves from fines and liability risks. They are building the foundation for a more resilient IT infrastructure, strengthening the trust of their customers and partners, and positioning themselves as dependable links in a security-conscious supply chain.

The effort is real. But it is manageable — with the right tools.

Frequently Asked Questions (FAQ)

Does NIS-2 apply to my company if we are not a technology business?
Yes, in many cases. NIS-2 covers companies across 18 sectors, including energy, transport, healthcare, mechanical engineering, chemicals, food production, and public administration. As a general rule: organizations with at least 50 employees or more than 10 million euros in annual revenue should actively check whether they fall within scope. This assessment should be carried out as soon as possible.

What happens if my company missed the registration deadline?
The BSI registration deadline expired on March 6, 2026. Companies that have not yet registered are at risk of fines and should complete registration without delay. The BSI has indicated that it is actively monitoring compliance with the obligations.

How significant are the potential fines?
For particularly important entities, fines can reach up to 10 million euros or 2 percent of global annual turnover. For important entities, the framework allows for fines of up to 7 million euros or 1.4 percent of global revenue.

What is the difference between “important” and “particularly important” entities?
Particularly important entities are larger organizations in critical sectors such as energy, water, financial market infrastructure, and healthcare. Important entities include mid-sized companies and organizations from additional sectors such as manufacturing, food, and digital services. The precise classification depends on sector, company size, and market position.

Does ISO 27001 certification help with NIS-2 implementation?
Yes, significantly. ISO 27001 and NIS-2 overlap in many areas — particularly around the information security management system (ISMS), risk analysis, and the documentation of security measures. Organizations that are already ISO 27001 certified have a meaningful head start. Good GRC platforms map both frameworks in parallel and use existing work as the foundation for NIS-2 compliance.

How long does NIS-2 implementation take with GRC software?
It depends on the organization’s starting point. With a GRC platform that includes structured templates, gap analyses, and automated workflows, well-prepared companies can reduce the time to compliance by up to 50 percent compared to a purely manual approach. Realistic timelines for reaching an initial solid compliance baseline are three to six months.

What exactly do I need to do as a managing director or executive?
Under Section 38 of the new BSIG, company management must actively oversee and approve the implementation of risk management measures. Regular training in four core areas is also mandatory — at a minimum every three years. Those who neglect these obligations face personal liability. A GRC platform helps document and evidence these activities in a structured and verifiable way.

Can GRC software also cover supply chain security?
Yes. Modern GRC platforms offer third-party management modules that allow suppliers and service providers to be systematically assessed and documented. This is particularly important given that NIS-2 explicitly requires supply chain security as part of an organization’s overall risk management obligations.

22 December 2025 | 5 min

GRC Regulation 2026: New Laws and Key Dates in the DACH Region

The turn of the year traditionally marks the starting point for new regulatory requirements in the field of Governance, Risk, and Compliance. While 2025 was heavily characterized by the final implementation of major EU frameworks such as DORA and NIS 2, the year 2026 is defined by expansion and technological deepening. For companies in the DACH region (Germany, Austria, Switzerland), January 1, 2026, specifically means: Grace periods are over, new reporting standards in the crypto sector take effect, and sustainability reporting reaches the next escalation level regarding the breadth of affected companies.

  • In Switzerland, the automatic exchange of information on crypto-assets (CARF) enters into force on January 1, 2026.
  • The CSRD reporting obligation expands to large, non-capital-market-oriented companies starting with the 2026 financial year.
  • For DORA and NIS 2, the implementation phase ends; from 2026 onwards, supervisory authorities will focus on auditing and sanctioning.
  • The EU AI Act approaches decisive deadlines, making 2026 the central year for AI governance implementation.

Switzerland: Transparency Push via CARF and Expanded AEOI

A central focus at the start of 2026 lies on Switzerland. On January 1, 2026, the Federal Council enacts the Crypto-Asset Reporting Framework (CARF) as well as amendments to the Common Reporting Standard (AIA/AEOI). This is a decisive step for tax transparency in the realm of digital assets.

The CARF framework obliges Swiss crypto service providers to record transaction data of their clients and information on held crypto-assets. This data must be reported to the Federal Tax Administration (FTA), which in turn exchanges it with partner states. The goal is to close tax loopholes that existed due to the previous non-recording of crypto-assets in the classic AEOI. For GRC managers at Swiss financial institutions and crypto service providers, this means that due diligence processes and KYC procedures (Know Your Customer) must be fully adapted to the new asset classes and reporting standards by the January 2026 deadline.

In parallel, amendments to the AEOI Act come into force, implementing recommendations of the Global Forum on Transparency and Exchange of Information for Tax Purposes. This affects, among other things, more precise due diligence obligations for Non-Reporting Financial Institutions.

CSRD: The Second Wave Rolls In

At the European level, January 1, 2026, is a crucial date for the Corporate Sustainability Reporting Directive (CSRD). While previously primarily capital-market-oriented companies were subject to reporting obligations, the obligation for large limited liability companies that are not capital-market-oriented begins with the 2026 financial year.

Companies fall under this second wave if they exceed at least two of the three following criteria: more than 250 employees, more than 50 million euros in net turnover, or more than 25 million euros in balance sheet total (taking into account inflation-related threshold adjustments). For compliance departments in these companies, the start of the 2026 financial year means that data collection for the report to be published in 2027 must now be operational. The time for preparation is over; from now on, ESG data must be recorded in an audit-proof manner. This requires functioning Internal Control Systems (ICS) for sustainability information.

DORA and NIS 2: From Project Mode to Regular Operations

Both the Digital Operational Resilience Act (DORA) and the NIS 2 Directive formally entered into force before 2026. Nevertheless, January 2026 marks a watershed moment. The phase of “Day 1 Compliance,” which was often still characterized by transitional solutions, is over.

From 2026 onwards, it is expected that national supervisory authorities – such as BaFin in Germany or FMA in Austria – will intensify their auditing activities. For DORA, this means that ICT third-party risk management must not only exist on paper, but contractual adjustments with IT service providers must be concluded. Registers of information relationships must be current and complete. GRC experts should use the year 2026 to test the processes implemented in the previous year for their operational effectiveness (e.g., through TLPT – Threat Led Penetration Testing), as real sanctions now loom.

Outlook: Supply Chain Acts and CSDDD

In Germany, the Supply Chain Due Diligence Act (LkSG) remains relevant, but the focus is increasingly shifting towards harmonization with the European Corporate Sustainability Due Diligence Directive (CSDDD). Although the national implementation laws of the CSDDD will only fully enter into force later, companies must strategically align their risk analyses with the more far-reaching requirements of the EU Directive from 2026 onwards to avoid double work. In particular, the climate transition plans, which are part of the CSDDD, require a lead time that should begin in January 2026.

FAQ

Who does the new CARF law in Switzerland affect starting January 2026?

It primarily affects Crypto-Asset Service Providers (CASPs/VASPs) resident in Switzerland. They must record client data and transactions and report them to the tax authorities.

Does my company have to create a CSRD report starting in 2026?

If your company is not capital-market-oriented but meets two of the three criteria (Balance sheet > 25m EUR, Turnover > 50m EUR, > 250 employees), the duty to collect data begins for the financial year 2026. The report itself will then appear in 2027.

What changes in 2026 regarding DORA?

Regulatorily, nothing new changes, but the grace period is over. From 2026, the first in-depth audits by supervisory authorities are expected to take place, and processes must be “lived and tested.”

What role does the EU AI Act play in January 2026?

The AI Act is already in force, but many obligations for high-risk AI systems only become strictly effective in mid-2026. January 2026 is therefore the starting signal for the final implementation phase of these requirements.

11 December 2025 | 6 min

Holiday gifts for business partners in the DACH region

During the Christmas season, many companies take the opportunity to thank their business partners with small gifts. These gestures strengthen relationships, show appreciation and are often part of a company’s culture. At the same time, tax rules, compliance requirements and internal guidelines must be respected – and these differ between Germany, Austria and Switzerland.

This article provides a current and balanced overview of the legal and practical framework for holiday gifts in all three DACH countries. It explains what companies should consider in order to give appropriately, avoid risks and maintain trust.

  • In all three countries, the same core principles apply: gifts must be business related, appropriate and transparent.
  • Germany has a tax threshold of 50 euros per recipient and calendar year for business gifts.
  • Austria and Switzerland do not use a single statutory value limit, but focus on appropriateness, business purpose and documentation.
  • Clear internal guidelines and consistent documentation are recommended throughout the DACH region.
  • Gifts to people in the public sector or highly regulated industries require particular caution.

Why clear rules are important in all three countries

Regardless of whether a company is based in Austria, Switzerland or Germany, gifts must never give the impression that they are intended to influence business decisions improperly. Compliance standards, anti-corruption rules and tax legislation are designed to ensure clean business relationships.

Companies should therefore apply clear and comprehensible principles in every country in which they operate. This prevents misunderstandings, reduces legal and tax risks and creates a uniform standard for all employees.

Current regulations at a glance

Germany

Germany is the only DACH country with a clearly defined tax limit for gifts to business partners. Business gifts are tax deductible up to 50 euros per recipient and calendar year if they are business related and properly documented.

For gifts that exceed this amount, the tax deduction may be denied unless the gift is clearly and exclusively usable for business purposes.

Austria

Austria does not work with a uniform fixed value limit. Instead, the following aspects are crucial:

  • the gift must serve a clear business purpose
  • the value must be reasonable in relation to the relationship and the occasion
  • the gift must be documented in a comprehensible way

As in the other DACH countries, gifts must not be used to gain improper advantages. Particular care is required in the public sector and in strongly regulated industries.

Switzerland

Switzerland also has no statutory standard limit for gifts to business partners. The focus is on:

  • usual appropriateness according to Swiss business practice
  • transparency and traceability
  • compliance with internal rules and industry-specific regulations

Swiss business culture tends to favour modest, high-quality but unobtrusive gifts rather than expensive luxury items.

Common basic principles for the entire DACH region

Despite the legal differences, companies in Germany, Austria and Switzerland can follow a common set of basic rules.

Appropriateness

The gift should match the business relationship, the role of the recipient and the occasion. Very expensive or flashy gifts can quickly appear inappropriate.

Business purpose

Holiday gifts should always serve a legitimate business purpose, such as maintaining a good relationship or thanking partners for successful cooperation. They must not be used to steer decisions or promises of business.

Documentation

For every gift, companies should record at least the following:

  • name of the recipient and company
  • occasion
  • date
  • value
  • business purpose

This documentation helps during tax audits and internal or external compliance checks.

Caution with public sector recipients

For employees of authorities, public hospitals, universities, municipalities and similar organisations, stricter requirements usually apply in all three countries. Often only very small tokens are permitted, and in some cases gifts are completely prohibited. When in doubt, it is better to ask in advance or avoid gifts altogether.

Recommendations for companies in the DACH region

  1. Create a clear, written gifting policy that applies in all locations.
  2. Define maximum values for gifts per person and per year.
  3. Ensure consistent documentation of all gifts to business partners.
  4. Pay special attention to sensitive sectors such as the public sector, healthcare or regulated industries.
  5. Plan gifts early and avoid borderline cases in terms of value or type of gift.
  6. Consider alternatives such as charitable donations in the name of a business partner instead of material gifts.

Why restraint is often the best strategy

No matter in which of the three countries a company operates, gifts that are too expensive or too personal can send the wrong signal. They may be perceived as an attempt to influence decisions and can trigger tax or compliance issues.

Modest, tasteful gifts or a personal handwritten card are often more effective and credible than high-value items. What counts in the long term is trust and partnership – not the material value of a present.

FAQ – Frequently asked questions in the DACH region

Is there a single value limit that applies to the whole DACH region?

No. Germany has a defined tax threshold of 50 euros per recipient and calendar year for business gifts. Austria and Switzerland use the principles of appropriateness, business purpose and documentation instead of fixed legal limits.

May I give expensive gifts in Austria or Switzerland if they seem appropriate?

In principle this is possible, but it is usually not advisable. High-value gifts increase the risk of compliance concerns, negative perceptions and disputes during audits. In practice, modest gifts are safer and more in line with expectations.

How should a business gift be documented correctly?

For each gift you should record who received it, for which company the person works, the date, the occasion, the value and the business reason. This information should be stored centrally, for example in a simple gifts register.

Are gifts to employees treated in the same way as gifts to business partners?

No. Gifts to employees are subject to different tax and payroll regulations in all three countries. Companies should therefore treat gifts to staff separately from gifts to external business partners and observe the respective rules.

How should I handle gifts to governmental bodies or public organisations?

With particular caution. In all DACH countries there are strict rules for the public sector, and many organisations either prohibit gifts completely or limit them to very small amounts. If you are unsure, ask for written guidance or refrain from giving a gift.

2 July 2025 | 4 min

Leadership Change in Risk Management at N26: What Companies Can Learn from a GRC Perspective

Intro

In the summer of 2025, German neobank N26 announced a significant leadership change: Chief Risk Officer (CRO) Carina Kozole will leave the company. She will be succeeded by Jochen Klöpper, formerly with Santander Consumer Bank.

Leadership transitions in key risk roles are always noteworthy – not only because of their impact on the organization itself, but also for what they reveal about the structural requirements of Governance, Risk, and Compliance (GRC) in fast-growing and heavily regulated businesses.

This article analyzes the developments at N26 through a systemic lens, outlines common challenges for digital financial service providers, and explains how integrated GRC systems help companies remain stable, compliant, and resilient during leadership transitions.

What Happened at N26?

Carina Kozole joined N26 in late 2023 as Chief Risk Officer and was responsible for enterprise-wide risk and compliance oversight. In 2025, the company announced her departure and named Jochen Klöpper as her successor. Klöpper brings extensive experience in risk management from his previous roles at Santander and other banks.

The timing is notable: N26, like many neobanks, is under increasing regulatory scrutiny. Topics such as AML compliance, IT security, credit risk, and internal controls are becoming critical not only from a regulatory perspective but also in terms of business continuity and market trust.

The Challenge: Growth, Complexity, and Regulatory Exposure

Digital organizations like N26 often face three structural issues:

1. Growth outpaces governance

Startups and digital scale-ups tend to prioritize innovation and customer growth. Governance, compliance, and process maturity often come later – sometimes too late.

2. Layered, evolving regulation

Digital banks operate under overlapping and evolving regulatory frameworks across jurisdictions. Without structured systems to track and manage these requirements, even competent teams can fall behind.

3. Dependency on individuals

In organizations where governance processes are not systematized, key responsibilities may rest with individuals. When those people leave, knowledge gaps, delays, or even compliance breaches can occur.

The GRC Perspective: Mitigating Risk Through Structure

Modern GRC systems help institutionalize risk and compliance processes, reduce dependency on individuals, and provide transparency across the organization.

What GRC software enables:

1. Centralized, auditable risk management

Risk categories, ownership, evaluations, and mitigation measures are documented in a structured, traceable system – not in spreadsheets.

2. Real-time regulatory oversight

Requirements (e.g., AML laws, data protection regulations, banking guidelines) are tracked centrally, with automated compliance status and escalation workflows.

3. Continuity during leadership transitions

With roles, responsibilities, deadlines, and documentation centralized, a new CRO can pick up critical tasks without process disruption or blind spots.

4. Visible governance culture

GRC systems can also track qualitative indicators – such as training effectiveness, audit response times, and cultural maturity – and contribute to an overall view of risk readiness.

Lessons Learned: From N26 to the Broader Market

  • People matter – but systems carry the organization. GRC systems ensure continuity when leadership changes.
  • Regulation is continuous, not project-based. Real-time visibility and structured compliance management are essential.
  • Good governance combines structure and culture. Systems alone are not enough; values, communication, and accountability must follow.
  • GRC tools are strategic, not just administrative. When well-integrated, they reduce risk exposure, improve investor confidence, and support long-term resilience.

Conclusion

The CRO transition at N26 illustrates the high stakes of governance and compliance in modern digital organizations. Especially in regulated sectors, leadership continuity and process integrity are inseparable.

A robust GRC system turns governance from a reactive obligation into a proactive capability – one that protects the organization, enables growth, and earns trust.


FAQ – Frequently Asked Questions on CRO Transitions and GRC

What does CRO stand for?
CRO stands for Chief Risk Officer – the executive responsible for enterprise-wide risk governance, including financial, regulatory, operational, and strategic risks.

Why is a CRO transition significant in banking?
Banks operate under strict regulatory regimes. A leadership change in the risk function may signal strategic shifts, regulatory attention, or internal restructuring. It can also affect market perception.

What happened at N26?
Carina Kozole will leave N26 in 2025. She will be succeeded by Jochen Klöpper, a seasoned risk executive from Santander. The move comes amid continued focus on strengthening risk and compliance capabilities.

What is a GRC system?
GRC (Governance, Risk, and Compliance) systems are software solutions that integrate regulatory management, risk monitoring, policy controls, and reporting into one framework.

How does a GRC platform support leadership transitions?
It ensures that responsibilities, regulatory obligations, and ongoing tasks are transparent and documented. That way, new leaders can take over without disruption or knowledge gaps.

Is GRC only relevant to large corporations or banks?
No. Any organization facing regulatory complexity, rapid growth, or cross-functional risk exposure can benefit from GRC systems – including in health care, energy, technology, and public administration.

What are the benefits of using GRC software?

  • Full visibility into risks and control measures
  • Regulatory tracking and automated compliance reporting
  • Role continuity and institutional memory
  • Improved audit readiness and accountability
  • Enhanced risk culture and decision-making

3 June 2025 | 3 min

How BaFin Uses Artificial Intelligence: Digitizing Financial Supervision

Germany’s Federal Financial Supervisory Authority (BaFin) is modernizing its tools for monitoring financial markets. To do this, it is increasingly relying on Artificial Intelligence (AI) to detect risks faster, uncover market manipulation, and automate compliance processes. In this blog post, we explore how BaFin uses AI, what benefits it brings, and what it means for companies and consumers.

AI in Market Surveillance: Algorithms Against Insider Trading

A key application of AI at BaFin is the detection of suspicious trading patterns. Using machine learning, BaFin analyzes vast amounts of trading data to uncover market manipulation and insider trading. These patterns are often hard for human analysts to detect but can be statistically significant indicators of abuse.

Automated Analysis of Company Data

Another field of application is the analysis of annual reports, ad-hoc disclosures, and financial statements. BaFin employs Natural Language Processing (NLP) to automatically identify risks, irregularities, or anomalies in corporate data. This accelerates the auditing of financial reports and helps detect adverse trends early.

AI in Banking Supervision: Risk Assessment and Early Warning Systems

AI is also used in regulatory assessments of banks and insurers. AI-powered early warning systems analyze metrics, capital structures, and market movements to identify risks early. This enables BaFin to intervene more quickly in times of crisis and prevent potential failures.

Anti-Money Laundering with AI

BaFin also uses AI to combat money laundering. By analyzing transaction patterns, suspicious activities can be automatically detected and reported. In collaboration with financial institutions, this improves both efficiency and the accuracy of prevention systems.

SupTech: Technological Shift in Supervision

Under the term SupTech (Supervisory Technology), BaFin is driving the digital transformation of its supervisory functions. AI plays a key role in processing large volumes of data, automating procedures, and making data-driven decisions.

Conclusion: Smarter Supervision Through Intelligent Systems

BaFin’s use of AI represents a decisive step toward modern, data-driven financial supervision. For companies, this means more transparency and faster processes. For consumers, it means greater protection from market abuse and financial crime. It also makes clear: supervisory authorities must evolve in the digital age to remain effective.


FAQ: Frequently Asked Questions About AI at BaFin

What is BaFin’s goal in using AI?

BaFin aims to detect risks earlier, uncover market abuse faster, and make supervision more efficient.

What technologies are being used?

Primarily machine learning, natural language processing (NLP), and data analytics.

Is the use of AI legally regulated?

Yes, BaFin must adhere to all applicable laws, including data protection and administrative law.

How do financial firms benefit?

Through clearer risk indicators, faster communication with regulators, and early warnings of potential problems.

What is SupTech?

SupTech refers to the technological advancement of supervisory work. AI is a central component of this development.

26 September 2023 | 0 min

Supply chain due diligence act (LkSG) from 1.1.2023

No content found

Share