Minimising board liability at banks requires strategic, legally compliant planning of security systems. By implementing robust fire alarm systems, intrusion detection systems and video surveillance that meet current standards such as DIN 14675 and VdS 2095, together with comprehensive risk management, board members can fulfil their duty of care and significantly reduce personal liability risk.

Comprehensive planning of security systems to reduce risk and ensure legal compliance

The personal liability of bank board members is a serious risk that can arise from inadequate security systems and poor risk management. Proactive, manufacturer-independent planning of fire alarm systems, intrusion detection systems and other security systems is essential to minimise these risks and ensure the institution is run in a legally compliant way.

Key Takeaways

  • Board liability at banks is a real risk that can arise from inadequate security systems and poor risk management, reinforced by MaRisk and DORA.
  • Manufacturer-independent, independent planning of fire alarm systems, intrusion detection systems, video surveillance and access control to DIN/VdS standards is essential for building legally compliant, effective security architectures.
  • Continuous review, adjustment of the security strategy, and a strong security culture, supported by external expertise, are decisive for permanently minimising liability risk.

Running a financial institution carries far-reaching responsibilities, which ultimately manifest in the personal liability of board members. Faced with an increasing complexity of threats, from cyberattacks to physical security risks, boards face the challenge of running their institutions not only successfully, but also securely and in a legally compliant way. An inadequate approach to these security aspects can have serious consequences, ranging from substantial financial damage to the institution through to the personal liability of board members. It is therefore essential to take preventive measures and rely on sound, independent planning of security systems in order to manage and minimise these risks effectively.

Article image: board liability bank security minimise - hero

The personal liability of board members and managing directors at banks in Germany is clearly defined by a series of laws and supervisory requirements. The central legal bases here are the Stock Corporation Act (AktG) and the Banking Act (KWG), supplemented by the Minimum Requirements for Risk Management (MaRisk) of the Federal Financial Supervisory Authority (BaFin) and, since January 2025, also by the Digital Operational Resilience Act (DORA) at European level. Under section 93(1) AktG, board members are obliged to apply the diligence of a prudent and conscientious manager in conducting business. A breach of this duty of care can lead to claims for damages by the institution against the board. The KWG specifies these obligations for the banking sector and sets out detailed rules intended to ensure that managers act with due care.

MaRisk, last updated in BaFin's circular 06/2024 (BA), sets out a holistic framework for managing all material risks, including IT and cyber risks. With DORA entering into force on 17 January 2025, the requirements for ICT security and operational resilience in the financial sector were harmonised across Europe, further tightening the requirements placed on boards. In January 2025, BaFin announced that it would phase out the national Supervisory Requirements for IT in Financial Institutions (BAIT) in favour of DORA, with BAIT being fully replaced by 31 December 2026. This underscores the need for boards to keep continuously informed of evolving regulatory frameworks and to ensure that internal processes and security systems always meet them. The distinction between negligent and intentional conduct is decisive for liability, with intentional breaches of duty often carrying stricter liability consequences.

Identifying and assessing specific security risks for banks

Because of their role in the financial system and the sensitivity of the data they manage, banks are exposed to a particularly wide range of security risks. These risks can be broadly divided into digital and physical threats, which are, however, increasingly interlinked. In the digital sphere, cyberattacks represent one of the biggest and fastest-growing dangers. BaFin's 2025 risk report highlights that the threat situation in cybersecurity intensified to a record level in 2024, with attacks on IT service providers, cloud environments, and AI-optimised attacks being particularly dangerous. An EY cybersecurity study from 2025 shows that 47% of the companies surveyed see a high risk from cyberattacks, and 73% report phishing attacks.

Alongside cyberattacks, physical security risks such as burglary, sabotage, vandalism and unauthorised access remain relevant. These can cause not only property damage but also enable access to sensitive data or critical infrastructure. A failure of IT systems, whether due to cyberattacks or technical faults, can paralyse the entire economic system. In its press releases, BaFin stresses that cyberattacks or IT outages represent one of the greatest risks to the financial sector, and that disruptions can occur not only at banks themselves but also at contracted service providers. FINMA (the Swiss Financial Market Supervisory Authority) also warns in its 2025 risk monitor of the increasing complexity of the cyber threat landscape, particularly due to technological interconnection and external dependency on third-party providers. A comprehensive risk assessment must therefore take account of all potential attack vectors and analyse the interplay between digital and physical security measures. Management is obliged to carry out a comprehensive risk assessment and to appoint a person responsible for IT security.

Holistic security concepts as a prevention strategy

Minimising board liability requires a move away from isolated security solutions towards an integrated, holistic security concept. Such a concept treats the various security systems not as separate units but as interconnected components of a comprehensive protective shield. This includes the planning of fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance systems, access control systems and security management systems that interlock seamlessly and can be centrally controlled. FINMA stresses that a modern security concept does not consist of individual technical measures but of coordinated, risk-based security mechanisms.

For fire alarm systems, compliance with DIN 14675 (structure and operation of fire alarm systems) and VdS 2095 (guidelines for automatic fire alarm systems, planning and installation) is of decisive importance. These standards and guidelines define not only technical requirements but also processes for planning, design, installation, commissioning, acceptance and servicing. VdS 2095 is particularly relevant where VdS recognition of the BMA is explicitly required, for example by property insurers. For fire alarm systems required under building law, implementation of DIN 14675 and DIN VDE 0833 is generally sufficient. A holistic concept also includes the integration of access control systems, which govern physical access to sensitive areas, and video surveillance systems, which serve to detect, verify and document security incidents. Linking these systems in a central security management system enables a faster response to incidents and more efficient coordination of security personnel. BaFin calls on banks to take greater precautions against cyberattacks and IT outages and to invest in their operational security and stability.

Article image: board liability bank security minimise - mid

The role of independent planning in minimising risk

The complexity of modern security systems and the constantly evolving threat scenarios call for specialist planning expertise. This is where the independent planning and consulting services of companies such as PLANATEL® come in. As a manufacturer-independent partner with over 34 years of experience in planning security systems since 1992, PLANATEL® provides decisive support in minimising board liability. Independence from manufacturers is a central factor here, as it ensures that the recommended solutions serve solely the individual requirements of the financial institution and are not driven by commercial interests. This leads to an objective selection of the best technologies and systems, optimally tailored to the specific risk profile and existing infrastructure.

The planning includes a detailed as-is survey, a precise needs analysis and the development of a target concept that takes account of all relevant standards and guidelines, including DIN 14675, VdS 2095, EN 54 and DIN VDE 0833. This sound planning ensures that the planned fire alarm systems, intrusion detection systems, video surveillance systems and access control systems are not only technically capable but also fully legally compliant. PLANATEL®'s expertise helps identify potential vulnerabilities at an early stage and define preventive measures that reduce the likelihood of security incidents. Producing detailed tender documents and providing support during the award process also ensures a transparent and cost-effective realisation of the projects. Independent planning of this kind is an essential building block for demonstrably fulfilling the board's duty of care and thereby reducing personal liability risk.

Implementation and operation: from planning to legally compliant realisation

The best planning is only as good as its execution. After detailed design by PLANATEL®, the phase of implementing and operating the security systems follows. Here it is decisive that the selected installer companies have the necessary certifications and specialist knowledge to install the planned fire alarm systems, intrusion detection systems, video surveillance systems and access control systems to the highest standards. PLANATEL® supports banks in selecting qualified, certified installers and accompanies the entire implementation process, to ensure compliance with the design specifications and relevant standards such as DIN 14675 and VdS 2095. DIN 14675-2, for example, sets requirements for the specialist firm and requires that persons responsible for fire alarm systems regularly review their knowledge and provide proof of training at least every four years.

A further critical aspect is comprehensive documentation of every step, from installation through commissioning to acceptance. Seamless documentation is not only essential for later maintenance and troubleshooting, but also serves as important evidence that the board has properly fulfilled its duty of care towards supervisory authorities such as BaFin. After successful acceptance of the systems, a structured maintenance and servicing concept is of great importance. PLANATEL® plans maintenance concepts that provide for regular inspections and servicing measures to ensure the permanent functionality and reliability of the security systems. This also includes planning operational-principle tests, particularly for complex interfaces between different systems, as required under VdS 2095. Continuous monitoring and upkeep of the systems prevents failures and ensures that the institution is protected against current threats at all times, which directly contributes to minimising board liability.

Use of technology and future-proof security architectures

Technological progress in security systems is rapid, and banks must continuously adapt their architectures to meet evolving threats. A future-proof security architecture is characterised by scalability, flexibility and the ability to integrate new technologies. This particularly affects the areas of video surveillance, access control and security management systems. Modern video surveillance systems increasingly use artificial intelligence (AI) and machine learning to automatically detect anomalies, people or objects, which significantly increases monitoring efficiency and reduces false alarms. FINMA points out that attackers are becoming ever more professional and their methods are evolving, particularly through faster automation and the use of generative AI.

Integrating biometric methods into access control systems, or using mobile authentication solutions, increases both security and convenience. A central security management system that brings together all security systems, from fire alarm systems to video surveillance, enables a holistic view of the security situation and a coordinated response to incidents. Redundancy and fail-safety are not optional features but essential components of a robust security architecture, particularly for critical infrastructure such as banks. This includes redundant power supplies, emergency backup power systems, and uninterruptible power systems, to ensure operation even during power outages. PLANATEL® advises on the design of such highly available architectures and ensures that the planned systems meet the requirements for digital resilience mandated by DORA. BaFin calls on banks to regularly review their IT infrastructure for security gaps and to develop preventive measures against cyberattacks.

Continuous review and adjustment of the security strategy

Security is not a static state but a dynamic process. The threat landscape is constantly evolving, and with it, banks' security strategies must be continuously reviewed and adjusted. This is a central aspect of the board's duty of care and a decisive factor in minimising board liability. Regular security audits and risk assessments are essential to evaluate the effectiveness of existing security systems and identify new risks. BaFin stresses the need to continuously strengthen risk management and adapt it to current developments, including new risk categories such as cyber risk.

PLANATEL® supports financial institutions in carrying out such audits and developing adjustment strategies. This includes reviewing compliance with current standards and guidelines (e.g. DIN 14675, VdS 2095, DORA, MaRisk), analysing vulnerabilities and recommending optimisation measures. An incident response plan that takes effect in the event of a cyberattack or a physical security incident is also an indispensable part of a robust security strategy. This plan should be tested and updated regularly to ensure a fast, effective response. Management must monitor compliance with, and implementation of, the cyber strategy and the security measures introduced, to ensure they remain effective and withstand current threats. Through proactive, continuous adjustment of their security strategy, banks can not only protect their assets and data but also significantly reduce the personal liability of their board members by demonstrably exercising the required duty of care.

Best practices and the importance of external expertise

To minimise board liability effectively, banks should rely on proven best practices and draw on external, independent expertise where needed. One of the most important best practices is establishing a strong security culture throughout the organisation. This means security is not only a task for the IT or security department, but must be embedded in the mindset of every employee. Regular training and awareness campaigns are essential for this, to sensitise employees to potential threats and train them in handling sensitive information and systems. BaFin calls for the implementation of robust compliance systems and regular training for staff and managers.

A further decisive point is transparent, seamless documentation of all security measures, risk assessments and incident responses. This documentation serves not only as evidence of the duty of care, but also as a basis for continuous improvement. Engaging external, manufacturer-independent consulting firms such as PLANATEL® offers considerable advantages here. With over 34 years of experience planning and optimising complex infrastructures, PLANATEL® can bring an objective perspective, uncover blind spots, and develop tailored solutions that meet the specific requirements of the financial sector. Independent assessment and planning of security systems, from fire alarm systems to DIN 14675 through to complex security management systems, ensures that banks not only meet current regulatory requirements but are also proactively prepared for future threats. This is the surest path to minimising board liability through demonstrably high security quality.

Article image: board liability bank security minimise - bottom

Next Step

Contact us for a no-obligation initial consultation.

PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de

Frequently Asked Questions

Why is manufacturer-independent planning of security systems so important for banks?

Manufacturer-independent planning is of decisive importance for banks, as it ensures an objective selection of the best and most cost-efficient security technologies. Without being tied to particular providers, solutions can be chosen that are optimally tailored to the specific needs and risk profile of the institution. This avoids unnecessary costs, prevents manufacturer dependency, and ensures that investments in security systems provide maximum protection, which in turn supports the board's duty of care.

Which specific security systems should a bank consider as part of a holistic concept?

A holistic security concept for banks should include a range of integrated systems. These include fire alarm systems (BMA) to DIN 14675 and VdS 2095, intrusion detection systems (EMA), video surveillance systems with intelligent analysis functions, modern access control systems (possibly with biometrics), and an overarching security management system that centrally controls and monitors all components. Telecommunications and IT infrastructure that ensures secure communication and data processing are also essential.

Permanent legal compliance of security systems requires ongoing effort. It begins with sound planning to current standards (e.g. DIN, VdS, EN) and regulatory requirements (MaRisk, DORA). After implementation, regular maintenance, inspections and audits must be carried out. Seamless documentation of all processes and staff training are also important. External, independent consulting helps identify new requirements early and proactively adjust systems to always meet current standards.

What role does documentation play in minimising board liability?

Documentation plays a central role in minimising board liability. It serves as evidence that the board has fulfilled its duty of care and taken adequate measures to minimise risk. Seamless documentation covers the needs analysis, planning, selection of systems, implementation, acceptance, maintenance, and all training carried out. In the event of a security incident or a supervisory examination, this documentation can be decisive in demonstrating proper management and defending against personal liability claims.

How do banks benefit from PLANATEL®'s more than 34 years of experience?

PLANATEL®'s more than 34 years of experience in independent planning and consulting offers banks an invaluable advantage. This long-standing expertise makes it possible to tackle complex security challenges with proven methods and in-depth specialist knowledge. PLANATEL® knows the specific requirements of the financial sector, the regulatory framework, and technological developments. This leads to tailored, future-proof, legally compliant security solutions that not only minimise risk but also ensure efficiency and investment security for the institution.

Which laws govern board liability at German banks?

Board liability at German banks is primarily governed by the Stock Corporation Act (AktG) and the Banking Act (KWG). In addition, BaFin's Minimum Requirements for Risk Management (MaRisk), and, since January 2025, the Digital Operational Resilience Act (DORA) at European level, are decisive. These frameworks define the board's duties of care and the conditions for personal liability in the event of breaches of duty.

What are the biggest security risks for banks in 2026?

In 2026, cyberattacks are among the biggest security risks for banks, particularly attacks on IT service providers, cloud environments, and AI-optimised attacks. Physical threats such as burglary and sabotage, as well as IT system outage risks, also remain critical. BaFin and FINMA both stress the increasing complexity and interconnection of these risks.

How does the Digital Operational Resilience Act (DORA) help minimise board liability?

DORA, in force since January 2025, harmonises the requirements for ICT security and operational resilience in the European financial sector. By establishing a uniform framework for managing ICT risk and reporting security incidents, DORA compels banks towards more robust security measures. Compliance with these requirements serves boards as evidence of their duty of care and helps minimise liability risk.

What role do DIN 14675 and VdS 2095 play in planning fire alarm systems at banks?

DIN 14675 and VdS 2095 are central standards for the planning and operation of fire alarm systems (BMA). DIN 14675 describes the structure and operation of BMA, while VdS 2095 provides specific guidelines for the planning and installation of automatic BMA, often required by property insurers. Compliance with these standards is decisive for the legally compliant and effective design of fire alarm systems at banks.

Sources and further information

  • Managing director liability at banks: when managers are personally liable – Kanzlei Herfurtner
  • Board liability at AG companies – liability, avoidance and compliance – Kanzlei ROSE & PARTNER
  • Reliably minimising your liability as an AG board member – Wollring Law
  • BaFin sanctions and personal board liability at banks – Der Bank Blog
  • Current topics – boards liable for poor compliance – BaFin