Security Concepts & Threat Analyses13 min read
Legal Certainty for Bank Board Members: Navigating a Complex Environment
Legal certainty for bank board members: the 2026 MaRisk amendment, DORA and BAIT in practice. Which obligations carry personal liability, and how independent planning closes the compliance gap.
Legal certainty for bank board members is shaped by a complex web of laws such as the Aktiengesetz (AktG) and Kreditwesengesetz (KWG), as well as supervisory requirements such as MaRisk and DORA. Proper organisation, robust risk management, and the implementation of secure IT and security systems play a central role in minimising personal liability risks and guaranteeing operational resilience.
Minimising liability risk through independent planning and robust infrastructure
The requirements placed on bank board members are continuously rising, particularly with regard to IT security and risk management. Personal liability risks call for a proactive strategy and the implementation of legally compliant, future-proof systems.
Key Takeaways
- The personal liability of the board in banks requires a comprehensive understanding of, and proactive approach to, regulatory requirements, particularly in the area of ICT and security systems.
- MaRisk and DORA are central pillars of legal certainty; their consistent, forward-looking implementation is decisive for the bank's digital and operational resilience.
- Independent planning and consulting by experts such as PLANATEL® are essential for creating manufacturer-independent, legally compliant and future-proof infrastructure, and for effectively minimising liability risk.
Running a bank is, today more than ever, a task that demands the utmost diligence and comprehensive knowledge. Board members operate in an environment shaped by dynamic markets, advancing digitalisation, and a steadily growing density of regulatory requirements. The board's personal liability under Section 93 of the Aktiengesetz (AktG) and Section 25a of the Kreditwesengesetz (KWG) makes guaranteeing legal certainty an existential challenge. Wrong decisions or omissions, particularly in the area of information and communication technology (ICT) and security systems, can have far-reaching consequences. A proactive, strategic approach is therefore essential, to identify, assess and effectively minimise risk.

The Tightening of Board Liability in the Banking Sector
The personal liability of board members in banks has grown considerably in importance in recent years. Under Section 93 of the AktG, board members are obliged to exercise the diligence of a prudent and conscientious business manager when running the business. A breach of this duty can lead to claims for damages against the bank, for which the board can be held personally liable. This is further specified by specific banking-supervisory requirements such as the Kreditwesengesetz (KWG) and the Mindestanforderungen an das Risikomanagement (MaRisk, minimum requirements for risk management). In its circulars, most recently in November 2025, BaFin has clarified the requirements placed on management and supervisory bodies, particularly with regard to knowledge and experience in the ICT area. A ruling by the Munich I Regional Court (LG München I) of August 2025 illustrated the scope of these duties in monitoring high-risk financial transactions, and the limits of the so-called business judgment rule where central control duties are breached.
Advancing digitalisation and the new risks that come with it, such as cyberattacks and system failures, present additional challenges. Board members must ensure that their institutions have adequate personnel and technical-organisational resources to address these risks. This includes not only implementing robust systems, but also establishing effective risk management and internal control procedures. BaFin expects business leaders to know the risks of new technologies such as cloud services and to be able to manage them appropriately. Documenting these measures and reporting regularly to the supervisory body are decisive for guaranteeing legal certainty and for being able to demonstrate compliance with duties of care in an emergency.
Regulatory Framework: MaRisk and DORA
BaFin's Mindestanforderungen an das Risikomanagement (MaRisk) have for years formed the central framework for risk management at German banks and financial institutions. MaRisk specifies the legal requirements of Section 25a(1) KWG and provides a holistic framework for managing all material risks. An amendment to MaRisk, which came into force on 1 January 2025, strengthens risk strategy and places particular emphasis on considering IT and cyber risks as well as ESG risks. Banks must regularly check their IT infrastructure for security gaps and develop preventive measures against cyberattacks.
A further decisive development is the EU regulation on digital operational resilience (Digital Operational Resilience Act, DORA), which has applied directly in Germany since 17 January 2025. DORA establishes uniform, Europe-wide requirements for managing information and communication technology risks (ICT risks) and covers areas such as ICT risk management frameworks, reporting of major ICT incidents, testing of digital operational resilience, and ICT third-party risk management. To avoid duplicate regulation, BaFin is progressively repealing the Bankaufsichtliche Anforderungen an die IT (BAIT, banking supervisory requirements for IT) by 31 December 2026, with institutions that manage their ICT risk under DORA already exempt from BAIT since 17 January 2025. This requires a precise adjustment of internal processes and systems, to implement the new requirements in a legally compliant way.
The Importance of Robust ICT Infrastructure for Legal Compliance
A capable, secure ICT infrastructure is the backbone of every modern bank and a decisive factor for the board's legal certainty. The requirements of MaRisk, and particularly of DORA, make clear that IT security and digital resilience are no longer purely technical tasks, but have strategic importance for corporate management. Effective risk management must cover the management of IT resources, information risks and IT security. This includes implementing systems that not only withstand current threats, but can also meet future developments.
Concretely, this means banks must be able to fend off cyberattacks, guarantee data integrity, and quickly resume operations in the event of an incident. BaFin already warned in February 2025 of a growing threat from cybercrime, partly due to new technological possibilities such as artificial intelligence. A robust ICT infrastructure covers not only software and networks, but also the physical security of data centres and communication routes. Selecting, planning and implementing these systems must therefore be done with the greatest care and with consideration of all relevant standards and guidelines. Independent advice is essential here, to find manufacturer-independent, tailor-made solutions that meet the institution's specific requirements.

Fire Alarm Systems and Evacuation Systems: Protecting People and Assets
In the context of legal certainty for bank board members, fire alarm systems (BMA) and voice alarm systems (SAA) play a fundamental role. They serve not only to protect human life and material assets, but are also an integral part of risk management and operational continuity. A fire can not only cause physical damage, but can also massively disrupt business operations and endanger sensitive data, which in turn can result in significant liability risks for the board. Planning and operating these systems must therefore strictly follow the relevant standards.
DIN 14675, often referred to as the "fire brigade standard," describes the proper design and operation of fire alarm systems and voice alarm systems in Germany. It contains fire-brigade-specific requirements for automatic alarm forwarding and the installation of fire brigade control panels. VdS 2095, a guideline of the Verband der Sachversicherer, supplements these standards and is frequently required contractually or for insurance reasons, to guarantee a high degree of functional safety and reliability. PLANATEL® plans fire alarm systems and evacuation systems to these standards, to guarantee early fire detection, effective alerting and safe evacuation. This not only minimises the risk of injury and material damage, but also strengthens the bank's operational resilience, thereby reducing the board's liability risks.
Physical Security: Access Control and Video Surveillance
Alongside digital security, the physical security of bank buildings and sensitive areas is of decisive importance for the board's legal certainty. Access control and video surveillance systems are indispensable components here. They protect against unauthorised entry, theft and vandalism, and enable seamless documentation of events. Particularly in banks, where highly sensitive customer data and substantial assets are managed, these measures are essential for minimising risk.
Access control systems must be planned in a differentiated way, to ensure only authorised personnel gain access to certain areas. This ranges from the main branch to high-security areas such as server rooms or strongrooms. Video surveillance systems serve to prevent and clear up incidents, but must at the same time strictly comply with data-protection requirements, in particular the GDPR. Storing and processing image material is subject to strict legal requirements. PLANATEL® plans these systems on a manufacturer-independent basis and in consideration of all relevant legal provisions and data-protection guidelines. Professional planning ensures the systems are effective, respect privacy, and can provide evidence usable in court where needed, thereby strengthening the board's legal certainty.
Energy and Facility Management: Operational Safety and Sustainability
A bank's operational safety depends significantly on a reliable power supply and efficient facility management. Uninterruptible power supply systems (UPS), battery systems, and emergency standby power systems (NEA) are critical infrastructure that guarantee the continuous operation of IT systems and security equipment even during power outages. A power supply failure can not only lead to data loss and system failures, but can also impair the functioning of fire alarm systems, access controls and communication systems. This would considerably weaken the bank's operational resilience and significantly increase the board's liability risks.
Planning these systems requires in-depth technical expertise and consideration of standards such as DIN VDE 0100-560 for safety power supplies. Beyond this, energy management is becoming increasingly important in the context of ESG requirements (environment, social, governance). Banks are required to increase their energy efficiency and reduce their ecological footprint. PLANATEL® supports banks in planning energy-efficient, failsafe systems that support both operational safety and the institution's sustainability goals. Optimising the energy infrastructure and facility management not only improves legal compliance with environmental requirements, but also increases resilience to external disruptions, which directly contributes to the board's legal certainty.
The Role of Independent Planning and Consulting for the Board
Given the complexity and the high liability risks, it is decisive for bank board members to draw on independent expertise. PLANATEL® has, since 1992, offered tailor-made solutions as an independent planning and consulting firm in the areas of IT, telecommunications, security systems, and energy and facility management. Our 100 percent manufacturer-independence and financial independence guarantee that the recommended solutions are always objective and in the bank's best interests, without any commissions from providers.
We support boards in understanding complex regulatory requirements and translating them into concrete technical and organisational measures. This begins with the as-is survey and needs analysis, continues through the target concept and detailed planning, and extends to the tender, award and support during implementation. Our expertise covers the planning of fire alarm systems to DIN 14675 and VdS 2095, intrusion detection systems to DIN VDE 0833, video surveillance, and access control. Drawing on over 34 years of experience in the industry, we help develop technical concepts and strategies that are not only legally compliant, but also optimised from a business perspective. This reduces not only operational risk, but also the board's personal liability risk, through demonstrably well-founded decisions and professional implementation.
Strategies for Continuous Risk Minimisation and Future Readiness
Guaranteeing legal certainty for a bank's board is not a one-off task, but a continuous process. The regulatory landscape, technological developments and threat scenarios are constantly changing. A dynamic strategy for risk minimisation and for securing the institution's future readiness is therefore essential. This includes regularly reviewing and adapting all relevant systems and processes, to always meet current requirements.
An effective risk management system must be regularly audited and checked for its effectiveness. This applies particularly to the ICT infrastructure, which, given the DORA requirements, is subject to continuous monitoring and testing. Boards should also ensure their staff are regularly trained, to guarantee a high level of security awareness and expertise. BaFin emphasises that management should have sufficient knowledge and experience in the ICT area, and that regular training should take place. PLANATEL® supports banks in developing such long-term strategies, planning maintenance concepts, and selecting certified installers. Through proactive management and the integration of independent expertise, banks can sustainably strengthen their operational resilience and guarantee legal certainty for their board, even in a changing environment.

Next Step
Contact us for a no-obligation initial consultation.
PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
E-Mail: info@planatel.de
Frequently Asked Questions
What specific requirements does BaFin place on the board's ICT knowledge?
In its circulars, most recently in November 2025, BaFin has clarified that management and supervisory bodies must have sufficient knowledge and experience in the ICT area. This is decisive for being able to appropriately manage the risks of advancing digitalisation, such as cloud services and cyber threats. Regular training is recommended, to keep these competencies up to date and to fulfil monitoring duties in a legally compliant way.
How can banks guarantee compliance with DIN 14675 for fire alarm systems?
Compliance with DIN 14675 for fire alarm systems is guaranteed through proper planning, installation, commissioning and servicing by certified specialist firms. PLANATEL® supports banks in the independent planning of fire alarm systems to DIN 14675 and VdS 2095, in preparing detailed concepts, and in selecting qualified installers. This ensures that all fire-brigade-specific requirements and technical standards are met, which significantly strengthens the board's legal certainty.
What role does risk management play in minimising board liability?
Robust, effective risk management is fundamental to minimising board liability. It covers the systematic identification, assessment, control and monitoring of all relevant risks, including operational, financial and, in particular, ICT risks. The board is obliged to establish such a system and to continuously review its effectiveness. Seamless documentation of the risk management processes serves as proof of the duty of care and protects against personal liability.
How do access control and video surveillance systems contribute to legal certainty?
Access control and video surveillance systems contribute significantly to legal certainty by guaranteeing the physical security of bank buildings and sensitive areas. They prevent unauthorised access, protect against theft and vandalism, and enable seamless documentation of security incidents. Compliance with data-protection requirements (GDPR) is essential when planning them. Professionally planned systems, such as those designed by PLANATEL®, offer not only protection, but also the legal compliance the board needs.
How does PLANATEL® support bank boards in complying with regulatory requirements?
PLANATEL® supports bank boards through independent planning and consulting for the legally compliant implementation of regulatory requirements. With over 34 years of experience, we offer manufacturer-independent expertise in IT, telecommunications, security systems (e.g. fire alarm systems to DIN 14675), and energy management. We analyse needs, develop tailor-made concepts, and support tenders and implementation. Our goal is to create robust, future-proof infrastructure that strengthens operational resilience and minimises the board's personal liability risks through well-founded decisions.
Which laws and regulations are particularly relevant to a bank board's legal certainty?
The Aktiengesetz (AktG), the Kreditwesengesetz (KWG), the Mindestanforderungen an das Risikomanagement (MaRisk), and the EU regulation DORA (Digital Operational Resilience Act) are of central importance for a bank board's legal certainty. These define duties of care and requirements for risk management and IT security.
How does DORA affect the liability of bank boards?
DORA (Digital Operational Resilience Act) sets uniform, comprehensive requirements for digital operational resilience across Europe. Failure to comply with these requirements can lead to significant disruption to business operations, thereby increasing the board's personal liability in the event of breaches of duty in risk management and IT security.
What role do fire alarm systems play in legal certainty at banks?
Fire alarm systems (BMA) are of great importance for legal certainty at banks, as they serve to protect human life and assets and to secure business continuity. Legally compliant planning and operation to DIN 14675 and VdS 2095 minimise risk and reduce the board's liability in the event of fire.
Why is independent advice important for bank boards when planning systems?
Independent advice is decisive for bank boards, to obtain manufacturer-independent, objective solutions for complex IT and security systems. This avoids potential conflicts of interest, guarantees the choice of optimal technologies, and supports legally compliant implementation, thereby underpinning the board's decision-making.
Sources and Further Reading
- Geschäftsleiterhaftung Banken: Wann Manager persönlich haften – Kanzlei Herfurtner
- Neue aufsichtsrechtliche Rahmenbedingungen für die Arbeit von Vorständen (2026)
- Die Legalitätspflicht von Vorstand und Aufsichtsrat im Konflikt zwischen deutschem und ausländischem Recht – Taylor Wessing
- BaFin-Sanktionen und persönliche Vorstandshaftung in Banken – Der Bank Blog
- Bankvorstände mit besonderen Qualifikationen – BaFin
