Security Concepts & Threat Analyses16 min read
Operator Obligations for Credit Institutions: Proof, Legal Compliance and Risk Minimisation
Inadequate record-keeping carries considerable legal and financial risks. This article examines the challenges and shows how strategic planning and independent consulting can secure legal compliance.
This covers regular inspections, maintenance, and the appointment of responsible persons in accordance with regulations such as MaRisk, BAIT, BetrSichV, DIN 14675, and VdS 2095. Independent planning and consulting helps to meet these complex requirements in a legally compliant and efficient way, and to make the proof obligations sound enough to stand up in court.
Comprehensive requirements for technical systems and their complete documentation
Inadequate record-keeping carries considerable legal and financial risks. This article examines the challenges and shows how strategic planning and independent consulting can secure legal compliance.
Key Takeaways
- Credit institutions must provide complete proof of operator obligations for technical systems, in particular BMA, to avoid legal risks and liability claims.
- Compliance with MaRisk, BAIT (or DORA), BetrSichV, DIN 14675, and VdS 2095, as well as the appointment of a "responsible person", are essential for legal compliance.
- Independent planning and consulting by PLANATEL® secures manufacturer-independent process optimisation and court-proof record-keeping, minimises risks, and increases operational safety.
The operator obligations for credit institutions have become considerably more complex in recent years. Given increasing digitalisation and the classification of many financial service providers as critical infrastructure (KRITIS), the requirements for operational safety and digital resilience are growing steadily. It is no longer just a matter of keeping technical systems functional, but also of documenting compliance with all relevant standards and statutory requirements completely and in a way that will stand up in court. Missing or deficient record-keeping can have far-reaching consequences for boards and managing directors, from significant fines to liability claims. A proactive and strategic approach is therefore essential to minimise risks and guarantee operational safety.

The legal basis of operator obligations for credit institutions
The operator obligations of credit institutions are anchored in a complex network of laws, regulations, and technical standards. At the centre are the requirements of the Federal Financial Supervisory Authority (BaFin), in particular the Minimum Requirements for Risk Management (MaRisk) and the Supervisory Requirements for IT in Financial Institutions (BAIT). MaRisk, most recently updated in circular 06/2024 (BA) of May 2024, sets a flexible framework for risk management and specifies the requirements for organisational and operational structure, risk control and monitoring processes, as well as technical and organisational equipment. BAIT, which was largely replaced by the DORA regulation (Digital Operational Resilience Act) by 16 January 2025, previously set the framework for the secure design of IT systems and IT risk management. For certain institutions newly regulated under DORA, however, BAIT remains applicable until 31 December 2026.
In addition, credit institutions are often classified as operators of critical infrastructure (KRITIS) under the BSI Act, which brings additional obligations for cybersecurity and physical resilience. The KRITIS umbrella act, approved by the Bundesrat in January 2026, obliges operators to consider physical and digital security measures in an integrated way and to submit risk assessments of hybrid threats. In addition, the Ordinance on Industrial Safety and Health (BetrSichV) governs the safe use of work equipment and the operation of installations requiring monitoring, which also covers many technical systems in credit institutions. It requires regular inspections and a risk assessment, in order to identify unsafe conditions in good time. Compliance with these diverse bodies of rules is not only a matter of legal compliance, but also a decisive factor for maintaining business operations and protecting against reputational damage.
Specific operator obligations for fire alarm systems (BMA) in credit institutions
Fire alarm systems (BMA) are of particular importance in credit institutions, as they protect not only human life but also the integrity of sensitive data and assets. The operator obligations for BMA are set out in detail in national and European standards. The decisive standards here are DIN 14675 (fire alarm systems, structure and operation) and VdS 2095 (guidelines for automatic fire alarm systems, planning and installation). These standards represent the current state of the art and are referred to in claims and expert assessments.
DIN 14675-1:2020-01 sets out requirements for the planning, detailed engineering, assembly, installation, commissioning, acceptance, operation, servicing, and modification of BMA. A central aspect is the appointment of a "responsible person for fire alarm systems" in accordance with DIN 14675-2. This person must have specific specialist knowledge, proven by a corresponding examination. Their duties include, among other things, the quarterly walk-through of the monitored areas, operating the system, and keeping the operations log.
VdS 2095:2022-06 concretises these requirements and supplements them with insurance-related aspects. It covers all life-cycle phases of a BMA, from concept development through installation to maintenance and servicing. Regular maintenance and servicing are essential to guarantee the functionality of the system and to avoid false alarms. All of these activities must be documented completely in the operations log, in order to meet the proof obligations. Compliance with these specific requirements is not only a legal necessity for credit institutions, but also an essential part of their comprehensive risk management.
The importance of proof: why documentation is decisive
Complete documentation of the operator obligations is of fundamental importance for credit institutions. It serves not only internal control, but above all as court-proof evidence to supervisory authorities, insurers, and in the event of liability claims. As part of its supervision, BaFin expects institutions to establish appropriate and effective risk management, which also covers record-keeping for technical systems. During audits or inspections, credit institutions must be able to demonstrate at any time that they have met their obligations.
Inadequate proof can have serious consequences. In the event of a loss, for example a fire, missing or deficient documentation can lead to insurance benefits being reduced or refused entirely. Even more serious are the potential civil-law liability risks for management and the board. In the event of a breach of operator obligations, injured parties can assert claims for damages, which can lead not only to considerable financial losses but also to massive reputational damage. JuraForum.de defines operator obligations as legal requirements placed on operators of installations, in order to prevent legal violations and liability claims.
Documentation must cover the entire life cycle of the systems, from planning and installation through regular maintenance and inspections to modifications and decommissioning. This includes inspection records, maintenance reports, training certificates for responsible persons, risk assessments, and emergency plans. Well-kept documentation creates transparency, enables the traceability of all measures, and proves the credit institution's duty of care. It is thus an indispensable instrument for risk minimisation and for ensuring legal compliance.

Challenges in fulfilling and documenting the operator obligations
Fulfilling and completely documenting the operator obligations presents credit institutions with considerable challenges. One of the biggest difficulties lies in the complexity and dynamism of the regulatory landscape. Laws, regulations, and technical standards are regularly updated, as shown by the replacement of BAIT by DORA in January 2025. It requires continuous effort to stay up to date and to integrate all changes into operational processes promptly. According to one source, more than 2,000 relevant legal provisions, standards, and guidelines must be taken into account in the operator responsibility for buildings, of which a fifth to a quarter are updated annually.
A further problem is the lack of internal resources and specialist expertise. Many credit institutions do not have sufficiently qualified staff to independently manage the complex technical and legal requirements. This affects both the technical expertise for the maintenance and inspection of systems, and the legal know-how for the correct interpretation of the regulations and the preparation of court-proof documentation. Historically grown, fragmented IT infrastructures and monolithic applications also make efficient data collection and management for risk management more difficult.
This often leads to inadequate or inconsistent documentation. Information is spread across various systems, or even kept on paper, which makes record-keeping for audits or in the event of a claim difficult or impossible. Dependence on individual manufacturers can also present a hurdle, as it limits flexibility in the selection of solutions and service providers. These challenges can lead to permanent exposure to legal risks and operational inefficiencies if no proactive measures are taken.
Strategies for legally compliant fulfilment and complete record-keeping
To meet the complex operator obligations in a legally compliant way and to guarantee complete record-keeping, credit institutions should pursue a multi-stage strategy. The first step is the implementation of a robust management system for technical systems and the associated obligations. This can be an integrated computer-aided facility management system (CAFM), which centralises and automates all relevant data and processes. Such systems support the recording of properties, technical systems, and the associated regulations, generate checklists for inspections and maintenance, and document all completed tasks.
Second, involving external expertise is decisive. Independent planning and consulting companies such as PLANATEL® can support credit institutions in analysing the as-is situation, determining needs, and developing tailored concepts. This includes evaluating existing systems, defining inspection and maintenance cycles, and preparing documentation standards. External specialists bring up-to-date expertise in standards and regulations and can help close internal gaps and optimise processes.
Third, digitalising record-keeping is a key factor. Instead of relying on manual or fragmented systems, digital solutions should be used that enable the automated recording, storage, and provision of inspection records, maintenance reports, and other relevant documents. This increases not only efficiency, but also the quality and tamper-resistance of the records. Fourth, continuous training and awareness-raising of staff is essential. Employees entrusted with the operation and maintenance of technical systems must be trained regularly, in order to understand and correctly implement the requirements of BetrSichV, DIN 14675, and other relevant standards. This includes, in particular, training for the role of "responsible person for fire alarm systems".
The role of independent planning and consulting in fulfilling operator obligations
The complexity of the operator obligations and the need for complete record-keeping often require external support. This is where PLANATEL®'s expertise comes in. As an independent planning and consulting company with more than 34 years of experience, we offer credit institutions tailored solutions to master the challenges of the operator obligations in a legally compliant and efficient way. Our core competence lies in manufacturer-independent and financially independent consulting, which ensures that the recommended solutions are always in the client's best interest and create no manufacturer dependency.
PLANATEL® supports credit institutions in all phases of planning and optimising their technical infrastructure, in particular in the field of fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance systems, and access control systems. Our services include a detailed as-is survey of the existing systems and processes, a comprehensive needs analysis, and the development of a target concept that takes into account all relevant statutory requirements and standards such as DIN 14675, VdS 2095, and DIN VDE 0833. We plan maintenance concepts and select certified installers, to guarantee the quality of installation and servicing.
Through our project-management expertise, we accompany implementation from detailed planning through tender and award to implementation support and acceptance. We ensure that all steps are documented and that the required proof is provided. Our aim is to relieve credit institutions of the burden of fulfilling the operator obligations, minimising risks, and at the same time optimising the efficiency and operational safety of their systems. Working with PLANATEL® allows management and the board to meet their responsibility with confidence and to concentrate on their core business, while the technical infrastructure remains legally compliant and future-proof.
Case study: optimising record-keeping at a mid-sized credit institution
A mid-sized credit institution faced the challenge that its record-keeping for technical systems, particularly the fire alarm systems (BMA), had grown historically and was fragmented. Inspection records were on paper, maintenance reports were spread across various departments, and training certificates for staff were not centralised. This led to uncertainty during audits and an increased risk in the event of a loss. Management recognised the urgent need for action and commissioned PLANATEL® with a comprehensive analysis and the development of an optimisation strategy.
Phase 1: as-is analysis and needs assessment. PLANATEL® began with a detailed as-is survey of all relevant technical systems, in particular the BMA, and checked the existing documentation for completeness and legal compliance. Gaps in record-keeping and deviations from standards such as DIN 14675 and VdS 2095 were identified. In parallel, interviews were conducted with the responsible staff, to understand the current processes and challenges. The needs analysis found that a central, digital system for documentation and a clearly defined responsibility concept were missing.
Phase 2: target concept and detailed planning. Based on the analysis, PLANATEL® developed a target concept providing for an integrated system to manage the operator obligations. This included introducing a digital platform for documenting all inspections, maintenance, and servicing. A concept for appointing and training a "responsible person for fire alarm systems" was drawn up and a training plan prepared. The detailed planning included defining interfaces to existing systems and preparing templates for inspection records and maintenance reports that complied with current standards.
Phase 3: implementation support and acceptance. PLANATEL® supported the credit institution in selecting a suitable software provider and accompanied the implementation of the digital documentation system. We prepared the tender documents for the required services (e.g. external maintenance of the BMA) and supported the award to certified specialist firms. Following implementation, a comprehensive acceptance was carried out, during which the functionality of the system and compliance with the new processes were checked. The result was transparent, legally compliant, and efficient record-keeping that sustainably relieved the credit institution and significantly minimised the risks.
Long-term benefits of a proactive operator-obligations strategy
A proactive and strategic approach to the operator obligations offers credit institutions far more than just avoiding sanctions. In the long term, considerable benefits arise that strengthen the institution's resilience, efficiency, and reputation. The most obvious benefit is sustainable risk minimisation. Through the systematic fulfilment of the operator obligations and complete record-keeping, liability risks, fines, and reputational damage are significantly reduced. Knowing that all relevant documents and proof can be presented at any time creates confidence for management and the board.
Second, an optimised operator-obligations strategy leads to increased operational safety and availability of the technical systems. Regular maintenance and inspections based on current standards prevent failures and disruptions, especially for critical systems such as fire alarm systems. This is essential for credit institutions, whose services are often classified as critical infrastructure and whose continuous availability is of great social importance. A study by FT Longitude, commissioned by SAS in July 2025, shows that 80 percent of German banks want to increase their investments in infrastructure, in order to address growing volatility and uncertainty in the market.
Third, digitalising record-keeping enables a considerable increase in efficiency and reduction in costs. Automated processes reduce the manual effort for documentation and administration. This frees up internal resources that can be used for higher-value tasks. In addition, predictive maintenance and optimised servicing concepts can avoid unnecessary repairs and emergency call-outs. Finally, a transparent and legally compliant operator-obligations strategy strengthens the confidence of customers, partners, and supervisory authorities. It signals a high degree of professionalism and a sense of responsibility, which sustainably enhances the credit institution's reputation in a positive way. Such a strategy is thus an investment in the future and the stability of the institution.

Next step
Contact us for a non-binding initial consultation.
PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de
Frequently asked questions
Which legal and normative bases are especially relevant for operator obligations at credit institutions?
For credit institutions, the Minimum Requirements for Risk Management (MaRisk) of BaFin, the Supervisory Requirements for IT in Financial Institutions (BAIT) or, since January 2025, the DORA regulation, as well as the Ordinance on Industrial Safety and Health (BetrSichV), are of central importance. Specifically for fire alarm systems, DIN 14675 and VdS 2095 are the decisive standards. These bodies of rules define the framework for the safe and legally compliant design of the technical infrastructure and risk management, with record-keeping playing a decisive role.
What is meant by the "responsible person for fire alarm systems", and what tasks does this person have?
The "responsible person for fire alarm systems" is a specialist trained and examined in accordance with DIN 14675-2, who is responsible within the credit institution for the proper operation of the BMA. Their duties include the regular, at least quarterly, walk-through of the monitored areas, operating the system, coordinating maintenance and servicing work, and keeping the operations log completely. This role is decisive for guaranteeing the functionality of the BMA and meeting the statutory proof obligations.
What risks arise for credit institutions from inadequate record-keeping of the operator obligations?
Inadequate record-keeping carries considerable risks for credit institutions. These include civil-law liability claims for personal injury or property damage, the refusal of insurance benefits in the event of a loss, significant fines from supervisory authorities, and massive reputational damage. Management and the board can be held personally responsible. Incomplete documentation also makes defence in legal disputes more difficult and can jeopardise operational safety.
How can PLANATEL® avoid manufacturer dependency when planning security systems?
PLANATEL® acts as an independent planning and consulting company and is financially separate from manufacturers and installers. We receive no commissions and are thus able to give objective, manufacturer-independent recommendations. Our expertise enables us to select the best solutions based on the specific requirements of the credit institution, without being tied to particular products or providers. This guarantees optimal, tailored, and future-proof systems.
To what extent are credit institutions, as critical infrastructure (KRITIS), affected by additional operator obligations?
As operators of critical infrastructure, credit institutions are subject to additional and stricter operator obligations that go beyond the general requirements. This includes the obligation to register, to conduct structured risk analyses (including of hybrid threats), and to develop resilience plans in accordance with the KRITIS umbrella act. BaFin and the BSI monitor compliance with these obligations, which aim to strengthen the physical and digital resilience of financial services and to guarantee security of supply.
What are the core obligations of a credit institution as an operator of technical systems?
The core obligations include guaranteeing safe operation, regular inspections and maintenance, preparing risk assessments, and complete documentation of all measures. This serves to protect people and assets and to comply with statutory regulations such as MaRisk, BAIT (DORA), and BetrSichV.
What role does DIN 14675 play for fire alarm systems at credit institutions?
DIN 14675 is a central standard for fire alarm systems (BMA) and governs their structure and operation. Among other things, it requires the appointment of a "responsible person for fire alarm systems", who has specific specialist knowledge and is responsible for the proper functioning and documentation of the BMA. Compliance is essential for legal compliance.
Why is digital record-keeping advantageous for credit institutions?
Digital record-keeping centralises all relevant documents, such as inspection records and maintenance reports, increases efficiency through automated processes, and improves tamper-resistance. It enables the fast and transparent provision of proof during audits and minimises the risk of liability claims through complete documentation.
How does PLANATEL® support credit institutions in fulfilling their operator obligations?
PLANATEL® offers manufacturer-independent planning and consulting for technical systems such as BMA, EMA, and video surveillance. We analyse as-is conditions, develop target concepts based on DIN and VdS standards, plan maintenance concepts, and support tendering, award, and implementation. Our aim is the legally compliant fulfilment of the obligations and the optimisation of record-keeping.
Sources and further information
- Bankaufsichtliche Auskünfte und Prüfungen • Definition, Gabler Banklexikon
- BaFin-Update kompakt: 8 neue Pflichten zum Geldwäschegesetz, S+P Compliance Advisor
- Bankzulassungsrecht, Teil 22, Pflichten der Kreditinstitut, brennecke-rechtsanwaelte.de
- Anzeige-, Mitteilungs- und Meldepflichten, BaFin
- Verordnung über die Prüfung der Jahresabschlüsse der Kreditinstitute und Finanzdienstleistungsinstitute sowie über die darüber zu erstellenden Berichte (Prüfungsberichtsverordnung, PrüfbV), Gesetze im Internet
