Security Concepts & Threat Analyses17 min read
The Risk Assessment Obligation for Banks: Legally Compliant Protection and Risk Management
The risk assessment is not merely a legal obligation here, but a central instrument for minimising a wide range of risks, from physical security to cyber threats.
The risk assessment is a statutory obligation for banks in Germany, anchored in the Arbeitsschutzgesetz (Occupational Health and Safety Act) and DGUV Vorschrift 1. It serves to systematically identify, evaluate and minimise hazards to employees and assets, including specific risks such as robberies, IT security and fire hazards, and must be updated regularly and documented comprehensively.
Comprehensive analysis and strategic planning for financial institutions
The risk assessment is not merely a legal obligation here, but a central instrument for minimising a wide range of risks, from physical security to cyber threats.
Key Takeaways
- The risk assessment is a statutory obligation for banks under the Arbeitsschutzgesetz and DGUV Vorschrift 1, and must cover all physical and digital risks.
- Specific risks in banks, such as robberies, IT security and fire hazards in data centres, require tailored technical and organisational protective measures planned to DIN and VdS standards.
- Independent, professional planning of security systems by experts such as PLANATEL® ensures legal compliance, manufacturer-independence and long-term cost efficiency.
Financial institutions operate in an environment shaped by specific and multi-layered risks. From the physical threat of robbery to the constantly growing challenges of cybercrime, the security of employees, customers and sensitive data is a top priority. In this context, the risk assessment for banks is not only an indispensable measure but an explicit statutory obligation. It forms the foundation for robust risk management and legally compliant business organisation. Careful and continuous performance of this assessment is essential to avoid potential damage, ensure operational capability and secure the trust of all stakeholders.

The legal obligation to conduct a risk assessment in banks
The need for a risk assessment for banks is clearly established in law in Germany. The Arbeitsschutzgesetz (ArbSchG) forms the central basis here. Under Section 5 ArbSchG, every employer is obliged to determine, through an assessment of the hazards employees are exposed to in the course of their work, which occupational health and safety measures are required. This also includes banks and financial service providers. The measures derived from this must be checked for effectiveness and, where necessary, adapted to changing circumstances, in order to pursue continuous improvement in safety and health protection.
In addition to the ArbSchG, DGUV Vorschrift 1 "Grundsätze der Prävention" (principles of prevention) specifies the employer's obligations in more detail. Section 3 of this regulation likewise requires the identification of hazards and the initiation and implementation of the necessary measures. For credit institutions, sector-specific DGUV information is also relevant, such as DGUV Information 215-611 "Kredit- und Finanzdienstleistungsinstitute – Hinweise für die Erstellung einer Gefährdungsbeurteilung" and DGUV Information 215-612 "Kredit- und Finanzdienstleistungsinstituten – Anforderungen an die sicherheitstechnische Ausrüstung von Geschäftsstellen". These documents provide detailed guidance and example solutions for meeting the protection objectives of the DGUV regulations.
Responsibility for carrying out the risk assessment lies with the executive board or management. While they may formally appoint qualified persons to perform the tasks on their own responsibility, ultimate responsibility for organising occupational health and safety, selecting personnel and the duty of supervision remains with the employer. Complete documentation of the entire process is essential in order to demonstrate legally compliant fulfilment of these obligations and to avoid fines or claims for damages.
Specific hazards in the banking environment
Due to the nature of their business and the type of assets they manage, banks are exposed to unique hazards that go beyond the general risks of an office workplace. A comprehensive risk assessment must analyse these specific threats in detail. These include, first and foremost, physical hazards such as robberies, which can occur both during business hours (typical robberies) and outside them (atypical robberies). This affects not only the employees who directly handle cash, but also those present at the branch or carrying out cash transports.
Another critical area is the handling of cash and valuables. The DGUV information provides concrete guidance here on minimising the incentive for offenders, for example by limiting the amount of readily accessible cash and making access to it more difficult. This also concerns the loading and servicing of cash machines. In addition, IT security and cybercrime play an ever greater role. Banks manage highly sensitive customer data and substantial assets, which makes them attractive targets for cyberattacks. The risk assessment must therefore also cover risks such as data loss, fraud, sabotage and system failures caused by external or internal attacks.
Fire risks must not be neglected either, particularly in data centres, server rooms and other technical infrastructure, where expensive equipment and critical data are stored. A fire alarm system (BMA) is essential here. Access control to sensitive areas such as strongrooms, safe-deposit installations or server rooms also represents a particular hazard that must be secured through suitable technical and organisational measures. The assessment must also take into account psychological strain on employees, for example from the risk of robbery or high work demands.
The systematic risk assessment process: a structured approach
Carrying out a risk assessment is a structured process that should follow seven systematic steps in order to cover all relevant aspects and ensure legally compliant protection. This action cycle should not be understood as a one-off task, but as a continuous process that must be reviewed and adjusted regularly.
- Defining work areas and activities: First, all work areas, workplaces and the associated activities within the bank are recorded. This covers not only counter areas or offices, but also data centres, archive rooms, self-service zones, ATM areas and external cash transports. Every activity carried out by employees must be considered.
- Identifying hazards: In this step, all potential hazards are identified. These include physical hazards (e.g. robberies, falls), psychological strain (e.g. stress, violence), ergonomic risks, chemical, biological and electrical hazards, and, particularly relevant for banks, IT and cyber risks.
- Assessing the risks: The identified hazards are evaluated in terms of their probability of occurrence and the potential extent of harm. It is important here to draw not only on subjective judgement but also on specialist expertise and industry-standard findings.
- Defining measures: Based on the risk assessment, suitable protective measures are defined. The TOP principle applies: technical measures take priority over organisational measures, which in turn take priority over personal measures.
- Implementing the measures: The defined measures must be implemented promptly and consistently. This includes assigning responsibilities and setting clear deadlines.
- Checking effectiveness: After implementation, it must be checked whether the measures achieve the desired effect and whether the hazards have actually been minimised. Adjustments should be made where necessary.
- Documentation and continuation: The entire process – from identifying hazards to checking the effectiveness of measures – must be comprehensively documented. The risk assessment is a living document and must be updated regularly, at the latest when working conditions or statutory requirements change.

Integrating security systems as technical protective measures
The risk assessment in banks inevitably leads to the need to implement adequate technical security systems. These systems are not isolated components; they must be planned and evaluated as an integral part of a holistic security concept. PLANATEL® supports banks in the manufacturer-independent planning of this complex system technology, in order to optimally achieve the protection objectives derived from the risk assessment.
Central security systems include fire alarm systems (BMA), which must be planned and installed in accordance with DIN 14675, DIN VDE 0833-2 and VdS 2095. These systems serve for early fire detection and alerting, particularly in critical areas such as data centres and server rooms, where a fire could have devastating consequences for business operations. VdS 2095, a guideline issued by the Verband der Sachversicherer (association of property insurers), supplements the national standards with insurance-related requirements and is often contractually required to ensure a high level of operational reliability.
Intrusion detection systems (EMA) to DIN VDE 0833-3 are essential for detecting and reporting unauthorised entry. Video surveillance systems contribute to deterrence, investigation and evidence gathering, while access control systems regulate and log access to sensitive areas. These systems must be planned in accordance with DIN VDE 0833-1 (general provisions for hazard alarm systems) and other specific standards. Planning these systems requires in-depth expertise in the relevant standards and guidelines, as well as the ability to tailor them optimally to the specific hazards and architecture of the bank. PLANATEL® ensures that the planned systems not only meet current technical standards but also fully satisfy statutory and insurance-related requirements.
IT security and information risk management as an integral component
IT security is an indispensable pillar of the risk assessment for banks. BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht, the Federal Financial Supervisory Authority) has, with the Minimum Requirements for Risk Management (MaRisk) and the Supervisory Requirements for IT in Financial Institutions (BAIT), created a clear framework for information risk management and IT governance in financial institutions. These frameworks give concrete form to the statutory requirements of the Kreditwesengesetz (KWG, Banking Act) and ensure that banks secure their IT systems and processes robustly against cyber threats.
The BAIT describe in detail which technical and organisational resources BaFin considers suitable for IT systems, particularly with regard to information security and contingency plans. This covers aspects such as IT strategy, information risk management, information security management, identity and access rights management, and IT contingency management. The risk assessment must therefore include a comprehensive analysis of the IT infrastructure, data flows and potential attack vectors. Cyber risks such as phishing, ransomware, DDoS attacks or data leaks pose a significant threat to a bank's financial stability and reputation.
Integrating these aspects into the risk assessment means that not only physical but also digital workplaces and processes must be assessed for their security. This includes assessing software, hardware, networks and externally sourced IT services (outsourcing). BaFin places great importance here on complete documentation of all IT components, their dependencies and the security measures implemented. Robust IT risk management, establishing preventive measures and clear guidelines for minimising damage, is therefore a central component of a legally compliant risk assessment and of a bank's overarching risk management.
Common mistakes and pitfalls in implementation
Despite the clear statutory obligation and the obvious need for a risk assessment, typical mistakes that can undermine the effectiveness of the entire process occur time and again in practice. One of the most serious mistakes is **inadequate or entirely missing performance** of the risk assessment. Important areas are often left out, or office workplaces are categorically classified as "harmless" without taking the specific risks of the banking environment into account.
Another common mistake is **inadequate assessment of risks**. Hazards are recognised, but their potential impact or probability of occurrence is underestimated. This means that no or only inadequate protective measures are taken. A subjective risk assessment without drawing on external specialist expertise can lead to misjudgements here.
Often, **no suitable or inadequate measures** are defined either. An action plan may exist, but concrete responsibilities and deadlines for implementation are missing. This means that measures are not implemented, or only sluggishly. **Lack of monitoring of effectiveness** of the implemented measures is another problem. Without regular review, it cannot be established whether the measures achieve the desired protective effect or whether adjustments are needed.
**Inadequate updating and continuation** of the risk assessment is also a critical issue. A risk assessment is a dynamic process that must adapt to changing working conditions, new technologies or statutory requirements. An assessment created once and then archived quickly loses its relevance. Last but not least, **inadequate documentation** is a common shortcoming. Incomplete or incomprehensible documentation not only makes it harder to trace the process for internal reviews, but can also lead to legal problems in the event of a claim.
The benefits of professional, independent planning
Given the complexity and far-reaching legal implications of the risk assessment for banks, working with a professional and independent planning partner is of inestimable value. Such a partnership offers decisive advantages that go beyond mere fulfilment of statutory obligations and create sustainable added value for the financial institution.
One of the primary benefits is **significant risk reduction**. Independent experts bring an objective perspective and in-depth expertise in industry-specific hazards and proven protection concepts. They identify potential weaknesses that may be overlooked internally and develop tailored solutions that effectively reduce the risk of robbery, cyberattacks, fires or other security incidents. This leads to **legally compliant protection**, as the planning experts ensure that all relevant laws, regulations and standards – from the ArbSchG and DGUV regulations to BaFin requirements such as MaRisk and BAIT, as well as technical standards such as DIN 14675, DIN VDE 0833 and VdS 2095 – are fully taken into account.
**Manufacturer-independence** is another decisive advantage. An independent planner is not tied to particular products or providers and can therefore objectively select the best and most cost-efficient solutions, tailored precisely to the individual needs and existing infrastructure of the bank. This prevents dependency on a single manufacturer and optimises investment in security systems. Through precise needs analysis and target-concept design, **cost efficiency and optimised systems** are achieved. Planning errors, over-dimensioning or the implementation of unsuitable systems are avoided, leading to substantial savings in the long run. In addition, **long-term investment security** is ensured, as the planned systems are future-proof and can be flexibly adapted to new requirements. Professional planning thus creates not only security but also economic benefits, and strengthens trust in the institution.
PLANATEL®: your partner for legally compliant risk assessment and system planning
PLANATEL® has operated as an independent planning and consulting company since 1992 and has more than 34 years of experience in the design and optimisation of complex infrastructure for financial institutions and medium-sized to large enterprises. Our core approach is 100% manufacturer-independence and financial independence. We receive no commissions of any kind from manufacturers or installers, which means we act solely in our clients' interests and can always recommend the objectively best solutions.
In the context of the risk assessment for banks, PLANATEL® positions itself as your competent partner for the planning and design of the resulting technical and organisational measures. We do not create risk assessments in the occupational health and safety sense; rather, we take over where the need for specific security systems has been identified. Our range of services includes the detailed planning of fire alarm systems (BMA) to DIN 14675, DIN VDE 0833 and VdS 2095, intrusion detection systems (EMA), video surveillance systems, access control systems and security management systems. We analyse your as-is situation, carry out a comprehensive needs analysis and develop a target concept tailored precisely to your specific hazards and requirements.
Our expertise extends from detailed planning through to the tender and award of the systems. We support you in selecting certified installer companies and accompany implementation as well as the acceptance of the systems. Through our project management, we ensure that your security projects are delivered on schedule, within budget and to the highest quality. With PLANATEL®, you ensure that your technical security systems not only meet current standards and guidelines but are also optimally integrated into your overall risk management. We help you navigate the complexity of the requirements and establish a future-proof, legally compliant and efficient security infrastructure.

Next step
Contact us for a no-obligation initial consultation.
PLANATEL®: Independent planning and consulting since 1992
Tel: 040 / 23 73 02-30
Email: info@planatel.de
Frequently asked questions
What exactly is the difference between a general risk assessment and one for banks?
While a general risk assessment examines all workplaces and activities for general risks such as ergonomics, noise or psychological strain, the risk assessment for banks extends this focus to industry-specific hazards. These particularly include risks from robberies, handling large amounts of cash, securing strongrooms, and the complex IT security and data protection requirements under BaFin rules such as MaRisk and BAIT. These specific risks require adapted protection concepts and technical solutions.
How can a bank ensure its risk assessment meets BaFin's requirements?
To meet BaFin's requirements, the risk assessment in banks must comprehensively integrate the provisions of MaRisk (Minimum Requirements for Risk Management) and BAIT (Supervisory Requirements for IT in Financial Institutions). This means that information risk management, IT strategy, information security management and IT contingency management must be assessed and documented in detail. Complete recording of all IT components, their dependencies and the security measures implemented is crucial here. External specialist expertise can help ensure legally compliant implementation.
What consequences can a bank face for an inadequate risk assessment?
An inadequate risk assessment can have far-reaching consequences for banks. In addition to fines and possible claims for damages from supervisory authorities or insurers in the event of a claim, civil liability claims may also arise. More serious, however, are the potential harms to employees (physical and psychological), the loss of assets, data leaks, business interruptions and massive reputational damage. In the worst case, this can jeopardise the institution's business foundation.
Why is documenting the risk assessment so important?
Documenting the risk assessment is crucial for several reasons. First, it is a statutory obligation under Section 6 ArbSchG and serves as evidence to supervisory authorities and insurers that the employer has fulfilled its obligations. Second, it enables traceability of the entire process, from hazard identification through to checking the effectiveness of measures. Third, it serves as the basis for regularly updating and continuing the assessment, and fosters a culture of continuous improvement within the company.
Can external service providers help with preparing the risk assessment?
Yes, external service providers can provide significant support to banks in preparing and implementing the risk assessment. They bring specialised expertise, an objective outside perspective, and experience with industry-specific requirements and best practices. While overall responsibility remains with the executive board or management, external experts can provide valuable support in identifying and assessing hazards, deriving measures and, in particular, in the manufacturer-independent planning of complex security systems.
How does PLANATEL® support banks in implementing the risk assessment?
PLANATEL® supports banks as an independent planning and consulting service provider in the design and optimisation of the technical security systems resulting from the risk assessment. We offer manufacturer-independent planning of fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance and access control. Our service covers as-is analysis, needs analysis, target-concept design, detailed planning, tendering, award and project management, to ensure that the implemented systems are legally compliant, efficient and future-proof. We do not carry out risk assessments ourselves, but translate the resulting requirements into planning.
Is the risk assessment a statutory requirement for banks?
Yes, the risk assessment is a statutory requirement for banks in Germany. The obligation arises primarily from the Arbeitsschutzgesetz (Sections 3, 5 ArbSchG) and is given concrete form by DGUV Vorschrift 1 "Grundsätze der Prävention" as well as sector-specific DGUV information. It serves to protect employees from all hazards associated with their work.
What specific risks must banks take into account in the risk assessment?
In addition to general workplace risks, banks must take into account specific hazards such as robberies (typical and atypical), the handling of cash and valuables, IT security risks (cybercrime, data loss), data protection breaches, fire hazards in technical infrastructure (e.g. data centres) and risks relating to access control systems. Psychological strain on employees must also be assessed.
How often must a risk assessment be updated in a bank?
A risk assessment is a continuous process and must be reviewed and updated regularly. This is particularly necessary when working conditions change, new technologies or work procedures are introduced, after accidents or near-misses, and when new statutory or normative requirements arise. An annual review cycle is a proven method of keeping it up to date.
What role do security systems play in a bank's risk assessment?
These include fire alarm systems (BMA), intrusion detection systems (EMA), video surveillance and access control systems. They serve to prevent, detect and respond to hazards and must be planned and implemented in accordance with relevant standards such as DIN 14675, DIN VDE 0833 and VdS 2095, to ensure the safety of people and assets.
Sources and further information
- DGUV Information 215-611 "Kredit- und Finanzdienstleistungsinstitute – Hinweise für die Erstellung einer Gefährdungsbeurteilung zur Umsetzung der DGUV Vorschrift "Kassen" i. V. m. §§ 5 und 6 Arbeitsschutzgesetz"
- Kreditinstitute – VBG
- Handlungshilfen für die Gefährdungsbeurteilung – DGUV Information 215-611 "Kredit- und Finanzdienstleistungsinstitute" – Bundesanstalt für Arbeitsschutz und Arbeitsmedizin – BAuA
- Seminar: Prävention von Raubüberfällen: Beurteilung der Gefährdung in Kreditinstituten | VBG
- Ist die Gefährdungsbeurteilung Pflicht? Alle Infos – CALIMA
