|
Minimum Requirements for Risk Management, MaRisk, Circular 06/2024BaFin
|
Credit and financial-services institutions within the circular’s scope |
Risk strategy, appetite, internal controls, risk controlling, compliance, internal audit, outsourcing, continuity and board reporting. |
|
Source
|
|
German Corporate Governance CodeGovernment Commission on the German Corporate Governance Code
|
German listed companies on an apply-and-explain basis |
Management and supervisory-board oversight, internal controls, risk management, audit committee responsibilities and transparent reporting. |
|
Source
|
|
Digital Operational Resilience ActEuropean Union and BaFin
|
Financial entities and ICT third-party providers within DORA’s scope |
ICT risk governance, incident classification and reporting, resilience testing, third-party risk, recovery and management-body oversight. |
|
Source
|
|
BSI Act and Critical-Infrastructure Incident ReportingBSI
|
Critical-infrastructure operators and other regulated organisations within national cybersecurity law |
State-of-the-art security, significant-incident notification, response coordination, evidence retention and resilience improvement. |
|
Source
|
|
General Data Protection RegulationBfDI and German state data-protection authorities
|
Controllers and processors handling personal data within the GDPR’s scope |
Accountability, security controls, processor oversight, breach assessment, 72-hour notification where required and corrective action. |
|
Source
|