Blog Practical guides for regulated institutions
We write when something changes for regulated institutions.
NIS2 implementation, GwG interpretation, new sanctions regimes, EU data sovereignty — assessing, not alarmist.
KRITIS & Public Sector
Reliability Screening in KRITIS: The Implementation Guide
Personnel security under the KRITIS-DachG and Art. 14 CER Directive: how operators implement background checks in a risk-based, audit-proof way.
KRITIS & Public Sector
KRITIS-Dachgesetz 2026: Obligations, Deadlines and Sectors
KRITIS-Dachgesetz 2026 in force: sectors, obligations and deadlines at a glance — and what applies if the 17 July 2026 registration deadline was missed.
Compliance
Sanctions screening: EU vs OFAC vs UN lists explained
Understand the differences between EU, OFAC, and UN sanctions lists, when each applies, and how to build a defensible screening process for KYC/AML compliance.
Banking & Insurance
Employee Reliability Screening Under § 6 GwG
What § 6 (2) no. 5 GwG requires of banks and insurers: the statutory definition of reliability, screening triggers and typical implementation gaps.
KRITIS & Public Sector
State Security Clearance vs. Employer Screening: Who Checks What?
Security clearance vs. own screening: what SÜG, LuftSiG and AtZüV cover — and what employers must check themselves under KRITIS-DachG and BSIG.
Legal & Fundamentals
Führungszeugnis vs. Background Check: The Limits of the Register
A clean Führungszeugnis is no proof of integrity: which entries are missing under the BZRG and when a structured background check closes the gap.
KRITIS & Public Sector
SÜG Amendment 2026: What Changes for Ü1, Ü2 and Ü3
SÜG amendment in force since 16 Jan 2026: changes to Ü1, Ü2 and Ü3, mandatory internet research even at Ü1 — and the consequences for companies.
KRITIS & Public Sector
NIS2 Personnel Security: The Duties Under § 30 BSIG
§ 30 BSIG demands personnel security and access control: what NIS2 entities must implement now and why § 38 BSIG targets senior management.
Legal & Fundamentals
Pre-Employment Screening: GDPR Legal Basis After the CJEU Ruling
After CJEU C-34/21, § 26 BDSG alone no longer carries screening: how to map screening categories to Art. 6 GDPR — with checklist and balancing test.
Banking & Insurance
Fit and Proper at BaFin: Documenting Reliability Properly
BaFin's fit-and-proper assessment: what §§ 25c, 25d and 24 KWG require of executive directors and supervisory boards, and how to prepare the notification.
Banking & Insurance
Background Check Providers: Why Software Alone Is Not Enough
Why software alone is not enough for fit-and-proper and reliability decisions: the hybrid approach for decisions you can defend.
Legal & Fundamentals
Continuous Compliance Monitoring or One-Time Check?
One-time check or continuous monitoring? When the point-in-time check is no longer enough: GwG duties, GDPR limits and a decision matrix.
Legal & Fundamentals
Screening Interim Managers and External Contractors: Closing the Gap
Interim managers and external providers slip through every screening grid: GDPR legal bases, DORA duties and a screening framework for externals.
Legal & Fundamentals
Social Media Screening of Applicants: What Is Permitted?
Social media screening of applicants: permitted on LinkedIn and Xing, off-limits for private profiles. Legal framework, DSK line and information duties.
Legal & Fundamentals
Works Council and Background Checks: Involving Co-determination
Works council and background checks: classify §§ 94, 95, 87 BetrVG and use co-determination as an opportunity — with key points for the works agreement.
Legal & Fundamentals
Background Checks in Switzerland: Art. 328b OR and the revFADP
Background checks in Switzerland: what Art. 328b OR and the revFADP permit, which limits apply and what a lawful, tiered screening depth looks like.
Legal & Fundamentals
LkSG 2026 and CSDDD: What Now Applies to Supplier Screening
LkSG amendment and postponed CSDDD: why the due-diligence duties persist and what really applies to your supplier due diligence in 2026.
Legal & Fundamentals
CV Fraud: The Numbers and the Cost of a Bad Hire
How often people lie on their CVs, what a bad hire really costs and why pre-hire verification is a business case.
Legal & Fundamentals
Employer Questions and the German ‘Right to Lie’
Applicants may lie to inadmissible questions without consequence: what employers may ask in Germany and how to screen lawfully instead.
KRITIS & Public Sector
Industrial Security: The Security Officer’s Duties Under SÜG and GHB
The security officer’s duties under SÜG, GHB and VSA — and why pre-selection before the clearance request rests with the company.
KRITIS & Public Sector
Employee Screening for Critical Infrastructure: A Decision Guide
KRITIS operators in energy, water and health: which role needs which screening depth — state-run, internal or software report. A decision guide.
KRITIS & Public Sector
AtZüV: The Nuclear Reliability Check Under § 12b AtG Explained
AtZüV in brief: Who is vetted under § 12b AtG in decommissioning, interim storage and transport — and which questions remain open for employers and contractors.
KRITIS & Public Sector
Personnel Security Screening in Switzerland: PSP Under ISG and PSPV
Personnel security screening under ISG and PSPV: screening levels, consent — and why private employers without a federal nexus need their own screening.
Banking & Insurance
Background Check Software for Banks: Requirements Catalogue
Requirements catalogue for background check software in banks: review categories, DACH sources, data protection concept and audit-proof documentation.
KRITIS & Public Sector
ZÜP under § 7 LuftSiG: What the Check Does Not Cover
What the ZÜP under § 7 LuftSiG checks — and what it does not: CV claims, foreign offences and ongoing conduct remain the employer's task. An overview.
Banking & Insurance
The AML Officer: Setting Up Employee Screening Operationally
How the anti-money laundering officer sets up employee screening under § 6 (2) no. 5 GwG: risk classes, review cycles and audit-proof documentation.
Banking & Insurance
§ 24 VAG: Assessing Reliability at Insurers Correctly
§ 24 VAG: who is vetted for reliability at insurers, which GwG duties apply to life insurers and how the two regimes fit together.
Banking & Insurance
DORA Requirements for Personnel and ICT Service Providers
What Regulation (EU) 2022/2554 requires for training, due diligence and contracts with third-party ICT providers — an overview.
Banking & Insurance
Pre-Employment Screening in Banks: What § 26 BDSG Permits
What § 26 BDSG permits in pre-employment screening at banks: lawful sources, proportionality by position, and the limits set by data protection law.
Banking & Insurance
Insider Risk in Banks: Why Internal Perpetrators Operate Differently
Internal perpetrators exploit legitimate access and system knowledge. Which safeguards § 25h KWG, § 6 GwG and MaRisk AT 7.1 require of banks.
Banking & Insurance
Know Your Employee: The Blind Spot in Anti-Money-Laundering
KYC is standard, Know Your Employee often is not: why employee vetting under § 6(2) no. 5 GwG ranks equally and how to implement it.
Executive Search
Backdoor hires: the hidden cost of executive search
When executive search skips structured background checks, the real cost shows up months later — in reputation damage, regulatory exposure, and board-level crises that a structured check from €79 can surface in time.
Compliance Operations
Adverse media screening: a practical guide for regulated firms
What adverse media screening actually is, how it fits into your compliance framework, and why automated screening without human assessment creates more risk than it removes.
KYC & Compliance
What is a background check and why it matters for KYC compliance
A practical breakdown of what background checks actually cover, how they differ from simple database lookups, and why they're essential for meeting KYC obligations under the GwG and EU AML directives.