Definition: What Is MaRisk?
The Minimum Requirements for Risk Management (MaRisk) are the central regulatory framework issued by BaFin, the German Federal Financial Supervisory Authority, for banks and financial services institutions in Germany. They specify the requirements of Section 25a of the German Banking Act (Kreditwesengesetz – KWG) and provide a flexible, practical framework for risk management.
The currently applicable version was published on June 30, 2026, and represents the 9th amendment to MaRisk.
The Objectives of MaRisk
Protecting customers’ assets and interests
Ensuring the institution’s risk-bearing capacity
Preventing conflicts of interest and compliance violations
Strengthening internal control systems and governance structures
Segregation of Duties as a Core MaRisk Requirement
Segregation of Duties is a central element of the internal control system and is explicitly required under MaRisk. It ensures that incompatible activities – such as initiating and reviewing transactions – are consistently separated and performed by different individuals.
Specifically, AT 4.3.1 requires incompatible activities to be performed by different employees and conflicts of interest to be avoided, including when employees change positions. Processes and their associated tasks, authorities, responsibilities, controls, and communication channels must be clearly defined and coordinated.
For access rights management, AT 4.3.1 No. 2 is particularly relevant: Access rights and authorities must be granted according to the Principle of Least Privilege, or Need-to-Know Principle, and adjusted promptly when required. This also includes regular and event-driven reviews of IT access rights and other granted privileges.
Goals of Segregation of Duties
Clear assignment of tasks, authorities, and controls
Prevention of conflicts of interest
Reduction of error and fraud risks
Traceable controls for regulators and auditors
Typical Examples
Business Area | SoD Required Between | Objective |
|---|---|---|
Credit Business | Front office and back office/review functions | Independent credit decisions |
Trading | Trading and risk control/settlement | Separation of execution from downstream control functions |
IT and Access Rights | Provisioning, control, and recertification | Prevention of conflicts of interest and prohibited access combinations |
For identity management, Segregation of Duties therefore goes beyond the four-eyes principle for an individual transaction. What also matters is the overall combination of roles and access rights assigned to a person. Two access rights may each be necessary on their own – but their combination can result in a violation of the SoD guidelines.
MaRisk and DORA in 2026: What Financial Institutions Need to Know
The EU’s Digital Operational Resilience Act (DORA) has applied since January 17, 2025. It establishes a European framework for digital operational resilience in the financial sector and covers areas including ICT risk management, ICT-related incidents, digital operational resilience testing, and risks associated with third-party ICT service providers.
This has also changed the interaction with national IT regulations. Financial entities required to maintain an ICT risk management framework under Articles 5 to 15 or Article 16 (DORA) were removed from the scope of BAIT (Supervisory Requirements for IT in Financial Institutions) as of January 17, 2025. BAIT will be fully phased out by the end of 2026.
For financial institutions, this means that when designing governance structures and access management processes, they need to determine which regulatory requirements specifically apply to them. MaRisk and DORA address different, but in some cases interconnected, areas.
Organizational Segregation of Duties remains explicitly embedded in MaRisk. DORA complements the regulatory framework with requirements relating to digital operational resilience.
Implementing Segregation of Duties in Identity Management
Consider a practical example: A mid-sized financial institution needs to implement the MaRisk requirements for Segregation of Duties within its IT environment. Its existing manual approach to documentation and access management is prone to errors and consumes valuable resources.
A structured approach can address several levels:
Clearly define roles and responsibilities
Map conflicting roles and access rights in an SoD matrix
Manage access requests and approvals through traceable workflows
Regularly recertify access rights
Document SoD conflicts and related decisions in a traceable manner
Integrate relevant target systems into centralized access management
An identity management system like Garancy can provide the technical foundation for these processes. However, the business rules governing Segregation of Duties are determined by the organization, its processes, and the requirements applicable to it. The software helps consistently implement these rules across roles, access rights, and systems.
Using an SoD Matrix to Identify Conflicting Access Rights
A Segregation of Duties (SoD) matrix defines which roles or access rights should not be combined. For example, an organization can specify that certain operational and control-related access rights must not be assigned to the same identity.
As the number of identities, roles, applications, and access rights increases, it becomes increasingly difficult to keep track of such combinations manually. An SoD matrix can help systematically identify predefined conflicts and make access decisions more transparent and traceable.
Recertification: Regularly Reviewing Access Rights
A user permission may be necessary initially, but become unnecessary later on. Employees change roles, responsibilities evolve, and projects come to an end. For this reason, MaRisk requires both event-driven and regular reviews of access rights and permissions.
Automated recertification campaigns can help business units regularly review existing access rights and identify access that is no longer required. SoD checks and recertification serve different purposes: An SoD logic evaluates predefined conflicts between roles or access rights, while recertification determines whether existing access rights are still required.
Challenges and Best Practices in MaRisk Compliance
Typical Challenges
Complex processes and heterogeneous system landscapes
Extensive manual documentation
Lack of transparency across roles and access rights
Historically grown role models and exception rules
Changes resulting from employee onboarding, internal transfers, and offboarding
Resistance to organizational change
Best Practices for Effective Segregation of Duties
Define business rules before technical implementation
Before implementing technical rules, organizations should determine which activities, roles, or access rights are actually incompatible within their specific environment. The SoD matrix can then translate these business requirements into technical rules.
Create transparency across roles and access rights
The more access rights are managed across distributed systems and business units, the more difficult it becomes to assess critical combinations. A centralized role and access model provides a common foundation.
Automate recurring processes
Workflows, SoD checks, and recertification campaigns can reduce recurring manual tasks while creating a traceable record of decisions. Business responsibility for access rights and Segregation of Duties remains with the relevant individuals and organizational units.
Manage exceptions transparently
Not every organization can completely separate every function. What matters is a risk-based assessment, appropriate compensating controls, and traceable documentation. In their implementation, MaRisk generally take into account the nature, scope, complexity, and risk profile of an institution’s business activities.
Treat Segregation of Duties as an ongoing process
Roles, responsibilities, applications, and business processes change over time. Segregation of Duties is therefore not a one-time configuration task. Role models, SoD rules, and existing access rights should be reviewed regularly or in response to specific events, in accordance with applicable requirements.
Segregation of Duties: Combining Compliance, Security, and Efficiency
MaRisk compliance through effective Segregation of Duties is not just a regulatory requirement – it’s a strategic enabler. It minimizes risk, strengthens compliance, and optimizes processes. In times of digital transformation and skill shortages, automated IGA and IAM solutions offer the opportunity to reduce costs while meeting supervisory requirements efficiently and sustainably.
Questions About Identity Management and Segregation of Duties?
In practice, user role models, recertification, and Segregation of Duties can quickly raise specific questions. Our IAM experts can help you assess your requirements and determine how the right processes can be implemented across your IT landscape.
:quality(100))
:quality(100))
:quality(100))
:quality(100))
:quality(100))
:quality(80))