Drei Personen an einem Tisch, auf dem Tablet und Diagramme liegen
Blog Article

MaRisk Compliance in Practice: How Segregation of Duties Reduces Risk

Last updated on 7 min read
Franziska Weiß
Franziska Weiß
Product Evangelist
Follow me for more content

Regulatory requirements, complex IT landscapes, and growing access structures make Segregation of Duties (SoD) an ongoing challenge for financial institutions. Who is authorized to initiate a transaction? Who approves it? And how can organizations reliably prevent conflicting access rights from being assigned to the same person?

The German Federal Financial Supervisory Authority’s Minimum Requirements for Risk Management (MaRisk) provide a binding framework for addressing these questions. The 9th amendment to MaRisk has been in effect since June 30, 2026. Segregation of Duties remains a key principle of an appropriate organizational and operational structure. This article explains what this means for financial institutions and how clear roles, transparent access rights, and automated controls can help support effective Segregation of Duties.

Key Takeaways

  • MaRisk requires incompatible activities to be performed by different employees. Segregation of Duties is therefore an important component of the internal control system.

  • Access rights and authorities must be clearly defined and traceable, assigned according to the Need-to-Know Principle, and adjusted as required.

  • DORA has applied directly since January 17, 2025. For institutions within its scope, this has also changed the interaction between MaRisk, BAIT, and European ICT requirements.

  • Transparent role models, an SoD matrix, and regular recertification can help systematically identify and prevent conflicting access rights.

  • IAM and IGA solutions can automate and document access management processes, helping organizations meet regulatory requirements.

Find out more

Definition: What Is MaRisk?

The Minimum Requirements for Risk Management (MaRisk) are the central regulatory framework issued by BaFin, the German Federal Financial Supervisory Authority, for banks and financial services institutions in Germany. They specify the requirements of Section 25a of the German Banking Act (Kreditwesengesetz – KWG) and provide a flexible, practical framework for risk management.

The currently applicable version was published on June 30, 2026, and represents the 9th amendment to MaRisk.

The Objectives of MaRisk

  • Protecting customers’ assets and interests

  • Ensuring the institution’s risk-bearing capacity

  • Preventing conflicts of interest and compliance violations

  • Strengthening internal control systems and governance structures

Segregation of Duties as a Core MaRisk Requirement

Segregation of Duties is a central element of the internal control system and is explicitly required under MaRisk. It ensures that incompatible activities – such as initiating and reviewing transactions – are consistently separated and performed by different individuals.

Specifically, AT 4.3.1 requires incompatible activities to be performed by different employees and conflicts of interest to be avoided, including when employees change positions. Processes and their associated tasks, authorities, responsibilities, controls, and communication channels must be clearly defined and coordinated.

For access rights management, AT 4.3.1 No. 2 is particularly relevant: Access rights and authorities must be granted according to the Principle of Least Privilege, or Need-to-Know Principle, and adjusted promptly when required. This also includes regular and event-driven reviews of IT access rights and other granted privileges.

Goals of Segregation of Duties

  • Clear assignment of tasks, authorities, and controls

  • Prevention of conflicts of interest

  • Reduction of error and fraud risks

  • Traceable controls for regulators and auditors

Typical Examples

Business Area

SoD Required Between

Objective

Credit Business

Front office and back office/review functions

Independent credit decisions

Trading

Trading and risk control/settlement

Separation of execution from downstream control functions

IT and Access Rights

Provisioning, control, and recertification

Prevention of conflicts of interest and prohibited access combinations

For identity management, Segregation of Duties therefore goes beyond the four-eyes principle for an individual transaction. What also matters is the overall combination of roles and access rights assigned to a person. Two access rights may each be necessary on their own – but their combination can result in a violation of the SoD guidelines.

MaRisk and DORA in 2026: What Financial Institutions Need to Know

The EU’s Digital Operational Resilience Act (DORA) has applied since January 17, 2025. It establishes a European framework for digital operational resilience in the financial sector and covers areas including ICT risk management, ICT-related incidents, digital operational resilience testing, and risks associated with third-party ICT service providers.

This has also changed the interaction with national IT regulations. Financial entities required to maintain an ICT risk management framework under Articles 5 to 15 or Article 16 (DORA) were removed from the scope of BAIT (Supervisory Requirements for IT in Financial Institutions) as of January 17, 2025. BAIT will be fully phased out by the end of 2026.

For financial institutions, this means that when designing governance structures and access management processes, they need to determine which regulatory requirements specifically apply to them. MaRisk and DORA address different, but in some cases interconnected, areas.

Organizational Segregation of Duties remains explicitly embedded in MaRisk. DORA complements the regulatory framework with requirements relating to digital operational resilience.

Implementing Segregation of Duties in Identity Management

Consider a practical example: A mid-sized financial institution needs to implement the MaRisk requirements for Segregation of Duties within its IT environment. Its existing manual approach to documentation and access management is prone to errors and consumes valuable resources.

A structured approach can address several levels:

  • Clearly define roles and responsibilities

  • Map conflicting roles and access rights in an SoD matrix

  • Manage access requests and approvals through traceable workflows

  • Regularly recertify access rights

  • Document SoD conflicts and related decisions in a traceable manner

  • Integrate relevant target systems into centralized access management

An identity management system like Garancy can provide the technical foundation for these processes. However, the business rules governing Segregation of Duties are determined by the organization, its processes, and the requirements applicable to it. The software helps consistently implement these rules across roles, access rights, and systems.

Using an SoD Matrix to Identify Conflicting Access Rights

A Segregation of Duties (SoD) matrix defines which roles or access rights should not be combined. For example, an organization can specify that certain operational and control-related access rights must not be assigned to the same identity.

As the number of identities, roles, applications, and access rights increases, it becomes increasingly difficult to keep track of such combinations manually. An SoD matrix can help systematically identify predefined conflicts and make access decisions more transparent and traceable.

Recertification: Regularly Reviewing Access Rights

A user permission may be necessary initially, but become unnecessary later on. Employees change roles, responsibilities evolve, and projects come to an end. For this reason, MaRisk requires both event-driven and regular reviews of access rights and permissions.

Automated recertification campaigns can help business units regularly review existing access rights and identify access that is no longer required. SoD checks and recertification serve different purposes: An SoD logic evaluates predefined conflicts between roles or access rights, while recertification determines whether existing access rights are still required.

Challenges and Best Practices in MaRisk Compliance

Typical Challenges

  • Complex processes and heterogeneous system landscapes

  • Extensive manual documentation

  • Lack of transparency across roles and access rights

  • Historically grown role models and exception rules

  • Changes resulting from employee onboarding, internal transfers, and offboarding

  • Resistance to organizational change

Best Practices for Effective Segregation of Duties

  1. Define business rules before technical implementation

    Before implementing technical rules, organizations should determine which activities, roles, or access rights are actually incompatible within their specific environment. The SoD matrix can then translate these business requirements into technical rules.

  2. Create transparency across roles and access rights

    The more access rights are managed across distributed systems and business units, the more difficult it becomes to assess critical combinations. A centralized role and access model provides a common foundation.

  3. Automate recurring processes

    Workflows, SoD checks, and recertification campaigns can reduce recurring manual tasks while creating a traceable record of decisions. Business responsibility for access rights and Segregation of Duties remains with the relevant individuals and organizational units.

  4. Manage exceptions transparently

    Not every organization can completely separate every function. What matters is a risk-based assessment, appropriate compensating controls, and traceable documentation. In their implementation, MaRisk generally take into account the nature, scope, complexity, and risk profile of an institution’s business activities.

  5. Treat Segregation of Duties as an ongoing process

    Roles, responsibilities, applications, and business processes change over time. Segregation of Duties is therefore not a one-time configuration task. Role models, SoD rules, and existing access rights should be reviewed regularly or in response to specific events, in accordance with applicable requirements.

Segregation of Duties: Combining Compliance, Security, and Efficiency

MaRisk compliance through effective Segregation of Duties is not just a regulatory requirement – it’s a strategic enabler. It minimizes risk, strengthens compliance, and optimizes processes. In times of digital transformation and skill shortages, automated IGA and IAM solutions offer the opportunity to reduce costs while meeting supervisory requirements efficiently and sustainably.


Questions About Identity Management and Segregation of Duties?

In practice, user role models, recertification, and Segregation of Duties can quickly raise specific questions. Our IAM experts can help you assess your requirements and determine how the right processes can be implemented across your IT landscape.

Book a meeting

Let’s Talk Business!

Are you facing challenges in cyber security, automation, or compliance? In a compact strategy meeting, we will clarify which IAM approaches make sense for your company.

What you can expect:

  • Discussion of your individual requirements

  • Practical insights into our identity management software

  • Q&A and recommendations for the next steps

Garancy – more than 6.16 million managed identities worldwide
A man in a white shirt, holding a yellow folder, smiles while speaking into a smartphone, standing beside a window with soft light.