Business continuity management in banks
Business continuity management (BCM) is how a bank keeps its critical functions running through an IT outage, a cyberattack or a fire, and how it restores them afterward. In Germany the rules come from MaRisk AT 7.3 for the bank as a whole and from DORA for ICT. Section 25a of the German Banking Act lists emergency management for IT systems as part of a proper business organization.
MaRisk AT 7.3: the emergency concept
MaRisk AT 7.3 asks for an emergency concept for all activities and processes that are critical or important functions. The concept contains business continuity and recovery plans based on plausible scenarios, names responsibilities, targets and measures, and sets the criteria for triggering a plan. The bank updates it every year and after relevant events, and the management board gets a written report on the state of emergency management at least once a quarter.
The concept rests on business impact analyses over a list of all functions. When a critical or important function is outsourced, the bank and the service provider need emergency concepts that fit together. The bank tests the concept regularly, every year for critical or important functions, records the tests and reports the results in writing to those responsible. The text in force since June 30, 2026 is on the BaFin website (in German).
DORA: ICT business continuity
For ICT, the Digital Operational Resilience Act sets the rules. Article 11 asks for an ICT business continuity policy and a business impact analysis of exposures to severe business disruptions. Plans are tested at least once a year and after substantive changes to the ICT systems that support critical or important functions. Except at microenterprises, the tests include cyberattack scenarios and switchovers between the primary ICT infrastructure and the redundant capacity.
Banks also need a crisis management function with procedures for internal and external crisis communication, and on request they give the supervisor an estimate of the aggregated annual costs and losses from major ICT-related incidents. Article 12 covers backups: a documented backup policy, restoration on systems physically and logically segregated from the source system, and recovery time and recovery point objectives for each function. The regulation as a whole is covered on DORA in the EU.
Upcoming events on risk and compliance
What is the difference between operational resilience and business continuity?
Business continuity management plans for the failure of specific processes, systems or sites and for their recovery. Operational resilience is the wider goal: the bank keeps delivering its critical services within a tolerance for disruption, whatever the cause. The Basel Committee's principles for operational resilience of March 31, 2021 count business continuity planning and testing as one of their parts.
What is a business impact analysis in a bank?
A business impact analysis looks at what happens when an activity or process fails, over graded periods of time. MaRisk asks it to consider the type and size of the tangible and intangible damage and the point in time of the failure. The result decides which functions come back first and how long an outage may last, and it feeds the recovery time objectives under DORA.
How often do banks test their business continuity plans?
At least once a year for critical or important functions, under MaRisk AT 7.3 and DORA Article 11 alike, and again after substantive changes to the ICT systems behind them. MaRisk adds that frequency and scope follow the threat level and that service providers take part. Advanced testing of live systems falls under threat-led penetration testing.
Business continuity and Finance Loop
Finance Loop is the meeting place for the people who run business continuity, IT risk and DORA programs at German banks. Finance Loop announced KI Exchange 2026 in Hamburg, a conference whose program listed DORA compliance, and its DORA training page sets out what the regulation asks of staff and management.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.