Hochleistungs-KI als IKT-Risikotreiber unter DORA
Read More

Frontier AI as an ICT Risk Driver under DORA

Frontier AI is changing the cyber risk landscape for financial entities – and with it the requirements for appropriate ICT risk management under DORA. A new statement by the European Supervisory Authorities explains how existing DORA requirements should be applied in light of faster, more scalable and more complex AI-enabled attacks. This article examines the supervisory expectations and identifies where financial entities should review their existing processes and controls.
Read More
Virtuelle IBANs im Visier Was die neue Bafin-Aufsichtsmitteilung für Banken und Zahlungsdienstleister bedeutet Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers
Read More

Virtual IBANs under BaFin scrutiny: New AML expectations for banks and payment service providers

Virtual IBANs have become an established component of modern payment models. With Supervisory Notice 06/2026, BaFin now clarifies its expectations for credit institutions and payment service providers regarding transparency, anti-money laundering compliance and risk management in complex virtual IBAN structures.
Read More
Datenschutz im Zahlungsverkehr – Rechtliche Grundlagen und Besonderheiten Data Protection in Payment Services – Legal Framework and Key Particularities
Read More

Data Protection in Payment Services – Legal Framework and Key Particularities

Data protection in payment services operates within the complex interplay of the GDPR, PSD2 and the German ZAG. A key challenge lies in the legal classification of payment data, as transaction data may reveal highly sensitive insights into individuals’ private lives. This article analyses the principal legal bases for data processing as well as the allocation of data protection responsibilities among payment service providers, PISPs and AISPs.
Read More
KI-Regulierung in der Praxis: Was die Aufsicht zu KI im Finanzsektor wirklich sehen will | ALLES LEGAL #126 AI Regulation in Practice
Read More

AI Regulation in Practice: What Supervisors Really Expect to See from AI in the Financial Sector | ALLES LEGAL #126

Annerton partner Josefine Spengler explains how supervisory authorities assess AI systems in the financial sector in practice. AI is not treated as a regulatory special case but as an ICT system embedded within existing frameworks, particularly DORA. The focus lies on governance, accountability, traceability and ongoing monitoring. The interaction between DORA and the EU AI Act adds further complexity. The key takeaway: AI is not merely an IT issue – it is a management responsibility.
Read More
Von Outsourcing zu Third Party Arrangements: Die neuen EBA-Leitlinien zum Drittparteienmanagement • Teil 1: Überblick über die wichtigsten Neuerungen
Read More

From Outsourcing to Third Party Arrangements: The New EBA Guidelines on Third-Party Risk Management 1/2

On 8 July 2025, the European Banking Authority (EBA) published a new consultation paper on the EBA Guidelines for third-party risk management. The draft goes well beyond the previous Outsourcing Guidelines from 2019. The objective is to establish a harmonised European framework for managing third-party risks, aligned in particular with the Digital Operational Resilience Act (DORA). Part 1 of the analysis highlights the key innovations and main content; a practical assessment will follow in Part 2.
Read More