Skip to main content
MaRisk & BAIT — German financial-supervision requirements

Hand the auditor a hash-verified log and a structured Berechtigungskonzept — not a screenshot folder.

TENSOR produces the audit evidence BaFin-supervised entities need — extended retention, role/permission exports, enforced segregation of duties, and information classification — from the same ITSM records your team works daily.

What the regulation requires → what TENSOR produces

Evidence a BaFin audit asks for — exported, not assembled.

MaRisk
AT 4.3.4 — Extended audit retention

Seven years by default, extended to ten when the MaRisk toggle is on. Audit entries are append-only — UPDATE and DELETE are revoked at the database role — and hash-chained per tenant, giving external auditors a tamper-evident record.

BAIT
BAIT 5 — Berechtigungskonzept export (PDF + JSON)

Export the full role and permission model — who can do what, in which module, with which segregation constraints — as a structured Berechtigungskonzept per BAIT 5.

BAIT
BAIT 5 — Segregation of duties (SoD)

Enforced in code, not just policy: developer ≠ approver ≠ basis admin. SoD constraints apply to change approvals, CAB membership, and transport promotion in SAP workflows. Granting a sensitive role — auditor or external auditor — itself takes a second approver.

BAIT
BAIT 8 — Information classification (IDV)

CIs carry an information-classification level and an IDV (individuelle Datenverarbeitung) flag. Classification drives visibility rules and audit depth per BAIT requirements.

MaRisk
AT 7.2 — Change governance

CAB workflow with approval chains, test evidence, rollback documentation, and full traceability from request through implementation — the audit trail MaRisk expects.

Common questions

MaRisk / BAIT FAQ

Informational only — not legal advice. Consult qualified counsel for regulatory obligations specific to your organization.

See the Berechtigungskonzept export from a live tenant.

30 minutes. We'll walk through SoD constraints, audit retention, and the permission model.