RegulationFirst version: Updated:
NIS2 vs DORA: what applies to banks and their IT?
NIS2 and DORA for banks: compare scope, BSI registration, reporting deadlines and ICT providers, with references to Germany’s BSIG.
Analyses and practice-oriented articles by the T-NEX editorial team: regulation, AI and governance, technology and operations, practice and projects. The articles identify their sources and the date of the current revision. T-NEX GmbH is the publisher.
26 articles

RegulationFirst version: Updated:
NIS2 and DORA for banks: compare scope, BSI registration, reporting deadlines and ICT providers, with references to Germany’s BSIG.

AI & GovernanceFirst version: Updated:
How RAG chatbots retrieve documents and support answers, with checks for permissions, knowledge maintenance and answer quality.

AI & GovernanceFirst version: Updated:
AI agents in financial institutions: limit tasks and permissions, assess approvals and trace actions under MaRisk, DORA and the AI Act.

AI & GovernanceFirst version: Updated:
The AI Act for banks after the July 2026 amendment: high-risk classification, transparency and current application dates.

RegulationFirst version: Updated:
AMLR from 10 July 2027, staged AMLD6 implementation and AMLA supervision: responsibilities and dates financial institutions need to assess.

Technology & OperationsFirst version: Updated:
Assess GRC software through functions, contractual requirements and operating evidence under MaRisk and DORA.

RegulationFirst version: Updated:
Key banking dates for DORA, MaRisk, AI regulation and anti-money laundering, with sources distinguishing applicable law from plans.

RegulationFirst version: Updated:
The ninth MaRisk amendment has applied since 30 June 2026. Changes from the previous version and implementation checks for institutions.

RegulationFirst version: Updated:
MaRisk under Circular 06/2026: scope, structure and relationship with DORA, including the limited transition and investment-firm distinction.

RegulationFirst version: Updated:
The DORA register of information: record contracts, identifiers and supply chains using the EU templates and BaFin requirements.

RegulationFirst version: Updated:
DORA since 17 January 2025: scope, ICT risk, incident reporting and third parties, with primary sources and implementation checks.
RegulationFirst version: Updated:
ICAAP and ILAAP for banks in Germany: normative and economic perspectives, a worked example, SREP and the ECB's July 2026 clarifications.
RegulationFirst version: Updated:
Understand P2R and P2G, CET1 composition and MDA. A worked capital example and 2026 methodology changes for ECB banks and German LSIs.
RegulationFirst version: Updated:
Classify outsourcing and ICT services under MaRisk AT 9 and DORA Articles 28–30. Contracts, registers, risk assessments and practical exit testing.
RegulationFirst version: Updated:
CRR III since 2025: the output floor rises from 55% in 2026 to 72.5% from 2030. Worked calculation and FRTB transitional measures for 2027–2029.
RegulationFirst version: Updated:
IReF for banks: planned pilot from Q2 2030 and official reporting from Q2 2031. How BIRD, AnaCredit and supervisory reporting differ, and how to prepare data.
RegulationFirst version: Updated:
A curated map connects guideline identifiers, business topics and German supervisory practice. It starts with the implementation list in MaRisk of 30 June 2026.
RegulationFirst version: Updated:
A GRC migration starts with fields, responsibilities and data quality. This sequence moves from the existing workbook through a trial run to business acceptance.
RegulationFirst version: Updated:
TLPT is advanced testing for financial entities identified by the supervisor. Selection follows DORA and Commission Delegated Regulation (EU) 2025/1190.
RegulationFirst version: Updated:
The SREP connects business model, governance, capital risks and liquidity risks. Banks need a consistent account of their data, assumptions, decisions and outstanding actions.
RegulationFirst version: Updated:
COREP principally addresses prudential risks and own funds. FINREP provides standardised financial information. Reliable reporting requires aligned definitions, sources and reconciliations.
RegulationFirst version: Updated:
A sound business case compares current operations with specific alternatives. It shows implementation effort, recurring cost and evidenced benefits over the same period.
RegulationFirst version: Updated:
Solvency II combines quantitative capital requirements with governance and reporting. This overview explains SCR, MCR and the role of ORSA in managing an insurer.
RegulationFirst version: Updated:
Sanctions screening requires current legal and list data, appropriate matching and traceable alert handling. A similar name starts an investigation.
RegulationFirst version: Updated:
ISO/IEC 27001 defines requirements for an information security management system. IT-Grundschutz adds a concrete methodology and building blocks. Begin with scope and the evidence you need.
RegulationFirst version: Updated:
Bank data has no single retention period. A deletion policy connects record type, legal basis, start date and justified exceptions with the data actually held.
Regulation here means DORA, MaRisk, BAIT and European supervisory practice, explained from primary sources. Every article names the legal act, the article and the exact reference, so each statement remains verifiable and can be carried straight into your own implementation.
AI and governance covers the use of language models in banks: control frameworks, traceability, source binding and the question of when an AI answer holds up in an audit. The benchmark is supervisory expectation, not what is technically possible.
Technology and operations shows how AI systems actually run in banking environments: architecture, hosting in the EU, operating models and outsourcing questions, described concretely enough that IT, business and internal audit speak the same language.
Practice articles explain individual steps and decisions from documented projects. Measurements are identified with the test or operating conditions they describe.