A GRC application must fit the institution’s processes. A long feature list is insufficient: data must remain maintainable, permissions must work and required evidence must be accessible for review. Classifying the service under MaRisk and DORA comes before comparing individual products.
What is GRC software and what must it deliver in a bank?
GRC software can support an institution in documenting and operating risk and control processes. Appropriate processes and evidence are required; MaRisk does not prescribe a particular software product. Selection criteria therefore need to start with the institution’s actual tasks. BaFin: Rundschreiben 06/2026 (BA), MaRisk
| GRC discipline (block B) | The tool should map | Legal reference |
|---|---|---|
| Risk management / ICS | risk inventory, control catalogue with target-actual comparison, action tracking | MaRisk AT 4.3 |
| Outsourcing / third parties | two separate registers (MaRisk outsourcing register, DORA register of information) plus due diligence and exit workflows | MaRisk AT 9 para. 12 b); Art. 28(3) DORA |
| ICT risk / information security | asset inventory, vulnerability tracking, incident capture with classification logic | Art. 6–15 DORA; RTS (EU) 2024/1774 |
| Business continuity | contingency concepts, business continuity and recovery plans incl. test evidence | MaRisk AT 7.3; Art. 11–12 DORA |
| Compliance | management of legal sources and obligations, reporting lines of the compliance function | MaRisk AT 4.4.2 |
| Internal audit | audit planning (regular cycle 3 years, non-material activities 5 years), follow-up with effectiveness evidence | MaRisk AT 4.4.3 para. 6 |
| Reporting | at least quarterly information of the supervisory body in text form; quarterly internal audit report | MaRisk AT 3.2 para. 2; AT 4.4.3 para. 9 |
Excel is not prohibited by supervisory rules. Whether a spreadsheet solution is sufficient depends on its controls and surrounding process. Access permissions, change history and approval evidence need assessment. Additional software is useful when it reliably supports those tasks in the intended operating environment. BaFin: Rundschreiben 06/2026 (BA), MaRisk Delegated Regulation (EU) 2024/1774
Is GRC software an outsourcing under MaRisk AT 9 or ICT third-party procurement under DORA?
The exception in MaRisk AT 9 covers ICT services under Article 3(21) DORA that are subject to ICT third-party risk management under Articles 28 to 30. Other components of mixed services require separate classification. BaFin: Rundschreiben 06/2026 (BA), MaRisk Regulation (EU) 2022/2554, DORA
“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management pursuant to Art. 28-30 DORA do not fall within the scope of AT 9.” (unofficial translation)
For GRC SaaS within DORA’s scope, assess pre-contractual due diligence, the register of information, contract clauses and exit arrangements; see the DORA overview. Separately assess whether the service constitutes outsourcing under section 25b KWG. The AT 9 exception does not create a blanket exemption from statutory outsourcing duties. Service components outside the exception require their own assessment under MaRisk AT 9.
| Form of procurement | Regime | Core obligations before signing | Reference |
|---|---|---|---|
| GRC software as SaaS/cloud (standard case) | DORA Art. 28–30 | pre-contractual assessment, register of information, Art. 30 contract content, exit arrangements | Circular 06/2026, AT 9 para. 1 explanatory note; Art. 28–30 DORA |
| Non-ICT procurement, material outsourcing | MaRisk AT 9, sec. 25b KWG | risk analysis, catalogue of mandatory contract clauses, outsourcing register | Circular 06/2026, AT 9 paras. 2, 7 a)–n), 12 b) |
| On-premises licence, consulting with a tool component | case-by-case assessment | clarify classification with third-party management and the data protection officer | no officially decided category per product |
The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. ESAs: first DORA report on major ICT-related incidents
The criteria translate the institution’s duties into requirements for selection. They do not constitute official product approval. Contract and exit requirements must distinguish whether the software supports a critical or important function. Regulation (EU) 2022/2554, DORA Delegated Regulation (EU) 2024/1773 Delegated Regulation (EU) 2024/1774
Which mandatory supervisory criteria apply?
The following criteria derive from the institution’s duties. Required contractual provisions and evidence depend partly on the service and function supported. The table provides a starting point. Regulation (EU) 2022/2554, DORA
| Mandatory criterion (block A) | Legal reference | What to look for |
|---|---|---|
| DORA contract capability | Art. 30(2)–(3) DORA | contract template with all mandatory elements incl. locations; willingness to renegotiate |
| Register-ready master data | Art. 28(3) DORA; ITS (EU) 2024/2956 | For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. |
| Suitability for the pre-contractual assessment | Art. 28(4), Art. 29 DORA | documents for criticality assessment, due diligence, concentration risk |
| Information security evidence | Art. 28(5) DORA; Art. 8 RTS (EU) 2024/1773 | Request evidence of appropriate information security standards. Assess the scope and currency of certificates and assurance reports, and secure the required inspection and access rights contractually. |
| Audit and access rights | Art. 28(6), Art. 30(3)(e) DORA; sec. 44 KWG | unrestricted rights for institution and supervisor, pooled audit options Assess the scope and criticality of the supported function. |
| Exit capability, data return | Art. 28(8), Art. 30(2)(d), (3)(f) DORA | complete data export, mandatory transition period, migration path Assess the scope and criticality of the supported function. |
| Transparent subcontractor chain | Art. 29(2) DORA; RTS (EU) 2025/532 | disclosure incl. hosting, change notification with objection period Assess the scope and criticality of the supported function. |
| AT 9 conformity for non-ICT components | sec. 25b KWG; MaRisk AT 9 paras. 7 a)–n), 12 b) | catalogue of mandatory contract clauses and entry in the outsourcing register |
| Segregation of duties (three lines) | sec. 25a(1) sentence 3 no. 3 KWG; MaRisk AT 4.3/4.4; Art. 6(4) DORA | role-specific views, access rights and reporting lines per line of defence |
| Auditability | MaRisk AT 4.4.3 (para. 10: 6 years retention) | full read access for internal audit, evaluable history, follow-up Assess the scope and criticality of the supported function. |
| Data protection conformity | Art. 28, 30, 35, 17(3)(b) GDPR | data processing agreement with minimum content, processing locations, configurable deletion periods |
On 18 November 2025, the ESAs designated 19 critical ICT third-party providers for the first time. SaaS selection should include the hosting supply chain in the assessment of concentration risk. Direct European oversight of a provider does not replace the institution’s responsibility. ESAs designate critical ICT third-party providers Regulation (EU) 2022/2554, DORA
What minimum content must a GRC SaaS contract contain?
Since 17 January 2025, every GRC SaaS contract needs the nine minimum elements of Art. 30(2) DORA (Regulation (EU) 2022/2554), including a complete description of services, the locations of service provision and data processing, data access and return, service levels and termination rights. If the GRC software supports a critical or important function, six further elements under Art. 30(3) DORA are added, including precise quantitative performance targets, unrestricted audit rights and a mandatory exit transition period. Existing contracts are affected as well; BaFin clarified this in its supervisory notice of 21 August 2025:
“No extended transition periods are provided for adapting the existing contractual arrangements (risk analyses, contractual content). The contractual arrangements should be adapted as soon as possible.” (unofficial translation)
The question catalogue for the vendor due diligence of a SaaS GRC vendor, ready to copy and with a reference for every question:
01Contract content under Art. 30 DORA
Does the contract template contain all nine minimum elements under Art. 30(2) DORA and, if a critical or important function is supported, the six additional elements under paragraph 3?
02Register-ready master data
For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity.
03Documents for the pre-contractual assessment
Which documents does the institution receive for the pre-contractual assessment, due diligence and concentration risk analysis (Art. 28(4), Art. 29 DORA)?
04Information security evidence
Which information security evidence is available, and do the institution's own audit activities remain possible (Art. 28(5) DORA; Art. 8 RTS (EU) 2024/1773)?
05Subcontractor chain
The supply chain must record the providers and ranks required by the templates. For ICT services supporting critical or important functions, the relevant subcontracting chain must be identified. A complete procurement directory and the supervisory register’s required chain are different datasets.
06Exit and data return
How do data export, transition period and migration work in the exit case, including insolvency or termination (Art. 28(8), Art. 30(2)(d) DORA)?
07Data processing under the GDPR
Is there a data processing agreement under Art. 28 GDPR, with processing locations and configurable deletion and retention periods?
Does the GRC vendor have to go into the DORA register of information?
Yes: Under Art. 28(3) DORA (applicable since 17 January 2025), the DORA register of information covers all contractual arrangements on ICT services, not only critical ones; the GRC SaaS contract belongs in it regardless of its criticality classification. The wording of the register obligation:
“As part of their ICT risk management framework, financial entities shall maintain and update at entity level, and at sub-consolidated and consolidated levels, a register of information in relation to all contractual arrangements on the use of ICT services provided by ICT third-party service providers."
The register must be maintained and updated continuously. Article 28(3) DORA distinguishes this from annual information on new arrangements and from providing the register when requested by the supervisor. A BaFin submission follows the applicable collection request and format instructions. Regulation (EU) 2022/2554, DORA BaFin: Informationsregister und Anzeigepflichten
For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956
Is an ISO 27001 certificate of the vendor sufficient as evidence?
Request evidence of appropriate information security standards. Assess the scope and currency of certificates and assurance reports, and secure the required inspection and access rights contractually. Regulation (EU) 2022/2554, DORA Delegated Regulation (EU) 2024/1773
Which technical criteria must the GRC tool meet?
The criteria translate the institution’s duties into requirements for selection. They do not constitute official product approval. Contract and exit requirements must distinguish whether the software supports a critical or important function. Regulation (EU) 2022/2554, DORA Delegated Regulation (EU) 2024/1773 Delegated Regulation (EU) 2024/1774
01Audit trail
The audit trail logs all changes completely and tamper-proof, with timestamp and user attribution (benchmark: Art. 12 RTS (EU) 2024/1774, incl. clock synchronisation).
02Access management
Access management works role-based on a need-to-know basis and supports recertification of access rights at least annually, for critical or important functions every 6 months (Art. 20–21 RTS (EU) 2024/1774).
03Approval workflows
Approval workflows technically separate capture, control and approval: Four-eyes principle with escalation and deadline management (segregation of duties, MaRisk AT 4.3).
04Multi-entity capability
Multi-entity capability carries registers at entity, sub-consolidated and consolidated level (Art. 28(3) DORA) or centrally at group/association level (MaRisk AT 9 para. 14 e)).
05Interfaces and exports
Interfaces and exports deliver the formats required by the authorities (xBRL taxonomy, BaFin Excel template) as well as machine-readable reports.
06Encryption and hosting
Encryption protects data at rest and in transit, and the hosting locations are traceable (benchmark: Art. 9 DORA; Art. 6–7 RTS (EU) 2024/1774).
07Retention and deletion
Configurable retention and deletion rules keep the GDPR deletion concept and retention obligations compatible, including historisation for the 6-year retention of internal audit records (MaRisk AT 4.4.3 para. 10).
What does proportionality mean and which criteria does a small institution really need?
Proportionality relates requirements to the institution’s size and risk profile. It does not prescribe one product configuration for every small institution. Each relief provision and its conditions require assessment. BaFin: Rundschreiben 06/2026 (BA), MaRisk Regulation (EU) 2022/2554, DORA
| Institution class | Regulatory fixed point | Reference |
|---|---|---|
| Very small institutions (total assets ≤ EUR 1 bn on a four-year average) | a managing director may take on the compliance function or internal audit; both functions fully outsourceable | Circular 06/2026: AT 1 para. 3; AT 4.4.2 para. 4; AT 4.4.3 para. 1; AT 9 para. 5 |
| Small institutions (SNCI under Art. 4(1) No. 145 CRR) | Regular AT 9 risk analysis every three years; adapt when material changes arise | Circular 06/2026, AT 9 |
| DORA scope with simplification | simplified ICT risk management framework with a considerably smaller ICT obligations catalogue to map | Art. 4, Art. 16 DORA |
| Significant institutions (SIs) | no longer MaRisk addressees; organisational duties via sec. 25a KWG and ECB supervision; tool needs group capability | Circular 06/2026, AT 2.1 para. 1; sec. 25a KWG |
Who decides on the purchase within the institution and which gates are there?
Before selection, the institution should decide who evaluates functional requirements and who checks contractual and operational evidence. Budget responsibility and approvals follow its own organisation. Public contracting authorities need a separate assessment of the applicable procurement procedure. Regulation (EU) 2022/2554, DORA
| Role | Checks / is responsible for in the selection |
|---|---|
| Compliance, risk control, ISO/CISO | define the functional criteria (blocks A–C), hold functional vetoes |
| Outsourcing/third-party management | pre-contractual assessment: Criticality assessment, due diligence, concentration risk |
| Data protection officer | data processing agreement, data protection impact assessment where applicable; early involvement |
| Works council | co-determination for audit trails containing personal data |
| Management board | Take responsibility for the ICT budget and approvals assigned by the organisation |
Give suppliers the same functional test cases and evidence requirements. This makes their responses comparable. Resolve open contractual questions before a binding procurement decision.
RFP template: compare suppliers using the same tasks
A GRC procurement exercise needs shared test cases. Start with one of your requirements, an incorrect mapping, an approved correction and the subsequent audit report. Each supplier works through the same starting point and identifies limitations. The editable template contains 16 review areas and space for responses, evidence, assessment and decisions.
| Review area | Specific request | Required evidence |
|---|---|---|
| Business workflow | Show a requirement through to an action and its evidence in one workflow. | End-to-end demonstration using a case supplied by us. |
| Scope | Which functions and datasets are included in the offer? | Service description with exclusions and required add-on modules. |
| Roles and separation | How are editing, approval and independent review separated? | Permission matrix and a test using two distinct user roles. |
| Change history | Which changes can later be traced to an actor and time? | Exported history and demonstrated handling of corrections. |
| Sources and versions | How does an update preserve the origin of a requirement? | Before/after example with source, version and affected downstream work. |
| AI assistance | Which output is a suggestion, who reviews it and what happens on failure? | Tests covering a supported answer, insufficient source and deliberately incorrect input. |
01Agree mandatory criteria first
Define required scope and exclusion criteria before reading supplier responses. Distinguish legally grounded requirements from your own preferences.
02Assess evidence separately
A presentation claim, a demonstration and a contractual commitment are different evidence types. Record product version, test date and deviations.
03Make open issues explicit
Many convenience features cannot compensate for a missing mandatory proof. Record clarifications, conditions, cost implications and the final decision.
The template does not score specific suppliers or certify compliance. It supports comparable procurement; contractual and assurance requirements depend on the actual arrangement.
Legal and professional sources: BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbank; Verordnung (EU) 2022/2554: DORA, insbesondere Artikel 11, 24 und 28–30.
Download the RFP template (Markdown)
Which deadlines drive GRC software selection?
The ninth MaRisk amendment has applied since 30 June 2026. The transition until 1 January 2027 applies only where additional requirements arise in an individual case. BaFin: Rundschreiben 06/2026 (BA), MaRisk
| Subject | Deadline | Reference |
|---|---|---|
| DORA date of application; GRC SaaS has since run through the ICT third-party regime (Art. 28–30) | since 17 Jan 2025 | Regulation (EU) 2022/2554, EUR-Lex |
| DORA register of information: Second submission cycle (register status 31 Dec 2025) via the BaFin portal MVP | 9–30 Mar 2026 (completed) | BaFin topic page on the register of information |
| MaRisk transition period of the 9th amendment for requirements additional in individual cases | until 1 Jan 2027 | Circular 06/2026 (BA), covering letter |
| BAIT fully repealed (no longer applicable to DORA institutions since 17 Jan 2025 anyway) | as of 31 Dec 2026 | BaFin announcement of 9 January 2025 |
Related topics
- DORA Regulation overview: Application, pillars and the contract system of Art. 28–30.
- MaRisk (BaFin): Module system, AT 9 and proportionality of the 9th amendment.
- 9th MaRisk amendment (Circular 06/2026): the AT 9 carve-out for ICT services in detail.
- DORA register of information in detail: Deadlines, templates and MVP submission.
- Banking regulation roadmap: key dates and milestones 2026 to 2028+.
Frequently asked questions on GRC software selection
Sources & further reading
- BaFin: Circular 06/2026 (BA), MaRisk (9th amendment, in force since 30 June 2026), incl. AT 9 para. 1 explanatory notebafin.de
- Regulation (EU) 2022/2554 (DORA), esp. Art. 5, 28–30 (EUR-Lex)eur-lex.europa.eu
- Implementing Regulation (EU) 2024/2956 (ITS register of information templates, EUR-Lex)eur-lex.europa.eu
- Delegated Regulation (EU) 2024/1773 (RTS third-party policy, esp. Art. 8, EUR-Lex)eur-lex.europa.eu
- Delegated Regulation (EU) 2024/1774 (RTS ICT risk management, esp. Art. 12, 16, 20–21, EUR-Lex)eur-lex.europa.eu
- BaFin: Register of information and notification requirementsbafin.de
- Sec. 25a KWG (proper business organisation), gesetze-im-internet.degesetze-im-internet.de
- Sec. 25b KWG (outsourcing, outsourcing register), gesetze-im-internet.degesetze-im-internet.de
- ESAs/EBA: press release on the first DORA annual report on major ICT-related incidents (3 June 2026)eba.europa.eu
- ESAs/EBA: press release on the designation of 19 critical ICT third-party service providers (18 November 2025)eba.europa.eu
- EBA: press release on consultation EBA/CP/2025/12 (TPRM guidelines for non-ICT third parties, 8 July 2025)eba.europa.eu
- BaFin: announcement of 9 January 2025 (DORA date of application; BAIT repeal as of 31 December 2026)bafin.de
- BaFin: DORA topic page (supervisory notices, incl. of 21 August 2025)bafin.de
- Delegated Regulation (EU) 2024/1773eur-lex.europa.eu
- Implementing Regulation (EU) 2024/2956, register templateseur-lex.europa.eu
- Corrigendum to Implementing Regulation (EU) 2024/2956eur-lex.europa.eu
- Delegated Regulation (EU) 2024/1774eur-lex.europa.eu
- Regulation (EU) 2022/2554, DORAeur-lex.europa.eu
- BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbankbundesbank.de
An offer from T-NEX GmbH
Discuss the project with T-NEX
Compare these criteria with the described workflows of T-NEX Compliance and the Banking Platform. The evidence page distinguishes documented functionality from the assurance required for your specific operation.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
