(1) The managers of an institution must be professionally qualified and reliable to manage an institution, and must devote sufficient time to performing their duties. Professional qualification requires that the managers have a sufficient degree of theoretical and practical knowledge of the relevant business, and management experience. Professional qualification is generally to be assumed where three years of management experience at an institution of comparable size and type of business is demonstrated.
(1a) The managers must, collectively, possess an adequately broad range of knowledge, skills, and experience necessary to understand the institution's activities, including its main risks.
(1b) Where a person does not meet the conditions of subsection (1), first sentence, or subsection (2), the institution must ensure without delay that 1. the person is not appointed as manager, 2. the person is removed from their position as manager, or 3. measures are taken so that the person meets the conditions.
(1c) Where an undertaking intends to appoint a person and facts exist showing that the person does not meet the conditions of subsection (1), first sentence, or subsection (2), or where material information necessary to assess qualification, reliability, and time availability is missing from the notification under section 24 of the intention to appoint, the Federal Institute may order that the person not be appointed.
(2) In determining the number of management or supervisory mandates that a manager may hold at the same time, the individual case and the type, scale, and complexity of the institution's business must be taken into account. A person cannot be a manager of a significant institution within the meaning of section 1(3c), or of an authorised financial holding company or mixed financial holding company to which such an institution is subordinate, where 1. that person is, in the same undertaking, a member of the administrative or supervisory body or, in the case of a European Company (SE) with a monistic system, chair or non-executive member of the administrative board, or 2. that person is a manager in another undertaking, or is already a member of the administrative or supervisory body in more than two undertakings. For the purposes of the second sentence, point 2, several mandates count as one mandate where the mandates are held at undertakings 1. belonging to the same financial holding group or mixed financial holding group, or that are affiliated undertakings within the meaning of the Commercial Code or are connected in a group in a comparable manner, 2. belonging to the same institutional protection scheme, or 3. in which the undertaking holds a significant holding. Several mandates are likewise counted as one mandate within the meaning of the third sentence where they include both mandates as manager and mandates as a member of the administrative or supervisory body. In this case they count together as one manager mandate. Mandates at organisations and undertakings that do not predominantly pursue commercial objectives, in particular undertakings serving municipal public services, are not counted towards the maximum permitted number of mandates under the second sentence, point 2. The supervisory authority may, taking into account the circumstances of the individual case and the type, scale, and complexity of the activities of the institution, the institutional group, the financial holding group, the financial holding company, or the mixed financial holding company, permit a manager to hold an additional mandate in an administrative or supervisory body, where this does not prevent the member from devoting sufficient time to performing their duties at the undertaking concerned. The additional mandate may be accepted only after the supervisory authority has granted permission.
(3) As part of their overall responsibility for the proper business organisation, the managers must 1. resolve on principles of proper management that ensure the diligence required in managing the institution and, in particular, establish a separation of duties within the organisation and measures to prevent conflicts of interest, and ensure the implementation of these principles; 2. monitor and regularly assess the effectiveness of the principles established and implemented under point 1; the managers must initiate appropriate steps to remedy any deficiencies; 3. devote sufficient time to determining the strategies and to the risks, in particular counterparty default risk, market risk, and operational risk; 4. ensure an adequate and transparent corporate structure that is geared to the undertaking's strategies and takes account of the transparency of the institution's business activities required for effective risk management, and possess the knowledge of the corporate structure and the risks associated with it necessary for this purpose; for the managers of a parent undertaking, this duty also relates to the group under section 25a(3); 5. ensure the correctness of accounting and financial reporting; this includes the controls necessary for this purpose and compliance with the statutory provisions and the relevant standards; and 6. monitor the processes relating to disclosure and communication.
(4) Institutions must deploy adequate personnel and financial resources to facilitate the induction of members of the management body into their office and to enable the further training necessary to maintain their professional qualification, including in relation to ICT risks within the meaning of Article 4(1), first subparagraph, point 52c, of Regulation (EU) No 575/2013.
(4a) As part of their overall responsibility for the institution's proper business organisation under section 25a(1), second sentence, the managers of an institution must ensure that the institution has the following strategies, processes, procedures, functions, and concepts: 1. a business strategy directed at the institution's sustainable development and a risk strategy consistent with it, together with processes for planning, implementing, assessing, and adapting the strategies under section 25a(1), third sentence, point 1; at a minimum, the managers must ensure that a) the overall objective, the institution's objectives for each material business activity, and the measures for achieving these objectives are documented at all times; b) the risk strategy comprises, at all times, the risk management objectives of the material business activities and the measures for achieving these objectives; 2. procedures for determining and ensuring risk-bearing capacity under section 25a(1), third sentence, point 2; at a minimum, the managers must ensure that a) the institution's material risks, in particular counterparty default, market price, liquidity, and operational risks, are identified and defined regularly and as occasion requires, as part of a risk inventory (overall risk profile); b) risk concentrations are taken into account as part of the risk inventory, and possible material impairments of the asset position, earnings position, or liquidity position are examined; 3. internal control procedures, with an internal control system and an internal audit function, under section 25a(1), third sentence, point 3, letters a to c; at a minimum, the managers must ensure that a) areas of responsibility are clearly delineated as part of the organisational and operational structure, with material processes and the associated tasks, powers, responsibilities, controls, and lines of communication clearly defined, and with it ensured that employees do not carry out mutually incompatible activities; b) there is a basic separation, on the one hand, between the area that initiates lending business and holds a vote in credit decisions (front office) and the trading area, and, on the other hand, the area that holds a further vote in credit decisions (back office) and the functions serving risk control and the settlement and control of trading transactions; c) the internal control system comprises risk-management and risk-control processes for identifying, assessing, managing, monitoring, and communicating the material risks and the risk concentrations associated with them, together with a risk control function and a compliance function; d) the management is reported to, at appropriate intervals but at least quarterly, on the risk situation, including an assessment of the risks; e) the administrative or supervisory body is reported to by the management, at appropriate intervals but at least quarterly, on the risk situation, including an assessment of the risks; f) adequate stress tests for the material risks and the institution's overall risk profile are carried out regularly, and any need for action is examined on the basis of the results; g) the internal audit function reports to the management and to the supervisory or administrative body at appropriate intervals but at least quarterly; h) the heads of the internal control functions possess sufficient authority, have direct access to the administrative and supervisory body, and are entitled to report directly to the administrative or supervisory body independently of the management, and in particular to issue warnings about risky developments, and i) the heads of the internal control functions may not be relieved of their function without the prior consent of the administrative or supervisory body; in urgent cases, the chair of the administrative or supervisory body may grant consent provisionally; 4. adequate staffing and technical-organisational resources for the institution under section 25a(1), third sentence, point 4; at a minimum, the managers must ensure that the quantitative and qualitative staffing, and the scope and quality of the technical-organisational resources, take account of the institution's internal requirements, its business activities, and its risk situation; 5. adequate contingency concepts for emergencies in time-critical activities and processes under section 25a(1), third sentence, point 5; at a minimum, the managers must ensure that contingency tests are carried out regularly to review the adequacy and effectiveness of the contingency concept, and that the persons responsible in each case are reported to on the results; 6. in the case of an outsourcing of activities and processes to another undertaking under section 25b(1), first sentence, at a minimum adequate procedures and concepts to avoid excessive additional risks and any impairment of the propriety of the transactions, services, and business organisation within the meaning of section 25a(1); 7. adequate procedures and concepts ensuring that holders of key functions meet the requirements of section 25e(1) at all times; at a minimum, the managers must ensure that the suitability of holders of key functions is assessed before they take up the function and regularly thereafter, and as needed, and 8. draw up, maintain, and update an overview in text form of the duties and individual responsibilities of the persons designated in Article 88(3) of Directive 2013/36/EU as amended on 27 November 2024; 9. concrete plans and quantifiable targets, in accordance with the requirements laid down in Article 7a of Regulation (EU) No 648/2012, to monitor and manage the concentration risk arising from risk positions vis-à-vis central counterparties from third countries that provide services of substantial systemic importance for the European Union or at least one of its member states.
(4b) For institutional groups, financial holding groups, mixed financial holding groups, and institutions within the meaning of Article 4 of Regulation (EU) No 575/2013, the managers of the parent undertaking are responsible for observing the duties of care within the institutional group, the financial holding group, the mixed financial holding group, or the institutions within the meaning of Article 4 of Regulation (EU) No 575/2013, where the parent undertaking is a parent company that exercises a controlling influence within the meaning of section 290(2) of the Commercial Code over other undertakings of the group, irrespective of the parent company's legal form. As part of their overall responsibility for the group's proper business organisation under the first sentence, the managers of the parent undertaking must ensure that the group has the following strategies, processes, procedures, functions, and concepts: 1. a group-wide business strategy directed at the group's sustainable development and a group-wide risk strategy consistent with it, together with processes for planning, implementing, assessing, and adapting the strategies under section 25a(1), third sentence, point 1; at a minimum, the managers must ensure that a) the group's overall objective, the group's objectives for each material business activity, and the measures for achieving these objectives are documented at all times; b) the group's risk strategy comprises, at all times, the risk management objectives of the material business activities and the measures for achieving these objectives; c) the strategic orientation of the undertakings belonging to the group is aligned with the group-wide business and risk strategies; 2. procedures for determining and ensuring the group's risk-bearing capacity under section 25a(1), third sentence, point 2; at a minimum, the managers must ensure that a) the group's material risks, in particular counterparty default, market price, liquidity, and operational risks, are identified and defined regularly and as occasion requires, as part of a risk inventory (overall risk profile of the group); b) risk concentrations within the group are taken into account as part of the risk inventory, and possible material impairments of the group's asset position, earnings position, or liquidity position are examined; 3. internal control procedures, with an internal control system and an internal audit function, under section 25a(1), third sentence, point 3, letters a to c; at a minimum, the managers must ensure that a) areas of responsibility are clearly delineated as part of the group's organisational and operational structure, with material processes and the associated tasks, powers, responsibilities, controls, and lines of communication within the group clearly defined, and with it ensured that employees do not carry out mutually incompatible activities; b) there is a basic separation, at the undertakings belonging to the group, on the one hand, between the area that initiates lending business and holds a vote in credit decisions (front office) and the trading area, and, on the other hand, the area that holds a further vote in credit decisions (back office) and the functions serving risk control and the settlement and control of trading transactions; c) the management is reported to, at appropriate intervals but at least quarterly, on the risk situation, including an assessment of the risks; d) the administrative or supervisory body is reported to by the management, at appropriate intervals but at least quarterly, at group level, on the group's risk situation, including an assessment of the risks; e) the group's internal control system comprises a risk control function and a compliance function, together with risk-management and risk-control processes for identifying, assessing, managing, monitoring, and communicating the material risks and the risk concentrations associated with them; f) adequate stress tests for the material risks and the overall risk profile are carried out regularly at group level, and any need for action is examined on the basis of the results; g) the group audit function reports to the management and to the administrative or supervisory body at appropriate intervals but at least quarterly; 4. adequate staffing and technical-organisational resources for the group under section 25a(1), third sentence, point 4; at a minimum, the managers must ensure that the quantitative and qualitative staffing, and the scope and quality of the technical-organisational resources, of the undertakings belonging to the group take account of the respective internal requirements, business activities, and risk situation of the undertakings belonging to the group; 5. adequate contingency concepts, at group level, for emergencies in time-critical activities and processes under section 25a(1), third sentence, point 5; at a minimum, the managers must ensure that contingency tests are carried out regularly at group level to review the adequacy and effectiveness of the contingency concept, and that the persons responsible in each case are reported to on the results; 6. in the case of an outsourcing of activities and processes to another undertaking under section 25b(1), first sentence, at a minimum adequate procedures and concepts to avoid excessive additional risks and any impairment of the propriety of the transactions, services, and business organisation within the meaning of section 25a(1), and 7. adequate procedures and concepts ensuring that holders of key functions meet the requirements of section 25e(1) at all times; at a minimum, the managers must ensure that the suitability of holders of key functions is assessed before they take up the function and regularly thereafter, and as needed.
(4c) Where the Federal Institute concludes that the institution or the group does not have the strategies, processes, procedures, functions, and concepts under subsections (4a) and (4b), it may, independently of other measures under this Act, order that suitable measures be taken to remedy the deficiencies identified within a reasonable period.
(5) In exceptional cases, the Federal Institute may also revocably appoint, as manager, another person entrusted with managing the business and authorised to represent the institution, where that person is reliable and has the necessary professional qualification; subsection (1) applies. Where the institution is operated by a sole trader, a person entrusted by the owner with managing the business and authorised to represent the institution may, in exceptional cases, under the conditions of the first sentence, be revocably appointed as manager. Where the appointment of a person as manager is based on an application by the institution, it may be revoked only on the application of the institution or the manager.
(6) (repealed)