Blog Practical guides for regulated institutions
We write when something changes for regulated institutions.
NIS2 implementation, GwG interpretation, new sanctions regimes, EU data sovereignty — assessing, not alarmist.
KYC & Compliance
Choosing a Background-Check Provider: The DACH Buyer's Checklist
A practical checklist for DACH financial institutions and firms evaluating background-check and due-diligence providers.
KYC & Compliance
Background checks for family offices: protecting UHNW principals
How family offices can structure background checks to shield UHNW principals from reputational, financial and security risks.
Compliance Operations
PE/VC screening playbook: deal principals and portfolio hires
A practitioner playbook for private equity and venture capital firms on integrating background screening into deal workflows and portfolio hiring.
Compliance Operations
From order to report: the screening implementation timeline
A step-by-step walkthrough of how a background-check order moves from intake to final report, including typical duration buckets per phase.
Executive Search
Executive search due diligence: protecting your placement fee
Discover how executive search due diligence safeguards your placement fee by mitigating candidate risk and ensuring successful C-level placements.
KYC & Compliance
Outsourced screening vs. manual: time, cost and audit trail
Comparing outsourced background screening with manual in-house processes across time, cost drivers, audit trail, and scalability.
Legal & Fundamentals
Reference checks in Switzerland: what employers can ask
A practical guide to permissible questions, off-limits topics, and documentation standards for reference checks under Swiss employment and data protection law
Banking & Insurance
Board member and managing director screening: Zuverlässigkeitsprüfung in DACH
A practical guide to Zuverlässigkeitsprüfung requirements for board members and managing directors across Germany, Austria, and Switzerland.
Executive Search
How long does a background check take? Realistic timelines for DACH employers
Understand the typical timelines for background checks in the DACH region and the factors that influence how long pre-employment screening takes.
KYC & Compliance
UBO Verification: 3 Levels of Beneficial Ownership Checks
A practical breakdown of the three verification levels for ultimate beneficial owners, from registry lookups to deep ownership tracing.
KYC & Compliance
What is PEP screening? Identifying politically exposed persons
PEP screening identifies individuals with prominent public functions and their associates, enabling the enhanced due diligence required under AML law.
KYC & Compliance
How much does a background check cost in Germany? 2026 pricing and ROI
Understand the cost drivers behind professional background checks in Germany and how to evaluate return on investment across screening types.
Legal & Fundamentals
ISO 27001 Audit: What Auditors Ask for First
ISO 27001 audit checklist: the ten document requests and questions auditors open with, why each comes first, and what a weak answer looks like.
Legal & Fundamentals
ISO 27001 explained: certification for regulated firms in Germany
What ISO/IEC 27001:2022 is, what certification proves for NIS2, KRITIS and DORA, how Stage 1 and Stage 2 audits run, and where personnel controls fit in.
Legal & Fundamentals
ISO 27001 A.6 Personnel Security: Screening Before, During and After Employment
ISO 27001 A.6.1 screening: the exact control wording, who must be screened, ongoing rescreening, auditor evidence and the German limits of BDSG § 26 and AGG.
KRITIS & Public Sector
KRITIS implementation: 8 mistakes that get expensive
The 8 most common KRITIS implementation mistakes: missed registration deadlines, the § 39 evidence cycle, § 32 incident reporting and personnel security gaps.
KRITIS & Public Sector
KRITIS registration: from self-assessment to BSI audit
KRITIS registration in steps: annual threshold self-check, § 33 BSIG via MIP, BBK registration under the Dachgesetz, and the § 39 BSIG evidence cycle.
KRITIS & Public Sector
NIS2 Compliance in Germany: Who Is Affected, What Applies, When
NIS2 compliance in Germany since 6 December 2025: who qualifies under § 28 BSIG, registration after the 6 March 2026 deadline, core duties and fines.
KRITIS & Public Sector
NIS2 incident reporting: deadlines under section 32 BSIG
Section 32 BSIG sets three reporting deadlines for significant incidents: early warning in 24 hours, notification in 72 hours, final report in one month.
KRITIS & Public Sector
NIS2 readiness: 10 questions that reveal your real status
A NIS2 readiness checklist of 10 questions: registration, § 30 BSIG measures, incident reporting and management duties, each with a good and a bad answer.
KRITIS & Public Sector
What is KRITIS? Sectors, thresholds and duties explained
What is KRITIS? The 2026 definition: ten sectors, the 500,000-person supply threshold, and operator duties under BSIG and the KRITIS-Dachgesetz.
Banking & Insurance
DORA Compliance 2026: What Financial Entities Must Have in Place
DORA compliance checklist for banks, insurers and asset managers: training, third-party due diligence, register of information and ICT risk management by 2026.
Company
Indicium joins Deutsche Telekom’s TechBoost program
Indicium joined TechBoost, Deutsche Telekom’s startup program. What the program means for infrastructure and regulated enterprise customers.
KRITIS & Public Sector
Reliability Screening in KRITIS: The Implementation Guide
Personnel security under the KRITIS-DachG and Art. 14 CER Directive: how operators implement background checks in a risk-based, reviewable way.
KRITIS & Public Sector
KRITIS-Dachgesetz 2026: Obligations, Deadlines and Sectors
KRITIS-Dachgesetz 2026 in force: sectors, obligations and deadlines at a glance — and what applies if the 17 July 2026 registration deadline was missed.
Compliance
Sanctions screening: EU vs OFAC vs UN lists explained
Understand the differences between EU, OFAC, and UN sanctions lists, when each applies, and how to build a defensible screening process for KYC/AML compliance.
Banking & Insurance
Employee Reliability Screening Under § 6 GwG
What § 6 (2) no. 5 GwG requires of banks and insurers: the statutory definition of reliability, screening triggers and typical implementation gaps.
KRITIS & Public Sector
State Security Clearance vs. Employer Screening: Who Checks What?
Security clearance vs. own screening: what SÜG, LuftSiG and AtZüV cover — and what employers must check themselves under KRITIS-DachG and BSIG.
Legal & Fundamentals
Führungszeugnis vs. Background Check: The Limits of the Register
A clean Führungszeugnis is no proof of integrity: which entries are missing under the BZRG and when a structured background check closes the gap.
KRITIS & Public Sector
SÜG Amendment 2026: What Changes for Ü1, Ü2 and Ü3
SÜG amendment in force since 16 Jan 2026: changes to Ü1, Ü2 and Ü3, mandatory internet research even at Ü1 — and the consequences for companies.
KRITIS & Public Sector
NIS2 Personnel Security: The Duties Under § 30 BSIG
§ 30 BSIG demands personnel security and access control: what NIS2 entities must implement now and why § 38 BSIG targets senior management.
Legal & Fundamentals
Pre-Employment Screening: GDPR Legal Basis After the CJEU Ruling
After CJEU C-34/21, § 26 BDSG alone no longer carries screening: how to map screening categories to Art. 6 GDPR — with checklist and balancing test.
Banking & Insurance
Fit and Proper at BaFin: Documenting Reliability Properly
BaFin's fit-and-proper assessment: what §§ 25c, 25d and 24 KWG require of executive directors and supervisory boards, and how to prepare the notification.
Banking & Insurance
Background Check Providers: Why Software Alone Is Not Enough
Why software alone is not enough for fit-and-proper and reliability decisions: the hybrid approach for decisions you can defend.
Legal & Fundamentals
Continuous Compliance Monitoring or One-Time Check?
One-time check or continuous monitoring? When the point-in-time check is no longer enough: GwG duties, GDPR limits and a decision matrix.
Legal & Fundamentals
Screening Interim Managers and External Contractors: Closing the Gap
Interim managers and external providers slip through every screening grid: GDPR legal bases, DORA duties and a screening framework for externals.
Legal & Fundamentals
Social Media Screening of Applicants: What Is Permitted?
Social media screening of applicants: permitted on LinkedIn and Xing, off-limits for private profiles. Legal framework, DSK line and information duties.
Legal & Fundamentals
Works Council and Background Checks: Involving Co-determination
Works council and background checks: classify §§ 94, 95, 87 BetrVG and use co-determination as an opportunity — with key points for the works agreement.
Legal & Fundamentals
Background Checks in Switzerland: Art. 328b OR and the revFADP
Background checks in Switzerland: what Art. 328b OR and the revFADP permit, which limits apply and what a lawful, tiered screening depth looks like.
Legal & Fundamentals
LkSG 2026 and CSDDD: What Now Applies to Supplier Screening
LkSG amendment and postponed CSDDD: why the due-diligence duties persist and what really applies to your supplier due diligence in 2026.
Legal & Fundamentals
CV Fraud: The Numbers and the Cost of a Bad Hire
How often people lie on their CVs, what a bad hire really costs and why pre-hire verification is a business case.
Legal & Fundamentals
Employer Questions and the German ‘Right to Lie’
Applicants may lie to inadmissible questions without consequence: what employers may ask in Germany and how to screen lawfully instead.
KRITIS & Public Sector
Industrial Security: The Security Officer’s Duties Under SÜG and GHB
The security officer’s duties under SÜG, GHB and VSA — and why pre-selection before the clearance request rests with the company.
KRITIS & Public Sector
Employee Screening for Critical Infrastructure: A Decision Guide
KRITIS operators in energy, water and health: which role needs which screening depth — state-run, internal or software report. A decision guide.
KRITIS & Public Sector
AtZüV: The Nuclear Reliability Check Under § 12b AtG Explained
AtZüV in brief: Who is vetted under § 12b AtG in decommissioning, interim storage and transport — and which questions remain open for employers and contractors.
KRITIS & Public Sector
Personnel Security Screening in Switzerland: PSP Under ISG and PSPV
Personnel security screening under ISG and PSPV: screening levels, consent — and why private employers without a federal nexus need their own screening.
Banking & Insurance
Background Check Software for Banks: Requirements Catalogue
Requirements catalogue for background check software in banks: review categories, DACH sources, data protection concept and reviewable documentation.
KRITIS & Public Sector
ZÜP under § 7 LuftSiG: What the Check Does Not Cover
What the ZÜP under § 7 LuftSiG checks — and what it does not: CV claims, foreign offences and ongoing conduct remain the employer's task. An overview.
Banking & Insurance
The AML Officer: Setting Up Employee Screening Operationally
How the anti-money laundering officer sets up employee screening under § 6 (2) no. 5 GwG: risk classes, review cycles and reviewable documentation.
Banking & Insurance
§ 24 VAG: Assessing Reliability at Insurers Correctly
§ 24 VAG: who is vetted for reliability at insurers, which GwG duties apply to life insurers and how the two regimes fit together.
Banking & Insurance
DORA Requirements for Personnel and ICT Service Providers
What Regulation (EU) 2022/2554 requires for training, due diligence and contracts with third-party ICT providers — an overview.
Banking & Insurance
Pre-Employment Screening in Banks: What § 26 BDSG Permits
What § 26 BDSG permits in pre-employment screening at banks: lawful sources, proportionality by position, and the limits set by data protection law.
Banking & Insurance
Insider Risk in Banks: Why Internal Perpetrators Operate Differently
Internal perpetrators exploit legitimate access and system knowledge. Which safeguards § 25h KWG, § 6 GwG and MaRisk AT 7.1 require of banks.
Banking & Insurance
Know Your Employee: The Blind Spot in Anti-Money-Laundering
KYC is standard, Know Your Employee often is not: why employee vetting under § 6(2) no. 5 GwG ranks equally and how to implement it.
Executive Search
Backdoor hires: the hidden cost of executive search
Why executive search without structured background checks is expensive: reputation and regulatory risks at board level that a check from €79 can prevent.
Compliance Operations
Adverse media screening: a practical guide for regulated firms
What adverse media screening is, how it fits your compliance framework, and why automation without human assessment creates more risk than it removes.
KYC & Compliance
What is a background check and why it matters for KYC compliance
What background checks cover, how they differ from database lookups, and why they are essential for KYC compliance under the GwG and EU AML directives.