Insider risks work fundamentally differently from external attacks: internal perpetrators do not have to overcome perimeter controls, because they operate with legitimate access rights, system knowledge and the trust of their colleagues. The supervisory answer to this is not more firewalls, but personnel-related safeguards — in particular the ongoing, not merely one-time, reliability screening under § 6 (2) no. 5 GwG (German Anti-Money Laundering Act), flanked by § 25h (1) KWG (German Banking Act) and the personnel requirements of MaRisk (BaFin’s Minimum Requirements for Risk Management).
Why Perimeter Controls Fail Against Insiders
The security architecture of most institutions is directed outward: access controls, network segmentation, fraud detection at the interfaces. An insider already stands behind these lines. They know which transactions trigger a four-eyes check, which thresholds set off the monitoring, and which processes nobody controls — knowledge an external attacker would first have to obtain laboriously. This does not make insider incidents more frequent than external attacks, but harder to detect and, in the individual case, more severe. Add to this a time factor: because no alarm sounds at the outer boundary, internal actions often remain undetected over extended periods — and the longer the period, the higher the damage and the more difficult the clean-up.
Perpetrator Typologies — and What They Mean Legally
Without alarmism, three basic constellations can be distinguished, each pointing to different obligations:
- The intentional actor: persons who deliberately use access rights for embezzlement, fraud or the facilitation of money laundering. This is the target of § 25h (1) KWG, which requires institutions to maintain appropriate internal safeguards also against other criminal acts to the detriment of the institution.
- The infiltrator: candidates or employees who reach sensitive positions with a falsified career history or concealed conflicts of interest. Against this works the reliability screening under § 6 (2) no. 5 GwG — at hiring and on an ongoing basis; the fundamentals are explained in our article on reliability screening under § 6 GwG.
- The at-risk employee: employees whose life circumstances change after hiring — for instance financial distress or problematic entanglements. This is precisely why the screening is designed as an ongoing measure and not as a one-time act at onboarding.
The Supervisory Answer: Personnel as Part of Risk Management
MaRisk (BaFin Circular 06/2024 (BA)) expressly treats personnel in AT 7.1 as a resource of risk management: employees’ qualifications and suitability must match their tasks, and absence and turnover risks must be managed. Together with § 25h (1) KWG and § 6 (2) no. 5 GwG, a consistent picture emerges: the legislator and the supervisor expect institutions to treat the human factor with the same rigour as technical and process risks. How the screening logic of the customer side can be transferred to the workforce is shown in the article KYC vs. Know Your Employee.
What Distinguishes an Effective Insider-Risk Programme
Effective programmes combine technical and personnel-related building blocks instead of relying on any single one; the following elements have proven themselves:
- risk-based classification of positions by damage potential and depth of access,
- reliability screening before hiring with position-dependent screening depth,
- event-driven re-screening upon role changes into sensitive functions,
- appropriate repeat cycles for key roles,
- audit-proof documentation of every screening for internal audit and the supervisory authority,
- inclusion of external staff with comparable access rights — explored further in Screening Interim Managers and External Contractors.
The interplay is decisive: technical controls limit what an insider can do; personnel-related measures reduce the probability that an unsuitable person reaches — or remains in — a critical role at all. Neither element replaces the other.
Recommended Course of Action
First check whether your personnel-related measures keep pace with the access depth of your roles: who can circumvent controls, and when was that person last screened? Then close the typical gap between hiring screening and ongoing employment through defined triggers and cycles. For documented implementation, Indicium delivers audit-proof reports with dated sources and human final review (Art. 22 GDPR); an overview of sector-specific requirements is available under Industries.
This article provides general information and does not constitute legal advice.