IndiciumIndicium
Log in
← Back to blog
Background checks for HR, Legal and Compliance

Turn public-source risk signals into audit-ready decisions.

Indicium helps regulated teams screen candidates, counterparties and sensitive hires — with dated sources, human review and reports your Legal team can defend.

With the Indicium report, you implement the personnel-related safeguard against insider risks in an audit-proof manner — with dated sources and human final review.

Insider Risk in Banks: Why Internal Perpetrators Operate Differently

Internal perpetrators exploit legitimate access and system knowledge. Which safeguards § 25h KWG, § 6 GwG and MaRisk AT 7.1 require of banks.

Insider risks work fundamentally differently from external attacks: internal perpetrators do not have to overcome perimeter controls, because they operate with legitimate access rights, system knowledge and the trust of their colleagues. The supervisory answer to this is not more firewalls, but personnel-related safeguards — in particular the ongoing, not merely one-time, reliability screening under § 6 (2) no. 5 GwG (German Anti-Money Laundering Act), flanked by § 25h (1) KWG (German Banking Act) and the personnel requirements of MaRisk (BaFin’s Minimum Requirements for Risk Management).

Why Perimeter Controls Fail Against Insiders

The security architecture of most institutions is directed outward: access controls, network segmentation, fraud detection at the interfaces. An insider already stands behind these lines. They know which transactions trigger a four-eyes check, which thresholds set off the monitoring, and which processes nobody controls — knowledge an external attacker would first have to obtain laboriously. This does not make insider incidents more frequent than external attacks, but harder to detect and, in the individual case, more severe. Add to this a time factor: because no alarm sounds at the outer boundary, internal actions often remain undetected over extended periods — and the longer the period, the higher the damage and the more difficult the clean-up.

Perpetrator Typologies — and What They Mean Legally

Without alarmism, three basic constellations can be distinguished, each pointing to different obligations:

  • The intentional actor: persons who deliberately use access rights for embezzlement, fraud or the facilitation of money laundering. This is the target of § 25h (1) KWG, which requires institutions to maintain appropriate internal safeguards also against other criminal acts to the detriment of the institution.
  • The infiltrator: candidates or employees who reach sensitive positions with a falsified career history or concealed conflicts of interest. Against this works the reliability screening under § 6 (2) no. 5 GwG — at hiring and on an ongoing basis; the fundamentals are explained in our article on reliability screening under § 6 GwG.
  • The at-risk employee: employees whose life circumstances change after hiring — for instance financial distress or problematic entanglements. This is precisely why the screening is designed as an ongoing measure and not as a one-time act at onboarding.

The Supervisory Answer: Personnel as Part of Risk Management

MaRisk (BaFin Circular 06/2024 (BA)) expressly treats personnel in AT 7.1 as a resource of risk management: employees’ qualifications and suitability must match their tasks, and absence and turnover risks must be managed. Together with § 25h (1) KWG and § 6 (2) no. 5 GwG, a consistent picture emerges: the legislator and the supervisor expect institutions to treat the human factor with the same rigour as technical and process risks. How the screening logic of the customer side can be transferred to the workforce is shown in the article KYC vs. Know Your Employee.

What Distinguishes an Effective Insider-Risk Programme

Effective programmes combine technical and personnel-related building blocks instead of relying on any single one; the following elements have proven themselves:

  • risk-based classification of positions by damage potential and depth of access,
  • reliability screening before hiring with position-dependent screening depth,
  • event-driven re-screening upon role changes into sensitive functions,
  • appropriate repeat cycles for key roles,
  • audit-proof documentation of every screening for internal audit and the supervisory authority,
  • inclusion of external staff with comparable access rights — explored further in Screening Interim Managers and External Contractors.

The interplay is decisive: technical controls limit what an insider can do; personnel-related measures reduce the probability that an unsuitable person reaches — or remains in — a critical role at all. Neither element replaces the other.

First check whether your personnel-related measures keep pace with the access depth of your roles: who can circumvent controls, and when was that person last screened? Then close the typical gap between hiring screening and ongoing employment through defined triggers and cycles. For documented implementation, Indicium delivers audit-proof reports with dated sources and human final review (Art. 22 GDPR); an overview of sector-specific requirements is available under Industries.

This article provides general information and does not constitute legal advice.

Ready to move from reading to doing?

See how a reviewable risk report is built — from name to verdict in minutes, not weeks.

Book a demo See a sample report