GermanyRechtsprechung des Bundes
Auditors must now test DORA ICT resilience at securities firms
BaFin ordinance of 26 August 2026 (BGBl I Nr. 256) extends the audit report to DORA ICT duties for Wertpapierinstitute and crowdfunding providers, first for years starting after 31 Dec 2024.
By Taxxa AI OyPublished 15 September 2026
Germany's financial supervisors have extended the statutory audit to cover digital operational resilience.WPK A BaFin ordinance dated 26 August 2026, published as BGBl I Nr. 256 on 10 September 2026, amends the audit-report rules for Wertpapierinstitute (securities institutions) and for Schwarmfinanzierungsdienstleister (crowdfunding service providers)
Bund
Bund so that auditors examine compliance with the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554 (DORA)
Bund. The ordinance entered into force the day after promulgation.
For Wertpapierinstitute, a new section 15 of the Wertpapierinstituts-Prüfungsberichtsverordnung requires the auditor to report in summary on the organisation of the institution's information and communication technology (ICT) and on those ICT systems that support material business processes or process supervisory-relevant data. Material changes to these systems and the projects serving them must be presented, and the auditor must describe and assess whether the organisational, staffing and technical safeguards for the integrity, confidentiality, authenticity and availability of the systems are adequate and effectively implemented. Where external ICT resources are used, the reporting duties extend to those resources.
The auditor must further assess whether the institution complies adequately and effectively with the listed DORA provisionsBund — Articles 5 to 14, 16 to 19, 24, 25, 28 to 30 and 45(3), together with legal acts adopted under them — applying the proportionality principle of Article 4 of Regulation (EU) 2022/2554. The assessment must address ICT risk management and its documented framework, the ICT business continuity policy, the handling, classification and reporting of ICT-related incidents, testing of digital operational resilience, management of ICT third-party risk, and the notification duty for information-sharing arrangements. Alongside this, section 12(2) No 4 now asks whether the internal audit function is set up as required by Article 24 of Delegated Regulation (EU) 2017/565 and performs its tasks effectively, and a rewritten section 17 requires an assessment of trading-book compliance under Article 21(2) of Regulation (EU) 2019/2033 and Part 3, Title I, Chapter 3 of Regulation (EU) No 575/2013.
For Schwarmfinanzierungsdienstleister, the Schwarmfinanzierungsdienstleister-Prüfungsverordnung mirrors the change: section 2 adds the DORA duties to the audit scopeBund, a new section 11a imposes the same ICT reporting and compliance assessment unless the DORA provisions are already audited under section 78(1) of the Wertpapierinstitutsgesetz or section 29 of the Kreditwesengesetz, and a new item 32 in the annex adds DORA Articles 5 to 14, 16 to 19, 23 to 25, 28 to 30 and 45(3) to the examination areas.
Both sets of DORA-related provisions apply for the first time to accounting documents and audits covering a financial year beginning after 31 December 2024Bund; earlier years remain under the previous versions of the two ordinances
Bund.
The Wirtschaftsprüferkammer (WPK) flagged the ordinance on 15 September 2026, noting that it extends the auditor's duties at small and medium-sized Wertpapierinstitute and at Schwarmfinanzierungsdienstleister, with a corresponding rise in audit fees. The WPK had opposed the extension during BaFin's 2024 consultation.
Legal basis: BaFin ordinance of 26 August 2026 amending the Wertpapierinstituts-Prüfungsberichtsverordnung and the Schwarmfinanzierungsdienstleister-Prüfungsverordnung (BGBl 2026 I Nr. 256), giving effect to Regulation (EU) 2022/2554 in statutory auditsBund.
Auditors of small and medium-sized Wertpapierinstitute and of Schwarmfinanzierungsdienstleister should extend their audit programmes for financial years beginning after 31 December 2024 to cover the DORA ICT reporting and compliance assessment in section 15 of the Wertpapierinstituts-Prüfungsberichtsverordnung and section 11a of the Schwarmfinanzierungsdienstleister-Prüfungsverordnung.