The next audit is knocking on the door?
We support you in implementing your test and quality processes in an audit-proof manner.
Audit readiness for banks and financial service providers - pragmatic and DORA-compliant
DORA, MaRisk, BAIT, ICT governance - the regulatory requirements for your testing and QA processes are becoming more stringent and the audit intervals shorter. We ensure that your test processes, documentation and governance structures can withstand a BaFin audit. Without paper tigers, without a proliferation of tools - with lean standards that your teams actually live by.
Less technology. Better business.
How confident could you provide information on these points during an audit?
-
How up-to-date and ICT governance-compliant are your test and QA concepts?
-
Can you trace requirements back to test cases and test results without any gaps?
-
Are acceptances, residual defects and management decisions documented in an audit-proof manner?
-
How well are specialist departments, service and cloud service providers integrated into the testing process?
-
Are test data, authorization and environment management DORA and GDPR-compliant?
What you get from our audit preparation
Your test and QA structures comply with DORA, MaRisk and BAIT. You go into the audit with clear documentation and reliable evidence - not a gut feeling.
We show you where the critical gaps are and what needs to be closed first. Not a collection of measures, but a risk-based roadmap.
Processes that your teams actually live by - instead of governance that falls asleep again after the audit. We pay attention to practicality, not mountains of paper.
We are not just consultants, but also play an operational role - from test planning to BaFin audit support. Regulatory know-how and project experience from a single source.
Most institutions have solid testing processes - but not in the form that DORA requires. Our task is to close this gap without compromising operations.
Our solution: three modules that interlock
Depending on the initial situation, we start at the right point - whether it's a quick assessment of the current situation, structured development or operational support in day-to-day project work.
Your test and resilience requirements are becoming significantly more complex with DORA - do your current structures stand up to a supervisory review? Our Quick Check gives you a well-founded assessment of your current situation in a short space of time. We analyze your test processes, documentation and tool landscape and systematically compare them with the requirements of DORA. You receive a clear gap analysis with a prioritized roadmap - as a reliable basis for decision-making for you and your management.
Our service:
- As-is analysis of test processes, documentation and organization
- Comparison with DORA guidelines
- Evaluation of test coverage in the SDLC and for critical business processes
- Review of audit security and traceability of acceptances and decisions
- Analysis of the security testing maturity level
- Inventory of test data, authorization and environment management (DORA, GDPR)
- Assessment of ICT resilience test readiness (incl. third-party and cloud services)
- Gap analysis along the DORA requirements for ICT risk management and ICT resilience testing
- Risk assessment of identified gaps (regulatory and operational risks)
- Action plan and specific recommendations for action with prioritization
You know where the gaps are - now it's time to close them in a structured way. We work with you to set up test processes, documentation and governance structures that meet DORA requirements. In doing so, we pay attention to practicality: no paper tigers, but lean standards that your teams can actually use and live by. The result is a resilient test framework that will carry you through every test.
Our service:
- Development or sharpening of a company-wide test strategy in line with DORA
- Introduction of risk-oriented test planning based on protection requirements and criticality analyses
- Establishment of consistent test processes and audit-proof documentation across all test stages
- Creating a security and resilience testing concept and integrating it into CI/CD and change processes
- IDV test concept and GDPR-compliant test data management
- Definition of regulatory test KPIs and integration into risk and MaGo/DORA reporting
- Anchoring roles, responsibilities and escalation paths in the ICS and IT governance
Standards on paper are only half the battle - it is crucial that they are put into practice in day-to-day project work. We support you operationally: from test planning and implementation to regulatory reporting. Whether ongoing projects, DORA resilience tests or the next BaFin audit - we bring hands-on experience and regulatory know-how directly to your teams.
Our service:
- Risk-oriented test planning, control and defect management in ongoing projects
- Implementation of functional, non-functional and security tests
- Preparing and supporting BaFin audits and internal audits
- Coaching teams in DORA-compliant testing and documentation
- Setting up test automation and integrating it into CI/CD pipelines
- Ensure regular compliance monitoring and stakeholder reporting
No matter where you stand: Our quick check provides clarity in two weeks. Well-founded gap analysis, prioritized roadmap, reliable basis for decision-making.
Who particularly benefits from our audit preparation
Our services are aimed at banks, capital management companies, insurers and financial service providers that fall under DORA, MaRisk or BAIT and need to raise their testing and QA processes to regulatory standards. Typical requirements include evolved IT landscapes, multiple cloud and service providers and a mixture of traditional software development and regulated specialist applications.
Our references & projects
A reference is worth more than 1,000 words. Fortunately, we have dozens of them. Click through a selection of our most exciting projects and see for yourself!
-
Virtualization of software testing for control units in the AWS cloudDigital twins for control units: can be tested worldwide, without waiting for hardware. Faster development, lower costs and more flexibility for the team.To the BMW referenceVirtualization of software testing for control units in the AWS cloudTo the BMW referenceProject durationsince June 2023
Digital twinEfficient software development
Integrationin AWS cloud
-
STARTRAIFF: Business Intelligence for the sales forceTo the STARTRAIFF referenceWe developed a web application for the sales force of an insurance company to improve their access to information. The application bundles and prepares data that is analyzed using AI.
STARTRAIFF: Business Intelligence for the sales forceTo the STARTRAIFF referenceDashboardfor more business intelligence
AI bundlesand analyzes customer data
Sales saves60 minutes per customer visit
-
MAN - ATLAS L4. Control Center for the autonomous truckTo the MAN referenceWe developed a control center for MAN's autonomous truck. This comprises basic remote functions, including monitoring, remote support, mission handling and reporting functions. The functions are constantly being expanded to meet operational and regulatory requirements.
MAN - ATLAS L4. Control Center for the autonomous truckTo the MAN referenceControl Centerfor driverless trucks
Visualizationof the vehicle data
Research projecton autonomous driving
-
NOW: National Organization for Change in Mobility: development of a data warehouse systemTo the NOW referenceA country is electrifying itself - the National Organization for Change in Mobility is coordinating the expansion. In just five months, we developed a cloud-based data warehouse that integrates and evaluates data sources. Efficient processing for well-founded decisions in the e-mobility sector.
NOW: National Organization for Change in Mobility: development of a data warehouse systemTo the NOW referenceProject duration5 months
Cloud data warehouseSecure data integration
TeamData and software engineers
-
NETZSCH: Development of an IoT platformTo the NETZSCH referenceThe machine and plant manufacturer has three business divisions for which it wants to establish a standardized IoT platform. Existing IoT solutions are to be harmonized on this platform.
NETZSCH: Development of an IoT platformTo the NETZSCH referenceProject durationsince August 2024
Standardized IoT platformfor three business divisions
Fast testingin a cloud infrastructure
-
OroraTech - Security & Compliance SupportTo the OroraTech referenceOroraTech GmbH is a start-up founded in 2018 that uses satellite data to provide high-quality temperature data of the earth. Its main application is the early detection and ongoing monitoring of forest fires. Other applications are already being piloted.
OroraTech - Security & Compliance SupportTo the OroraTech referenceProject duration:February 2025 to May 2025
Procedure4x6, ThreatSea, workshops, interviews, questionnaires
TeamSecurity Architects and IT Consultants
-
TK Elevator: Health Check Connectivity for the IoT gateway of elevatorsTo the TKE referenceThe IoT gateway is the linchpin for the increasing digitalization of elevators. Within 6 weeks, we put the quality of the software, hardware and operation through their paces.
TK Elevator: Health Check Connectivity for the IoT gateway of elevatorsTo the TKE referenceIoT gatewayconnects elevator with IoT platform
Code analysesand 22 interviews & workshops
Optimizationof the connectivity of the gateways
-
inCTRL Solutions: Modernization of the IoT platform for water treatment plantsTo inCTRL referenceWe are making the opsCTRL IoT platform highly resilient, maintainable, and capable of further development. New functions can be integrated into products more quickly.
inCTRL Solutions: Modernization of the IoT platform for water treatment plantsTo inCTRL referenceRenovationof the IoT platform
Maintenance & new featuresgo hand in hand
Change code quicklythanks to CI/CD pipelines
-
TÜV NORD: IT system for damage assessmentsTo the TÜV Nord referenceWith the cloud-based system, TÜV NORD experts can efficiently prepare and invoice damage assessments and vehicle valuations. Car dealerships can order spare parts directly after the damage calculation, which shortens the repair time by at least 2 working days.
TÜV NORD: IT system for damage assessmentsTo the TÜV Nord referenceSince August 2023in productive operation
2 daystime savings for garages
Operation of the systemand the virtual infrastructure -
University Medicine Frankfurt - Mixed reality for the training of doctorsTo the Mixed Reality referenceWe developed a knee training simulator with the University Medical Center Frankfurt. Thanks to the mixed reality application, medical students and specialists will be able to examine the human knee in detail.
University Medicine Frankfurt - Mixed reality for the training of doctorsTo the Mixed Reality referenceProject durationfor 4 years
Virtual RealityTechnology-supported medical training
3DInteractive training environment
-
Health.exe: AI-supported platform creates training plans for patientsTo the Health.exe referenceWe developed a cloud-based platform that uses AI to automatically generate tailored treatment recommendations for patients based on a small number of medical parameters.
Health.exe: AI-supported platform creates training plans for patientsTo the Health.exe referenceProject duration5 months
AI in HealthcareServices for orthopaedics
Simple integrationin practice systems
-
Research: AI-supported robotics for employees with physical limitationsSee robotics referenceWith demographic change, employees with physical limitations need better support to remain productive. Assistance robots can help, but are not flexible enough. The KiRo4LeMi research project aims to use AI to dynamically adapt robots to individual changes in performance. Using digital models and "living personas", the AI optimizes robot operation in real time.
Research: AI-supported robotics for employees with physical limitationsSee robotics reference3 yearsresearch project, funded by the Bavarian Ministry of Economic Affairs
Design of the robotmore individuality thanks to AI
Digital twinhelps to be able to react quickly during operation
-
MAN: Efficient threat analysis for control unitsSee MAN referenceDigitalization increases cyber risks - especially for MAN's new CM4 control unit. Our experts use the 4×6 methodology and ThreatSea to identify threats at an early stage and develop targeted protective measures. Find out how MAN uses intelligent risk analysis to strengthen the security of its vehicles.
MAN: Efficient threat analysis for control unitsSee MAN referenceProject duration7 months
Over 20 workshopsThreat analyses
Over 500Potential risks evaluated
-
Siemens: AI demand prediction platform for industrial production planningSee Siemens referenceSiemens is looking to the future with the AI Demand Prediction Platform. Thanks to machine learning and AutoML, precise demand forecasts can be created for over 100 products and production can be better planned. Launched as a proof of concept, the platform quickly developed into a system that can be used productively. The self-service web application will soon be used in other plants.
Siemens: AI demand prediction platform for industrial production planningSee Siemens referenceProject durationsince February 2022
Proof of conceptin a few weeks
Time series predictionfor 100 different products
-
TÜV NORD GPT: Development of AI assistanceSee TÜV NORD referenceFind relevant information faster by chatting with documents? It's possible! The TÜV NORD GROUP uses GPT technology in the secure Microsoft Azure Cloud. With the aim of optimizing knowledge management and efficiency. The system enables new usage options within the testing group and is operated securely. Find out more about the innovative AI assistance system now.
TÜV NORD GPT: Development of AI assistanceSee TÜV NORD referenceProject durationsince September 2023
33.000GPT applications in the first month
ChatGPT Model 4in the European Microsoft Azure Cloud
-
Schöck components: Improvement of the requirements processSee Schöck Bauteile referenceTogether with MaibornWolff, the construction industry specialist optimized the requirements management of its Scalix design software. Thanks to the digital design approach, the technical requirements were re-specified and the software was further developed in a user-centered manner. The aim is to continuously increase user satisfaction and integrate internal and external interests. Read more about the methodology and results now!
Schöck components: Improvement of the requirements processSee Schöck Bauteile referenceProject durationsince 2022
Team size2-3 Digital Designer:inside
In 2024Scalix replaces old software -
VW: Digitization of key production figures with the iProcess appSee VW referenceLess paper, more efficiency: Volkswagen replaces analog processes with the iProcess app. Cloud-native technologies and digital design enable intuitive recording and analysis of key production figures. This increases transparency and overall equipment effectiveness and paves the way for predictive maintenance at the automotive group.
VW: Digitization of key production figures with the iProcess appSee VW referenceProject durationsince January 2021
Team size5 to 10 persons
Fast app developmentthanks to Digital Design
-
digikoo GmbH: Apple Vision Pro for city plannersSee digikoo referencePlanning cities smarter: Together with TUM, we developed the 3Digipad for Apple Vision Pro. It visualizes complex energy data in 3D and makes scenarios intuitively tangible. Dynamic building data and KPIs support urban planners in making sustainable decisions.
digikoo GmbH: Apple Vision Pro for city plannersSee digikoo referenceProject duration4 months
3D map with KPIsDisplay building data dynamicallyEnergy dataImmersive visualization -
Miele domestic appliances are networked worldwideSee Miele referenceHow do household appliances become smart? Miele relies on an IoT platform that we played a key role in developing. Container-based architecture ensures stable communication, DevOps for continuous improvement - so that smart appliances can be found in millions of households worldwide.
Miele domestic appliances are networked worldwideSee Miele referenceProject durationsince 2016
Success factorshigh availability and scalability
IoT platformwith container-based architecture
-
BMW Group: Replacement of a production-critical legacy systemSee BMW Group reference20-year-old system, new digital future. We gradually migrated production software to a flexible architecture. After two years, central plants were running on the new solution - stable, fail-safe and ready for the challenges of tomorrow.
BMW Group: Replacement of a production-critical legacy systemSee BMW Group referenceProject durationMid-2018 to the beginning of 2024
Team size25 employees
Legacy systemreplaced after 20 years
-
Mixed reality: driving a real car in a virtual worldSee BMW referenceVirtual racing in a real car? MaibornWolff made it possible for the BMW M. Within three months, we used Unreal Engine 4 to develop a prototype that processes vehicle signals with high performance and creates an immersive driving experience without motion sickness. The cockpit remains real, the surroundings become the racetrack.
Mixed reality: driving a real car in a virtual worldSee BMW reference<3 monthsFrom the vision to the prototype
3D applicationsin real time
TeamUnreal development, XR technology, game design, smart devices, 3D content
-
KUKA: Web interface for a new Human Machine InterfaceSee KUKA referenceRethinking robotics: KUKA is working with us to develop iiQKA.OS - an operating system with an intuitive web HMI. Using web technologies and scrum methods, we enable flexible customization and simple control. Open collaboration makes robotics more accessible than ever before.
KUKA: Web interface for a new Human Machine InterfaceSee KUKA referenceGoalReplacing the current control software
iiQKA.OSFast and intuitive development
> 11,000 hoursProject work
-
STIHL: Control iMOW robotic mower via appSee STIHL referenceRobot mower redefined: The iMOW from STIHL makes lawn care smarter. Our software expertise combined with STIHL's hardware know-how ensures intuitive app control. The result? A networked device that makes gardening easier - simple, efficient, innovative.
STIHL: Control iMOW robotic mower via appSee STIHL referenceProject durationsince August 2020
Robot mowerControl via app
Process optimizationwith the customer
-
ifm services: Remote maintenance of systems and machinesSee ifm services referenceMaintenance, anywhere and at any time - together with ifm services, we developed a remote access solution for industrial plants. A small, agile team created a full-stack cloud application that combines intuitive operation and secure connectivity. The product celebrated its premiere at HMI 2024.
ifm services: Remote maintenance of systems and machinesSee ifm services referenceProject durationsince March 2023
Remote Accessintegrated in platform
Team5 Developers
-
DER Touristik Online: Development and migration of a multi-client capable travel booking platformSee DER Touristik referenceDifferent brands, one platform: DER Touristik merges several independent websites. We are supporting the migration to the AWS cloud with digital design, microservices and testing. The focus is on performance, SEO and UX - for a seamless digital travel experience.
DER Touristik Online: Development and migration of a multi-client capable travel booking platformSee DER Touristik referenceStandardized platformMulti-client travel portalQuality assuranceEnd-2-End test automationCloud transformationMigration to AWS cloud -
MAN: Secure Software Development Life CycleSee MAN referenceTrucks are networked - and therefore unfortunately also targets for attack. With SSDLC, MAN relies on security by design and integrates the highest security standards directly into development. Together with 22 teams, we have established security measures that go beyond the legal requirements.
MAN: Secure Software Development Life CycleSee MAN referenceProject duration22 months
UNECE R155successfully integratedMethodsSecurity Champions, DevSecOps, OWASP SAMM
-
Bayernwerk: Knowledge management via teamsSee Bayernwerk referenceExperience must not be lost - Bayernwerk digitizes the knowledge of long-standing employees. MaibornWolff designed an intuitive MS Teams app with a clear UX/UI. Close collaboration, lived Scrum values and user-centered development make the app a success. Promoting exchange, optimizing processes - this is how knowledge transfer works today.
Bayernwerk: Knowledge management via teamsSee Bayernwerk referenceProject duration6 months
Target:Identify implicit knowledge
Requirements:a user-centered, intuitive and clear UX/UI design
-
Es geht LOS: Development of a cloud-based application for citizen participationSee Es geht LOS referenceDemocracy meets digitalization: For "Es geht LOS!", we developed a cloud-based app for candidate management in five weeks. Built on AWS, it enables secure draws and efficient user management - for more citizen participation digitally.
Es geht LOS: Development of a cloud-based application for citizen participationSee Es geht LOS referenceStrengthening democracythrough random selection
Recruit candidatesfor citizens' councils via app
In 5 monthsfrom concept to prototype with AWS Amplify
-
Monitoring alarms in industrial plantsSee referenceSafety in industrial plants requires a real-time overview. We developed a live monitoring platform that networks measuring devices and collects data via Azure IoT and Kubernetes. A scalable MVP was created in just three months: alarms appear in under ten seconds thanks to automated data acquisition via smartphone and Bluetooth.
Monitoring alarms in industrial plantsSee referenceProject duration3 years
<3 monthsto the MVP
Cloud migrationmodernization & relocation -
Planning systems: Optimizing the capacity utilization of pressing plantsSee referenceMaximum capacity utilization, minimum costs: Our customer relies on a central planning system for pressing plants. We have been supporting its further development with .NET Core, GraphQL and PostgreSQL for over ten years. Now the journey is moving to the cloud - for greater scalability, flexibility and efficiency.
Planning systems: Optimizing the capacity utilization of pressing plantsSee reference>10 yearsCustomer support
Technological modernizationCloud-ready platformEfficiency through dataSite-specific cost planning -
Global workforce planning systemSee referenceHow do you achieve globally harmonized workforce planning? With a modern web application based on domain-driven design and hexagonal architecture. Event sourcing ensures transparent traceability, while Azure and Quarkus provide stability and scalability. The result: a flexible, future-proof solution.
Global workforce planning systemSee referenceTeam sizeup to 8 employees
Domain Driven Designdevelopment approach
Microsoft Azure Cloudallows easy roll-out of new versions
-
DER Touristik: Become a digital travel companion in 7 monthsSee DER Touristik referenceTravel information, bookings, support - all in one app. With Flutter, MaibornWolff developed a cross-platform solution for DER Touristik. In just seven months, a stable app was created for iOS and Android that supports multiple brands, languages and countries. This is how customer proximity travels.
DER Touristik: Become a digital travel companion in 7 monthsSee DER Touristik reference7 monthsFrom Kickoff to Go Live
iOS and AndroidDigital travel companion
Whitelabelling solutionUncomplicated integration of additional brands, languages and countries
-
KUKA: UI/UX design for an app for load data analysis for industrial robotsSee KUKA referenceHow do you reduce support requests? With a smart UX! KUKA and MaibornWolff developed a web-based application for load data analysis. Through "Understand/Build/Learn" we recognized challenges early on and validated solutions for an intuitive user experience.
KUKA: UI/UX design for an app for load data analysis for industrial robotsSee KUKA referenceMethodProduct Experience Design
Customer requestEasier interaction between users and the system
Our goalOptimized load data analysis, fewer support requests, higher satisfaction -
DEKRA: Modern enterprise architecture thanks to co-creationSee DEKRA referenceNew IT for a sustainable future: the global auditing group needed to modernize its IT landscape. Co-Creation created a harmonized architecture and the EA Community promotes cross-border exchange for strong IT until 2025 - and beyond.
DEKRA: Modern enterprise architecture thanks to co-creationSee DEKRA referenceMost important method:Building an EA community
Created conceptEnterprise Architecture
Cooperationat eye level
-
BMW Group: Remote software upgrade for vehiclesSee BMW Group referenceNo visits to the workshop, no stress - thanks to Remote Software Upgrade, BMW vehicles worldwide remain up-to-date "over-the-air". MaibornWolff has been developing and operating the backend for secure updates for over three years. Microservice architectures and DevOps approaches guarantee stability, performance and security.
BMW Group: Remote software upgrade for vehiclesSee BMW Group referenceProject duration5 years
Millions of vehiclesreceive new features thanks to "over-the-air" upgrade
IT securityAlways up-to-date thanks to remote software upgrade
-
digikoo: A data platform for the Azure CloudSee digikoo referenceStructured geodata, automated quality assurance, seamless provision - we developed a powerful Snowflake data platform on Azure for Digikoo. It makes analysis easier for data scientists and lays the foundation for precise forecasts and new use cases.
digikoo: A data platform for the Azure CloudSee digikoo referenceProject duration5 months
Climate changePlan digitally and implement efficiently
Foundation data platformMicrosoft Azure Cloud
-
Creditreform: Secure proof of identity on the webSee Creditreform referenceVerifying online identities in a forgery-proof manner while maintaining user-friendliness - CrefoTrust makes it possible. Together, we developed a solution that creates trust with blockchain technology and proofs of concept. Personal and company data remain protected, while verifications run smoothly.
Creditreform: Secure proof of identity on the webSee Creditreform referenceProject duration:5 years
Pilot testsbased on several PoCs
Decentralized identityallows tamper-proof storage of identities and company information
-
SMA: Development of a Web UI for ennexOS platformSee SMA referenceOptimizing energy flows, reducing costs - we have been developing the Web UI of the ennexOS platform with SMA Solar Technology since 2016. It digitizes energy management processes for over a million users and combines smart solutions for a sustainable energy future.
SMA: Development of a Web UI for ennexOS platformSee SMA referenceProject durationsince 2016
> 1.000Modules and components in ennexOS platform
> 7.000Fuse tests
-
Weidmüller: Progression of the Industrial Service PlatformSee Weidmüller referenceIoT meets agility - Weidmüller and MaibornWolff developed the easyConnect platform for remote access, data visualization and machine learning. After intensive exploration, an MVP was created, accompanied by a cross-functional Scrum team. Making Industrial IoT smarter and more efficient.
Weidmüller: Progression of the Industrial Service PlatformSee Weidmüller referenceApprox. 7 monthsup to the MVP
8 weeks analysisof professional, technical and organizational factors
Innovative portalfor end-to-end solutions
-
BMW Group: Virtual reality brings vehicle design to lifeSee BMW Group referenceFrom the first draft to series production - BMW uses VR to visualize the entire development process. Based on the Unreal Engine, a uniform platform visualizes designs and processes. This saves on hardware prototypes and enables location-independent collaboration. MaibornWolff plays a key role in driving the development and integration of these VR use cases.
BMW Group: Virtual reality brings vehicle design to lifeSee BMW Group referenceProject duration3.2 years
CooperationLocation-independent and virtual
InfrastructureScalable and expandable thanks to the cloud
-
Travel information systems: 25 percent savings in cloud costs and stable operation thanks to FinOpsTo the FinOps referenceCloud transparency and FinOps governance for a networked travel information system - with clearly measurable savings and less operational risk.
Travel information systems: 25 percent savings in cloud costs and stable operation thanks to FinOpsTo the FinOps referenceCloud operating costsreduced by 25%
Reductionof the availability zones in the development environment
Time-controlled switch-offof the development environment
-
Supply chain management: Reducing cloud operating costs by 50 percent with FinOpsTo the FinOps referenceWe have made the supply chain management system for an international industrial company more scalable and robust through process modernization, improved monitoring, automation and rightsizing. Targeted optimization of the infrastructure reduced oversizing and unnecessary resources - the platform is more stable.
Supply chain management: Reducing cloud operating costs by 50 percent with FinOpsTo the FinOps referenceLoweringof the cloud operating costs
Fastto the new release
More transparencyand control
Frequently asked questions about audit preparation
What does DORA specifically require of test and QA processes?
DORA (Digital Operational Resilience Act) requires financial companies to have a risk-based, documented and traceable approach to ICT risks - and this explicitly includes testing. Specifically, this means that their test processes must take into account the criticality of applications and business processes, include third-party providers and cloud services, cover resilience and security tests and document acceptances, defects and management decisions in an audit-proof manner. In addition, there are extended requirements for ICT resilience tests that go far beyond traditional functional tests. We systematically compare your existing test and QA structures with these requirements and show you where specific improvements need to be made.
How long does an audit preparation take until BaFin readiness?
This depends heavily on your starting position. Our Quick Check delivers a reliable assessment of the current situation with a gap analysis and prioritized roadmap in two weeks - the fastest way to clarity. The subsequent optimization and development phase typically takes three to nine months, depending on the scope. If an audit is due at short notice, we prioritize the critical gaps and prepare you specifically for the audit - including a dress rehearsal and support on the day of the audit. The decisive factor is not maximum perfection, but a comprehensible structure and reliable documentation.
Does MaibornWolff carry out audits or certifications itself?
No. We are an advisory and implementation partner, not an audit or certification body. Official BaFin audits are carried out by the supervisory authority itself or by commissioned auditors. It is precisely this separation that is important: we can prepare you for an audit independently and without any conflict of interest, set up your test structures pragmatically and support you during the audit - without becoming dependent on the subsequent audit body. We also do not offer legal advice, but work closely with your legal advisors or external law firms if required.
How do the requirements from DORA, MaRisk and BAIT differ - and do you cover them all?
DORA has applied throughout Europe since January 2025 and sets the overarching framework for digital operational resilience. MaRisk and BAIT are national BaFin regulations that are partly overlaid and partly supplemented by DORA - particularly with regard to the requirements for ICT risk management, outsourcing and test processes. In practice, this means that your test and QA structures must now comply with several sets of regulations at the same time, without resulting in parallel documentation. We rely on an integrated approach: a structure that is DORA-compliant and at the same time fulfills MaRisk/BAIT requirements - so that your teams do not have to answer the same question three times.
How do your services interact with our internal audit and the ICS?
Our work is designed to relieve internal auditing and ICS, not to replace them. We set up test and QA structures in such a way that they meet the requirements of internal audit and ICS from the outset - with clear roles, escalation paths, test KPIs and audit-proof documentation. Where appropriate, we coordinate with your internal audit department at an early stage so that auditability and the control environment are considered from the outset. The aim is for the results of our work to flow directly into your existing reporting to the Executive Board, Supervisory Board and BaFin - without an additional layer of translation.
Why MaibornWolff?
As one of the most innovative IT service providers with a great passion for AI, we focus entirely on the project business and individual software development - without our own products. To stay at the forefront, we continuously invest in our team of digital technology engineers and develop digital solutions that are well thought-out, efficient and reduced to the essentials.
Our principle: simplicity instead of complexity. We only develop what is really needed - tailor-made, useful and reliable. Our results speak for themselves. With over 800 large-scale systems and more than 10,000 person-years of experience in high-end software engineering, we are one of the few who can reliably implement even the largest and most complex IT landscapes. Thanks to close partnerships with leading hyperscalers, our customers operate their solutions in today's most modern and powerful environments.
Less technology. Better Business.