BaFin authorisation process

Turn an idea into an authorisation-ready organisation.

An authorisation process does not begin with the application. It begins with a precise assessment of the business model – and the question of how law, organisation and technology form a viable whole.

Authorisation
readiness
Business Model
Governance
Technology
Operations
Legal
Initial orientation

What are you planning?

Select an option for an initial non-binding assessment
Beyond documents

The application is only the visible tip.

Authorisation readiness emerges when the business model, responsibilities, processes and systems tell the same story.

01Application and evidence

Business plan, capital evidence, management, ownership and formal documentation.

02Policies and governance

Responsibilities, segregation of duties, controls and traceable decision-making.

03Processes and resources

From customer onboarding and AML controls to reporting lines, staffing and outsourcing.

04IT and operational resilience

Systems, information security, third parties, business continuity and robust evidence.

05The viable operating model

What is applied for must be capable of being operated, governed and audited once authorisation has been granted.

Regulatory Map

Four layers. One consistent target model.

Legislation defines the regulatory perimeter. Organisational and technology requirements determine how the firm meets it over time.

01 / ENTRY

Authorisation basis

Which activity will be performed and to what extent?

KWGWpIGZAGKAGBMiCAR
02 / ORGANISATION

Governance

How will management, controls, risk and compliance be organised?

MaRiskMaCompWpHGGwG
03 / RESILIENCE

Technology

How will systems, data and service providers remain controlled and resilient?

DORAICT RiskOutsourcing
04 / RUN

Ongoing supervision

Which notifications, reports, controls and audits apply during operations?

ReportingAuditMonitoring
Process logic

Not a straight line.
A manageable process.

1

Project

Clarify business model and target market

2

Classification

Define activities and authorisation scope

3

Architecture

Plan organisation, roles and evidence

4

Implementation

Build documentation, processes and systems

5

Verfahren

Coordinate submission and follow-up questions

6

Operations

Transfer authorisation into BAU

↶ Iteration is part of the process. Good project governance makes questions, dependencies and decisions visible early.
Strategic options

Nicht jedes Project braucht denselben Weg.

01

Own authorisation

For firms that intend to own and develop the regulated business model independently.

  • High strategic autonomy
  • Own governance and resources
  • Full ongoing responsibility
02

Partner model

Regulated services are delivered with a partner under a clearly defined allocation of roles.

  • Precise service delineation
  • Interface management
  • Transparent dependencies
03

Tied-agent model

For certain investment services, acting as a tied agent may be an option.

  • Not a universal exemption
  • Acting on behalf and under liability
  • Observe control and instruction structures

The viable structure depends on the specific activity, target model and commercial parameters. Online guidance does not replace an individual legal assessment.

Projektsteuerung

The bridge between requirements and reality.

Legal counsel defines the regulatory framework. Project management translates it into responsibilities, decisions, processes and reliable deliverables.

Project management is not an additional cost block.
It protects the investment in the process by reducing friction, inconsistent workstreams and late fundamental decisions.

01
Requirements registerConsolidate obligations, evidence and sources
connected
02
Stakeholder managementSponsors, counsel, functions and providers
coordinated
03
Consistency controlApplication, policies, processes and systems
aligned
04
Decision LogDecisions, assumptions and dependencies
traceable
05
Readiness managementFrom application to operational launch
manageable
Briefing Cards

Worth knowing

01 / Actual activity

The label does not decide.

Regulatory classification depends on what the business model actually delivers in economic terms – not merely on the label used for the product or company.

02 / Responsibility

Outsourcing does not outsource responsibility.

Providers may perform services. Requirements for selection, oversight, control and evidence nevertheless remain part of the organisational architecture.

03 / Consequences

The authorisation question belongs at the beginning.

Unauthorised business may be prohibited and wound down; personal, civil and criminal consequences may also arise.

04 / Commencement of business

Authorisation is not the finish line.

It marks the beginning of ongoing supervision. Organisation, controls and documentation must therefore be fit not only for the application, but for lasting operation.

The next useful step

Clarify the project before complexity becomes expensive.

Whether initial classification, an ongoing application or the transition to operations: the starting point is a shared understanding of the target model, roles and open decisions.

Discuss your project →