Download PDF
Our 3 Key Take-away's
Sonderprüfungen machen Strukturen, Verantwortlichkeiten und Schwachstellen sichtbar – ein wertvoller Moment institutioneller Reflexion, der aktiv genutzt werden sollte.
Institute, die Prüfungen als reine Compliance-Pflicht behandeln, schöpfen das Potenzial nicht aus. Wer sie hingegen als strategisches Werkzeug für nachhaltige Veränderung begreift, stärkt Prozesse, IT und Governance dauerhaft
Nicht die Prüfung selbst entscheidet über Erfolg oder Misserfolg, sondern die Haltung: Proaktives Denken, strukturierte Umsetzung und eine klare Vision machen aus regulatorischem Druck einen echten Entwicklungstreiber
1 Introduction
When supervisors come knocking, an intensive and potentially business‑critical phase begins for many banks. Audits by BaFin/Bundesbank or the ECB – e.g., special audits pursuant to Section 44 of the German Banking Act (KWG) – are deep‑reaching, dynamic, and require a professional approach. Without a concise strategy, such an audit can tie up substantial internal resources, disrupt operational processes, and lead to business‑damaging consequences. With the right preparation and targeted support, however, you can not only master the challenges but also gain important insights for the further development of the organization.
2 Special Audits: The Process
Special audits by banking supervisors follow a clearly structured yet highly dynamic process. From the announcement to the remediation of findings, an audit goes through six key phases:

Fig. 1 - Phases of the special audit
1. Audit preparation: Immediately after the announcement, the race against time begins. Set up an internal project management office that clearly defines responsibilities, creates a realistic schedule, and ensures the availability of critical resources. This early structuring largely determines the entire course of the audit.
2. Document submission: Supervisors request extensive documentation that must be provided on time and in high quality. Implement a central document repository with systematic versioning and quality assurance. This not only ensures traceability but also prevents critical inconsistencies between different departments.
3. Interview preparation: Thorough preparation of the interviewees is crucial for the impression made on the auditors and later for the quality of the report. Through structured mock interviews and binding communication guidelines, you retain control over the audit process and avoid unnecessary findings caused by uncoordinated statements.
4. Conducting interviews: Most findings arise in direct discussions with the auditors. Appear confident yet factual, demonstrating your technical expertise. Through systematic debriefings after each interview, you document key statements.
5. Reporting phase: This is where initial findings become visible and the course is set for the final report. Implement a structured process to validate the auditors’ statements for factual accuracy – auditors can also misinterpret circumstances. An orderly involvement of the management board in this process is essential and strengthens your position.
6. Remediation and follow‑up: Even during the reporting phase, you should begin planning and addressing initial indications. Develop a binding action plan with clear milestones and continuous reporting to senior management. Consistent adherence to timelines is critical – ignoring the report can lead to significant economic damage for the institution.
3 Mastering the Audit with Confidence
A successful audit is built on experience and a well‑orchestrated approach. The following best practices have proven particularly effective in practice:

ig. 2 - IT special audits: Process – Best Practices – Self Assessment
Central Coordination
Operations Control Center: Establish a central coordination room with daily, focused 15‑minute updates instead of time‑consuming recurring meetings. Especially in audit preparation and during the intensive interview phase, this approach prevents information gaps and ensures rapid decision‑making.
Central editorial team: All documents and communication should be checked for consistency by a dedicated team. This is essential for document submission, but also pays off in all other phases.
Clear allocation of roles: Define binding responsibilities for each phase of the audit from the outset. Establish a strict separation between the operational team handling the audit and creating documents on the one hand, and the (senior) management level making strategic decisions on the other. Particularly important: Appoint a lead for each interview to conduct the discussion and a dedicated note‑taker.
Documentation and Consistency
Single source of truth: Create a central data foundation with all audit‑relevant metrics and facts. Ensure all team members access the same reference data. This basis should be established before document submission and maintained throughout the audit.
Interview log: Complete documentation of all discussions, commitments, and open points is indispensable. After each interview, a debrief with all participants should take place to clarify misunderstandings and contradictions immediately.
Findings dashboard: As soon as initial indications of potential findings arise, they should be captured centrally, prioritized, and assigned concrete responsibilities. Begin planning measures during the audit, not only after receiving the final report.
Avoidable Mistakes
Ad‑hoc/retroactive documentation: Documents created retroactively are recognized immediately by experienced auditors. Focus instead on the quality and consistency of existing documentation.
Defensive stance: A justificatory or defensive position regarding findings significantly worsens the audit climate. Demonstrate constructive acceptance and proactive willingness to address issues.
Quick fixes: Short‑term superficial solutions without sustainable process adjustments convince neither auditors nor solve the underlying problems. Use the free minutes during the audit instead to fully understand the auditors’ statements and the substantive rationale, so that your remediation planning captures the intent of the finding.
4 Viewing the Situation Through the Auditors’ Lens
A self‑assessment puts you in the auditors’ position and identifies weaknesses before the actual audit. This includes both target‑to‑target and target‑to‑actual comparisons in view of the regulatory requirements relevant to the institution [e.g., DORA; MaRisk, etc.]. This critical self‑reflection is often uncomfortable, but indispensable. Three core aspects are at the center:
Process forensics– Trace selected key processes [e.g., risk management] from start to finish through all involved departments. This deep‑dive reveals deviations between target processes and lived practice–exactly what auditors willidentifyfirst.
Documentation review– Critically examine your documented policies and procedures for consistency and up‑to‑dateness.Pay particular attention to cross‑references and potential contradictions between different rulebooks.
Governance effectiveness– Honestly assess how effective your control mechanisms really are. Does the three‑lines‑of‑defense model work asintended? Are escalation paths not only defined but also practical?
5 Support: External Assistance Creates Added Value
Successfully supporting a special audit requires more than just theoretical knowledge or formal qualifications:
Practical audit experience: Experts with experience from various special audits know the typical processes and auditors’ expectations. This knowledge helps to plan resources optimally and structure the audit process. In recent years, special audits pursuant to Section 44 KWG have increasingly focused on IT topics. This makes it ever more important to have expertise available both in compliance and in IT. As auditors have developed their knowledge in this area, it is equally important for financial institutions to build regulatory knowledge within the “core IT organization”.
Cross‑institution best practices: External consultants bring experience from numerous institutions – a pool of knowledge that is not available internally. This broader perspective enables access to proven approaches, early identification of typical pitfalls, and regulatory focal points.
Relief of internal resources: During an audit, internal subject matter experts experience an extreme workload peak. External support relieves pressure by taking over coordination, documentation, and the preparation and follow‑up of auditor interactions, allowing internal experts to focus on their critical technical contributions.
6 Conclusion: The Audit as a Transformation Opportunity
A special audit is far more than a regulatory mandatory exercise – it provides a unique window of time for organizational development. In our practice, we have repeatedly observed that intensive engagement with one’s own processes creates an institution‑wide shared understanding of the status quo.
The audit creates a rare moment of clarity in which responsibilities, workflows, and weaknesses become visible. This momentum can be leveraged: When else are such extensive resources made available to improve IT and risk management? Institutions that move beyond mere compliance thinking use this opportunity to implement structural improvements.
The decisive difference lies in the approach: Those who do not view the remediation of findings as an annoying obligation but as a strategic transformation along defined guardrails – close to the standard, with a high degree of automation – achieve sustainable improvements. The special audit thus changes from a potential risk to a valuable catalyst for the institution’s further development.
About the author(s)

Executive Advisor
Maximilian Dietz
6+ years of management consulting experience in regulatory compliance, IT security, and transformation management with a focus on financial services. Former professional work at CORE SE and NTT DATA

Executive Advisor
Mauritz von Lenthe
Industrial Engineer with 5+ years of expertise in strategic consulting, data science, and enterprise architecture. Special focus on digital platform strategy, compliance and data/AI. Former professional work at CORE SE, Digital Spine, and BMW.




