Financial Market Regulation.

Regulatory advice for banks, investment firms, funds, and FinTechs — with direct access to BaFin and ECB.

Classification

Regulation that enables.

Financial market regulation shapes business models — from licensing requirements to capital requirements and product design.

We advise supervised institutions, fund initiators, asset managers, and FinTechs on all regulatory matters — pragmatically, solution-oriented, and with direct access to supervisory authorities.

Range of Services

What we handle for you.

01

Licensing Procedures

BaFin and ECB licenses, ownership control, management qualification

02

KWG, WpIG & WpHG

Banking supervisory law, investment firm law, and securities trading law.

03

Company Acquisitions & Sales

Management companies, depositaries, product structuring.

04

MiFID II / MaRisk / MaComp

Conduct of business rules, governance, remuneration, outsourcing.

05

FinTech & Crypto

Crypto custody, MiCA, payment services (ZAG), e-money.

06

Enforcement & Sanctions

Support during special audits, administrative proceedings, and sanctions.

Who We Work For

Clients seeking clarity.

  • K
    Banks and Investment Firms
  • K
    Capital Management Companies
  • K
    Asset Managers and Family Offices
  • K
    FinTechs and Crypto Providers
  • K
    Payment Service Providers
  • K
    Asset Managers and Fund Initiators

Our Approach

How we work.

Pragmatic

Regulation should enable business. We develop solutions that are legally sound and economically viable.

Experienced

We regularly support proceedings before BaFin, Deutsche Bundesbank, and the ECB and are familiar with regulatory requirements in practice.

Structured

We resolve complex regulatory issues with clear processes, precise analysis, and efficient implementation.

International

European regulation does not stop at national borders. We support cross-border structures and international financial market participants.

Process

From the first meeting to completion.

I

Mapping

Licensing requirement, applicability, license needs.

II

Concept

Regulatory mapping of business model and governance.

III

Application

Complete application documents, support during the process.

IV

Implementation

Policies, processes, reporting.

V

Ongoing Consulting

Execution, post-closing, implementation.

Insights

Clarity in minutes.

Clarity remains the strongest regulatory advice for banks, investment firms, funds, and FinTechs (BaFin/ECB).

A golden hourglass on a white background, with the heading What it really costs

FAQ

Frequently Asked Questions.

Do you have a specific question? We will respond within 24 hours.

What is understood by banking supervisory law and financial market regulation?

This includes the rules that determine who may offer financial services, which licenses are required, and which ongoing organizational, capital, risk, and compliance obligations institutions must adhere to.

When do I need a license under KWG, ZAG, or KAGB?

Typically, when a business model involves banking transactions/financial services (KWG), payment services or e-money (ZAG), or fund management/investment business (KAGB) – the exact classification depends on the specific product and processes.

What is a KWG license – and what is a "licensing requirement"?

A licensing requirement is a legally defined fact in the KWG (e.g., deposit business, lending business, or certain financial services) which – if met by the business model – can trigger a supervisory license. This is not only relevant for traditional banks: lending can also – depending on its design and systematics – establish a licensing requirement, for example, if it is operated commercially or in a business-like manner. Entrepreneurial financing solutions should therefore be checked early on to determine whether they are to be classified as a licensing-required business under supervisory law.

What does "Fit-and-Proper" mean in supervisory law?

"Fit-and-Proper" describes the requirements for managing directors and supervisory bodies, particularly professional suitability, experience, reliability, and sufficient time availability.

Why is "Corporate Governance" particularly relevant for regulated institutions?

Because supervisors and auditors view governance as the basis for risk and compliance management: clear responsibilities, control functions, remuneration systems, and documented decision-making processes.

What are MaRisk – and why do they appear in almost every audit?

MaRisk (Minimum Requirements for Risk Management) specify the organizational expectations of the supervisory authority – including organizational structure/processes, risk controlling, compliance, outsourcing, and documentation.

What is SREP and what is typically assessed?

SREP (Supervisory Review and Evaluation Process) is the supervisory review process in which, among other things, the business model, governance, risk profile, capital adequacy, and liquidity are assessed; results can trigger additional requirements.

What does outsourcing of "critical functions" mean – and why is it so sensitive?

For critical/material outsourcing, the supervisory authority expects, among other things, provider due diligence, minimum contract contents, steering and control rights, exit strategies, and ongoing monitoring – otherwise, objections may arise.

Which contract clauses are practically indispensable for outsourcing/IT providers?

Typical clauses include audit and access rights, sub-service provider rules, information/incident obligations, data and confidentiality, location/cloud rules, exit/transition, and clear KPIs/SLAs – aligned with supervisory requirements.

What is DORA – and what topics does it cover?

DORA (Digital Operational Resilience Act) is an EU-wide regulation on ICT risk management, incident reporting, resilience testing, and ICT third-party risks (including minimum contractual requirements). It has been in effect since January 17, 2025.

What does "DORA-Readiness" mean in practice?

It refers to the ability to operationally implement DORA requirements: governance, policies, incident management, tests, third-party management, and robust documentation (e.g., information register/provider landscape).

What is MiCAR and what is a CASP?

MiCAR (Markets in Crypto-Assets Regulation) creates an EU regime for crypto-assets. A CASP is a "Crypto-Asset Service Provider" (e.g., custody, trading, exchange, platform operation) and requires a MiCAR license – depending on the activity.

When does MiCAR practically apply – and why is the timing important?

MiCAR applies gradually; among other things, regulations for certain token categories started earlier, while the regime for services broadly became applicable at the end of 2024. Timing is important due to transition/grandfathering issues and licensing planning.

How are MiCAR, KWG, ZAG, and KAGB related in the crypto sector?

Depending on the design, crypto services can additionally trigger interfaces with banking/payment/investment law (e.g., payment processing, e-money, fund structure) – therefore, product structuring is crucial.

What does "ownership control" mean according to § 2c KWG?

This is the supervisory procedure for the acquisition/increase of qualified holdings in institutions. It examines, among other things, the reliability of the acquirer, financial strength, and influence on sound business management.

Why are M&A/JVs in a regulated environment different from "normal" deals?

Because, in addition to SPA/share deal issues, supervisory notifications/approvals, ownership control, governance adjustments, outsourcing and IT risks, and often a tight schedule with communication with authorities are relevant.

What are EMIR obligations and whom do they typically concern?

EMIR regulates, among other things, clearing, reporting, and risk mitigation obligations for OTC derivatives; depending on the constellation, financial and certain non-financial undertakings are affected.

What do LCR and NSFR mean in liquidity regulation?

LCR (Liquidity Coverage Ratio) and NSFR (Net Stable Funding Ratio) are key figures for short-term and structural liquidity, respectively – central in supervisory dialogues, funding strategy, and SREP.

What is MREL and why is it important for banks?

MREL (Minimum Requirement for own funds and Eligible Liabilities) is a minimum requirement for loss-absorbing funds/liabilities, relevant for resolution and resolvability and funding structures.

What do SAG/BRRD and "Recovery & Resolution Planning" mean?

SAG/BRRD form the framework for the recovery and resolution of institutions. Recovery & Resolution Planning concerns, among other things, recovery plans, resolution strategies, and operational implementability in a crisis.

What is market abuse (MAR) and why is it relevant even for non-listed companies?

MAR (Market Abuse Regulation) concerns insider information and market manipulation; points of contact arise, for example, via issuers, tradable instruments, project information, or insider lists/compliance processes.

What does an AML framework (anti-money laundering) typically include?

An AML framework includes risk analysis, KYC/monitoring, suspicious activity reports, training, internal controls, and clear responsibilities – often closely intertwined with sanctions/embargo screening.

What does "Enforcement" mean in supervisory law?

Enforcement comprises supervisory measures and procedures – from objections and orders to special audits, fine proceedings, and remediation programs.

What are SFDR/Taxonomy and what does "Sustainable Finance Compliance" mean?

SFDR and EU Taxonomy regulate ESG disclosure and the classification of sustainable activities; relevant aspects include governance, product disclosure, data processes, and consistent communication (also to avoid greenwashing risks).

Which supervisory authorities are responsible for banks and financial service providers in Germany?

In Germany, BaFin as the central financial supervisory authority and the Deutsche Bundesbank are typically involved in ongoing supervision and audits. Depending on the type and size of the institution, European institutions may also be involved, particularly within the Single Supervisory Mechanism (SSM).

What role do the ECB and SSM (Single Supervisory Mechanism) play in banking supervision?

The SSM is the European supervisory system in which the ECB directly supervises significant institutions, while national authorities (e.g., BaFin/Bundesbank) remain involved in supervision. Less significant institutions are usually still supervised nationally, but within the framework of the SSM.

What are EBA/ESMA/EIOPA and why are these authorities practically relevant?

The EBA (banks), ESMA (capital markets), and EIOPA (insurance) are EU authorities that develop technical standards, guidelines, and interpretative aids. Even if they do not always issue direct "supervisory decisions," their guidelines significantly shape supervisory practice and thus requirements for governance, reporting, and compliance.

What does "EU Passporting" (EU passport) mean in financial supervisory law – and how does it work in practice?

EU Passporting allows regulated companies to provide certain financial services cross-border within the EEA, either through a branch or under the freedom to provide services. In practice, this is done via a notification procedure: the institution notifies its home NCA (National Competent Authority) in which countries and with which activities it intends to operate; the home NCA informs the competent authorities in the host state. Depending on the regime (e.g., MiFID context), the content and form of the notifications are standardized in detail.

How does passporting from Luxembourg (CSSF) work – e.g., to Germany?

For Luxembourg institutions, notification typically occurs via the CSSF as the competent home supervisory authority. The CSSF describes the "European passport" processes and the submission of notification documents (including changes/termination) via the designated channels/portals for various types of institutions (e.g., credit institutions, investment firms).

Is there also "passporting" to Switzerland – and how is FINMA to be classified in this context?

Switzerland is not part of the EU/EEA passporting system. Cross-border activities with a Swiss connection must therefore be structured according to Swiss supervisory law; the central contact point is FINMA as the Swiss Financial Market Supervisory Authority. Whether and which local obligations (e.g., approvals, conduct/organizational obligations, possibly registrations/connections) are triggered depends heavily on the business model and the target clientele.

Regulation that supports.

Contact us — we will analyze your project from a regulatory perspective and show you the fastest way to implementation.

Q