1. Home/
  2. Services/
  3. Risikomanagement/
  4. Strategisches Enterprise Risk Management/
  5. Risk Culture Risk Strategy

Subscribe to Newsletter

Stay up to date with the latest trends and developments

By subscribing, you agree to our privacy policy.

A
ADVISORI FTC GmbH

Transformation. Innovation. Security.

Office Address

Kaiserstraße 44

60329 Frankfurt am Main

Germany

View on map

Contact

info@advisori.de+49 69 913 113-01

Mon-Fri: 9:00 AM - 6:00 PM

Company

Services

Social Media

Follow us and stay up to date.

  • /
  • /

© 2024 ADVISORI FTC GmbH. All rights reserved.

Your browser does not support the video tag.
Risk Awareness at All Levels for Sustainable Business Success

Risk Culture and Risk Strategy

We help you build a strong risk culture and a clear risk strategy — from assessment through risk appetite framework design to sustainable organizational embedding. MaRisk-compliant and proven in practice.

  • ✓Strengthening organizational resilience through lived risk culture at all levels
  • ✓Strategic decision support through clear risk appetite definitions
  • ✓Optimized resource allocation through risk-adjusted performance consideration
  • ✓Improved stakeholder communication through transparent risk attitude

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

info@advisori.de+49 69 913 113-01

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Strengthening Your Risk Culture and Risk Strategy

Our Strengths

  • Extensive experience in cultural change and strategic risk management
  • Proven methods and tools for risk culture assessment and development
  • Industry-specific know-how and understanding of regulatory requirements
  • Pragmatic approach with focus on sustainable implementation
⚠

Expert Tip

A strong risk culture cannot be mandated but must be lived and continuously developed. It requires clear commitment from management, transparent communication, and consistent alignment of incentive systems with risk-oriented behavior. Successful cultural change takes time and requires patience and perseverance.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

We pursue a systematic and comprehensive approach to developing and strengthening your risk culture and risk strategy.

Our Approach:

Assessment of current risk culture and identification of strengths and development areas

Development of target risk culture and risk strategy aligned with business objectives

Design of implementation roadmap with clear milestones and responsibilities

Implementation of cultural change measures and governance structures

Continuous monitoring and adjustment of measures based on progress

"A strong risk culture and clear risk strategy are essential for sustainable corporate success. Through our structured approach, we help organizations develop a risk-aware culture that enables proactive risk management and strategic decision-making while meeting regulatory requirements."
Melanie Düring

Melanie Düring

Head of Risk Management

Our Services

We offer you tailored solutions for your digital transformation

Development and Implementation of Risk Strategy

We develop a comprehensive risk strategy that is aligned with your business objectives and defines clear risk appetite and risk tolerance.

  • Analysis of strategic objectives and risk landscape
  • Development of risk appetite and risk tolerance framework
  • Definition of risk limits and escalation mechanisms
  • Integration into strategic planning and decision-making processes

Risk Culture Assessment and Development

We assess your current risk culture and develop targeted measures to strengthen risk awareness and risk competence.

  • Comprehensive risk culture assessment through surveys and interviews
  • Identification of cultural strengths and development areas
  • Development of target culture and transformation roadmap
  • Implementation of cultural change measures and monitoring

Risk Management Governance and Leadership

We design risk-oriented governance structures and support management in their role as risk culture ambassadors.

  • Design of risk governance structures and committees
  • Definition of roles, responsibilities, and decision-making authorities
  • Development of risk-oriented leadership principles and behaviors
  • Training and coaching for management and risk owners

Risk/Return Optimization and Strategic Risk Management

We support you in integrating risk considerations into strategic planning and performance management to optimize risk-adjusted returns.

  • Development of risk-adjusted performance metrics (RAROC, EVA)
  • Integration of risk considerations into strategic planning
  • Optimization of capital allocation and resource deployment
  • Alignment of incentive systems with risk-oriented behavior

Looking for a complete overview of all our services?

View Complete Service Overview

Our Areas of Expertise in Risk Management

Discover our specialized areas of risk management

Strategic Enterprise Risk Management

Develop a comprehensive risk management framework that supports and secures your business objectives.

▼
    • Building and Optimizing ERM Frameworks
    • Risk Culture & Risk Strategy
    • Board & Supervisory Board Reporting
    • Integration into Corporate Goal System
Operational Risk Management & Internal Control System (ICS)

Implement effective operational risk management processes and internal controls.

▼
    • Process Risk Management
    • ICS Design & Implementation
    • Ongoing Monitoring & Risk Assessment
    • Control of Compliance-Relevant Processes
Financial Risk

Comprehensive consulting for the identification, assessment, and management of market, credit, and liquidity risks in your company.

▼
    • Credit Risk Management & Rating Methods
    • Liquidity Management
    • Market Risk Assessment & Limit Systems
    • Stress Tests & Scenario Analyses
    • Portfolio Risk Analysis
    • Model Development
    • Model Validation
    • Model Governance
Non-Financial Risk

Comprehensive consulting for the identification, assessment, and management of non-financial risks in your company.

▼
    • Operational Risk
    • Cyber Risks
    • IT Risks
    • Anti-Money Laundering
    • Crisis Management
    • KYC (Know Your Customer)
    • Anti-Financial Crime Solutions
Data-Driven Risk Management & AI Solutions

Leverage modern technologies for data-driven risk management.

▼
    • Predictive Analytics & Machine Learning
    • Robotic Process Automation (RPA)
    • Integration of Big Data Platforms & Dashboarding
    • AI Ethics & Bias Management
    • Risk Modeling
    • Risk Audit
    • Risk Dashboards
    • Early Warning System
ESG & Climate Risk Management

Identify and manage environmental, social, and governance risks.

▼
    • Sustainability Risk Analysis
    • Integration of ESG Factors into Risk Models
    • Decarbonization Strategies & Scenario Analyses
    • Reporting & Disclosure Requirements
    • Supply Chain Act (LkSG)

Frequently Asked Questions about Risk Culture and Risk Strategy

What is risk culture and why does BaFin require it from banks?

Risk culture describes the totality of norms, attitudes, and behaviors that shape risk awareness and risk handling within an organization. MaRisk (AT 3) requires management to develop, promote, and integrate an appropriate risk culture across all levels. BaFin emphasizes that risk culture is not a side issue but must permeate the daily thinking and actions of all employees. The 9th MaRisk amendment

2026 further tightens these requirements.

What is a risk appetite statement and how is it developed?

A Risk Appetite Statement (RAS) defines the type and extent of risks an institution is willing to take to achieve its strategic objectives. It derives from the business strategy and includes quantitative metrics (capital ratios, VaR limits, concentration thresholds) and qualitative guidelines (reputational risk tolerance, compliance principles). The RAS bridges business strategy and risk strategy and is approved by the executive board and endorsed by the supervisory board.

What is the difference between risk strategy and risk appetite?

Risk strategy is the overarching document defining objectives, principles, and measures of risk management, consistent with business strategy per MaRisk AT 4.2. Risk appetite is a subset that quantifies how much risk the institution is willing to accept. The Risk Appetite Framework (RAF) operationalizes risk appetite through limits, thresholds, and escalation mechanisms. The risk strategy contains risk appetite but also governance, processes, and reporting channels.

How do you measure and assess an organization's risk culture?

Measurement covers three dimensions: First, quantitative indicators such as risk report escalations, limit breaches, compliance violations, and whistleblower reports. Second, qualitative assessments including structured leadership interviews, tone-from-the-top analysis, and decision process observation. Third, employee surveys on risk awareness perception, psychological safety, and error handling. ADVISORI uses a proprietary risk culture assessment approach with benchmark comparison.

What role does the board play in risk culture?

Under MaRisk, the board bears overall responsibility for risk culture. It must actively demonstrate it (tone from the top), define the risk strategy, and monitor its implementation. This means: regular communication on risk appetite, incorporating risk considerations in strategic decisions, fostering an open error culture, and including risk behavior in performance evaluations. BaFin explicitly examines board involvement in risk management during SREP assessments.

What requirements does the 9th MaRisk amendment 2026 place on risk strategy?

The 9th MaRisk amendment, consulted in April 2026, tightens requirements for risk strategy and culture. New focus areas include: stronger integration of ESG risks into risk strategy, expanded requirements for risk data management, deeper specifications for risk culture across all organizational levels, tighter requirements for business model analysis, and heightened expectations for IT governance in risk management. Institutions must review and adapt their existing strategies promptly.

What does developing risk culture and risk strategy cost?

Typical project budgets range from EUR 80,

000 to 250,

000 depending on institution size and maturity. The scope includes risk culture assessment (four to six weeks), risk strategy development including risk appetite statement (six to ten weeks), and implementation support with change management (eight to twelve weeks). ADVISORI offers modular packages from risk culture quick checks through complete strategy development to ongoing support for cultural anchoring.

Success Stories

Discover how we support companies in their digital transformation

Digitalization in Steel Trading

Klöckner & Co

Digital Transformation in Steel Trading

Case Study
Digitalisierung im Stahlhandel - Klöckner & Co

Results

Over 2 billion euros in annual revenue through digital channels
Goal to achieve 60% of revenue online by 2022
Improved customer satisfaction through automated processes

AI-Powered Manufacturing Optimization

Siemens

Smart Manufacturing Solutions for Maximum Value Creation

Case Study
Case study image for AI-Powered Manufacturing Optimization

Results

Significant increase in production performance
Reduction of downtime and production costs
Improved sustainability through more efficient resource utilization

AI Automation in Production

Festo

Intelligent Networking for Future-Proof Production Systems

Case Study
FESTO AI Case Study

Results

Improved production speed and flexibility
Reduced manufacturing costs through more efficient resource utilization
Increased customer satisfaction through personalized products

Generative AI in Manufacturing

Bosch

AI Process Optimization for Improved Production Efficiency

Case Study
BOSCH KI-Prozessoptimierung für bessere Produktionseffizienz

Results

Reduction of AI application implementation time to just a few weeks
Improvement in product quality through early defect detection
Increased manufacturing efficiency through reduced downtime

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance

Latest Insights on Risk Culture and Risk Strategy

Discover our latest articles, expert knowledge and practical guides about Risk Culture and Risk Strategy

Less & Faster IRB Model Changes — What Actually Changed (and Why It Matters)
Risikomanagement

Less & Faster IRB Model Changes — What Actually Changed (and Why It Matters)

April 24, 2026
5 min

How the new IRB rules transform many previously time-consuming model changes into simple notifications—thereby drastically shortening approval times and significantly accelerating implementation

Dr. Helge Thiele
Read
ESG Dashboard: Structure, KPIs & Tools for CSRD Sustainability Reporting
Risikomanagement

ESG Dashboard: Structure, KPIs & Tools for CSRD Sustainability Reporting

April 20, 2026
12 min

An ESG dashboard makes sustainability performance visible and auditable. This guide covers essential environmental, social, and governance KPIs, CSRD/ESRS alignment, data collection strategies, and tool selection for organizations building audit-ready ESG reporting.

Boris Friedrich
Read
DORA ICT Risk Management: Requirements and Implementation Guide for Financial Institutions
Risikomanagement

DORA ICT Risk Management: Requirements and Implementation Guide for Financial Institutions

April 16, 2026
16 min

DORA Articles 5–15 establish the ICT risk management framework that financial institutions must implement. This guide breaks down governance, framework structure, ICT systems management, detection, business continuity, and the learning loop — with a practical implementation roadmap.

Boris Friedrich
Read
DPIA-Guide: Data Protection Impact Assessment Under GDPR - Step by Step
Risikomanagement

DPIA-Guide: Data Protection Impact Assessment Under GDPR - Step by Step

April 7, 2026
12 min

A Data Protection Impact Assessment (DPIA) is mandatory for high-risk data processing under GDPR. This step-by-step guide covers when a DPIA is required, the 6-step methodology, risk evaluation, mitigating measures, and documentation requirements for regulatory compliance.

Boris Friedrich
Read
Third-Party Risk Management: The Complete TPRM Guide for 2026
Risikomanagement

Third-Party Risk Management: The Complete TPRM Guide for 2026

April 6, 2026
16 min

Third-party risk management (TPRM) identifies, assesses, and mitigates risks from vendors and suppliers. This guide covers the full TPRM lifecycle, risk classification, due diligence methods, continuous monitoring, DORA Articles 28–30 requirements, and practical tools for every maturity level.

Boris Friedrich
Read
Intelligent ICS automation with RiskGeniusAI: Reduce costs, strengthen compliance, increase audit security
Künstliche Intelligenz - KI

Intelligent ICS automation with RiskGeniusAI: Reduce costs, strengthen compliance, increase audit security

October 29, 2025
5 min

Transform your control processes: With RiskGeniusAI, compliance, efficiency and transparency in the ICS become measurably better.

Angelo Tarda
Read
View All Articles
ADVISORI Logo
BlogCase StudiesAbout Us
info@advisori.de+49 69 913 113-01