Professional crisis management for organisations. Crisis planning, business continuity, communication and recovery in crisis situations.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










A key success factor in crisis management is preparation for the unexpected. Crisis management structures should be flexible enough to respond to various scenarios rather than focusing on managing specific, predictable events. Particularly important is regular practice of crisis management processes under realistic conditions – only this way can weaknesses be identified and addressed before an actual emergency occurs.
Years of Experience
Employees
Projects
Our approach to developing and implementing crisis management systems follows a structured yet flexible methodology that we adapt to your specific requirements and business circumstances.
Assessment of existing crisis management capabilities and structures
Development of a customized crisis management framework and governance model
Building and training of crisis teams and responsible persons
Creation of crisis management documentation and tools
Validation through exercises and continuous improvement of the crisis management system
"The effectiveness of a crisis management system only becomes apparent in an actual emergency – which makes it all the more important to continuously test and improve crisis readiness through regular exercises and realistic simulations. Successful organizations are not characterized by not experiencing crises, but by their ability to manage them quickly and effectively and emerge stronger from them."

Head of Risk Management
We offer you tailored solutions for your digital transformation
A clearly structured crisis team with defined roles and escalation levels ensures that the right decisions are made quickly in an emergency.
A standardized process ensures that no step is overlooked from alerting to follow-up.
A comprehensive crisis plan bundles strategy, handbook, and infrastructure in an audit-proof document.
An effective early warning system detects emerging crises in time and enables proactive action.
Transparent, structured communication is crucial to maintain trust internally and externally.
Choose the area that fits your requirements
Anti-financial crime consulting for financial institutions and regulated companies. We build end-to-end AFC frameworks: AML compliance, KYC processes, sanctions screening and fraud detection with AI-powered analytics.
Anti money laundering and AML compliance for financial institutions. Risk analysis, transaction monitoring, KYC and regulatory requirements.
Cyber risks encompass all threats arising from IT vulnerabilities, cyberattacks and third-party dependencies. Since DORA (January 2025), banks, insurers and payment service providers must demonstrate a documented ICT risk management framework. ADVISORI supports risk identification, framework development and incident response.
Identify, assess and manage ICT risks – from BAIT to DORA. We support financial institutions in developing and implementing regulatory-compliant IT risk management frameworks.
KYC (Know Your Customer) compliance is a regulatory obligation under Germany's Anti-Money Laundering Act (GwG) and EU AML directives. ADVISORI helps banks and financial institutions implement efficient KYC processes — from customer identification and due diligence to continuous monitoring. With risk-based approaches and modern technology, we transform your KYC compliance into a competitive advantage.
We design and implement tailored ORM frameworks for your institution – from risk identification through RCSA and scenario analysis to regulatory-compliant loss data collection and KRI monitoring.
Crisis management encompasses all measures for preparing for, managing, and recovering from crisis situations. For banks, MaRisk AT 7.3 and BAIT mandate establishing emergency management that ensures the continuity of critical business processes. DORA adds specific requirements for ICT-related incident response from 2025. Effective crisis management protects against reputational damage, regulatory sanctions, and existentially threatening operational disruptions.
Business Continuity Management (BCM) is the overarching management process that identifies which time-critical processes must be maintained during disruptions. Emergency planning defines concrete measures for emergency operations and recovery, including resources, responsibilities, and timelines. Crisis management activates the crisis team and coordinates decision-making, communication, and escalation during an acute crisis. All three disciplines interlink and must be planned in an integrated manner.
The crisis team typically includes the executive board, risk management, IT, legal, compliance, communications, and affected business units. The structure must be predefined with clear roles, deputies, escalation paths, and decision-making authority. A crisis handbook documents alerting chains, situation room setup, and reporting channels. Regular crisis exercises, at minimum annually, ensure the crisis team functions under pressure.
MaRisk AT 7.3 requires emergency concepts for time-critical activities and processes with regular review and testing. BAIT specifies IT emergency management requirements. DORA mandates ICT-related incident reporting and response, digital operational resilience testing, and information sharing from 2025. BSI Standard 200–4 provides a recognized BCM framework. BaFin reviews the adequacy of emergency management under SREP and expects documented business impact analyses.
The Business Impact Analysis identifies and assesses the effects of operational disruptions on business processes. It determines Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) for each critical process, defines maximum tolerable downtime, and identifies dependencies between processes, systems, and external service providers. The BIA forms the foundation for all emergency plans and is mandatory for financial institutions under MaRisk and DORA.
Crisis exercises follow a defined sequence: planning with a realistic scenario (cyberattack, system failure, natural disaster), execution under conditions as realistic as possible with an activated crisis team, observation and documentation by an evaluation team, and structured debriefing with lessons learned and improvement measures. MaRisk requires at minimum annual emergency tests. ADVISORI supports from scenario development through exercise execution to results evaluation.
Costs depend on maturity level and scope. Typical project budgets range from EUR 100,
000 to 300,
000 for complete BCM setup including business impact analysis, emergency plans, crisis team establishment, crisis handbook, and initial exercise. Ongoing support including annual reviews, exercise delivery, and plan updates requires additional resources. ADVISORI offers modular packages from BCM quick checks through full implementation to ongoing crisis management support.
Discover how we support companies in their digital transformation
Klöckner & Co
Digital Transformation in Steel Trading

Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Festo
Intelligent Networking for Future-Proof Production Systems

Bosch
AI Process Optimization for Improved Production Efficiency

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance
Discover our latest articles, expert knowledge and practical guides about Crisis Management (NFR)

The credit risk function of 2026 looks materially different from the one most banks still operate. Here are the five shifts, from generative AI to ESG integration, that risk managers should plan for now.

How the new IRB rules transform many previously time-consuming model changes into simple notifications—thereby drastically shortening approval times and significantly accelerating implementation

An ESG dashboard makes sustainability performance visible and auditable. This guide covers essential environmental, social, and governance KPIs, CSRD/ESRS alignment, data collection strategies, and tool selection for organizations building audit-ready ESG reporting.

DORA Articles 5–15 establish the ICT risk management framework that financial institutions must implement. This guide breaks down governance, framework structure, ICT systems management, detection, business continuity, and the learning loop — with a practical implementation roadmap.

A Data Protection Impact Assessment (DPIA) is mandatory for high-risk data processing under GDPR. This step-by-step guide covers when a DPIA is required, the 6-step methodology, risk evaluation, mitigating measures, and documentation requirements for regulatory compliance.

Third-party risk management (TPRM) identifies, assesses, and mitigates risks from vendors and suppliers. This guide covers the full TPRM lifecycle, risk classification, due diligence methods, continuous monitoring, DORA Articles 28–30 requirements, and practical tools for every maturity level.