Key takeaways
- • A rollout across 200+ locations is a governance decision, not an IT routine. Operational entropy becomes the central risk factor.
- • CERTavia evidence has a 90-day validity. Without a centralized clearing house, expired evidence appears widely at exactly the moment of an audit.
- • The liability demarcation line clearly separates service provider, individual institution, and association under MaRisk AT 9 and DORA.
- • Five prioritized steps secure the rollout, from positioning as a Compliance Verification Layer to a liability exclusion framework.
An association rolling out CERTavia validation across a network of more than 200 locations faces a different task than a single institution with one domain. Varying IT maturity levels, local configurations, and evidence that is inherently time-limited by design meet a supervisory authority that expects uniform, robust evidence. This second part addresses the scaling risks, draws the liability demarcation line, and names the five steps with which an association implements the rollout safely.
Scaling Risks at 200+ Locations
A rollout across a network of this size is characterized by significant operational heterogeneity. Varying IT maturity levels and local configurations jeopardize the comparability of results.
Operational Entropy and Versioning
If location A receives a FAILED due to local DNS configurations while location B reports CERTIFIED, the association faces a coordination and explanation crisis. The uniform assessment of the overall infrastructure becomes a task in its own right.
The 90-Day Validity as an Operational Constant
CERTavia evidence carries an inherent 90-day validity by design. This period reflects the technical reality of volatile infrastructures. In the banking environment it creates a permanent operational burden. Without a centralized clearing house at the association level that monitors these cycles, expired evidence appears widely at exactly the moment of an audit.
Change Management as a Standardization Task
Integrating external verification data into the local IT processes of 200+ units requires standardization that goes beyond the technical measurement. A uniform format for escalation, documentation, and approval carries the rollout beyond the first wave.
A technical error remains a technical error as long as a defined SLA process catches it. Without that process it becomes a governance problem.
Liability Profiles and Outsourcing Governance
In the context of MaRisk AT 9 and DORA, CERTavia is classified as an IT service provider. The use of external evidence does not relieve the institution of the duty to independently monitor risk through the central outsourcing management function (ZAM). The liability demarcation line clearly assigns the three levels involved.
Service provider: CERTavia
Liable solely for the technical correctness of the measurement across 80+ parameters in six clusters at the time of the check.
Individual institution
Bears full responsibility for assessing the results and for the procedural implementation of MaRisk and BAIT requirements.
Association
Takes on the role of enabler. The association does not act as a substitute auditor. An implicit compliance promise in external communications is not legally covered and does not reduce the depth of control of the bank's internal audit function.
Strategic Recommendations for the Association
To use the advantages of the CERTavia engine safely, the association prioritizes five steps.
Consistently communicate CERTavia as machine-readable compliance evidence. Avoid terms like "AI Act certification." The goal is audit-ready status, not blanket compliance.
Position the CERTavia result as a modular, technically valid puzzle piece that internal audit embeds into the Conformity Assessment Dossier under Annex VII.
Establish binding workflows for handling FAILED signals. A technical error is escalated within defined SLAs to preserve the documentary integrity of the network.
Internal audit is involved early. The cryptographic artifacts are accepted as robust building blocks for IT audits under BAIT.
A framework defines which requirements are checked under Art. 50 and which remain within the bank's area of responsibility under Art. 9, 10, and 14.
Conclusion
CERTavia delivers evidence. The bank delivers compliance.
The rollout offers a strategic advantage as a trust layer for the digital ecosystem of banks. Its success depends on strict adherence to the governance demarcation lines. The number of parameters checked alone does not carry this success.
← Back to Part 1: The Evidence Gap between CERTavia and Art. 50 EU AI Act
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, consult an accredited conformity assessment body.