June 14, 2026 Regulation & Banking
Series · Part 2 of 2

The 200+ Location Rollout: Scaling, Liability, and Recommendations for the Association

By Thorsten Litzki · Litzki Systems LLC

You are reading Part 2 of our series on the bank rollout of technical verification systems. Part 1 explains what CERTavia delivers under Art. 50 EU AI Act, where the evidence gap runs, and why a CERTIFIED signal is not a compliance certification.

tl;dr

Key takeaways

  • •  A rollout across 200+ locations is a governance decision, not an IT routine. Operational entropy becomes the central risk factor.
  • •  CERTavia evidence has a 90-day validity. Without a centralized clearing house, expired evidence appears widely at exactly the moment of an audit.
  • •  The liability demarcation line clearly separates service provider, individual institution, and association under MaRisk AT 9 and DORA.
  • •  Five prioritized steps secure the rollout, from positioning as a Compliance Verification Layer to a liability exclusion framework.
Thesis The strategic advantage of the rollout arises from strict adherence to the governance demarcation lines between service provider, institution, and association. The number of parameters checked alone does not carry this advantage.

An association rolling out CERTavia validation across a network of more than 200 locations faces a different task than a single institution with one domain. Varying IT maturity levels, local configurations, and evidence that is inherently time-limited by design meet a supervisory authority that expects uniform, robust evidence. This second part addresses the scaling risks, draws the liability demarcation line, and names the five steps with which an association implements the rollout safely.

Scaling Risks at 200+ Locations

A rollout across a network of this size is characterized by significant operational heterogeneity. Varying IT maturity levels and local configurations jeopardize the comparability of results.

Operational Entropy and Versioning

If location A receives a FAILED due to local DNS configurations while location B reports CERTIFIED, the association faces a coordination and explanation crisis. The uniform assessment of the overall infrastructure becomes a task in its own right.

The 90-Day Validity as an Operational Constant

CERTavia evidence carries an inherent 90-day validity by design. This period reflects the technical reality of volatile infrastructures. In the banking environment it creates a permanent operational burden. Without a centralized clearing house at the association level that monitors these cycles, expired evidence appears widely at exactly the moment of an audit.

Change Management as a Standardization Task

Integrating external verification data into the local IT processes of 200+ units requires standardization that goes beyond the technical measurement. A uniform format for escalation, documentation, and approval carries the rollout beyond the first wave.

A technical error remains a technical error as long as a defined SLA process catches it. Without that process it becomes a governance problem.

Liability Profiles and Outsourcing Governance

In the context of MaRisk AT 9 and DORA, CERTavia is classified as an IT service provider. The use of external evidence does not relieve the institution of the duty to independently monitor risk through the central outsourcing management function (ZAM). The liability demarcation line clearly assigns the three levels involved.

Service provider: CERTavia

Liable solely for the technical correctness of the measurement across 80+ parameters in six clusters at the time of the check.

Individual institution

Bears full responsibility for assessing the results and for the procedural implementation of MaRisk and BAIT requirements.

Association

Takes on the role of enabler. The association does not act as a substitute auditor. An implicit compliance promise in external communications is not legally covered and does not reduce the depth of control of the bank's internal audit function.

Strategic Recommendations for the Association

To use the advantages of the CERTavia engine safely, the association prioritizes five steps.

Precise positioning as a Compliance Verification Layer

Consistently communicate CERTavia as machine-readable compliance evidence. Avoid terms like "AI Act certification." The goal is audit-ready status, not blanket compliance.

Modularization of the Conformity Assessment Dossier

Position the CERTavia result as a modular, technically valid puzzle piece that internal audit embeds into the Conformity Assessment Dossier under Annex VII.

Definition of centralized approval processes

Establish binding workflows for handling FAILED signals. A technical error is escalated within defined SLAs to preserve the documentary integrity of the network.

Early involvement of internal audit under MaRisk

Internal audit is involved early. The cryptographic artifacts are accepted as robust building blocks for IT audits under BAIT.

Liability exclusion and governance framework

A framework defines which requirements are checked under Art. 50 and which remain within the bank's area of responsibility under Art. 9, 10, and 14.

Conclusion

CERTavia delivers evidence. The bank delivers compliance.

The rollout offers a strategic advantage as a trust layer for the digital ecosystem of banks. Its success depends on strict adherence to the governance demarcation lines. The number of parameters checked alone does not carry this success.

← Back to Part 1: The Evidence Gap between CERTavia and Art. 50 EU AI Act

Infrastructure evidence

Your SOVP evidence in 90 seconds

Free scan — no account required. CERTIFIED or FAILED with a complete cluster report.