Investitionsbank Berlin Optimizes Recertification with a New IAM Solution

Success Story·3 min
Logo Investitionsbank Berlin
Investitionsbank Berlin IBB
Financial service provider

Since implementing the Garancy Suite, Investitionsbank Berlin (IBB) no longer relies on manual responses from different departments. Instead, the IAM software automatically retrieves the necessary data from connected systems and prompts managers at defined intervals to recertify access rights.

The provider had competent answers to all our questions regarding IAM that also convinced the auditors.

Logo Investitionsbank Berlin
Percy Frahm
Department Head Technical Infrastructure, Investitionsbank Berlin

Initial Situation

The staff of the ‘monitoring office’ at Investitionsbank Berlin (IBB) used to face significant challenges. This team is responsible for regularly reviewing the IT access permissions of all 850 employees at the financial institution, playing a key role in ensuring the bank meets all compliance requirements.

With growing regulatory demands in the financial sector, manual reviews have become increasingly time-consuming and error-prone – especially since many of IBB’s IT systems were not yet connected to a centralized Identity & Access Management (IAM) system.

Challenge

Many managers lacked a clear understanding of the scope and implications of individual access rights, making it difficult to carry out proper and regular recertifications as required by MaRisk (Minimum Requirements for Risk Management).

To address this challenge, the bank initiated a public tender for a new IAM system. A key driver behind this move was the auditing firm’s demand for a daily, up-to-date overview of all access rights. In addition, the bank aimed to implement a consistent, standardized recertification process as part of the new solution.

Implementation

A surprisingly fast implementation: Beta Systems was awarded the project, “because they have long-standing expertise in the banking sector,” says Percy Frahm, Head of Technical Infrastructure at Investitionsbank Berlin. “The provider had competent answers to all our questions regarding IAM that also convinced the auditors.”

The recertification portal included in the Garancy Suite, which required no additional programming effort, as well as the predefined role profiles were further key advantages. Implementation took just about six months – a remarkably short timeline for a project of this scale.

We now have an out-of-the-box Identity Access Management solution simply not offered by other software providers.

Logo Investitionsbank Berlin
Eike Schmaida
Chief Digital Officer & Head of IT Department, Investitionsbank Berlin

Outcome

The Garancy Identity Manager provisioning module allows IBB to centrally administrate and control all user-related authorization information – including identities, groups, and roles – across its entire IT landscape.

Recertification of access rights is handled through the intuitive web interface of the Garancy Recertification Center, where the persons in charge review employee roles and authorizations. If a permission is not renewed, it is automatically revoked.

“With Garancy, we now have an out-of-the-box Identity Access Management solution that other software providers simply do not offer,” says Eike Thore Schmaida, highlighting one of the key reasons the bank chose Beta Systems.

Today, IBB’s authorization and certification workflows are considered a best-practice model within the promotional banking sector. By automating and streamlining IAM processes, the bank’s IT and management teams are free to focus more on customer-facing and strategic initiatives.

Customer

Logo Investitionsbank Berlin
Year of foundation
1924
Number of employees
620
Head office
Berlin
Sector
Financial service provider
Investitionsbank Berlin IBB
Bundesallee 210
10719 Berlin
Germany

Further Resources

Webinar
nis2-requirements-for-critical-infrastructure.jpg

Practical NIS-2 Requirements for Critical Infrastructure Operators in Public Services

The NIS-2 Directive significantly tightens cybersecurity requirements for operators of critical infrastructure and essential public services across the EU ‒ including energy, water supply, and municipal utilities. But what does this mean in practice for organizations affected today? This on-demand webinar shows you exactly how to interpret and implement NIS-2 requirements effectively.
Webinar
iam-project-management-insights.jpg

Action Over Planning – IAM Project Management Tips and Insights (DE)

Identity and Access Management (IAM) isn’t just an IT initiative – it’s a strategic enabler of security, operational efficiency, and compliance in modern digital businesses. Yet too many IAM projects stall before they begin: over-planning, uncertain priorities, regulatory complexity, and limited resources can slow progress and undermine results.
Whitepaper
Whitepaper Titelbild: NIS-2 und der strategische Wert von Identity & Access Management

Turning Obligation into Advantage: NIS-2 and the Strategic Value of Identity & Access Management

The NIS-2 Directive significantly raises the bar for cybersecurity across Europe, placing Identity & Access Management at the center of compliance and security efforts. This whitepaper explains why IAM under NIS-2 is not merely a regulatory obligation, but a strategic foundation for resilience, transparency, and control. Developed in collaboration with egerer Consulting, it brings together regulatory insight and strategic consulting expertise with practical guidance on implementing NIS-2 requirements using a modern IAM solution.