← Back to news 11.09.2026

What exactly did you approve?

Section 38 BSIG puts the management body personally on the hook. The approval of measures is usually minuted as a resolution: date, subject, done. Two years later that is exactly the question nobody can answer any more.

The NIS2 debate is mostly about deadlines and technology. The provision that ends up getting the management body's attention is a different one.

Section 38 BSIG puts them personally on the hook, in three subsections: subsection 1 requires the approval of the risk management measures and oversight of their implementation. Subsection 2 confirms liability under the applicable company law. Subsection 3 requires regular participation in training.

The resolution that does not answer the question

In practice subsection 1 is usually handled like this: a meeting approves the list of measures, the minutes name the date, the subject and the resolution, and the file is closed.

Two years later an audit asks: what exactly did you approve back then?

The list of measures has been revised twice since. Measures have been added, others closed, some reworded. The resolution refers to a list that no longer exists in that form. It therefore evidences that approval happened, but not what was approved.

That is not a formality. It is the point at which the personal responsibility under subsection 2 has nothing left to attach to, because its subject can no longer be established.

So the state gets frozen

Alongside the date, subject, resolution and minutes, an approval therefore needs one more thing: a snapshot of the implementation state at that moment. Not a pointer to the living list, but its condition on the day of approval, fixed.

Whoever edits the file later does not change that snapshot. That is the whole point: evidence you can adjust after the fact is not evidence.

The same principle already carries elsewhere: what was submitted in a registration stays as its own version. A declaration of conformity freezes the state it refers to. An approval is the same case.

Who is on the management body anyway?

A question that sounds technical and is legal: membership of the management body attaches to the entity, not to the person.

A group may run several entities subject to registration, and someone may sit on the board of one and not the other. Record the marker against the person rather than against the relationship between person and entity, and you produce a file that asserts obligations for the wrong company.

And now the place where market practice is taken for law

Subsection 3 requires regular training. Almost everywhere you read that it has to be completed annually.

Section 38(3) names no frequency. The annual cycle is market practice, not a statutory requirement. It is good practice, but it is practice, and the same applies to the cycle for oversight under subsection 1.

That sounds like splitting hairs and it is the difference between a justification and an assertion. Asked in an audit why training happens annually, you want to be able to answer "that is our determination, here is the resolution" rather than "NIS2 requires it". The second answer is wrong, and it shows.

In our module the annual cycle therefore lives in the configuration and not as a fixed value in the code. A convention that sits in code turns into an obligation in the reader's mind.

Two questions to ask of your own organisation

Take the last resolution by which your management approved measures. Which list does it refer to, and does that list still exist today in exactly that version? If not, the resolution evidences less than it appears to.

And the second: where does your training cycle come from? Is there a resolution about it in the file, or only the assumption that the law prescribed it?

How the approval, the management body and the training status are kept in the file is described on the NIS2 file module page. The deadlines with legal references are in the compliance calendar.

Matching solution isidaten for NIS2

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.