MaRisk: BaFin's minimum requirements for risk management
MaRisk is the BaFin circular on the minimum requirements for risk management at German banks. It turns section 25a of the German Banking Act into working rules, from risk-bearing capacity to outsourcing and emergency management. The current version is Circular 06/2026 (BA), the ninth amendment.
What MaRisk is and who applies it
MaRisk is an administrative regulation that interprets the law, and Wikipedia calls it de facto binding for the institutions it addresses. Its first module names section 25a(1) KWG as its basis and says it also specifies section 25b on outsourcing and section 26c on ESG risks.
The circular applies to all institutions under the KWG unless they are significant institutions under the SSM Regulation, which the European Central Bank supervises directly. Financial services institutions and large investment firms apply it as far as their size and business require. Through MaRisk, BaFin also implements EBA guidelines, among them those on internal governance, outsourcing, loan origination and monitoring, and the management of ESG risks.
How the circular is built
The general part, module AT, holds the rules for every institution: scope, the responsibility of the management board and the supervisory board, risk-bearing capacity, strategies, the internal control system with stress tests and the use of models, and three special functions for risk control, compliance and internal audit. It continues with documentation, staff and technical equipment, emergency management in AT 7.3, the new product process and outsourcing in AT 9.
The special part covers the lending business in BTO 1, trading in BTO 2 and real estate business in BTO 3. BTR 1 to BTR 5 set the risk control processes for counterparty, market price, liquidity, operational and credit spread risks, and BT 2 sets the requirements for risk reports. The pages on operational risk in banks and business continuity management go into BTR 4 and AT 7.3.
What the ninth amendment changed
BaFin published the ninth amendment on June 30, 2026 and describes it as more principle-based, with more room for proportional application and further relief for small and very small institutions. According to the Genoverband's summary, the duty to use several methods to identify ESG risks is gone, as is the written form for material outsourcing contracts. Emergency plans now have to cover all critical or important functions, without the earlier focus on time criticality, and internal audit gets clearer access to large projects.
Smaller institutions with sufficient capital buffers may keep reviewing their strategy and capital planning once a year. The circular applies from its publication, and new or stricter requirements have to be in place by January 1, 2027. BaFin states that a more principle-based text does not lower the standard: risks still have to be identified, measured, managed and monitored.
Upcoming events on risk and compliance
Does MaRisk apply to banks supervised by the ECB?
No. Under module AT 2.1 of the current circular, MaRisk addresses institutions that are not classified as significant under the SSM Regulation. The significant institutions, which the ECB supervises directly in its SREP, follow the ECB's own guides. Branches of German institutions abroad apply MaRisk; branches of companies from other EEA states in Germany do not.
How does MaRisk relate to DORA?
The circular says that outsourced or purchased ICT services that fall under the ICT third-party risk rules of DORA, Articles 28 to 30, are outside the scope of AT 9. For those, the DORA third-party rules apply, while AT 9 keeps the outsourcing of other activities and processes. The IT requirements that BaFin had set in the BAIT are being replaced by DORA.
What does MaRisk AT 7.3 require?
AT 7.3 requires an emergency concept for activities and processes that are critical or important functions. It rests on business impact analyses and contains business continuity and recovery plans. The concept is updated every year and when there is a reason, the management board receives a written report on emergency management at least every quarter, and the plans for critical or important functions are tested every year.
MaRisk and Finance Loop
Finance Loop is the meeting place for the risk controllers, compliance officers and internal auditors who turn MaRisk into processes and tools at German banks. Finance Loop co-organized the Frankfurt Quantum Finance Forum at Frankfurt School with the Deutsche Bundesbank and IBM, where risk modeling was on the agenda, and works with the Frankfurt consultancy d-fine as an event and network partner.
Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.