DEEN
Regulation

Ninth MaRisk amendment: changes and implementation

The ninth MaRisk amendment has applied since 30 June 2026. Changes from the previous version and implementation checks for institutions.

First version: Updated: Reading time: about 15 minutes

Symbolic image for the 9th MaRisk amendment: two compliance professionals at a conference table comparing two printed versions of a circular, one with revision marks, with the Frankfurt banking skyline in the background

The 9th MaRisk amendment is the new version of the German Minimum Requirements for Risk Management published by BaFin on 30 June 2026 as Circular 06/2026 (BA), more principles-oriented and with more proportionality (BaFin announcement of 30 June 2026). It entered into force upon publication; a transition period until 1 January 2027 applies only where additional requirements arise in individual cases (cover letter of 30 June 2026, ref. BA 54-FR 2210/00067#00005). The amendment emerged from consultation 02/2026 (draft of 1 April 2026, BaFin announcement of 1 April 2026). This article covers the change delta in detail; the framework, structure (AT/BT) and amendment history of the MaRisk as a whole are covered by the reference article MaRisk: current version, Circular 06/2026, AT/BT structure and amendments.

What does the 9th MaRisk amendment change?

The 9th MaRisk amendment (Circular 06/2026 (BA), 82 pages) streamlines the MaRisk at the interfaces with DORA, restructures the Special Part (BT), introduces AT 3.2 as a dedicated module on the responsibility of the supervisory body and scales the requirements by size category. According to BaFin, the level of requirements remains unchanged. The cover letter to Circular 06/2026 (BA) of 30 June 2026 states verbatim:

“No fundamental lowering of the level of requirements has occurred as a result of the more strongly principles-oriented approach.”
BaFin, cover letter to Circular 06/2026 (BA) of 30 June 2026, ref. BA 54-FR 2210/00067#00005, p. 1, unofficial translation

The delta table shows the key changes of the 9th MaRisk amendment versus the 8th amendment (Circular 06/2024), each with its reference:

Delta table: 8th amendment (Circular 06/2024) vs. 9th amendment (Circular 06/2026)
Module8th amendment (Circular 06/2024)9th amendment (Circular 06/2026)Reference (Circular 06/2026)
AT 3.2 (supervisory body)No standalone AT module on the responsibility of the supervisory bodyNew module “Responsibility of the supervisory body and its committees”: information at least quarterly in text form on business and risk situation; forwarding to a committee possible by resolutionAT 3.2 paras. 1–2
AT 7.2 (IT)Detailed IT requirements in 6 paragraphs (paras. 1–6: IT systems, end-user computing, IT risks), specified further by the BAITReduced to 2 paragraphs; detailed IT requirements dropped in favour of DORAAT 7.2
AT 9 (outsourcing)No DORA carve-out (the 06/2024 source text does not mention DORA); outsourced ICT services not exempted from AT 9ICT services within the meaning of Art. 3 No. 21 DORA (Art. 28–30) “do not fall within the scope of AT 9”AT 9 para. 1, explanatory note
AT 9 para. 12Central outsourcing officer (para. 12) plus, proportionally, central outsourcing management; outsourcing register separately in AT 9 para. 14 (EBA/GL/2019/02)Central outsourcing management instead of an officer; outsourcing register (Section 25b (1) sentence 4 KWG) expressly namedAT 9 para. 12 b
BT structureBT 2 = standalone module “Internal audit”; risk reporting in BT 3BT 2 “Internal audit” dropped (consolidated into AT 4.4.3); risk reporting moves from BT 3 to BT 2Table of contents
AT 4.3.4AT 4.3.4 = risk data aggregation (significant institutions only, BCBS 239); “Use of models” in AT 4.3.5Risk data aggregation dropped without replacement; “Use of models” now AT 4.3.4 (previously 4.3.5), expressly including artificial intelligenceAT 4.3.4
ESG/environmentESG anchored in AT 2.2 para. 1 / AT 4.3.3 para. 1; without a Section 26c KWG reference in AT 1, without EBA/GL/2025, without separate resilience analysesAT 1 para. 1 now also specifies Section 26c KWG; implementation of EBA/GL/2025/01 and EBA/GL/2025/04; environmental risks in stress tests plus resilience analysesAT 1 paras. 1–2; AT 4.3.3 para. 7
AT 1 para. 3 / AT 2.1Proportionality without fixed “small/very small” categories; SIs (Art. 6 SSM Regulation, AT 1 para. 6) within scope (AT 2.1 para. 1)Small = SNCI (Art. 4 (1) No. 145 CRR); very small = total assets ≤ EUR 1 billion on a four-year average; SIs (Art. 6 SSM Regulation) removedAT 1 para. 3; AT 2.1 para. 1

When did the 9th MaRisk amendment enter into force and by when must it be implemented?

The 9th MaRisk amendment entered into force on 30 June 2026 with the publication of Circular 06/2026 (BA); BaFin grants a transition period until 1 January 2027 only where additional requirements arise in individual cases (cover letter of 30 June 2026, ref. BA 54-FR 2210/00067#00005). The cover letter states verbatim:

“The new version of the MaRisk enters into force upon publication today. Where the MaRisk give rise to additional requirements in individual cases, a transition period until 1 January 2027 is granted.”
BaFin, cover letter to Circular 06/2026 (BA) of 30 June 2026, ref. BA 54-FR 2210/00067#00005, section “Übergangsfrist” (transition period), unofficial translation

The deadline therefore does not apply across the board; beyond that, it only covers adjustments where an institution has documented a deviating interpretation of the supervisory notice of 26 November 2024, which has been incorporated into the MaRisk. A full calendar of implementation deadlines is provided by the banking regulation roadmap.

Timeline of the 9th MaRisk amendment
MilestoneDateReference
Consultation 02/2026 published1 April 2026BaFin announcement of 1 April 2026
End of the comment period8 May 2026BaFin announcement of 1 April 2026
9th amendment published in final form and in force30 June 2026BaFin announcement of 30 June 2026
End of the transition period (only for additional requirements in individual cases; supervisory notice of 26 November 2024)1 January 2027Cover letter of 30 June 2026

What was in consultation 02/2026 and what changed in the final version?

BaFin published the draft of the 9th MaRisk amendment on 1 April 2026 as consultation 02/2026 (comments until 8 May 2026); the final version of 30 June 2026 adopts the main lines of the draft but deviates in verifiable respects. New is AT 4.2 para. 5: small institutions may monitor strategy and capital planning only annually “if, in addition to the supervisory capital requirements and recommendations, they hold a further buffer of at least two percentage points of Common Equity Tier 1 capital" (Circular 06/2026, unofficial translation).

Compared with the consultation draft 02/2026, the final version of the 9th MaRisk amendment also deleted the standalone duty of internal audit to accompany projects (draft AT 4.4.3 para. 5); in the final version, only the right to information and access remains, “including when accompanying material projects” (AT 4.4.3 para. 1, unofficial translation). The final version names the outsourcing register expressly in AT 9 para. 12 b); the draft contained the duty without the term. The explanatory note to AT 9 para. 10 still refers to an overall report to be prepared by the audit officer under AT 4.4.3 para. 11, and to a review of remediation in accordance with AT 4.4.3 para. 13; this reference already appears word for word in the explanatory note of the consultation draft and matches neither its numbering nor the final version: the final AT 4.4.3 has only 12 paragraphs and knows no overall report. Until BaFin corrects this editorial error, the passage cannot serve as evidence of an overall reporting duty.

The revised MaRisk refer to the European requirements identified in the circular. Later changes need assessment for their effect on the institution’s processes. A consultation date is not the application date of a final rule. BaFin: Rundschreiben 06/2026 (BA), MaRisk

What relief applies to small and very small institutions?

The 9th MaRisk amendment defines the size categories in AT 1 para. 3 (Circular 06/2026): small institutions are institutions classified as SNCIs (Art. 4 (1) No. 145 CRR) as well as CRD third-country branches of risk class 2; very small institutions have total assets of no more than EUR 1 billion on a four-year average and can use the relief even without an SNCI classification. SIs within the meaning of Art. 6 SSM Regulation are removed from the scope (AT 2.1 para. 1); all other LSIs remain the regular addressees.

Specific relief (each per Circular 06/2026): at very small institutions, a member of the management board may perform the compliance officer function (AT 4.4.2 para. 4) and tasks of internal audit (AT 4.4.3 para. 1), in each case with safeguards against conflicts of interest; the complete outsourcing of both functions is possible (AT 9 para. 5). A member of the management board of a very small institution may also take on the tasks of the audit officer where an appointment below management board level would be disproportionate (AT 9 para. 10). Very small institutions may dispense with risk-type-specific stress tests (AT 4.3.3 para. 2); for small institutions, an institution-wide downturn scenario generally suffices, and inverse stress tests are dispensable (AT 4.3.3 paras. 3–4). Small institutions need to review the risk analysis of their outsourcing arrangements only every three years (AT 9 para. 2). Annual strategy monitoring is conditional on the capital buffer under AT 4.2 para. 5.

LSI checklist: changes to review by 1 January 2027

The checklist bundles the review points of the 9th MaRisk amendment for an LSI; the transition period until 1 January 2027 applies only where additional requirements arise in individual cases. Everything else has applied since 30 June 2026 (cover letter):

  1. 01Scope of application

    Document the classification as an SNCI, a very small institution (total assets ≤ EUR 1 billion on a four-year average) or another LSI (AT 1 para. 3; AT 2.1 para. 1).

  2. 02AT 9/DORA dividing line

    Assign ICT services under Article 3(21) DORA that are subject to third-party risk management under Articles 28–30 DORA to the DORA register of information. Only these services fall within the AT 9 exception. Separately assess whether they also constitute outsourcing under section 25b KWG and whether the associated register duties apply.

  3. 03Central outsourcing management

    Set up the role in place of the outsourcing officer; maintain the outsourcing register under Section 25b (1) sentence 4 KWG (AT 9 para. 12 b).

  4. 04Internal audit setup

    Reflect the removal of BT 2; quarterly reports instead of an annual overall report (AT 4.4.3 para. 9).

  5. 05Supervisory body reporting

    Define the procedure under AT 3.2; information at least quarterly in text form, with delegation to a committee by resolution where applicable (AT 3.2 para. 2).

  6. 06ESG/stress tests

    Integrate environmental risks into stress tests, add resilience analyses (AT 4.3.3 para. 7); review the ESG anchoring via Section 26c KWG (AT 1 para. 1).

  7. 07Decide on relief

    Combination of offices, tiered stress testing, three-year cycle for the outsourcing risk analysis (AT 9 para. 2), annual strategy monitoring (only with a buffer of at least 2 percentage points of Common Equity Tier 1 capital, AT 4.2 para. 5); justify and document every instance of relief used.

  8. 08Supervisory notice of 26 November 2024

    Where a deviating interpretation has been documented, plan adjustments by 1 January 2027 (cover letter).

What changes for outsourcing (AT 9) and ICT/DORA?

The ninth MaRisk amendment removes certain DORA ICT services from the scope of AT 9. Whether statutory outsourcing duties under section 25b KWG also apply requires a separate assessment. The explanatory note on AT 9 paragraph 1 states:

“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management under Art. 28-30 DORA do not fall within the scope of AT 9.”
BaFin, Circular 06/2026 (BA), MaRisk of 30 June 2026, AT 9 para. 1, explanatory note “DORA”, unofficial translation

Flanking this, AT 7.2 has been reduced to 2 paragraphs because ICT risk management runs via the DORA regulation; the BAIT will be repealed as of 31 December 2026 (BaFin announcement of 9 January 2025). Business continuity management under AT 7.3 also follows the DORA alignment: AT 7.3 para. 1 now uses the DORA terminology “critical or important functions” and requires management to be informed in writing about the state of business continuity management at least quarterly and on an ad hoc basis (Circular 06/2026).

For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956 ESAs: first DORA report on major ICT-related incidents

Within AT 9, the 9th MaRisk amendment replaces the outsourcing officer with central outsourcing management, which documents outsourcing arrangements including sub-outsourcing in accordance with Section 25b (1) sentence 4 KWG; the outsourcing register is expressly named in the regulatory text (AT 9 para. 12 b, Circular 06/2026). The report on material outsourcing goes to the management board (para. 13); at very small institutions, a board meeting suffices.

Does the 9th MaRisk amendment also apply to AI models?

Yes: module AT 4.3.4 “Use of models” of the MaRisk (Circular 06/2026 (BA) of 30 June 2026) expressly extends its requirements to artificial intelligence in para. 1:

“They also apply to automated models, technology-driven innovation and artificial intelligence.”
BaFin, Circular 06/2026 (BA), MaRisk of 30 June 2026, AT 4.3.4 para. 1, unofficial translation

The amendment to the AI Act under Regulation (EU) 2026/1744 has been in force since 27 July 2026. The relevant obligations for Annex III high-risk systems apply from 2 December 2027; those for Annex I high-risk systems apply from 2 August 2028. Regulation (EU) 2026/1744 amending the AI Act European Commission: AI Omnibus enters into force

What changes for stress tests, ESG and reporting?

For stress tests, the 9th MaRisk amendment requires environmental risks to be taken into account and supplemented by long-term resilience analyses (AT 4.3.3 para. 7, Circular 06/2026); AT 1 para. 1 now also specifies Section 26c KWG (ESG risks), implementing, among others, EBA/GL/2025/01 and EBA/GL/2025/04 (AT 1 para. 2). The tiering of stress tests by size category is governed by AT 4.3.3: very small institutions may dispense with risk-type-specific stress tests (para. 2), for small institutions an institution-wide downturn scenario generally suffices, and inverse stress tests are dispensable for small institutions (paras. 3–4).

In reporting, the 9th MaRisk amendment restructures the Special Part: BT 2 “Internal audit” is dropped (consolidated into AT 4.4.3), and risk reporting moves from BT 3 to BT 2 (Circular 06/2026). The annual overall report of internal audit is dropped; quarterly reports remain (AT 4.4.3 para. 9). Newly regulated is the involvement of the supervisory body: under AT 3.2 para. 2, management must inform the supervisory body at least quarterly in text form about the business and risk situation; forwarding can be limited to a committee by resolution. The former AT 4.3.4 (risk data aggregation) has been dropped without replacement; “Use of models” now carries the number AT 4.3.4.

Where is the comparison version (redline 8th ↔ 9th amendment) available?

BaFin provides the official comparison versions on the download page for Circular 06/2026 (BA): the comparison 8th ↔ 9th amendment as well as the comparison consultation draft ↔ final version, each alongside the circular and the cover letter. Deutsche Bundesbank lists the new version as the “MaRisk-Neufassung 2026” (MaRisk new version 2026). The delta table above provides the entry point; for paragraph-level precision, only the official redline documents are authoritative.

FAQ

Frequently asked questions about the 9th MaRisk amendment

Do the MaRisk still apply to significant institutions (SIs)?

No. Significant institutions (SIs) within the meaning of Art. 6 SSM Regulation under direct ECB supervision are removed from the scope of the MaRisk by the 9th amendment (AT 2.1 para. 1 of Circular 06/2026 (BA) of 30 June 2026). All other, nationally supervised LSIs remain the regular addressees of the MaRisk.

Does the 9th MaRisk amendment lower the level of requirements?

No. BaFin's cover letter to Circular 06/2026 (BA) of 30 June 2026 states verbatim (unofficial translation): “No fundamental lowering of the level of requirements has occurred as a result of the more strongly principles-oriented approach.” Deleted explanatory notes also do not mean that existing solutions based on them would no longer be recognised.

How long is the current MaRisk version?

The published Circular 06/2026 (BA) of 30 June 2026 comprises 82 pages. For comparing individual requirements, the official comparison documents are more useful than the page count alone.

By when must the 9th MaRisk amendment be implemented?

The ninth MaRisk amendment has applied since 30 June 2026. The transition until 1 January 2027 applies only where additional requirements arise in an individual case.

Do the MaRisk also apply to AI models?

Where an AI model is used for purposes covered by MaRisk AT 4.3.4, the module’s model requirements apply. The assessment depends on its task and use within the institution. Other duties, including DORA and data protection obligations, may apply independently.

Where is the comparison version (redline) of the 9th MaRisk amendment available?

BaFin provides official comparison versions on the download page for Circular 06/2026 (BA): the comparison of the 9th amendment with the 8th amendment (Circular 06/2024) as well as the comparison of the final version with the consultation draft 02/2026. The official text is always authoritative for references.

What applies to small and very small institutions under the 9th MaRisk amendment?

Small institutions are institutions classified as SNCIs (Art. 4 (1) No. 145 CRR); very small institutions have total assets of no more than EUR 1 billion on a four-year average (AT 1 para. 3 of the MaRisk, Circular 06/2026). Very small institutions may, among other things, assign the compliance officer function and internal audit tasks to a member of the management board and dispense with risk-type-specific stress tests; for small institutions, an institution-wide downturn scenario generally suffices, and inverse stress tests are dispensable (AT 4.3.3 paras. 2 to 4).

An offer from T-NEX GmbH

Discuss the project with T-NEX

Regulatory changes need to become requirements, accountabilities and implementation projects. T-NEX Compliance supports the business workflow; PPM helps structure projects and dependencies.

Management: Andreas Unruh and Christoph Gembruch.

Published by T-NEX GmbH.