The MaRisk (Minimum Requirements for Risk Management) are BaFin's central circular on the risk management of German credit institutions; they specify Section 25a (1) of the German Banking Act (KWG) (proper business organisation). The MaRisk are not a law but an administrative provision. The current version is the 9th amendment: Circular 06/2026 (BA) of 30 June 2026, in force upon publication (BaFin download page). Where this gives rise to additional requirements in individual cases, a transition period until 1 January 2027 applies (cover letter, ref. BA 54-FR 2210/00067#00005).
What are the MaRisk? (explained simply)
On the basis of Section 25a (1) KWG, the MaRisk set out a flexible and practical framework for structuring the risk management of institutions; they additionally specify Section 25b KWG (outsourcing) and, since the 9th amendment, Section 26c KWG on ESG risks (AT 1 para. 1, Circular 06/2026 (BA) of 30 June 2026). The final version addresses the group dimension under Section 25a (3) KWG in its scope of application: parent undertakings of a group of institutions must observe the MaRisk requirements at group level to the extent this appears sensible and necessary for adequate risk management at group level pursuant to Section 25a (3) KWG (AT 2.1 including explanatory note, Circular 06/2026 (BA)). The MaRisk thereby translate qualitative Pillar 2 supervision (ICAAP/SREP) into German administrative practice. The legal bases are named by the regulatory text itself:
“On the basis of Section 25a (1) of the German Banking Act (KWG), this circular sets out a flexible and practical framework for structuring the risk management of institutions. It further specifies the requirements of Section 25b KWG (outsourcing) and Section 26c KWG (ESG risks).”
The MaRisk are not a law: as an administrative provision, they specify the underlying statutory duty under Section 25a (1) KWG, which continues to apply independently of the circular's wording. A principle that has run through the framework since the first version (Circular 18/2005, Deutsche Bundesbank) is proportionality: the MaRisk requirements scale via opening clauses with the size, complexity and riskiness of the business.
Which MaRisk version is current?
The current version is the 9th amendment of the MaRisk: Circular 06/2026 (BA) of 30 June 2026, in force upon publication (BaFin announcement “MaRisk-Novelle: Mehr Proportionalität” of 30 June 2026). For additional requirements arising in individual cases, the cover letter (ref. BA 54-FR 2210/00067#00005) grants a transition period until 1 January 2027; the supervisory notice of 26 November 2024 has been incorporated into the MaRisk regulatory text. In the official wording:
“The new version of the MaRisk enters into force upon publication today. Where the MaRisk give rise to additional requirements in individual cases, a transition period until 1 January 2027 is granted.”
The predecessor version, Circular 06/2024 (BA) of 29 May 2024 (8th amendment, BaFin), has been superseded since 30 June 2026; Deutsche Bundesbank lists the current version as the “MaRisk-Neufassung 2026”. The MaRisk deadlines at a glance; a cross-regulatory bundling of all dates is provided by the banking regulation roadmap:
| Subject | Deadline / status | Reference |
|---|---|---|
| 9th amendment (Circular 06/2026 (BA)) in force | 30 June 2026, upon publication | BaFin announcement of 30 June 2026 |
| Transition period for additional requirements arising in individual cases; likewise adjustments where a documented interpretation deviates from the supervisory notice of 26 November 2024 | until 1 January 2027 | Cover letter of 30 June 2026 (ref. BA 54-FR 2210/00067#00005) |
| 8th amendment (Circular 06/2024 (BA)); BTR 5 transition period ran until 31 December 2024 | 29 May 2024 to 30 June 2026 (superseded) | BaFin, Circular 06/2024 |
| BAIT no longer applicable to DORA institutions | since 17 January 2025 | BaFin announcement “DORA kommt”, 9 January 2025 |
| BAIT fully repealed (FinmadiG: further institutions subject to DORA from 1 January 2027) | as of 31 December 2026 | BaFin announcement “DORA kommt”, 9 January 2025 |
Where can I find the MaRisk as a PDF (with explanatory notes)?
BaFin provides the official MaRisk version (Circular 06/2026 (BA) of 30 June 2026, regulatory text including explanatory notes, 82 pages) on the download page for Circular 06/2026. All official accompanying documents of the 9th amendment are available there:
01Circular 06/2026 (BA)
The complete MaRisk text of the 9th amendment with integrated explanatory notes (82 pages).
02Cover letter of 30 June 2026
Ref. BA 54-FR 2210/00067#00005: governs entry into force and the transition period until 1 January 2027.
03Official comparison versions
8th vs. 9th amendment (comparison version directly as PDF) as well as consultation draft vs. final version: the source for the frequently searched “MaRisk comparison version”.
04Historical version
Circular 06/2024 (BA) of 29 May 2024 (8th amendment) remains available on the BaFin publication page.
05Bundesbank topic page
Supplementary overview by Deutsche Bundesbank on the “MaRisk-Neufassung 2026”.
How are the MaRisk structured? (AT and BT)
The MaRisk are divided into two parts: the General Part (AT 1–AT 9) contains the risk management principles applying to all institutions, while the Special Part (BT) provides business-specific detail: BTO for the organisational and operational structure in lending, trading and real-estate business, BTR 1–5 for the risk management and controlling processes per risk type, and BT 2 for risk reporting (structure per Circular 06/2026 (BA)). The module map shows the subject and key references per MaRisk module:
| Module | Subject (brief purpose) | Key reference (Circular 06/2026) |
|---|---|---|
| AT 1 | Preliminary remarks: legal bases (Sections 25a, 25b, 26c KWG), proportionality, definition of “small/very small institutions” | AT 1 paras. 1–3 |
| AT 2 | Scope of application: addressees (SIs excluded), material risks, covered business | AT 2.1 para. 1 |
| AT 3 | Overall responsibility of the management board; new: “AT 3.2 Responsibility of the supervisory body and its committees” | AT 3.2 (new) |
| AT 4 | Risk-bearing capacity, strategies, internal control system (incl. stress tests, models), special functions incl. internal audit | AT 4.3.3; AT 4.3.4 (models); AT 4.4.3 (internal audit) |
| AT 5 | Organisational guidelines | AT 5 |
| AT 6 | Documentation | AT 6 |
| AT 7 | Resources: staff, technical and organisational resources, business continuity management | AT 7.2 (2 paragraphs) |
| AT 8 | Adjustment processes: new products and markets, changes to operational processes and structures | AT 8 |
| AT 9 | Outsourcing: risk analysis, contractual requirements, central outsourcing management, outsourcing register; ICT carve-out to DORA | AT 9 paras. 1, 5, 12–13 |
| BT 1 (BTO/BTR) | Internal control system of business processes: BTO 1 lending, BTO 2 trading, BTO 3 real estate; BTR 1 counterparty default, BTR 2 market price, BTR 3 liquidity, BTR 4 operational, BTR 5 credit spread risks | BTO; BTR 1–5 |
| BT 2 | Risk reporting (until the 8th amendment: BT 3) | BT 2 |
The module structure of the MaRisk has been verified against the table of contents of Circular 06/2026. Brief purpose descriptions of individual modules are partly still based on the 06/2024 version; statements that depend on the version name the version explicitly.
What did the 9th MaRisk amendment change?
The 9th MaRisk amendment (Circular 06/2026 (BA) of 30 June 2026) makes the MaRisk more strongly principles-based, reduces complexity considerably and expands the relief for small and very small institutions (BaFin announcement of 30 June 2026); the final PDF version comprises 82 pages. According to BaFin's estimate, the new size categories create relief for 80 to 85 percent of institutions; BaFin quantifies the reduction in text volume as “122 pages became around 80” (BaFin expert article “MaRisk schaffen mehr Spielraum für Banken”, BaFinJournal, 25 June 2026). The amendment emerged from consultation 02/2026 (draft of 1 April 2026, comments until 8 May 2026, BaFin consultation announcement). The most important changes versus the 8th amendment, verified against the full text:
01DORA delineation
AT 7.2 is reduced to 2 paragraphs; ICT services within the meaning of Art. 3 No. 21 DORA under third-party risk management pursuant to Art. 28–30 DORA no longer fall under AT 9 (explanatory note on AT 9 para. 1).
02Outsourcing
A central outsourcing management function replaces the outsourcing officer; its tasks explicitly include the outsourcing register pursuant to Section 25b (1) sentence 4 KWG (AT 9 para. 12).
03Structural rebuild
The internal audit module BT 2 of the 8th amendment is removed (consolidated into AT 4.4.3; quarterly reports instead of an annual overall report, AT 4.4.3 para. 9); risk reporting moves from BT 3 to BT 2; “use of models” is finally named AT 4.3.4, and the former AT 4.3.4 (risk data aggregation) is removed without replacement.
04ESG
The 9th amendment implements EBA/GL/2025/01 (ESG risks) and EBA/GL/2025/04 (environmental scenario analyses); environmental risks must be taken into account in stress tests, supplemented by long-term resilience analyses (AT 4.3.3 para. 7).
Where internal audit is fully outsourced, AT 9 para. 10 still requires a designated person within the institution to ensure proper performance. The current explanatory note refers to quarterly reporting under AT 4.4.3 para. 9 and findings follow-up under para. 11. Further changes and implementation by 1 January 2027 are explained in 9th MaRisk amendment: changes and implementation.
What applies to IT: MaRisk, BAIT or DORA?
For institutions within the DORA scope, ICT risk management has been governed since 17 January 2025 by the DORA Regulation; the same institutions have been excluded from the BAIT scope since 17 January 2025, and as of 31 December 2026 BaFin repeals the BAIT entirely (BaFin announcement “DORA kommt” of 9 January 2025). Via the FinmadiG, further institutions become subject to DORA from 1 January 2027 (same BaFin announcement).
The MaRisk remain authoritative for general risk management alongside this and have tidied up the interfaces to IT since the 9th amendment: AT 7.2 is limited to 2 paragraphs (technical and organisational resources, data quality processes), and ICT services under the DORA third-party regime fall outside AT 9. The explanatory note on AT 9 para. 1 states the carve-out verbatim:
“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management under Art. 28-30 DORA do not fall within the scope of AT 9.”
For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956 ESAs: first DORA report on major ICT-related incidents
The practical consequence of the AT 9 carve-out is two separate registers that institutions must keep cleanly apart:
| Feature | MaRisk outsourcing register | DORA register of information |
|---|---|---|
| Legal basis | Section 25b (1) sentence 4 KWG; AT 9 para. 12 (Circular 06/2026 (BA)) | Art. 28(3) DORA; ITS templates of Implementing Regulation (EU) 2024/2956 |
| Subject | All material and non-material outsourcing under section 25b(1) KWG; assess separately whether an ICT service constitutes outsourcing | all contractual arrangements on ICT services (15 templates, provider identifiers under the ITS (LEI/EUID rules apply)) |
| Supervisory contact | maintained on an ongoing basis by the central outsourcing management function | annual submission via the BaFin portal MVP; 2nd cycle 9 to 30 March 2026 with reference date 31 December 2025 |
The data model, submission format and ongoing maintenance are covered in DORA register of information. The scope of the two cybersecurity frameworks is compared in NIS2 vs. DORA.
Who do the MaRisk apply to? (scope and proportionality)
Since the 9th amendment, the standard addressees of the MaRisk are the nationally supervised institutions (LSIs); significant institutions (SIs) within the meaning of Art. 6 of the SSM Regulation under direct ECB supervision fall outside the scope (AT 2.1 para. 1, Circular 06/2026 (BA) of 30 June 2026). Within the scope, AT 1 para. 3 tiers the requirements by size category: small institutions are institutions classified as SNCIs (Art. 4 (1) No. 145 CRR) as well as CRD third-country branches of risk class 2; very small institutions have total assets of at most EUR 1 billion on a four-year average (factoring institutions: in addition, annual receivables purchase volume of up to EUR 5 billion on a four-year average) and use the relief even without an SNCI classification.
Specific relief under the 9th MaRisk amendment: very small institutions may assign the compliance officer role (AT 4.4.2 para. 4) and internal audit tasks (AT 4.4.3 para. 1) to a member of the management board (each with safeguards against conflicts of interest), dispense with risk-type-specific stress tests (AT 4.3.3 para. 2) and fully outsource the compliance function or internal audit (AT 9 para. 5). For small institutions, a bank-wide downturn scenario generally suffices and inverse stress tests are dispensable (AT 4.3.3 paras. 3–4); merely annual monitoring of strategy and capital planning requires an additional buffer of at least two percentage points of Common Equity Tier 1 capital (AT 4.2 para. 5).
In lending business, the risk relevance threshold, to be defined individually by each institution, remains the central proportionality lever of the MaRisk: for credit decisions on business classified as not material from a risk perspective, the institution may determine that only one vote is required instead of two votes from front office and back office (“non-risk-relevant lending business”, BTO 1.1 para. 4, Circular 06/2026 (BA)). Each institution defines the delineation between risk-relevant and non-risk-relevant lending business on its own responsibility from a risk perspective (explanatory note on BTO 1.1 para. 4).
BaFin published the WpI MaRisk on 24 August 2026. They apply to small and medium-sized investment firms from 1 January 2027. Until then, the banking MaRisk remain the basis; large investment firms continue to apply the banking MaRisk. BaFin: MaRisk für Kleine und Mittlere Wertpapierinstitute
Which MaRisk amendments have there been since 2005?
The MaRisk were first issued in 2005. This selected history puts the first version and the three most recent amendments in context. The current text is Circular 06/2026 (BA) of 30 June 2026; Deutsche Bundesbank provides previous versions and comparison documents.
| Amendment | Circular | Date | Core change | Source |
|---|---|---|---|---|
| First version | Circular 18/2005 | 2005 | First version of the Minimum Requirements for Risk Management | Deutsche Bundesbank |
| 7th amendment | Circular 05/2023 (BA) | 29 June 2023 | Loan origination and monitoring, ESG risks, models in risk management, real estate business and trading from home | BaFin |
| 8th amendment | Circular 06/2024 (BA) | 29 May 2024 | Implementation of EBA/GL/2022/14: BTR 2.3 (interest rate risk) specified, BTR 5 (credit spread risk) new, implementation deadline 31 December 2024; clarifications incl. AT 4.2, AT 4.3.3, AT 7.2, AT 7.3 | BaFin |
| 9th amendment | Circular 06/2026 (BA) | 30 June 2026 | Principles orientation, size categories (SIs excluded), DORA carve-out (AT 7.2, AT 9 para. 1), central outsourcing management with outsourcing register (AT 9 para. 12), ESG (EBA/GL/2025/01 and /04, Section 26c KWG), risk reporting newly as BT 2 | BaFin |
Three Lines: who acts, who challenges and who independently assesses?
The Three Lines Model describes governance roles. The first line operates processes and controls. The second contributes expertise, monitoring and challenge. Internal audit forms the independent third line. The IIA edition of July 2026 emphasises coordinated information and clear accountability; the model does not replace specific statutory functions.
| Role | Contribution and information handover |
|---|---|
| Business team / first line | Changes its workflow, implements actions and provides evidence of implementation. |
| Compliance / second line | Assesses regulatory relevance within its remit, challenges the mapping and reports remaining gaps. |
| Internal audit / third line | Assesses effectiveness under its own risk-based mandate and independently follows up findings. |
| Management and governing body | Receive information appropriate to their mandates and decide on or oversee material unresolved issues. |
In a shared record, each handover needs an originator, a traceable version and an accountable recipient role. A business team must not describe its own completion notice as independent assurance. Differing assessments should remain visible instead of disappearing into a single green status. Actual responsibilities follow the relevant MaRisk functions and the institution’s organisational structure.
For institutions subject to section 25a KWG, statutory separation governs: paragraph 1 no. 3 prohibits combining internal audit with other business areas or control functions. Flexibility in the general IIA model does not override that requirement.
Legal and professional sources: The IIA: Three Lines Model, Statement of Position, 2026; BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbank; KWG § 25a: Organisation, Kontrollfunktionen und unabhängige Interne Revision.
Related topics
- 9th MaRisk Amendment: Changes, Consultation 02/2026, Timeline: delta table, relief, LSI checklist.
- DORA Regulation: the ICT regime since 17 January 2025: scope, core obligations and pillars.
- DORA register of information: deadline, content, template: cycles, ITS templates and completion guide.
- MaRisk deadlines in the banking regulation roadmap: all dates 2026 to 2028+ bundled cross-regulatorily.
- GRC software for banks: selection criteria under MaRisk and DORA: regime switch, mandatory criteria and contract content.
Frequently asked questions about the MaRisk
Sources & further reading
- BaFin: Circular 06/2026 (BA), MaRisk. Download page with circular, cover letter and comparison versions (30 June 2026)bafin.de
- BaFin: announcement “MaRisk-Novelle: Mehr Proportionalität” (30 June 2026)bafin.de
- BaFin: announcement “BaFin konsultiert 9. MaRisk-Novelle” (consultation 02/2026, 1 April 2026)bafin.de
- BaFin: Circular 06/2024 (BA), MaRisk (29 May 2024; historical 8th amendment)bafin.de
- Section 25a KWG: special organisational duties (gesetze-im-internet.de)gesetze-im-internet.de
- Section 25b KWG: outsourcing (gesetze-im-internet.de)gesetze-im-internet.de
- Deutsche Bundesbank: “MaRisk-Neufassung 2026” (MaRisk topic page)bundesbank.de
- BaFin: announcement “DORA kommt: Änderungen bei den aufsichtlichen Anforderungen an die IT” (9 January 2025, BAIT transition)bafin.de
- BaFin: expert article “MaRisk schaffen mehr Spielraum für Banken” (BaFinJournal, 25 June 2026)bafin.de
- BaFin: announcement “WpI MaRisk: BaFin konsultiert Rundschreiben” (6 May 2026)bafin.de
- ESAs/EBA: press release on the first annual report on major ICT-related incidents under DORA (3 June 2026)eba.europa.eu
- ESAs/EBA: press release on the designation of 19 critical ICT third-party providers (CTPPs) under DORA (18 November 2025)eba.europa.eu
- Implementing Regulation (EU) 2024/2956 (ITS: templates of the DORA register of information) (EUR-Lex)eur-lex.europa.eu
- BaFin: MaRisk für Kleine und Mittlere Wertpapierinstitutebafin.de
- Implementing Regulation (EU) 2024/2956, register templateseur-lex.europa.eu
- Corrigendum to Implementing Regulation (EU) 2024/2956eur-lex.europa.eu
- The IIA: Three Lines Model, Statement of Position, 2026theiia.org
- BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbankbundesbank.de
An offer from T-NEX GmbH
Discuss the project with T-NEX
Moving from a requirement to daily work means connecting requirements, assessments and actions. The product pages describe documented workflows; consulting helps establish the appropriate scope for your institution.
Management: Andreas Unruh and Christoph Gembruch.
Published by T-NEX GmbH.
