DEEN
Regulation

MaRisk 2026: current version and requirements

MaRisk under Circular 06/2026: scope, structure and relationship with DORA, including the limited transition and investment-firm distinction.

First version: Updated: Reading time: about 15 minutes

Symbolic image for the MaRisk: a risk manager reviewing a printed BaFin circular at a conference table, with the Frankfurt banking skyline in the background

The MaRisk (Minimum Requirements for Risk Management) are BaFin's central circular on the risk management of German credit institutions; they specify Section 25a (1) of the German Banking Act (KWG) (proper business organisation). The MaRisk are not a law but an administrative provision. The current version is the 9th amendment: Circular 06/2026 (BA) of 30 June 2026, in force upon publication (BaFin download page). Where this gives rise to additional requirements in individual cases, a transition period until 1 January 2027 applies (cover letter, ref. BA 54-FR 2210/00067#00005).

What are the MaRisk? (explained simply)

On the basis of Section 25a (1) KWG, the MaRisk set out a flexible and practical framework for structuring the risk management of institutions; they additionally specify Section 25b KWG (outsourcing) and, since the 9th amendment, Section 26c KWG on ESG risks (AT 1 para. 1, Circular 06/2026 (BA) of 30 June 2026). The final version addresses the group dimension under Section 25a (3) KWG in its scope of application: parent undertakings of a group of institutions must observe the MaRisk requirements at group level to the extent this appears sensible and necessary for adequate risk management at group level pursuant to Section 25a (3) KWG (AT 2.1 including explanatory note, Circular 06/2026 (BA)). The MaRisk thereby translate qualitative Pillar 2 supervision (ICAAP/SREP) into German administrative practice. The legal bases are named by the regulatory text itself:

“On the basis of Section 25a (1) of the German Banking Act (KWG), this circular sets out a flexible and practical framework for structuring the risk management of institutions. It further specifies the requirements of Section 25b KWG (outsourcing) and Section 26c KWG (ESG risks).”
Circular 06/2026 (BA), AT 1 para. 1, of 30 June 2026, unofficial translation; BaFin download page

The MaRisk are not a law: as an administrative provision, they specify the underlying statutory duty under Section 25a (1) KWG, which continues to apply independently of the circular's wording. A principle that has run through the framework since the first version (Circular 18/2005, Deutsche Bundesbank) is proportionality: the MaRisk requirements scale via opening clauses with the size, complexity and riskiness of the business.

Which MaRisk version is current?

The current version is the 9th amendment of the MaRisk: Circular 06/2026 (BA) of 30 June 2026, in force upon publication (BaFin announcement “MaRisk-Novelle: Mehr Proportionalität” of 30 June 2026). For additional requirements arising in individual cases, the cover letter (ref. BA 54-FR 2210/00067#00005) grants a transition period until 1 January 2027; the supervisory notice of 26 November 2024 has been incorporated into the MaRisk regulatory text. In the official wording:

“The new version of the MaRisk enters into force upon publication today. Where the MaRisk give rise to additional requirements in individual cases, a transition period until 1 January 2027 is granted.”
BaFin, cover letter to the new MaRisk version of 30 June 2026, ref. BA 54-FR 2210/00067#00005, section “Übergangsfrist” (transition period), unofficial translation; BaFin download page

The predecessor version, Circular 06/2024 (BA) of 29 May 2024 (8th amendment, BaFin), has been superseded since 30 June 2026; Deutsche Bundesbank lists the current version as the “MaRisk-Neufassung 2026”. The MaRisk deadlines at a glance; a cross-regulatory bundling of all dates is provided by the banking regulation roadmap:

MaRisk deadlines at a glance
SubjectDeadline / statusReference
9th amendment (Circular 06/2026 (BA)) in force30 June 2026, upon publicationBaFin announcement of 30 June 2026
Transition period for additional requirements arising in individual cases; likewise adjustments where a documented interpretation deviates from the supervisory notice of 26 November 2024until 1 January 2027Cover letter of 30 June 2026 (ref. BA 54-FR 2210/00067#00005)
8th amendment (Circular 06/2024 (BA)); BTR 5 transition period ran until 31 December 202429 May 2024 to 30 June 2026 (superseded)BaFin, Circular 06/2024
BAIT no longer applicable to DORA institutionssince 17 January 2025BaFin announcement “DORA kommt”, 9 January 2025
BAIT fully repealed (FinmadiG: further institutions subject to DORA from 1 January 2027)as of 31 December 2026BaFin announcement “DORA kommt”, 9 January 2025

Where can I find the MaRisk as a PDF (with explanatory notes)?

BaFin provides the official MaRisk version (Circular 06/2026 (BA) of 30 June 2026, regulatory text including explanatory notes, 82 pages) on the download page for Circular 06/2026. All official accompanying documents of the 9th amendment are available there:

  1. 01Circular 06/2026 (BA)

    The complete MaRisk text of the 9th amendment with integrated explanatory notes (82 pages).

  2. 02Cover letter of 30 June 2026

    Ref. BA 54-FR 2210/00067#00005: governs entry into force and the transition period until 1 January 2027.

  3. 03Official comparison versions

    8th vs. 9th amendment (comparison version directly as PDF) as well as consultation draft vs. final version: the source for the frequently searched “MaRisk comparison version”.

  4. 04Historical version

    Circular 06/2024 (BA) of 29 May 2024 (8th amendment) remains available on the BaFin publication page.

  5. 05Bundesbank topic page

    Supplementary overview by Deutsche Bundesbank on the “MaRisk-Neufassung 2026”.

How are the MaRisk structured? (AT and BT)

The MaRisk are divided into two parts: the General Part (AT 1–AT 9) contains the risk management principles applying to all institutions, while the Special Part (BT) provides business-specific detail: BTO for the organisational and operational structure in lending, trading and real-estate business, BTR 1–5 for the risk management and controlling processes per risk type, and BT 2 for risk reporting (structure per Circular 06/2026 (BA)). The module map shows the subject and key references per MaRisk module:

MaRisk module map (Circular 06/2026 (BA))
ModuleSubject (brief purpose)Key reference (Circular 06/2026)
AT 1Preliminary remarks: legal bases (Sections 25a, 25b, 26c KWG), proportionality, definition of “small/very small institutions”AT 1 paras. 1–3
AT 2Scope of application: addressees (SIs excluded), material risks, covered businessAT 2.1 para. 1
AT 3Overall responsibility of the management board; new: “AT 3.2 Responsibility of the supervisory body and its committees”AT 3.2 (new)
AT 4Risk-bearing capacity, strategies, internal control system (incl. stress tests, models), special functions incl. internal auditAT 4.3.3; AT 4.3.4 (models); AT 4.4.3 (internal audit)
AT 5Organisational guidelinesAT 5
AT 6DocumentationAT 6
AT 7Resources: staff, technical and organisational resources, business continuity managementAT 7.2 (2 paragraphs)
AT 8Adjustment processes: new products and markets, changes to operational processes and structuresAT 8
AT 9Outsourcing: risk analysis, contractual requirements, central outsourcing management, outsourcing register; ICT carve-out to DORAAT 9 paras. 1, 5, 12–13
BT 1 (BTO/BTR)Internal control system of business processes: BTO 1 lending, BTO 2 trading, BTO 3 real estate; BTR 1 counterparty default, BTR 2 market price, BTR 3 liquidity, BTR 4 operational, BTR 5 credit spread risksBTO; BTR 1–5
BT 2Risk reporting (until the 8th amendment: BT 3)BT 2

The module structure of the MaRisk has been verified against the table of contents of Circular 06/2026. Brief purpose descriptions of individual modules are partly still based on the 06/2024 version; statements that depend on the version name the version explicitly.

What did the 9th MaRisk amendment change?

The 9th MaRisk amendment (Circular 06/2026 (BA) of 30 June 2026) makes the MaRisk more strongly principles-based, reduces complexity considerably and expands the relief for small and very small institutions (BaFin announcement of 30 June 2026); the final PDF version comprises 82 pages. According to BaFin's estimate, the new size categories create relief for 80 to 85 percent of institutions; BaFin quantifies the reduction in text volume as “122 pages became around 80” (BaFin expert article “MaRisk schaffen mehr Spielraum für Banken”, BaFinJournal, 25 June 2026). The amendment emerged from consultation 02/2026 (draft of 1 April 2026, comments until 8 May 2026, BaFin consultation announcement). The most important changes versus the 8th amendment, verified against the full text:

  1. 01DORA delineation

    AT 7.2 is reduced to 2 paragraphs; ICT services within the meaning of Art. 3 No. 21 DORA under third-party risk management pursuant to Art. 28–30 DORA no longer fall under AT 9 (explanatory note on AT 9 para. 1).

  2. 02Outsourcing

    A central outsourcing management function replaces the outsourcing officer; its tasks explicitly include the outsourcing register pursuant to Section 25b (1) sentence 4 KWG (AT 9 para. 12).

  3. 03Structural rebuild

    The internal audit module BT 2 of the 8th amendment is removed (consolidated into AT 4.4.3; quarterly reports instead of an annual overall report, AT 4.4.3 para. 9); risk reporting moves from BT 3 to BT 2; “use of models” is finally named AT 4.3.4, and the former AT 4.3.4 (risk data aggregation) is removed without replacement.

  4. 04ESG

    The 9th amendment implements EBA/GL/2025/01 (ESG risks) and EBA/GL/2025/04 (environmental scenario analyses); environmental risks must be taken into account in stress tests, supplemented by long-term resilience analyses (AT 4.3.3 para. 7).

Where internal audit is fully outsourced, AT 9 para. 10 still requires a designated person within the institution to ensure proper performance. The current explanatory note refers to quarterly reporting under AT 4.4.3 para. 9 and findings follow-up under para. 11. Further changes and implementation by 1 January 2027 are explained in 9th MaRisk amendment: changes and implementation.

What applies to IT: MaRisk, BAIT or DORA?

For institutions within the DORA scope, ICT risk management has been governed since 17 January 2025 by the DORA Regulation; the same institutions have been excluded from the BAIT scope since 17 January 2025, and as of 31 December 2026 BaFin repeals the BAIT entirely (BaFin announcement “DORA kommt” of 9 January 2025). Via the FinmadiG, further institutions become subject to DORA from 1 January 2027 (same BaFin announcement).

The MaRisk remain authoritative for general risk management alongside this and have tidied up the interfaces to IT since the 9th amendment: AT 7.2 is limited to 2 paragraphs (technical and organisational resources, data quality processes), and ICT services under the DORA third-party regime fall outside AT 9. The explanatory note on AT 9 para. 1 states the carve-out verbatim:

“Outsourced or externally procured ICT services within the meaning of Art. 3 No. 21 DORA that are subject to ICT third-party risk management under Art. 28-30 DORA do not fall within the scope of AT 9.”
Circular 06/2026 (BA), explanatory note on AT 9 para. 1, subheading “DORA (Verordnung (EU) 2022/2554)”, unofficial translation; BaFin download page, 30 June 2026

For ICT third-party providers that are legal persons established in the EU, the register permits an LEI or EUID. Equivalent providers outside the EU must use an LEI. Separate template rules govern identifiers for natural persons acting in a business capacity. The European Supervisory Authorities reported 3,383 major ICT-related incidents under DORA for 2025. Around one third involved third-party providers. These figures come from their first annual report, published on 3 June 2026. Implementing Regulation (EU) 2024/2956, register templates Corrigendum to Implementing Regulation (EU) 2024/2956 ESAs: first DORA report on major ICT-related incidents

The practical consequence of the AT 9 carve-out is two separate registers that institutions must keep cleanly apart:

MaRisk outsourcing register vs. DORA register of information
FeatureMaRisk outsourcing registerDORA register of information
Legal basisSection 25b (1) sentence 4 KWG; AT 9 para. 12 (Circular 06/2026 (BA))Art. 28(3) DORA; ITS templates of Implementing Regulation (EU) 2024/2956
SubjectAll material and non-material outsourcing under section 25b(1) KWG; assess separately whether an ICT service constitutes outsourcingall contractual arrangements on ICT services (15 templates, provider identifiers under the ITS (LEI/EUID rules apply))
Supervisory contactmaintained on an ongoing basis by the central outsourcing management functionannual submission via the BaFin portal MVP; 2nd cycle 9 to 30 March 2026 with reference date 31 December 2025

The data model, submission format and ongoing maintenance are covered in DORA register of information. The scope of the two cybersecurity frameworks is compared in NIS2 vs. DORA.

Who do the MaRisk apply to? (scope and proportionality)

Since the 9th amendment, the standard addressees of the MaRisk are the nationally supervised institutions (LSIs); significant institutions (SIs) within the meaning of Art. 6 of the SSM Regulation under direct ECB supervision fall outside the scope (AT 2.1 para. 1, Circular 06/2026 (BA) of 30 June 2026). Within the scope, AT 1 para. 3 tiers the requirements by size category: small institutions are institutions classified as SNCIs (Art. 4 (1) No. 145 CRR) as well as CRD third-country branches of risk class 2; very small institutions have total assets of at most EUR 1 billion on a four-year average (factoring institutions: in addition, annual receivables purchase volume of up to EUR 5 billion on a four-year average) and use the relief even without an SNCI classification.

Specific relief under the 9th MaRisk amendment: very small institutions may assign the compliance officer role (AT 4.4.2 para. 4) and internal audit tasks (AT 4.4.3 para. 1) to a member of the management board (each with safeguards against conflicts of interest), dispense with risk-type-specific stress tests (AT 4.3.3 para. 2) and fully outsource the compliance function or internal audit (AT 9 para. 5). For small institutions, a bank-wide downturn scenario generally suffices and inverse stress tests are dispensable (AT 4.3.3 paras. 3–4); merely annual monitoring of strategy and capital planning requires an additional buffer of at least two percentage points of Common Equity Tier 1 capital (AT 4.2 para. 5).

In lending business, the risk relevance threshold, to be defined individually by each institution, remains the central proportionality lever of the MaRisk: for credit decisions on business classified as not material from a risk perspective, the institution may determine that only one vote is required instead of two votes from front office and back office (“non-risk-relevant lending business”, BTO 1.1 para. 4, Circular 06/2026 (BA)). Each institution defines the delineation between risk-relevant and non-risk-relevant lending business on its own responsibility from a risk perspective (explanatory note on BTO 1.1 para. 4).

BaFin published the WpI MaRisk on 24 August 2026. They apply to small and medium-sized investment firms from 1 January 2027. Until then, the banking MaRisk remain the basis; large investment firms continue to apply the banking MaRisk. BaFin: MaRisk für Kleine und Mittlere Wertpapierinstitute

Which MaRisk amendments have there been since 2005?

The MaRisk were first issued in 2005. This selected history puts the first version and the three most recent amendments in context. The current text is Circular 06/2026 (BA) of 30 June 2026; Deutsche Bundesbank provides previous versions and comparison documents.

MaRisk amendment tracker (excerpt)
AmendmentCircularDateCore changeSource
First versionCircular 18/20052005First version of the Minimum Requirements for Risk ManagementDeutsche Bundesbank
7th amendmentCircular 05/2023 (BA)29 June 2023Loan origination and monitoring, ESG risks, models in risk management, real estate business and trading from homeBaFin
8th amendmentCircular 06/2024 (BA)29 May 2024Implementation of EBA/GL/2022/14: BTR 2.3 (interest rate risk) specified, BTR 5 (credit spread risk) new, implementation deadline 31 December 2024; clarifications incl. AT 4.2, AT 4.3.3, AT 7.2, AT 7.3BaFin
9th amendmentCircular 06/2026 (BA)30 June 2026Principles orientation, size categories (SIs excluded), DORA carve-out (AT 7.2, AT 9 para. 1), central outsourcing management with outsourcing register (AT 9 para. 12), ESG (EBA/GL/2025/01 and /04, Section 26c KWG), risk reporting newly as BT 2BaFin

Three Lines: who acts, who challenges and who independently assesses?

The Three Lines Model describes governance roles. The first line operates processes and controls. The second contributes expertise, monitoring and challenge. Internal audit forms the independent third line. The IIA edition of July 2026 emphasises coordinated information and clear accountability; the model does not replace specific statutory functions.

Self-developed example: an amended policy
RoleContribution and information handover
Business team / first lineChanges its workflow, implements actions and provides evidence of implementation.
Compliance / second lineAssesses regulatory relevance within its remit, challenges the mapping and reports remaining gaps.
Internal audit / third lineAssesses effectiveness under its own risk-based mandate and independently follows up findings.
Management and governing bodyReceive information appropriate to their mandates and decide on or oversee material unresolved issues.

In a shared record, each handover needs an originator, a traceable version and an accountable recipient role. A business team must not describe its own completion notice as independent assurance. Differing assessments should remain visible instead of disappearing into a single green status. Actual responsibilities follow the relevant MaRisk functions and the institution’s organisational structure.

For institutions subject to section 25a KWG, statutory separation governs: paragraph 1 no. 3 prohibits combining internal audit with other business areas or control functions. Flexibility in the general IIA model does not override that requirement.

Legal and professional sources: The IIA: Three Lines Model, Statement of Position, 2026; BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbank; KWG § 25a: Organisation, Kontrollfunktionen und unabhängige Interne Revision.

FAQ

Frequently asked questions about the MaRisk

Are the MaRisk a law?

No. The MaRisk (Minimum Requirements for Risk Management) are a BaFin circular and thus an administrative provision, not a law. The statutory duty of proper business organisation that the MaRisk specify is set out in Section 25a (1) of the German Banking Act (KWG); for outsourcing, the MaRisk additionally specify Section 25b KWG.

Since when have the MaRisk existed?

The first version of the MaRisk appeared in 2005 as Circular 18/2005. The framework has been amended several times since: the current version is the 9th amendment (Circular 06/2026 (BA) of 30 June 2026); the predecessor was the 8th amendment (Circular 06/2024 (BA) of 29 May 2024).

What is the difference between AT and BT?

The General Part (AT 1–9) of the MaRisk contains the basic principles applying to all institutions: from the overall responsibility of the management board through risk-bearing capacity, strategies and the internal control system to resources and outsourcing. The Special Part (BT) provides business-specific detail: BTO governs lending, trading and real-estate business, BTR 1–5 the risk management and controlling processes per risk type, and BT 2 (since the 9th amendment) risk reporting.

What does double proportionality mean?

Double proportionality means that both the intensity of an institution's risk management and the frequency and intensity of supervision grow with the size, complexity and riskiness of the business. The MaRisk translate this principle of qualitative Pillar 2 supervision (ICAAP/SREP) into German administrative practice: smaller institutions use opening clauses, while particularly large or risk-exposed institutions must take more far-reaching precautions.

Are the MaRisk available in English?

The authoritative reference is the German version of Circular 06/2026 (BA) of 30 June 2026. The Bundesbank provides the current text and comparison documents. Translated terms and paragraph references should be checked against the German original.

What is MaRisk compliance?

MaRisk compliance colloquially refers to an institution's adherence to the MaRisk requirements. Within the MaRisk, the compliance function is also a special function of the internal control system: it works towards adherence to the material legal rules and requirements. Since the 9th amendment (Circular 06/2026 (BA)), very small institutions may assign the role of compliance officer to a member of the management board, with safeguards against conflicts of interest (AT 4.4.2 para. 4).

Sources & further reading

  1. BaFin: Circular 06/2026 (BA), MaRisk. Download page with circular, cover letter and comparison versions (30 June 2026)bafin.de
  2. BaFin: announcement “MaRisk-Novelle: Mehr Proportionalität” (30 June 2026)bafin.de
  3. BaFin: announcement “BaFin konsultiert 9. MaRisk-Novelle” (consultation 02/2026, 1 April 2026)bafin.de
  4. BaFin: Circular 06/2024 (BA), MaRisk (29 May 2024; historical 8th amendment)bafin.de
  5. Section 25a KWG: special organisational duties (gesetze-im-internet.de)gesetze-im-internet.de
  6. Section 25b KWG: outsourcing (gesetze-im-internet.de)gesetze-im-internet.de
  7. Deutsche Bundesbank: “MaRisk-Neufassung 2026” (MaRisk topic page)bundesbank.de
  8. BaFin: announcement “DORA kommt: Änderungen bei den aufsichtlichen Anforderungen an die IT” (9 January 2025, BAIT transition)bafin.de
  9. BaFin: expert article “MaRisk schaffen mehr Spielraum für Banken” (BaFinJournal, 25 June 2026)bafin.de
  10. BaFin: announcement “WpI MaRisk: BaFin konsultiert Rundschreiben” (6 May 2026)bafin.de
  11. ESAs/EBA: press release on the first annual report on major ICT-related incidents under DORA (3 June 2026)eba.europa.eu
  12. ESAs/EBA: press release on the designation of 19 critical ICT third-party providers (CTPPs) under DORA (18 November 2025)eba.europa.eu
  13. Implementing Regulation (EU) 2024/2956 (ITS: templates of the DORA register of information) (EUR-Lex)eur-lex.europa.eu
  14. BaFin: MaRisk für Kleine und Mittlere Wertpapierinstitutebafin.de
  15. Implementing Regulation (EU) 2024/2956, register templateseur-lex.europa.eu
  16. Corrigendum to Implementing Regulation (EU) 2024/2956eur-lex.europa.eu
  17. The IIA: Three Lines Model, Statement of Position, 2026theiia.org
  18. BaFin: MaRisk, Rundschreiben 06/2026 (BA), 30.06.2026, amtlicher Volltext bei der Bundesbankbundesbank.de

An offer from T-NEX GmbH

Discuss the project with T-NEX

Moving from a requirement to daily work means connecting requirements, assessments and actions. The product pages describe documented workflows; consulting helps establish the appropriate scope for your institution.

Management: Andreas Unruh and Christoph Gembruch.

Published by T-NEX GmbH.