Key takeaways
- The current version is BaFin Circular 06/2026 (BA) of June 30, 2026, the ninth MaRisk amendment. It has applied since publication, with a transition period until January 1, 2027 for additional requirements.
- Its legal basis is § 25a(1) KWG; MaRisk also specifies § 25b KWG (outsourcing) and § 26c KWG (ESG risks).
- Significant institutions under direct ECB supervision are no longer in scope. Small and very small institutions receive expressly regulated reliefs.
- ICT services subject to ICT third-party risk management under Articles 28 to 30 of DORA fall outside the outsourcing module AT 9.
What is MaRisk?
MaRisk (Mindestanforderungen an das Risikomanagement, minimum requirements for risk management) is a BaFin circular that specifies what § 25a(1) KWG, the German Banking Act, requires of the risk management of credit and financial services institutions. Under AT 1 para. 1, it sets out a flexible and practical framework for designing risk management. BaFin and the Deutsche Bundesbank develop it jointly, and it also brings guidelines of the European Banking Authority (EBA) into German supervisory practice.
A circular is not a statute. With a circular, BaFin publishes its administrative practice and its reading of the law, and audits measure against that reading. The circular is principles-based: requirements apply in proportion to the nature, scale, complexity and risk content of the business. How MaRisk relates to a bank's risk management as a whole is explained in the entry on risk management in banks; the framework for ICT risk is set by DORA, which the DORA guide explains.
Which MaRisk version is current?
The current version is Circular 06/2026 (BA) of June 30, 2026, the ninth MaRisk amendment (as of October 2026). BaFin published the revised circular on June 30, 2026, and it took effect on publication. Where it creates additional requirements in individual cases, BaFin grants a transition period until January 1, 2027. With the amendment, BaFin also moved its supervisory notice of November 26, 2024 into the text of the circular. Record the version and the retrieval date in internal policies, not just the name: MaRisk is revised at intervals, and each new version replaces the previous one.
The 9th MaRisk amendment: 5 changes
According to BaFin, the ninth amendment is shorter, more principles-based and more proportionate. Five changes stand out:
- Length: According to a BaFin article, 122 pages became around 80; the circular runs to 82 pages. Detailed rules were turned into more general wording rather than simply deleted.
- Size classes: On top of general proportionality, MaRisk defines size classes with expressly regulated reliefs (AT 1 para. 3). BaFin estimates that the size classes create relief for 80 to 85 percent of institutions.
- Scope: Significant institutions under direct ECB supervision are removed from scope (AT 2.1 para. 1).
- Interface with DORA: ICT services subject to third-party risk management under Articles 28 to 30 of DORA are excluded from the outsourcing module AT 9 (explanatory note to AT 9 para. 1).
- New EBA guidelines: These include the guidelines on environmental scenario analysis (EBA/GL/2025/04).
Who does MaRisk apply to?
Under AT 2.1 para. 1, MaRisk applies to all institutions under § 1(1b) KWG and § 53(1) KWG unless they are classified as significant institutions under Article 6 of the SSM Regulation and supervised directly by the ECB. It also covers CRD third-country branches and the foreign branches of German institutions. Financial services institutions and large investment firms under the WpIG apply it to the extent their size and the nature, scale, complexity and risk content of their business require (AT 2.1 para. 2).
| MaRisk size class | Definition | Consequence |
|---|---|---|
| Very small institutions | total assets of up to EUR 1 billion on a four-year average | may use the reliefs for small institutions even without SNCI status |
| Small institutions | small and non-complex institutions (SNCI) under Article 4(1)(145) CRR | expressly regulated reliefs in the individual modules |
| Other less significant institutions | not SNCI, not directly supervised by the ECB | full application, proportionate to the risk profile |
| Significant institutions | Article 6 SSM Regulation, direct ECB supervision | outside the scope of MaRisk |
MaRisk structure: general and special part
MaRisk is modular. The general part (AT) holds the core principles of risk management, the special part (BT) the requirements for specific business lines, risk types and risk reporting.
| Module | Content |
|---|---|
| AT 1 to AT 3 | purpose, scope, responsibility of management and supervisory body |
| AT 4 | risk-bearing capacity, strategies, internal control system, stress tests, models, special functions (risk control, compliance, internal audit) |
| AT 5 to AT 8 | organizational policies, documentation, resources including business continuity management, adjustment processes |
| AT 9 | outsourcing |
| BTO 1 to BTO 3 | organization of lending, trading and real estate business |
| BTR 1 to BTR 5 | counterparty, market price, liquidity, operational and credit spread risks |
| BT 2 | risk reporting |
What does MaRisk compliance mean?
In the narrow sense, MaRisk compliance means the compliance function under AT 4.4.2 MaRisk; in the broad sense, adherence to the whole circular. Under AT 4.4.2, every institution must have a compliance function that counters the risks arising from non-compliance with legal rules and requirements:
- It works toward effective procedures for compliance with the material legal rules and corresponding controls, and advises management (para. 1).
- It identifies, at regular intervals and on a risk basis, the material legal rules whose breach could endanger the institution's assets (para. 2).
- It generally reports directly to management and must be independent of front office and trading units (para. 3).
- It may be combined with other suitable functions; the circular expressly names the money laundering officer, the data protection officer and the ICT risk control function under Article 6(4) of DORA. The money laundering officer and the data protection officer generally may not be combined with each other.
- It reports to management at least annually and when needed (para. 6).
What does MaRisk require for business continuity management?
Under AT 7.3 para. 1 MaRisk, an institution must provide for activities and processes that constitute critical or important functions through a business continuity plan. The plan must be updated annually and when needed, and management must be informed in writing at least quarterly and when needed about the state of business continuity management. It rests on business impact analyses based on an overview of all functions, including the ICT systems needed. The plan comprises business continuity and recovery plans based on plausible scenarios (para. 3), and its effectiveness must be reviewed annually for critical or important functions (para. 4). The entry on emergency management covers the topic in general.
The 8 EBA guidelines in MaRisk
Under the explanatory notes to AT 1 para. 2, MaRisk version 06/2026 implements eight EBA guidelines insofar as they concern risk management:
- Stress testing of institutions (EBA/GL/2018/04)
- Management of non-performing and forborne exposures (EBA/GL/2018/06)
- Outsourcing arrangements (EBA/GL/2019/02)
- Loan origination and monitoring (EBA/GL/2020/06)
- Internal governance (EBA/GL/2021/05)
- Interest rate risk and credit spread risk in the banking book (EBA/GL/2022/14)
- Management of ESG risks (EBA/GL/2025/01)
- Environmental scenario analysis (EBA/GL/2025/04)
Sections of these guidelines apply in addition only where MaRisk expressly refers to them; otherwise the guidelines count as implemented in MaRisk.
MaRisk, BAIT and DORA: the boundary in brief
DORA, Regulation (EU) 2022/2554, has applied directly to the ICT risk of financial entities since January 17, 2025; MaRisk remains in place for risk management as a whole under § 25a KWG. BAIT, which specified the IT requirements within MaRisk, has no longer applied to DORA institutions since January 17, 2025 and will be repealed in full at the end of December 31, 2026. Where the 06/2026 revision draws the line to DORA, for strategy, control functions and outsourcing, is covered in the article MaRisk and DORA; the comparison DORA vs BAIT shows the move from BAIT to DORA.
Where Rizzqo meets MaRisk
Rizzqo holds DORA as a requirement catalog, and that is the interface: Rizzqo attaches the DORA requirements, by asset category and subcategory, to the systems, services and ICT service providers they apply to. The responsible person answers each requirement on the asset with a justification and evidence, and finalization carries a name and a timestamp. Open items can be captured in a risk assessment with likelihood in percent and impact in euros that is linked to the affected assets, and the resulting tasks can sync with Jira.