On June 30, 2026, the German regulator, the Federal Financial Supervisory Authority (Bundesanstalt für FinanzdienstleistungsaufsichtBaFin), published the revised circular “Minimum Requirements for Risk Management “(Mindestanforderungen an das Risikomanagement (MaRisk)) after consultation. It is the ninth revision of the MaRisk.

In brief, the revised MaRisk are shorter, more principles-based and more proportionate than the old MaRisk and the entities subject to MaRisk have been redefined.

Scope of application

MaRisk has traditionally applied to all types of German institutions, including significant institutions. Going forward, however, MaRisk will apply to all credit institutions that are not directly supervised by the European Central Bank (ECB), i.e excluding significant credit institutions.  

Furthermore, the scope of application has been extended to CRD third-country branches (CRD-Drittstaatenzweigstellen) as defined in Section 53c(1) of the German Banking Act (KreditwesengesetzKWG). This was consequently done in light of the fact that the German CRD VI Implementing and Bureaucracy Reduction Act (Bankenrichtlinienumsetzungs- und Bürokratieentlastungsgesetz – BRUBEG) introduces a new comprehensive supervisory regime for CRD third country branches in sections 53c to 53cq of the KWG. Since CRD third-country branches do not have a supervisory body (Aufsichtsorgan), these institutions must instead appropriately involve their corporate headquarters in their risk management.   

Under certain conditions, the MaRisk also apply to financial services institutions and large investment firms pursuant to Section 2(18) of the German Securities Trading Institutions Act (WertpapierinstitutsgesetzWpIG), which are required to comply with Sections 25a, 25b and 26c of the KWG, insofar as this is appropriate given the institution’s size, the nature, scope, complexity and risk profile of its business activities.

Although significant institutions that are directly supervised by the ECB will no longer fall within the scope of the MaRisk framework, some might continue to voluntarily apply selected MaRisk requirements going forward.

Three clearly defined categories of firms

BaFin has introduced three clearly defined size categories. For most institutions, the balance sheet total will be the key criterion in determining whether, and to what extent, they can benefit from regulatory relief. The three categories are:

Very small institutions: This category includes institutions and CRD third-country branches with a balance sheet of less than EUR 1 billion calculated on the basis of a four-year average;

Small institutions: Small and non-complex institutions (SNCIs) as defined in Article 4(1)no.145 CRR (Capital Requirements Regulation, Regulation (EU) No 575/2013) and Class 2 CRD third-country branches; and

Other Less Significant Institutions (LSIs).

Very small institutions may rely on the exemptions and simplifications available to SNCIs, notwithstanding that they do not satisfy the requirements for classification as SNCIs;

For SNCIs and/or very small institutions, the relevant sections of MaRisk expressly provide for specific regulatory relief, for example with respect to stress testing requirements (AT 4.3.3), Risk-bearing capacity (AT 4.1 (9)), Monitoring of the business strategy and capital planning (AT 4.2 (5)), Risk controlling function (AT 4.4.1(1) and (4)), Compliance function (AT 4.4.2 (4)), the Internal audit function (AT 4.4.3 (1)), to mention just a few passages.

The revised MaRisk do not provide for specific regulatory relief for LSIs.

Paradigm shift

The revised MaRisk have been reduced in length by approximately one third. To simplify the framework and reduce its complexity, a number of detailed requirements have been removed and replaced by more general, principles-based provisions. This reflects a deliberate move away from granular, prescriptive rules toward high-level principles that give institutions greater flexibility in implementing risk management systems appropriate to their individual size, business model, and risk profile.

Implementation of EBA Guidelines

The ninth MaRisk amendment incorporates the following EBA Guidelines to the extent that they concern the risk management framework of institutions. The main reason is that BaFin sought to align MaRisk with the current European regulatory framework and to avoid duplication between national and European supervisory requirements. They include: 

– Guidelines on institutions stress testing (EBA/GL/2018/04)

– Guidelines on management of non-performing and forborne exposures (EBA/GL/2018/06)

– Guidelines on outsourcing arrangements (EBA/GL/2019/02)

– Guidelines on loan origination and monitoring (EBA/GL/2020/06)

– Guidelines on internal governance under CRD (EBA/GL/2021/05)

– Guidelines issued on the basis of Article 84 (6) of Directive 2013/36/EU specifying criteria for the identification, evaluation, management and mitigation of the risks arising from potential changes in interest rates and of the assessment and monitoring of credit spread risk, of institutions’ non-trading book activities (EBA/GL/2022/14)

– Guidelines on the management of environmental, social and governance (ESG) risks (EBA/GL/2025/01)

– Guidelines on environmental scenario analysis (EBA/GL/2025/04).

In section AT 2.2 (3) the MaRisk now include, for the first time, a definition of ESG risks.

Examples of other material amendments

New MaRisk Requirements on Outsourcing and DORA: ICT services that fall within the scope of DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) and are subject to the ICT third-party risk management requirements under Articles 28-30 DORA are excluded from the scope of MaRisk AT 9. The ninth MaRisk amendment has abolished the requirement to establish a central outsourcing officer (zentraler Auslagerungsbeauftragter).

Outlook

According to Nikolas Speer, BaFin’s Executive Director for Banking Supervision, BaFin expects that the vast majority of institutions will benefit from the simplifications introduced, for example through the transparent definition of size categories. The shift towards more principle-based requirements and fewer detailed rules represents a genuine paradigm change, coupled with a greater degree of trust in supervised institutions.

The move towards a more principles-based regime is intended to simplify compliance by reducing prescriptive requirements and allowing institutions greater flexibility in implementing supervisory expectations in a manner proportionate to their size, complexity and risk profile. Whether this objective will be achieved in practice, however, remains to be seen.

At the same time, the transition from a prescriptive, rules-based regime to a more principles-based framework places greater responsibility on institutions to identify, assess and document their risks, and to demonstrate that such risks are being managed appropriately through their internal governance and risk-management arrangements. Consequently, the reduction in detailed regulatory requirements may not necessarily translate into a reduced compliance burden.