9th MaRisk Amendment 2026: What Changes for Banks Now

David Curtis Behm
David Curtis Behm
7 min read
9th MaRisk Amendment 2026: What Changes for Banks Now

Regulatory Compliance · Risk Management · BaFin

The 9th MaRisk Amendment is the revision of Germany’s Minimum Requirements for Risk Management published on 30 June 2026. The new MaRisk remains principles-based, reinforces the principle of proportionality, and, above all, reduces the burden on small and very small institutions. The transition period for new and stricter requirements runs through January 1, 2027; the relief measures are effective immediately.

Understood in 2 Minutes

- What’s new? Three mandatory size categories (very small, small/SNCI, other LSIs) with category-specific exemption clauses. The circular has been reduced from 122 to about 80 pages.
- Who benefits? According to BaFin’s assessment, the new size categories will ease the regulatory burden for 80 to 85 percent of institutions. Approximately 950 institutions (about three-quarters of German credit institutions) fall under the SNCI definition.
- Who is excluded? Significant institutions (SIs) under direct ECB supervision. Now included: Branches of third-country institutions pursuant to § 53c of the German Banking Act (KWG).
- When? Reliefs apply immediately; additional requirements benefit from the transition period until 1 January 2027. This does not suspend existing obligations or their review.
- The catch: Reliefs are optional. Eligibility and appropriateness require an institution-specific assessment. A concise decision record can help; a separate extensive opinion for every relief is not a universal standard requirement.

BaFin itself frames the revision as a "vote of confidence" ("Vertrauensvorschuss") in the institutions: fewer detailed prescriptions, more personal responsibility. By the supervisor’s own estimate, the vast majority of German credit institutions benefit from the new reliefs. This article covers the most important changes of the 9th amendment and a concrete implementation roadmap.

Timeline: from consultation to application

  • 26 Nov 2024 — supervisory notice with the first SNCI reliefs (precursor)
  • 1 Apr 2026 — BaFin publishes the draft for consultation (Consultation 02/2026)
  • 19 Jun 2026 — digital supervisory briefing: final content presented
  • 30 Jun 2026 — publication of the final 9th MaRisk Amendment
  • 1 Jan 2027 — end of the transitional period for new and stricter requirements

The revised MaRisk have applied since 30 June 2026. The cover letter grants a transition period until 1 January 2027 for additional requirements in individual cases. Certain organisational adjustments following clarifications of the supervisory notice of 26 November 2024 can also qualify where the institution documented its earlier differing interpretation. Existing requirements remain applicable.

Timeline of the 9th MaRisk Amendment: from the 2024 supervisory notice through consultation and briefing to mandatory application on 1 January 2027

The key changes at a glance

The 9th amendment is the most far-reaching revision of the MaRisk in years. The core points:

  1. New scope: Significant institutions (SIs) under direct ECB supervision fall outside the MaRisk; third-country branches (§ 53c of the German Banking Act, KWG) are newly covered.
  2. New size categories: Less significant institutions (LSIs) are differentiated into "very small", "small" (SNCI) and "other" institutions — with category-specific reliefs.
  3. Risk inventory & risk-bearing capacity: Materiality threshold and the validation cycle can be extended.
  4. Stress testing: Reduced requirements for small and very small institutions.
  5. Risk reporting: Greater flexibility in frequency and design in particular for small institutions.
  6. ESG risks: Specific requirements with a focus on environmental and climate risks, as well as scenario analyses.
  7. Outsourcing: A central outsourcing officer is no longer mandatory.
  8. Lending business: Both additional requirements and simplification in specific areas.
  9. European integration: Implementation of CRD VI (where not already covered by the KWG), EBA guidelines and alignment with DORA.

Scope: SIs out, third-country branches in

The most striking structural change: significant institutions under direct ECB supervision no longer fall under the MaRisk. Consistent — the MaRisk are guidelines by which BaFin binds itself in applying § 25a KWG; they have no binding effect on the ECB. It remains to be seen to what extent SIs (and their auditors) will voluntarily continue applying individual MaRisk modules such as the requirements for trading processes.

Newly in scope are third-country branches within the meaning of § 53c KWG — the logical complement to the new KWG requirements introduced by the German act implementing CRD VI (BRUBEG).

New size categories: who counts as a small or very small institution?

Very small institutions

  • Criterion: total assets of no more than EUR 1 billion on a four-year average. Factoring institutions must additionally meet a EUR 5 billion limit for annual purchased receivables on a four-year average (AT 1 para. 3).
  • Reliefs: very small institutions can also use the reliefs for small institutions without meeting the SNCI criteria. The conditions of each specific provision still apply.

Small institutions (SNCI)

  • Criterion: SNCI criteria under Art. 4(1)(145) CRR, in particular total assets ≤ €5 billion
  • Reliefs: validation, stress testing, separation of functions, outsourcing, lending business and reporting

Other LSIs

  • All remaining less significant institutions — general proportionality and opening clauses

By BaFin’s estimate, around three quarters of German credit institutions qualify as SNCIs — the amendment matters for the breadth of the market, not just for niches.

The new size categories of the 9th MaRisk Amendment: very small institutions up to 1 billion euros, SNCIs up to 5 billion, other LSIs — SIs carved out of scope

The reliefs in detail

Validation and risk-bearing capacity: For risk-bearing-capacity methods, procedures and parameters, AT 4.1 para. 9 requires initial validation before use and follow-up validation at least every three years and when triggered by events. Validation of complex methods is independent of development; small institutions may dispense with this separation. The three-year cycle is not a universal deadline for all models: further model- and process-specific requirements must be assessed. The 5% threshold in AT 2.2 para. 1 concerns an individual risk category; risks that become material in combination must be appropriately considered under AT 4.1 para. 1.

Outsourcing: A central outsourcing officer is no longer explicitly prescribed. Central outsourcing management, including the outsourcing register, remains required under AT 9 para. 12. Full outsourcing of risk control, compliance or internal audit is possible for certain immaterial subsidiary institutions within groups. AT 9 para. 5 additionally permits very small institutions to fully outsource compliance or internal audit; this additional permission does not generally extend to risk control.

Stress testing and reporting: The reliefs in AT 4.3.3 are conditional. For small institutions, a severe downturn or comparable stagflation scenario generally suffices at bank level if it adversely affects all material risks; reverse stress tests may be omitted. Very small institutions may omit risk-type-specific tests if the relevant risks are adversely affected in the overall stress test. Small institutions may use qualitative approaches for environmental risks. Reporting reliefs under BT 2.2 para. 1 also require application in the relevant risk context.

Lending business: The redesign opens up simplification potential, particularly in collateral valuation processes.

ESG risks: specification, not relief

With the amendment, BaFin and the Bundesbank specify the requirements for managing ESG risks under sec. 26c KWG. The focus is on environmental and climate risks; scenario analyses are explicitly required. Institutions that have treated ESG as a qualitative side topic will need to sharpen their risk inventory and scenario capabilities — here the amendment is not a relief but a clarification of supervisory expectations.

More Than Just Relief: Governance and ICT

The requirements for Internal Audit are consolidated in AT 4.4.3. Moving provisions from the former BT 2 does not by itself turn previously non-binding expectations into newly binding requirements. Implementation requires comparison of individual changes, responsibilities and reporting duties with the previous provisions.

ICT/DOR Strategy and Distinction from DORA: Under AT 4.2 para. 2, management establishes an ICT strategy consistent with the business strategy. Where a DOR strategy is required, both may be documented together depending on size and overall risk profile; the same applies to the ICT and business strategies. AT 9 excludes outsourced or externally procured ICT services that fall under Article 3 point 21 and the third-party risk management requirements of Articles 28 to 30 DORA. Other outsourcing arrangements still require separate assessment.

8th vs 9th amendment: the paradigm shift

The 8th amendment of 29 May 2024 implemented, in particular, the EBA Guidelines on interest-rate and credit-spread risks in the banking book. The 9th amendment of 30 June 2026 additionally changes scope, size categories and structure and reinforces proportionate application. Streamlining does not automatically invalidate existing procedures; the 9th redistributes them — by size, complexity and risk profile.

What institutions should do now: roadmap to 1 January 2027

  1. Start with an impact analysis: Determine your size category (check the SNCI criteria under the CRR) and run a gap analysis against the final version.
  2. Decide on reliefs deliberately (September–October): For each proposed relief, assess eligibility, risk profile and the decision. Use a traceable decision record proportionate to its significance; the necessary depth depends on the individual case.
  3. Update your documentation (October–November): Update the risk manual, internal guidelines, outsourcing and validation frameworks to the new structure; set up ESG scenario analyses.
  4. Involve internal audit and the supervisory body early: Define roles, reporting channels and implementation evidence from the outset. Internal audit can accompany the work and review it independently; management and the responsible business functions retain decision and implementation responsibility.

ADVISORI supports your MaRisk implementation from gap analysis and assessment of reliefs to traceable implementation documentation. See also: MaRisk Ongoing Compliance and MaRisk Audit Readiness.

Making implementation concrete: a decision, not a generic checklist

Illustrative example, not a client case: an institution classified as small wants to change the follow-up validation cycle for its risk-bearing-capacity methods. Before deciding, it checks the actual scope of AT 4.1 para. 9, recent validation findings, model changes and unusual data or results. A quiet calendar alone does not justify a longer cycle.

A useful decision note can connect five items: the method and applicable provision; baseline findings and unresolved issues; decision and risk rationale; responsible role and next review date; events that trigger earlier validation. The three-year interval is an upper limit for scheduled follow-up validation within this scope, not an exemption from event-driven reviews.

This turns “relief used” into a reviewable decision. The design and documentation must fit the institution; the example replaces neither a complete gap analysis nor an independent review.

Which support fits your implementation stage?

If applicability is unclear, start by defining the institution category, affected modules and available evidence. Once gaps are known, define concrete engagement outputs such as a prioritised action list, updated policies and traceable decision records. Ahead of a review, also assess whether existing evidence is complete and understandable.

When selecting advisers, ask about comparable institutions, the specialists actually assigned, boundaries with internal and external audit, and agreed outputs. Effort and cost depend particularly on module scope, data and documentation quality, unresolved findings and implementation support. These factors cannot guarantee a successful supervisory or audit outcome.

For an initial inquiry to ADVISORI, start with the institution type, relevant topics, current implementation stage and desired timeframe. Confidential audit reports or customer data are not needed for that initial description. Clarify the engagement scope and required documents with the advisory team through the linked MaRisk consulting page.

Primary sources for verification: final MaRisk text and cover letter of 30 June 2026 on the Deutsche Bundesbank website.

FAQ: the 9th MaRisk Amendment

When does the 9th MaRisk Amendment come into force?

The final version has applied since publication on 30 June 2026. The cover letter grants a transition period until 1 January 2027 for additional requirements in individual cases. Reliefs can already be used where their conditions are met. The transition period does not generally suspend existing obligations or reviews.

What changes with the 9th MaRisk Amendment?

The MaRisk become more proportionate: new size categories with reliefs for small and very small institutions; other changes include a 5% materiality threshold, extended validation cycles, more flexible stress testing and reporting, no mandatory central outsourcing officer, and specified ESG requirements.

Which institutions fall outside the MaRisk now — and who is newly covered?

Significant institutions (SIs) under direct ECB supervision are carved out of the scope. Newly covered are third-country branches under sec. 53c of the German Banking Act (KWG) — relevant for foreign banking groups with German branches.

What are small and very small institutions (SNCIs)?

Very small institutions have total assets of at most €1 billion on a four-year average. Small institutions (SNCIs) meet the criteria of Art. 4(1)(145) CRR, in particular total assets up to €5 billion. Around three quarters of German institutions qualify as SNCIs according to BaFin.

Is a central outsourcing officer still mandatory?

A separate central outsourcing officer is no longer explicitly prescribed. However, AT 9 para. 12 still requires central outsourcing management proportionate to the outsourcing activities, including documentation and an outsourcing register. Decentralised monitoring tasks do not automatically replace this requirement.

What is the 5% materiality threshold?

This applies to each individual risk category: A risk that does not exceed 5% of the risk coverage potential may be classified as immaterial in the economic perspective (AT 2.2, 1). This is an upper limit — the internal standard of an institution may be stricter. However, multiple risks that are individually immaterial but become material when combined must still be appropriately taken into account in the risk-bearing capacity (AT 4.1, para. 1); conversely, there is no fixed 5% limit for the sum of all immaterial risks.

Do institutions have to use the SNCI reliefs?

No. Use of relief is an institution-specific decision. Eligibility and appropriateness need to be explainable. We recommend a short decision note covering the provision, risk assessment, owner and review trigger; this is a working aid, not a prescribed form for every case.

Conclusion

The 9th MaRisk Amendment does not redefine the principles-based framework of MaRisk, but for the first time, proportionality is operationalized through binding size categories with specifically assigned exceptions. Unlike earlier revisions—particularly the 7th amendment—this amendment not only expands the scope of MaRisk but also, in some cases, reduces the regulatory burden. This relief may be particularly noticeable for small and very small institutions. However, this does not happen automatically: It requires that an institution accurately determine its size category, use the exemption clauses in a deliberate and risk-based manner, and document this. At the same time, the amendment introduces additional requirements in specific areas—particularly regarding ESG risks—so that “relief” does not apply to all issues or to all categories of institutions.

Sources: BaFin, announcement of 30 June 2026 ("MaRisk-Novelle: Mehr Proportionalität"); BaFin Consultation 02/2026; supervisory briefing of 19 June 2026.

Hat ihnen der Beitrag gefallen? Teilen Sie es mit:
Further reading

Continue exploring with related insights from our experts.

The EU AI Act for Banks: What 13 Years of BCBS 239 Are Really Worth in the Age of AI
Künstliche Intelligenz - KI

The EU AI Act for Banks: What 13 Years of BCBS 239 Are Really Worth in the Age of AI

The EU AI Act finds banks on familiar ground: data quality, data lineage, model risk management, and human oversight are disciplines that BCBS 239 has required since 2013 and that the ECB has tightened in its RDARR Guide. The head start is real, but limited. Three requirements have no equivalent in the current framework: bias and fairness controls, the explainability of model decisions, and the fundamental rights impact assessment under Article 27. An assessment that identifies specific areas requiring action.

10 min read
Read article
AI-Ready Data: Assessing Your Data – The Data Quality Dimensions That Determine AI Success
Künstliche Intelligenz - KI

AI-Ready Data: Assessing Your Data – The Data Quality Dimensions That Determine AI Success

AI readiness is decided earlier than most organizations expect — at the level of the data itself. This article sets out the data quality dimensions that make data AI-ready, places data readiness for AI within the regulatory framework from the EU AI Act to BCBS 239, and explains why the four classic quality dimensions are not sufficient for AI models.

10 min read
Read article
The CRA Single Reporting Platform (SRP): status, registration and what to prepare
Informationssicherheit

The CRA Single Reporting Platform (SRP): status, registration and what to prepare

The Single Reporting Platform (SRP) is how manufacturers report under the Cyber Resilience Act from 11 September 2026. Till now it is not live, there is no API, and cross-border sharing is manual. What you can prepare regardless.

13 min read
Read article

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance