Choose the regulatory path for your firm. Each question connects the requirement, its purpose and the operational evidence; expand it for triggers, owners and common gaps.
Two frameworks, two review paths
These review paths are editorial implementation examples, not an individual supervisory finding. The statuses are local to this browser view and are not saved.
14 high-level questions for the applicable framework, including risk inventory, capacity, controls, continuity and reporting.
AT 2.1
Scope
Requirement
Determine the firm type, activities and applicable MaRisk modules.
Why
Only applicable obligations can be implemented effectively.
Expected in operation
Reasoned applicability matrix, reviewed when the model changes.
Operational review path
When to check
New licence, activity or structure.
Typical owner
Management / compliance.
Possible evidence
Approved obligations map.
Common gap
An exemption is copied without reasons.
AT 2.2
Risk inventory and concentrations
Requirement
Identify material risks across the firm; consider concentrations and ICT and ESG risk drivers.
Why
Unknown or aggregated risks cannot be controlled.
Expected in operation
Overall risk profile with materiality decisions and actions.
Operational review path
When to check
New product, market or external shock.
Typical owner
Risk control / management.
Possible evidence
Inventory, method, approval.
Common gap
Risks are viewed only by department.
AT 3
Management and oversight
Requirement
Management retains overall responsibility; the supervisory body fulfils its oversight role.
Why
Risk control needs decisions and effective challenge.
Expected in operation
Regular reporting, decisions and tracked findings.
Operational review path
When to check
Strategy change or material risk finding.
Typical owner
Management / supervisory body.
Possible evidence
Minutes, action log.
Common gap
Reports receive no follow-up decision.
AT 4.1
Risk-bearing capacity
Requirement
Align risk-bearing capacity with the overall risk profile and available capital.
Why
Material risks must remain supportable.
Expected in operation
Defined perspectives, limits, recurring calculation and escalation.
Operational review path
When to check
Capital change, loss or limit breach.
Typical owner
Risk control / finance.
Possible evidence
Calculation, limit report, action.
Common gap
A breach appears only in the annual report.
AT 4.2
Business and risk strategy
Requirement
Define, align and review strategies and translate them into steering.
Why
Growth and risk appetite must remain consistent.
Expected in operation
Approved goals, limits and documented review.
Operational review path
When to check
New business line or risk profile change.
Typical owner
Management.
Possible evidence
Strategy, minutes, limits.
Common gap
Expansion exceeds approved risk appetite.
AT 4.3.1–4.3.2
Organisation and controls
Requirement
Design responsibilities, separation of duties and risk control processes.
Why
Uncontrolled decisions and hidden conflicts amplify losses.
Expected in operation
Process owners, measurement, monitoring and corrective action.
Operational review path
When to check
Process change or anomaly.
Typical owner
Business / risk control.
Possible evidence
Process map, control record, escalation.
Common gap
One person initiates and checks a critical step.
AT 4.3.3–4.3.4
Stress tests and models
Requirement
Review stress scenarios and models in proportion to the risks.
Why
Normal data may conceal extreme events and model weakness.
Expected in operation
Scenarios, assumptions, model controls and decisions.
Operational review path
When to check
Market shock or model change.
Typical owner
Risk control / model owner.
Possible evidence
Stress test, validation, minutes.
Common gap
An adverse scenario has no consequence.
AT 4.4
Special control functions
Requirement
Provide and involve risk control, compliance and internal audit as applicable.
Why
Independent functions identify and review weaknesses.
Expected in operation
Mandates, resources, reporting lines and remediation.
Operational review path
When to check
Organisational change or audit finding.
Typical owner
Management / control functions.
Possible evidence
Mandates, audit plan, reports.
Common gap
A named function lacks time or access.
AT 5–7
Rules, records and resources
Requirement
Keep policies current, document decisions and provide adequate staff and technology.
Why
Controls work only when people and systems can execute them.
Expected in operation
Versioned rules, training, records and capacity planning.
Operational review path
When to check
System change, staff turnover or control gap.
Typical owner
Business / HR / IT.
Possible evidence
Approvals, training and capacity records.
Common gap
The policy differs from actual operations.
AT 7.3
Business continuity
Requirement
Plan and test the recovery of critical processes.
Why
Outages must not interrupt material functions without control.
Expected in operation
Scenarios, owners, recovery plan and test evidence.
Operational review path
When to check
Provider outage or new critical dependency.
Typical owner
Continuity / business teams.
Possible evidence
Test report, actions, revised plan.
Common gap
A provider dependency is never exercised.
AT 8–9
Changes and outsourcing
Requirement
Assess new products, material changes and outsourcing before launch and during operation.
Why
New interfaces can create risks before teams recognise them.
Expected in operation
Approval, provider oversight, controls and exit planning.
Operational review path
When to check
Launch or critical provider change.
Typical owner
Product committee / outsourcing owner.
Possible evidence
Approval, contract, monitoring.
Common gap
A product launches before controls are ready.
BTO 1–3
Lending, trading and real estate
Requirement
Apply activity-specific process and segregation rules where these businesses are conducted.
Why
Different activities require different controls.
Expected in operation
Relevant approval, settlement and monitoring steps.
Operational review path
When to check
Beginning an in-scope activity.
Typical owner
Business / control team.
Possible evidence
Approval and control records.
Common gap
An irrelevant module is marked as implemented.
BTR 1–5
Risk types in operation
Requirement
Manage credit, market, liquidity, operational and relevant banking-book spread risks.
Why
The overall risk profile needs active management of its components.
Expected in operation
Indicators, limits, concentrations and actions by risk type.
Operational review path
When to check
Limit pressure or a new risk source.
Typical owner
Risk control / treasury / business.
Possible evidence
Risk report, limit review, action.
Common gap
Aggregate risk conceals an unmanaged exposure.
BT 2
Risk reporting
Requirement
Report risk information to management clearly and in time.
Why
Decisions depend on visible changes.
Expected in operation
Reports on material risks, limits, findings and actions.
Operational review path
When to check
Regular cycle or material deviation.
Typical owner
Risk control.
Possible evidence
Report, receipt, decision.
Common gap
Reports contain numbers without trends or escalation.
Investment firms · WpI MaRisk 09/2026 (WA)
13 high-level questions for preparation ahead of 1 January 2027. Separate from the bank framework.
AT 1–2.1
Effective date and firm class
Requirement
From 1 January 2027, assess scope for small and medium investment firms; large firms follow the KWG framework.
Why
The wrong regime creates gaps and misplaced obligations.
Expected in operation
Documented classification and implementation plan.
Operational review path
When to check
Change in WpIG size category.
Typical owner
Management / compliance.
Possible evidence
Classification, roadmap.
Common gap
Bank MaRisk and WpI MaRisk are mixed.
AT 2.2
Risks and materiality
Requirement
Inventory risks to clients, the market and the firm, as well as other and liquidity risks.
Why
Investment-service-specific exposures must be visible.
Expected in operation
Overall risk profile, concentrations and reasoned materiality.
Operational review path
When to check
New strategy, product or warning signal.
Typical owner
Risk management / management.
Possible evidence
Inventory, thresholds, decision.
Common gap
Client risk disappears from the corporate view.
AT 3
Management and oversight
Requirement
Take effective responsibility for organisation and risk management.
Why
Delegation does not remove steering and oversight duties.
Expected in operation
Reports, decisions, escalation and action follow-up.
Operational review path
When to check
Material finding or strategic decision.
Typical owner
Management / supervisory body.
Possible evidence
Minutes and action log.
Common gap
A critical finding has no decision owner.
AT 4.1
Risk capacity and capital planning
Requirement
Assess appropriate risk capacity and capital planning for the firm size.
Why
Risks and business plans need adequate financial resources.
Expected in operation
Capital assumptions, forecasts and options for action.
Operational review path
When to check
Growth, loss or new capital requirement.
Typical owner
Finance / risk management.
Possible evidence
Plan, assumptions, decisions.
Common gap
Capital planning ignores changed volumes.
AT 4.2
Strategies
Requirement
Connect business and risk strategies.
Why
A new service changes exposures and resource needs.
Expected in operation
Approved strategy with reviewable risk objectives.
Operational review path
When to check
New channel or product.
Typical owner
Management.
Possible evidence
Strategy, limits, review.
Common gap
Growth targets conflict with risk budget.
AT 4.3
Controls and risk processes
Requirement
Design organisation, risk identification, control and proportionate stress testing.
Why
Errors in digital journeys can scale quickly.
Expected in operation
Owners, controls, scenarios and fixes in live workflows.
Operational review path
When to check
System change or repeated exception.
Typical owner
Operations / risk management.
Possible evidence
Tests, control records, stress test.
Common gap
Automated flows are never tested for failure.
AT 4.4
Control functions
Requirement
Establish risk management, compliance and internal audit to the applicable extent.
Why
Controls must challenge decisions and follow up issues.
Expected in operation
Clear mandates, resources and reports to management.
Operational review path
When to check
Structural change or finding.
Typical owner
Management / control functions.
Possible evidence
Mandates, reports, actions.
Common gap
A role exists on paper but cannot act.
AT 5–7
Policies and readiness
Requirement
Maintain proportionate policies, records, staff, technology and continuity arrangements.
Why
Processes must survive staff and system disruption.
Expected in operation
Current instructions, capacity and tested recovery.
Operational review path
When to check
New provider or staffing shortage.
Typical owner
Operations / IT / management.
Possible evidence
Versions, training, recovery test.
Common gap
A single person has no deputy.
AT 8
Product and process change
Requirement
Assess new products and material changes before launch for risks and control readiness.
Why
A launch may create client, market or firm risks.
Expected in operation
Approval with risk assessment, owners and tested implementation.
Operational review path
When to check
Derivatives service, copy trading or new channel.
Typical owner
Product committee / business / controls.
Possible evidence
Approval, test, follow-up.
Common gap
Distribution starts before controls are tested.
AT 9
Outsourcing
Requirement
Select, contract and monitor outsourced activities based on risk.
Why
An external provider does not replace firm accountability.
Expected in operation
Register, diligence, oversight, escalation and exit.
Operational review path
When to check
Cloud or onboarding provider change.
Typical owner
Outsourcing owner / management.
Possible evidence
Contract, service report, exit plan.
Common gap
A critical provider is reviewed only at signing.
BTH; BTV
Trading and tied agents
Requirement
Address specific trading and tied-agent requirements when applicable.
Why
These service chains need clear segregation and monitoring.
Expected in operation
Trading controls, interfaces and agent oversight.
Operational review path
When to check
Trading launch or new tied agent.
Typical owner
Trading / agent oversight.
Possible evidence
Control records and contracts.
Common gap
Agent activity never appears in risk reports.
BTR 1–4
Clients, market, firm and liquidity
Requirement
Manage client, market, firm and liquidity risks and disorderly wind-down.
Why
Harm extends beyond the balance sheet to clients and market integrity.
Expected in operation
Indicators, scenarios and actions for each relevant risk.
Operational review path
When to check
Client loss, market disruption or liquidity stress.
Typical owner
Risk management / finance.
Possible evidence
Inventory, limits, contingency action.
Common gap
Client harm is treated only as a complaint.
BT 2
Risk reporting
Requirement
Report material risks clearly and promptly.
Why
Management needs information to respond.
Expected in operation
Targeted reports with escalation and decisions.
Operational review path
When to check
Regular cycle or material breach.
Typical owner
Risk management.
Possible evidence
Report, minutes, action.
Common gap
Anomalies surface after quarter end.
Review status:
When is implementation demonstrable?
Who decides, checks and escalates?
Which process actually runs when the risk changes?
Where are versions, tests, reports and remediation recorded?
Sources and limits
Sources: BaFin Circular 06/2026 (BA), 30 June 2026, and Circular 09/2026 (WA), 24 August 2026. This is a selective high-level translation into operational review questions. It is not a complete obligations register. Confirm the rules applicable to your firm and subsequent changes.
Considering a local office, a branch or a standalone authorisation in Germany? The appropriate route depends on your home jurisdiction, activities and operating model. 3RMCN combines experience from complex supervisory projects with product, technology and delivery expertise: from entry strategy and key interfaces through to operational readiness.
Experience in the context of CySEC (Cyprus), MFSA (Malta), FCA (United Kingdom), the European ESMA framework and MAS (Singapore). ESMA is not a national licensing authority.
For incorporation in offshore jurisdictions, relevant specialists from the network can be involved. Jurisdiction, activities and regulatory obligations need to be considered for each project.