erlaubnisantrag.comRegulatory Pathfinder
DEEN
REGULATORY TOOLS / MARISK

MaRisk: from risk framework to daily operation

Choose the regulatory path for your firm. Each question connects the requirement, its purpose and the operational evidence; expand it for triggers, owners and common gaps.

Two frameworks, two review paths

These review paths are editorial implementation examples, not an individual supervisory finding. The statuses are local to this browser view and are not saved.

Bank MaRisk · 06/2026 (BA)

14 high-level questions for the applicable framework, including risk inventory, capacity, controls, continuity and reporting.

AT 2.1

Scope

Requirement

Determine the firm type, activities and applicable MaRisk modules.

Why

Only applicable obligations can be implemented effectively.

Expected in operation

Reasoned applicability matrix, reviewed when the model changes.

Operational review path
When to check
New licence, activity or structure.
Typical owner
Management / compliance.
Possible evidence
Approved obligations map.
Common gap
An exemption is copied without reasons.
AT 2.2

Risk inventory and concentrations

Requirement

Identify material risks across the firm; consider concentrations and ICT and ESG risk drivers.

Why

Unknown or aggregated risks cannot be controlled.

Expected in operation

Overall risk profile with materiality decisions and actions.

Operational review path
When to check
New product, market or external shock.
Typical owner
Risk control / management.
Possible evidence
Inventory, method, approval.
Common gap
Risks are viewed only by department.
AT 3

Management and oversight

Requirement

Management retains overall responsibility; the supervisory body fulfils its oversight role.

Why

Risk control needs decisions and effective challenge.

Expected in operation

Regular reporting, decisions and tracked findings.

Operational review path
When to check
Strategy change or material risk finding.
Typical owner
Management / supervisory body.
Possible evidence
Minutes, action log.
Common gap
Reports receive no follow-up decision.
AT 4.1

Risk-bearing capacity

Requirement

Align risk-bearing capacity with the overall risk profile and available capital.

Why

Material risks must remain supportable.

Expected in operation

Defined perspectives, limits, recurring calculation and escalation.

Operational review path
When to check
Capital change, loss or limit breach.
Typical owner
Risk control / finance.
Possible evidence
Calculation, limit report, action.
Common gap
A breach appears only in the annual report.
AT 4.2

Business and risk strategy

Requirement

Define, align and review strategies and translate them into steering.

Why

Growth and risk appetite must remain consistent.

Expected in operation

Approved goals, limits and documented review.

Operational review path
When to check
New business line or risk profile change.
Typical owner
Management.
Possible evidence
Strategy, minutes, limits.
Common gap
Expansion exceeds approved risk appetite.
AT 4.3.1–4.3.2

Organisation and controls

Requirement

Design responsibilities, separation of duties and risk control processes.

Why

Uncontrolled decisions and hidden conflicts amplify losses.

Expected in operation

Process owners, measurement, monitoring and corrective action.

Operational review path
When to check
Process change or anomaly.
Typical owner
Business / risk control.
Possible evidence
Process map, control record, escalation.
Common gap
One person initiates and checks a critical step.
AT 4.3.3–4.3.4

Stress tests and models

Requirement

Review stress scenarios and models in proportion to the risks.

Why

Normal data may conceal extreme events and model weakness.

Expected in operation

Scenarios, assumptions, model controls and decisions.

Operational review path
When to check
Market shock or model change.
Typical owner
Risk control / model owner.
Possible evidence
Stress test, validation, minutes.
Common gap
An adverse scenario has no consequence.
AT 4.4

Special control functions

Requirement

Provide and involve risk control, compliance and internal audit as applicable.

Why

Independent functions identify and review weaknesses.

Expected in operation

Mandates, resources, reporting lines and remediation.

Operational review path
When to check
Organisational change or audit finding.
Typical owner
Management / control functions.
Possible evidence
Mandates, audit plan, reports.
Common gap
A named function lacks time or access.
AT 5–7

Rules, records and resources

Requirement

Keep policies current, document decisions and provide adequate staff and technology.

Why

Controls work only when people and systems can execute them.

Expected in operation

Versioned rules, training, records and capacity planning.

Operational review path
When to check
System change, staff turnover or control gap.
Typical owner
Business / HR / IT.
Possible evidence
Approvals, training and capacity records.
Common gap
The policy differs from actual operations.
AT 7.3

Business continuity

Requirement

Plan and test the recovery of critical processes.

Why

Outages must not interrupt material functions without control.

Expected in operation

Scenarios, owners, recovery plan and test evidence.

Operational review path
When to check
Provider outage or new critical dependency.
Typical owner
Continuity / business teams.
Possible evidence
Test report, actions, revised plan.
Common gap
A provider dependency is never exercised.
AT 8–9

Changes and outsourcing

Requirement

Assess new products, material changes and outsourcing before launch and during operation.

Why

New interfaces can create risks before teams recognise them.

Expected in operation

Approval, provider oversight, controls and exit planning.

Operational review path
When to check
Launch or critical provider change.
Typical owner
Product committee / outsourcing owner.
Possible evidence
Approval, contract, monitoring.
Common gap
A product launches before controls are ready.
BTO 1–3

Lending, trading and real estate

Requirement

Apply activity-specific process and segregation rules where these businesses are conducted.

Why

Different activities require different controls.

Expected in operation

Relevant approval, settlement and monitoring steps.

Operational review path
When to check
Beginning an in-scope activity.
Typical owner
Business / control team.
Possible evidence
Approval and control records.
Common gap
An irrelevant module is marked as implemented.
BTR 1–5

Risk types in operation

Requirement

Manage credit, market, liquidity, operational and relevant banking-book spread risks.

Why

The overall risk profile needs active management of its components.

Expected in operation

Indicators, limits, concentrations and actions by risk type.

Operational review path
When to check
Limit pressure or a new risk source.
Typical owner
Risk control / treasury / business.
Possible evidence
Risk report, limit review, action.
Common gap
Aggregate risk conceals an unmanaged exposure.
BT 2

Risk reporting

Requirement

Report risk information to management clearly and in time.

Why

Decisions depend on visible changes.

Expected in operation

Reports on material risks, limits, findings and actions.

Operational review path
When to check
Regular cycle or material deviation.
Typical owner
Risk control.
Possible evidence
Report, receipt, decision.
Common gap
Reports contain numbers without trends or escalation.

Investment firms · WpI MaRisk 09/2026 (WA)

13 high-level questions for preparation ahead of 1 January 2027. Separate from the bank framework.

AT 1–2.1

Effective date and firm class

Requirement

From 1 January 2027, assess scope for small and medium investment firms; large firms follow the KWG framework.

Why

The wrong regime creates gaps and misplaced obligations.

Expected in operation

Documented classification and implementation plan.

Operational review path
When to check
Change in WpIG size category.
Typical owner
Management / compliance.
Possible evidence
Classification, roadmap.
Common gap
Bank MaRisk and WpI MaRisk are mixed.
AT 2.2

Risks and materiality

Requirement

Inventory risks to clients, the market and the firm, as well as other and liquidity risks.

Why

Investment-service-specific exposures must be visible.

Expected in operation

Overall risk profile, concentrations and reasoned materiality.

Operational review path
When to check
New strategy, product or warning signal.
Typical owner
Risk management / management.
Possible evidence
Inventory, thresholds, decision.
Common gap
Client risk disappears from the corporate view.
AT 3

Management and oversight

Requirement

Take effective responsibility for organisation and risk management.

Why

Delegation does not remove steering and oversight duties.

Expected in operation

Reports, decisions, escalation and action follow-up.

Operational review path
When to check
Material finding or strategic decision.
Typical owner
Management / supervisory body.
Possible evidence
Minutes and action log.
Common gap
A critical finding has no decision owner.
AT 4.1

Risk capacity and capital planning

Requirement

Assess appropriate risk capacity and capital planning for the firm size.

Why

Risks and business plans need adequate financial resources.

Expected in operation

Capital assumptions, forecasts and options for action.

Operational review path
When to check
Growth, loss or new capital requirement.
Typical owner
Finance / risk management.
Possible evidence
Plan, assumptions, decisions.
Common gap
Capital planning ignores changed volumes.
AT 4.2

Strategies

Requirement

Connect business and risk strategies.

Why

A new service changes exposures and resource needs.

Expected in operation

Approved strategy with reviewable risk objectives.

Operational review path
When to check
New channel or product.
Typical owner
Management.
Possible evidence
Strategy, limits, review.
Common gap
Growth targets conflict with risk budget.
AT 4.3

Controls and risk processes

Requirement

Design organisation, risk identification, control and proportionate stress testing.

Why

Errors in digital journeys can scale quickly.

Expected in operation

Owners, controls, scenarios and fixes in live workflows.

Operational review path
When to check
System change or repeated exception.
Typical owner
Operations / risk management.
Possible evidence
Tests, control records, stress test.
Common gap
Automated flows are never tested for failure.
AT 4.4

Control functions

Requirement

Establish risk management, compliance and internal audit to the applicable extent.

Why

Controls must challenge decisions and follow up issues.

Expected in operation

Clear mandates, resources and reports to management.

Operational review path
When to check
Structural change or finding.
Typical owner
Management / control functions.
Possible evidence
Mandates, reports, actions.
Common gap
A role exists on paper but cannot act.
AT 5–7

Policies and readiness

Requirement

Maintain proportionate policies, records, staff, technology and continuity arrangements.

Why

Processes must survive staff and system disruption.

Expected in operation

Current instructions, capacity and tested recovery.

Operational review path
When to check
New provider or staffing shortage.
Typical owner
Operations / IT / management.
Possible evidence
Versions, training, recovery test.
Common gap
A single person has no deputy.
AT 8

Product and process change

Requirement

Assess new products and material changes before launch for risks and control readiness.

Why

A launch may create client, market or firm risks.

Expected in operation

Approval with risk assessment, owners and tested implementation.

Operational review path
When to check
Derivatives service, copy trading or new channel.
Typical owner
Product committee / business / controls.
Possible evidence
Approval, test, follow-up.
Common gap
Distribution starts before controls are tested.
AT 9

Outsourcing

Requirement

Select, contract and monitor outsourced activities based on risk.

Why

An external provider does not replace firm accountability.

Expected in operation

Register, diligence, oversight, escalation and exit.

Operational review path
When to check
Cloud or onboarding provider change.
Typical owner
Outsourcing owner / management.
Possible evidence
Contract, service report, exit plan.
Common gap
A critical provider is reviewed only at signing.
BTH; BTV

Trading and tied agents

Requirement

Address specific trading and tied-agent requirements when applicable.

Why

These service chains need clear segregation and monitoring.

Expected in operation

Trading controls, interfaces and agent oversight.

Operational review path
When to check
Trading launch or new tied agent.
Typical owner
Trading / agent oversight.
Possible evidence
Control records and contracts.
Common gap
Agent activity never appears in risk reports.
BTR 1–4

Clients, market, firm and liquidity

Requirement

Manage client, market, firm and liquidity risks and disorderly wind-down.

Why

Harm extends beyond the balance sheet to clients and market integrity.

Expected in operation

Indicators, scenarios and actions for each relevant risk.

Operational review path
When to check
Client loss, market disruption or liquidity stress.
Typical owner
Risk management / finance.
Possible evidence
Inventory, limits, contingency action.
Common gap
Client harm is treated only as a complaint.
BT 2

Risk reporting

Requirement

Report material risks clearly and promptly.

Why

Management needs information to respond.

Expected in operation

Targeted reports with escalation and decisions.

Operational review path
When to check
Regular cycle or material breach.
Typical owner
Risk management.
Possible evidence
Report, minutes, action.
Common gap
Anomalies surface after quarter end.

Review status:

When is implementation demonstrable?

Sources and limits

Sources: BaFin Circular 06/2026 (BA), 30 June 2026, and Circular 09/2026 (WA), 24 August 2026. This is a selective high-level translation into operational review questions. It is not a complete obligations register. Confirm the rules applicable to your firm and subsequent changes.

Bank MaRisk · original PDF ↗ · WpI MaRisk · original PDF ↗

← Back to GRC

Did you know?

From the Pathfinder

Business concept

How an app can become an activity that requires permission.

Explore topic →

Have you explored?

Across our tools & projects

Fit & Proper · skills matrix

Prepare management profiles and collective suitability reviews.

Explore tool or project →

International market entry / Germany

Is Germany your next market?

Considering a local office, a branch or a standalone authorisation in Germany? The appropriate route depends on your home jurisdiction, activities and operating model. 3RMCN combines experience from complex supervisory projects with product, technology and delivery expertise: from entry strategy and key interfaces through to operational readiness.

Discuss your plans ↗

Supervisory perspectives

Familiar with several regimes

Experience in the context of CySEC (Cyprus), MFSA (Malta), FCA (United Kingdom), the European ESMA framework and MAS (Singapore). ESMA is not a national licensing authority.

International structuring

Incorporating offshore?

For incorporation in offshore jurisdictions, relevant specialists from the network can be involved. Jurisdiction, activities and regulatory obligations need to be considered for each project.