Skip to main content

MaRisk, as a reference process you can map against.

BaFin circular 06/2024 (8th MaRisk amendment) turned into a documented target process across 13 modules and 31 grounded controls — from ICAAP and outsourcing to IRRBB. With the BAIT sunset and the DORA overlap flagged instead of glossed over.

31
grounded controls
13
process modules
2026
BAIT repeal · 31 Dec
MaRisk (RS 06/2024) & BAIT
Legal basis
RS 06/2024 (BA) · 29 May 2024
BAIT status
Non-DORA institutions only · repealed 31 Dec 2026
9th amendment
In consultation (02/2026) — not in force
Controls
31 (module-level references)
Grounding
AT/BTO/BTR/BT module + source on every step
Map & Gap

From target process to a prioritised gap list.

01

Reference process (target state)

The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.

02

Map your current state

Map your existing processes module by module against the reference — system of record, owner, last review.

03

See the gaps

Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.

04

Evidence, not opinion

The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.

Target process

13 modules, each control covered exactly once.

The reference process groups all 31 MaRisk & BAIT controls into 13 modules — from board responsibility to the quarterly overall risk report.

AT 3 / AT 5 / AT 6

Overall responsibility, org guidelines & documentation

All board members own the proper business organisation; written organisational guidelines and comprehensible, retained documentation.

AT 4.1

Risk-bearing capacity (ICAAP) & capital planning

Material risks continuously covered by risk coverage potential — normative and economic perspective incl. ESG — plus multi-year capital planning.

AT 4.2 / AT 8

Strategies & adaptation processes (NPP)

Consistent business and risk strategy incl. ESG, the new-product process and impact analysis before material changes or mergers.

AT 4.3.1 / 4.3.2

Internal control system: structure & risk processes

Segregation of incompatible duties up to board level and processes to identify, assess, treat, monitor and communicate all material risks.

AT 4.3.3 - 4.3.5

Stress testing, risk data & models

Regular stress tests incl. ESG scenarios, BCBS-239-type risk data aggregation and validated models.

AT 4.4 / BT 2

Control functions: risk control, compliance, audit

Independent risk control function, MaRisk compliance function with annual report, and risk-oriented internal audit.

AT 7 / BAIT

Resources: staff, IT & business continuity (BAIT sunset)

Adequate staffing, IT per established standards and a contingency concept — with the BAIT transition path for non-DORA institutions until 31 Dec 2026.

AT 9

Outsourcing

Risk analysis before every material outsourcing, contractual audit/termination rights, central outsourcing management with register and exit strategies.

BTO 1

Credit business

Front/back-office separation with two votes, intensified handling, problem-loan workout and timely risk provisioning.

BTO 2 / BTO 3

Trading & real-estate business

Trading segregation with market-conformity checks and home-office rules, plus processes and independent valuation for own real estate.

BTR 1 / BTR 2

Counterparty & market price risk (IRRBB/CSRBB)

Limit systems and concentration monitoring plus IRRBB steering and CSRBB assessment per the 8th amendment.

BTR 3 / BTR 4

Liquidity & operational risk

Solvency at all times with stress scenarios and a contingency funding plan, plus annual OpRisk assessment and loss-event analysis.

BT 3

Risk reporting

Comprehensible, timely risk reports with forward-looking elements and the at-least-quarterly overall risk report to the board.

Accuracy first

Module-level references, honestly labelled.

Controls reference the verified AT/BTO/BTR/BT modules of RS 06/2024 — not individual Textziffern, which would require line-exact verification. The 9th amendment is only a consultation draft (02/2026) and changes nothing here yet. BAIT applies solely to non-DORA institutions until 31 Dec 2026, and every ICT control affected by the DORA overlap is flagged instead of double-counted. The circular text is never conflated with our process opinion.

Book a demo

Set up your MaRisk blueprint together.

30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.