From target process to a prioritised gap list.
Reference process (target state)
The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.
Map your current state
Map your existing processes module by module against the reference — system of record, owner, last review.
See the gaps
Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.
Evidence, not opinion
The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.
13 modules, each control covered exactly once.
The reference process groups all 31 MaRisk & BAIT controls into 13 modules — from board responsibility to the quarterly overall risk report.
Overall responsibility, org guidelines & documentation
All board members own the proper business organisation; written organisational guidelines and comprehensible, retained documentation.
Risk-bearing capacity (ICAAP) & capital planning
Material risks continuously covered by risk coverage potential — normative and economic perspective incl. ESG — plus multi-year capital planning.
Strategies & adaptation processes (NPP)
Consistent business and risk strategy incl. ESG, the new-product process and impact analysis before material changes or mergers.
Internal control system: structure & risk processes
Segregation of incompatible duties up to board level and processes to identify, assess, treat, monitor and communicate all material risks.
Stress testing, risk data & models
Regular stress tests incl. ESG scenarios, BCBS-239-type risk data aggregation and validated models.
Control functions: risk control, compliance, audit
Independent risk control function, MaRisk compliance function with annual report, and risk-oriented internal audit.
Resources: staff, IT & business continuity (BAIT sunset)
Adequate staffing, IT per established standards and a contingency concept — with the BAIT transition path for non-DORA institutions until 31 Dec 2026.
Outsourcing
Risk analysis before every material outsourcing, contractual audit/termination rights, central outsourcing management with register and exit strategies.
Credit business
Front/back-office separation with two votes, intensified handling, problem-loan workout and timely risk provisioning.
Trading & real-estate business
Trading segregation with market-conformity checks and home-office rules, plus processes and independent valuation for own real estate.
Counterparty & market price risk (IRRBB/CSRBB)
Limit systems and concentration monitoring plus IRRBB steering and CSRBB assessment per the 8th amendment.
Liquidity & operational risk
Solvency at all times with stress scenarios and a contingency funding plan, plus annual OpRisk assessment and loss-event analysis.
Risk reporting
Comprehensible, timely risk reports with forward-looking elements and the at-least-quarterly overall risk report to the board.
Module-level references, honestly labelled.
Controls reference the verified AT/BTO/BTR/BT modules of RS 06/2024 — not individual Textziffern, which would require line-exact verification. The 9th amendment is only a consultation draft (02/2026) and changes nothing here yet. BAIT applies solely to non-DORA institutions until 31 Dec 2026, and every ICT control affected by the DORA overlap is flagged instead of double-counted. The circular text is never conflated with our process opinion.
Set up your MaRisk blueprint together.
30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.