On June 30, 2026, BaFin published the final version of the 9th amendment to the Minimum Requirements for Risk Management (MaRisk). Anyone familiar with previous amendments reflexively expects more regulatory requirements, more granular detail, more paperwork, and more documentation obligations. But this time everything is different. The 9th amendment marks a genuine paradigm shift - away from rigid detailed regulation, toward a principles-based, proportional approach. This was already confirmed by Nikolas Speer, Executive Director of BaFin Banking Supervision, back in April 2026. Institutions gain more latitude in terms of interpretation. In return, they take on greater responsibility for properly justifying that latitude.
This becomes visible in two central building blocks, which must be considered together in their interaction: the new size classes and the expanded opening clauses.
1. New Size Classes
The proportionality principle of MaRisk already existed before, but without clear criteria for who could benefit from it and to what extent. The 9th amendment creates transparency here for the first time:
- Very small institutions (balance sheet total ≤ €1 billion): access to all opening clauses.
- Small, non-complex institutions (SNCI per Art. 4(1) No. 145 CRR, balance sheet total ≤ €5 billion): broad access to relief provisions.
- Remaining less significant institutions (LSIs): general proportionality and opening clauses, but without the SNCI-specific relief provision.
An estimated three-quarters of German creditinstitutions fall into the SNCI category. This means the amendment is primarilya relief for mid-sized institutions, not for large banks - which will in futureno longer fall within the scope of MaRisk.
2. AT 9 and DORA
The second innovation concerns third-party riskmanagement and the restriction of scope itself. With the introduction of the 9th MaRisk amendment, the regulator draws a clear dividing line in AT 9 for the first time between outsourcing management under MaRisk and ICT third-party riskmanagement under DORA. Externally sourced ICT services within the meaning of Art. 3 No. 21 DORA - which, since the introduction of the DORA framework, have been documented, monitored, and governed pursuant to Arts. 28–30 DORA - will infuture no longer fall within the scope of MaRisk.
Anyone assuming this means a lowering of the requirements standard is mistaken.
This is merely a regime demarcation. Inpractice, this means that governance of ICT services occurs exclusively under DORA, while AT 9 now applies only to non-ICT-related service sourcing.
This is underscored and clarified by the deletion of the previous list regarding other outsourced services (Other Third-Party Procurement) and the previous provisions on standalone software procurement.
In practice, this regime demarcation results in a classification obligation for outsourced services: institutions must decideand document, for each individual service relationship as part of a serviceclassification, whether it is governed under MaRisk AT 9 or under DORA. The resulting documentation, assessment, and notification obligations derive from that preceding decision.
3. TPRM Between MaRisk, DORA, and the Consultation Draft of the New EBA Guidelines
In parallel with the publication of the 9th MaRisk amendment, the EBA guideline on managing third-party risk is in its consultation phase. This means a revision of the previous 2019 outsourcing guidelines is imminent. Anyone reading the consultation draft quickly discoversthat the scope is intended to be expanded from the classic outsourcing scenarioto cover all third-party arrangements.
This, however, raises new questions for discussion, since the 9th MaRisk amendment does not (yet) follow this change. Article 9 [AT 9] of MaRisk provides for the DORA demarcation but does not adopt the proposal to expand scope to all third-party arrangements.
As a result, the European level is one step ahead of the national level. For institutions that build their governance andservice management exclusively based on MaRisk, this means additional work inthe not-too-distant future. They will need to revise their governance and service management and reassess relevant matters once the final EBA version is published.

