Cybersecurity Glossary

What are MaRisk?

MaRisk stands for Mindestanforderungen an das Risikomanagement. The BaFin circular describes principles-based requirements for governance, internal controls and risk management at German institutions within its scope. It addresses responsibilities, risk-bearing capacity, control processes, outsourcing and internal audit.

Technology and information risk is part of this overall management responsibility. The exact interaction with current European rules, including DORA, depends on the institution and current supervisory publications and should be assessed with qualified regulatory expertise.

What is important for implementation?

Institutions translate general requirements into proportionate controls, document decisions and demonstrate effectiveness. A policy collection without functioning ownership, monitoring and escalation does not meet the objective of effective risk management.

How are MaRisk structured?

AreaContent
General section (AT)Management responsibility, strategies, risk-bearing capacity, controls, organization, resources, change processes and outsourcing.
Special section (BT)Requirements for selected business and risk types, control functions and internal audit.
ProportionalityAllows implementation to reflect an institution's size, complexity and risk profile.
AssuranceDocumentation alone is insufficient; processes and controls must be appropriate, implemented and effective.

MaRisk, DORA and ICT risk

DORA has applied since 17 January 2025 as the specific European framework for digital operational resilience of covered financial entities. It addresses ICT risk management, incident reporting, resilience testing and third-party risk in detail. MaRisk remain the broader principles-based framework for an institution's overall risk management. Applicability and overlap need review against current BaFin versions, transition arrangements and the type of institution.

What should implementation evidence show?

Reliable evidence connects risk, decision, control, owner and effectiveness test. Examples include approved risk limits, traceable escalation, outsourcing registers, control tests and closed audit findings. Technical assessments such as vulnerability scans or penetration tests provide individual evidence but do not replace risk inventory, governance and continuous oversight.

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on MaRisk? Tell us!