9. MaRisk amendment
The 9th amendment to the MaRisk (Minimum Requirements for Risk Management) sets the standard for proper business organization and risk management — and thereby directly determines the personal liability risk of management, compliance officers, and money laundering officers. Ignoring MaRisk 2026 exposes institutions to organizational negligence and heightened civil, regulatory, and criminal liability.
II. Deadlines, timeframes and cycles
Supervisory timeframe: The consultation ran until 8 May 2026; the final version has been available since 30 June 2026 and is immediately applicable. Supervisory authorities usually distinguish "clarifying" provisions (immediately effective) from new requirements with transitional periods; for earlier amendments these extended in some cases to 31 December of the following year (e.g. NPL rules, outsourcing contracts), and similar transitions are expected in 2026.
Strategic and technical timelines: ESG and environmental risks must be assessed short-, medium- and long-term using scenarios spanning at least ten years (resilience analyses). Capital planning must be reviewed annually with a multi-year horizon and key assumptions updated as needed. NPE strategies require short-, medium- and long-term reduction targets plus quarterly KPI reviews. Emergency management and significant outsourcing require at least annual reviews, with quarterly reporting to management.
Operational audit and reporting cycles: Risk inventory, risk classification and credit rating must be conducted at least annually, including a review of materiality and ESG impacts. Internal Audit follows a risk-oriented plan on a 3-year cycle for all activities and a 5-year cycle for non-material areas; material deficiencies must be addressed no later than the next quarterly report. Risk reports go to senior management at least quarterly for all material risk types, with far more frequent reporting during periods of stress.
III. Duties for C-level executives and compliance
MaRisk 2026 specifies key organizational, risk and outsourcing obligations affecting management, supervisory bodies and control functions.
1. Management and supervisory body: Management must ensure proper business organization and effective risk management, and must define and regularly review business, risk, ICT and — where applicable — DOR strategies, including risk appetite, capital planning and, for high NPL portfolios, an NPE strategy. The supervisory body must be informed at least quarterly about business situation, risk profile and specific risks.
2. Risk management and internal control systems: Institutions must establish a risk-bearing capacity concept with an ICAAP process, run regular stress and resilience analyses, and identify, assess, manage and monitor all material risks, including ESG and ICT risks. The structure must reflect a clear separation of functions (market, back office, trading, risk control, compliance, audit), underpinned by binding organizational guidelines.
3. Special functions, resources and documentation: Risk control, compliance and internal audit are mandatory, organizationally independent and adequately resourced. Internal audit works risk-based on a 3- to 5-year cycle, monitors remediation and reports at least quarterly. Institutions must ensure sufficient staffing, suitable technical infrastructure and an emergency management system with an annually reviewed emergency plan and quarterly reporting to senior management. Records must be kept systematically and transparently and retained for several years.
4. Adaptation processes, outsourcing and reporting: New products, new markets and significant organizational or ICT changes trigger a structured new-product/adaptation process involving risk controlling, compliance and audit. Significant outsourcing requires a risk analysis, clearly defined agreements, centralized outsourcing management, contingency and exit planning, and ongoing monitoring — with senior management’s responsibility remaining non-transferable. Risk controlling must prepare comprehensive risk reports and specific reports on credit, market-price, liquidity and operational risks at least quarterly.
IV. Liability risks and critical areas
MaRisk 2026 is not itself a liability provision but a more specific standard for judging whether corporate bodies and their functions have properly fulfilled their duties. The core risks:
1. Management (Board / Executive): Breaches of duty in business organization, risk management, outsourcing, ESG and IT can constitute a breach of the duty of care (internal liability under § 43 GmbHG, § 93 AktG). Violations of Section 25a KWG (organization, risk management), Section 25b KWG (outsourcing), Sections 25c and 25d KWG (requirements for managers and supervisory bodies) and Section 26c KWG (ESG risks) form the basis for supervisory measures, fines and withdrawal of "fit and proper" suitability. Organizational omissions can trigger criminal liability for omission under Section 13 StGB together with relevant offenses, plus breach of supervisory duties under Section 130 OWiG.
2. Supervisory body: Insufficient oversight of management and risk management — particularly with obvious MaRisk deficiencies (missing segregation of functions, inadequate outsourcing control, ignored ESG risks) — can lead to liability under Sections 116 and 93 AktG. Breaches also affect personal reliability and professional suitability, indirectly via Section 25d KWG.
3. Compliance function: Compliance must systematically identify essential legal requirements and ensure their monitoring; system failures or "blind spots" count as organizational deficiencies, with consequences for management and, in serious cases, for the responsible compliance officers. Relevant provisions: Section 25a KWG, Section 80 WpHG in conjunction with Article 16 of MiFID II. In extreme cases, employment-law and criminal liability may arise if serious violations are deliberately tolerated or concealed (Section 13 StGB, Section 130 OWiG).
4. Money Laundering Officer: Failure to report suspected cases or to implement appropriate AML processes can trigger personal liability under Sections 43 et seq. GwG, supplemented by the AML Regulation (EU) 2024/1624. Missing, late or inadequate controls can lead to personal criminal or administrative liability under Section 130 OWiG and Section 13 StGB (guarantor status from legally transferred duty).
5. Outsourcing, ESG and IT/DORA: "Empty shell" structures, missing risk analysis, insufficient controllability or absent contingency/exit planning for significant outsourcing violate Section 25b KWG and corresponding WpIG provisions (e.g. Sections 4 and 82 WpIG). Insufficient integration of ESG risks can breach Section 26c KWG and the MaRisk-derived obligations. Missing or inadequate ICT risk and emergency management sits in the tension between Section 25a KWG and the DORA Regulation (EU) 2022/2554, raising both corporate and criminal/administrative risk after security incidents.
V. Recommendations for action
The aim is twofold: meet supervisory expectations while refuting typical liability claims.
1. Governance and clarity of accountability: Update and formally adopt a governance map (management, supervisory body, special functions, outsourcing management) with clear responsibility and reporting lines, anchored in organizational guidelines and individual declarations of responsibility; document an annual review of responsibilities, resources and reporting cycles. This counters the charge of improper business organization (§ 25a KWG, § 43 GmbHG, § 93 AktG) and the "empty shell" allegation.
2. Structured implementation and a "chain of justification": Develop an institution-wide MaRisk implementation concept with gap analysis, priorities, timelines and owners (risk management, ESG, ICT/DORA, outsourcing, reporting). For every essential principle (proportionality, simplifications, model use, stress tests), record a written "why so?" rationale and decide it at management (and, where relevant, supervisory-body) level. This reduces exposure to the charge of only formal — not effective — implementation of Sections 25a, 25b and 26c KWG, to supervisory-audit findings of no comprehensible decision basis, and to negligence charges under § 13 StGB for "looking the other way".
3. Strengthen ESG, ICT and model governance: Integrate ESG as an explicit risk driver into inventory, strategy and stress tests with documented methodology; adopt an ICT/DORA strategy with clear objectives, risk appetite and emergency/outsourcing frameworks; document the model register, validation plan, data-quality processes and override policy. This defuses allegations of inadequate consideration of ESG risks (§ 26c KWG), of insufficient IT organization or digital resilience (Section 25a KWG and DORA), and of model liability.
4. Make outsourcing management "liability-proof": Run a central risk analysis for all outsourcing (including onward outsourcing) with materiality classification and scenario analysis; maintain a complete outsourcing register, standardized contract clauses (information, audit, instruction, termination, exit) and coordinated emergency/exit strategies; report at least annually to the board with a per-provider traffic-light rating. This addresses the "empty shell" charge under § 25a, § 25b KWG, controllability-related liability (fines, Section 82 WpIG for securities institutions), and breach of guarantor/supervisory duties on outsourcing failure.
5. Sharpen the reporting and escalation chain: Produce quarterly comprehensive risk reports focused on risk appetite, limit breaches, stress-test results, ESG and ICT risks and key outsourcing/emergency issues; set binding escalation rules; verifiably track all significant audit and compliance findings (action plan, deadlines, status). This reduces liability from missing or delayed information of the supervisory body (breach of Section 25a KWG) and the "known defects not rectified" starting point for Section 13 StGB and Section 130 OWiG.
6. Specifically for compliance and money laundering officers: Maintain a risk-based compliance risk atlas classifying key norms (AML, AMLR, sanctions, ESG, IT and data-protection law) with regular updates; keep a clear separation of roles (compliance, MLRO, data protection) with written reporting lines; for AML, establish clear suspicious-case reporting, training, random checks and a documented no-tolerance policy. This avoids the charge of structural omission in compliance/AML systems (§ 25a KWG, § 80 WpHG, GwG) and personal allegations against MLROs and compliance officers (§ 43 GwG, § 13 StGB, § 130 OWiG).
VI. Conclusion
MaRisk 2026 is not merely a supervisory document but a liability-critical organizational benchmark for management, supervisory bodies, compliance officers and money laundering officers. Institutions that visibly align and justify their governance, risk management, ESG and ICT structures, outsourcing and reporting with these principles materially reduce their exposure. The decisive factor is documented, risk-based implementation — not a merely formal adaptation of guidelines.
VII. List of Sources
BaFin, Circular 06/2026 (BA) – Minimum Requirements for Risk Management – MaRisk: https://www.bafin.de/… , accessed on 02.07.2026
Deutsche Bundesbank, Circular 06/2026 (BA): Minimum requirements for risk management – MaRisk (PDF): https://www.bundesbank.de/… , accessed on 02.07.2026
BaFin, press release “BaFin consults on 9th MaRisk amendment” (Consultation 02/2026): https://www.bafin.de/… , accessed on 02.07.2026
S+P Unternehmerforum GmbH mit Sitz in München ist ein führender Anbieter für praxisnahe, rollenbasierte Weiterbildung im deutschsprachigen Raum. Seit der Gründung im Jahr 2004 unterstützt S+P Fach- und Führungskräfte sowie C-Level-Manager:innen aus der Finanzwirtschaft und Industrie dabei, sich gezielt weiterzuentwickeln und regulatorisch sowie strategisch sicher zu handeln.
S+P bietet ein breites Portfolio an Online-Seminaren, E-Learnings, Zertifikatslehrgängen und Executive Education Programmen. Themenschwerpunkte sind unter anderem Compliance, Geldwäscheprävention, Risikomanagement, Projektmanagement, Finance, Leadership und digitale Transformation.
Ein Alleinstellungsmerkmal ist die S+P Tool Box – mit sofort einsetzbaren Arbeitshilfen wie Leitfäden, Checklisten, Gantt-Plänen und Risikochecks. Zusätzlich steht allen Teilnehmer:innen die digitale Lernplattform S+P Lounge zur Verfügung.
Mit dem Zertifikat S+P Certified und dem digitalen Karriere-Badge dokumentieren Absolvent:innen ihre Kompetenz sichtbar – für Arbeitgeber, Kunden und Netzwerke.
Teilnehmer bewerten S+P Seminare auf ProvenExpert mit 4,65 von 5 Sternen. Für jedes gebuchte Seminar pflanzt S+P im Rahmen des ESG-Projekts „Dein Seminar, dein Baum, deine Zukunft“ einen Baum in Deutschland.
Mehr Informationen unter: www.sp-unternehmerforum.de
S&P Unternehmerforum GmbH
Feringastr. 12 A
85774 Unterföhring bei München
Telefon: +49 (89) 45242970100
Telefax: +49 (89) 45242970299
http://www.sp-unternehmerforum.de
E-Mail: cb@sp-unternehmerforum.de
Online Marketing Managerin
Telefon: +49 89 452 429 70 113
E-Mail: at@sp-unternehmerforum.de
![]()


