> ## Documentation Index
> Fetch the complete documentation index at: https://docs.matproof.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Getting Started with BaFin MaRisk

> A practical guide to implementing BaFin MaRisk requirements for German banking and financial institutions using Matproof.

# Getting Started with BaFin MaRisk

MaRisk (Mindestanforderungen an das Risikomanagement) is BaFin's circular on the minimum requirements for risk management in German credit institutions and financial services institutions. It implements the EBA Guidelines on internal governance and translates Basel requirements into binding supervisory expectations for the German market.

The current version (MaRisk 7.0, effective 2023) incorporates requirements from the EBA Guidelines on ICT and security risk management, making it directly relevant to operational resilience and IT governance. MaRisk applies to all institutions supervised by BaFin under the KWG (German Banking Act).

Matproof maps MaRisk requirements to controls, policies, and evidence workflows so you can demonstrate compliance during BaFin audits and Section 44 KWG examinations.

<Note>
  Activate MaRisk under **Settings - Frameworks - BaFin MaRisk**. Controls are pre-populated across all MaRisk modules (AT, BT, BTR).
</Note>

***

## Am I in Scope?

MaRisk applies to:

* Credit institutions (Kreditinstitute) under Section 1(1) KWG
* Financial services institutions (Finanzdienstleistungsinstitute) under Section 1(1a) KWG
* Payment institutions and e-money institutions (to the extent BaFin circular applies)
* Groups of institutions at both individual entity and group level

<Tip>
  MaRisk applies proportionally. Smaller, less complex institutions may implement simplified approaches where the circular explicitly allows it. Document your proportionality assessment in your risk management framework.
</Tip>

***

## MaRisk Structure

MaRisk is organized into modules:

| Module                    | Scope                                                                           | Matproof Module                 |
| ------------------------- | ------------------------------------------------------------------------------- | ------------------------------- |
| **AT** (Allgemeiner Teil) | General requirements: governance, risk strategy, internal controls, outsourcing | Policies, Controls, Vendor Risk |
| **AT 7**                  | IT resources and IT risk management (incorporates EBA ICT Guidelines)           | Controls, Evidence              |
| **AT 9**                  | Outsourcing                                                                     | Vendor Risk                     |
| **BT** (Besonderer Teil)  | Specific requirements for organizational structure and processes                | Controls                        |
| **BT 1**                  | Lending business                                                                | Controls                        |
| **BT 2**                  | Trading business                                                                | Controls                        |
| **BT 3**                  | Internal control system requirements                                            | Controls, Audit Programs        |
| **BTR**                   | Risk types: credit, market, liquidity, operational risk                         | Risk Management                 |

***

## Key Requirements in Matproof

<CardGroup cols={2}>
  <Card title="Risk Strategy" icon="compass">
    **Policies, Risk Management**

    Document a risk strategy consistent with the business strategy. The management board is responsible for defining the institution's risk appetite and ensuring adequate risk management.
  </Card>

  <Card title="IT Governance (AT 7)" icon="server">
    **Controls, Evidence**

    Implement IT risk management covering IT strategy, information security, IT operations, and IT project management. This module now incorporates EBA ICT Guidelines requirements.
  </Card>

  <Card title="Outsourcing (AT 9)" icon="building">
    **Vendor Risk**

    Classify outsourced activities by materiality. Material outsourcing requires risk analysis, contractual safeguards, exit strategies, and ongoing monitoring.
  </Card>

  <Card title="Internal Control System" icon="scale-balanced">
    **Controls, Audit Programs**

    Maintain the three lines of defense: operational management, risk management and compliance, and internal audit. Document segregation of duties.
  </Card>

  <Card title="Operational Risk" icon="triangle-exclamation">
    **Risk Management, Incidents**

    Identify, assess, and manage operational risks including IT failures, fraud, and process errors. Maintain a loss database and report material incidents.
  </Card>

  <Card title="Business Continuity" icon="rotate-right">
    **Policies, Controls**

    Maintain business continuity plans for time-critical activities and processes. Test plans regularly and document results.
  </Card>
</CardGroup>

***

## Recommended Implementation Plan

<Steps>
  ### Step 1 - Document your risk strategy and governance

  MaRisk AT 4.2 requires a written risk strategy derived from the business strategy:

  1. Go to **Policies - Generate** and create your Risk Management Framework Policy
  2. Document the management board's risk appetite statement
  3. Define roles and responsibilities for risk management across the three lines of defense
  4. Ensure the supervisory board (Aufsichtsrat) receives regular risk reporting

  ### Step 2 - IT risk management (AT 7)

  AT 7 is one of the most operationally intensive MaRisk modules:

  1. Document your IT strategy and ensure it aligns with the business strategy
  2. Complete controls for information security management (AT 7.2)
  3. Document IT operations including change management and incident handling (AT 7.3)
  4. Establish IT project management governance with risk assessment for major projects (AT 7.4)
  5. Define access rights management (AT 7.2) with regular recertification

  <Warning>
    BaFin examiners pay close attention to AT 7 implementation. Ensure your information security officer (ISB) has sufficient authority and reports directly to the management board.
  </Warning>

  ### Step 3 - Outsourcing register and risk assessments (AT 9)

  1. Go to **Vendor Risk** and create a complete outsourcing register
  2. Classify each outsourced activity as **material** or **non-material**
  3. For material outsourcing: conduct a risk analysis, verify contractual clauses (including BaFin audit rights), and document exit strategies
  4. Establish ongoing monitoring with defined escalation criteria
  5. Ensure BaFin notification requirements are met for material outsourcing arrangements

  ### Step 4 - Internal control system and segregation of duties

  1. Document your three lines of defense model
  2. Map key processes and verify segregation of duties (AT 4.3.1)
  3. Ensure the compliance function covers all regulatory requirements and reports to the management board
  4. Document the internal audit function's scope, independence, and reporting line

  ### Step 5 - Operational risk management

  1. Go to **Risk Management - New Risk Assessment** for operational risk
  2. Document your operational risk identification and assessment methodology
  3. Set up the **Incidents** module for operational loss event tracking
  4. Define risk indicators (KRIs) and escalation thresholds
  5. Ensure operational risk is included in the overall risk reporting

  ### Step 6 - Business continuity management

  1. Identify time-critical activities and processes
  2. Go to **Policies - Generate** and create your Business Continuity Policy
  3. Document recovery time objectives (RTOs) and recovery point objectives (RPOs)
  4. Conduct and document BCP tests at least annually
  5. Link test results as evidence against the relevant MaRisk controls

  ### Step 7 - Internal audit and gap review

  1. Go to **Audit Programs - New Audit - MaRisk**
  2. Run an internal audit covering all MaRisk modules
  3. Document findings as Corrective Actions with remediation timelines
  4. Ensure the audit report is presented to the management board and supervisory board
</Steps>

***

## Common BaFin Examination Findings

| Finding                         | How to Avoid                                                                                                                          |
| ------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| Incomplete outsourcing register | Include all outsourced activities, not just IT. Review procurement records for missed arrangements.                                   |
| IT risk management gaps (AT 7)  | Ensure the ISB role is formally established with clear authority. Document IT risk assessments for all critical systems.              |
| Missing segregation of duties   | Map dual-control requirements for all risk-relevant processes. Document compensating controls where full segregation is not feasible. |
| Insufficient BCP testing        | Test plans annually at minimum. Document test scenarios, results, and improvement actions.                                            |
| Risk reporting gaps             | Ensure ad-hoc reporting triggers are defined and management board reporting covers all material risk types.                           |

***

## Relationship to Other Frameworks

| Framework          | Overlap with MaRisk                                                                                                                                                         |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **DORA**           | DORA supersedes parts of MaRisk AT 7 for ICT risk. Institutions in scope for DORA should implement both, with DORA taking precedence for ICT-specific requirements.         |
| **ISO 27001**      | Strong overlap with AT 7 information security requirements. ISO 27001 certification can serve as evidence for many AT 7 controls.                                           |
| **EBA Guidelines** | MaRisk 7.0 incorporates EBA Guidelines on internal governance and ICT security risk management. Compliance with MaRisk generally satisfies the underlying EBA requirements. |

***

## Next Steps

* [Risk Management](/features/risk-management) - building your MaRisk-compliant risk assessment framework
* [Vendor Risk](/features/vendor-risk) - outsourcing register and material outsourcing assessments
* [Incidents](/features/incidents) - operational loss event tracking and reporting
* [Audit Programs](/features/audit-programs) - internal audit planning for BaFin examinations
