The Federal Financial Supervisory Authority (“Bafin”) published the 9th amendment to the Circular on Minimum Requirements for Risk Management (“MaRisk”). The stated goal of the amendment is to reduce complexity, strengthen the principle of proportionality, and place greater emphasis on principles rather than detailed requirements. In addition to these fundamental decisions, Bafin’s statement that ICT services will no longer be classified as “outsourcing” is likely to have far-reaching consequences for affected institutions and their third-party risk management.
In the new version of MaRisk (Circular 06/2026 (BA)) published on 30 June 2026, the explicit statement in the explanatory note to AT 9 para. 1 is particularly noteworthy. According to this statement, “outsourced or externally procured ICT services within the meaning of Article 3 No. 21 DORA that are subject to ICT third-party risk management under Articles 28–30 DORA” do not fall within the scope of AT 9.
For some time, MaRisk has contained requirements for credit institutions and financial services institutions regarding the management of risks arising from the outsourcing of activities and processes to other companies. These include, for example, mandatory contractual clauses to be agreed in the case of material outsourcing arrangements. With Chapter V of Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (“DORA”), which entered into force in 2025 and addresses ICT third-party risk management, an additional legal framework for the management of externally procured services was introduced.
The point of reference for these DORA requirements, which also include minimum contractual provisions, is the term “ICT service”. Since the definition of ICT services under DORA is not based on the definition of outsourcing and does not simply constitute “IT outsourcing”, it is possible for a service arrangement to fall conceptually under one or both of these definitions. Bafin had previously taken the view that, in many cases, an ICT service may also constitute an outsourcing arrangement (see, for example, Chapter 6.1 of Bafin’s supervisory statement on implementation guidance regarding DORA).
This potential dual regulation posed a challenge for affected institutions. For example, in order to comply with the (comparable but not identical) contractual requirements upon DORA becoming applicable, many contractual relationships (often involving complex contractual structures and “DORA annexes”) had to be amended to comply with both MaRisk and DORA. Similarly, recording contractual relationships both in the DORA information register and in the outsourcing register under MaRisk, in conjunction with the EBA Guidelines on outsourcing arrangements (EBA/GL/2019/02), created considerable administrative effort.
With the clear statement that ICT services within the meaning of DORA do not fall under AT 9 MaRisk, Bafin now enables affected institutions to draw a strict distinction between outsourcing arrangements and ICT services. As a result, only the requirements of the respectively applicable and self-contained legal framework need to be met. The European Banking Authority (“EBA”) is also pursuing this separation in its consultation on the update of the EBA Guidelines on outsourcing arrangements (EBA/CP/2025/12), under which ICT services are to be removed from the scope of application. In this respect, Bafin is anticipating the EBA Guidelines that are not yet final.
However, the EBA’s consultation paper also provides for an expansion of the scope. Instead of using “outsourcing” as the point of reference, the applicability of the Guidelines is now to be based on the newly introduced umbrella term “third-party arrangements”. It remains to be seen when and how Bafin will implement this requirement after the EBA Guidelines enter into force. It is also currently unclear how such an amendment to MaRisk can be reconciled with Section 25b KWG, which still refers to “outsourcing” and has so far been specified through MaRisk. Finally, it is unclear whether and when the amendments to MaRisk, to the extent transferable, will be incorporated into other Bafin circulars, such as the ZAG-MaRisk for payment institutions, which are also subject to DORA and therefore to potential double regulation. Affected institutions are therefore advised to closely monitor these regulatory developments in third-party risk management.