Supervisory minimum requirements for the risk management of banks.
MaRisk sets out the requirements of the German Banking Act (KWG) regarding risk management at banks. It covers areas including lending business, internal controls, contingency management, and the management of outsourcing arrangements. For IT service providers, section AT 9 on outsourcing is of central importance: it requires institutions to conduct a risk analysis, establish clear contracts, carry out ongoing monitoring, and develop exit strategies for outsourced services. The IT-specific requirements have partly transitioned into the European regulatory framework through DORA, but MaRisk remains the overarching framework for risk management.
For IT service providers with banking clients, MaRisk means that your client must manage you as an outsourcing arrangement in a compliant manner and passes these obligations on to you. This manifests itself in questionnaires on security and contingency planning, in requests for evidence, and in contractually guaranteed audit and termination rights. These requirements recur across clients and closely resemble DORA and outsourcing inquiries. Those who handle them quickly and verifiably are perceived as a reliable partner in the banking environment.
With Tendry, you answer MaRisk-driven inquiries from your banking clients from a verified, reusable knowledge base. How institutions manage their outsourcing arrangements on the buyer side is demonstrated by our platform Leno.