FiorLab is BaFin MaRisk 9th amendment compliance software built for German banks and financial services institutions under BaFin supervision. Central outsourcing management function, sub-outsourcing reporting, AML gate on the pre-outsourcing risk assessment, contingency planning where no viable exit exists, DORA delineation, and live Handelsregister verification. Aligned to the 9th amendment published 30 June 2026 — 12-month grace period ends approximately 30 June 2027.
Germany is the European Union's largest banking market and one of its most closely supervised. BaFin (Bundesanstalt für Finanzdienstleistungsaufsicht) publishes MaRisk — the Minimum Requirements for Risk Management (Mindestanforderungen an das Risikomanagement) — as its principal supervisory framework for German banks and financial services institutions. The 9th amendment to MaRisk was published on 30 June 2026 and reshapes the outsourcing architecture that every regulated firm must build around.
BaFin's supervisory posture is famously exacting. Onsite inspections work through the outsourcing register line by line, test the criticality methodology under real scrutiny, and expect the central outsourcing management function to demonstrate — not describe — how it exercises oversight. The 9th amendment changes the governance shape (central outsourcing officer replaced by a management function), tightens sub-outsourcing reporting, brings AML explicitly into outsourcing decisions, and introduces a minimum contingency-planning requirement where no viable exit exists. It also delineates MaRisk from DORA cleanly: ICT third-party arrangements in DORA scope are no longer covered by MaRisk outsourcing requirements.
The transition period is 12 months. From roughly 30 June 2027 BaFin expects full alignment. Off-the-shelf US-centric tools do not model MaRisk's German-specific fields, do not reach the Handelsregister live, and do not distinguish MaRisk from DORA when the two regimes overlap. FiorLab's German MaRisk assessment type is built into the platform from day one, with live Handelsregister verification, a MaRisk-specific question bank tuned to the 9th amendment, and audit-ready output aligned to the new register plus governance structure.
The 9th amendment introduces four operational shifts that reshape how German regulated firms manage outsourcing. Each has an immediate operational implication for the outsourcing register, the governance function, and the audit-ready evidence file.
Where prior versions of MaRisk required a named central outsourcing officer with individual accountability, the 9th amendment repositions the role as a team responsibility — a central outsourcing management function. In practice, outsourcing governance is now a documented function with defined responsibilities, reporting lines, and interfaces to the management body — not a single person's title. Operational implication: the outsourcing register, criticality methodology, and management-body escalation must all be attributable to the function rather than an individual; the sign-off log must map to the function's charter; and any handover between individuals must not create a gap in accountability. BaFin will test the operating model at inspection.
The 9th amendment strengthens the reporting obligations that apply along the sub-outsourcing chain. Firms must maintain a clearer view of Tier-2 (and beyond) dependencies for material outsourcings and surface material changes upward through the outsourcing register. Operational implication: the chain-of-consent capture, the sub-processor listing, and the change-notification workflow all need explicit fields in the register — spreadsheet-based approaches routinely miss Tier-2 changes because the firm has never asked the Tier-1 provider for a live map.
AML (anti-money-laundering) considerations must now be factored into outsourcing decisions and documented in the pre-outsourcing risk assessment. Operational implication: the pre-outsourcing risk assessment gains an AML gate — where an outsourced function touches client onboarding, transaction monitoring, sanctions screening, or KYC, the AML review is a mandatory step and must be evidenced in the sign-off log with a named approver.
Where a firm cannot demonstrate a viable exit option for a material outsourcing arrangement, the 9th amendment requires a documented minimum contingency plan. Operational implication: this closes a loophole where firms declared "no realistic alternative provider" and stopped there. From now, "no viable exit" is not the end of the analysis — it is the trigger for a contingency plan (in-house reintegration steps, service degradation modes, buyer and customer communications, regulator notification) that must be tested and kept current.
Alongside these four, Internal Audit gains flexibility on outsourcing coverage, and proportionality relief applies for small and very small institutions (SNCIs). The 12-month grace period ends approximately 30 June 2027.
Each shift in the 9th amendment maps to a concrete artefact BaFin will ask for at supervisory review. Four to have ready.
Written charter defining responsibilities, reporting lines, escalation paths, and interface with the management body. Sign-off log attributable to the function, not a single officer. BaFin question: "walk us through the function's operating model since the 9th amendment came into force."
Tier-1 provider identified per material outsourcing, Tier-2 dependencies enumerated, chain-of-consent evidence where the contract requires consent. Change-notification workflow documented. "We rely on the provider's quarterly report" is a finding.
Where an outsourced function touches AML in-scope activities (onboarding, monitoring, sanctions, KYC), the pre-outsourcing risk assessment carries an explicit AML review section with named approver and dated decision. Absent AML gate on an AML-touching function is a first-order finding.
Where the firm cannot demonstrate a viable exit, a documented minimum contingency plan covering in-house reintegration, service degradation, communications, and regulator notification. Dated tabletop or live test report. "Not tested" is a finding; "no contingency plan because no exit" is a finding under the 9th amendment.
Perhaps the most consequential change in the 9th amendment is what it removes: outsourcing arrangements within DORA scope are no longer covered by MaRisk outsourcing requirements. BaFin has deliberately delineated its national outsourcing rule set from the binding EU DORA regime to reduce regulatory duplication. The practical consequence for a German-regulated financial firm running both regimes is that the outsourcing register no longer has to hold a MaRisk-and-DORA hybrid entry per ICT arrangement — the ICT arrangements sit under DORA Article 28 with the ESAs ITS Register of Information template, and the non-ICT arrangements sit under MaRisk with the German-specific fields.
That delineation reads clean on paper and creates work in practice. Three specific interfaces trip up firms.
Register template alignment. The ESAs ITS template for the DORA Register of Information and the MaRisk outsourcing register are not identical. Fields overlap (provider identity, service description, criticality classification, sub-processors) but do not map one-to-one. A single register that produces both outputs requires a canonical data model with an ITS export for DORA and a MaRisk export for BaFin — not a single spreadsheet re-badged for each request.
Sub-outsourcing reporting mismatch. DORA Article 28(3) requires ICT sub-contracting to be recorded in the ITS template; MaRisk's 9th-amendment sub-outsourcing reporting applies to non-ICT chains. For a supplier that delivers both ICT and non-ICT services (rare but real — think a facilities-management provider with an embedded IT platform), the buyer must map the Tier-2 chain twice with the correct field set for each regime. FiorLab flags the boundary case at register entry so the buyer never signs off on the wrong template.
Governance interface — central outsourcing management function vs DORA governance. DORA imposes management-body responsibility for ICT third-party risk (Article 5) with named senior-management-level reporting. MaRisk's 9th-amendment central outsourcing management function is a team responsibility for non-ICT outsourcing governance. Firms must ensure the two governance chains meet — a single escalation path where the ICT chain and the non-ICT chain converge on the management body — or the audit committee finds two governance shadows and no single register of truth.
For a German financial firm running both regimes in parallel, the practical read is: one platform, two assessment types, one canonical supplier record. FiorLab supports the German MaRisk assessment type and the DORA Article 28 assessment type natively, with shared supplier records and the boundary flagged at entry.
Three structural failure modes when a German BaFin-supervised firm tries to use a US-centric supplier risk or GRC platform for MaRisk 9th-amendment compliance.
US-centric tools are built for NIST, COSO, SOC 2, and US GRC frameworks. MaRisk is a German-language, principles-based supervisory framework with its own terminology — "wesentliche Auslagerungen" (material outsourcings), "gruppeninterne Auslagerung" (intra-group outsourcing) — and the specific reporting structures BaFin expects at onsite inspection. US tools deliver the MaRisk overlay through professional services rather than out-of-the-box, which means weeks-to-months of customisation before the platform produces output a BaFin inspector would accept. Every 9th-amendment change — central outsourcing management function, sub-outsourcing reporting, AML gate, contingency plan — restarts that professional-services clock.
US-headquartered tools remain subject to FISA Section 702 and the CLOUD Act regardless of where customer data is hosted. BaFin has published concerns about US-hosted data in the context of critical banking functions, and the DORA sub-contracting RTS treats non-EU sub-processing as a scored risk factor. After the EU Tech Sovereignty Package adopted 3 June 2026, EU corporate jurisdiction is a formal procurement-scoring criterion at regulated buyers under DORA, EBA, and MaRisk-adjacent frameworks. A US-headquartered vendor holding the German outsourcing register is a live procurement-scoring problem, not a hypothetical one.
German BaFin-supervised firms need live verification against the German Handelsregister (the federal commercial register), plus VIES and GLEIF for cross-border counterparties. Most US-centric tools rely on paid premium data partners (Dun & Bradstreet, Bureau van Dijk) rather than live Handelsregister calls. The buyer pays for what should be a free public signal and gets it weeks stale rather than seconds fresh. FiorLab reaches the Handelsregister live at supplier onboarding and on a 30-day recheck cadence.
The German MaRisk assessment type in FiorLab is a first-class workflow, not a renamed generic questionnaire. Five steps from start to audit-ready output.
Add the supplier via CSV import or manual entry. FiorLab calls the German Handelsregister for German-registered suppliers, CRO Ireland, UK Companies House, VIES, and GLEIF live. The registry status, registered name, and entity identifier are written to the supplier record with a timestamp. ISO certifications declared by the supplier are auto-verified against the accredited certification body via IAF CertSearch.
Choose the German MaRisk assessment type. The platform presents the MaRisk-specific question bank aligned to the 9th amendment — materiality (wesentliche Auslagerungen) methodology, the central outsourcing management function sign-off structure, the strengthened sub-outsourcing reporting fields, the AML gate on the pre-outsourcing risk assessment, and the contingency-planning trigger where no viable exit exists. Where DORA also applies to a given arrangement, FiorLab flags the boundary at entry and routes ICT-specific fields to the DORA Article 28 assessment.
FiorLab scores the supplier across financial stability, regulatory compliance, ESG / sustainability, delivery performance, quality management, and innovation. Each dimension carries a 5-tier verification multiplier (registry_verified 1.0x through self_declared 0.65x) and a document staleness decay (fresh through expired). The scoring is deterministic and rules-based, and every sub-metric traces to the underlying evidence — no "black box" the audit committee cannot challenge and no output the BaFin inspector cannot follow line by line.
One click produces an audit-ready PDF report. Every score traces to a Handelsregister record, IAF CertSearch lookup, or OCR-verified document with timestamps. The report includes the MaRisk-specific sections aligned to the 9th amendment: central outsourcing management function sign-off log, sub-outsourcing chain map, AML gate log, contingency plan reference, and the three-lines-of-defence sign-off chain. Suitable for the BaFin supervisory file.
Once onboarded, FiorLab continues to monitor: weekly cert re-verification via the IAF CertSearch cron, daily registry status checks on a 30-day cadence, document staleness decay applied automatically, anomaly detection across six anomaly types, and a full immutable audit trail of every change. When BaFin asks for the latest position, the answer is one query away.
Comparison rows are based on publicly available product documentation, official websites, and analyst coverage as of 15 July 2026. To request a correction, email hello@fiorlab.com.
| FiorLab | Aprovall | Vendorica | OneTrust | |
|---|---|---|---|---|
| HQ jurisdiction | Ireland (Dublin, CRO 813471) — EU | France (EU) | USA | USA |
| Data residency | EU (Frankfurt) | EU | US default; EU on Enterprise | US default; EU on Enterprise |
| MaRisk 9th amendment native | Yes — first-class | Generic EU mapping | Via professional services | Via professional services |
| DORA + MaRisk overlap handled | Both natively, boundary flagged | DORA only | DORA only | DORA only (modular) |
| Handelsregister live integration | Live public API | Not advertised | Paid premium data only | Paid premium data only |
| Sub-outsourcing register export (9th amendment) | Export-ready | Manual workflow | Via PS | Via PS |
| Contingency plan module | Built-in, tabletop-test log | Document-repository only | Document-repository only | Document-repository only |
| Published pricing | Free + from €329/mo | Contact sales | Contact sales | Contact sales |
| Time to first audit-ready output | ~5 minutes | Days | Days–weeks | Weeks |
| Best fit for German-regulated entity | Banks, financial services institutions, insurers under BaFin | Procurement-led mid-market | Global mid-market with US footprint | Enterprise multi-region GRC |
The MaRisk 9th amendment is the ninth revision of BaFin's Minimum Requirements for Risk Management (Mindestanforderungen an das Risikomanagement), published on 30 June 2026. It reshapes the outsourcing architecture that German banks and financial services institutions must maintain: outsourcing arrangements within DORA scope are removed from MaRisk (delineation from the binding EU regime); the central outsourcing officer role is replaced by a central outsourcing management function (team responsibility); sub-outsourcing reporting obligations are strengthened; AML considerations must be factored into outsourcing decisions; a minimum contingency plan is required where no viable exit exists; Internal Audit gains flexibility; and proportionality relief applies for small and very small institutions (SNCIs). The 12-month grace period runs until approximately 30 June 2027.
The 9th amendment replaces the individual central outsourcing officer with a central outsourcing management function — a team responsibility with defined charter, reporting lines, and interface to the management body. In practice this means outsourcing governance is now a documented function rather than a single person's title. The outsourcing register, criticality methodology, and management-body escalation must all be attributable to the function; the sign-off log must map to the function's charter; and any handover between individuals must not create a gap in accountability. BaFin will test the function's operating model at onsite inspection — "the officer left last month" is no longer an accepted answer.
The 9th amendment removes outsourcing arrangements within DORA scope from MaRisk outsourcing requirements. In practical terms: ICT third-party arrangements sit under DORA Article 28 with the ESAs ITS Register of Information template; non-ICT outsourcing sits under MaRisk with German-specific fields. For a German financial firm running both regimes in parallel, three interfaces demand attention: register template alignment (ITS vs MaRisk field mapping), sub-outsourcing reporting mismatch (DORA applies to ICT chains; MaRisk's strengthened reporting applies to non-ICT chains), and the governance interface (DORA management-body responsibility vs the MaRisk central outsourcing management function). A single canonical supplier record with two assessment types — DORA Article 28 and MaRisk — is the operational answer.
The 9th amendment strengthens the reporting obligations that apply along the sub-outsourcing chain for non-ICT outsourcing. Firms must maintain a clearer view of Tier-2 (and beyond) dependencies for material outsourcings and surface material changes upward through the outsourcing register. In compliance software terms this means explicit fields for the chain-of-consent capture, the sub-processor listing, and the change-notification workflow. Spreadsheet-based approaches routinely miss Tier-2 changes because the firm has never asked the Tier-1 provider for a live map. The BaFin expectation at supervisory review is a current sub-outsourcing chain map with dated consent evidence.
The 9th amendment introduces a minimum contingency-planning requirement where a firm cannot demonstrate a viable exit option for a material outsourcing arrangement. This closes a loophole under prior versions of MaRisk where firms declared "no realistic alternative provider" and stopped there. From now, "no viable exit" is not the end of the analysis — it is the trigger for a documented minimum contingency plan covering in-house reintegration steps, service degradation modes, buyer and customer communications, and regulator notification. The plan must be tested (tabletop or live), kept current, and evidenced in the outsourcing file. BaFin will ask "when did you last test it?" at inspection.
Three reasons. First, US-centric tools map first to NIST, COSO, and US GRC frameworks; MaRisk is a German-language, principles-based framework with terminology ("wesentliche Auslagerungen", "gruppeninterne Auslagerung") and reporting structures that US tools deliver through professional services rather than out-of-the-box — and every 9th-amendment change restarts that professional-services clock. Second, US-headquartered tools remain subject to FISA Section 702 and the CLOUD Act regardless of where customer data is hosted; BaFin has published concerns about US-hosted data in critical banking functions, and after the EU Tech Sovereignty Package (3 June 2026) EU corporate jurisdiction is a formal procurement-scoring criterion. Third, German firms need live verification against the German Handelsregister plus VIES and GLEIF; most US-centric tools rely on paid premium data partners (D&B, Bureau van Dijk) rather than live public-registry calls.
We built FiorLab for the regulators our buyers sit closest to — and BaFin sits at the top of the list for anyone operating a bank or a financial services institution inside Germany. The 9th MaRisk amendment is not a rebadge. It changes the governance shape, it changes the sub-outsourcing reporting expectation, it brings AML explicitly into outsourcing decisions, and it forces a contingency plan where the firm cannot demonstrate a viable exit. Twelve months is not a long grace period when the register, the function's charter, and the contingency tests all have to be in place by inspection. The platforms purpose-built for that wave are the ones that do not make a BaFin inspector translate the output before they can read it. If you would like to talk through how the German MaRisk assessment type maps onto your firm's operating model — bank, financial services institution, insurer, or intra-group outsourcing — reach us at hello@fiorlab.com.
— Word from our founder
DORA is enforced across all 27 EU states · MaRisk 9th amendment in force · BaFin outsourcing supervision live. Native MaRisk assessment type with live Handelsregister verification, six-dimension scoring, audit-ready PDF from day one, EU-hosted, customer-owns-data.
Start Your Assessment