BaFin Publishes 7th Update of MaRisk

30. June 2023

Yesterday, an important regulatory circular reached all credit and financial services institutions in Germany: The German Federal Financial Supervisory Authority (BaFin) published an update of the Minimum Requirements for Risk Management (MaRisk).

In the 7th update of MaRisk, BaFin implements the guidelines of the European Banking Authority (EBA), for example on lending and monitoring. It also updates key aspects and even introduces new ones.

We have worked out the most important changes for you here:

  • Addition of the risk category "ESG risks" (Environmental, Social and Governance) and highlighting their relevance for the institutions
  • Defining Risk Culture monitoring as a new management responsibility
  • Inclusion of minimum requirements on institutions' real estate business
  • Addition of a new section to address Model Risks
  • Establishing regulations on trading at the residential workplace

The chapters describing Information Security Risks for institutions remain almost completely unaffected by the update.

Like previous BaFin regulatory circulars, the updated version of MaRisk will become effective immediately. Institutions are granted a transition period until January 1, 2024 to implement the requirements.

The current MaRisk 05/2023 in German can be found here: https://www.bafin.de/SharedDocs/Veroeffentlichungen/DE/Rundschreiben/2023/rs_05_2023_MaRisk_BA.html


Your organization is regulated by BaFin and you need assistance with a harmonization project or with the implementation of individual information security requirements? Contact us, we are happy to help.

Also interesting:

DORA Countdown: One Month Left Until the Deadline

DORA Countdown: One Month Left Until the Deadline

DORA, the Digital Operational Resilience Act, will fully apply as of 17 January 2025. We have summarized everything you need to know about the EU regulation, preparation and best practices from our news blog.

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

PCI DSS v4.0: In March 2024, version 4.0 of the Payment Card Industry Data Security Standard became mandatory after a two-year transition phase. Just a few months later, version 4.0.1 was released as a minor update of the standard, which will become mandatory on...

Top 3 Vulnerabilities in SSO Pentests

Top 3 Vulnerabilities in SSO Pentests

During their penetration tests (pentests), our security analysts at usd HeroLab repeatedly uncover vulnerabilities that pose significant risks to corporate security. They increasingly encounter the same vulnerabilities. Our blog series "Top 3 Vulnerabilities" presents...

Categories

Categories