2026-08-24
Added
This circular establishes the minimum requirements for risk management for Medium and Small Securities Firms under German law, effective January 1, 2027. It mandates the implementation of flexible risk management frameworks, including risk inventories, capital planning, and stress tests, while explicitly excluding Large Securities Firms which remain subject to KWG regulations. The document requires institutions to identify material risks, including ESG and ICT risks, and to maintain specific internal control mechanisms and reporting structures.
Business Area WA/Section WA 41 Status: 24.08.2026 Circular 09/2026 (WA) Minimum Requirements for the Risk Management of Securities Firms ("WpI MaRisk")
WpI MaRisk 2 of 35 TABLE OF CONTENTS AT 1 OBJECTIVE OF THE CIRCULAR AND COMMENCEMENT OF APPLICATION ....................................................................................................................................................................................... 4 AT 2 SCOPE AND DEFINITIONS......................................................................................................................................................................................... 5 AT 2.1 APPLICABLE ENTITIES .......................................................................................................................................................................................................................................................................................... 5 AT 2.2 RISKS ......................................................................................................................................................................................................................................................................................................... 5 AT 2.3 TRANSACTIONS ................................................................................................................................................................................................................................................................................................... 7 AT 3 RESPONSIBILITY OF MANAGEMENT AND SUPERVISORY BOARD ................................................................................................................................................... 8 AT 3.1 OVERALL RESPONSIBILITY OF MANAGEMENT ................................................................................................................................................................................................................................... 8 AT 3.2 RESPONSIBILITY OF THE SUPERVISORY BOARD .............................................................................................................................................................................................................................................. 9 AT 4 GENERAL REQUIREMENTS FOR RISK MANAGEMENT .................................................................................................................................................................... 9 AT 4.1 RISK APPETITE AND CAPITAL PLANNING .......................................................................................................................................................................................................................................... 9 AT 4.1.1. Risk Appetite ........................................................................................................................................................................................................................................................................ 9 AT 4.1.2 Capital Planning ............................................................................................................................................................................................................................................................................. 11 AT 4.2 STRATEGIES ................................................................................................................................................................................................................................................................................................ 11 AT 4.3 INTERNAL CONTROL MECHANISMS .......................................................................................................................................................................................................................................................... 12 AT 4.3.1 Structural and Process Organization ............................................................................................................................................................................................................................................ 12 AT 4.3.2 Risk Management Processes ..................................................................................................................................................................................................................................................... 13 AT 4.3.3 Stress Tests ....................................................................................................................................................................................................................................................................................... 14 AT 4.4 SPECIAL FUNCTIONS ......................................................................................................................................................................................................................................................................... 14 AT 4.4.1 Risk Management Function ................................................................................................................................................................................................................................................... 14 AT 4.4.2 Compliance Function ................................................................................................................................................................................................................................................................. 15 AT 4.3.3 Internal Audit ............................................................................................................................................................................................................................................................................. 16 AT 5 ORGANIZATIONAL GUIDELINES ........................................................................................................................................................................................................................... 18 AT 6 DOCUMENTATION.............................................................................................................................................................................................................................................. 19 AT 7 RESOURCES ....................................................................................................................................................................................................................................................... 19 AT 7.1 PERSONNEL ................................................................................................................................................................................................................................................................................................... 19 AT 7.2 TECHNICAL-ORGANIZATIONAL EQUIPMENT .................................................................................................................................................................................................................................... 20 AT 7.3 EMERGENCY MANAGEMENT ............................................................................................................................................................................................................................................................................ 20 AT 8 ADAPTATION PROCESSES .................................................................................................................................................................................................................................... 20
WpI MaRisk 3 of 35 AT 8.1 NEW PRODUCT PROCESS ......................................................................................................................................................................................................................................................................... 20 AT 8.2 CHANGES TO OPERATIONAL PROCESSES OR STRUCTURES ................................................................................................................................................................................................................ 21 AT 9 OUTSOURCING .................................................................................................................................................................................................................................................................................................. 21 BT 1 SPECIAL REQUIREMENTS FOR INTERNAL CONTROL MECHANISMS .................................................................................................................................................... 27 BTH SPECIAL REQUIREMENTS FOR THE DESIGN OF TRADING TRANSACTIONS ............................................................................................................................... 27 BTH 1 FUNCTIONAL SEPARATION............................................................................................................................................................................................................................................................................... 27 BTH 2 REQUIREMENTS FOR PROCESSES IN TRADING ................................................................................................................................................................................................................. 28 BTV CONNECTION OF CONTRACTUALLY BOUND BROKERS .................................................................................................................................................................................................. 28 BTR REQUIREMENTS FOR RISK MANAGEMENT PROCESSES .......................................................................................................................................................................... 29 BTR 1 RISKS FROM ONGOING OPERATIONS .............................................................................................................................................................................................................. 30 BTR 1.1 RISKS FOR CUSTOMERS ....................................................................................................................................................................................................................................................................... 30 BTR 1.2 RISKS FOR THE MARKET ........................................................................................................................................................................................................................................................................ 30 BTR 1.3 RISKS FOR THE SECURITIES FIRM ................................................................................................................................................................................................................................................. 31 BTR 2 OTHER RISKS ............................................................................................................................................................................................................................................ 33 BTR 3 LIQUIDITY RISKS ......................................................................................................................................................................................................................................... 33 BTR 4 RISK OF DISORDERLY WINDING UP.............................................................................................................................................................................................. 34 BT 2 REQUIREMENTS FOR RISK REPORTING ............................................................................................................................................................................... 35
WpI MaRisk 4 of 35 Minimum Requirements for the Risk Management of Securities Firms ("WpI MaRisk") AT 1 Objective of the Circular and Commencement of Application 1 This circular presents a flexible and practice-oriented framework for the design of the business organization and risk management of securities firms based on the following legal foundations: Sections 13, 20, 28, Chapter 5, Section 1 of the Securities Trading Institutions Act (WpIG) - in particular Sections 38, 39, 40, 41, 43, 44 and 45 WpIG as well as Sections 80, 81 of the Securities Trading Act (WpHG) and Delegated Regulation (EU) 2017/565 (Del. VO) - in particular Articles 21 - 25 Del. VO.
The circular implements the following EBA Guidelines insofar as they concern the risk management of securities firms: • Guidelines on internal governance pursuant to Directive (EU) 2019/2034 (EBA/GL/2021/14) • Suitability of members of the management body and holders of key functions (EBA/GL/2021/06, ESMA35-36-2319).
2 Compliance with the requirements set out in this circular by securities firms is also intended to help, in accordance with Section 5(1) sentence 3 WpIG, counteract deficiencies in the securities sector that could endanger the safety of entrusted assets, impair the proper provision of securities services, securities ancillary services or ancillary business, or cause significant disadvantages to the overall economy. The requirements must also be complied with with the proviso of protecting the interests of securities service customers. Furthermore, compliance with the requirements set out is intended to help mitigate the risk of a disorderly winding up of securities firms. The guiding principle of WpI MaRisk is solvency supervision to protect customers, which requires a proper business organization of the securities firm with effective risk management.
3 The appropriate handling of the principle of proportionality underlying WpI MaRisk by securities firms involves that securities firms take further precautions beyond certain requirements presented in WpI MaRisk in individual cases, insofar as this may be necessary to ensure appropriate and effective risk management.
4 The Federal Financial Supervisory Authority (BaFin) expects that the flexible basic orientation of the circular is taken into account in the context of examination activities. Examinations are to be carried out on the basis of a risk-oriented examination approach.
5 This circular applies from 01.01.2027.
AT 2 Scope and Definitions AT 2.1 Applicable Entities
The requirements of this circular are directed at Medium and Small Securities Firms within the meaning of Section 2(16) and (17) WpIG including their foreign branches.
The requirements set out in this circular do not apply to Large Securities Firms.
Large Securities Firms For Large Securities Firms within the meaning of Section 2(18) WpIG, the statutory supervisory framework according to Section 4 WpIG is to be applied. For these securities firms, Sections 25a and 25b of the Banking Act (KWG) and the requirements specifying these provisions (cf. Circular 06/2026 (BA) - Minimum Requirements for Risk Management - MaRisk) continue to apply unchanged.
AT 2.2 Risks
WpI MaRisk 5 of 35 1 The requirements of the circular relate to the management of risks that are material to the firm. To assess materiality, management must regularly and on an ad-hoc basis gain an overview of the risks of the securities firm as part of a risk inventory (overall risk profile). The risks must be captured at the level of the entire securities firm, regardless of in which organizational unit the risks originated.
The securities firm must examine within the framework of the risk inventory which risks are to be classified as material. Material risks are in particular those that may have significant impacts on the amount of available own funds, or which may significantly impair the asset, earnings, or liquidity position. The risk inventory must not be oriented exclusively towards the impacts in financial accounting or formal legal designs.
In principle, at least the following risks are to be examined for materiality and classified accordingly: a. Risks from ongoing operations (depending on the specific business activities provided), i. Risks for customers (RtC), ii. Risks for the market (RtM), iii. Risks for the securities firm (RtF), b. Other risks and c. Liquidity risks.
Risk concentrations associated with material risks are to be taken into account.
Appropriate precautions are to be taken for risks that are classified as immaterial.
Small Securities Firms For Small Securities Firms, the assessment of materiality can generally be qualitative, e.g., by means of expert estimation. Risks for the market can be disregarded in this context.
Risk Concentrations In addition to risk positions against individual counterparties, which alone constitute a risk concentration due to their size, risk concentrations can arise both through the correlation of risk positions within one risk category ("Intra-risk concentrations") as well as through the correlation of risk positions across different risk categories (due to common risk factors or through interactions of different risk factors of different risk categories - "Inter-risk concentrations").
Information and Communication Technology Risks Information and communication technology risks (ICT risks) are to be explicitly included in the risk inventory.
2 As part of the risk inventory, Medium Securities Firms must also consider the risk of disorderly winding up in accordance with the requirements of BTR 4, taking into account the legal form, business model, business and risk strategy, as well as the scope and complexity of activities, in a comprehensible manner.
WpI MaRisk 6 of 35 3 When assessing materiality as part of the risk inventory, the design of the respective General Requirements for Risk Management (AT 4) and the requirement for risk reporting (BT 2), the impacts of ESG risks must be appropriately taken into account.
Consideration of ESG Risks ESG risks (ESG: Environment, Social, Governance) are understood to be events or conditions from the areas of environment, social issues, or corporate governance that act as risk drivers/factors and thus radiate onto the risk categories listed in para. 1 lit. a. to c. and other material risk categories.
AT 2.3 Transactions 1 Transactions within the meaning of this circular are securities services, securities ancillary services, and ancillary business according to Section 2(2), (3), and (4) WpIG. Other, license-free transactions are only included insofar as risks for the securities firm or its proper fulfillment of securities services, securities ancillary services, and ancillary business can arise from these transactions.
Transactions with bearer bonds and securities lending are also considered trading transactions, but not the initial issuance of securities. Trading transactions also include agreements on return or repurchase obligations and repurchase agreements, regardless of the subject matter of the transaction.
Issuance Business The initial issuance of securities is in principle not a trading transaction. However, the initial acquisition from an issuance constitutes a trading transaction. Facilitations regarding the control of market fairness are possible in the case of initial acquisition.
WpI MaRisk 7 of 35
WpI MaRisk 8 of 35
AT 3 Responsibility of the Management Board and the Supervisory Body
AT 3.1 Overall Responsibility of the Management Board
1 All members of the management board are responsible for the proper organization of the business and its further development, regardless of the internal allocation of responsibilities. The management board fulfills this responsibility only if it can assess the risks and take the necessary measures to limit them. This also includes the development, promotion, and monitoring of an appropriate risk culture at all levels within the securities firm.
Risk Culture The risk culture generally describes the manner in which employees of the securities firm handle (or should handle) risks in the course of their activities. The risk culture should promote the identification and conscious handling of risks and ensure that decision-making processes lead to results that are balanced even from a risk perspective. Characteristic of an appropriate risk culture is above all the clear commitment of the management board to risk-appropriate behavior, the observance by all employees of the risk appetite communicated by the management board, the responsibility of employees for their risk behavior, and the enabling and promotion of a transparent and open dialogue within the institution on risk-relevant issues.
Risk Appetite The management board makes a conscious decision regarding the extent to which it is willing to take on risks (risk appetite). The risk appetite can be expressed in various ways. In addition to purely quantitative specifications (e.g., strictness of risk measurement, global limits, definition of buffers for certain stress scenarios), the risk appetite can also be expressed through the definition of qualitative specifications (e.g., avoidance or restriction of certain businesses). The nature and scope of the specifications regarding risk appetite take into account the size of the securities firm and its business model.
2 Irrespective of the overall responsibility of the management board for the proper organization of the business and in particular for an appropriate and effective risk management, each member of the management board is responsible for establishing appropriate control and monitoring processes in their respective area of responsibility.
WpI MaRisk 9 of 35
AT 3.2 Responsibility of the Supervisory Body
1 Risk management must be designed in such a way that the supervisory body is appropriately involved and can perform its monitoring function properly. The management board must inform the supervisory body – if one exists – at appropriate intervals and, if necessary, on an ad hoc basis about the business situation, the business and risk strategy, and the risk situation, including existing risk concentrations. For this purpose, the management board must jointly with the supervisory body establish a suitable procedure.
2 The management board must inform the chairman of the supervisory body without delay about serious findings of the Internal Audit and Compliance functions against members of the management board. If the management board fails to fulfill its reporting obligation or does not decide on appropriate measures, the Internal Audit must inform the chairman of the supervisory body. Information transmitted to the supervisory body must be comprehensible and meaningful.
AT 4 General Requirements for Risk Management
AT 4.1 Risk Bearing Capacity and Capital Planning
AT 4.1.1. Risk Bearing Capacity
1 The provisions set out in this section apply only to Medium-sized Securities Firms.
Authority to Issue Directives The authority of BaFin under Section 39(3) of the Securities Trading Act (WpIG) to require Small Securities Firms to comply with the requirements of Section 39(1) and (2) WpIG remains unaffected by the restriction of the application of this section.
Requirements for Certain Medium-sized Securities Firms For the purposes of this section, heightened requirements are to be placed on securities firms that, in the course of their business activities, acquire ownership or possession of client funds or client securities to a not merely insignificant extent.
WpI MaRisk 10 of 35
2 The securities firm must ensure, based on the overall risk profile, that the risk coverage potential continuously covers the essential risks of the securities firm, also taking into account risk concentrations, thereby ensuring risk bearing capacity. If several risks are each classified as immaterial, but are material when aggregated, the procedures for ensuring risk bearing capacity must ensure appropriate consideration of the risks that exceed the materiality threshold when aggregated.
3 The securities firm must establish an internal process for ensuring risk bearing capacity. The procedures used for this purpose must appropriately consider the goal of continuing the securities firm as well as investor protection and market integrity.
4 Essential risks that are not included in the risk bearing capacity concept must be defined. Their non-inclusion must be comprehensibly justified.
5 The choice of methods and procedures for assessing risk bearing capacity lies in the responsibility of the securities firm. The assumptions underlying the methods and procedures must be comprehensibly justified. The management board must approve the risk bearing capacity concept and its essential elements. The securities firm must ensure that it has a complete and current overview at all times of the methods and procedures used for risk quantification. It must critically engage with them during reviews to determine whether the applied methods and procedures depict the risks sufficiently conservatively.
WpI MaRisk 11 of 35
AT 4.1.2 Capital Planning
Small and Medium-sized Securities Firms must have a process for planning future capital requirements and the capital available to cover these capital requirements, integrated into earnings and risk management. The planning horizon must cover an appropriately long, multi-year period. In doing so, it must be taken into account, if necessary, how changes in the firm's own business activities, strategic objectives, and the economic environment during this period affect capital requirements and capital stock. In addition to the plan scenario, at least one appropriate adverse scenario must be considered.
Consistency between Operational Business Planning and Capital Planning The capital planning of the securities firm must be consistent with its operational business planning and its strategic foundations.
AT 4.2 Strategies
1 The management board must define a viable business strategy in which the objectives of the securities firm for the essential business activities and the measures to achieve these objectives are presented. Plausible assumptions must be made regarding the development of essential influencing factors, which must be reviewed regularly and, if necessary, on an ad hoc basis; if required, the business strategy must be adapted.
Audit Activities by the Statutory Auditor or Internal Audit The content of the business strategy lies solely in the responsibility of the management board and is not subject to review by the statutory auditor or Internal Audit. When reviewing the risk strategy, the business strategy must be used to ensure that the consistency between both strategies can be comprehended.
2 The management board must define a risk strategy that is consistent with the business strategy and the resulting risks. The risk strategy must include the objectives of risk management for the essential business activities as well as the measures to achieve these objectives. In particular, the risk appetite of the securities firm must be defined, taking into account risk concentrations.
3 The degree of detail of the strategies depends on the nature, scope, complexity, and risk content of the planned business activities. It is up to the securities firm to integrate the risk strategy into the business strategy.
WpI MaRisk 12 of 35
4 For the purposes of assessment, the objectives set out in the strategies must be formulated in such a way that a meaningful review of the achievement of objectives is possible.
Small Securities Firms In Small Securities Firms, the strategy process or the monitoring of the achievement of objectives can be designed simply. The strategy process must be designed in such a way that the monitoring of the achievement of pre-defined objectives by the management can be ensured.
5 The content and changes of the strategies must be communicated within the institution in a suitable manner.
AT 4.3 Internal Control Mechanisms
In every institution, appropriate to the nature, scope, complexity, and risk content of the business activities, a. regulations for organizational structure and workflow must be established, b. risk management processes must be set up, c. a compliance function must be implemented, and d. to the extent proportionate and appropriate, a risk management function and Internal Audit must be established.
Employees of the risk management function, compliance function, and Internal Audit must be granted all necessary powers and unrestricted access to all information (in particular also the risk data of the securities firm) required for the fulfillment of their tasks.
AT 4.3.1 Organizational Structure and Workflow
The organizational structure and workflow must ensure that incompatible activities are generally carried out by different employees. Processes, tasks, competencies, responsibilities, and communication channels must be clearly defined and coordinated. Conflicts of interest must also be avoided in the event of job changes.
WpI MaRisk 13 of 35
When employees change functions, care must be taken to avoid self-review and self-monitoring in principle.
AT 4.3.2 Risk Management Processes
1 The securities firm must establish appropriate processes for a. identification b. assessment c. control, and d. monitoring and communication of essential risks. The securities firm must also address operational risks through appropriate risk management. Risks and risk concentrations must be effectively limited and monitored, taking into account the risk appetite and, where AT 4.1.1 is applicable, risk bearing capacity. These processes must be integrated into a common earnings and risk management. The securities firm must ensure appropriate recording of loss events.
Risks and Risk Concentrations To limit and monitor risks and risk concentrations, quantitative instruments (e.g., limit systems, traffic light systems) and qualitative instruments (e.g., regular risk analyses) can be used. The limitation and monitoring of risks included in the risk bearing capacity concept generally takes place on the basis of an effective limit system. For risks that cannot be sensibly limited by limits, other, possibly qualitative, instruments are used.
Loss Events Depending on the size of the institution and its business model, the establishment of an event database for loss events may be necessary.
2 The risk management processes must ensure that essential risks are detected early, fully captured, and appropriately represented.
3 The management board must be informed at appropriate intervals about the business situation and risk situation, including risk concentrations.
4 Information that is essential from a risk perspective must be forwarded without delay to the management board, the respective persons responsible, and, if necessary, Internal Audit, in order to initiate appropriate measures early.
WpI MaRisk 14 of 35
AT 4.3.3 Stress Tests
1 Medium-sized Securities Firms regularly conduct stress tests that also take into account extraordinary but plausibly possible events. The frequency of implementation and the design of the stress tests are to be determined by the securities firm, taking into account the nature, scope, complexity, and risk content of the business activities and the internal and external influencing factors (in particular economic fluctuations and market changes). The identified essential risks must be appropriately covered. Interactions between individual risks must be appropriately considered.
Requirements for Certain Medium-sized Securities Firms For the purposes of this section, heightened requirements are to be placed on securities firms that trade financial instruments on their own account to a relevant extent, engage in issuance business, or acquire ownership or possession of client funds or client securities.
2 The results of the stress tests must be critically reflected upon. It must be investigated whether, and if so, what need for action exists. The results of the stress tests must also be appropriately considered in the assessment of risk bearing capacity.
Need for Action If a need for action is identified, measures such as intensified monitoring of risks, limit adjustments, or adjustments in business policy orientation may be suitable. A backing with risk coverage potential is required if the stress tests are consciously used to quantify internal capital requirements.
AT 4.4 Special Functions
AT 4.4.1 Risk Management Function
1 To the extent that this is appropriate and proportionate given the nature, scope, complexity, and risk content of the business conducted, securities firms establish an independent risk management function. If a securities firm does not establish a risk management function, the responsibilities for the corresponding tasks lie with the management board. The management board can delegate operational tasks internally or outsource them in accordance with AT 9 Para. 5.
If no independent risk management function is established, measures to avoid or limit conflicts of interest must be implemented.
Requirement for Certain Securities Firms For securities firms that acquire ownership and possession of client funds or client securities, distribute complex products, or operate a Multilateral Trading Facility (MTF) or Organized Trading Facility (OTF), the establishment of an independent risk management function is generally appropriate and proportionate.
WpI MaRisk 15 of 35
2 The risk management function should support the management board on risk issues, be actively involved in the development of the risk strategy, capture and assess risks, develop early warning systems, monitor risks, and report regularly to the management board. Information that is essential from a risk perspective must be forwarded to the management board without delay.
3 The head of the risk management function must be involved in important risk policy decisions of the management board. This task must be assigned to a person at a sufficiently high management level.
AT 4.4.2 Compliance Function
1 Securities firms must have a compliance function to counteract the risks that may arise from non-compliance with legal regulations and requirements. The compliance function must promote the implementation of effective procedures for compliance with the legal regulations and requirements essential for the institution and corresponding controls. Furthermore, the compliance function must support and advise the management board on compliance with these legal regulations and requirements.
Relationship to Other Regulatory Requirements All other requirements resulting from supervisory laws outside the WpIG remain unaffected.
2 The compliance function identifies essential legal regulations and requirements, the non-compliance with which could endanger the assets of the securities firm, at regular intervals, taking risk perspectives into account. The compliance function must ensure within the framework of a structured process that the respective affected areas monitor compliance with these regulations and requirements.
3 The compliance function is generally subordinate directly to the management board. However, taking into account the nature, scope, complexity, and risk content of the activities of the securities firm, it can also be attached to the risk management function and other suitable functions, provided that a direct reporting line to the management board exists. The compliance function must be located independently of the operational areas.
WpI MaRisk 16 of 35
4 The securities firm must appoint a compliance officer who is responsible for the leadership and fulfillment of the tasks of the compliance function.
Proportionality The task of the compliance officer can be performed by a member of the management board, taking into account the principle of proportionality. Conflicts of interest must be avoided in doing so.
5 The compliance function reports to the management board at least annually and on an ad hoc basis. The report also contains indications of deficits and countermeasures and is forwarded to Internal Audit.
AT 4.4.3 Internal Audit
1 To the extent that this is appropriate and proportionate given the nature, scope, complexity, and risk content of the business conducted, securities firms establish Internal Audit as an independent unit. If the establishment of a separate audit unit is disproportionate, the tasks can be performed by a member of the management board. If no separate independent audit unit is established, measures to avoid or limit conflicts of interest must be implemented. If the establishment of a separate audit unit and the performance of the task by a member of the management board are both disproportionate, the performance of the task may be omitted.
Presumption of Disproportionality Disproportionality of the establishment of an independent Internal Audit unit and the performance of the tasks by a member of the management board is generally assumed if the securities firm, including the management board, has fewer than ten employees or corresponding full-time equivalents. The scope of outsourced areas must be included in an appropriate manner.
Audit Unit The establishment of an independent Internal Audit unit is generally appropriate and proportionate if the securities firm acquires ownership or possession of client funds or client securities, distributes complex products, or operates an MTF or OTF. In these cases, the aforementioned presumption of disproportionality does not apply.
WpI MaRisk 17 of 35
2 The planning, methods, and quality of the audit must be reviewed and further developed regularly and on an ad hoc basis. The management board must inform Internal Audit of essential decisions.
3 Internal Audit is directly subordinate to the management board and reports to them. Internal Audit must perform its tasks independently and independently and is not subject to instructions regarding the valuation of the audit results.
4 Internal Audit must examine and assess in a risk-oriented and process-independent manner whether risk management is effective and appropriate and whether essentially all activities and processes are proper, also in the event of outsourcing.
5 The activity of Internal Audit must be based on an audit plan. Audit planning must be risk-oriented and, for Medium-sized Securities Firms, annual, and must be approved by the management board. It must be ensured that short-term necessary special audits can be carried out at any time. Essentially all activities and processes from a risk perspective, including those that are outsourced, must generally be reviewed within three years. Other activities and processes must be reviewed at an appropriate rhythm. However, in the presence of special risks, a shorter review cycle is required.
6 The audits must be documented with comprehensible working papers. A document containing the audit subject, findings, and, if necessary, measures must be created promptly for each audit and submitted to the responsible management board members. Significant deficiencies must be highlighted particularly. These documents and working papers must be retained for six years.
Reporting to the Management Board If a quarterly report is created, the submission of the documents for the individual audits can be waived.
Grading of Deficiencies A distinction is made between "significant," "serious," and "particularly serious" deficiencies. This differentiation represents a graded classification of the identified deficiencies according to their significance from a risk perspective. The specific delimitation of the individual categories lies with the respective securities firm. For deficiencies with low risk relevance, the securities firm can define independent criteria.
7 If serious findings against members of the management board arise during the audits, Internal Audit must report to the management board without delay. These must inform BaFin and the Deutsche Bundesbank without delay.
WpI MaRisk 18 von 35
8 The Internal Audit must report to the Management Board in a concise manner on the significant deficiencies identified during the annual cycle and on the material deficiencies that have not yet been remedied (annual report).
9 The Internal Audit must monitor the timely remediation of deficiencies identified during audits in an appropriate manner. If necessary, a follow-up audit should be initiated for this purpose.
If material deficiencies are not remedied within an appropriate period, the Internal Audit must inform the Management Board in writing.
AT 5 Organizational Policies
1 The securities firm must ensure that business activities are conducted on the basis of organizational policies (e.g., manuals, work instructions, or workflow descriptions) and that these serve as a basis for audit by the Internal Audit.
2 The organizational policies must be documented in text form and made known to the affected employees in an appropriate manner. The policies must be adapted promptly in the event of changes to activities and processes and made available to employees in their current version.
3 The organizational policies must in particular contain the following:
a. Regulations for the structural and functional organization, as well as for the assignment of tasks, allocation of competencies, and responsibilities,
b. Regulations regarding the design of risk management processes,
c. Regulations on Internal Audit,
Outsourcing
The regulations on procedures for outsourcing must cover the central phases of the lifecycle of outsourcing agreements and contain definitions of the principles, responsibilities, and processes.
WpI MaRisk 19 von 35
d. Regulations ensuring compliance with legal regulations and requirements (e.g., data protection, compliance),
e. Regulations on procedures for outsourcing,
f. depending on the size of the securities firm as well as the nature, scope, complexity, and risk content of the business activities, a code of conduct for employees.
AT 6 Documentation
1 Business, control, and monitoring documents must be drafted systematically and in a manner comprehensible to knowledgeable third parties, and retained for five years. The currency and completeness of the file management must be ensured.
2 The implementation of the requirements, material actions, and determinations set out in this circular must be documented. This also includes determinations regarding in which cases the involvement and decision-making of the Management Board is required.
AT 7 Resources
AT 7.1 Personnel
1 The securities firm must align the type and scope of its staffing with internal requirements, business activities, and the risk situation. The staffing must be suitable to ensure the uninterrupted operation of business processes.
2 Employees and their representatives must possess the necessary knowledge and experience depending on their tasks, competencies, and responsibilities.
WpI MaRisk 20 von 35
AT 7.2 Technical-Organizational Equipment
1 The scope and quality of the technical-organizational equipment must be aligned with internal requirements, business activities, and the risk situation.
2 Appropriate technical and organizational capacities must be maintained for the generation of data and information on material risk types. Furthermore, effective processes must be established to ensure data quality, enabling the correct and complete recording and presentation of the material risk components.
AT 7.3 Emergency Management
Precautions must be taken through an emergency concept for activities and processes that represent critical or important functions. The measures defined therein must be suitable to limit possible damage. The effectiveness and appropriateness of the emergency concept must be reviewed regularly. The emergency concept must be updated as needed, reviewed annually for currency, and communicated appropriately.
AT 8 Adaptation Processes
AT 8.1 New Product Process
Securities firms must understand their business activities. For the introduction of business activities in new products or on new markets (including new distribution channels), a concept must be prepared in advance that presents the risk content, the impact on the overall risk profile, and the consequences for risk management.
Content of the Concept
The consequences to be presented include those regarding organization, personnel, necessary adjustments to ICT systems, methods for assessing associated risks, and legal consequences (e.g., accounting and tax law), insofar as they are of material significance.
WpI MaRisk 21 von 35
A test phase must generally be conducted before trading in new products or on new markets. The Special Functions (AT 4.4) must be involved in the concept and test phase.
The concept and the commencement of business activities require the approval of the competent Management Board. Delegation with clear specifications is permissible.
The securities firm must maintain a catalog of the products and markets it distributes.
Resumption
For products and markets that have not been the subject of business activities for a longer period, the new product process must be reviewed for re-execution upon the resumption of business activities.
One-off Transactions
In the case of trading transactions, a test phase may be waived within the framework of one-off transactions.
AT 8.2 Changes to Operational Processes or Structures
Before material changes to the structural and functional organization as well as to ICT systems, the securities firm must analyze the impact of the planned changes on control procedures and control intensity. The organizational units to be integrated into the workflows later must be included in these analyses.
AT 9 Outsourcing
1 Outsourcing exists when a securities firm commissions another company to perform activities and processes in connection with the provision of securities services or other securities firm-typical services that it would otherwise provide itself.
Other External Procurement of Services
Other external procurement of services does not constitute outsourcing. This includes the one-time or occasional procurement of goods or services. This also includes services that are typically procured by securities firms and cannot be provided by them for factual or legal reasons, such as the use of market information services or representation in court.
Notwithstanding this, the securities firm must also ensure in the case of other external procurement of services that the regularity of the business organization is not impaired.
WpI MaRisk 22 von 35
Other Securities Firm-Typical Services
For other securities firm-typical services, Article 16(5) sentence 1 of MiFID II must be observed. Other securities firm-typical services also include, for example, the ancillary services listed in Annex I Section B of MiFID II.
DORA (Regulation (EU) 2022/2554)
Outsourced or externally procured ICT services pursuant to Article 3(21) of DORA, which are subject to ICT third-party risk management pursuant to Articles 28-30 of DORA, do not fall within the scope of AT 9.
2 The securities firm must assess, using a risk analysis, which risks are associated with outsourcing. Based on this, it must be determined which outsourcing of activities and processes is material from a risk perspective within the meaning of Section 40(1) of the Securities Trading Act (WpIG) in conjunction with Article 30 of Delegated Regulation (EU) 2017/565. The risk analysis must be carried out regularly and as needed on the basis of firm-wide or group-wide framework specifications. It must be adapted in the event of material changes to the risk situation.
The results of the risk analysis must be taken into account in outsourcing and risk steering.
The risk analysis must be supplemented by a scenario analysis, insofar as this is sensible and proportionate.
Risk Analysis
In the risk analysis, all aspects relevant to the securities firm in connection with the outsourcing must be considered, whereby the intensity of the analysis depends on the nature, scope, complexity, and risk content of the outsourced activities and processes. In the case of outsourcing of considerable significance, such as the complete or partial outsourcing of the risk management function, the compliance function, or the Internal Audit, intensive examination must be conducted to determine whether and how the inclusion of the outsourced activities and processes in risk management can be ensured.
Scenario Analysis
The scenario analysis represents a predefined event in which multiple or all risk factors are changed simultaneously.
3 For outsourcing that is not material from a risk perspective, the general requirements for internal corporate governance pursuant to Section 41 WpIG must be observed.
4 Generally, activities and processes may be outsourced as long as this does not impair the regularity of the business organization pursuant to Section 40 WpIG. Outsourcing does not result in the delegation of the Management Board's responsibility to the outsourcing company. The management tasks of the Management Board may not be outsourced. The Internal Audit of the outsourcing securities firm may refrain from its own audit activities, provided that audit activities are carried out elsewhere that meet supervisory requirements and the performance of the outsourcing company
WpI MaRisk 23 von 35
relevant audit results are passed on. The Internal Audit of the outsourcing institution must regularly satisfy itself of compliance with these prerequisites.
Special standards arise in the case of the complete or partial outsourcing of the risk management function, the compliance function, and the Internal Audit. Outsourcing must not lead to the securities firm existing only as an empty shell (Empty Shell).
Registration by the competent supervisory authorities would be required, it must further ensure:
Empty Shell
An "Empty Shell" may exist in particular in the following cases:
5 Outsourcing of activities and processes in control areas may be carried out to an extent that ensures effective monitoring of the services provided by the outsourcing company by the securities firm, subject to the requirements mentioned in paragraph 4.
In the case of outsourcing activities that fall under risk management, Internal Audit, or the compliance area, it must be ensured in particular that the necessary knowledge remains in the securities firm and that the Management Board continues to be able to fulfill and exercise its responsibilities.
Risk Management
In the area of risk management, operational activities such as ongoing monitoring, reporting, etc., may be outsourced, but not risk-relevant decisions.
Internal Audit
In the area of Internal Audit, it must be ensured that a basic knowledge of audit remains in the outsourcing securities firm. The ultimate responsibility for audit planning, preparation of the overall report, and tracking of deficiency remediation is not delegable.
6 The securities firm must take precautions in the case of material outsourcing to ensure the continuity and quality of the outsourced activities and processes even after the termination of the outsourcing agreement.
WpI MaRisk 24 von 35
7 In the case of material outsourcing, the outsourcing agreement documented in text form must in particular agree on the following:
a. Specification and, if necessary, delimitation of the services to be provided by the outsourcing company,
b. Date of commencement and, if necessary, end of the outsourcing agreement,
c. the applicable law for the outsourcing agreement, if deviating from German law,
d. locations (i.e., regions or countries) where the service is performed and/or significant data is stored and processed, and the regulation that the securities firm will be notified if the outsourcing company changes its location,
e. agreed service quality with clearly defined performance targets,
f. where applicable, obligation of the outsourcing company to provide proof of insurance,
g. requirements for the implementation and review of emergency concepts,
h. definition of appropriate information and audit rights for the Internal Audit as well as external auditors,
i. ensuring the unrestricted information and audit rights as well as control possibilities of the authorities competent pursuant to Section 40(3) WpIG regarding the outsourced activities and processes,
j. where necessary, right to issue instructions,
k. regulations ensuring that data protection provisions and other security requirements are observed,
l. termination rights and appropriate notice periods,
Right to Issue Instructions of the Securities Firm
Explicit agreement on right to issue instructions in favor of the securities firm may be waived if the service to be provided by the outsourcing company is sufficiently clearly specified in the outsourcing agreement.
Audits by Internal Audit
The Internal Audit of the outsourcing securities firm may refrain from its own audit activities under the conditions of AT 9 paragraph 4. These relaxations may also be utilized for outsourcing to so-called multi-tenant service providers.
Information and Audit Rights
Information and audit rights pursuant to paragraph 7 letters h and i also include the rights necessary for entry, access, or access.
Other Security Requirements
Regulations on other security requirements should be agreed contractually for all, i.e., also non-material outsourcing.
WpI MaRisk 25 von 35
m. Regulations on the possibility and modalities of further outsourcing (including reporting obligations), ensuring that the securities firm continues to comply with supervisory requirements,
n. obligation of the outsourcing company to inform the securities firm about developments that could impair the proper completion of the outsourced activities and processes.
8 With regard to further outsourcing, consent reservations in favor of the outsourcing securities firm should be agreed in the outsourcing agreement wherever possible. Furthermore, the contractual agreements for further outsourcing must include an obligation of the outsourcing company to inform the outsourcing securities firm. It must be ensured that the outsourcing company remains reporting-obligated to the outsourcing institution in the event of further outsourcing to a subcontractor.
9 The securities firm must appropriately steer the risks associated with outsourcing and properly monitor the execution of the outsourced activities and processes. This includes, in the case of material outsourcing, the ongoing monitoring of the performance of the outsourcing company.
10 For the documentation, steering, and monitoring of material outsourcing, the securities firm must define clear responsibilities.
11 The requirements for the outsourcing of activities and processes also apply to the further outsourcing of outsourced activities and processes.
Risk Analysis
The risks associated with further outsourcing are assessed as part of the risk analysis pursuant to AT 9 paragraph 2. This also includes the assessment of the materiality of further outsourcing.
Furthermore, the risk must be taken into account that the ability of institutions to monitor outsourced activities and processes may be restricted by long and complex outsourcing chains.
WpI MaRisk 26 von 35
12 Each securities firm must establish a central outsourcing management depending on the nature, scope, complexity, and risk content of the outsourcing.
Its tasks include in particular:
a. the implementation and further development of appropriate outsourcing management and corresponding control and monitoring processes,
b. the regular and as-needed assessment of the service quality of the outsourcing companies depending on the nature, scope, complexity, and risk content of the outsourced activities and processes,
c. the creation and continuous maintenance of complete documentation of the outsourcing, including further outsourcing (outsourcing register),
d. if necessary, support of the business units regarding firm-internal and legal requirements in outsourcing,
e. if necessary, coordination and review of the risk analysis carried out by the competent departments pursuant to paragraph 2.
13 The following relaxations apply for groups within the meaning of Section 2(24) WpIG or financial conglomerates:
a. In the case of group and affiliated internal outsourcing, effective precautions at the group or conglomerate level, in particular a uniform and comprehensive risk management and piercing rights, may be taken into account in a risk-reducing manner in the creation and adaptation of the risk analysis within the framework of the risk analysis pursuant to paragraph 2.
b. For the outsourcing of several institutions of a group or a conglomerate to one or more common outsourcing companies, there is the possibility of establishing a central outsourcing management at the group or conglomerate level, provided that the central
Common Emergency Concepts
If the institutions within an institutional group or a financial conglomerate have agreed on a common emergency concept for a material outsourcing pursuant to AT 7.3, the securities firms must retain the part of the emergency concept relevant to them.
WpI MaRisk 27 von 35
common outsourcing management meets the requirements of section AT 9.
BT 1 Special Requirements for Internal Control Mechanisms
This section presents special requirements for the design of internal control mechanisms (BTH, BTV, and BTR). These concern the design of trading activities (BTH) and the connection of contractually bound intermediaries (BTV). Furthermore, requirements are presented for the design of risk management processes for risks to customers, risks to the market, risks to the securities firm, other risks, liquidity risks, and the risk of disorderly resolution (BTR).
BTH Special Requirements for the Design of Trading Activities
BTH 1 Separation of Functions
1 The decisive principle for the design of processes in trading is the clear structural separation of the trading area from risk management as well as settlement and control up to and including the level of the Management Board.
2 The separation of functions up to and including the level of the Management Board may be dispensed with if the trading activities as a whole focus on trading transactions that are classified as non-material from a risk perspective ("non-risk-relevant trading activities").
Non-Risk-Relevant Trading Activities
Securities firms may utilize this relaxation if the volume of trading activities (trading and investment book transactions) is low measured against the business volume and the structure of the trading activities is not complex. In this case, the proper execution of trading transactions must be ensured by the direct involvement of the Management Board.
WpI MaRisk 28 of 35
BTH 2 Requirements for Processes in Trading Business
Securities firms must ensure that trading activities are designed to be transparent and secure, so that misunderstandings or errors can be detected and corrected early. Trading activities must therefore be conducted and settled in accordance with market conventions.
Trading activities are subject to ongoing control. Identified discrepancies and anomalies must be clarified immediately under the leadership of a department independent of trading.
Trading activities (including ancillary agreements that lead to positions) must be immediately reflected in risk management.
BTV Attachment of Contractually Bound Intermediaries
Overall Inclusion of Risks In the context of the risk analysis for this outsourcing, the securities firm must consider not only the activity of the individual bound intermediary but also the significance of liability assumptions overall with regard to the risk management of the securities firm.
The securities firm must have the professional suitability and reliability of an intermediary demonstrated to it in a suitable form and document this. The suitability must be taken into account when selecting the product range.
The status as a contractually bound intermediary pursuant to Section 3 Paragraph 2 WpIG is only established when the liable securities firm announces the assumption of liability pursuant to the Ordinance on Contractually Bound Intermediaries and the Public Register pursuant to Section 2 Paragraph 10 Sentence 5 of the Banking Act (KWG) and pursuant to Section 3 Paragraph 2 Sentence 5 of the Securities Institutes Act (KWGWpIGVermV) to BaFin.
The liable securities firm must develop strategies and procedures to systematically monitor the activity of each of its contractually bound intermediaries.
In doing so, the securities firm must take into account the special position of the contractually bound intermediaries in relation to the liability umbrella in its organizational precautions and regulations for their integration and monitoring.
The securities firm must ensure that statutory and internal requirements are complied with through suitable procedures, such as spot checks, computer-aided controls, or on-site audits. This also applies to contractually bound intermediaries who operate independently and in separate locations.
Relationship with Third Parties The contractually bound intermediary acts legally and economically for the liable securities firm and is to be integrated into its sales organization. As far as the contractually bound intermediary performs activities under the exception regulation of Section 3 Paragraph 2 WpIG, the securities firm must ensure that it appears as the invoicing party to customers and that payments from customers are recorded in the securities firm's accounting in accordance with commercial law provisions.
BTR Requirements for Risk Management Processes This section presents special requirements for the design of risk management processes (AT 4.3.2), taking into account risk concentrations, for:
Material Risks The special requirements under BTR generally apply only if and to the extent that the risks mentioned here have been classified as material in accordance with AT 2.2 Para. 1.
Business-Specific Capital Risks Risks from ongoing operations are business-specific capital risks.
WpI MaRisk 29 of 35
BTR 1 Risks from Ongoing Operations
BTR 1.1 Risks for Customers
Risks for Customers Risks for customers are the risks that customers of the securities firm may incur from transactions within the meaning of AT 2.3 Para. 1.
Risk Identification Indications of risks are above all the K-factor requirements pursuant to Regulation (EU) 2019/2033 (IFR) as well as previous losses or damages due to breaches of duty.
Losses or damages due to breaches of duty may include in particular: Incorrect or insufficient investment advice, missing or inadequate control procedures, errors in trading or valuation, failures of systems or processes, actions by contractually bound intermediaries or representatives.
Further indications for determining the risk for customers arise from Article 6 Paragraph 2 of Delegated Regulation (EU) 2023/1668.
Securities firms that do not provide separate custody of customer funds pursuant to Section 84 Paragraph 2 of the Securities Trading Act (WpHG) must take this into account appropriately in the risks for customers.
The securities firm must examine whether the conclusion of professional liability insurance makes it possible to reduce risks towards customers.
Professional Liability Insurance The conclusion of professional liability insurance does not reduce the requirements for proper business organization.
BTR 1.2 Risks for the Market
Risks for the Market Risks for the market are the risks that market participants may incur from transactions within the meaning of AT 2.3 Para. 1 of the securities firm.
WpI MaRisk 30 of 35
b. the significance of trading in complex and illiquid products. c. market depth (role of the securities firm in the market, e.g., number of market participants/quote providers).
Small Securities Firms The requirements of BTR 1.2 do not apply to small securities firms.
BTR 1.3 Risks for the Securities Firm
Risks for the Securities Firm Risks for the securities firm are loss risks that may arise directly to the securities firm itself.
Positions to be Considered In determining risks for the securities firm, the securities firm must take into account the positions mentioned in Section 45 Paragraph 3 WpIG. Here, risks from non-trading book transactions must also be included. Further indications for determining the risk for the securities firm arise from Article 6 Paragraph 4 of Delegated Regulation (EU) 2023/1668.
Small Securities Firms Even small securities firms that have identified material loss risks as part of their risk inventory must take these into account appropriately as part of proper corporate governance.
Small Securities Firms Paragraphs 2-9 do not apply to small securities firms.
Loss Risks The mention of loss risks due to market price changes in the following paragraphs does not automatically mean that such transactions must always be attributed to the risks for the securities firm.
WpI MaRisk 31 of 35
Counterparty Limits Excluded from this are exchange transactions and cash transactions where the consideration has been acquired or is to be acquired simultaneously or where corresponding coverage exists.
In addition, issuer limits must generally be established for trading activities. If no limit regulation exists for issuers in the trading area yet, issuer limits can be granted for trading purposes in the short term on the basis of clear specifications.
No transaction involving loss risks from changes in market prices may be concluded without a market price risk limit.
It must be ensured that transactions involving loss risks from changes in market prices are immediately credited against the relevant limits. The person responsible for positions must be informed promptly about the limits relevant to them and their current utilization.
Limit utilization must be monitored continuously. Exceedances and measures taken must be documented. From a risk-based threshold, exceedances must be reported daily to the responsible managing director.
The procedures for assessing loss risks from changes in market prices must be reviewed at appropriate intervals, including with regard to their reliability in the event of market disruptions. For prolonged cases of missing, outdated, or distorted market prices, alternative valuation methods must be defined for material positions.
Trading book positions must be valued daily and a result must be determined. The existing risk positions must be summarized at least once daily at the end of the business day into total risk positions.
WpI MaRisk 32 of 35
The risk values determined by model must be continuously compared with actual development.
A result for the investment book must also be determined at least quarterly.
Market Risks in the Investment Book Depending on the type, scope, complexity, and risk content of the positions in the investment book, daily, weekly, or monthly valuation, result determination, and communication of risks may also be required.
BTR 2 Other Risks Securities firms must consider all material risks, even if they are not covered by the risk types mentioned in BTR 1, 3, and 4.
BTR 3 Liquidity Risks
Intraday Liquidity Risk The management of intraday liquidity risk is generally expected from securities firms that trade on own account or engage in issuance business.
Liquidity Overviews For small securities firms, it is generally sufficient to create one or more meaningful liquidity overviews for a suitable period, in which expected cash inflows are compared with expected cash outflows. Here, the effects of potentially delayed payments and payment defaults must also be taken into account appropriately.
WpI MaRisk 33 of 35
Prevention of Liquidity Shortages Medium-sized securities firms must size their liquid assets and other liquidity resources so that liquidity needs arising in both normal market phases and predefined stress scenarios can be fully bridged. It must be ensured that the use of liquid assets is not opposed by legal, regulatory, technical, or operational restrictions.
Medium-sized securities firms must define measures to prevent or overcome liquidity shortages and regularly review the appropriateness of these precautions.
BTR 4 Risk of Disorderly Wind-Down
Medium-sized securities firms must regularly and on an ad hoc basis determine within what timeframe an orderly wind-down could take place and what costs (wind-down-specific and ongoing) would arise in this period. The period until the cessation and wind-down of securities services or until the return of the authorization is decisive. The results must be documented in writing and explained in a comprehensible manner upon request by the supervisory authority. In cases where the institution acquires ownership and possession of customer funds or customer securities, these results must be more detailed.
The results must be critically reflected upon. It must be investigated whether and, if so, what need for action exists.
WpI MaRisk 34 of 35
BT 2 Requirements for Risk Reporting
Data must generally be collected and reported as of the cut-off date of the risk report.
Reporting Comprehensible and meaningful business and risk reporting also requires an appropriate content-related relationship between quantitative information and qualitative assessment of material positions and risks.
Risk reports must contain the stress test results, their assumptions, and their effects on the risk situation and risk coverage potential. Risk concentrations must also be presented separately.
The securities firm must also be able to create ad hoc risk reports outside the regular schedule if current risks or market developments require it. In addition to the regular creation of risk reports, the securities firm must be able to generate ad hoc risk information if this appears advisable due to the current risk situation of the securities firm or the current situation of the markets on which the securities firm is active.
The reports must be created in time so that risks can be actively and promptly managed. The creation time depends on the type and volatility of the risks.
WpI MaRisk 35 of 35
More like this from Bundesbank
Bundesbank published 1 document in the last 30 days. We email you each new one the day it's published.