Introduction
With the publication of the 9th amendment to MaRisk (only in German), BaFin and the Bundesbank have initiated a significant change of course: the supervisory authority aims to reduce the complexity of MaRisk, strengthen proportionality and grant institutions greater autonomy. Instead of further detailed regulations, the focus will in future be increasingly on a principles-based approach and risk-oriented implementation.
Particularly in the area of validation, there are notable simplifications for savings banks, co-operative banks and other smaller institutions. At the same time, however, this by no means implies that risk identification and parameterisation may be reviewed less frequently in future! Rather, the focus is shifting from regular (annual) reviews to more event-driven and risk-oriented monitoring.
Validation as one of the key areas for reducing the workload
In future, a standard validation carried out at intervals of (at least) three years will generally suffice. In addition, organisational simplifications will be introduced, for example regarding the separation of roles in model development, parameterisation and validation.
Particularly in the savings bank sector, where numerous procedures are provided, further developed and validated centrally by S Rating und Risikosysteme GmbH (SR), this represents a sensible and practical reduction in the administrative burden. On the one hand, the supervisory authority recognises the division of labour between centralised and decentralised validation; on the other hand, it takes into account that the added value of an annual full validation is often limited in the case of stable procedures, and that resources can be put to better use.
The new three-year cycle is therefore fundamentally sound. It enables institutions to focus their capacities more strongly on actual risk and management issues, rather than primarily on meeting regulatory cycle requirements.
However: Fewer regulatory validations do not mean less risk management
The new regulation is, however, frequently misunderstood. The regulator has not introduced a ‘validation hiatus’. Institutions must continue to ensure that the methods, models, data and results they use are appropriate, plausible and robust. The critical analysis of procedures and assumptions remains an integral part of the regulatory requirements.
The experiences of recent years in particular have shown that market conditions, interest rates, business models and risk drivers can change significantly within a short space of time. Those who wait exclusively for the next scheduled validation date run the risk of identifying key developments too late.
The success of the new regulations will therefore not be measured by how infrequently validation takes place, but by how effectively institutions identify and assess relevant changes between two scheduled validations.
Ad hoc validations are becoming a key control tool
As the frequency of scheduled validations is extended, the importance of event-driven validations is increasing significantly. The supervisory authority expressly expects institutions to define appropriate triggers which, when they occur, will result in an unscheduled review.
Typical triggers for ad hoc validation may include, for example:
- material changes to models or methodologies, such as those resulting from software releases,
- notable changes in risk indicators,
- market distortions or breaks in the yield curve,
- significant changes to the business or risk profile, and
- data quality issues or material audit findings.
The challenge here lies not so much in the documentation as in defining a practical and risk-based framework that is tailored to the institution’s specific circumstances.
Centralised validation provides the basis – responsibility remains with the institution
Another key aspect of the 9th amendment to MaRisk concerns the use of centrally validated procedures. The regulator makes it clear that institutions may refer to the work of central service providers, such as the SR for the savings banks. At the same time, however, the obligation remains to critically evaluate the results for their own institution and to assess their appropriateness.
The crucial question is therefore:
Is central validation sufficient for my organisation’s individual risk and portfolio structure, or are there additional issues that require further analysis?
Additional institution-specific validation procedures may be required, particularly in the case of special business structures, specific portfolios, regional particularities or exceptional developments.
This means that the expert assessment of the central validation results will, in future, be at least as important as the actual standard validation process.
Quality assurance is becoming more important than the validation cycle
Whilst there is intense debate about the new three-year cycle, another issue is increasingly coming into focus: the ongoing quality assurance of data, parameters and key performance indicators.
The validity of any risk measurement depends directly on the quality of the data and parameters used. Incorrect or incomplete data, or inappropriate or incomplete parameterisation, lead to flawed performance indicators. Ultimately, this can even result in misguided management decisions.
Institutions should therefore establish processes and regular mechanisms for:
- Data quality analyses, including data cleansing where necessary.
- Plausibility checks on risk metrics and the comparison of forecasts with actual developments.
- Monitoring of key parameters.
This creates a continuous quality assurance process that identifies risks at an early stage and serves as an early-warning system for potential ad hoc validations.
Conclusion
The 9th amendment to MaRisk, with its three-year validation cycle, represents one of the most significant simplifications of recent years. The new approach is sensible, practical and supports the desired proportionality in risk management.
However, anyone who views the change merely as a reduction in administrative burden is missing the point. Institutions’ responsibility for ensuring the adequacy of their procedures remains unchanged. Ad hoc validations, institution-specific assessments and the continuous quality assurance of data and results will become even more important in future.
A three-year interval until the next regulatory validation is a relief. However, it remains crucial that risks, data quality and model adequacy are continuously monitored.

How msg for banking supports savings banks with implementation
The new flexibility introduced by the 9th amendment to MaRisk opens up opportunities, but also presents many institutions with organisational and technical challenges. This is precisely where msg for banking supports savings banks in ensuring efficient and audit-proof implementation.
We provide support in revising existing validation concepts and processes. Together with the institutions, we develop a bespoke approach for unscheduled validations and audit procedures. In doing so, we define suitable triggers, thresholds, decision-making processes and documentation requirements to ensure that risks can be identified at an early stage, even between two scheduled validations.
Institution-specific assessment of central validations
We support savings banks in the technical assessment of central SR validations and in deriving institution-specific conclusions. This results in a transparent adequacy assessment that meets the expectations of regulators and auditors. This also includes assessing whether the underlying assumptions, data sets and models of the central SR validation are appropriate for the structure of the respective institution and whether the existing validation evidence is sufficient.
Supplementary quality assurance of data, parameters and results
A key focus is on establishing pragmatic and effective quality assurance processes. Particularly in the case of an extended validation cycle, quality assurance becomes a continuous management tool rather than merely an activity carried out as part of a routine validation process.
Market conditions change continuously, not just every three years; technical release processes also have a significantly shorter cycle. Key technical and business parameters within the models, in particular, must therefore undergo quality assurance much more frequently.













